This week's security roundup covers the Anubis web AI firewall, AI exploit generation, a vulnerability in CodeRabbit, the potential illegality of adblocking in Germany, a Microsoft Copilot audit log issue, and a disputed Elastic EDR vulnerability.
   
    
 
 
  
   
   US crosswalk buttons were hijacked to play AI-generated voices of prominent figures like Bezos, Musk, and Zuckerberg. The hack exploited a default password (1234) on Polara's Field Service app, which allowed unauthorized configuration of the crosswalk signals.
   
    
 
 
  
   
   The US government initially ended funding for the Common Vulnerabilities and Exposures (CVE) database. However, funding has been restored through the CVE Foundation and CISA. This article covers CVE from the perspective of effects on Android alone.
   
    
 
 
  
   
   Two security vulnerabilities have been disclosed in the Mailcow open-source mail server suite that could be exploited by malicious actors to achieve arbitrary code execution on susceptible instances.