0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
TrueConf Server Missing Authentication for Critical Function Vulnerability
TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script.
TrueConf Server Code Injection Vulnerability
TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.
MLflow SSRF Lets Attackers Steal Cloud Credentials via Metadata Services
A server-side request forgery in MLflow before 3.15.0 allows unauthenticated access to internal endpoints including cloud metadata services, enabling cloud credential and IAM secret theft.
Apple macOS Improper Authentication Vulnerability
Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.
Ray-Project Ray Code Injection Vulnerability
Ray-Project Ray has a code injection flaw enabling RCE, added to CISA KEV on August 18, 2026. Ray installs with browser-reachable interfaces are at risk. Federal patch deadline is August 21.
From the desk

China-Linked AI Framework Hits APAC Government Targets
A Chinese-language operator used a complex AI framework to compromise APAC government agencies in what researchers call the first purported near-autonomous nation-state attack.

CISA, FBI: Medusa Ransomware Has 500+ Victims
CISA and the FBI updated their Medusa ransomware advisory, confirming the group has hit more than 500 organizations in critical infrastructure since 2021.

CoSnitch: Three Copilot Flaws Enable One-Click Data Theft
Varonis Threat Labs found three flaws in Microsoft Copilot Personal, named CoSnitch, that let attackers silently pull data from all connected apps in one click.

MLflow SSRF, FUXA Auth Flaws Actively Exploited
Attackers are exploiting an SSRF in MLflow's AI platform and scanning FUXA SCADA installs—critical flaws in both enabling cloud credential theft and full RCE.

Clop's Windchill Implant Decrypts Passwords, Steals Files
ReliaQuest finds a Clop-linked JSP implant engineered for PTC Windchill that decrypts LDAP credentials and maps file vaults to steal engineering data.

16 Fake RubyGems Steal Browser Creds, Crypto Wallets
Sixteen malicious RubyGems packages tracked as StubMaker are stealing browser credentials and crypto wallets via typosquatting—audit your Gemfile now.




