HeadFlash

Security

Security Flash: Zoom, 7-Zip, Google, Shark, Fairlife Ransomware

A critical Zoom flaw, 7-Zip RCE, Google OAuth takeover, Shark vacuum RCE, and Fairlife ransomware halt production.

Listen

Zoom Warns of Critical Account Takeover Vulnerability

Zoom has disclosed a critical vulnerability (CVE-2026-53412) in its desktop client and SDK for Windows, with a CVSS severity score of 9.8. The flaw is an improper input validation issue that allows an unauthenticated attacker to achieve account takeover over the network. Affected products include Zoom Workplace for Windows before version 7.0.0, the Windows VDI Client before versions 7.0.10, 6.6.15, and 6.5.18, and the Meeting SDK for Windows before version 7.0.0. Zoom recommends applying the latest updates immediately. At the time of disclosure, there were no indications that any of the fixed vulnerabilities were being exploited in attacks.

Zoom warns of critical account takeover vulnerability →

7-Zip XZ Parser RCE Flaw Still Unpatched

A heap-based buffer overflow in 7-Zip’s XZ parser, tracked as ZDI-26-444 and CVE-2026-14266, enables remote code execution when a user opens a specially crafted archive. The vulnerability resides in processing chunked XZ data, allowing a write past the boundaries of a heap-allocated buffer. No elevated privileges are required, and the malicious code runs with the user’s permissions. Trend Micro’s Zero Day Initiative disclosed the advisory on July 15, 2026, after notifying the vendor on June 5, 2026. The CVSS score is 7.0. At the time of the advisory, no official 7-Zip fix was available; the patch URL pointed back to the advisory. No evidence of in-the-wild exploitation has been documented.

7-Zip XZ Parser RCE Vulnerability: Opening an Archive Is Enough | DeafNews →

Google OAuth Device Code Flow Hijack Allows Universal Account Takeover

A vulnerability in Google’s implementation of the OAuth 2.0 device authorization grant (RFC 8628) allows universal account takeover on any site using ‘Sign in with Google’. The attack chains two bugs: a fully transferable session anchored in a device-code sign-in, and the lack of server-side binding of client_id and scope to the device_code. By combining these with the prompt=none parameter, an attacker who gets a victim to open a link can silently obtain an access token for any Google-registered client that the victim has previously granted basic scopes to, without consent screens or 2FA. Full Gmail inbox access is achievable by substituting a client_id allowed to request the https://mail.google.com/ scope, such as Apple’s iOS Mail client. The vulnerability was reported to Google’s VRP on February 25, 2026. Initially closed twice as ‘Won’t Fix’, it was reopened after a one-click proof of concept using Facebook’s client_id. Google fixed the issue on March 28, 2026, and rewarded the researcher $13,337.

Confused Deputy: Google IdP Universal Account Takeover via Device Code Flow Hijacking // weirdmachine64 →

Millions of Shark Robot Vacuums Vulnerable to Unpatched RCE

A critical vulnerability in all internet-connected Shark robot vacuums allows remote code execution. Discovered in March 2026, the researcher gained physical access to an RV2320EDUS via UART debug pins, booted into a root shell, and inserted an SSH startup script. The device’s MQTT client (appd) connects to AWS IoT Core, and the device’s certificate permitted subscribing to all topics via the wildcard ‘$aws/things/#’. The appd binary contains a function that passes an ‘Exec_Command’ field from MQTT messages to popen, executing arbitrary shell commands. A 24-hour scan of the broker identified 1,517,605 unique devices; 673,816 (44%) published an ‘Exec_Response’ message, confirming they support command execution and are vulnerable. The researcher demonstrated RCE on an AV1102ARUS, extracting live video, controlling motors, and retrieving the Wi-Fi password and house map. SharkNinja was notified on March 1, acknowledged on March 12, but after the 90-day disclosure period ended June 9, no patch was released. The researcher requested a CVE from MITRE with no response. SharkNinja downplayed the severity. The vulnerability remains unpatched.

Just a moment… →

Coca-Cola’s Fairlife Ransomware Attack Halts US Dairy Production

The Coca-Cola Company disclosed in an SEC Form 8-K filing that a ransomware attack on its Fairlife dairy subsidiary disrupted operations. Fairlife detected unauthorized access to some systems, including production-related systems. Coca-Cola activated incident response and business continuity protocols, and has engaged outside advisors, cybersecurity experts, and law enforcement. Production at Fairlife’s U.S. facilities has been temporarily suspended while systems are restored. Canadian operations are not affected. Product quality and safety have not been impacted. Coca-Cola has not disclosed whether data was stolen, whether the company is being extorted, or which ransomware operation is responsible. No ransomware gang has claimed responsibility. The investigation is ongoing; the company has not yet determined if the attack is reasonably likely to materially affect its business.

Coca-Cola says Fairlife ransomware attack halts US dairy production →