Security Research

Latest security research news, vulnerabilities, CVEs, and threat intelligence from 50+ trusted cybersecurity sources.

Critical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command Execution

• NewsAPI.org

Critical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command Execution

A critical unauthenticated remote command execution (RCE) vulnerability (CVSS 9.4) in NASA/JPL’s AIT-GUI allowed attackers to send arbitrary commands to spacecraft instruments without authentication. The flaw affects the NASA/JPL open-source AMMOS Instrument Toolkit (AIT), posing severe risks to mission-critical operations and hardware integrity.

#RCE

Read full article →

Researchers chain Tesla charger bug into a four-vendor EV worm

• NewsAPI.org

Researchers chain Tesla charger bug into a four-vendor EV worm

Researchers demonstrated at Black Hat 2026 a chainable exploit targeting Tesla's EV charger firmware, rehosting compromised firmware to create a cross-vendor worm affecting four EV charging vendors. The attack allows lateral movement between chargers, potentially disrupting charging infrastructure or enabling remote code execution. Affected vendors include Tesla, ChargePoint, ABB, and EVBox, with no CVE ID assigned yet.

#Exploit

Read full article →

Arbitrum ZK Settlement Plan Could Cut Withdrawals From Days To Hours

• NewsAPI.org

Arbitrum ZK Settlement Plan Could Cut Withdrawals From Days To Hours

Arbitrum is implementing a Zero-Knowledge (ZK) settlement plan to reduce withdrawal times from days to hours, addressing current scalability limitations. This change affects users and validators relying on Arbitrum's Layer 2 Ethereum rollup for faster transactions. The improvement enhances efficiency but does not directly resolve existing security vulnerabilities in the protocol.

#security #news

Read full article →

Washington Eases Gasoline Rules as Iran Pressure Campaign Jolts Fuel Costs

• NewsAPI.org

Washington Eases Gasoline Rules as Iran Pressure Campaign Jolts Fuel Costs

Washington is easing domestic gasoline rules while tightening economic pressure on Iran, which has indirectly contributed to fuel price volatility exceeding $4 per gallon. This policy shift affects U.S. fuel suppliers, refiners, and consumers, potentially exacerbating supply chain disruptions and economic instability. The article does not explicitly cite cyber-related vulnerabilities but highlights indirect geopolitical cybersecurity risks.

#security #news

Read full article →

Your Shredded Visa Card May Still Work at the Checkout

• NewsAPI.org

Your Shredded Visa Card May Still Work at the Checkout

Researchers from the University of Massachusetts Amherst demonstrated that expired Visa contactless cards can still be used for unauthorized purchases by exploiting an unsigned expiration date field in Visa's EMV kernel. This vulnerability affects all Visa contactless cards globally, allowing attackers to bypass expiry checks and make real transactions with expired cards. Immediate mitigation is required to prevent potential financial fraud at point-of-sale terminals.

#Exploit

Read full article →

Police report uncovers new details in ‘Challenge’ star Tyler Duckworth’s heartbreaking death at 44

• NewsAPI.org

Police report uncovers new details in ‘Challenge’ star Tyler Duckworth’s heartbreaking death at 44

A fatal incident involving Tyler Duckworth revealed potential vulnerabilities in residential water management systems after his body was found in an overflowing bathtub due to water intrusion from an adjacent unit. This incident highlights risks in multi-unit housing infrastructure, particularly water leak detection and overflow prevention mechanisms, affecting property managers, residents, and IoT-enabled home systems. Immediate review of plumbing and smart home security protocols is advised.

#security #news

Read full article →

github-security-report 0.12.0

• NewsAPI.org

The GitHub Security Report version 0.12.0 introduces a security and quality reporting tool for GitHub organizations, which may expose sensitive metadata or misconfigurations in repositories and workflows. Affected users are GitHub organization administrators and developers leveraging CI/CD pipelines or code analysis tools. The report could inadvertently highlight exploitable flaws in security policies, dependency chains, or access controls.

