GitHub Security Lab Introduces AI-Powered Fuzzing Taskflow Agent
GitHub Security Lab has introduced a new fuzzing taskflow based on its Taskflow Agent AI framework, designed to leverage artificial intelligence for automated vulnerability discovery.
Trust and the Risks of Social Media Elicitation in Cybersecurity
Cisco Talos warns of highly targeted social media elicitation campaigns aiming to exploit cybersecurity professionals. Attackers use enticing consultancy offers to bypass defenses by targeting professional trust and industry hubris.
CVE-2025-39964: Linux Kernel AF_ALG Local Privilege Escalation
Researchers at STAR Labs share a retrospective on discovering CVE-2025-39964, a Linux kernel AF_ALG vulnerability enabling local privilege escalation to root. The bug was responsibly disclosed and earned a $113,337 reward through Google kernelCTF.
Dirty Cert: Cisco Smart Software Manager's Silently Patched RCE
Researchers discovered a post-authentication remote code execution vulnerability in Cisco Smart Software Manager involving command injection via TLS certificates during nginx certificate uploads. The flaw was silently patched by Cisco in an August 2026 upgrade before the report could be finalized.
F5 BIG-IP Unauthenticated Heap-Overflow to RCE (CVE-2026-94127)
WatchTowr has detailed a critical unauthenticated heap-overflow vulnerability leading to remote code execution in F5 BIG-IP, tracked as CVE-2026-94127 and located in the authentication header.
CVE-2026-13795: Chrome for iOS Policy Bypass via Shortcuts Callback
A policy bypass vulnerability in Chrome for iOS tracked as CVE-2026-13795 allowed web pages to trigger telephone or FaceTime handlers without user confirmation. By leveraging native Apple Shortcuts callback URLs, attackers could bypass Chrome’s standard user-interaction checks for sensitive URL schemes.
Canon MF753Cdw Heap Buffer Overflow Exploit (CVE-2024-0244)
An analysis of CVE-2024-0244 reveals a heap-based buffer overflow vulnerability affecting Canon MF753Cdw printers. This vulnerability could allow an attacker to execute arbitrary code or cause a denial of service state on affected devices.
Beyond Images: Bringing Rust Brotli to Edge Network Stack
The Microsoft Edge Security team is expanding its rustification model beyond image codecs to secure the edge network stack, introducing Rust Brotli to handle attacker-controlled compression inputs safely.
HTTP/3 Support in Burp Suite and Turbo Intruder
Turbo Intruder now supports HTTP/3, enabling security researchers to exceed 100,000 requests per second over Wi-Fi with auto-tuning capabilities.
Apple macOS CoreWLAN Information Disclosure Vulnerability
An information disclosure vulnerability has been identified in Apple macOS CoreWLAN. Researchers at Talos Intelligence reported the security issue under TALOS-2026-2376.