<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Update &#8211; First Hackers News</title>
	<atom:link href="https://firsthackersnews.com/category/security-update/feed/" rel="self" type="application/rss+xml" />
	<link>https://firsthackersnews.com</link>
	<description>Latest cybersecurity news, real attacks, and practical IOCs—made simple and actionable.</description>
	<lastBuildDate>Fri, 07 Aug 2026 22:03:53 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.6</generator>

<image>
	<url>https://firsthackersnews.com/wp-content/uploads/2026/03/cropped-FHN_512x512-32x32.png</url>
	<title>Security Update &#8211; First Hackers News</title>
	<link>https://firsthackersnews.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Windows Hello Key Flaw Opens Door to Entra ID Access</title>
		<link>https://firsthackersnews.com/windows-hello-for-business-security-flaw/</link>
					<comments>https://firsthackersnews.com/windows-hello-for-business-security-flaw/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Fri, 07 Aug 2026 15:50:00 +0000</pubDate>
				<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[Windows Security]]></category>
		<category><![CDATA[active directory]]></category>
		<category><![CDATA[Authentication]]></category>
		<category><![CDATA[cloud security]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[Enterprise Security]]></category>
		<category><![CDATA[Entra ID]]></category>
		<category><![CDATA[identity security]]></category>
		<category><![CDATA[MFA]]></category>
		<category><![CDATA[Microsoft Entra]]></category>
		<category><![CDATA[microsoft security]]></category>
		<category><![CDATA[Passwordless Authentication]]></category>
		<category><![CDATA[security research]]></category>
		<category><![CDATA[threat intelligence]]></category>
		<category><![CDATA[Windows Hello for Business]]></category>
		<category><![CDATA[windows security]]></category>
		<category><![CDATA[Zero Trust]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12149</guid>

					<description><![CDATA[<p>Security researcher Dirk-jan Mollema has uncovered a new technique that could allow attackers to misuse Windows Hello for</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/windows-hello-for-business-security-flaw/">Windows Hello Key Flaw Opens Door to Entra ID Access</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Security researcher <strong>Dirk-jan Mollema</strong> has uncovered a new technique that could allow attackers to misuse <strong>Windows Hello for Business (WHFB)</strong> to authenticate to Microsoft Entra ID services without requiring the victim&#8217;s password, PIN, or biometric verification.</p>



<p>Rather than breaking Windows Hello encryption, the technique takes advantage of an already authenticated Windows session. If an attacker gains access to a logged-in device, they may be able to leverage the victim&#8217;s existing Windows Hello credentials to request authentication tokens and potentially establish long-term access to Microsoft Entra resources.</p>



<p>The research highlights how attackers can abuse trusted authentication mechanisms once an endpoint has already been compromised.</p>



<h2 class="wp-block-heading"><strong>How the Attack Works</strong></h2>



<p>Windows Hello for Business replaces passwords with cryptographic keys that are securely stored on the user&#8217;s device, typically inside the <strong>Trusted Platform Module (TPM)</strong>. These keys are designed to remain protected and cannot normally be exported from the device.</p>



<p>However, the research demonstrates that an application running with standard user privileges inside an active Windows session can request cryptographic operations from the Windows Hello key without asking the user to re-enter their PIN or biometric authentication.</p>



<figure class="wp-block-image size-large"><img fetchpriority="high" decoding="async" width="1024" height="282" src="https://firsthackersnews.com/wp-content/uploads/2026/08/image-1024x282.png" alt="" class="wp-image-12153" srcset="https://firsthackersnews.com/wp-content/uploads/2026/08/image-300x83.png 300w, https://firsthackersnews.com/wp-content/uploads/2026/08/image-768x212.png 768w, https://firsthackersnews.com/wp-content/uploads/2026/08/image-1024x282.png 1024w, https://firsthackersnews.com/wp-content/uploads/2026/08/image-1536x423.png 1536w, https://firsthackersnews.com/wp-content/uploads/2026/08/image.png 1600w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><strong>Windows Hello Authentication Flow (Source: Dirk-jan Mollema)</strong></figcaption></figure>



<p>Instead of stealing the private key itself, the attacker simply instructs Windows to use it on their behalf. As long as the user remains logged in, Windows considers the authentication request valid.</p>



<p>This effectively allows attackers to &#8220;borrow&#8221; the trusted Windows Hello credentials without directly compromising them.</p>



<h2 class="wp-block-heading"><strong>Authentication Without Traditional Credentials</strong></h2>



<p>Researchers showed that the borrowed Windows Hello key can be used during Microsoft&#8217;s <strong>WebAuthn</strong> authentication process.</p>



<p>Since the authentication challenge is not permanently tied to a specific device or session, attackers can generate the request from their own system while having the victim&#8217;s compromised device perform the required cryptographic signing.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p><strong>&#x200d;Follow Us on:<strong><a href="https://www.linkedin.com/in/firsthackers-news/" target="_blank" rel="noopener">Linkedin</a>,<a href="https://www.instagram.com/firsthackersnews/" target="_blank" rel="noreferrer noopener"> Instagram</a>, <a href="https://www.facebook.com/FirsthackerNews" target="_blank" rel="noreferrer noopener">Facebook</a></strong> to get the latest security news!</strong></p>
</blockquote>



<p>Once the challenge is successfully signed, Microsoft Entra treats the authentication as legitimate and issues cloud authentication tokens.</p>



<p>Unlike earlier attack techniques, this approach removes the need for attackers to control another Microsoft Entra-registered device, making exploitation significantly easier.</p>



<h2 class="wp-block-heading"><strong>Potential Impact</strong></h2>



<p>Successful exploitation could provide attackers with access to Microsoft Entra cloud resources while using legitimate authentication mechanisms.</p>



<p>Depending on the organization&#8217;s security configuration, attackers may be able to:</p>



<ul class="wp-block-list">
<li>Authenticate to Microsoft Entra services.</li>



<li>Obtain cloud authentication tokens.</li>



<li>Register attacker-controlled devices.</li>



<li>Add new authentication methods.</li>



<li>Maintain persistent access to cloud identities.</li>



<li>Expand access across enterprise environments.</li>
</ul>



<p>Because Windows Hello for Business satisfies multi-factor authentication requirements, attackers may also bypass additional protections designed to secure identity management functions.</p>



<h2 class="wp-block-heading"><strong>Why Organizations Should Pay Attention</strong></h2>



<p>The research demonstrates that passwordless authentication is only as secure as the endpoint itself.</p>



<p>Even though Windows Hello protects credentials from theft, an attacker who compromises an active Windows session may still abuse trusted authentication processes without ever knowing the user&#8217;s password or PIN.</p>



<p>This reinforces the importance of endpoint security alongside identity protection.</p>



<p>Organizations should not rely solely on passwordless authentication but should also focus on preventing attackers from gaining access to active user sessions.</p>



