Threat actors have begun exploiting a newly disclosed Microsoft SharePoint vulnerability, CVE-2026-55040 (CVSS 9.1), following the public release of a proof-of-concept (PoC)…
Security researchers at Rapid7 have disclosed an AI-assisted exploit chain targeting Microsoft SharePoint Server that allows unauthenticated attackers to achieve remote code…
Two critical vulnerabilities in Paperclip, an open-source control plane for AI agents, could allow attackers to execute arbitrary commands on a server…
INC Ransomware has emerged as the dominant threat actor exploiting recently disclosed vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN…
The article discusses how AI models like Anthropic's Mythos are compressing exploit timelines, forcing a reevaluation of vulnerability management strategies. It argues…
AI SecurityAnthropicArtificial Intelligenceattack path prioritization
Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain…
authentication bypassCheck PointCheck Point Security Management ServerCVE-2026-16232
Zimbra has released security updates addressing nine vulnerabilities in Zimbra 10.1.20, including a critical command injection flaw in the Simple Network Management…
Classic Web Clientcommand injectionCVE-2026-50055email security
A malware operator left its delivery server exposed, allowing Rapid7 to recover a full toolkit of 1,048 files including lure templates, filename-spoofing…
A previously undocumented threat actor, tracked as UTA0533 by Volexity, exploited two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series…
Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a proof-of-concept (PoC) exploit called LegacyHive, targeting a Windows User Profile Service (ProfSvc) arbitrary…