vulnerability Critical GitLab Zero-Click Flaw Poses Mitigation Challenges GitLab has released an out-of-band security update addressing two critical vulnerabilities, CVE-2026-19478 and CVE-2062-19650, that could allow unauthenticated attackers to manipulate or delete data. The vulnerabilities stem from a code-injection flaw in GitLab's GraphQL functionality and a CSRF issue, respectively. Wh… Dark Reading · Aug 18, 2026 Critical CVE-2026-19478CVE-2026-19650graphqlcvezero-click
vulnerability Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client A Security, an Israeli offensive-security startup, discovered three Zoom vulnerabilities that could allow a meeting participant to hijack another attendee’s computer. The flaws, including a buffer over-write and a use-af… The Hacker News · Aug 11, 2026 High CVE-2026-53413CVE-2026-53414CVE-2026-53415ISzoomvulnerabilitybuffer overflow
vulnerability Zoom Patches Zero-Click Code Execution Vulnerability Zoom has released patches to address four critical vulnerabilities, including a zero-click remote code execution flaw that could allow an attacker to take control of any participant’s machine without any user interaction… SecurityWeek · Aug 11, 2026 Critical CVE-2026-53413CVE-2026-53414CVE-2026-53415vulnerabilityremote code executionzero-click
threat-intel Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts Zenity researchers have uncovered two zero-click hacking techniques targeting AI browser agents, ChatGPT Atlas and Claude in Chrome. These attacks allow attackers to hijack user sessions, conduct phishing campaigns (incl… SecurityWeek · Aug 6, 2026 High zero-clickprompt injectionagentic browser
threat-intel AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking A new vulnerability, dubbed 'PleaseFix,' is exposing AI browsers like Claude, Gemini, and Perplexity Comet to zero-click exploits. Attackers can inject malicious instructions into seemingly harmless content – such as ema… Dark Reading · Aug 5, 2026 High aiagentic browserzero-click
threat-intel Agentic Browsers Rewind Web Security by 20 years Researchers at Zenity have discovered a significant vulnerability class – "PleaseFix" – that allows attackers to socially engineer AI agentic browsers to perform malicious actions, including account takeover and remote c… Dark Reading · Jul 27, 2026 High agentic browserssocial engineeringzero-click
threat-intel International alert spotlights Russia-linked attacks on Zimbra webmail Russian state-aligned hackers, operating under the APT group Laundry Bear, are targeting governmental and commercial organizations globally through zero-click phishing campaigns exploiting a vulnerability in Zimbra webma… The Record · Jul 23, 2026 High CVE-2025-66376UKRUNEzero-clickphishingzimbra
threat-intel Russian Global Webmail Espionage A persistent cyberespionage campaign, tracked as CL-STA-1114, originating from Russian threat actors (Void Blizzard and LAUNDRY BEAR) is targeting Zimbra webmail instances across various sectors, including governments, d… Palo Alto Unit 42 · Jul 23, 2026 High CVE-2025-66376NAUKCIcyberespionagephishingvulnerability
threat-intel Spyware found on phone of European Parliament member probing it A former European Parliament member, Stelios Kouloglou, was repeatedly targeted with Pegasus spyware while investigating the misuse of commercial spyware. Citizen Lab researchers discovered the infections occurred during… The Record · Jul 3, 2026 High GRDERUspywarepegasuseuropean parliament
threat-intel Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands A critical vulnerability, dubbed DuneSlide, has been discovered in Cursor, an AI code editor used by over half of the Fortune 500, allowing attackers to bypass the editor's sandbox and execute arbitrary commands on a dev… The Hacker News · Jul 1, 2026 Critical CVE-2026-50548CVE-2026-50549CVE-2025-54135prompt-injectionsandboxai-code-editor
threat-intel A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens Google Project Zero researchers discovered a critical 0-click vulnerability in the Google Pixel 10's VPU driver, allowing for arbitrary kernel code execution. The vulnerability stems from a flaw in the `vpu_mmap` functio… Google Project Zero · May 13, 2026 Critical CVE-2025-54957zero-clickkernel-exploitationdriver-vulnerability