<h2 class="wp-block-heading"><strong>Detection and Mitigation</strong></h2>



<p>Security teams should monitor Microsoft Entra sign-in activity for unusual Windows Hello authentication events, particularly those that do not contain an associated device ID.</p>



<p>Administrators should also investigate unexpected device registrations, monitor changes to authentication methods, strengthen endpoint detection and response capabilities, and regularly review Conditional Access policies to ensure only trusted devices can register new authentication factors.</p>



<p>Monitoring active user sessions and detecting suspicious endpoint activity remain critical for preventing attackers from abusing trusted authentication mechanisms.</p>



<h2 class="wp-block-heading"><strong>Conclusion</strong></h2>



<p>Mollema&#8217;s research demonstrates that compromising an active Windows session can have serious consequences, even in environments that have adopted passwordless authentication.</p>



<p>While the technique does not break Windows Hello&#8217;s cryptographic protections, it shows how trusted authentication workflows can be abused after an endpoint has been compromised.</p>



<p>Organizations using Windows Hello for Business and Microsoft Entra should prioritize endpoint protection, continuous monitoring, and identity security controls to reduce the risk of attackers turning temporary access into persistent cloud compromise.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/windows-hello-for-business-security-flaw/">Windows Hello Key Flaw Opens Door to Entra ID Access</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/windows-hello-for-business-security-flaw/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Threat Analysis: DarkSword Framework Leverages iOS Exploits for Apple ID Harvesting</title>
		<link>https://firsthackersnews.com/darksword-iphone-exploit-fake-apple-id/</link>
					<comments>https://firsthackersnews.com/darksword-iphone-exploit-fake-apple-id/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Wed, 05 Aug 2026 05:16:00 +0000</pubDate>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Email Security]]></category>
		<category><![CDATA[Exploitation]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[Apple ID Phishing]]></category>
		<category><![CDATA[Apple security]]></category>
		<category><![CDATA[C2 Server]]></category>
		<category><![CDATA[credential theft]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[DarkSword]]></category>
		<category><![CDATA[iOS Exploit]]></category>
		<category><![CDATA[iOS Malware]]></category>
		<category><![CDATA[iPhone Security]]></category>
		<category><![CDATA[iPhone Vulnerability]]></category>
		<category><![CDATA[mobile malware]]></category>
		<category><![CDATA[phishing attack]]></category>
		<category><![CDATA[Safari Exploit]]></category>
		<category><![CDATA[threat intelligence]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12130</guid>

					<description><![CDATA[<p>DarkSword, a powerful iPhone exploit kit whose source code was leaked online, is now being used by multiple</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/darksword-iphone-exploit-fake-apple-id/">Threat Analysis: DarkSword Framework Leverages iOS Exploits for Apple ID Harvesting</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>DarkSword, a powerful iPhone exploit kit whose source code was leaked online, is now being used by multiple threat actors to launch large-scale cyberattacks. The latest campaigns combine one-click Safari exploits with fake Apple ID login pages, allowing attackers to steal credentials and compromise iPhones in a single attack.</p>



<p>The exploit chain was originally discovered by Google Threat Intelligence Group, iVerify, and Lookout. After the complete JavaScript-based toolkit was leaked on GitHub, several unrelated attackers began reusing the same code instead of creating their own versions.</p>



<p>Researchers found that at least seven threat groups are now operating DarkSword infrastructure. The attackers use identical exploit files, matching code hashes, and even the same Russian-language comments found in the leaked source code, confirming they are all relying on the leaked toolkit.</p>



<p>One of the newest operators appears to be a Chinese-speaking threat actor managing more than 100 malicious websites across Hong Kong, Japan, the United States, and several European countries. Earlier campaigns mainly used fake AWS login pages, but researchers have now identified Apple ID phishing pages hosted on the same servers that deliver the DarkSword exploit.</p>



<h2 class="wp-block-heading"><strong>How the DarkSword Campaign Works</strong></h2>



<p>Researchers tracked the attackers by comparing file hashes and exploit pages instead of relying only on domains or IP addresses, which change frequently. This method helped identify additional DarkSword infrastructure that traditional detection methods had missed.</p>



<p>According to Censys, the campaign continues to grow as attackers regularly move their infrastructure to new hosting providers and domains.</p>



<p>Researchers identified several key characteristics of the operation:</p>



<ul class="wp-block-list">
<li>Multiple DarkSword administration panels hosted in Hong Kong, Japan, and the United States.</li>



<li>Chinese-language login panels running on ports such as 3000, 8443, and 8888.</li>



<li>Fake Apple ID login pages hosted on the same servers as the exploit chain.</li>



<li>Identical exploit files and malware modules reused across different operators.</li>



<li>Infrastructure spread across multiple hosting providers to avoid easy detection.</li>
</ul>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p><strong>&#x200d;Follow Us on:<strong><a href="https://www.linkedin.com/in/firsthackers-news/" target="_blank" rel="noopener">Linkedin</a>,<a href="https://www.instagram.com/firsthackersnews/" target="_blank" rel="noreferrer noopener"> Instagram</a>, <a href="https://www.facebook.com/FirsthackerNews" target="_blank" rel="noreferrer noopener">Facebook</a></strong> to get the latest security news!</strong></p>
</blockquote>



<h2 class="wp-block-heading"><strong>What Happens After an iPhone Is Compromised?</strong></h2>



<p>One of the most dangerous changes in this campaign is the combination of Apple ID phishing pages with DarkSword&#8217;s exploit delivery. Victims believe they are signing in to a legitimate Apple account, while hidden exploit code is loaded in the background through Safari.</p>



<p>Security researchers say DarkSword chains multiple iOS vulnerabilities affecting WebKit, the GPU, the dynamic linker, and the kernel to gain deep access to vulnerable devices.</p>



<p>After a successful compromise, the malware can:</p>



<ul class="wp-block-list">
<li>Steal Apple Keychain passwords and saved credentials.</li>



<li>Extract iCloud account information.</li>



<li>Collect saved Wi-Fi passwords.</li>



<li>Download files stored on the device.</li>



<li>Send stolen data to attacker-controlled command-and-control (C2) servers.</li>
</ul>



<p>Researchers also found that most DarkSword deployments use identical malware files, showing attackers are directly reusing the leaked toolkit instead of developing new versions. Although many servers are hosted in Hong Kong, the infrastructure is distributed across several internet providers, making IP-based blocking less effective.</p>



