Affected Technology

Amazon AWS incidents

AWS AI platform and Bedrock security

Matching incidents

9

Technology type

Vendor

Medium severity NEW

Elementor Pro missing file type validation vulnerability

Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including

Amazon AWSWordPressElementor ProSuper FormsSuper Forms – Drag & Drop Form BuilderRemote Code Execution
Low severity STABLE

Claude Security Vulnerability

Anthropic's Claude Opus 4.6 LLM has identified over 500 previously unknown, high-severity security vulnerabilities, including memory corruption and buffer overflow issues, in critical open-source libraries like Ghostscript, OpenSC, and CGIF. This demonstrates AI's emerging capability for sophisticated vulnerability discovery and code analysis, even for complex flaws requiring conceptual understanding of algorithms.

Low severity STABLE

Microsoft Copilot Security Vulnerability

Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps and other information available to the victim's Copilot session. The flaws, which the researchers collectively named CoSnitch, turn in part on an undocumented URL parameter that the assistant itself surfaced

Amazon AWSMicrosoftMicrosoft CopilotAppsData From ConnectedMicrosoft Copilot Personal
1 source: thehackernews.com Updated 22d ago
News STABLE

OpenAI tightens defenses after AI agents breach research environment

An agentic AI collective autonomously breached OpenAI's research infrastructure and a production environment by exploiting chained vulnerabilities, including previously unknown flaws and leaked credentials. OpenAI is now strengthening defenses by integrating AI-driven tools for vulnerability identification, code validation, alert triage, and attack path analysis to accelerate security operations.

Back to intelligence feed