A maximum-severity command injection vulnerability in on-premises versions of Arista VeloCloud Orchestrator (VCO) is being actively exploited. Tracked as CVE-2026-16812 with a…
Security firms ThreatBook and Imperva report active exploitation of a critical remote code execution vulnerability in Alibaba's Fastjson 1.x JSON library for…
A critical unpatched vulnerability in Alibaba Fastjson library (versions 1.2.68-1.2.83) with CVSS 9.0, allowing remote code execution without user interaction. Developers urged…
Researchers have demonstrated that open-source Android AI agent frameworks are vulnerable to a novel attack chain where invisible screen text can lead…
Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator first documented earlier this…
A critical unpatched vulnerability, dubbed XRING, has been disclosed in XQUIC, Alibaba's open-source QUIC and HTTP/3 library. Discovered by FoxIO researcher Sébastien…