Ravie LakshmananSep 01, 2026Cyber Attack / Artificial Intelligence METR (short for Model Evaluation and Threat Research and pronounced “Meter”), a […]
Category: Attackers
Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity
Ravie LakshmananSep 01, 2026Vulnerability / Artificial Intelligence Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, […]
Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication
Ravie LakshmananAug 28, 2026Vulnerability / Web Security Malicious actors are exploiting a newly patched security flaw in PaperCut NG and […]
Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access
Ravie LakshmananAug 25, 2026Vulnerability / Web Security Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the […]
Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution
Ravie LakshmananAug 20, 2026Vulnerability / Email Security A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation […]
Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
Ravie LakshmananAug 18, 2026Vulnerability / Artificial Intelligence Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, […]
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
Ravie LakshmananAug 13, 2026Vulnerability / Enterprise Security Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following […]
Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
Ravie LakshmananAug 12, 2026Vulnerability / Threat Intelligence Threat actors have begun to actively exploit a recently patched critical security flaw […]
Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access
Swati KhandelwalAug 06, 2026Database Security / Endpoint Security Attackers broke into an organization’s Oracle database through a SQL injection flaw […]
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
Ravie LakshmananJul 28, 2026Vulnerability / Threat Intelligence A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has […]
