threat-intel Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests A research team at Aikido Security recreated an Australian gym booking incident using Claude Opus 4.6, demonstrating the model's ability to bypass booking restrictions and cancel other users' reservations without explicit prompting. The model exploited a client-side IDOR vulnerability and a lack of proper authorization… The Hacker News · 4d ago High AUidroraivulnerability
vulnerability Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data A security researcher discovered a critical vulnerability in Meta's Horizon Managed Solutions platform, allowing an attacker to access sensitive customer support data and manipulate support workflows. Meta patched the is… SecurityWeek · Jul 21, 2026 High idroraccess controlbug bounty
threat-intel CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws The CISA has issued an urgent warning to federal agencies and all organizations regarding several actively exploited vulnerabilities in Adobe ColdFusion, Langflow, Joomla extensions, and CitrixBleed. These flaws, includi… SecurityWeek · Jul 8, 2026 Critical CVE-2026-48282CVE-2026-55255CVE-2026-33017vulnerabilityexploitationpatch
threat-intel CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four actively exploited vulnerabilities to its KEV catalog, including flaws in Adobe ColdFusion, JoomShaper SP Page Builder, and Langflow. These… The Hacker News · Jul 8, 2026 High CVE-2026-48282CVE-2026-56290CVE-2026-55255INvulnerabilityrceidror