Ledger Fixes Ethereum App Flaw as Disclosure Timeline Is Disputed
Ledger has patched a clear-signing vulnerability in its Ethereum app that could allow malicious applications to substitute transactions on device screens, but disputes with security firm TestMachine over the disclosure timeline and lack of public version documentation have left users unable to independently verify their protection status. The flaw, which TestMachine's AI scanner discovered on Ledger Flex and potentially affects Nano X, Nano S Plus, Stax, and Apex devices, has resulted in no independently confirmed fund theft as of late August 2026. The incident underscores the need for transparent security advisories with version identifiers and affected-device lists to help users confirm they have received patches.
Researchers have demonstrated that prompt injection attacks can evade AI safety measures by concealing malicious instructions within encrypted text, potentially compromising guardrails in popular AI assistants. This technique highlights a significant vulnerability in current AI security implementations, allowing attackers to manipulate models like Grok and Gemini into executing unintended actions despite their built-in protections.
Australian officials are warning TeamCity customers of an active exploitation campaign targeting a critical server vulnerability and urging immediate patching. The alert mirrors a similar warning previously issued by US government authorities, indicating the flaw poses a significant threat across international organizations.
CISA has issued an emergency three-day patching deadline for a critical Oracle vulnerability that was disclosed in January and subsequently exploited in the wild, as evidenced by honeypot activity. The urgency reflects the flaw's severity and active exploitation, requiring U.S. government agencies to prioritize immediate remediation of this high-risk vulnerability.
Attackers are actively exploiting two critical authentication bypass vulnerabilities in the Xecurify miniOrange SAML 2.0 Single Sign On plugin for WordPress, allowing them to gain unauthorized access as any user including administrators. The flaws require no authentication and have been disclosed by Patchstack, with at least one tracked as CVE-2026-61979 carrying a CVSS score of 8.1. WordPress administrators using this plugin should prioritize patching immediately to prevent account takeover attacks.