#attackers.


Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

Aug 24, 2026 // 15:03

Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could […]

Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution

Aug 20, 2026 // 16:26

A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT […]

NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands

Aug 20, 2026 // 14:14

Security researchers at Cycode have disclosed a chain of flaws in AIT-GUI, the browser-based operator console for NASA/JPL’s open-source AMMOS Instrument Toolkit, that allow an […]

Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

Aug 20, 2026 // 09:12

Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution. […]

Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

Aug 18, 2026 // 23:28

Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) […]

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

Aug 18, 2026 // 00:07

GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could […]

Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access

Aug 17, 2026 // 14:57

Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc modem firmware through […]

AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS

Aug 13, 2026 // 17:23

Cybersecurity researchers have disclosed details of a new macOS-oriented, Rust-based information stealer called AmnesiaStealer that’s capable of hijacking Chromium web browsers to steal session data. […]

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

Aug 13, 2026 // 10:35

Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is […]

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

Aug 12, 2026 // 12:15

Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO. The vulnerability […]

Previous 1 … 3 4 5 6 7 … 15 Next