vulnerability

Vulnerability Landscape in Q4 2025

Q4 2025 saw a surge in high-profile vulnerability disclosures, with attackers exploiting several critical flaws in popular libraries and applications. The most prevalent exploits targeted Microsoft Office products and directory traversal vulnerabilities in WinRAR, highlighting the importance of timely security updates. Additionally, a significant increase in Linux-based exploit attempts underscores the need for robust security measures on these devices.

https://securelist.com/vulnerabilities-and-exploits-in-q4-2025/119105/

Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit

Google's Threat Intelligence Group identified a new iOS exploit kit, “Coruna,” targeting iPhone models from iOS 13.0 to 17.2.1. Coruna comprises five exploit chains and uses advanced techniques to bypass mitigations. It was initially discovered with links to commercial surveillance, later leveraged by Russian espionage and Chinese financial criminals. Users are urged to update their devices to the latest iOS version or enable Lockdown Mode for security. The kit features sophisticated mechanisms for targeting and data theft, indicating a growing market for reused zero-day exploits.

https://cloud.google.com/blog/topics/threat-intelligence/coruna-powerful-ios-exploit-kit

Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild

IDPI exploits hidden instructions in web content processed by LLMs, causing unauthorized actions without direct interaction. Recent evidence shows substantial real-world malicious exploitation, including AI ad review evasion and SEO manipulation targeting phishing. 22 techniques were identified, necessitating proactive defenses against such threats. Understanding and mitigating web-based IDPI is crucial for the safety of AI systems integrated into web operations.

https://unit42.paloaltonetworks.com/ai-agent-prompt-injection/

New AirSnitch Attack Bypasses Wi-Fi Encryption in Homes, Offices, and Enterprises

New research reveals a series of attacks, named AirSnitch, that bypass Wi-Fi encryption and client isolation, allowing attackers to intercept and manipulate data between connected clients. The attacks exploit vulnerabilities in the lowest levels of the network stack, specifically targeting the interaction between Layers 1 and 2. AirSnitch enables bidirectional man-in-the-middle attacks, potentially compromising sensitive data and enabling advanced cyberattacks.

https://arstechnica.com/security/2026/02/new-airsnitch-attack-breaks-wi-fi-encryption-in-homes-offices-and-enterprises/

Software Vulnerabilities Are Being Weaponized Faster Than Ever

VulnCheck reports that software vulnerabilities are being weaponized rapidly, with a 16.5% increase in exploits linked to 10,500 CVEs in 2025, partly due to AI-generated proof-of-concept code. Less than 1% of vulnerabilities were exploited, complicating threat assessment for security teams. Notably, over 50% of ransomware CVEs were zero-days. Major vulnerabilities include React2Shell (236 exploits) and a Microsoft Sharepoint flaw (36 exploits).

https://www.cybersecuritydive.com/news/software-vulnerabilities-are-being-weaponized-faster-than-ever/813096/

Caught in the Hook: RCE and API Token Exfiltration Through Claude Code Project Files

Check Point Research identified critical vulnerabilities in Anthropic’s Claude Code enabling remote code execution and API key theft through malicious project configurations. Attackers can exploit Hooks and Model Context Protocol to execute unauthorized commands and intercept API communications. All discovered vulnerabilities have been remediated by Anthropic. Developers must carefully scrutinize project configurations to prevent configuration-based attacks, treating them with the same caution as executable code.

https://research.checkpoint.com/2026/rce-and-api-token-exfiltration-through-claude-code-project-files-cve-2025-59536/

Man Accidentally Gains Control of 7,000 Robot Vacuums

A software engineer, Sammy Azdoufal, accidentally accessed the live feeds of nearly 7,000 connected DJI Romo robot vacuums while trying to control his own with a gaming controller. His development efforts revealed a significant security flaw, allowing him to view camera and microphone data from many vacuums. Azdoufal reported the bug, which DJI has since fixed, highlighting ongoing cybersecurity concerns as more households adopt smart technology.

https://www.popsci.com/technology/robot-vacuum-army/

Lessons From AI Hacking: Every Model, Every Layer Is Risky

Hillai Ben Sasson and Dan Segev, researchers at Wiz, discovered vulnerabilities in every major AI platform they targeted over two years of research. Their findings, to be presented at the RSAC Conference, highlight the importance of focusing on AI infrastructure security across model training, inference, application, and cloud layers. The researchers emphasize the need for regular security reviews and compliance checks to address the rapidly evolving threat landscape.

https://www.darkreading.com/application-security/lessons-ai-hacking-model-every-layer-risky

Password Managers’ Promise That They Can’t See Your Vaults Isn’t Always True

Password managers, despite claims of “zero-knowledge” security, may still have vulnerabilities that allow data theft under certain conditions, particularly during account recovery or when sharing vaults. Researchers warn that these flaws can be exploited by malicious actors, undermining the touted security benefits.

https://arstechnica.com/security/2026/02/password-managers-promise-that-they-cant-see-your-vaults-isnt-always-true/

I Hacked ChatGPT and Google’s AI – And It Only Took 20 Minutes

User hacked ChatGPT and Google's AI in 20 minutes. Demonstrated that AI tools can easily be manipulated to spread misinformation, even about serious topics. Created a fake ranking of “best tech journalists at eating hot dogs,” and AI accepted it as fact. Experts say AI is now easier to trick, raising concerns about misinformation's impact on public safety. Solutions include enhancing disclaimers and promoting critical thinking when using AI for information.

https://www.bbc.co.uk/future/article/20260218-i-hacked-chatgpt-and-googles-ai-and-it-only-took-20-minutes

Connected and Compromised: When IoT Devices Turn Into Threats

IoT devices, often lacking sufficient security features, pose significant risks to both home and enterprise networks. Reused passwords, lack of encryption, and poor data storage practices make these devices vulnerable to credential theft and unauthorized access. While vendors are moving towards more secure devices, the sheer number of existing IoT devices means it will take years to fully mitigate these risks.

https://www.darkreading.com/iot/connected-compromised-iot-devices-turn-threats

Microsoft Says Bug Causes Copilot to Summarize Confidential Emails

Microsoft 365 Copilot bug since January causes AI to incorrectly summarize confidential emails, bypassing DLP policies. A code error allows emails marked with confidentiality labels to be processed, prompting Microsoft to initiate a fix. As of mid-February, they continue monitoring the situation but have not disclosed the full impact or timeline for resolution.

https://www.bleepingcomputer.com/news/microsoft/microsoft-says-bug-causes-copilot-to-summarize-confidential-emails/

Flaws in Popular VSCode Extensions Expose Developers to Attacks

Flaws in popular VSCode extensions allow attackers to steal files and execute code. Vulnerabilities affect extensions like Code Runner and Markdown Preview Enhanced, with over 128 million total downloads. Discovered by Ox Security, the issues pose risks such as data exfiltration and system takeover. Developers are advised against using untrusted configurations and to only install reputable extensions.

https://www.bleepingcomputer.com/news/security/flaws-in-popular-vscode-extensions-expose-developers-to-attacks/

Scroll to Top