Browsing Tag
Vulnerability
1632 posts
China-Nexus Fire Ant Hackers Target Cisco Routers, TACACS Servers for Espionage
Sygnia details Fire Ant attacks on Cisco routers, TACACS servers and Linux hosts used to steal credentials, collect traffic data and conceal malicious activity.
September 1, 2026
2 PaperCut NG/MF Zero-Days Exploited in Attacks, Emergency Patch Released
PaperCut NG and MF are under active attack as two zero-day flaws enable unauthenticated remote code execution, prompting an emergency patch.
August 29, 2026
OpenAI Report Explains How Its AI Agents Breached Hugging Face Systems
OpenAI says internal AI agents gained internet access, exploited vulnerabilities and accessed Hugging Face systems during July cybersecurity evaluations.
August 27, 2026
Account Takeover Flaw Hits TranslatePress Plugin Used on 400K WordPress Sites
The vulnerability, CVE-2026-19632, exposes WordPress admin password-reset links through TranslatePress, allowing unauthenticated attackers to take over affected WordPress websites.
August 27, 2026
CISA Warns Agencies to Patch Actively Exploited Oracle WebLogic Proxy Flaw
CISA has given federal civilian agencies until August 27 to patch the exploited Oracle flaw that can expose or alter critical data without prior authentication.
August 26, 2026
NVIDIA NemoClaw Flaw Lets Malicious Websites Hijack OpenClaw AI Agents
A NemoClaw network configuration flaw lets malicious websites reach local Ollama servers, alter model templates and plant lasting instructions inside AI agents.
August 25, 2026
Cudy WR3000 Router Flaws Can Be Chained to Gain Root Access
Public exploit tools for 2 Cudy WR3000 flaws can forge JWTs, bypass MQTT authentication, and remotely execute operating-system commands as root on the router.
August 24, 2026
Attackers Exploit Critical Flaw in MLflow, an AI Platform Downloaded 30M Times Monthly
The MLflow SSRF flaw CVE-2026-64849 can let unauthenticated attackers access internal services and cloud metadata, potentially exposing sensitive credentials and secrets.
August 22, 2026
Attackers Probe Critical GeoServer SQL Injection Vulnerability
Attackers are probing internet-facing GeoServer systems for a critical SQL injection vulnerability affecting deployments that use PostGIS 12…
August 17, 2026
AI Agents Used to Compromise 85 Taiwan Government Accounts in 4 Days
Dream Group says AI agents mapped 21 Taiwanese government systems, cracked 85 accounts and stole over 2,500 personnel records in a four-day attack in July 2026.
August 14, 2026