Vulnerability & Exploit Coverage
732 articles · sorted newest first

JADEPUFFER Uses Stolen Service Principals to Destroy Azure
Microsoft Threat Intelligence tracks JADEPUFFER-linked attackers using compromised Azure service principals to delete cloud resources. Audit your tenant's non-human identities now.

ShinyHunters Retooled PeopleSoft Exploit, Google Warns
Google warns ShinyHunters has retooled its CVE-2026-35273 exploit and is running a fresh campaign against Oracle PeopleSoft. Patch or take exposed instances offline now.

Bitget Resumes Withdrawals After $387.5M DPRK Heist
Bitget restored Bitcoin withdrawals September 28, days after suspected North Korean hackers stole $387.5 million from the exchange in a backend compromise.

Citrix Patches NetScaler Zero-Days CVE-2026-88771, -88772
Citrix patched CVE-2026-88771 and CVE-2026-88772 in NetScaler ADC and Gateway. CISA orders federal agencies to apply by September 30.

Obot AI Platform Patches Three CVEs, Two Critical
Three GitHub Security Advisories disclose an unauthenticated Docker exposure and two MCP endpoint access control failures in the Obot AI agent platform.

Budibase 3.45.0 Fixes Six Security Flaws
Budibase 3.45.0 patches six CVEs including arbitrary file write (CVSS 8.8), SSO auth bypass (8.1), and SQL injection (8.0). Update now if Builder is exposed.

Citrix NetScaler: Two Unpatched RCEs Actively Exploited
Two unpatched RCEs in Citrix NetScaler ADC and Gateway are actively exploited in the wild. CVE IDs are pending assignment; Citrix expects patches by end of September 2026.

Critical File Upload Bug in WooCommerce Quote Plugin
CVE-2026-18143 is a CVSS 9.8 arbitrary file upload flaw in the Request a Quote for WooCommerce plugin through version 2.9.2. Update to 2.9.3.

SharePoint Code Injection CVE-2026-65660 Added to KEV
CISA added a SharePoint code injection flaw to its KEV catalog on September 25. CVSS 8.8, active exploitation confirmed, federal patch deadline September 28.

ShinyHunters WAF Bypass Keeps PeopleSoft Attacks Alive
ShinyHunters uses URL encoding to bypass WAF rules protecting against Oracle PeopleSoft CVE-2026-35273, continuing to deploy web shells on servers organizations thought were protected.

Elementor CSRF Flaw Lets Attackers Create Admin Accounts
A CSRF flaw in the Elementor WordPress plugin lets attackers create administrator accounts without valid credentials. Site owners should update the plugin immediately.

CISA Adds MikroTik RouterOS Chain Flaw to KEV Catalog
CISA added CVE-2026-67279 to KEV on September 25. The medium-severity flaw chains with CVE-2026-86060 to enable full unauthenticated exploitation of MikroTik RouterOS. Federal deadline is September 28.

Kiteworks Flags Potential Zero-Day, Urges Server Shutdown
Kiteworks warned customers Thursday of potential zero-day attack activity and asked them to take servers offline for a six-hour window on Saturday, September 26.

Clop Moves Leak Site After Grav CMS Attack Confirmed
Clop ransomware confirmed its Tor leak site was breached via an unpatched Grav CMS path traversal flaw. The group has migrated to a new Tor address.

U.S. Soldier Gets 70 Months for Telecom Extortion
A U.S. Army soldier sentenced to 70 months for hacking AT&T and Verizon and extorting the carriers using 100 million customers' stolen call and text metadata.

Suspected DPRK Hackers Steal $351.6M from Bitget
Bitget says suspected North Korean actors stole $351.6 million from hot and warm wallets in a backend compromise detected at 18:31 UTC on September 24.

SalesBleed: Agentforce Flaws Enable Data Exfiltration
Three SalesBleed flaws in Salesforce Agentforce allow attackers to hijack AI agents and exfiltrate data via trusted Slack channels without user interaction.

CISA KEV: WSO2 and Adobe Commerce Flaws Exploited
CISA added CVE-2026-5430 (WSO2, CVSS 10.0) and CVE-2026-71362 (Adobe Commerce, CVSS 9.1) to KEV on September 24. Federal patch deadline: September 27.

MacSync macOS Malware Abuses Public iCloud Calendars
Kaspersky found a new MacSync variant that hides C2 commands inside public iCloud calendar events, bypassing domain-based network controls on macOS.

Ryuk Member Gets 2 Years for $1.2M Ransomware Attacks
Armenian national Karen Vardanyan sentenced to 2 years in US federal prison for Ryuk ransomware attacks, ordered to pay over $1.2M in restitution to victims.

Roundcube SQL Injection Flaw Under Active Attack
Canada's CCCS confirmed active exploitation of CVE-2026-48842, a SQL injection in Roundcube Webmail patched in May. Upgrade to 1.6.16 or 1.7.1 now.

SolarWinds Fixes Two Unauth RCE Flaws in Observability
SolarWinds patches CVE-2026-28324 (CVSS 9.8) and CVE-2026-28325 (CVSS 8.8), two unauthenticated RCE flaws in Observability Self-Hosted. No active exploitation reported.

CISA: Ransomware Gangs Exploiting TeamCity RCE Flaw
CISA warns federal agencies that ransomware groups are exploiting CVE-2026-63077, a CVSS 9.8 unauthenticated RCE in JetBrains TeamCity. Patch released July 28.

InfraTrust: Network Management Systems Under Attack
InfraTrust's September report finds attackers targeting network management and control infrastructure at or before patch availability. Here's what to prioritize.
No articles match the current filters.