<p>Additional evidence, including Chinese-language control panels, references to an &#8220;Asia-Pacific Group,&#8221; and a Telegram contact, suggests the latest infrastructure is operated by a Chinese-speaking threat actor. However, researchers say there is not yet enough evidence to confidently attribute the campaign to a specific group.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/darksword-iphone-exploit-fake-apple-id/">Threat Analysis: DarkSword Framework Leverages iOS Exploits for Apple ID Harvesting</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/darksword-iphone-exploit-fake-apple-id/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Critical TP-Link Router Flaw Enables Remote Code Execution</title>
		<link>https://firsthackersnews.com/tp-link-router-vulnerability/</link>
					<comments>https://firsthackersnews.com/tp-link-router-vulnerability/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Mon, 03 Aug 2026 17:03:23 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[CVE-2026-12935]]></category>
		<category><![CDATA[cyber threats]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[firmware update]]></category>
		<category><![CDATA[IT security]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[remote code execution]]></category>
		<category><![CDATA[router security]]></category>
		<category><![CDATA[Router Vulnerability]]></category>
		<category><![CDATA[security advisory]]></category>
		<category><![CDATA[security update]]></category>
		<category><![CDATA[threat intelligence]]></category>
		<category><![CDATA[TL-WR940N]]></category>
		<category><![CDATA[tp-link]]></category>
		<category><![CDATA[TP-Link Router]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12110</guid>

					<description><![CDATA[<p>TP-Link has released a security advisory for a high-severity vulnerability affecting the TL-WR940N v6 wireless router. The flaw,</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/tp-link-router-vulnerability/">Critical TP-Link Router Flaw Enables Remote Code Execution</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>TP-Link has released a security advisory for a <strong>high-severity vulnerability</strong> affecting the <strong>TL-WR940N v6 wireless router</strong>. The flaw, tracked as <strong>CVE-2026-12935</strong>, could allow attackers to execute malicious code on vulnerable devices, potentially giving them full control of the router.</p>



<p>The vulnerability has been assigned a <strong>CVSS v4.0 score of 8.7</strong>, highlighting the importance of applying the latest firmware updates as soon as possible.</p>



<h2 class="wp-block-heading"><strong>Buffer Overflow Vulnerability Identified</strong></h2>



<p>The issue is caused by a <strong>stack-based buffer overflow</strong> in the router&#8217;s <strong>Real-Time Streaming Protocol (RTSP)</strong> connection-tracking component.</p>



<p>The vulnerability can be triggered when a device connected to the local network communicates with a malicious RTSP server. If the server responds with specially crafted data, it can cause improper memory handling inside the router, leading to a system crash or remote code execution.</p>



<p>Unlike many router vulnerabilities, this flaw does <strong>not require attackers to authenticate</strong> with the device under its default configuration.</p>



<p>However, exploitation requires some user interaction. A user must first access a malicious RTSP stream, such as opening a harmful media link or connecting to an attacker-controlled streaming service.</p>



<h2 class="wp-block-heading"><strong>Potential Security Risks</strong></h2>



<p>If successfully exploited, attackers could:</p>



<ul class="wp-block-list">
<li>Execute malicious code on the router.</li>



<li>Modify network or security settings.</li>



<li>Monitor or intercept network traffic.</li>



<li>Install persistent malware.</li>



<li>Use the compromised router to launch attacks against other devices on the network.</li>
</ul>



<p>Because routers act as the gateway between users and the internet, compromising one can expose every connected device to additional risks.</p>



<h2 class="wp-block-heading"><strong>Affected Versions and Fixes</strong></h2>



<p>The vulnerability only impacts <strong>TP-Link TL-WR940N hardware version v6</strong>.</p>



<p>TP-Link has released firmware updates that address the issue for regional versions, including:</p>



<ul class="wp-block-list">
<li><strong>(EN)_V6_260528</strong></li>



<li><strong>(US)_V6_260528</strong></li>



<li><strong>(JP)_V6_260527</strong></li>
</ul>



<p>Users should download and install the appropriate firmware from TP-Link&#8217;s official support website as soon as possible.</p>



<h2 class="wp-block-heading"><strong>Recommended Security Measures</strong></h2>



<p>Until systems are updated, users and organizations should:</p>



<ul class="wp-block-list">
<li>Install the latest TP-Link firmware.</li>



<li>Avoid connecting to untrusted RTSP streaming services.</li>



<li>Secure the router&#8217;s administration interface with a strong, unique password.</li>



<li>Monitor network activity for unusual behavior.</li>



<li>Regularly review router firmware for new security updates.</li>
</ul>



<h2 class="wp-block-heading"><strong>Conclusion</strong></h2>



<p>The discovery of <strong>CVE-2026-12935</strong> highlights the importance of keeping networking devices up to date. Since routers are a critical part of any home or enterprise network, timely firmware updates and good security practices remain essential to protecting against remote attacks and maintaining a secure network environment.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p><strong>&#x200d;Follow Us on:<strong><a href="https://www.linkedin.com/in/firsthackers-news/" target="_blank" rel="noopener">Linkedin</a>,<a href="https://www.instagram.com/firsthackersnews/" target="_blank" rel="noreferrer noopener"> Instagram</a>, <a href="https://www.facebook.com/FirsthackerNews" target="_blank" rel="noreferrer noopener">Facebook</a></strong> to get the latest security news!</strong></p>
</blockquote>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/tp-link-router-vulnerability/">Critical TP-Link Router Flaw Enables Remote Code Execution</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/tp-link-router-vulnerability/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Google Chrome 151 Patches Critical Vulnerabilities</title>
		<link>https://firsthackersnews.com/google-chrome-151-security-update/</link>
					<comments>https://firsthackersnews.com/google-chrome-151-security-update/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Fri, 31 Jul 2026 04:05:06 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[Browser Security]]></category>
		<category><![CDATA[Chrome 151]]></category>
		<category><![CDATA[CVE]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[google chrome]]></category>
		<category><![CDATA[patch tuesday]]></category>
		<category><![CDATA[security update]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12107</guid>

					<description><![CDATA[<p>Google has released Chrome 151 for Windows, macOS, and Linux, bringing an important security update that fixes 370</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/google-chrome-151-security-update/">Google Chrome 151 Patches Critical Vulnerabilities</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Google has released <strong>Chrome 151</strong> for Windows, macOS, and Linux, bringing an important security update that fixes <strong>370 vulnerabilities</strong> across the browser. The update is being rolled out gradually, so it may take a few days before it becomes available to all users.</p>



<p>To help reduce the risk of attacks before users install the update, Google is temporarily limiting technical details about many of the vulnerabilities until the rollout is complete.</p>



<h2 class="wp-block-heading"><strong>370 Security Flaws Addressed</strong></h2>



<p>This release includes fixes for vulnerabilities affecting several core Chrome components, including graphics, networking, browser rendering, and platform-specific features.</p>



<p>Many of these issues were discovered by Google&#8217;s internal security teams using automated testing tools designed to detect memory errors and other software weaknesses before they could be exploited.</p>



<h2 class="wp-block-heading"><strong>Seven Critical Vulnerabilities Fixed</strong></h2>



