Cybersecurity

OpenAI, Trend Micro, HPE, and Microsoft Patch Critical Zero-Click and RCE Vulnerabilities Amid Surge in Telecom and Cloud Exploits

OpenAI, Trend Micro, HPE, and Microsoft Patch Critical Zero-Click and RCE Vulnerabilities Amid Surge in Telecom and Cloud Exploits

TL;DR * OpenAI patches ZombieAgent and ShadowLeak vulnerabilities in ChatGPT connectors, enabling zero-click exfiltration of Gmail, GitHub, and Outlook data via memory and file upload exploits * Trend Micro releases Critical Patch Build 7190 to remediate CVE-2025-69258 allowing unauthenticated remote code execution in Apex Central via DLL injection
Barista @ Cafecito
Critical n8n RCE Vulnerability CVE-2026-21858 Exploited, GoBruteforcer Botnet Grows, and OpenAI’s ChatGPT Health Faces Legal and Medical Risks

Critical n8n RCE Vulnerability CVE-2026-21858 Exploited, GoBruteforcer Botnet Grows, and OpenAI’s ChatGPT Health Faces Legal and Medical Risks

TL;DR * CVE-2026-21858 Critical RCE Vulnerability in n8n Allows Unauthenticated Attackers to Exfiltrate Credentials and Execute Commands on Systems * GoBruteforcer Botnet Targets 50,000+ Exposed FTP/MySQL Servers to Steal Cryptocurrency Wallets via Brute-Force Attacks on Default Credentials * Kensington and Chelsea Council Data Breach Exposes Hundreds of
Barista @ Cafecito
North Korean Hackers Use AI-Enhanced Smart Contract Malware, Physical Crypto Attacks Surge as Phishing Fades

North Korean Hackers Use AI-Enhanced Smart Contract Malware, Physical Crypto Attacks Surge as Phishing Fades

TL;DR * North Korean hackers embed malware in blockchain smart contracts via UNC5342 group, leveraging Ethereum and Binance Smart Chain to evade detection and distribute InvisibleFerret payloads * ShinyHunters breached Resecurity’s honeypot, exfiltrating 28,000+ consumer records and impersonating victims to exploit Vietnam’s National Credit Information Center (CIC) data
Barista @ Cafecito
Flow Foundation Halts Network to Recover $3.9M Without Rollback; AMD, Microsoft, and Trust Wallet Also Deploy Major Security Fixes

Flow Foundation Halts Network to Recover $3.9M Without Rollback; AMD, Microsoft, and Trust Wallet Also Deploy Major Security Fixes

TL;DR * Flow Foundation patches $3.9M blockchain exploit, recovers 2,596 compromised addresses via validator-authorized cleanup * Trust Wallet browser extension compromise leads to $7M in crypto losses, prompting security audit and user reimbursement plan * AMD releases microcode patches for Zen CPU signature verification flaw, enabling secure custom microcode
Barista @ Cafecito