Skip to main content

Tag: vulnerability exploitation

148 articles

Security device on a rack surrounded by networking equipment in a well-lit IT room.

Fortinet FortiSandbox Flaws Targeted by Attackers in Wide-Ranging Exploits

Cyber attackers are actively exploiting three high-severity Fortinet FortiSandbox vulnerabilities, CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089, which were patched just last month and carry a near-critical CVSS score of 9.1. These flaws have been targeted in wide-ranging exploits over the past 24 hours, according to threat intelligence firm Defused Cyber.

Analyst 207
Blurred server room background with a prominent, illuminated network switch or router in sharp focus in the foreground.

Fortinet Flaws Exposed to Active Exploitation

Critical vulnerabilities in Fortinet's FortiSandbox platform are under active attack, with multiple flaws, including CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089, being exploited by hackers just 24 hours after security updates were issued.

Analyst 207
Network management system interface on a monitor with blurred background.

Cisco SD-WAN Vulnerability Exploited for Root Access

Cisco has warned of a critical vulnerability in its SD-WAN system that allows attackers to gain root access by sending a malicious HTTP request. This flaw, now patched, could have let hackers create or overwrite files and ultimately elevate their privileges.

Analyst 207
Cluttered modern office workstation with blurred screens and scattered papers.

AI Coding Agents Exposed to Agentjacking Attack

Imagine a sneaky new attack that tricks AI coding assistants into doing an attacker's bidding - without ever touching the victim's infrastructure. This clever hack, dubbed Agentjacking, uses a sneaky sequence of steps to get AI tools to execute malicious code on developers' machines.

Analyst 207
Developer workstation with laptop, code, notes, and coffee cups, set against a blurred office or city backdrop.

AI Coding Agents Exposed to 'Agentjacking' Attacks

Beware of "agentjacking" attacks that exploit AI coding agents' implicit trust, allowing hackers to trick them into executing malicious code on developers' machines. This new class of attack starts with a simple exploit of publicly available credentials, putting even the most secure systems at risk.

Analyst 207
Secure mobile gateway device on a rack with cables, set against a neutral background with a cityscape.

Ivanti Sentry vulnerability exploited in attacks

Within 24 hours of Ivanti releasing a patch for a high-severity vulnerability in its Sentry software, attackers began exploiting it in real-world attacks, with a large number of exploitation attempts detected. The flaw, tracked as CVE-2026-10520, allows hackers to execute code with root privileges on vulnerable mobile gateways.

Analyst 207
Blurred laptop screen and server rack in a brightly-lit workstation setting.

Attackers Exploit Langflow Path Traversal Flaw in Active Attacks

A single, unauthenticated request is all it takes to exploit a high-severity flaw in Langflow, a popular AI development platform, allowing attackers to write arbitrary files to its filesystem. This is made possible by a path traversal vulnerability, CVE-2026-5027, which can be easily triggered due to Langflow's default unauthenticated auto-login feature.

Analyst 207
Brightly-lit tech setting with rows of equipment in the background and an unoccupied computer terminal in the foreground.

Langflow Vulnerability Exploited for Unauthenticated Remote Code Execution

A single, unauthenticated request is all it takes to exploit a high-severity flaw in Langflow, allowing attackers to execute remote code without needing any login credentials. This vulnerability, tracked as CVE-2026-5027, enables malicious actors to write files to any location on a host filesystem.

Analyst 207
Modern network hub with sleek architecture symbolizing tech and security intersection.

AI-Fueled Attacks Prompt Enterprises to Overhaul Security Architecture

Enterprises in APAC are scrambling to revamp their security architecture as AI-fueled attacks exploit new vulnerabilities at lightning-fast speed, making rapid containment more crucial than ever. Automation is now a vital defense against these accelerated threats.

Analyst 207
Technicians check network equipment and cables in a brightly-lit operations room with a prominent router on a rack.

Cisco SD-WANs Hit by Seventh Zero-Day Exploit This Year

Cisco SD-WANs have been hit by a seventh zero-day exploit this year, with the latest vulnerability, CVE-2026-20245, already being actively exploited by attackers. A security patch is currently in the works, but no workaround is available to mitigate the issue in the meantime.

Analyst 207
Rows of computer servers and equipment racks in a dimly lit industrial server room.

AI Worm Uses Open-Weight Models to Spread, Evade Defenses

Imagine a self-navigating AI worm that can identify vulnerabilities and gain access to over 70% of a network's hosts - in a test, it found 31.3 vulnerabilities and elevated access on 23.1 hosts in just 15 isolated runs. Researchers at the University of Toronto and elsewhere have now created a proof-of-concept AI-driven worm to demonstrate this unsettling possibility.

Analyst 207
Network equipment and router on a rack with technician checking a laptop in the background.

Cisco SD-WAN Manager Flaw Actively Exploited

Cisco is warning of a high-severity vulnerability in its Catalyst SD-WAN Manager that allows attackers to execute commands as root, and it's already being exploited by hackers. This flaw, rated 7.8 on the CVSS scale, could give attackers control over your system if they're able to upload a malicious file.

