Search results for CVSS
AI & Enterprise
Three trust vulnerabilities found in Claude Code, Gemini CLI and Codex
A shared trust risk has been identified in three AI coding agents - Claude Code, Gemini CLI and Codex - in which malicious GitHub issues can influence subsequent agent runs. Security firm Nobi Security found trust boundaries can break across tool permissions, sandbox isolation and shared workspaces. Researchers said the structure could enable remote code execution, data leaks and persistent control of follow-on agents. Google rated the issue at CVSS 10.0 and adjusted trust mechanisms.
AI & Enterprise
Ruby on Rails patches critical CVSS 9.5 flaw, urges update
Ruby-based web development framework Ruby on Rails has released a patch for a serious vulnerability that could allow unauthenticated attackers to execute remote code, SecurityWeek reported. The flaw, tracked as CVE-2026-66066 and rated 9.5 on the CVSS scale, involves arbitrary file reads that could expose secrets and enable lateral movement. Administrators urged users to update affected Active Storage versions and raise libvips to at least 8.13.
AI & Enterprise
Ransomware targeting AI models emerges, encrypting training weights and raising recovery cost concerns
U.S. security firm Sysdig said the same attacker breached an internet-exposed Langflow server twice, using AI-focused ransomware called ENCFORGE in the second attack. The intrusions exploited a Langflow authentication bypass flaw to run arbitrary Python code and later evolved to encrypt AI assets. ENCFORGE selectively encrypts model checkpoints, vector indexes and training data. Sysdig estimated rebuilding a fine-tuned production model could cost $75,000 to $500,000.
-
AI & Enterprise
Cl0p ransomware affiliate shows signs of exploiting PTC Windchill, FlexPLM flaw
-
AI & Enterprise
AI era puts focus on shift-left security to find and fix vulnerabilities during development
-
AI & Enterprise
U.S. government cuts deadline to 3 days for most critical cyber flaws amid AI attacks
-
AI & Enterprise
No time to respond to ultra-fast AI attacks, \'patch gap\' alarm
-
Games & Commerce
18-year-old Excel bug still used in attacks, warning for legacy Office users
-
AI & Enterprise
VMware Aria Operations flaw exploited in real-world attacks