Google Fixes CVSS 10 Gemini CLI CI RCE and Cursor Flaws Enable Code Execution

Overview Google has addressed a maximum severity security flaw in Gemini CLI (the “@google/gemini-cli” npm package and the “google-github-actions/run-gemini-cli” GitHub Actions workflow) that could have allowed attackers to execute arbitrary commands on host systems. The vulnerability, which carries a CVSS score of 10.0, represents one of the most critical AI…

The Latest

Breaking News and Alerts

Adobe Issues Emergency Patch for ‘SessionReaper,’ One of the Most Severe Magento Flaws Ever

The critical bug could let attackers hijack customer accounts without authentication through Adobe Commerce and Magento REST APIs.

Spotlight

Cybersecurity Profiles and Stories

GhostAction Supply Chain Attack Leaks 3,325 Secrets from GitHub Projects

The attack exploited compromised maintainer accounts to silently inject malicious GitHub Actions workflows into hundreds of repositories.

Lovesac Discloses Data Breach Linked to RansomHub Ransomware Attack

Hackers infiltrated Lovesac's internal systems for over two weeks, stealing personal data and prompting a RansomHub ransomware extortion attempt.

Scammers Exploit Apple iCloud Calendar to Deliver Callback Phishing Emails

A new phishing scheme uses legitimate Apple email infrastructure to bypass spam filters and trick victims into calling fake support numbers.

Phishing in Plain Sight: Malicious SVG Files Impersonate Colombia’s Judiciary to Spread Malware

VirusTotal’s AI-enhanced detection revealed an SVG-based phishing campaign that slipped past traditional antivirus tools by disguising malicious portals as official judicial sites.

Features

Research and Thought Leadership