#attackers.


Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

Oct 5, 2026 // 12:35

A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS […]

Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets

Sep 30, 2026 // 19:50

Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from […]

Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks

Sep 30, 2026 // 19:40

Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of meeting invitations, PDF-themed […]

Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager

Sep 30, 2026 // 18:30

Attackers are exploiting a critical flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks, Cisco said in an […]

Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures

Sep 30, 2026 // 18:00

Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures […]

Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT

Sep 30, 2026 // 11:30

Unknown threat actors have been observed exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target organizations in North […]

JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources

Sep 28, 2026 // 12:10

The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised service principals. Microsoft, which is tracking […]

Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

Sep 26, 2026 // 14:47

Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The […]

Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link

Sep 26, 2026 // 13:38

Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create […]

Elementor WordPress flaw lets attackers create admin accounts

Sep 26, 2026 // 00:58

A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts. Threat actors can exploit […]

1 2 3 … 15 Next