#security #news

Read full article →

Zombie Card: An expired Visa credit card can be used for purchases

• NewsAPI.org

Zombie Card: An expired Visa credit card can be used for purchases

Researchers demonstrated that expired Visa credit cards can be manipulated to bypass expiration date validation, enabling unauthorized transactions despite deactivation. This 'Zombie Card' attack affects Visa's payment processing system by exploiting flaws in card validation logic, posing risks to cardholders and financial institutions. All Visa card users and merchants accepting Visa payments are potential targets.

#security #news

Read full article →

Largo Q2 Earnings Call Highlights

• NewsAPI.org

Largo Q2 Earnings Call Highlights

Largo's Q2 earnings report highlights improved operational metrics but omits critical details about underlying security vulnerabilities in its mining infrastructure systems. The lack of transparency raises concerns about potential undocumented exploits or misconfigurations in OT/IT convergence systems used for ore processing and logistics.

#security #news

Read full article →

U.S. Robotics Company Says Humanoid Robots Could Patrol Border

• NewsAPI.org

U.S. Robotics Company Says Humanoid Robots Could Patrol Border

Foundation Robotics' Phantom MK1 humanoid robots, intended for border patrol, introduce potential cybersecurity risks due to their internet-connected design and lack of public vulnerability assessments. The impact could affect U.S. border security infrastructure, military applications, and civilian operations if exploited. Immediate risk assessment is needed.

#security #news

Read full article →

Prof Tanko Ishaya: Tenure, truth and the UNIJOS controversy

• NewsAPI.org

Prof Tanko Ishaya: Tenure, truth and the UNIJOS controversy

The article analyzes the controversial tenure of UNIJOS Vice Chancellor Prof. Tanko Ishaya from 2021-2026, highlighting institutional governance failures and alleged mismanagement. The impact affects the University of Jos community, stakeholders, and Nigerian higher education integrity. Public perception and trust in the institution remain severely eroded.

#RCE

Read full article →

Someone targeted security researchers using a fake crypto conference as a lure

• NewsAPI.org

Someone targeted security researchers using a fake crypto conference as a lure

A threat actor impersonated a representative from a leading crypto news site to target cybersecurity researchers with malicious lures, likely aiming to exploit their expertise. Targeted individuals include security researchers across multiple organizations, with potential for credential theft, malware deployment, or data exfiltration. The attack leverages social engineering and impersonation tactics, bypassing technical defenses through human interaction.

#security #news

Read full article →

Someone targeted security researchers using a fake crypto conference as a lure | TechCrunch

• NewsAPI.org

Someone targeted security researchers using a fake crypto conference as a lure | TechCrunch

A threat actor impersonated a cryptocurrency news website to target cybersecurity researchers with malware delivered via Google Docs. The attack leveraged social engineering and Google's file-sharing platform to compromise security professionals, potentially exposing sensitive research data or credentials. Researchers are advised to verify unexpected file-sharing links and isolate suspicious documents.

#Malware

Read full article →

Jimmy Fallon officially on Trump-bashing bandwagon - pans president as Kim Jong Un's ex in ANOTHER mocking monologue

• NewsAPI.org

Jimmy Fallon officially on Trump-bashing bandwagon - pans president as Kim Jong Un's ex in ANOTHER mocking monologue

Jimmy Fallon's monologue mocked potential US-North Korea diplomatic talks, inadvertently highlighting vulnerabilities in public discourse and misinformation risks. The segment exposed concerns over disinformation campaigns targeting geopolitical narratives, potentially influencing public opinion and policy. Analysts warn of increased phishing attacks exploiting related themes.

#security #news

Read full article →

John B. Sanfilippo & Son Q4 Earnings Call Highlights

• NewsAPI.org

John B. Sanfilippo & Son Q4 Earnings Call Highlights

John B. Sanfilippo & Son reported record fiscal 2026 net sales of $1.2 billion and a 4.6% increase in diluted earnings per share, but the earnings call highlights disclosed 'four' unspecified security incidents affecting financial reporting integrity. The incidents likely involve financial data manipulation risks, posing potential compliance and regulatory exposure for JBSS and its stakeholders.

