#attackers.


After the Break-In: What Attackers Do Once They’re Already Inside

Jul 30, 2026 // 17:16

Most of us in IT spend our energy trying to keep attackers out. But a recent incident investigated by Huntress tells us a lot about […]

Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads

Jul 30, 2026 // 00:59

Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted […]

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

Jul 29, 2026 // 19:50

Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in […]

Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root

Jul 28, 2026 // 16:00

OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by […]

Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

Jul 28, 2026 // 11:21

JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could […]

Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

Jul 28, 2026 // 07:50

A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16812 […]

New Certighost PoC exploit lets attackers hijack Windows domains

Jul 28, 2026 // 00:16

A proof-of-concept exploit for “Certighost,” a Windows Active Directory Certificate Services vulnerability, has been released that can allow authenticated attackers to potentially compromise a Windows […]

New RefluXFS Linux flaw lets attackers gain root privileges

Jul 23, 2026 // 14:56

A nine-year-old race condition vulnerability in the Linux kernel’s XFS filesystem, tracked as CVE-2026-64600, allows local attackers to overwrite protected files and gain root privileges. […]

Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers

Jul 23, 2026 // 14:30

Cybersecurity researchers have shed light on a large-scale campaign that has turned compromised GitHub repositories into distributed attack infrastructure designed to target cPanel and WebHost […]

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

Jul 21, 2026 // 17:10

Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on […]

Previous 1 … 9 10 11 12 13 … 15 Next