On August 9th, 2026, Wordfence Argus, created by the Wordfence Threat Intelligence team, discovered an Arbitrary File Upload vulnerability in Gravity…
Tag: Vulnerability
CISA review makes the case for eliminating vulnerability classes
For years, the security industry has treated vulnerabilities as an endless queue of individual fixes. A recent CISA review argues that this is precisely…
5 Million WordPress Sites Affected by SQL Injection Vulnerability in All-in-One WP Migration and Backup WordPress Plugin
On August 14th, 2026, we received a submission for an Unauthenticated Second-Order SQL Injection vulnerability in All-in-One WP Migration and Backup, a…
21,000+ Microsoft Exchange Servers Remain Exposed to Active CVE-2026-62911 Exploitation
Nearly 22,000 Microsoft Exchange servers worldwide are still running unpatched for CVE-2026-62911, a critical authentication-bypass vulnerability that…
Expanding AI Benchmarks in Cybersecurity Beyond Vulnerability Discovery
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: Expanding AI Benchmarks in Cybersecurity Beyond Vulnerability Discovery
Hackers Actively Exploiting Critical Langflow RCE and Rails Vulnerability
Two critical vulnerabilities affecting Langflow and Ruby on Rails deployments are being actively exploited, with attackers quickly moving from public…
Hackers Start Exploiting Critical Langflow Vulnerability
Tracked as CVE-2026-0768, the security defect allows unauthenticated attackers to execute arbitrary Python code remotely.
Public PoC Released for Microsoft Exchange Server Pre-auth RCE Vulnerability
A public proof-of-concept exploit has been released for CVE-2026-62911, a Microsoft Exchange Server vulnerability linked to an authentication…
Chaotic Eclipse Releases Kaspersky Zero-Day HardBreacher
Chaotic Eclipse released HardBreacher, a PoC exploit for a Kaspersky Endpoint Security privilege escalation flaw, adding another zero-day to his list.…
Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild
Exploitation of the authentication bypass vulnerability CVE-2026-82329 started just days after its public disclosure.
PoC Released for Microsoft Exchange CVE-2026-62911 Pre-Auth RCE Attack Chain
A public proof-of-concept (PoC) repository has garnered attention for a pre-authentication remote code execution chain targeting Microsoft Exchange…
PaperCut Zero-Days Exploited, Emergency Patch Released
PaperCut Software has released a second emergency patch after confirming that attackers exploited two zero-day vulnerabilities in its NG and MF print…
HardBreacher Exploit Targets Kaspersky Endpoint Security Zero-Day for Windows 11 Privilege Escalation
A proof of concept called HardBreacher allegedly exploits an unpatched local privilege escalation flaw in Kaspersky Antivirus for Endpoint. This…
Metasploit Adds Exploit for PaperCut MF/NG Zero-Day RCE Vulnerabilities
Rapid7’s Metasploit Framework is set to add an exploit module targeting the actively exploited chain of vulnerabilities affecting PaperCut MF and PaperCut…
Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs
Named KindaRails2Shell, the arbitrary file read flaw allows attackers to extract secrets and execute arbitrary code remotely.
ServiceNow vulnerabilities warning, PaperCut zero-day, McKesson healthcare breach
ServiceNow warns of three maximum severity security vulnerabilities PaperCut zero-day exploited in attacks Healthcare giant McKesson discloses breach Get…
What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree
In this Help Net Security interview, Dr. Joye Purser, Global Field CISO at Cohesity, explains how to rank vulnerabilities when KEV, EPSS, and CVSS point…
OpenAI Warns Astra AI Model May Develop Zero-Day Exploits and Launch Autonomous Cyberattacks
OpenAI has issued a warning regarding Astra, an upcoming artificial intelligence model, which may be close to a threshold of cybersecurity capabilities…
Storm-1175 Deploys StormEncryptor Ransomware After N-able N-central Vulnerability Exploitation
Financially motivated hackers believed to be based in China are using a new ransomware for the first time after targeting a vulnerability in the N-central…
Critical Avada WordPress Vulnerability Allows Unauthenticated PHP Code Execution
A critical vulnerability chain in the popular Avada theme for WordPress could allow an unauthenticated attacker to execute arbitrary PHP code on the…
