4 min read
News Brief A researcher found a path traversal flaw in the boot process of Apple's Private Cloud Compute, letting them redirect AI inference telemetry to a server they controlled. Apple fixed it and paid out its top bounty tier.
A researcher found a path traversal flaw in the boot process of Apple's Private Cloud Compute, letting them redirect AI inference telemetry to a server they controlled. Apple fixed it and paid out its top bounty tier.
Three high-severity vulnerabilities in the OpenClaw AI assistant allow a remotely-sent WhatsApp message to trigger host code execution, SSH key theft, and Docker socket escape. All three are patched in version 2026.6.6.
A path traversal vulnerability in Langflow's file API allows unauthenticated attackers to overwrite arbitrary files and chain to RCE. Active exploitation confirmed in June 2026. Fix is in version 1.9.0.