CTM360 says the InsureOTP Kit relays stolen logins and OTPs in real time, letting attackers hijack insurance accounts in one ...
DevMan's v3 RaaS portal centralizes payload builds, network access, victim tracking, team controls, deadlines, and an 80-20 ...
A public GitLab 18.11.3 PoC chains two Oj parser bugs through crafted Jupyter notebook diffs to execute commands as git ...
Fastjson 1.x flaw CVE-2026-16723 can trigger unauthenticated RCE in Spring Boot fat-JAR apps, with attacks reported and no patched 1.x fix available.
Suspected Cl0p actors chain a FlexPLM WSDL leak with a Windchill flaw for unauthenticated RCE, dropping JSP web shells and ...
Certighost exploit lets a domain user obtain a Domain Controller certificate and reach DCSync through a vulnerable AD CS ...
An operator ran the Hermes AI agent with approval prompts disabled during a Thai finance ministry intrusion, then left its ...
AI agent visibility alone cannot enforce least privilege, requiring identity-centric, intent-aware, platform-agnostic ...
AgentForger could let a phishing link forge, publish, and schedule a rogue ChatGPT Workspace Agent with access to connected ...
Redis ships seven security releases after authenticated RESTORE RCE PoCs target versions 6.2.22, 7.4.9, 8.6.4, and 8.8.0.
BlueNoroff uses fake Zoom and Teams meetings to profile crypto wallets, hijack Telegram accounts, and deliver Windows and ...
NodeBB fixes eight flaws Aikido rates high severity, including bugs exposing admin pages, private messages, and federation ...