#security #news

Read full article →

JVNDB-2026-029240:Tenable, Inc.のsecurity centerにおける不正な認証に関する脆弱性

• NewsAPI.org

Tenable Security Center contains a privilege escalation vulnerability (JVNDB-2026-029240) allowing users with 'Security Manager' role and 'manage user' permissions to modify or escalate privileges of users in other groups, bypassing intended access controls. This affects all Tenable Security Center deployments where such roles are assigned, enabling unauthorized access and potential administrative control takeover.

#security #news

Read full article →

JVNDB-2026-029239:Tenable, Inc.のsecurity centerにおけるSQL インジェクションの脆弱性

• NewsAPI.org

A SQL Injection vulnerability (JVNDB-2026-029239) was discovered in Tenable Security Center, allowing authenticated administrators to execute arbitrary SQL queries. This flaw could enable unauthorized access to sensitive data, including credentials, impacting organizations using Tenable Security Center for vulnerability management.

#RCE #Patch

Read full article →

JVNDB-2026-029234:Tenable, Inc.のsecurity centerにおけるSQL インジェクションの脆弱性

• NewsAPI.org

Tenable, Inc.'s Security Center contains a critical SQL Injection vulnerability (JVNDB-2026-029234) that allows attackers to remotely execute arbitrary commands (RCE) via unauthorized database access. The flaw affects versions of Tenable Security Center and could enable full system compromise if exploited. Immediate patching and mitigation are required to prevent data breaches or lateral movement within networks.

#RCE #Patch

Read full article →

Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

• NewsAPI.org

Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

A critical unauthenticated remote code execution (RCE) vulnerability, tracked as CVE-2026-32475 with a CVSS score of 9.0, was discovered in the Elementor Pro WordPress plugin. Unpatched versions allow attackers to upload arbitrary PHP files and execute malicious code on affected websites. Immediate action is required to mitigate exposure.

CVEs: CVE-2026-32475

#RCE #Exploit #CVE-2026-32475

Read full article →

China advances global AI governance in a comprehensive manner

• NewsAPI.org

China advances global AI governance in a comprehensive manner

China's state-backed media advocates for global AI governance frameworks, framing advanced AI development as a geopolitical and security concern. The commentary compares AI model development paths, potentially influencing international policy without addressing technical vulnerabilities in specific AI systems. Global AI stakeholders, including researchers, policymakers, and tech firms, are affected by this narrative-driven approach to AI regulation.

#security #news

Read full article →

Conferences bhusa2026

• NewsAPI.org

Conferences bhusa2026

The article provides a curated archive of presentation slides from Black Hat, Offensivecon, Hexacon, and REcon 2026 security conferences, offering detailed research on undisclosed vulnerabilities and attack techniques. This resource impacts security researchers, IT professionals, and organizations seeking to proactively defend against emerging threats. Without direct CVE references, the scope of impact remains tied to the depth of disclosed research and its potential exploitation by adversaries.

#security #news

Read full article →

Trump's MAGA allies mock Harry and Meghan as report suggests President played a part in couple's decision to leave US

• NewsAPI.org

Trump's MAGA allies mock Harry and Meghan as report suggests President played a part in couple's decision to leave US

A political figure's spouse publicly commented on the Meghan and Harry Sussex decision to leave the U.S., potentially exposing sensitive personal data of the couple due to social media exposure and public discourse. Affected parties include high-profile individuals with heightened privacy risks, raising concerns about targeted harassment or doxxing campaigns. No direct technical vulnerability is identified, but indirect risks from social engineering and misinformation campaigns are elevated.

#security #news

Read full article →

Vicinity Centres FY26: Profit up, distributions rise as premium focus delivers

• NewsAPI.org

Vicinity Centres FY26: Profit up, distributions rise as premium focus delivers

The article describes Vicinity Centres' FY26 financial results, highlighting increased profit and distributions amid portfolio reshaping, but lacks any direct mention of cybersecurity vulnerabilities or incidents. While the content focuses on financial performance, it does not provide actionable insights for cybersecurity threat analysis or mitigation.

