US TROOP APPS LACED WITH CHINESE, RUSSIAN CODE
■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE
Security researchers discovered that more than 12% of applications marketed to US military personnel contain code from China and Russia. The findings raise concerns about potential surveillance and data compromise risks.
■ MORE FROM THE SECURITY DESK
N-able has released an emergency hotfix for a maximum-severity remote code execution vulnerability in its N-central RMM platform. The flaw is being actively exploited in ongoing attacks.
QBittorrent, the popular open-source torrent client, has been found capable of breaking out of sandbox environments to execute unauthorized operations. Security researchers identified the vulnerability, raising concerns about the application's access to system resources.
Threat actors are deploying invisible Unicode characters in phishing campaigns to evade email security systems. The ASCII smuggling technique allows attackers to conceal malicious content from detection tools.
A Unicode block invisible to human readers has transitioned from an academic curiosity used to test AI systems into an active tool for spammers. The technique exploits characters that machines process but humans cannot see.