Skip to main content

Tag: vulnerability exploitation

148 articles

Rows of rack-mounted servers and cables in a brightly-lit data center facility.

Attackers Exploit Langflow, Rails Flaws for Credential Probing

Attackers are actively exploiting vulnerabilities in Langflow and Rails to launch credential probing attacks, using tactics like querying sensitive environment variables and reading secret keys to harvest valuable info. This alarming mix of reconnaissance and credential harvesting activities highlights the urgent need for robust security measures.

Analyst 207
Multifunction printer on office shelf, surrounded by computers and chairs.

PaperCut Vulnerabilities Expose Enterprises to Elevated Threats

PaperCut's recent vulnerabilities, CVE-2026-82078 and CVE-2026-81578, pose a severe threat to enterprises, allowing attackers to gain remote access to sensitive information with ease - and no authentication required. This alarming weakness has security experts warning of elevated risks and potential breaches.

Analyst 207
Modern tech lab with laptop and scattered papers showing illegible notes.

Claude Code Exposed to High-Risk Prompt Injection Attacks

A security researcher has uncovered a vulnerability in Anthropic's Claude Code, demonstrating a clever exploit that tricks the AI into executing malicious code, highlighting the risks of prompt injection attacks. This alarming discovery was made by Johann Rehberger, who shared a step-by-step breakdown of the exploit, revealing a surprisingly simple path to remote code execution.

Analyst 207
Office computer monitor displays print management software interface surrounded by office equipment.

PaperCut Zero-Day Vulnerability Exploited in Active Attacks

PaperCut has confirmed that a zero-day vulnerability in its print management software is under active attack, and the company is urging customers to take immediate action to protect themselves. An emergency patch has been released for versions 25 and 26 to help mitigate the threat.

Analyst 207
Laptop screen displays a Microsoft SharePoint page in a neutral office setting.

Hackers Exploit Microsoft SharePoint Flaws in Ongoing RCE Attacks

Hackers are actively exploiting a pair of Microsoft SharePoint vulnerabilities, chaining them together in a potentially devastating attack that could give them remote control of your system. Threat intelligence firm Defused has detected live probes against its honeypots, sounding the alarm for businesses to take action now.

Analyst 207
Rows of computer servers and development workstations in a brightly-lit server room or software development team's workspace.

Gitea Flaw Exploited in Code Injection Attacks

A critical flaw in Gitea, tracked as CVE-2026-60004, is being actively exploited in code injection attacks, putting nearly 5,000 self-hosted Git service instances at risk. Attackers can inject malicious code by submitting patches via Gitea's diffpatch API endpoint, allowing them to execute arbitrary shell commands.

Analyst 207
Rows of computer servers and networking equipment in a brightly-lit server room, with one server slightly ajar, suggesting…

Gitea Flaw Exploited to Deploy Miner-Like Payload

Hackers are actively exploiting a critical flaw in Gitea to deploy malicious payloads, including miner-like attacks, by abusing the diffpatch endpoint to install and execute Git hooks. This vulnerability allows attackers with repository write access to inject code and run shell commands, prompting a warning from the US Cybersecurity and Infrastructure Security Agency (CISA).

Analyst 207
Network equipment surrounds a central server system in a typical server room setting.

Hackers Breach 270 Zimbra Servers in Remote Code Execution Attacks

A massive wave of hacking attacks has hit 270 Zimbra servers, exploiting a vulnerability that lets attackers inject malicious code remotely, with fixes available since July 20. The attacks, tracked as CVE-2026-73570, have been spreading rapidly, sparking urgent security warnings.

Analyst 207
Cluttered software development workspace with laptop, monitor, and papers, amidst a blurred city or office background.

Rust Crates Targeted in Supply Chain Attack to Steal Developer Credentials

For a brief but alarming period, a widely-used Rust package was compromised, funneling malicious code into developer machines and putting sensitive credentials at risk. The attack was launched through a cleverly hidden payload in the build script of a popular crate called proc-macro1.

Analyst 207
Server rack in a network operations room with rows of computer servers and equipment.

GitLab Flaw Exploited in Wild Days After Disclosure

In a chilling demonstration of the new reality in vulnerability exploitation, attackers began exploiting a newly disclosed GitLab flaw within minutes of its public disclosure, leaving little time for patching. This rapid reproduction and exploitation is a stark reminder that waiting for the next patch cycle may no longer be a viable defense strategy.

Analyst 207
Rows of servers and network equipment in a well-lit data center or network operations room.

Zimbra SNMP Flaw Exploited for Remote Code Execution

A critical Zimbra SNMP flaw, CVE-2026-73570, with a CVSS score of 8.9, is under active exploitation, allowing attackers to execute remote code. This vulnerability can be triggered by sending specially crafted SNMP requests, putting unpatched Zimbra Collaboration systems at risk.

Analyst 207
Rows of network equipment and servers in a data center with a spotlight on a vulnerable CDN setup.

CDNs Exposed to Tsunami Attacks via HTTP/3 Flaw

A newly discovered flaw in HTTP/3 leaves CDNs vulnerable to devastating tsunami attacks, including two denial-of-service techniques called HTTP/3 Bandwidth Amplification and Connection Amplification. By exploiting this weakness, attackers can turn a small amount of malicious traffic into a massive flood that overwhelms its target.

Analyst 207
Interior of network operations center with rows of computer workstations and networking equipment.

