Skip to main content
221 stories
GitLab Fixes Critical Path Traversal Flaw That Could Expose Arbitrary Server Files
cybersecurityTrendingvia GitLab / CVE.org

GitLab Fixes Critical Path Traversal Flaw That Could Expose Arbitrary Server Files

GitLab has patched CVE-2026-85706, a critical path traversal vulnerability in its repository commits API that could allow unauthenticated users to read arbitrary files from affected GitLab servers.

2 days ago4 min read
Cloudflare CASB Adds Automatic Remediation Policies for SaaS Security FindingsTrending
cloud-securityvia Cloudflare Blog

Cloudflare CASB Adds Automatic Remediation Policies for SaaS Security Findings

Cloudflare CASB now lets security teams automatically respond to SaaS security findings with supported remediation actions, webhooks, or both, reducing the need for manual intervention.

2 days ago6 min read
Russian Developers Used AI to Build Autonomous Drone Software, Anthropic ReportsTrending
cybersecurityvia Anthropic

Russian Developers Used AI to Build Autonomous Drone Software, Anthropic Reports

Anthropic says a small Russia-based freelance team used Claude to develop software for an autonomous FPV drone swarm, highlighting the growing security risks of AI-assisted weapons development.

2 days ago8 min read
GitLab Releases Critical Security Patch for 19.3, 19.2 and 19.1Trending
cybersecurityvia GitLab Docs

GitLab Releases Critical Security Patch for 19.3, 19.2 and 19.1

GitLab has released versions 19.3.2, 19.2.6 and 19.1.8 to address 18 security issues, including two Critical vulnerabilities and six High-severity flaws.

2 days ago7 min read
GuardBreaker: How a Simple Code Comment Can Disrupt AI-Assisted Malware AnalysisTrending
cybersecurityvia ESET WeLiveSecurity

GuardBreaker: How a Simple Code Comment Can Disrupt AI-Assisted Malware Analysis

ESET researchers identified GuardBreaker, a prompt-injection technique that uses a malicious code comment to trigger an LLM safety refusal and potentially disrupt AI-assisted malware analysis.

2 days ago7 min read
Mantax Otax Android Malware Combines Ransomware, Spyware and Remote Device ControlTrending
cybersecurityvia Zimperium zLabs

Mantax Otax Android Malware Combines Ransomware, Spyware and Remote Device Control

Zimperium researchers have uncovered Mantax Otax, an Android malware strain linked to Indonesian threat actors that combines ransomware, spyware, credential theft and remote device control in a single campaign.

2 days ago6 min read
How Codex and ChatGPT Are Helping Researchers Search for New Antimicrobial MoleculesTrending
ai-mlvia OpenAI

How Codex and ChatGPT Are Helping Researchers Search for New Antimicrobial Molecules

Researchers are combining AI models, ChatGPT, Codex and laboratory experiments to search vast biological datasets for potential antimicrobial molecules that could help address drug-resistant infections.

3 days ago6 min read

Get this in your inbox every morning

One daily email with the cyber and tech stories that matter, curated by Xcademia editors. No spam, unsubscribe anytime.

Google Spanner Removes Cumulative DML Mutation Limits, Enabling Larger TransactionsTrending
devopsvia Google Cloud Blog

Google Spanner Removes Cumulative DML Mutation Limits, Enabling Larger Transactions

Google Cloud has changed how Spanner handles DML mutation limits. The 80,000-mod cap now applies separately to each DML statement, allowing transactions to contain multiple larger operations without a cumulative DML mutation limit.

3 days ago6 min read
OpenAI Brings GPT-Live-1 to API, Making Voice Agents More Natural and ResponsiveTrending
ai-mlvia OpenAI

OpenAI Brings GPT-Live-1 to API, Making Voice Agents More Natural and Responsive

OpenAI has launched GPT-Live-1 in its API, bringing full-duplex voice conversations, smoother interruption handling, backend model delegation, telephony support and greater control over voice-agent behaviour.

3 days ago5 min read
OpenAI Introduces Agents API to Bring Codex-Style Cloud Agents to DevelopersTrending
ai-mlvia OpenAI

OpenAI Introduces Agents API to Bring Codex-Style Cloud Agents to Developers

OpenAI has launched the Agents API in public beta, giving developers a managed way to build long-running cloud agents with the Codex harness, tools, sandboxes, context management and multi-agent workflows.

3 days ago6 min read
Vwork and Gigabud: How Attackers Are Abusing Android App CloningTrending
cybersecurityvia Group-IB

Vwork and Gigabud: How Attackers Are Abusing Android App Cloning

Group-IB has uncovered how the Gigabud Android banking trojan uses Vwork, a modified open-source app cloner, to isolate cloned banking apps and evade security controls during fraudulent transactions.

3 days ago10 min read
Beyond Database Migration: How to Replicate SQL Server Logins and Users to Cloud SQLTrending
cloud-securityvia Google Cloud Blog

Beyond Database Migration: How to Replicate SQL Server Logins and Users to Cloud SQL

Migrating SQL Server databases to Google Cloud can leave applications unable to authenticate. Here is how sp_help_revlogin helps preserve SQL logins, password hashes and SIDs during Cloud SQL migrations.

3 days ago7 min read