search
compromised running
Trends
- 1Hackers Weaponize Open-Source AI Agent Against Docker ServersโผHackers Turn an Open-Source AI Agent Into a Tool for Controlling Compromised Docker Servers
Hackers have repurposed an open-source AI agent into a command-and-control tool for operating compromised Docker servers. Security researchers report attackers are using the agent's automation capabilities to run commands, move laterally and manage infected containers remotely. The case highlights a growing trend of malicious actors abusing legitimate AI tooling, and Docker deployments left exposed online remain a prime target for takeover.
- 2Storm-3168 Wiped Azure Resources Using Stolen Service Principalsโ๐ค Storm-3168/JADEPUFFER abused compromised Azure service principals to run destructive operations โ deleting resources o
The threat actor tracked as Storm-3168, associated with the JADEPUFFER campaign, abused compromised Azure service principals to carry out destructive operations, deleting cloud resources over roughly 18 hours in early June 2026. Microsoft assesses the activity as an evolution of the actor's tradecraft, and security teams are being urged to review service principal permissions.
- 3Developer runs AI coding mentor entirely on budget Android phoneโMost people think building an AI coding mentor on a budget Android phone means cutting corners. They're wrong. Constrain
A developer reports stress-testing KODA, an AI coding mentor built to run on a low-cost Android phone, against nine industry benchmark challenges from Anthropic, OpenAI, DeepSeek and SpaceX/Grok. The argument is that tight hardware constraints force ruthless optimization rather than compromise, and that capable AI coding assistance does not require expensive infrastructure or flagship devices.
- 4Runner completes 10K session split by strength stationsโผโ ๐โโ๏ธ๐๏ธ10K Running ( 7K Compromised ) Started with 7 x 1K runs with 6 fitness stations in between. This is called compro
A fitness enthusiast completed a 10-kilometre run broken into seven 1-kilometre segments, with six strength stations in between โ wall balls, lunges and farmer carries. The format, known as compromised running, adds fatigue to each interval before finishing with an easy 3K treadmill jog. The whole workout took nearly 100 minutes. Compromised running is drawing attention as a hybrid training style mixing endurance and strength in a single session.
- 5Critical Command Injection Flaw Disclosed in Fortra BoKS Privileged Access ManagerโผCVE-2026-9862: Critical OS Command Injection Vulnerability in Fortra BoKS Core Privileged Access Manager Threatens System Security
A critical vulnerability tracked as CVE-2026-9862 has been disclosed in Fortra's BoKS Core Privileged Access Manager, an OS command injection flaw that could let attackers run arbitrary commands on affected systems. Security teams are being urged to patch or restrict exposure, given that privileged access management tools sit at the heart of enterprise infrastructure and a compromise would hand attackers keys to entire environments.
- 6Storm-3168 attackers exploit Azure via compromised service principalsโผActive Exploitation Alert: Storm-3168 (JADEPUFFER) Agentic Attack Targets Azure via Compromised Service Principals
Security firm Rescana has issued an alert about active exploitation by the threat group Storm-3168, also tracked as JADEPUFFER, which is using compromised Azure service principals to attack Microsoft Azure environments. The campaign is described as an agentic attack, meaning the attackers deploy automated tooling to move through cloud infrastructure. Organizations running Azure are being urged to review service principal credentials and permissions.
- 7
Advice columnist Annie fields a letter about an ongoing household dispute over thermostat settings, which the writer frames as a 'cold war' between family members or housemates. The column offers guidance on compromise and communication in shared living situations. Readers of the long-running advice feature follow such domestic conflicts for both entertainment and practical takeaways.
- 8Roundcube Webmail SQL Injection Flaw Actively ExploitedโผRoundcube Webmail SQL Injection Vulnerability CVE-2026-48842 Under Active Exploitation Roundcube Webmail high-severity S
A high-severity SQL injection vulnerability in Roundcube Webmail, tracked as CVE-2026-48842, is under active exploitation. The flaw resides in the virtuser_query plugin and allows unauthenticated attackers to compromise servers running the popular open-source webmail software. Security administrators are being urged to patch affected installations immediately and check systems for signs of compromise.
- 9Dell Patches Critical Flaws in Container Storage ModulesโผDell CSM Flaws Allow Unauthenticated Admin Access and Root on Kubernetes Nodes Dell patched 37 vulnerabilities in its Co
Dell has released fixes for 37 vulnerabilities in its Container Storage Modules, including six critical flaws. The most serious allow unauthenticated attackers to steal storage administrator credentials and gain root access on Kubernetes nodes. Administrators running Dell storage with Kubernetes are urged to apply the patches promptly to avoid credential theft and full system compromise.
- 10Microsoft's X account hacked in crypto pump-and-dump schemeโ# Microsoft โs # X account hacked in # crypto pump-and-dump scheme https://www. bleepingcomputer.com/news/secu rity/micr
Microsoft's X account was compromised and used to promote a cryptocurrency pump-and-dump scheme, according to security outlet BleepingComputer. The hijacked account was used to push a fraudulent token to Microsoft's large follower base, raising fresh concerns about the security of major corporate accounts on the platform.
- 11Sisi: Egypt backs diplomacy on Ethiopian dam, water security non-negotiableโผAl-Sisi: Egypt committed to diplomacy on Ethiopian dam, but water security is non-negotiable
Egyptian President Abdel Fattah Al-Sisi said Egypt remains committed to a diplomatic solution over Ethiopia's Grand Renaissance Dam, but stressed that the country's water security is a red line that cannot be compromised. His remarks underline the ongoing tension between Cairo and Addis Ababa over the Nile dam, which Egypt sees as a threat to its freshwater supply.
