One-Tap Android Root Can Forge C2PA Camera Signatures
A one-tap Android root bug lets attackers get Pixel's secure chip to sign forged photos as genuine C2PA captures; Google says it can't be fixed.
4 verified stories covering Security flaws, product updates and industry developments.
A one-tap Android root bug lets attackers get Pixel's secure chip to sign forged photos as genuine C2PA captures; Google says it can't be fixed.
A TeamPCP supply-chain campaign used Nx Console and related packages to steal developer credentials from GitHub, OpenAI and Mistral environments.
CVE-2026-25874 lets anyone who can reach a Hugging Face LeRobot PolicyServer execute code through unsafe pickle deserialization.
A supply chain security report reveals 11 CVEs tied to a design-level flaw in Anthropic's MCP STDIO transport, affecting over 150 million downloads and 200,000 servers. Anthropic declined to fix it, calling the behavior "expected."