Analyst 207
Technicians examine a large router and network diagram in a control room with a map of network topology on a screen.

Cisco SD-WAN Zero-Day Exploited in Targeted Attacks

Cisco is warning of a high-severity zero-day vulnerability in its Catalyst SD-WAN Manager that is being actively exploited, allowing attackers to gain root privileges and execute arbitrary commands. This critical flaw affects all deployment types and could put your network at risk if left unpatched.

Analyst 207
Rack of servers with one server highlighted, its indicators glowing neutrally.

Codex Agent Uncovers Lethal HTTP/2 DoS Exploit

A home computer on a typical 100Mbps connection can cripple a vulnerable server in mere seconds with the HTTP/2 Bomb, a potent DoS exploit that combines two decade-old attack techniques. This devastating attack exhausts server memory by sending tiny, compressed HTTP/2 header fragments and holding connections open, taking the service offline.

Analyst 207
Laptop screen displays hacker forum on cluttered desk in home office setting.

Hackers Exploit Gaps in Vulnerability Programs with Simplified Playbook

Meet Hercules, the mastermind behind a notorious underground tutorial that spills the beans on how to turn vulnerability exploitation into cold, hard cash. With a refreshingly blunt approach, Hercules breaks down the process into simple, actionable steps that even novice attackers can follow.

Analyst 207
Network operations center with a next-generation firewall on a rack and cables connected.

Palo Alto Networks Vulnerability Exploited in Active Attacks

Palo Alto Networks is urging users to patch their systems ASAP, as hackers are actively exploiting a critical vulnerability (CVE-2026-0257) in unpatched PAN-OS devices. This highly sought-after flaw was initially rated medium-severity but quickly upgraded to critical after exploitation was confirmed.

Analyst 207
Network security appliance on a rack in a brightly-lit data center.

Hackers Exploit Palo Alto GlobalProtect VPN Auth Bypass Flaw in Attacks

Hackers are actively exploiting a critical flaw in Palo Alto's GlobalProtect VPN, known as CVE-2026-0257, to gain unauthorized access to corporate networks. This alarming vulnerability allows attackers to bypass security restrictions and establish fake VPN connections.

Analyst 207
Server room with rows of equipment, focusing on a single server screen displaying a plugin interface.

CISA Mandates Emergency Patch for Exploited cPanel Plugin Flaw

A critical vulnerability in the LiteSpeed cPanel plugin, known as CVE-2026-48172, is being actively exploited by remote attackers, allowing them to execute arbitrary scripts with root privileges. CISA has issued an emergency patch, giving affected users just four days to update and protect themselves.

Analyst 207
Laptop screen displays a blurred CMS interface with a cityscape background.

Ghost CMS Flaw Exploited to Hijack Over 700 Sites in ClickFix Attacks

Over 700 websites were hijacked in a massive campaign that exploited a critical Ghost CMS vulnerability, turning legitimate pages into gateways for Windows malware. This alarming attack was made possible by CVE-2026-26980, an SQL injection flaw with a near-perfect CVSS score of 9.4.

Analyst 207
Laptop screen displays website homepage amidst papers and coffee cups in a busy workspace.

Ghost CMS SQL flaw fuels large-scale ClickFix attacks

Over 700 domains were hit in a massive cyberattack that exploited a critical vulnerability in Ghost CMS, putting sensitive data at risk. The flaw, tracked as CVE-2026-26980, allowed hackers to tap into site databases and steal admin API keys.

Analyst 207
Software development workspace with laptop and monitor displaying Git repository interface.

GitHub Tags Exploited to Deploy Credential-Stealing Malware

Malicious actors have manipulated hundreds of GitHub tags to spread credential-stealing malware through popular Laravel Lang localization packages, putting countless users at risk. By rewriting historical tags, attackers tricked Composer installations into downloading the malicious payload.

Analyst 207
Windows 11 laptop on a minimalist desk with lid ajar, screen displaying ambient daylight.

Exploiting Windows Drivers Without Hardware: The BYOVD Perspective

Discover how attackers can exploit Windows drivers without hardware, turning kernel-mode driver bugs into powerful tools to bypass security controls. The Atos Threat Research Center reveals a game-changing method to manipulate reachability from userland on Windows 11 23H2.

Analyst 207
Rows of computer servers and networking equipment in a server room or network operations center.

Drupal Sites Targeted in SQL Injection Attacks

Drupal sites are under attack as SQL injection exploits are now being detected in the wild, taking advantage of a vulnerability that can be triggered without authentication. This critical flaw, CVE-2026-9082, allows attackers to execute arbitrary SQL and potentially run remote code, putting sites that use PostgreSQL at risk.

Analyst 207
Modern office setting with an unsecured laptop and exposed network cable on a desk.

Vulnerability Exploitation Surpasses Credentials as Top Breach Entry Point

The latest Verizon Data Breach Investigations Report reveals a significant shift in how breaches occur: vulnerability exploitation now accounts for 31% of breaches, surpassing stolen credentials as the top entry point for hackers. Ransomware remains a major threat, involved in nearly half of all breaches.

Analyst 207