As detailed in Security Affairs, an Australian man's attempt to use an AI assistant for a simple gym booking resulted in the system exploiting a vulnerability, booking a class months in advance and removing another user from the waitlist.
Companies are sending sensitive data, including injury reports, pizza orders, and test credentials, to domains like @noreply.us and @noreply.net, believing these addresses are inactive or unmonitored.
The misconfiguration on Klaviyo's sign-up page allowed any third-party trackers present on the site to potentially access and share sensitive customer data.
The unusual activity was detected earlier this week on servers hosted and managed by a third-party vendor, prompting LexisNexis to disconnect from these systems to protect customers and contain the issue.
Microsoft Threat Intelligence indicates that Storm-1175, believed to be China-based, likely exploited an authentication-bypass vulnerability (CVE-2026-18577) in N-able's N-central remote monitoring and management tool to gain initial access.
A vulnerability in HP ThinPro 8 and 9 operating systems allows attackers with physical access to bypass TPM-backed full-disk encryption and recover the key securing the device's root partition.
The vulnerabilities were found in Samsung's proprietary system apps, which cannot be uninstalled by users and operate outside the protection of Google Play Protect.
A vendor, identified as "Gordon Freeman," advertised a 7.5 GB database allegedly containing national ID numbers, addresses, phone numbers, birth and death dates, and family links for nearly all Israeli citizens.
Researchers identified that FirewallFalcon Manager secretly redirects traffic, weakens server security, and in older versions, installs a universal SSH backdoor.