‼️A single malicious page may be enough to compromise Tor Browser, according to new research into the Firefox flaw CVE-2026-10702.
The bug allows arbitrary code execution in the browser renderer, and researchers say it also worked against Tor Browser before patches landed.
Source: https://t.co/PAmPs0tPEb
#cybersecurityawareness #cybersecuritynews
🛑 One malicious webpage visit was enough to compromise Tor Browser. No settings changes. No extra clicks.
Firefox JIT flaw, CVE-2026-10702, runs code inside the browser’s renderer process and forms the first stage of an Android 17 root chain.
Read how the exploit works: https://t.co/92ObVWyORg
‼️ BREAKING — Claude AI found a working HAWK-256 key-recovery attack.
HAWK is a NIST post-quantum cryptography candidate. It also made an impractical 7-round AES-128 attack up to 800x faster.
Read this here: https://t.co/JbDhrTjjt2
🛑 ALERT - WordPress sites are under active attack.
Attackers are exploiting the #wp2shell chain to gain unauthenticated RCE on vulnerable stock installations, with no plugins required. Public exploit code is now fueling mass scanning and web shell deployments.
Read what defenders should check: https://t.co/p6S8ILrUw0
We've reproduced the pre-auth RCE chain in Wordpress (wp2shell). It's real, patch!
Shoutout to @hash_kitten at Assetnote for catching such an awesome bug!
Yes, the software is called LG OnScreen Control Plus. it runs silently in the background. it tracks which applications you use, when you use them, and how long. it phones home to LG servers. it cannot be uninstalled through normal means without leaving registry traces.
gamers noticed because some anti-cheat systems flagged it as suspicious software. the monitor was getting people banned from games.
now the TV side:
LG also updated its webOS terms of service. if you use the AI voice features on your LG TV, the company says you may need to inform guests in your home that conversations could be recorded.
not LG informing your guests.
you. the homeowner. legally responsible for notifying anyone who walks into your living room that the television is listening.
LG built a surveillance device. sold it to you. and made the disclosure your legal problem.
so to recap what LG shipped this year:
a monitor that installs tracking software on your PC without asking.
a TV that records conversations in your home and requires you to warn your guests.
both devices look exactly like a monitor and a TV.
neither one tells you what it actually is at the point of sale.
you found out when your game banned you.
or when you read the terms.
Credit: @GamersNexus for the discovery.
🛑 Hugging Face, the world’s largest AI model repository, says an autonomous AI agent breached its production systems through a malicious dataset.
It accessed internal data and service credentials, then moved across several clusters through thousands of actions in short-lived sandboxes.
Full story: https://t.co/ULJfbJfhmW
Chinese Backdoor for Telecom Systems
A while ago we showed the backdoor that the Chinese have been using to maintain persistence across telecom systems.
The backdoor attaches itself to a raw network socket and inspects incoming traffic. It sees packets before firewall rules have a chance to process them. So even if your firewall is configured correctly, the backdoor can still see traffic that should have been blocked.
To access the system hackers send a magic byte to get a reverse shell
We also showed how you can detect it
https://t.co/fBXtksn2Ju
@three_cube@_aircorridor