Welcome to LoopSec
We are a group that is focused on teaching others how to program and exposing any corruption we might run into. If you would like any assistence or would like to join us then please apply. Please sign in/sign up to view the full site.
The Hacker News
-
Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
Tuesday, 28. July 2026 10:11 o'clock
JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution. The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity On-Premises versions. It has been addressed in versions 2025.11.7 and 2026.1.3. TeamCity Cloud instances have already -
Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit
Tuesday, 28. July 2026 10:04 o'clock
STAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted. The flaw, tracked as CVE-2026-53264 (CVSS score: 7.8), is a use-after-free race in the kernel's network traffic-control subsystem.Researcher Lee Jia Jie said artificial intelligence (AI) helped him find the bug and speed up exploit development. This is local -
Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Cost
Tuesday, 28. July 2026 08:07 o'clock
Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness. The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored 95.95% on CyberGym. It also claims the configuration costs 50% less than its current best MDASH combination of GPT-5.4, GPT-5.4 mini, and GPT-5.3 Codex. Access is limited to approved -
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
Tuesday, 28. July 2026 06:43 o'clock
A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating system command injection that could pave the way for arbitrary code execution. "VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue -
NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework
Monday, 27. July 2026 20:10 o'clock
NVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and artificial intelligence (AI) agents. The 37-member group spans cloud, security, enterprise software, and AI companies, including Microsoft, Cisco, Cloudflare, CrowdStrike, Hugging Face, IBM, Palo Alto Networks, Red Hat, and the Linux -
Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
Monday, 27. July 2026 19:16 o'clock
Dysphoria, an Internet of Things (IoT) botnet line tracked by CNCERT and XLab, has adopted blockchain-based name services and infected-device relays after a March law-enforcement operation against JackSkid infrastructure. The researchers say the design makes the botnet harder to disrupt. CNCERT, China's national computer emergency response team, and XLab, the threat-intelligence lab of Chinese
My Account