vulnerability

GPS Is Vulnerable to Jamming—here’s How We Might Fix It

GPS is susceptible to jamming, as evidenced by a recent incident involving a Widerøe Airlines flight in Norway during Russian military exercises causing navigation failures. The frequency of GPS disruptions has risen globally, impacting various sectors, including emergency services and agriculture. Agencies like the Department of Defense and the FAA are seeking alternatives and enhancements to GPS, investing in modernization efforts totaling billions. Innovations include higher frequency signals and alternative positioning systems to reduce vulnerability to interference. While improvements are in progress, the reliance on GPS remains a challenge due to its ubiquity and free access.

https://arstechnica.com/information-technology/2025/12/gps-is-vulnerable-to-jamming-heres-how-we-might-fix-it/

Pen Testers Accused of ‘blackmail’ Over Eurostar AI Flaws

Pen testers identified four significant flaws in Eurostar's AI chatbot, allowing potential injection of malicious HTML and system prompts leakage. After initial reports were ignored, the team accused the company's security head of “blackmail” for following up. Eurostar later found the report and addressed some issues. The chatbot's poor design permits users to manipulate chat history and bypass security checks, leading to risks like data leaks and phishing attacks. The incident highlights the need for robust security in consumer-facing chatbots.

https://www.theregister.com/2025/12/24/pentesters_reported_eurostar_chatbot_flaws/

How We Pwned X (Twitter), Vercel, Cursor, Discord, and Hundreds of Companies Through a Supply-chain Attack

A 16-year-old hacker discovered a critical XSS vulnerability in Mintlify, an AI documentation platform used by major companies like Discord and Twitter. By exploiting this vulnerability, attackers could inject malicious scripts into company documentation, risking user credentials. After identifying the flaw during Discord's transition to Mintlify, he and collaborators reported the issue, leading Discord to temporarily revert documentation changes and Mintlify to quickly patch vulnerabilities. The incident highlighted the risks of supply chain attacks and resulted in around $11,000 in bug bounties.

https://gist.github.com/hackermondev/5e2cdc32849405fff6b46957747a2d28

Two Chrome Flaws Could Be Triggered by Simply Browsing the Web: Update Now

Google has issued an unscheduled Chrome update to fix two serious vulnerabilities, CVE-2025-14765 in WebGPU and CVE-2025-14766 in the V8 JavaScript engine, that can be triggered remotely when users load maliciously crafted web pages. Because Chrome has billions of users, these flaws are high-value targets for attackers, and users are strongly urged to update immediately to version 143.0.7499.146/.147 on Windows and macOS or 143.0.7499.146 on Linux. The piece provides simple update instructions (using Chrome’s About page or automatic updates) and briefly explains that one bug is a use-after-free in WebGPU, leading to potential heap corruption, while the other is an out-of-bounds read/write in V8 that can allow attackers to access or modify memory and potentially run code with elevated permissions. The core message is that users should not delay restarting and updating Chrome, since merely browsing the web could expose them to attacks until the patch is applied.

https://www.malwarebytes.com/blog/news/2025/12/two-chrome-flaws-could-be-triggered-by-simply-browsing-the-web-update-now

GeminiJack: The Google Gemini Zero-Click Vulnerability Leaked Gmail, Calendar and Docs Data

GeminiJack: A discovered zero-click vulnerability in Google Gemini Enterprise allowed attackers to exfiltrate sensitive corporate data through shared documents, emails, or calendar invites without user interaction. This architectural flaw permits harmful content to instruct the AI to retrieve confidential information, which is then sent to the attacker via an external image request. The attack operates silently, bypassing traditional security measures. Google has since updated its systems to prevent such vulnerabilities, marking a shift in enterprise AI security considerations. Organizations must enhance monitoring and trust boundaries as AI tools evolve.

https://noma.security/blog/geminijack-google-gemini-zero-click-vulnerability/

Novel Clickjacking Attack Relies on CSS and SVG

Security researcher Lyra Rebane has developed a novel clickjacking attack utilizing CSS and SVG, which poses risks by bypassing the web's same-origin policy. This attack enables manipulation of user interface elements without JavaScript. Rebane's technique was explored in her BSides presentation and is based on SVG filters, allowing for complex attack chains. While it hasn't been fixed, defenders may use the Intersection Observer API to detect such vulnerabilities. The attack exemplifies the evolving nature of web security threats.

