Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
This article summarizes a week of cybersecurity news from Malwarebytes Labs, covering scams like fake Fortnite rewards and Flash Player installs, privacy issues with Hims & Hers and shared Claude chats, and threats including AI worms and fake Walmart stores. It also notes product updates like Malwarebytes for Windows on the Microsoft Store and rebuilt mobile security.
Fake Fortnite rewards are stealing players' accounts, AI robocalls plague caller ID, OpenAI explains Hugging Face breach — this week's roundup from Malwarebytes Labs.
This article reports that attackers exploited an authentication bypass vulnerability (CVE-2026-18577) in N-able's N-central platform to gain remote administrative access and compromise customer systems. N-able's initial fix was incomplete, and the attackers used the access to install persistent Cloudflare tunnels on managed endpoints.
This article discloses three high-severity security flaws in Hugging Face's Diffusers library, named FaceHugger, which allow crafted model repositories to execute arbitrary code by bypassing the trust_remote_code safeguard. The vulnerabilities pose significant risk to AI supply chains due to Diffusers' widespread use in enterprise environments.
This article discloses three high-severity security flaws in Hugging Face's Diffusers library, named FaceHugger, which allow crafted model repositories to execute arbitrary code by bypassing the trust_remote_code safeguard. The vulnerabilities pose significant risk to AI supply chains due to Diffusers' widespread use in enterprise environments.
Three high-severity vulnerabilities (CVE-2026-44827, CVE-2026-45804, CVE-2026-44513) in Hugging Face's Diffusers library could allow malicious model repositories to execute arbitrary code on systems loading them, bypassing the trust_remote_code security safeguard. The flaws, collectively named FaceHugger by Zafran Labs researchers, exploit Time-of-Check to Time-of-Use (TOCTOU) race conditions and code injection techniques during the model loading process.