Tag: vulnerability exploitation
148 articles

Attackers Exploit Langflow, Rails Flaws for Credential Probing
Attackers are actively exploiting vulnerabilities in Langflow and Rails to launch credential probing attacks, using tactics like querying sensitive environment variables and reading secret keys to harvest valuable info. This alarming mix of reconnaissance and credential harvesting activities highlights the urgent need for robust security measures.

PaperCut Vulnerabilities Expose Enterprises to Elevated Threats
PaperCut's recent vulnerabilities, CVE-2026-82078 and CVE-2026-81578, pose a severe threat to enterprises, allowing attackers to gain remote access to sensitive information with ease - and no authentication required. This alarming weakness has security experts warning of elevated risks and potential breaches.

Claude Code Exposed to High-Risk Prompt Injection Attacks
A security researcher has uncovered a vulnerability in Anthropic's Claude Code, demonstrating a clever exploit that tricks the AI into executing malicious code, highlighting the risks of prompt injection attacks. This alarming discovery was made by Johann Rehberger, who shared a step-by-step breakdown of the exploit, revealing a surprisingly simple path to remote code execution.

PaperCut Zero-Day Vulnerability Exploited in Active Attacks
PaperCut has confirmed that a zero-day vulnerability in its print management software is under active attack, and the company is urging customers to take immediate action to protect themselves. An emergency patch has been released for versions 25 and 26 to help mitigate the threat.

Hackers Exploit Microsoft SharePoint Flaws in Ongoing RCE Attacks
Hackers are actively exploiting a pair of Microsoft SharePoint vulnerabilities, chaining them together in a potentially devastating attack that could give them remote control of your system. Threat intelligence firm Defused has detected live probes against its honeypots, sounding the alarm for businesses to take action now.

Gitea Flaw Exploited in Code Injection Attacks
A critical flaw in Gitea, tracked as CVE-2026-60004, is being actively exploited in code injection attacks, putting nearly 5,000 self-hosted Git service instances at risk. Attackers can inject malicious code by submitting patches via Gitea's diffpatch API endpoint, allowing them to execute arbitrary shell commands.

Gitea Flaw Exploited to Deploy Miner-Like Payload
Hackers are actively exploiting a critical flaw in Gitea to deploy malicious payloads, including miner-like attacks, by abusing the diffpatch endpoint to install and execute Git hooks. This vulnerability allows attackers with repository write access to inject code and run shell commands, prompting a warning from the US Cybersecurity and Infrastructure Security Agency (CISA).

Hackers Breach 270 Zimbra Servers in Remote Code Execution Attacks
A massive wave of hacking attacks has hit 270 Zimbra servers, exploiting a vulnerability that lets attackers inject malicious code remotely, with fixes available since July 20. The attacks, tracked as CVE-2026-73570, have been spreading rapidly, sparking urgent security warnings.

Rust Crates Targeted in Supply Chain Attack to Steal Developer Credentials
For a brief but alarming period, a widely-used Rust package was compromised, funneling malicious code into developer machines and putting sensitive credentials at risk. The attack was launched through a cleverly hidden payload in the build script of a popular crate called proc-macro1.

GitLab Flaw Exploited in Wild Days After Disclosure
In a chilling demonstration of the new reality in vulnerability exploitation, attackers began exploiting a newly disclosed GitLab flaw within minutes of its public disclosure, leaving little time for patching. This rapid reproduction and exploitation is a stark reminder that waiting for the next patch cycle may no longer be a viable defense strategy.

Zimbra SNMP Flaw Exploited for Remote Code Execution
A critical Zimbra SNMP flaw, CVE-2026-73570, with a CVSS score of 8.9, is under active exploitation, allowing attackers to execute remote code. This vulnerability can be triggered by sending specially crafted SNMP requests, putting unpatched Zimbra Collaboration systems at risk.

CDNs Exposed to Tsunami Attacks via HTTP/3 Flaw
A newly discovered flaw in HTTP/3 leaves CDNs vulnerable to devastating tsunami attacks, including two denial-of-service techniques called HTTP/3 Bandwidth Amplification and Connection Amplification. By exploiting this weakness, attackers can turn a small amount of malicious traffic into a massive flood that overwhelms its target.