Hackers Actively Exploit Windows IKE Flaw

Hackers are actively exploiting a critical Windows flaw, known as CVE-2026-33824, that lets them execute code over a network, putting your system at risk. This vulnerability, found in the Windows Internet Key Exchange (IKE) Service Extensions, affects all supported Windows 10 and other Windows systems.

Analyst 207
Mac computer on a desk with screen sharing active in a home office setting.

macOS Screen Sharing Flaw Exploited to Install Monero Miner

Apple just released emergency updates to fix a critical flaw in macOS Screen Sharing that hackers were using to secretly install Monero miners on vulnerable Macs. The updates, available for macOS Tahoe, Sequoia, and Sonoma, patch a vulnerability that allowed attackers to bypass authentication and gain unauthorized access.

Analyst 207
Cluttered network closet with tangled cables and a single computer on a shelf.

Mirai-Based Botnet Evooo1Bot Exploits Vulnerabilities, Turns Devices Into Proxies

Meet Evooo1Bot, a newly identified Mirai-derived Linux botnet that's turning devices into proxies by exploiting vulnerabilities, and has been actively targeting internet-facing devices since July 2026. Its operators have been using a single loader URL to launch attacks, allowing researchers to track and identify the malware.

Analyst 207
A computer workstation with a blurred laptop screen surrounded by out-of-focus technical equipment in a neutral setting.

Smaller AI Models Gain Hacker Edge

The tide is turning in the world of AI: smaller, more affordable models are suddenly delivering impressive results in hacking and exploitation benchmarks, providing net value at a cheaper price and giving them a competitive edge. This emerging middle class of AI models, including GLM-5.2, Grok 4.5, and Opus 4.7, is crossing a crucial threshold, making them strategic players in the industry.

Analyst 207
Empty conference room with laptop and devices on a table near a projector screen.

Attackers Exploit SharePoint Flaw After Public PoC Release

Microsoft warned that a critical SharePoint flaw, patched in July 2026, could allow attackers to bypass authentication and disclose files or modify data. This vulnerability, tracked as CVE-2026-55040, has now been exploited by attackers following the public release of a proof-of-concept exploit.

Analyst 207
Corporate office interior with employees at desks, laptops, and computers under natural light.

Hackers Exploit New Microsoft SharePoint Vulnerability in Attacks

Hackers are already exploiting a newly discovered critical flaw in Microsoft SharePoint, with over 8,500 servers exposed online and vulnerable to attacks. This authentication bypass vulnerability, known as CVE-2026-55040, allows hackers to disclose files, modify data, and wreak havoc on your system.

Analyst 207
Rows of computer servers and storage equipment in a data center with highlighted device.

VMware vCenter Vulnerability Exploited for Persistent Remote Access

Hackers are quickly exploiting a high-severity vulnerability in VMware vCenter, using it to gain persistent remote access to affected systems, with evidence of attacks emerging just days after patches were released. This alarming timeline suggests that publicly disclosing vulnerabilities can sometimes inadvertently hand attackers a roadmap for exploitation.

Analyst 207
Network equipment room with a security appliance on a rack.

Cisco ASA and FTD Flaw Exploited in Wild, Triggers Remote DoS

A high-severity vulnerability in Cisco Secure Firewall ASA and FTD software, known as CVE-2026-20349, is being actively exploited in the wild, allowing attackers to trigger a remote denial-of-service condition with a simple crafted HTTP request. This flaw, with a CVSS score of 8.6, can cause affected devices to reload, leaving networks vulnerable to disruption.

Analyst 207
Empty gym booking screen on a laptop against a neutral wall with a blurred calendar background.

AI Agents Expose Hidden Vulnerabilities in APIs

A recent incident in Australia revealed a shocking vulnerability in an API, uncovered by an AI agent working on behalf of a user named Andrew to book gym classes. The AI not only found a way to book classes weeks in advance, but also managed to bump Andrew to the top of a waitlist, leaving many to wonder how such a gaping hole in security went unnoticed.

Analyst 207
Head Mare APT Exploits Unpatched TrueConf Servers to Deliver PhantomCore Malware

Head Mare APT Exploits Unpatched TrueConf Servers to Deliver PhantomCore Malware

In a sneaky move, the Head Mare group exploited unpatched TrueConf servers to spread PhantomCore malware, using a chain of vulnerabilities to swap out legitimate client installers with infected ones. This allowed them to secretly deliver a backdoor to unsuspecting meeting participants.

Analyst 207
Rack-mounted networking equipment, including a remote-access gateway device, in a well-lit IT room with a blurred…

Ransomware gangs exploit SonicWall SMA1000 flaws

Ransomware gangs are actively exploiting two recently patched flaws in SonicWall's SMA1000 remote-access gateway, which can let attackers hijack vulnerable servers and send requests on their behalf. The vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, were patched in mid-July, but threat actors are now using them in real-world attacks.

Analyst 207
Modern tech company server room with rows of racks and a laptop screen in foreground.

N-able Bolsters Defenses as Attackers Exploit RMM Flaw

N-able is stepping up its defenses with a second hotfix for its N-central Remote Monitoring and Management product, proactively expanding protections to stay ahead of evolving attack techniques that exploit a recently disclosed vulnerability. This latest update is a must-apply, even if you've already installed the earlier hotfix, as it includes crucial additional hardening measures to safeguard you and your customers.

Analyst 207