Attackers are taking over dormant publisher accounts in Canonical’s Snap Store by re-registering expired web domains and associated email servers, then swapping trusted packages with trojanized versions that steal cryptocurrency. The supply chain abuse highlights a weak link in publisher verification; Linux users should re-check publishers, minimize snap permissions, and audit recently updated snaps in high-trust environments.
Source: Help Net Security
Anthropic MCP server flaws allow prompt‑injection to trigger code execution and data exposure
Researchers disclosed vulnerabilities in Anthropic’s official Git Model Context Protocol (MCP) server that could be exploited via prompt injection to read/delete arbitrary files or execute code when chained with other tools. The bugs underscore that LLM agents inherit the risk of their toolchains; teams should patch to the fixed version, sandbox agents, and restrict tool permissions and egress.
Source: SecurityWeek
Chainlit AI framework bugs enable secret theft via arbitrary file read and SSRF
Two high‑severity vulnerabilities in Chainlit could expose API keys, databases, and internal cloud metadata without user interaction, raising risk of lateral movement from AI apps. Organizations using Chainlit should update immediately, isolate AI apps behind strong egress controls, and treat AI inputs as untrusted to prevent prompt-injection‑driven abuse.
Source: SecurityWeek
Cloudflare fixes ACME validation bug that let attackers bypass WAF to origin servers
A flaw in Cloudflare’s handling of HTTP-01 ACME challenges under /.well-known/acme-challenge/* allowed adversaries to sidestep WAF protections and directly reach origin servers, risking data theft or full compromise. Customers should review access logs around challenge paths, ensure origins only accept traffic from Cloudflare IPs, and validate WAF and firewall policies for challenge endpoints.
Source: The Hacker News
Critical TP‑Link VIGI camera flaw enabled takeover of 32 models
TP‑Link patched CVE‑2026‑0629 (CVSS 8.7), an authentication bypass affecting more than 32 VIGI C and VIGI InSight camera models, with thousands found exposed online. Organizations should update firmware immediately, remove cameras from direct internet exposure, and segment surveillance networks to prevent pivoting.
Source: Security Affairs
Let’s Encrypt launches 6‑day and IP‑based certificates
Let’s Encrypt’s new short‑lived TLS certificates (160 hours) are now generally available via the “shortlived” ACME profile, reducing reliance on revocation and shrinking attacker dwell time on stolen certs. The CA also introduced IP‑based certificates, expanding use cases for services without stable domain names; operators will need robust automation to handle faster rotation.
Source: Help Net Security
UK warns of continuing pro‑Russian hacktivist campaigns against critical services
The UK National Cyber Security Centre reports sustained operations by Russian‑aligned hacktivist groups such as NoName057(16), with ongoing DDoS and nuisance campaigns targeting government and private sector entities. While impacts are often short‑lived, persistent activity can disrupt services; the NCSC urges layered DDoS defenses, resilient incident response, and public‑facing service hardening.
Source: Help Net Security
You May Also Be Interested In...
Oracle’s January 2026 Critical Patch Update fixes 337 issues across 30+ products
VoidLink Linux malware framework built with AI assistance reaches 88,000 lines
LinkedIn DM phishing targets high‑value execs with weaponized downloads