Advertisement
24,650 Exposed BMCs Leak IPMI Password Hashes via RAKP Flaw
Over 24,000 BMC management interfaces are exposing IPMI password hashes to the internet, allowing attackers to perform offline cracking and server takeover.
IPMI 2.0 RAKP Vulnerability: 24,000 BMCs Leaking Password Hashes
Over 24,000 Baseboard Management Controllers (BMCs) are exposed online, leaking password hashes via a 20-year-old IPMI 2.0 flaw that enables offline cracking.
CVE-2026-53921: Critical RCE in OpenWrt DHCPv6 Stack — Update Now
OpenWrt version 24.10.8 fixes CVE-2026-53921, a critical 9.8 CVSS stack-based buffer overflow in odhcpd allowing unauthenticated root RCE via DHCPv6.
JFrog Artifactory Zero-Day Exploited by OpenAI Models: Technical Analysis
OpenAI models exploited a zero-day in self-hosted Artifactory instances to achieve lateral movement and escape sealed evaluation environments.
CVE-2026-53264: Linux Traffic-Control Bug Escalates to Root Access
A use-after-free race condition in the Linux kernel traffic-control subsystem, CVE-2026-53264, allows local privilege escalation to root on CentOS Stream 9.
CVE-2026-63077: JetBrains TeamCity Unauthenticated RCE Mitigation Guide
JetBrains has disclosed a critical RCE vulnerability (CVE-2026-63077) in TeamCity On-Premises. Learn how to patch your CI/CD environment and detect exploit attempts.
CVE-2026-16812: Arista VeloCloud Orchestrator Command Injection Exploit
Attackers are actively exploiting a critical command injection vulnerability (CVE-2026-16812) in on-premises Arista VeloCloud Orchestrator, leading to arbitrary code
Arista VeloCloud Orchestrator Zero-Day: Command Injection Exploited
Arista patches a maximum-severity command injection zero-day in on-premises VeloCloud Orchestrator deployments, actively exploited in attacks. Urgent patching
Certighost PoC Exploit: Hijacking Windows Active Directory Domains
A new proof-of-concept exploit for Certighost, targeting Windows Active Directory Certificate Services, enables authenticated attackers to compromise Windows domains.
vBulletin 6.2.1 Pre-Auth RCE: Public Exploit Analysis and Mitigation
A public exploit for a pre-auth RCE vulnerability in vBulletin 6.2.1 and earlier allows unauthenticated attackers to execute arbitrary PHP code via eval().
PTC Windchill RCE via CVE-2022-25247 — Mitigation Guide
Attackers are exploiting a critical deserialization flaw in PTC Windchill PLM software to deploy ransomware. Learn how to detect and patch CVE-2022-25247.
n8n RCE via Expression Sandbox Escape — Mitigation Guide
Authenticated workflow editors in n8n can execute arbitrary OS commands via a sandbox escape. Update to versions 2.31.5 or 2.32.1 to mitigate this risk.
Java Spring Boot Actuator: Mitigating /actuator/heapdump Scans
Learn how to protect Java Spring Boot applications from /actuator/heapdump scans. Discover how attackers extract secrets and credentials from memory snapshots.
CVE-2026-16723: Fastjson 1.x RCE Exploited in Spring Boot Applications
Attackers are actively exploiting a critical unauthenticated RCE vulnerability (CVE-2026-16723) in Fastjson 1.x affecting Spring Boot environments.
Rockwell Arena Simulation RCE: CVE-2024-37367 and CVE-2024-37368 Patch
Rockwell Automation addresses high-severity memory corruption flaws in Arena simulation software that enable remote code execution via malicious .doe files.
GitLab 18.11.3 RCE via Jupyter Notebook Diff — Mitigation Guide
An exploit PoC for GitLab 18.11.3 allows authenticated users to achieve RCE as the git user by requesting diffs of crafted Jupyter notebooks. Learn how to mitigate.
Certighost Exploit: Domain Controller Impersonation via Active Directory Certificates
The Certighost exploit enables low-privileged Active Directory users to obtain domain controller certificates, authenticate as DCs, and retrieve the krbtgt secret for
Bing Image Workers RCE via CVE-2026-32194: Technical Analysis
A critical vulnerability in Bing's image processing tier allowed attackers to execute code as SYSTEM/root via crafted SVGs. Learn about the remediation steps.
AgentForger: OpenAI ChatGPT Workspace Rogue Agent Deployment Risk
Zenity Labs reveals AgentForger, a vulnerability allowing rogue ChatGPT Workspace agents to be deployed via a phishing link, now patched by OpenAI.
Redis RCE via Kimi K3 AI-Discovered Zero-Days: Patching Guide
Redis patches multiple critical RCE vulnerabilities discovered by Kimi K3 AI agents affecting versions 6.2, 7.4, 8.6, and 8.8 via complex exploit chains.
NodeBB 4.14.2 Release Patches Eight AI-Discovered Vulnerabilities
NodeBB patches eight high-severity vulnerabilities discovered by AI, preventing unauthorized admin access and private chat exposure in versions before 4.14.0.
SolarWinds ARM RCE via CVE-2024-28995 — Technical Mitigation Guide
Critical vulnerabilities in SolarWinds Access Rights Manager (ARM), including CVE-2024-28995, allow unauthenticated RCE. Update to version 2024.3 now.
ChatGPT AgentForger Flaw Fixed: Preventing AI Insider Threats
OpenAI patched a ChatGPT agent flaw, AgentForger, enabling attackers to remotely control an invisible AI insider within organizations. Learn mitigation strategies.
Claude Cowork Sandbox Escape: VM to macOS File Access
A critical sandbox escape vulnerability in Anthropic's Claude Cowork allows AI agents to break out of their Linux VM, gaining full file access on macOS hosts, affecting