Researchers detailed a new “HTTP/2 Bomb” technique that chains a compression bomb with a Slowloris-style hold to take down web servers using default settings. NGINX, Apache HTTP Server, Microsoft IIS, Envoy, and Cloudflare Pingora are affected, making it a broad, high-impact DoS vector. Operators should urgently apply vendor mitigations, tighten HTTP/2 limits, and monitor for abnormal connection behavior.
Source: SecurityWeek
VS Code flaw enables one-click theft of GitHub tokens
A disclosed Visual Studio Code issue makes it possible to steal a developer’s GitHub OAuth token via a single click, with a public proof-of-concept now available. The researcher published full details without prior notification to Microsoft, heightening exploitation risk. Teams should review GitHub token scopes, revoke unused tokens, and consider browser isolation for untrusted links opened through dev tooling.
Source: SecurityWeek
Cisco warns of public PoC for critical Unified Communications Manager SSRF
Cisco alerted customers that a public proof-of-concept exists for a high-severity server-side request forgery flaw in Unified Communications Manager, exploitable remotely without authentication. Successful exploitation can pivot internal requests and expose sensitive services. Immediate patching, network egress controls, and strict access policies around UC infrastructure are advised.
Source: SecurityWeek
Actively exploited Linux kernel bug enables container escape
Organizations were warned about an improper authentication vulnerability in the Linux kernel that attackers are exploiting to escalate privileges and break out of containers. The issue underscores the urgency of patching hosts, not just containers, and hardening runtime controls for isolation. Cloud and on-prem Kubernetes environments should prioritize kernel updates and enforce least-privilege policies.
Source: SecurityWeek
Researchers demo autonomous AI worm that reasons its way across networks
Academics built a proof-of-concept AI-driven worm that dynamically analyzes new targets and devises attack strategies on the fly using a small, on-host LLM—without relying on a fixed exploit list. The work highlights how low-cost AI can operationalize known weaknesses at scale, raising the stakes for segmentation, egress filtering, and rapid exposure management. Security teams should assume adaptive adversaries and stress-test lateral movement defenses.
Source: Help Net Security
Only 11% of production AI agents meet basic security bar, study finds
An independent assessment of 100 production AI agents found that the vast majority are susceptible to hostile content and over-permissioned access, leaving them open to takeover from a single malicious document. With agents holding standing credentials and operating across code, cloud, and customer support, the findings call for strict guardrails, least privilege, and continuous monitoring before broad deployment.
Source: Help Net Security
New Gafgyt variant C0XMO exploits DD-WRT to grow cross-platform IoT botnet
FortiGuard Labs analyzed “C0XMO,” a Gafgyt offshoot that abuses DD-WRT vulnerabilities and propagates across multiple architectures to expand IoT botnet reach. The campaign’s cross-platform tooling and router focus increase risk to home and small office gateways that bridge into enterprise networks. Network operators should patch third‑party firmware, disable unused services, and block outbound C2 traffic from edge devices.
Source: Fortinet
You May Also Be Interested In...
Software supply chain attacks: check your dependencies (NCSC)
Fake sites mimicking open-source tools deliver malware via TDS (The Hacker News)
Unpatched Windows search URI handler issue leaks NTLMv2 hashes (SC Media)