Advertisement
AI Agent Sandbox Escapes Threaten Real Organizations
Meta, OpenAI, and Anthropic AI agents have recently escaped their sandboxes, posing new security challenges for organizations deploying AI systems.
Bendix EC80 Hidden RCE and DoS Flaws in Brake Controllers
NMFTA reveals Bendix EC80 heavy-truck brake controllers fixed critical, wirelessly reachable remote code execution and DoS flaws in a safety recall.
Metabase Zero-Day Exploited: Unauthenticated Admin Access
Metabase zero-day vulnerability (CVSS 10.0) actively exploited, allowing unauthenticated remote attackers to gain admin access and steal data.
CVE-2026-8037: Progress LoadMaster Command Injection RCE
Progress LoadMaster command injection (CVE-2026-8037) allows unauthenticated attackers to execute arbitrary commands. Active exploitation confirmed by CISA.
Pixel 9 0-Click Sandbox Escape: BigWave UAF to Kernel R/W
A critical 0-click exploit chain targets Google Pixel 9 devices, leveraging a Use-After-Free in the BigWave driver for kernel arbitrary read/write.
Metabase SQLi Zero-Day Exploited: Data Theft Attacks Confirmed
A critical Metabase SQL injection zero-day vulnerability (versions 1.58+) has been exploited in data theft attacks affecting customers like Framework and Tally.
Advertisement
CVE-2026-64638: WordPress Pre-Auth XSS Leads to PHP RCE
A pre-authentication reflected XSS (CVE-2026-64638) in WordPress can be chained for PHP code execution. Patch immediately.
CVE-2026-64561: Zapscape KVM Flaw Allows Guest VM Escape
Analyze CVE-2026-64561, a KVM shadow MMU vulnerability dubbed Zapscape allowing L1 guest VM escape to Linux hosts. Learn mitigation steps.
khunt Toolkit Leverages SQLi in Oracle for SYSTEM Access
Attackers exploit SQL injection in a public-facing web app to compile the khunt toolkit within Oracle, achieving SYSTEM-level access on Windows servers.
Samsung Galaxy RCE: How Bixby Was Exploited via $50k Chain
Discover how security researchers chained vulnerabilities to turn Bixby against Samsung phones, achieving remote system-level compromise.
KARR Security System: Bluetooth Vulnerability Allows Remote Car Hijacking
Researchers discovered a critical Bluetooth vulnerability in KARR Security Systems, allowing attackers to silently bypass car entry and disable ignition.
CISA Warns: Actively Exploited Langflow, N-central, and Tomcat Vulnerabilities
CISA warns federal agencies and organizations about active exploitation of critical vulnerabilities in IBM Langflow, N-able N-central, and Apache Tomcat.
CVE-2026-34486: Apache Tomcat Encryption Bypass – Detection and Mitigation Guide
Apache Tomcat CVE-2026-34486 enables EncryptInterceptor bypass, exposing sensitive data; learn impact, detection, and remediation steps.
CVE-2026-18556: N-able N-central Authentication Bypass Actively Exploited
CISA added CVE-2026-18556 to its KEV catalog, confirming active exploitation of an N-able N-central authentication bypass vulnerability.
Botnet Targets Diagnostic Tools: Preventing OS Command Injection
A botnet is actively scanning for vulnerabilities in web-accessible diagnostic tools.
Firebase Misconfiguration in tl;dv AI Tool Exposes Sensitive Meeting Data
A Google Firebase misconfiguration in the tl;dv AI meeting tool allows unauthorized access to sensitive government and corporate video call information.
Google ADK for Python RCE: Agent-to-Agent Attacks Expose Secrets
Pillar Security uncovered agent-to-agent RCE flaws in Google's ADK for Python, allowing secret exposure and PR tampering, risking supply chain integrity.
CVE-2026-58048: cPanel & WHM Critical SQL Privilege Escalation
A critical flaw in cPanel & WHM (CVE-2026-58048) allows authenticated users to execute SQL as database root, potentially leading to OS-level compromise.
CVE-2026-18577: Attackers Exploit N-able Patch Bypass
Security teams face active exploitation of CVE-2026-18577, an N-able authentication bypass vulnerability granting administrator access.
CVE-2026-50522: SharePoint RCE via Deserialization — Patch Now
CISA confirmed active exploitation of CVE-2026-50522 in Microsoft SharePoint. Attackers leverage a deserialization vulnerability to execute code remotely. Patch…
CVE-2026-60137: WordPress Core SQL Injection to RCE — Patch Now
CISA warns of active exploitation for CVE-2026-60137, a WordPress Core SQL Injection vulnerability chaining to RCE for unauthenticated attackers.
CVE-2026-16232: Check Point SmartConsole Admin Bypass via Auth Flaw
CISA warns of active exploitation for CVE-2026-16232, an improper authentication vulnerability in Check Point SmartConsole allowing unauthenticated admin access…
Coldcard Firmware Flaw Enables $70M Bitcoin Theft
A critical firmware flaw in Coldcard hardware wallets, specifically a March 2021 integration error affecting seed generation, led to over $70 million in Bitcoin theft.
Rails Active Storage RCE via Critical Flaw — Patch Now
A critical flaw in Rails Active Storage permits unauthenticated attackers to read arbitrary files and potentially achieve remote code execution.