AWS Kiro Flaw Turned Hidden Web Text Into Code Execution
AWS patched a Kiro IDE flaw that let hidden web text rewrite mcp.json and run commands without approval. Update Kiro and check MCP configurations now.
News desk
Security incidents, exploited vulnerabilities, breach reports, malware campaigns, and urgent patch notes arranged for fast daily scanning.
August 24, 2026
AWS patched a Kiro IDE flaw that let hidden web text rewrite mcp.json and run commands without approval. Update Kiro and check MCP configurations now.
Fake coding-test repositories hide OTTERCOOKIE fragments in SVG flags. Here is what executes, what it steals, and what to check after running one.
Grok Build 0.2.93 was observed uploading tracked repositories and Git history. Here is how to scope exposure, rotate secrets, review logs, and harden future…
Microsoft tracked ACR Stealer ClickFix chains using WebDAV, MSHTA and PowerShell. Check scheduled tasks, browser sessions, exposed passwords and cleanup steps.
Symantec documented a Spirals ransomware attack that moved from an exposed IIS server to network-wide encryption in under 24 hours. Check the confirmed indicators…
Starland RAT hides in trojanized Zoom, WebEx, and other Windows installers. Check persistence, scan the PC, and secure passwords and wallets.
CVE-2026-53412 is a critical Zoom Workplace for Windows flaw that may allow unauthenticated account takeover. Check your version and update now.
A disclosed Cursor flaw can run a repository-local git.exe on Windows when a project opens. Check the root folder and recover safely after exposure.
Fake LastPass and Bitwarden security-policy emails use newsletter and compliance lookalike domains. Check the sender, avoid the download, and secure your vault.