A CVSS 10.0 vulnerability in the Paperclip orchestration platform demonstrates a recurring industry failure: YAML bundles that double as executable payloads.
Zoom has patched a vulnerability that could allow attackers to execute code on other meeting participants’ systems.