Security researcher Chinmohan Nayak has detailed a WhatsApp-to-host attack chain leveraging three now-patched vulnerabilities in the OpenClaw personal AI assistant. The flaws,…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence…
Adobe has released critical security updates addressing multiple maximum-severity vulnerabilities in Adobe ColdFusion and Adobe Campaign Classic. The patches fix seven CVSS…
CVE-2023-32315 is a path traversal vulnerability in Openfire, an XMPP server. It was exploited in the StrikeShark campaign to target Taiwanese software…
A high-severity path traversal vulnerability in Langflow, designated CVE-2026-5027 (CVSS 8.8), is being actively exploited in the wild. Discovered by Tenable, the…
Threat actors are actively exploiting three security vulnerabilities in Fortinet FortiSandbox, according to threat intelligence firm Defused Cyber. The flaws include CVE-2026-39813…
Active DirectoryAI-generated exploitcommand injectioncredential harvesting
A path traversal vulnerability in FortiSandbox JRPC API that could allow an unauthenticated attacker to bypass authentication via specially crafted HTTP requests.…
Cybersecurity researchers at Zafran Security have disclosed four vulnerabilities in Dify, an open-source agentic workflow platform with over 146,000 GitHub stars, collectively…
AI SecurityCloud SecurityCVE-2024-5846CVE-2026-11645