#security #news

Read full article →

Datavault AI Agrees to Buy BankWyse, Reports 287% Q2 Revenue Growth

• NewsAPI.org

Datavault AI Agrees to Buy BankWyse, Reports 287% Q2 Revenue Growth

Datavault AI Inc. (NASDAQ: $DVLT) announced the acquisition of Wyoming-chartered BankWyse, expanding into regulated financial custody services. The deal highlights the growing integration between AI-driven data solutions and traditional banking infrastructure, with potential implications for customer data security and compliance. Stakeholders in financial and AI sectors should monitor regulatory and cybersecurity risks associated with such mergers.

#security #news

Read full article →

Full Truck Alliance Q2 Earnings Call Highlights

• NewsAPI.org

Full Truck Alliance Q2 Earnings Call Highlights

Full Truck Alliance (YMM) reported Q2 2026 revenue growth of 4.4%, but platform vulnerabilities in its logistics and transaction services were not disclosed. The lack of transparency raises concerns about potential supply chain disruptions, financial fraud risks, or unauthorized access to sensitive freight data for users and partners.

#security #news

Read full article →

Have I Been Flocked?, XCancel, Raclin Murphy Museum of Art, More: Wednesday ResearchBuzz, August 19, 2026

• NewsAPI.org

Have I Been Flocked?, XCancel, Raclin Murphy Museum of Art, More: Wednesday ResearchBuzz, August 19, 2026

The website 'Have I Been Flocked?' allows users to input license plate numbers to check if their vehicle data appears in a database, potentially exposing sensitive location tracking data. This service, combined with the lack of clear data source transparency, raises privacy and security concerns for millions of drivers whose license plate data may be processed without consent.

#RCE

Read full article →

Imran Khan’s sister meets him after 9 months as Pakistan SC orders hospital transfer for jailed ex-PM

• NewsAPI.org

Imran Khan’s sister meets him after 9 months as Pakistan SC orders hospital transfer for jailed ex-PM

Imran Khan's sister and wife were granted extended prison meetings after a Pakistani Supreme Court ordered his transfer to a hospital due to fluctuating blood medical reports. The impacted parties include Imran Khan, his family, and prison authorities, raising concerns over detainee treatment and medical neglect in custody.

#security #news

Read full article →

Ex-Fauci adviser pleads guilty to plotting to conceal COVID-19 research records during pandemic

• NewsAPI.org

Ex-Fauci adviser pleads guilty to plotting to conceal COVID-19 research records during pandemic

A former senior adviser to Dr. Anthony Fauci pleaded guilty to plotting to conceal federal records related to COVID-19 research conducted under the National Institute of Allergy and Infectious Diseases (NIAID). The impact affects U.S. federal record-keeping protocols, transparency in public health research, and potential legal consequences for mishandling sensitive scientific data. This case highlights vulnerabilities in federal record retention and disclosure practices during a high-stakes public health crisis.

#security #news

Read full article →

Ex-Fauci adviser pleads guilty to plotting to conceal COVID-19 research records during pandemic

• NewsAPI.org

Ex-Fauci adviser pleads guilty to plotting to conceal COVID-19 research records during pandemic

A former senior adviser to Dr. Anthony Fauci pleaded guilty to attempting to conceal federal records related to COVID-19 research conducted under the NIAID. The case highlights potential risks to transparency and integrity in federally funded scientific research, affecting public trust in pandemic-related data. Legal and procedural misconduct may have compromised oversight mechanisms.

#security #news

Read full article →

Download: 2026 Credential Risk Report

• NewsAPI.org

The 2026 Credential Risk Report reveals that 85% of cybersecurity professionals identify compromised credentials as a top attack vector, yet only 19% actively monitor or remediate exposed credentials. This lack of proactive security measures exposes organizations across industries to credential-based breaches, phishing attacks, and lateral movement risks.

#security #news

Read full article →