Vista elenco

Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting

16 Giugno 2026 ore 21:05
A flaw in the Google Cloud Vertex AI SDK for Python let an attacker with no access to a victim's project hijack the victim's machine learning model upload and run code inside Google's serving infrastructure. Palo Alto Networks Unit 42, which found and reported the bug through Google's bug bounty program, calls the technique "Pickle in the Middle" and said it saw no exploitation in the wild.

New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds

16 Giugno 2026 ore 15:10
Security researchers at Zimperium's zLabs have documented a new Android banking trojan, Rokarolla, that targets 217 banking and cryptocurrency apps and packs 137 remote commands. Together, they give an operator near-total control of an infected phone: it lifts lock-screen PINs, reads and sends SMS, rewrites the clipboard to redirect crypto payments, and switches off Google Play

❌