Browsing Tag
Vulnerability
1633 posts
Critical JFrog Artifactory Vulnerability Exploited Days After Disclosure
watchTowr reports attackers exploiting critical CVE-2026-82329 to obtain administrator tokens from vulnerable JFrog Artifactory servers.
September 2, 2026
China-Nexus Fire Ant Hackers Target Cisco Routers, TACACS Servers for Espionage
Sygnia details Fire Ant attacks on Cisco routers, TACACS servers and Linux hosts used to steal credentials, collect traffic data and conceal malicious activity.
September 1, 2026
2 PaperCut NG/MF Zero-Days Exploited in Attacks, Emergency Patch Released
PaperCut NG and MF are under active attack as two zero-day flaws enable unauthenticated remote code execution, prompting an emergency patch.
August 29, 2026
OpenAI Report Explains How Its AI Agents Breached Hugging Face Systems
OpenAI says internal AI agents gained internet access, exploited vulnerabilities and accessed Hugging Face systems during July cybersecurity evaluations.
August 27, 2026
Account Takeover Flaw Hits TranslatePress Plugin Used on 400K WordPress Sites
The vulnerability, CVE-2026-19632, exposes WordPress admin password-reset links through TranslatePress, allowing unauthenticated attackers to take over affected WordPress websites.
August 27, 2026
CISA Warns Agencies to Patch Actively Exploited Oracle WebLogic Proxy Flaw
CISA has given federal civilian agencies until August 27 to patch the exploited Oracle flaw that can expose or alter critical data without prior authentication.
August 26, 2026
NVIDIA NemoClaw Flaw Lets Malicious Websites Hijack OpenClaw AI Agents
A NemoClaw network configuration flaw lets malicious websites reach local Ollama servers, alter model templates and plant lasting instructions inside AI agents.
August 25, 2026
Cudy WR3000 Router Flaws Can Be Chained to Gain Root Access
Public exploit tools for 2 Cudy WR3000 flaws can forge JWTs, bypass MQTT authentication, and remotely execute operating-system commands as root on the router.
August 24, 2026
Attackers Exploit Critical Flaw in MLflow, an AI Platform Downloaded 30M Times Monthly
The MLflow SSRF flaw CVE-2026-64849 can let unauthenticated attackers access internal services and cloud metadata, potentially exposing sensitive credentials and secrets.
August 22, 2026
Attackers Probe Critical GeoServer SQL Injection Vulnerability
Attackers are probing internet-facing GeoServer systems for a critical SQL injection vulnerability affecting deployments that use PostGIS 12…
August 17, 2026