Critical macOS Screen Sharing flaw gives attackers remote root access — CISA bumps bug to 9.8 severity following active Monero cryptojacking attacks

NCSC-NL first flagged the vulnerability in an advisory on August 7, a day after Apple’s patch, urging organizations to update immediately. The August 12 revision added that public proof-of-concept code is now available a…

Critical macOS Screen Sharing flaw gives attackers remote root access — CISA bumps bug to 9.8 severity following active Monero cryptojacking attacks

NCSC-NL first flagged the vulnerability in an advisory on August 7, a day after Apple’s patch, urging organizations to update immediately. The August 12 revision added that public proof-of-concept code is now available a…

Critical ‘Zoomsday’ flaw enables total device takeover during Zoom calls — AI-assisted research only used 20 prompts to find an exploit to hack hundreds of mill

First, the scientists decompiled the Android package and asked an AI agent to rank the potential attack surfaces to relatively little success. They then turned their attention to the communications protocol. They found t…

Fake Go DNS scanner spread malware through over 200 GitHub repos — ‘Operation Muck and Load’ has published 700 malicious modules since January

Go derives a pseudo-version from the commit timestamp and hash for any commit that lacks a semantic version tag. Socket attributes the sprawl to the threat actor’s own GitHub Actions workflow, saying its timed commits co…