One Week, Nine Flaws, No Easy Fix
SecurityWeek's roundup covers a ransomware sentencing, a zero-click AI plugin flaw, and a critical SAP bug under active scrutiny.
8 results for “zero-click”
SecurityWeek's roundup covers a ransomware sentencing, a zero-click AI plugin flaw, and a critical SAP bug under active scrutiny.
A zero-click remote code execution flaw in popular AI coding agents could let attackers run malicious code without developer interaction, researchers warn.
Tencent patches zero-click flaw that allowed account takeover via VoIP calls.
Citizen Lab finds NSO Group spyware on an activist's iPhone via a zero-click exploit, highlighting ongoing surveillance of Serbian civil society.
A 9.8-rated flaw chain in the Avada WordPress theme lets unauthenticated attackers run PHP code.
A flaw in Zoom's annotation tool could let any participant take over a sharer's client — with zero clicks.
A sophisticated campaign by the threat group Laundry Bear has bypassed user interaction to harvest sensitive government data.
A severe vulnerability in the Classic Web Client requires immediate patching to prevent unauthorized code execution via email.