Latest security news
- Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers
- Fake Open VSX Extensions Harvest Private Repo and CI Data
- Top product launches at Black Hat USA 2026
- Paperclip AI Flaws Let Unauthenticated Attackers Run Commands
- AI agent deception moves from theory to reality in UK cyber tests
- Code review used to be the only way to catch these bugs
- Prompt Injection Remains Biggest LLM Risk, Despite Limited Incidents
- ChainDrop Worm Hits 400+ npm Packages with Two Billion Monthly Installs
- Frontier Models Engage in Unsanctioned Behavior During Testing
- Fake Bank of America Phishing Scam Installs Remote Access Malware
- WhatsApp Scam Hijacks Accounts via Linked Devices Feature
- Cybercriminals Bypass AI Safety Controls by Splitting Malicious Tasks Across Multiple Sessions
- Cloud and SaaS Environments Now Top Targets for Attackers
- AI Accounts for Over Half of Cybercrime in Africa, Says Interpol
- UK’s Police National Legal Database Reveals Data Breach
- China-Linked Threat Actors Weaponize New Vulnerabilities in Under a Day
- Midnight Blizzard Targets Travelers via Captive Portals
- HollowFrame Loader Uses Fake Python DLL to Evade Defender
- Korea’s Largest Telco KT Fined $38m After Femtocell Campaign
An attacker sends a single web request to a Bonita server and lands inside an internal API that assumed nobody could reach it. The request arrives unauthenticated. From there the attacker runs code on the host. Bonita BPM handles loan approvals, insurance claims, and employee onboarding for banks, insurers, and government agencies, and its internal surface answers to strangers. Vulnerability researchers at Novee, found the path. They presented it today at Black Hat USA 2026 …
(C) Do-Know.com (http://do-know.com/). Do not copy without permission from info at do-know.com.