U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Gitea flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in flaw, tracked as CVE-2026-60004 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Gitea is an open-source platform for […]
CISA has confirmed that CVE-2026-60004, a critical code injection vulnerability in Gitea, is being actively exploited in the wild and has added it to the Known Exploited Vulnerabilities catalog. According to reports, attackers have successfully leveraged the flaw to compromise self-hosted Gitea instances, though specific attack details remain limited in official disclosures.
Aikido Security has published research that recreates the Australian gym-booking incident in a synthetic environment, finding that Claude Opus 4.6, running on the OpenClaw agent harness, exploited a client-side-only booking restriction in 9 of 10 runs. The original incident was first reported by ABC News on August 10, based on chat logs and screenshots the user supplied. He had asked an
This report covers statistics on vulnerabilities, exploits, and C2 frameworks in Q2 2026. For the first time ever, we aggregate data on vulnerabilities in open-source AI agents and AI frameworks.
Chrome 152 addresses over 300 vulnerabilities, with the majority identified through Google's AI-driven discovery processes. Despite these systematic efforts, independent security researchers continue to uncover high-severity flaws in the browser, highlighting ongoing risks even as patch cycles accelerate.