<p>Chrome 151 resolves <strong>seven critical vulnerabilities</strong>, tracked as <strong>CVE-2026-17650</strong> through <strong>CVE-2026-17656</strong>.</p>



<p>Several of these are <strong>use-after-free</strong> memory vulnerabilities found in components such as <strong>Compositing, Views, Skia, and Ozone</strong>. If successfully exploited, these flaws could allow attackers to execute malicious code through specially crafted web content.</p>



<p>The update also fixes:</p>



<ul class="wp-block-list">
<li><strong>Insufficient input validation</strong> in the Dawn and ANGLE graphics libraries.</li>



<li><strong>A race condition</strong> in Chrome&#8217;s Updater that could lead to unexpected behavior during software updates.</li>
</ul>



<p>These vulnerabilities could potentially be used to bypass security protections, escalate privileges, or compromise browser stability.</p>



<h2 class="wp-block-heading"><strong>Additional High-Severity Fixes</strong></h2>



<p>Beyond the critical issues, Chrome 151 addresses numerous high-severity vulnerabilities affecting components such as:</p>



<ul class="wp-block-list">
<li>V8 JavaScript Engine</li>



<li>Navigation</li>



<li>QUIC</li>



<li>Audio and Media</li>



<li>WebGL</li>



<li>Downloads</li>
</ul>



<p>Many of these flaws involve memory corruption issues, including out-of-bounds reads and writes, integer overflows, and type confusion vulnerabilities, all of which could increase the risk of remote code execution.</p>



<h2 class="wp-block-heading"><strong>Medium and Low-Severity Improvements</strong></h2>



<p>The update also includes fixes for medium-severity vulnerabilities affecting features such as <strong>Autofill, DevTools, Extensions, Password Manager, WebXR, WebView, and ANGLE</strong>.</p>



<p>In addition, Google resolved several lower-severity issues impacting Enterprise features, Bluetooth, NFC, Google Lens, Settings, Picture-in-Picture, and AI-related functionality. While these vulnerabilities are less severe individually, addressing them helps strengthen Chrome&#8217;s overall security.</p>



<h2 class="wp-block-heading"><strong>Update Chrome as Soon as Possible</strong></h2>



<p>Google credited both its internal security teams and external researchers for identifying many of the vulnerabilities before they could be exploited.</p>



<p>With <strong>370 security fixes</strong>, including <strong>seven critical vulnerabilities</strong>, this release highlights the importance of keeping web browsers up to date. Users and organizations should install <strong>Chrome 151</strong> as soon as it becomes available to reduce the risk of attacks targeting known security flaws.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/google-chrome-151-security-update/">Google Chrome 151 Patches Critical Vulnerabilities</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/google-chrome-151-security-update/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Active Exploitation of Cisco Secure Firewall Zero-Day Prompts CISA Alert</title>
		<link>https://firsthackersnews.com/cisa-cisco-secure-firewall-vulnerability/</link>
					<comments>https://firsthackersnews.com/cisa-cisco-secure-firewall-vulnerability/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Fri, 31 Jul 2026 03:54:48 +0000</pubDate>
				<category><![CDATA[CISA]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[cisa]]></category>
		<category><![CDATA[Cisco FMC]]></category>
		<category><![CDATA[CVE-2026-20316]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[security update]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12103</guid>

					<description><![CDATA[<p>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert regarding the active exploitation of a</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/cisa-cisco-secure-firewall-vulnerability/">Active Exploitation of Cisco Secure Firewall Zero-Day Prompts CISA Alert</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert regarding the active exploitation of a critical security vulnerability affecting <strong>Cisco Secure Firewall Management Center (FMC)</strong>. This vulnerability is known as <strong>cisa-cisco-secure-firewall-vulnerability</strong>. Organizations using the platform are advised to take immediate action to reduce the risk of compromise.</p>



<p>The vulnerability, tracked as <strong>CVE-2026-20316</strong>, impacts Cisco&#8217;s centralized firewall management solution, which enables administrators to manage firewall policies, monitor security events, and control intrusion prevention systems across enterprise environments. Because FMC plays a central role in network security management, a successful attack could have significant operational and security consequences related to the <strong>cisa-cisco-secure-firewall-vulnerability</strong>.</p>



<h2 class="wp-block-heading"><strong>Hard-Coded Credentials Enable Unauthorized Access</strong></h2>



<p>According to Cisco, the vulnerability is caused by the presence of <strong>hard-coded credentials</strong> within the software. Since these embedded credentials cannot be modified by administrators, an attacker can exploit the flaw to authenticate to a vulnerable FMC instance without valid user credentials.</p>



<p>Successful exploitation allows an unauthenticated attacker to gain access with low-level privileges, creating an initial foothold inside the firewall management environment.</p>



<h2 class="wp-block-heading"><strong>Why the Vulnerability Matters</strong></h2>



<p>Although the access obtained is limited, compromising a centralized management platform can provide attackers with valuable intelligence about an organization&#8217;s security infrastructure.</p>



<p>An attacker may be able to:</p>



<ul class="wp-block-list">
<li>View firewall configurations and security policies</li>



<li>Access security event logs and system information</li>



<li>Gather network intelligence for follow-on attacks</li>



<li>Modify security configurations to weaken existing defenses</li>
</ul>



<p>Because Cisco FMC acts as the central management console for enterprise firewall deployments, unauthorized access can significantly increase the likelihood of lateral movement and additional compromise within the network.</p>



<h2 class="wp-block-heading"><strong>CISA Advises Immediate Remediation</strong></h2>



<p>CISA has added <strong>CVE-2026-20316</strong> to its <strong>Known Exploited Vulnerabilities (KEV) Catalog</strong>, confirming that the vulnerability is being actively exploited in real-world attacks.</p>



<p>Organizations should prioritize remediation by:</p>



<ul class="wp-block-list">
<li>Applying Cisco&#8217;s latest security updates without delay</li>



<li>Identifying and securing internet-accessible FMC deployments</li>



<li>Restricting management interface access to trusted administrative networks</li>



<li>Following the remediation timelines outlined in <strong>Binding Operational Directive (BOD) 26-04</strong></li>
</ul>



<p>Where patches or effective mitigations cannot be implemented immediately, organizations should evaluate temporarily removing affected systems from service until they can be secured.</p>



<h2 class="wp-block-heading"><strong>Review Systems for Indicators of Compromise</strong></h2>



<p>Security teams should also assess affected environments for signs of unauthorized activity. Recommended actions include reviewing authentication logs, monitoring administrative access, validating configuration changes, and preserving forensic evidence if compromise is suspected.</p>



<p>Organizations operating cloud-hosted or hybrid deployments should ensure the same security controls and remediation measures are consistently applied across all FMC instances.</p>



