FileRun: Four More Ways to Run Your Files
VulnCheck's Initial Access Intelligence team details four authenticated remote code execution vulnerabilities in FileRun, where a contact-sheet handler and a settings test endpoint run attacker input through a shell, and a delegated administrator turns a control-panel field into stacked SQL that a permission-blob deserialization weaponizes into a webshell.
The Anthropic Glasswing Receipts Are Starting to Trickle In
A look into Anthropic Glasswing's latest update to their vulnerability disclosure ledger.
Same Target, Different Playbooks: Two Attackers, Two Different Paths to Pwning the AI Stack
A look into real threat actor activity targeting Langflow hosts using different techniques and tactics.