Security researchers have disclosed a serious attack chain affecting Microsoft System Center Configuration Manager, commonly known as SCCM or…
Tag: Vulnerability
Update your Mac: Screen Sharing vulnerability exploited in the wild
Attackers are exploiting a Mac Screen Sharing vulnerability to gain root access and install Monero cryptominers.
SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch
A maximum-severity security vulnerability impacting SAP Commerce Cloud is witnessing active exploitation efforts. The vulnerability, tracked as…
Expanding AI Benchmarks in Cybersecurity Beyond Vulnerability Discovery
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: Expanding AI Benchmarks in Cybersecurity Beyond Vulnerability Discovery
Recent macOS Screen Sharing Vulnerability Exploited in Attacks
Threat actors gained root access to the vulnerable systems and deployed a Monero miner.
GeoServer’s Unauthenticated SQL injection Vulnerability Enables RCE Attacks
GeoServer administrators should urgently update affected systems after researchers disclosed an unauthenticated SQL injection flaw in the…
Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure
The vulnerability tracked as CVE-2026-58231 can be exploited to execute arbitrary code and compromise internal components.
Critical SAP Commerce Cloud RCE Vulnerability Actively Exploited in the Wild
Defused, a threat intelligence provider, reported exploitation attempts targeting CVE-2026-58231, a critical unauthenticated remote code execution…
Apple Screen Sharing Vulnerability Exploited to Execute Command as Root
A newly disclosed logic flaw in macOS Screen Sharing shows how a feature meant only to grant screen-viewing access can be twisted into a path for full…
SAP Commerce Cloud Vulnerability Targeted After Patch
A maximum-severity vulnerability in SAP Commerce Cloud is reportedly facing exploitation attempts only days after SAP released a security update. Tracked…
SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild
Attackers are actively exploiting a maximum severity SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231, just days after SAP released a patch. A…
Russian Hackers Use Exchange Zero-Day in Email Attacks
Russia-aligned cyberespionage group Laundry Bear, also tracked as Void Blizzard and TA488, is exploiting a Microsoft Exchange Outlook Web Access (OWA)…
GeoServer Zero Day Being Probed While No Patch Available
A newly found GeoServer zero-day is already receiving active exploitation efforts, while there is no patch ready yet. Firms using the open-source…
Critical macOS Screen Sharing Bug (CVE-2026-65400) Exploitation to Install Monero Miners
Cybersecurity agencies, including the Netherlands National Cyber Security Centre (NCSC-NL), have issued urgent warnings regarding active macOS screen…
GeoServer Zero-Day Is Already Being Probed. That’s the Problem
GeoServer faces an unpatched zero-day enabling SQL injection and potentially RCE, with attackers already probing exposed systems. A newly disclosed…
40,000 WordPress Sites affected by Authentication Bypass Vulnerability in User Profile Builder WordPress Plugin
On July 14th, 2026, we received a submission for an Authentication Bypass vulnerability in User Profile Builder, a WordPress plugin with more than 40,000…
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft…
Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era?
And will today’s surge in AI-driven vulnerability discovery eventually make tomorrow’s software safer?
Lazarus Abuses Zero-Day Exploit to Install a New Backdoor
Lazarus does a zero-day exploitt The North Korean hacking group called Lazarus has been linked to the zero-day compromise of a recently patched…
After Microsoft threatened legal action, a security researcher publishes a new Windows zero-day bug
This is the latest zero-day released by security researcher Nightmare Eclipse, despite Microsoft publicly threatening to take legal action against them.