<h2 class="wp-block-heading"><strong>Conclusion</strong></h2>



<p>The active exploitation of <strong>CVE-2026-20316</strong> demonstrates how vulnerabilities involving hard-coded credentials continue to present a serious risk to enterprise environments. Since Cisco Secure Firewall Management Center is responsible for managing critical network security controls, organizations should treat this vulnerability as a high-priority issue. </p>



<p>Prompt patching, restricted administrative access, continuous monitoring, and thorough log analysis remain essential to reducing the risk of unauthorized access and protecting enterprise networks.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/cisa-cisco-secure-firewall-vulnerability/">Active Exploitation of Cisco Secure Firewall Zero-Day Prompts CISA Alert</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/cisa-cisco-secure-firewall-vulnerability/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Critical Rails Vulnerability Exposes Sensitive Data</title>
		<link>https://firsthackersnews.com/ruby-on-rails-vulnerability-cve-2026-66066/</link>
					<comments>https://firsthackersnews.com/ruby-on-rails-vulnerability-cve-2026-66066/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Thu, 30 Jul 2026 15:28:00 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[Active Storage]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[CVE-2026-66066]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[libvips]]></category>
		<category><![CDATA[rce]]></category>
		<category><![CDATA[remote code execution]]></category>
		<category><![CDATA[Ruby on Rails]]></category>
		<category><![CDATA[security news]]></category>
		<category><![CDATA[Web Security]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12094</guid>

					<description><![CDATA[<p>A newly disclosed security vulnerability, tracked as CVE-2026-66066, affects Ruby on Rails&#8217; Active Storage component and could allow</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/ruby-on-rails-vulnerability-cve-2026-66066/">Critical Rails Vulnerability Exposes Sensitive Data</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>A newly disclosed security vulnerability, tracked as <strong>CVE-2026-66066</strong>, affects <strong>Ruby on Rails&#8217; Active Storage</strong> component and could allow attackers to read sensitive files from vulnerable servers. In some cases, the flaw could lead to <strong>remote code execution (RCE)</strong>, making it a serious risk for organizations using affected Rails applications.</p>



<p>The issue impacts applications that use <strong>Active Storage</strong> with the <strong>libvips</strong> image-processing library. According to the Rails maintainers, applications that allow image uploads from untrusted users are at the highest risk. To give organizations time to update their systems, technical details of the exploit have been temporarily withheld until <strong>August 28, 2026</strong>.</p>



<h2 class="wp-block-heading"><strong>How the Vulnerability Works</strong></h2>



<p>The flaw is caused by the way <strong>Active Storage</strong> interacts with the <strong>libvips</strong> image-processing library during image variant generation. Active Storage failed to block certain unsafe image-processing operations, allowing a specially crafted image upload to trigger unintended behavior.</p>



<p>As a result, an attacker may be able to read files that are accessible to the Rails application. These files can contain valuable information, including:</p>



<ul class="wp-block-list">
<li>Application <strong>secret_key_base</strong></li>



<li>Database usernames and passwords</li>



<li>Cloud storage access keys</li>



<li>Third-party API tokens</li>



<li>Environment variables and deployment secrets</li>
</ul>



<p>If attackers obtain these credentials, they could potentially forge application sessions, access cloud resources, compromise databases, or move further inside an organization&#8217;s infrastructure.</p>



<h2 class="wp-block-heading"><strong>Affected Versions and Protection</strong></h2>



<p>Applications are vulnerable if they:</p>



<ul class="wp-block-list">
<li>Use <strong>Active Storage</strong> with <strong>libvips</strong> (<code>config.active_storage.variant_processor = :vips</code>)</li>



<li>Accept image uploads from untrusted users</li>



<li>Run affected versions of Active Storage</li>
</ul>



<p>The vulnerability affects:</p>



<ul class="wp-block-list">
<li>Active Storage versions earlier than <strong>7.2.3</strong></li>



<li>Versions <strong>8.0.0 to 8.0.4</strong></li>



<li>Versions <strong>8.1.0 to 8.1.2</strong></li>
</ul>



<p>Rails has released security updates to fix the issue and recommends using <strong>libvips 8.13.8 or later</strong>, which blocks unsafe image-processing operations. Organizations that cannot immediately upgrade Rails can enable additional protection by setting the <strong><code>VIPS_BLOCK_UNTRUSTED</code></strong> environment variable when using a supported version of libvips.</p>



<h2 class="wp-block-heading"><strong>Recommended Actions</strong></h2>



<p>Organizations should act quickly to reduce the risk of exploitation by:</p>



<ul class="wp-block-list">
<li>Updating Rails Active Storage to the latest patched version.</li>



<li>Upgrading <strong>libvips</strong> to <strong>8.13.8 or newer</strong>.</li>



<li>Reviewing applications that accept image uploads.</li>



<li>Rotating sensitive credentials, including database passwords, cloud keys, API tokens, and <strong>secret_key_base</strong>.</li>



<li>Monitoring systems for suspicious file access or unauthorized activity.</li>
</ul>



<p>Changing the <strong>secret_key_base</strong> will invalidate existing user sessions, signed cookies, and Active Storage URLs, requiring users to log in again.</p>



<h2 class="wp-block-heading"><strong>Conclusion</strong></h2>



<p><strong>CVE-2026-66066</strong> highlights how vulnerabilities in image-processing components can expose critical application secrets and potentially lead to full server compromise. Organizations using Ruby on Rails should install the latest security updates immediately, review uploaded file handling, and rotate any sensitive credentials that may have been exposed before applying the patch.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/ruby-on-rails-vulnerability-cve-2026-66066/">Critical Rails Vulnerability Exposes Sensitive Data</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/ruby-on-rails-vulnerability-cve-2026-66066/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Apple iOS 26.6 Fixes Critical Security Flaws</title>
		<link>https://firsthackersnews.com/apple-ios-26-6-security-update/</link>
					<comments>https://firsthackersnews.com/apple-ios-26-6-security-update/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Wed, 29 Jul 2026 04:00:07 +0000</pubDate>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Security Update]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12086</guid>

					<description><![CDATA[<p>Apple has released iOS 26.6 and iPadOS 26.6, delivering an important set of security updates for supported iPhones</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/apple-ios-26-6-security-update/">Apple iOS 26.6 Fixes Critical Security Flaws</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Apple has released <strong>iOS 26.6</strong> and <strong>iPadOS 26.6</strong>, delivering an important set of security updates for supported iPhones and iPads. The release addresses multiple vulnerabilities that could allow attackers to execute code with kernel privileges, gain root access, or bypass Apple&#8217;s app sandbox.</p>



<p>The updates are available for <strong>iPhone 11 and newer models</strong>, along with supported iPads. While Apple has not reported any active exploitation of these vulnerabilities, the nature of the flaws makes this update a high priority for all users.</p>



<h2 class="wp-block-heading"><strong>Critical Vulnerabilities Patched</strong></h2>



