Category Archives: Security & Privacy
SGLang RCE Vulnerability (CVE-2026-5760) Exploits AI Pipelines
Security researchers have identified a critical SGLang RCE vulnerability (CVE-2026-5760) that allows remote code execution through malicious GGUF model files. Continue reading
Tor Browser 15.0.10 Released to Address Critical Identity Leakage
The Tor Project has released Tor Browser 15.0.10, a critical security update that fixes a high-priority identity leakage bug and updates Snowflake STUN servers for 2026. Continue reading
Surfshark Dausos Protocol: Post-Quantum Individualized VPN Tunnels
The Surfshark Dausos protocol introduces individualized post-quantum secure tunnels to eliminate neighbor noise and boost speeds by 30% compared to traditional protocols. Continue reading
Void Dokkaebi Supply Chain Worm Targets Developers via Fake Interviews
Security researchers have uncovered a Void Dokkaebi supply chain worm that spreads through malicious VS Code tasks and fraudulent job recruitment interviews targeting software developers. Continue reading
NymVPN Post-Quantum Lewes Protocol and Split Tunneling Update
NymVPN v2026.7 introduces the NymVPN post-quantum Lewes Protocol to secure data against future decryption threats, alongside new beta split-tunneling features. Continue reading
Pig Butchering Scams: AI-Augmented Digital Extortion Surges in 2026
A recent House hearing reveals how pig butchering scams are being hyper-personalized through generative AI, leading to billions in losses via automated social engineering and crypto fraud. Continue reading
Device Code Phishing: AI-Augmented Attacks Target Microsoft 365
A sophisticated device code phishing campaign is leveraging generative AI to exploit Microsoft 365 OAuth 2.0 flows and bypass multi-factor authentication. Continue reading
Axios Supply Chain Compromise: CISA Issues Emergency Alert
CISA has issued an emergency alert regarding the Axios supply chain compromise, where malicious code in the popular NPM package delivers a Remote Access Trojan to developer environments and CI/CD pipelines. Continue reading
SaaS Supply Chain Vulnerabilities: Lessons from the Vercel Incident
The 2026 Vercel security breach exposes critical SaaS supply chain vulnerabilities, demonstrating how OAuth token hijacking bypasses traditional authentication protocols. Continue reading