#attackers.


Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

Sep 2, 2026 // 14:02

SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in […]

Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

Sep 2, 2026 // 11:35

Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The vulnerability in […]

Attackers Steal METR API Key and Consume AI Credits Worth About $600,000

Sep 1, 2026 // 12:12

METR (short for Model Evaluation and Threat Research and pronounced “Meter”), a research non-profit that evaluates frontier artificial intelligence (AI) models for their ability to […]

Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity

Sep 1, 2026 // 11:13

Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck. The vulnerabilities in question are listed […]

Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication

Aug 28, 2026 // 20:20

Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released […]

Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL

Aug 28, 2026 // 14:30

ServiceNow has released patches for four security flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring system and exploitable, […]

China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access

Aug 28, 2026 // 14:00

VulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (ZBT), each of which gives an unauthenticated remote […]

Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code

Aug 26, 2026 // 15:00

The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura’s HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary […]

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

Aug 25, 2026 // 11:42

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its […]

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

Aug 25, 2026 // 11:42

Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible […]

Previous 1 2 3 4 5 6 … 15 Next