<p>One of the most serious issues, tracked as CVE-2026-64747, affects the AVEVideoEncoder component. The vulnerability could allow a malicious application to execute arbitrary code with kernel-level privileges through a buffer overflow. Apple resolved the issue by improving input size validation.</p>



<p>The update also fixes several vulnerabilities in the iOS kernel. These flaws could lead to system crashes, kernel memory corruption, sensitive information disclosure, or unauthorized memory access. Apple addressed these issues by strengthening memory handling, improving bounds checking, and resolving race conditions.</p>



<p>Some of the key security fixes include:</p>



<ul class="wp-block-list">
<li><strong>CVE-2026-64747</strong> – Kernel code execution vulnerability in AVEVideoEncoder.</li>



<li><strong>CVE-2026-28931</strong> – Kernel memory corruption when connecting to a malicious NFS server.</li>



<li><strong>CVE-2026-43810</strong> – Remote vulnerability that could trigger system crashes or corrupt kernel memory.</li>



<li><strong>CVE-2026-43723</strong> – Root privilege escalation flaw in MediaRemote.</li>



<li><strong>CVE-2026-64740</strong> – Sandbox escape vulnerability in Game Center.</li>



<li><strong>CVE-2026-28973</strong> – Sandbox escape issue in libc caused by an integer overflow.</li>
</ul>



<h2 class="wp-block-heading"><strong>Additional Security Improvements</strong></h2>



<p>Apple also patched several code execution vulnerabilities affecting <strong>AppleDouble, ImageIO, and SceneKit</strong>. These flaws could be exploited through specially crafted files, images, textures, or 3D content delivered via websites, downloads, email attachments, or malicious applications.</p>



<p>The company also strengthened <strong>WebKit</strong>, the browser engine used by Safari and many iOS apps. The update fixes issues related to memory disclosure, browser crashes, UI spoofing, iframe sandbox enforcement, and unauthorized file access outside the intended sandbox.</p>



<p>The combination of kernel vulnerabilities, root privilege escalation, code execution, and sandbox escape flaws makes <strong>iOS 26.6</strong> one of Apple&#8217;s most significant security releases in recent months. Although there is no evidence that these vulnerabilities have been exploited in the wild, installing the update is strongly recommended to keep devices protected.</p>



<p>Users can install the latest update by navigating to <strong>Settings → General → Software Update</strong> on their iPhone or iPad.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/apple-ios-26-6-security-update/">Apple iOS 26.6 Fixes Critical Security Flaws</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/apple-ios-26-6-security-update/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Kimi K3 AI Discovers Redis RCE Flaws</title>
		<link>https://firsthackersnews.com/kimi-k3-ai-redis-rce-flaws/</link>
					<comments>https://firsthackersnews.com/kimi-k3-ai-redis-rce-flaws/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Thu, 23 Jul 2026 21:01:22 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[RCE Flaw]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[AI in Cybersecurity]]></category>
		<category><![CDATA[AI security]]></category>
		<category><![CDATA[artificial intelligence]]></category>
		<category><![CDATA[CVE]]></category>
		<category><![CDATA[cyber threats]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Ethical Hacking]]></category>
		<category><![CDATA[Fuzz Testing]]></category>
		<category><![CDATA[Kimi K3 AI]]></category>
		<category><![CDATA[memory corruption]]></category>
		<category><![CDATA[rce]]></category>
		<category><![CDATA[redis]]></category>
		<category><![CDATA[Redis Security]]></category>
		<category><![CDATA[Redis Vulnerability]]></category>
		<category><![CDATA[remote code execution]]></category>
		<category><![CDATA[security news]]></category>
		<category><![CDATA[security research]]></category>
		<category><![CDATA[threat intelligence]]></category>
		<category><![CDATA[Vulnerability Research]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12071</guid>

					<description><![CDATA[<p>Moonshot AI&#8217;s latest Kimi K3 model is making headlines after demonstrating its ability to automatically identify critical security</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/kimi-k3-ai-redis-rce-flaws/">Kimi K3 AI Discovers Redis RCE Flaws</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Moonshot AI&#8217;s latest <strong>Kimi K3</strong> model is making headlines after demonstrating its ability to automatically identify critical security flaws in <strong>Redis</strong>. During testing, the AI agent reportedly found multiple remote code execution (RCE) vulnerabilities in several Redis versions within just <strong>27 minutes</strong>.</p>



<p>The achievement highlights how artificial intelligence is changing vulnerability research by reducing the time needed to discover complex software flaws.</p>



<h2 class="wp-block-heading"><strong>How Kimi K3 Found the Vulnerabilities</strong></h2>



<p>The AI was given a simple task: search for memory-related security issues such as buffer overflows and use-after-free bugs in the Redis source code.</p>



<p>To complete the task, Kimi K3 automatically:</p>



<ul class="wp-block-list">
<li>Cloned the Redis source code.</li>



<li>Performed fuzz testing to trigger unexpected behavior.</li>



<li>Analyzed application crashes.</li>



<li>Used debugging tools to identify the root cause.</li>



<li>Generated proof-of-concept (PoC) exploits in a controlled testing environment.</li>
</ul>



<p>The entire process was completed without manual intervention, showing how AI can automate complex security research.</p>



<h2 class="wp-block-heading"><strong>Redis Versions Affected</strong></h2>



<p>The reported vulnerabilities were found in the following Redis versions:</p>



<ul class="wp-block-list">
<li>Redis 6.2.22</li>



<li>Redis 7.4.9</li>



<li>Redis 8.6.4</li>



<li>Redis 8.8.0</li>
</ul>



<p>Researchers shared the proof-of-concept findings publicly for validation and further analysis.</p>



<h2 class="wp-block-heading"><strong>Key Vulnerabilities Identified</strong></h2>



<p>The AI agent reportedly discovered multiple critical issues, including:</p>



<ul class="wp-block-list">
<li>A <strong>double-free vulnerability</strong> related to Redis stream consumer groups (CVE-2026-25589).</li>



<li>A <strong>heap overflow vulnerability</strong> in the RedisBloom module.</li>
</ul>



<p>These types of memory corruption vulnerabilities can allow attackers to manipulate application memory and may eventually lead to remote code execution if successfully exploited.</p>



<h2 class="wp-block-heading"><strong>Why This Matters</strong></h2>



<p>Finding serious vulnerabilities has traditionally required experienced researchers spending days or even weeks reviewing source code and performing extensive testing.</p>



<p>AI-powered tools are now changing that process by:</p>



<ul class="wp-block-list">
<li>Reducing vulnerability discovery time.</li>



<li>Automating repetitive security testing.</li>



<li>Identifying bugs across large codebases much faster.</li>



<li>Helping security teams strengthen software before attacks occur.</li>
</ul>



<h2 class="wp-block-heading"><strong>Opportunities and Risks</strong></h2>



<p>While AI offers significant advantages for defenders, it also introduces new concerns.</p>



