Caught in the Hook: RCE and API Token Exfiltration Through Claude Code Project Files | CVE-2025-59536 | CVE-2026-21852

Caught in the Hook: RCE and API Token Exfiltration Through Claude Code Project Files | CVE-2025-59536 | CVE-2026-21852

• By Aviv Donenfeld and Oded Vanunu Check Point Research has discovered critical vulnerabilities in Anthropic’s Claude Code that allow attackers to achieve remote code execution an

Threat Intelligence · February 25, 2026 (updated February 25, 2026) · 2 min · 234 words
Zyxel warns of critical RCE flaw affecting over a dozen routers

Zyxel warns of critical RCE flaw affecting over a dozen routers

• Zyxel warns of critical RCE flaw affecting over a dozen routers February 25, 2026 07:53 AM 0 Taiwan networking provider Zyxel has released security updates to address a critical

Cybersecurity · February 25, 2026 (updated February 25, 2026) · 2 min · 283 words
ZDI-26-107: Autodesk AutoCAD MODEL File Out-Of-Bounds Write Remote Code Execution Vulnerability

ZDI-26-107: Autodesk AutoCAD MODEL File Out-Of-Bounds Write Remote Code Execution Vulnerability

• Remote code execution via out-of-bounds write in AutoCAD MODEL file parsing. • Requires user to open malicious file or visit malicious page. • Exploit writes past allocated buffe

Threat Intelligence · February 18, 2026 (updated February 24, 2026) · 3 min · 565 words
One threat actor responsible for 83% of recent Ivanti RCE attacks

One threat actor responsible for 83% of recent Ivanti RCE attacks

• One threat actor responsible for 83% of recent Ivanti RCE attacks February 14, 2026 11:02 AM 0 Update: The article initially listed the wrong CVEs. • This has now been corrected

Cybersecurity · February 14, 2026 (updated February 18, 2026) · 2 min · 264 words
Prompt injection to RCE in AI agents

Prompt injection to RCE in AI agents

• Prompt injection to RCE in AI agents Modern AI agents increasingly execute system commands to automate filesystem operations, code analysis, and development workflows. • While so

Threat Intelligence · October 22, 2025 (updated February 24, 2026) · 2 min · 283 words
Crafting a Full Exploit RCE from a Crash in Autodesk Revit RFA File Parsing

Crafting a Full Exploit RCE from a Crash in Autodesk Revit RFA File Parsing

• In April of 2025, my colleague Mat Powell was hunting for vulnerabilities in Autodesk Revit 2025. • While fuzzing RFA files, he found the following crash (CVE-2025-5037 / ZDI-CAN