FASTJSON ZERO-DAY PUTS US FIRMS AT RISK
■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE
Hackers are actively exploiting a remote code execution vulnerability in FastJson, a widely-used Java library. The zero-day requires no user interaction or elevated privileges to trigger.
■ MORE FROM THE SECURITY DESK
The Head Mare hacktivist group has compromised TrueConf video conferencing servers and replaced legitimate client installers with trojaned versions containing backdoors.
OpenAI inadvertently launched a denial-of-service attack against Hugging Face, the popular machine learning platform. The incident has prompted questions about AI infrastructure security and unintended consequences of large-scale operations.
Framework's customer database was compromised in a data breach, though payment information was not exposed. The company has disclosed the incident to affected users.
Security researchers have identified potential hardware backdoors in certain x86 processors. The findings, detailed in a GitHub repository called Rosenbridge, reveal vulnerabilities at the processor level that could allow unauthorized access.