<p>Potential benefits include:</p>



<ul class="wp-block-list">
<li>Faster vulnerability detection.</li>



<li>Improved software security.</li>



<li>More efficient penetration testing.</li>



<li>Better support for security researchers.</li>
</ul>



<p>However, the same technology could also be used by attackers to accelerate exploit discovery, making timely patching and responsible disclosure more important than ever.</p>



<h2 class="wp-block-heading"><strong>The Future of AI in Cybersecurity</strong></h2>



<p>The Kimi K3 demonstration shows that AI is becoming an important tool in modern cybersecurity. As large language models continue to improve, they are expected to assist with vulnerability research, code analysis, and automated security testing at a much larger scale.</p>



<p>Organizations should prepare by:</p>



<ul class="wp-block-list">
<li>Applying security updates quickly.</li>



<li>Continuously monitoring critical systems.</li>



<li>Using AI-assisted security tools alongside traditional defenses.</li>



<li>Strengthening vulnerability management programs.</li>
</ul>



<h2 class="wp-block-heading"><strong>Conclusion</strong></h2>



<p>Although these findings are still being reviewed by the security community, they demonstrate how quickly AI-powered security research is evolving. Kimi K3&#8217;s ability to discover complex Redis vulnerabilities in minutes signals a major shift in how software security testing may be performed in the future, making AI an increasingly valuable asset for both cybersecurity researchers and defenders.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/kimi-k3-ai-redis-rce-flaws/">Kimi K3 AI Discovers Redis RCE Flaws</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/kimi-k3-ai-redis-rce-flaws/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Apple Strengthens Hide My Email Privacy with New Security Fix</title>
		<link>https://firsthackersnews.com/apple-hide-my-email-vulnerability/</link>
					<comments>https://firsthackersnews.com/apple-hide-my-email-vulnerability/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Wed, 22 Jul 2026 21:53:58 +0000</pubDate>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[Apple security]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[data privacy]]></category>
		<category><![CDATA[email security]]></category>
		<category><![CDATA[Hide My Email]]></category>
		<category><![CDATA[iCloud+]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[security update]]></category>
		<category><![CDATA[vulnerability]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12066</guid>

					<description><![CDATA[<p>Apple has addressed a privacy vulnerability affecting its Hide My Email feature, an iCloud+ service designed to keep</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/apple-hide-my-email-vulnerability/">Apple Strengthens Hide My Email Privacy with New Security Fix</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Apple has addressed a privacy vulnerability affecting its <strong>Hide My Email</strong> feature, an iCloud+ service designed to keep users&#8217; personal email addresses private. The flaw raised concerns because it could allow an email alias to be linked back to the user&#8217;s actual email address, reducing the privacy protection the feature was built to provide. This fix reinforces the commitment to user privacy, highlighting the importance of features like <strong>Apple Hide My Email</strong>.</p>



<p>The issue has sparked discussions about how even privacy-focused technologies can be affected by weaknesses outside their core design.</p>



<h2 class="wp-block-heading"><strong>How Hide My Email Protects Users</strong></h2>



<p>As part of Apple&#8217;s ongoing efforts to enhance security, the <strong>Apple Hide My Email</strong> feature continues to evolve, providing users with innovative ways to maintain their privacy online.</p>



<p>As part of Apple&#8217;s ongoing efforts to enhance security, the <strong>Apple Hide My Email</strong> feature continues to evolve, providing users with innovative ways to maintain their privacy online.</p>



<p>Hide My Email allows users to create unique email aliases whenever they sign up for websites or online services. Messages sent to these aliases are automatically forwarded to the user&#8217;s real inbox, while the actual email address remains hidden.</p>



<p>This approach helps users reduce spam, limit online tracking, and avoid exposing their primary email address if a service experiences a data breach.</p>



<h2 class="wp-block-heading"><strong>What Went Wrong?</strong></h2>



<p>Although the feature successfully generated anonymous email aliases, researchers found that the email delivery process itself could unintentionally reveal the original email address.</p>



<p>Instead of breaking the alias directly, the weakness appeared during the way certain emails were processed. Under specific conditions, backend email handling systems could expose information that linked the alias to the user&#8217;s real address.</p>



<p>This meant attackers didn&#8217;t have to compromise an Apple account—they only needed to exploit the email processing workflow.</p>



<h2 class="wp-block-heading"><strong>Why This Matters</strong></h2>



<p>Privacy tools are designed to separate a user&#8217;s identity from the services they use.</p>



<p>If someone can trace an anonymous email alias back to its owner, it becomes much easier to build user profiles, launch targeted phishing campaigns, or connect accounts across multiple platforms.</p>



<p>While the vulnerability did not expose passwords or give attackers access to Apple accounts, it weakened an important layer of privacy that many users relied on.</p>



<h2 class="wp-block-heading"><strong>Apple Responds</strong></h2>



<p>After the issue was reported through responsible disclosure, Apple investigated the vulnerability and later released a security update to address it.</p>



<p>The fix prevents the conditions that allowed email aliases to be linked with real email addresses, strengthening the privacy protections offered by Hide My Email.</p>



<p>The update highlights Apple&#8217;s continued efforts to improve security across its ecosystem as new vulnerabilities are identified.</p>



<h2 class="wp-block-heading"><strong>Can Older Aliases Still Be a Concern?</strong></h2>



<p>Although the vulnerability has now been patched, security experts note that information exposed before the update cannot always be erased.</p>



<p>Some email providers and enterprise mail systems store message logs for operational and security purposes. If an email address was previously revealed during processing, that information may still exist in archived records.</p>



<p>Because of this, users who created aliases before the fix may wish to review important accounts that rely on older aliases.</p>



<p>This incident demonstrates that protecting privacy is about more than building secure features.</p>



<p>Modern email systems involve multiple technologies, including spam filtering, message routing, logging services, and third-party infrastructure. Even when the main application is secure, weaknesses elsewhere in the communication process can introduce unexpected privacy risks.</p>



<p>Organizations developing privacy-focused services must evaluate the entire ecosystem rather than only the application itself.</p>



<h2 class="wp-block-heading"><strong>Best Practices for Users</strong></h2>



<p>While Apple has resolved the vulnerability, users should continue following good security practices:</p>



<ul class="wp-block-list">
<li>Keep Apple devices updated with the latest security releases.</li>



<li>Review important online accounts that use older email aliases.</li>



<li>Enable Multi-Factor Authentication (MFA) wherever available.</li>



<li>Be cautious of unexpected emails requesting personal information.</li>



<li>Regularly monitor important accounts for suspicious activity.</li>
</ul>



<p>Privacy tools like Hide My Email remain valuable for reducing online tracking and limiting data exposure. However, they work best when combined with strong account security and regular software updates to provide multiple layers of protection.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/apple-hide-my-email-vulnerability/">Apple Strengthens Hide My Email Privacy with New Security Fix</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/apple-hide-my-email-vulnerability/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Critical RefluXFS Flaw Threatens Linux Systems</title>
		<link>https://firsthackersnews.com/refluxfs-linux-vulnerability/</link>
					<comments>https://firsthackersnews.com/refluxfs-linux-vulnerability/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Wed, 22 Jul 2026 21:18:24 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cyber threat]]></category>
		<category><![CDATA[Cybercriminals]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Linux Malware]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12062</guid>

