Vulnerability & Exploit Coverage
498 articles · sorted newest first

MaxUpload for WordPress: Unauthenticated File Upload
CVE-2026-15965: MaxUpload (≤1.4.0) lets unauthenticated attackers upload arbitrary files via a filename validation mismatch between chunk and final assembly. CVSS 8.8, no patch confirmed.

Thirteen New Metasploit Modules, One Old Pattern
Rapid7's latest wrap-up adds thirteen exploit modules spanning Ghost CMS, SonicWall SMA1000, Langflow, Ray, and more. The targets rotate. The underlying pattern doesn't.

MindsDB: Unauthenticated RCE, Max CVSS Score
CVE-2026-73678: MindsDB Minds Platform up to 26.1.0 exposes unprotected API endpoints enabling unauthenticated OS command execution. CVSS 10.0.

Patch Now: Critical Auth Bypass Hits WordPress Plugins
Two WordPress plugins patched this week carry CVSS 9.8 authentication bypass flaws. A third allows unauthenticated file deletion that hands attackers RCE.

Evooo1Bot Turns Routers Into SOCKS5 Relay Nodes
A Mirai-based modular Linux botnet is converting compromised routers into SOCKS5 relay nodes — the same ORB infrastructure pattern, repackaged again.

Unauth Access to AI Memory: CVE-2026-50027 Patched
CVE-2026-50027: mcp-memory-service exposed all /api/documents/* routes without auth, letting anyone read, write, or delete AI memories. Patch to 10.67.1.

ShieldBreak: New Unpatched EoP in Defender Scan Engine
CVE-2026-69414 is a second ShieldBreak-tagged EoP — this one in Defender's Malware Protection Engine, CVSS 7.8. No patch yet. MSRC advisory is live.

CISA ICS Advisory: SCADA Deserialization Bug CVE-2025-7639
CISA advisory ICSA-26-225-01 covers CVE-2025-7639, a deserialization flaw that lets authenticated ICS operators execute code at elevated privilege.

NIST Bets on AI to Clear AI-Created CVE Backlog
AI tools are flooding the CVE pipeline faster than NVD can enrich them. NIST's proposed fix is more AI — a structural response to a structural problem, with real triage implications downstream.

GeoServer Zero-Day Under Active Attack, No Patch Available
An unpatched SQL injection in GeoServer enables RCE on PostGIS and Oracle deployments. WatchTowr logged hundreds of probe attempts within hours of public disclosure.

Three Critical OpenWrt LuCI Flaws Allow Root RCE
Two CVSS 9.9 and one 8.8 vulnerabilities in OpenWrt's LuCI web interface let authenticated users execute arbitrary code as root. Update LuCI now.

Trivy, Not LiteLLM, Drove the March Supply Chain Breach
SOCRadar's forensics show 95% of the 2,188 affected orgs were compromised via the Trivy scanner before any LiteLLM package was poisoned.

Scottish Crown Office Breach May Spread Across Agencies
Scotland's Crown Office confirms a data breach via a compromised third-party service provider. Investigators warn other government agencies may share the exposure.

Seven Arrested in €30M Commerzbank Account Fraud
German BKA and Brazil's federal police arrested seven over a service provider flaw that enabled withdrawals from Commerzbank customer accounts. €30M stolen.

France Confirms DGFIP Breach; Hacker Claims 600K
France's tax authority confirms unauthorized access in late June via credential theft. A threat actor claims 600,000 records stolen. Investigation ongoing.

AmnesiaStealer Hijacks macOS Browser Sessions
Jamf finds AmnesiaStealer: macOS infostealer that hijacks live browser sessions, steals keychain data, and destroys saved passwords via ClickFix terminal prompts.

macOS Screen Sharing Auth Bypass Exploited in Wild
Netherlands NCSC confirms active exploitation of a macOS Screen Sharing authentication bypass after public PoC release. Attackers deploying Monero cryptocurrency miners.

SAP Commerce Cloud RCE Exploit Hits Days After Patch
Defused flagged active exploitation of a max-severity SAP Commerce Cloud RCE within 72 hours of patching. Unpatched instances are live targets now.

Clop Claims 89GB Shell Theft; Investigation Open
Shell confirms investigating a potential incident after Clop listed the oil giant on its extortion site, claiming 89GB of exfiltrated data. No breach confirmed; initial access vector undisclosed.

ShinyHunters Hits RingCentral: 1.6M Accounts Exposed
ShinyHunters breached RingCentral in July, exposing 1.6 million accounts. Names, addresses, emails, and phone numbers are now published by the group.
Beacon CRM Breach Hits 1,000+ Charities via AWS Key
Over 1,000 UK charities had supporter data exposed after attackers used an AWS access key found in Beacon's public JavaScript build artifacts.

WordPress 7.0.4 Patches High-Severity RCE Flaw
WordPress 7.0.4 fixes a high-severity RCE allowing Author-level accounts to execute code via malicious PostScript files. Update now.

GeoServer Zero-Day SQL Injection Exploited in Wild
Threat actors are actively exploiting an unpatched SQL injection in GeoServer that enables remote code execution. No patch available; restrict exposure immediately.

Apple Notifies Users of Mercenary Spyware Attacks
Apple issued Threat Notifications to iPhone users warning of active mercenary spyware attacks. If you received one, here is what to do immediately.
No articles match the current filters.