Good morning
We’ve found 4 important news and 4 useful articles for you today. Enjoy reading.
News
CVE-2026-25089: FortiSandbox unauthenticated command injection added to CISA KEV
securityinfrastructurenetwork
Technical analysis of a critical unauthenticated command injection (CVE-2026-25089) in FortiSandbox, now added to the CISA KEV catalog.
AI Agents with Cloud Credentials Are Outrunning Billing Guardrails Built for Human-Speed Mistakes
aiinfrastructuresecurity
Critical analysis of cloud billing risks when using AI agents. Advocates for SCPs, scoped credentials, and real-time observability to prevent 'human-speed' budget explosions.
Period tracker Stardust shares users’ health data with analytics firm, says Mozilla research
securitymobiledata
Mozilla research reveals Stardust period-tracking app shares sensitive health data with third-party analytics firms, highlighting ongoing mobile privacy risks.
UK cops say arrest of two young hackers disrupted the operations of an infamous hacking group
securityindustry
Two hackers sentenced for the 2024 attack on Transport for London, marking a significant operational blow to the Scattered Spider cybercrime group.
Articles
Show HN: Mojibake – a low-level Unicode library written in C
systemsopen sourcebackend
A high-quality, zero-dependency C11/C++17 Unicode 17 library. Offers practical, robust text handling for low-level systems.
A modular, explainable security framework designed to detect and block prompt injection attacks in LLM applications using rule-based and ML-based layers.
openinterpreter/openinterpreter
aiopen sourcedevops
Rust-based coding agent that allows interaction with local files, terminal commands, and browser automation via various model harnesses.
How Our Rust-to-Zig Rewrite Is Going
systemsopen sourcerelease
Insightful engineering retrospective on the Roc compiler's migration from Rust to Zig, detailing architectural trade-offs, build times, and memory management.