					<description><![CDATA[<p>A newly discovered Linux vulnerability, called RefluXFS (CVE-2026-64600), could allow a local user to gain root access by</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/refluxfs-linux-vulnerability/">Critical RefluXFS Flaw Threatens Linux Systems</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>A newly discovered Linux vulnerability, called <strong>RefluXFS (CVE-2026-64600)</strong>, could allow a local user to gain <strong>root access</strong> by exploiting a flaw in the Linux kernel&#8217;s XFS filesystem. Security researchers at <strong>Qualys Threat Research Unit (TRU)</strong> discovered the issue and warned that it can be exploited even when <strong>SELinux is running in Enforcing mode</strong>.</p>



<p>The vulnerability affects the <strong>copy-on-write (CoW)</strong> feature of XFS. It is caused by a race condition that occurs when two <strong>O_DIRECT</strong> write operations access the same reflink-enabled file at nearly the same time.</p>



<h2 class="wp-block-heading"><strong>How the Vulnerability Works</strong></h2>



<p>Normally, when a shared file is modified, XFS creates a new private copy of the data before writing changes. However, during this process, the kernel briefly releases an internal lock while waiting for transaction log space.</p>



<p>If another write request arrives during this short window, it can change the file mapping before the first operation finishes. As a result, the first write uses outdated information and writes data directly to the original disk block instead of a new one.</p>



<p>Since <strong>O_DIRECT</strong> bypasses the page cache, the corrupted data is written straight to disk, allowing attackers to overwrite protected system files.</p>



<h2 class="wp-block-heading"><strong>Why It Is Dangerous</strong></h2>



<p>Qualys demonstrated that a normal local user could exploit the flaw on a default <strong>RHEL 10.2</strong> system and remove the root account&#8217;s password protection within seconds. After the attack, the system granted <strong>passwordless root access</strong>.</p>



<p>The attack is difficult to detect because:</p>



<ul class="wp-block-list">
<li>No kernel log entries are generated.</li>



<li>The changes remain after a reboot.</li>



<li>Even systems protected by SELinux are vulnerable.</li>



<li>Existing Linux security protections do not block the attack.</li>
</ul>



<p>Researchers believe the vulnerability has existed since <strong>Linux kernel version 4.11</strong>, released in <strong>2017</strong>, potentially affecting <strong>more than 16 million systems</strong> worldwide.</p>



<h2 class="wp-block-heading"><strong>Who Is Affected?</strong></h2>



<p>A system is vulnerable if it has:</p>



<ul class="wp-block-list">
<li>Linux kernel <strong>4.11 or later</strong> without the security patch.</li>



<li>An <strong>XFS filesystem</strong> with <strong>reflink=1</strong> enabled.</li>



<li>A directory writable by an unprivileged user.</li>



<li>A valuable target file such as a <strong>SUID binary</strong> or protected system file.</li>
</ul>



<h3 class="wp-block-heading">Confirmed affected distributions include:</h3>



<ul class="wp-block-list">
<li>RHEL 8, 9 and 10</li>



<li>CentOS Stream 8, 9 and 10</li>



<li>Oracle Linux 8, 9 and 10</li>



<li>Rocky Linux 8, 9 and 10</li>



<li>AlmaLinux 8, 9 and 10</li>



<li>CloudLinux 8, 9 and 10</li>



<li>Amazon Linux 2 and Amazon Linux 2023</li>



<li>Fedora Server 31 and later</li>
</ul>



<h3 class="wp-block-heading">Lower-risk distributions</h3>



<ul class="wp-block-list">
<li>Debian</li>



<li>Ubuntu</li>



<li>SUSE</li>
</ul>



<p>These distributions are mainly affected only if <strong>XFS with reflink support</strong> has been manually configured.</p>



<h2 class="wp-block-heading"><strong>Existing Security Features Cannot Stop It</strong></h2>



<p>One of the biggest concerns is that common Linux security protections do not prevent this attack. Technologies such as <strong>SELinux</strong>, <strong>KASLR</strong>, <strong>SMEP</strong>, <strong>SMAP</strong>, kernel lockdown, and container isolation operate at different layers and cannot stop exploitation of this filesystem flaw.</p>



<p>At present, <strong>there is no temporary workaround</strong> that completely mitigates the vulnerability. Installing the security update is the only effective solution.</p>



<h2 class="wp-block-heading"><strong>AI Helped Discover the Flaw</strong></h2>



<p>The vulnerability was identified through a collaboration between <strong>Qualys</strong> and <strong>Anthropic</strong>. Researchers used Anthropic&#8217;s <strong>Claude Mythos Preview</strong> AI model to search for race-condition vulnerabilities similar to the well-known <strong>Dirty COW</strong> bug.</p>



<p>After identifying the issue, Qualys engineers independently verified the findings, created a proof-of-concept, and responsibly disclosed the vulnerability to Linux maintainers.</p>



<h2 class="wp-block-heading"><strong>Part of a Growing Trend</strong></h2>



<p>RefluXFS is one of several major Linux privilege escalation vulnerabilities disclosed during 2026. Other recent discoveries include:</p>



<ul class="wp-block-list">
<li><strong>Copy Fail (CVE-2026-31431)</strong></li>



<li><strong>Dirty Frag (CVE-2026-43284 and CVE-2026-43500)</strong></li>



<li><strong>DirtyClone (CVE-2026-43503)</strong></li>
</ul>



<p>These vulnerabilities highlight a growing trend of attackers exploiting flaws that allow protected files or memory to be modified, ultimately leading to privilege escalation.</p>



<h2 class="wp-block-heading"><strong>What Organizations Should Do</strong></h2>



<p>Organizations should patch affected systems as soon as possible, especially <strong>internet-facing servers</strong>, <strong>multi-tenant environments</strong>, and <strong>shared systems</strong>.</p>



<p>Security updates are already available for major enterprise Linux distributions, including <strong>RHEL, Oracle Linux, AlmaLinux, Rocky Linux, and Fedora</strong>. After installing the update, administrators should perform a <strong>full system reboot</strong> to ensure the patched kernel is running.</p>



<p>Since there is currently <strong>no reliable mitigation</strong> other than patching, keeping systems updated is the best defense against the RefluXFS vulnerability.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/refluxfs-linux-vulnerability/">Critical RefluXFS Flaw Threatens Linux Systems</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/refluxfs-linux-vulnerability/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