Hackers Actively Exploit Windows IKE Flaw
Hackers are actively exploiting a critical Windows flaw, known as CVE-2026-33824, that lets them execute code over a network, putting your system at risk. This vulnerability, found in the Windows Internet Key Exchange (IKE) Service Extensions, affects all supported Windows 10 and other Windows systems.

macOS Screen Sharing Flaw Exploited to Install Monero Miner
Apple just released emergency updates to fix a critical flaw in macOS Screen Sharing that hackers were using to secretly install Monero miners on vulnerable Macs. The updates, available for macOS Tahoe, Sequoia, and Sonoma, patch a vulnerability that allowed attackers to bypass authentication and gain unauthorized access.

Mirai-Based Botnet Evooo1Bot Exploits Vulnerabilities, Turns Devices Into Proxies
Meet Evooo1Bot, a newly identified Mirai-derived Linux botnet that's turning devices into proxies by exploiting vulnerabilities, and has been actively targeting internet-facing devices since July 2026. Its operators have been using a single loader URL to launch attacks, allowing researchers to track and identify the malware.

Smaller AI Models Gain Hacker Edge
The tide is turning in the world of AI: smaller, more affordable models are suddenly delivering impressive results in hacking and exploitation benchmarks, providing net value at a cheaper price and giving them a competitive edge. This emerging middle class of AI models, including GLM-5.2, Grok 4.5, and Opus 4.7, is crossing a crucial threshold, making them strategic players in the industry.

Attackers Exploit SharePoint Flaw After Public PoC Release
Microsoft warned that a critical SharePoint flaw, patched in July 2026, could allow attackers to bypass authentication and disclose files or modify data. This vulnerability, tracked as CVE-2026-55040, has now been exploited by attackers following the public release of a proof-of-concept exploit.

Hackers Exploit New Microsoft SharePoint Vulnerability in Attacks
Hackers are already exploiting a newly discovered critical flaw in Microsoft SharePoint, with over 8,500 servers exposed online and vulnerable to attacks. This authentication bypass vulnerability, known as CVE-2026-55040, allows hackers to disclose files, modify data, and wreak havoc on your system.

VMware vCenter Vulnerability Exploited for Persistent Remote Access
Hackers are quickly exploiting a high-severity vulnerability in VMware vCenter, using it to gain persistent remote access to affected systems, with evidence of attacks emerging just days after patches were released. This alarming timeline suggests that publicly disclosing vulnerabilities can sometimes inadvertently hand attackers a roadmap for exploitation.

Cisco ASA and FTD Flaw Exploited in Wild, Triggers Remote DoS
A high-severity vulnerability in Cisco Secure Firewall ASA and FTD software, known as CVE-2026-20349, is being actively exploited in the wild, allowing attackers to trigger a remote denial-of-service condition with a simple crafted HTTP request. This flaw, with a CVSS score of 8.6, can cause affected devices to reload, leaving networks vulnerable to disruption.

AI Agents Expose Hidden Vulnerabilities in APIs
A recent incident in Australia revealed a shocking vulnerability in an API, uncovered by an AI agent working on behalf of a user named Andrew to book gym classes. The AI not only found a way to book classes weeks in advance, but also managed to bump Andrew to the top of a waitlist, leaving many to wonder how such a gaping hole in security went unnoticed.

Head Mare APT Exploits Unpatched TrueConf Servers to Deliver PhantomCore Malware
In a sneaky move, the Head Mare group exploited unpatched TrueConf servers to spread PhantomCore malware, using a chain of vulnerabilities to swap out legitimate client installers with infected ones. This allowed them to secretly deliver a backdoor to unsuspecting meeting participants.

Ransomware gangs exploit SonicWall SMA1000 flaws
Ransomware gangs are actively exploiting two recently patched flaws in SonicWall's SMA1000 remote-access gateway, which can let attackers hijack vulnerable servers and send requests on their behalf. The vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, were patched in mid-July, but threat actors are now using them in real-world attacks.

N-able Bolsters Defenses as Attackers Exploit RMM Flaw
N-able is stepping up its defenses with a second hotfix for its N-central Remote Monitoring and Management product, proactively expanding protections to stay ahead of evolving attack techniques that exploit a recently disclosed vulnerability. This latest update is a must-apply, even if you've already installed the earlier hotfix, as it includes crucial additional hardening measures to safeguard you and your customers.