https://www.theregister.com/2025/12/05/css_svg_clickjacking/

New Prompt Injection Attack Vectors Through MCP Sampling

Palo Alto Networks' Unit 42 article discusses security risks associated with the Model Context Protocol (MCP) in coding applications. MCP enables large language models (LLMs) to connect with external services, but without safeguards, malicious servers can exploit it for various attacks. Key risks identified include resource theft, conversation hijacking, and covert tool invocation. The article presents proof-of-concept attacks demonstrating these vulnerabilities and emphasizes the need for effective prevention strategies. Additionally, it outlines MCP's structure and operational flow, detailing how sampling allows servers to request LLM responses. Overall, this creates potential attack vectors that necessitate robust security measures.

https://unit42.paloaltonetworks.com/model-context-protocol-attack-vectors/

How I Reverse Engineered a Billion-Dollar Legal AI Tool and Found 100k+ Confidential Files

TLDR: Alex Schapiro discovered a serious security vulnerability in Filevine, a billion-dollar legal AI tool, on October 27, 2025, allowing full admin access to confidential law firm files without authentication. He responsibly disclosed the issue, which could have exposed sensitive data like HIPAA-protected documents. Filevine quickly acknowledged and resolved the problem, demonstrating effective security disclosure practices.

https://alexschapiro.com/security/vulnerability/2025/12/02/filevine-api-100k

Critical RSC Bugs in React and Next.js Allow Unauthenticated Remote Code Execution

Critical security flaw in React Server Components (CVE-2025-55182) allows unauthenticated remote code execution, affecting multiple React versions. Exploitable due to unsafe deserialization, attackers can craft HTTP requests to execute arbitrary JavaScript. This impacts versions of React libraries and Next.js. Patches are available; users advised to update and monitor for suspicious traffic until then. Various cloud providers have implemented protective measures.

https://thehackernews.com/2025/12/critical-rsc-bugs-in-react-and-nextjs.html

Microsoft “mitigates” Windows LNK Flaw Exploited as Zero-day

Microsoft mitigated a severe Windows LNK vulnerability exploited by state and cybercrime groups (CVE-2025-9491), allowing attackers to conceal malicious operations in LNK files, requiring user interaction to execute. Despite initial inaction, Microsoft silently adjusted LNK file visibility in June 2025, while unofficial patches have been offered to limit risks until a thorough fix is provided.

https://www.bleepingcomputer.com/news/microsoft/microsoft-mitigates-windows-lnk-flaw-exploited-as-zero-day/

Critical Vulnerability in React and Next.js (CVE-2025-55182)

TLDR: On December 3, 2025, React disclosed CVE-2025-55182, a critical remote code execution vulnerability (CVSS 10) in React Server Components due to unsafe deserialization. Affects React versions 19.0-19.2.0; fixed in 19.0.1, 19.1.2, 19.2.1. Next.js versions 15.0.5-15.5.7 and 16.0.7 also need updates. Vulnerability allows remote exploitation without authentication.

https://www.vulncheck.com/blog/cve-2025-55182-react-nextjs

Google Fixes Two Android Zero Days Exploited in Attacks, 107 Flaws

Google's December 2025 Android security update fixes 107 vulnerabilities, including two exploited in attacks. Major issues address information disclosure and elevation of privileges. Critical flaws also include a denial-of-service vulnerability in the Android Framework and several severe vulnerabilities in the Kernel affecting Qualcomm devices. Users should update to newer Android versions or use third-party distributions for security.

https://www.bleepingcomputer.com/news/security/google-fixes-two-android-zero-days-exploited-in-attacks-107-flaws/

OpenAI Codex CLI Vulnerability: Command Injection

CVE-2025-61260 – OpenAI Codex CLI Command Injection Vulnerability:
OpenAI Codex CLI is susceptible to command injection via project-local configurations, enabling attackers to execute arbitrary commands on developer machines without user consent. By manipulating .env and config.toml files, an attacker can leverage the automatic loading of MCP server entries to create a backdoor, allowing persistent remote access and command execution. This vulnerability compromises developer workflows and can propagate through supply chains. A fix was issued in version 0.23.0, blocking the unsafe redirection of configuration paths. Users are advised to update immediately.

https://research.checkpoint.com/2025/openai-codex-cli-command-injection-vulnerability/

Years of JSONFormatter and CodeBeautify Leaks Expose Thousands of Passwords and API Keys

JSONFormatter and CodeBeautify leaks expose thousands of sensitive data, including passwords and API keys. Research identified over 80,000 files revealing credentials from sectors like government and finance. Both tools allowed users to store and share links, making sensitive data accessible to malicious actors. The tools' functionality has been temporarily disabled amid security concerns, as organizations are warned against using such platforms for sensitive information.

https://thehackernews.com/2025/11/years-of-jsonformatter-and-codebeautify.html

Scroll to Top