Claude Fable 5 Generates Bootable Windows Kernel in Rust in 38 Minutes
Anthropic's Claude Fable 5 autonomously produced a bootable NT-compatible Windows kernel in Rust, raising security implications for AI-authored critical infrastructure.
Stories cluster related articles into a single narrative, linked to the underlying CVEs and affected products. 3,755 stories synthesized.
Anthropic's Claude Fable 5 autonomously produced a bootable NT-compatible Windows kernel in Rust, raising security implications for AI-authored critical infrastructure.
Google will now notify all administrators when any admin password is reset, expanding the Alert Center rule beyond super admins to improve privileged account oversight.
Cisco disclosed a critical SSRF vulnerability in Unified CM and Unified CM SME that lets unauthenticated attackers write arbitrary files and gain root privileges.
A SANS researcher published a proof-of-concept that spoofs both /proc//comm and /proc//cmdline, evading standard process-name detection.
Praxen, an open-source tool from Exabeam, implements Agent Behavior Verification to audit whether AI agents act within their declared policies, identifying drift and compliance gaps before and during deployment.
A high-severity vulnerability in Fuji Electric Tellus allows local attackers to escalate privileges to SYSTEM via exposed dangerous methods in the pcid64 driver.
A critical argument injection vulnerability in Docker MCP Plugin (CVE-2026-55887, CVSS 8.6) allows remote code execution when users reference malicious Docker images.
A critical code injection vulnerability in FlowiseAI Flowise's CSV Agent customReadCSV function, tracked as CVE-2026-41137, allows authenticated attackers to execute arbitrary code remotely.
A use-after-free vulnerability in Adobe Acrobat Reader DC's Field signatureInfo component, tracked as CVE-2026-27278 with a CVSS score of 7.8, could allow remote attackers to execute arbitrary code by tricking users into opening a malicious file or visiting a malicious page.
A high-severity cross-site scripting vulnerability in Quest NetVault Backup's viewclient component allows remote attackers to bypass authentication and potentially execute code as SYSTEM.
A high-severity cryptographic signature verification flaw in ATEN Unizon, tracked as CVE-2026-9779 with a CVSS score of 7.2, allows authenticated remote attackers to execute arbitrary code at the SYSTEM level.
A directory traversal vulnerability in ATEN Unizon, tracked as CVE-2026-9775 with a CVSS score of 5.5, allows authenticated remote attackers to delete arbitrary files via the uploadSSL function.
A directory traversal vulnerability in ATEN Unizon, tracked as CVE-2026-9778 with a CVSS score of 7.2, allows authenticated remote attackers to execute arbitrary code at the SYSTEM level.
A high-severity command injection flaw in Unraid's Web Server FileUpload functionality, tracked as CVE-2026-9772, could let authenticated attackers execute arbitrary code on affected systems.
A cross-site scripting flaw in the addclient3 component of Quest NetVault Backup (CVE-2026-9780) allows remote attackers to bypass authentication with a CVSS score of 8.8.
A local out-of-bounds read vulnerability in X.Org Server's ChangeDrawableAttributes function could allow attackers to leak sensitive information after gaining low-privileged code execution.
A critical prompt injection vulnerability in FlowiseAI's CSV Agent, tracked as CVE-2026-41264, allows unauthenticated attackers to achieve remote code execution with a CVSS score of 9.8.
A use-after-free bug in X.Org Server's FreeCounter component (CVE-2026-50260, CVSS 7.8) lets local attackers escalate privileges to root on affected Linux systems.
A use-after-free bug in X.Org Server's SyncChangeCounter function (CVE-2026-50261, CVSS 7.8) lets local attackers escalate privileges to root on affected Linux systems.
A high-severity vulnerability in Fuji Electric Tellus allows local attackers to escalate privileges to SYSTEM via exposed dangerous methods in the pcid64 driver.
A new SQL injection flaw in Quest NetVault Backup's NVBUDashboard component, tracked as CVE-2026-9786 with a CVSS score of 8.8, allows authenticated attackers to bypass authentication and execute arbitrary code.
A deserialization vulnerability in MosaicML Composer, tracked as CVE-2026-10043 with a CVSS score of 7.8, allows remote attackers to execute arbitrary code by tricking users into opening malicious checkpoint files.
A critical SQL injection flaw in Quest NetVault Backup's NVBURemovableMedia component, tracked as CVE-2026-9783 with a CVSS score of 8.8, allows authenticated attackers to bypass authentication and execute arbitrary code.
A command injection vulnerability in Quest NetVault Backup's NVBULogDaemon component, tracked as CVE-2026-9787 with a CVSS score of 8.8, allows authenticated attackers to bypass authentication and execute arbitrary code at the SYSTEM level.