Buddy Security

Buddy Security We Deliver Best Cybersecurity Services Around the Globe
━━━━━━♥♠♥━━━━━━
Our Mission is to Create 1 Million Cyber Warriors in Pakistan

732-byte Python script grants root on virtually all Linux distributions since 2017, actively exploited.This AF_ALG AEAD ...
11/05/2026

732-byte Python script grants root on virtually all Linux distributions since 2017, actively exploited.

This AF_ALG AEAD page-cache corruption flaw lets unprivileged users chain writable scatterlists during decryption to hijack setuid binaries. CISA issued urgent alert as hacking campaigns actively exploit it against servers and data centers.

Critical firewall zero-day with CVSS 9.3 allows unauthenticated root access, patches delayed until May 13.Attackers are ...
11/05/2026

Critical firewall zero-day with CVSS 9.3 allows unauthenticated root access, patches delayed until May 13.

Attackers are actively exploiting this memory corruption vulnerability to gain root privileges on PA-Series and VM-Series firewalls. CISA added it to Known Exploited Vulnerabilities catalog with May 9 deadline for federal agencies. Evidence suggests Chinese state hacking involvement.

Attackers silently redirect MCP traffic to intercept tokens and maintain persistent SaaS platform access.Mitiga research...
11/05/2026

Attackers silently redirect MCP traffic to intercept tokens and maintain persistent SaaS platform access.

Mitiga researchers discovered attackers can hijack Claude Code's Model Context Protocol traffic to steal OAuth tokens, enabling persistent access to connected SaaS platforms without triggering alerts. Critical for AI tool users and developers.

Five water facilities breached with ability to change equipment settings, creating direct public safety risk.Polish Secu...
11/05/2026

Five water facilities breached with ability to change equipment settings, creating direct public safety risk.

Polish Security Agency reported ICS breaches at five water treatment plants where attackers gained ability to modify operational parameters. This creates existential risk to public water supply—a critical infrastructure nightmare for OT security professionals.

Polish Security Agency reported ICS breaches at five water treatment plants where attackers gained ability to modify ope...
11/05/2026

Polish Security Agency reported ICS breaches at five water treatment plants where attackers gained ability to modify operational parameters. This creates existential risk to public water supply—a critical infrastructure nightmare for OT security professionals.

A massive industry collaboration known as Project Glasswing—involving giants like Apple, Google, and Microsoft—has sent ...
10/05/2026

A massive industry collaboration known as Project Glasswing—involving giants like Apple, Google, and Microsoft—has sent shockwaves through the dev world. Using Anthropic’s "Mythos" vulnerability discovery model, Mozilla found 271 previously unknown vulnerabilities in Firefox, some of which had existed in the code for over a decade without human detection. While this is a win for "AI for defense," the shock comes from the sheer volume; the speed at which AI can now weaponize or fix software is far outstripping human "Patch Tuesday" cycles, forcing a total rethink of how we secure legacy code.

The education sector was rocked this week when the Canvas learning management system was hit by a massive extortion camp...
10/05/2026

The education sector was rocked this week when the Canvas learning management system was hit by a massive extortion campaign. The hacking group ShinyHunters reportedly used AI-generated "lures"—including hyper-realistic video meeting invites and cloned administrator voices—to harvest credentials at an unprecedented scale. The breach didn't just leak emails; it exposed personal data for over 275 million users across 9,000 schools and universities globally. This marks the largest instance to date of AI-powered social engineering successfully dismantling a critical public infrastructure, proving that "human weakness" is now being exploited with industrial-grade precision.

In a startling discovery this week, researchers identified vulnerabilities (like CVE-2026-25592) in popular AI agent fra...
10/05/2026

In a startling discovery this week, researchers identified vulnerabilities (like CVE-2026-25592) in popular AI agent frameworks that turn "prompt injection" into full-blown Remote Code Ex*****on (RCE).
Essentially, because modern AI agents are designed to execute code and use tools autonomously, attackers can now "whisper" a specific instruction into a prompt that bypasses sandboxes.
This allows the AI to execute malicious shell commands on the very server hosting it. It’s a paradigm shift: the AI isn't just hallucinating; it’s being tricked into becoming a highly privileged, automated hacker against its own creator's infrastructure.

Address

Jupiter
Karachi

Opening Hours

Monday 09:00 - 18:00
Tuesday 09:00 - 18:00
Wednesday 09:00 - 18:00
Thursday 09:00 - 18:00
Friday 09:00 - 18:00
Saturday 09:00 - 18:00

Alerts

Be the first to know and let us send you an email when Buddy Security posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share