- 12DIVD reports compromise via chained Zammad vulnerabilitiesโDIVD reported a compromise involving two chained Zammad vulnerabilities, with session hijacking, remote code execution,
The Dutch Institute for Vulnerability Disclosure has reported a security compromise involving two chained vulnerabilities in the open-source ticketing system Zammad. The attack combined session hijacking, remote code execution, privilege escalation and data exfiltration, showing how separate flaws in a single service can be combined into a full intrusion path. Security professionals are circulating the report as a case study in chained exploits and the importance of patching interconnected components.
- 13Senators Reach Construction Permitting Deal Ahead of ElectionsโผSenators clinch construction permitting deal before election jet-set
A group of US senators has clinched a deal on construction permitting reform, reaching agreement just before lawmakers leave Washington for the election campaign period. The agreement would streamline approval processes for building projects, a long-stalled issue. With congressional time running out before the elections, the timing of the breakthrough is drawing attention to whether the deal can advance further.
- 14Microsoft details Zimbra flaw allowing code execution via emailโZimbra CVE-2026-73570 lets one crafted email run code. Microsoft details the Zimbra command injection attacks: web shell
Microsoft researchers have detailed attacks exploiting a Zimbra command injection vulnerability, CVE-2026-73570, in which a single crafted email is enough to run code on the mail server. The documented attacks involve deploying web shells, gaining root access, and stealing cryptographic keys. Security teams running Zimbra are being urged to patch and review their servers for signs of compromise.
- 15Affordable Fitness Band Challenging Expensive SmartwatchesโผThis Affordable Fitness Band Gives Expensive Smartwatches A Run For Their Money
A budget-priced fitness band is drawing attention for matching many features of far more expensive smartwatches. Coverage highlights its ability to track activity and health metrics at a fraction of the cost, prompting buyers to question whether premium smartwatches are worth the price. Commenters appear divided between praising the value and noting compromises in quality and features compared with high-end devices.
- 16Citrix NetScaler Flaw Used to Create Superuser Accountsโ๐ Security News Digest - 2026-10-01 ๐ 10 updates from 3 sources: ๐น The Hacker News: Citrix NetScaler Post-Exploitation P
Security reports detail post-exploitation activity targeting Citrix NetScaler appliances, where attackers deploy payloads that create superuser accounts and disguise web shells as CSS-like URLs to evade detection. The technique raises concerns for organisations running NetScaler gateways, as compromised devices may grant persistent privileged access. Administrators are advised to review devices for unexpected accounts and unusual URL patterns.
- 17Unsloth Studio Flaw Turns Model Inspection Into Code ExecutionโผUnsloth Studio Flaw Turns Routine Model Inspection Into Code Execution
A security vulnerability has been reported in Unsloth Studio that lets a routine AI model inspection action escalate into arbitrary code execution on a user's machine. The flaw means simply examining an untrusted model could compromise the system running it. Details on the affected versions, discovery, and patch status remain sparse as the story circulates among security and AI developer communities.
- 18Critical stored XSS flaw reported in Kiteworks Coreโ๐จ CVE-2026-102147 โ CVSS 9.3 CRITICAL A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an unau
Security researchers are flagging CVE-2026-102147, a critical vulnerability in Kiteworks Core carrying a CVSS score of 9.3. The flaw is a stored cross-site scripting weakness that could let an unauthenticated attacker plant crafted content which then executes arbitrary JavaScript in the session of an administrator who views it, potentially giving attackers privileged access. Organizations running Kiteworks are urged to review the advisory and apply patches.
- 19US senators reach deal on energy permitting billโUS senators hit deal on energy project permitting bill, vote seen after November
A bipartisan group of US senators has reached an agreement on a bill to reform permitting for energy projects, with a vote expected after November. The legislation aims to speed up approvals for power lines, pipelines and other infrastructure. Details of the compromise and its chances of passing remain to be seen, and the proposal is likely to draw scrutiny from both environmental groups and industry.
- 20Cisco Patches Exploited SD-WAN Zero-Day VulnerabilityโCisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability
Cisco has released patches for a zero-day vulnerability in its Catalyst SD-WAN software that was being actively exploited, according to a report by SecurityWeek. The flaw allowed attackers to compromise affected SD-WAN devices. Administrators are urged to apply the updates promptly, and details about the exploitation campaign remain limited.
- 21Questions raised over Seventh-day Adventist Church's UN tiesโDoes the Adventist Church have close ties to the UN?
Adventist Today is examining whether the Seventh-day Adventist Church maintains close institutional ties to the United Nations. The question touches on a long-running debate within the denomination, where some members worry that official engagement with UN bodies, including its status as an NGO, could compromise the church's independence, while others see advocacy work as consistent with its humanitarian mission. The publication invites readers to weigh the evidence behind the claim.
- 22Kiteworks patches critical vulnerability after intelligence warningโKiteworks patched an undisclosed critical vulnerability after federal intelligence warned of an imminent attack that pro
Kiteworks has patched an undisclosed critical vulnerability after federal intelligence warned of an imminent attack, prompting the company to shut down servers globally. All hosted instances have been restored, and no evidence of compromise has been reported. Operators running on-premises Kiteworks deployments are being urged to prioritize applying the patch to protect their systems.