Skip to main content

Tag: apache tomcat

5 articles

Rows of servers in a brightly-lit data center with one server in focus and others blurred.

Oracle Database Exploited to Hide Post-Exploitation Toolkit

Stay one step ahead of hackers by ensuring your online forms are secure and not vulnerable to injection - a crucial defense against SQL injection attacks that can lead to devastating breaches.

Analyst 207
Server room interior with rows of equipment and a blurred database server in the foreground.

Hackers Embed khunt Toolkit in Oracle Database via SQL Injection

Security researchers have uncovered a rare and stealthy attack where hackers embedded the Khunt toolkit in an Oracle database using a SQL injection technique, highlighting a seldom-documented threat in the wild. The attack started with a simple vulnerability in an autocomplete search feature that allowed malicious input to slip through.

Analyst 207
Modern tech facility with server racks in background and laptop in foreground.

CISA Warns of Active Exploits in Langflow, N-central, Apache Tomcat Flaws

A critical flaw in IBM's Langflow, rated 9.8 out of 10, allows hackers to remotely execute code on vulnerable systems - and multiple easy-to-follow exploits have already surfaced online. This severe vulnerability enables attackers to bypass login and wreak havoc, making it a pressing concern for Langflow users.

Analyst 207
Rack of computer equipment with monitors in a neutral industrial setting.

CISA Warns of Active Exploits Targeting Langflow, Tomcat, and N-central Flaws

Stay safe online: CISA has flagged three major cybersecurity vulnerabilities, including a critical remote code execution flaw in Langflow, that are being actively exploited by hackers. A patch is available for the Langflow flaw, which was fixed in version 1.10.1.

Analyst 207
Dimly lit server room with outdated equipment and exposed cables.

Legacy Infrastructure Exposes AI Agents to Hijacking Risks

Legacy infrastructure can put your AI agents at risk of hijacking, as seen with CVE-2025-24813, a remote code execution flaw that lets attackers turn a routine server compromise into a full takeover. An unpatched Internet-facing Apache Tomcat server is all it takes to expose your enterprise to this threat.

Analyst 207