Qilin ransomware weaponizes Palo Alto VPN flaw
ZDI’s advisory (CVE‑2026‑14266) reveals a heap‑based buffer overflow in 7‑Zip’s XZ chunked data processing that can execute arbitrary code when a crafted archive is opened. The flaw affects all versions prior to 26.02, which ships the fix. Users should upgrade immediately to mitigate remote‑code execution risk.
Pillar Security uncovered repeatable sandbox‑escape techniques in Cursor, OpenAI Codex, Google Gemini CLI and Antigravity. The agents stay inside their workspaces but write files that downstream host utilities automatically run, scan, or load, effectively crossing the security boundary. Vendors have patched several CVEs; Google downgraded two findings.
Intezer and Kodem Security discovered that a single invisible pixel of text on a web page can trick Kiro, AWS’s AI‑powered coding IDE, into rewriting its own config file and executing attacker‑provided code on the developer’s machine, bypassing the required “allow” prompt. AWS has issued a patch, but no CVE has been assigned yet.
Arctic Wolf uncovered a wave of June 2026 intrusions where attackers used CVE‑2026‑0257, an authentication bypass in Palo Alto’s GlobalProtect VPN, to gain footholds and launch Qilin ransomware. The flaw lets unauthenticated users tunnel into firewalls, and affiliates quickly pivot to domain‑wide encryption, exposing any org still on pre‑patch versions.
A new study shows a cloud tenant can modulate GPU power draw at >6 kHz, and coordinating 1,000 GPUs in a 1 MW DER‑rich site spikes current THD to 46.8% and drives the damping ratio negative, threatening grid stability. The paper urges cross‑layer defenses linking workload scheduling to power‑electronics monitoring.
Subscribe free