Oracle Database Hijacked for Tool Storage
Researchers identified a post-exploitation toolkit concealed within Oracle database schema objects to bypass endpoint security tools.
From zero-day disclosures to routine patch Tuesdays, this is Xploitwire's feed on the vulnerabilities and advisories that security teams actually need to act on — what's exploitable, what's patched, and what to prioritize first.
Researchers identified a post-exploitation toolkit concealed within Oracle database schema objects to bypass endpoint security tools.
A high-severity cryptographic key derivation vulnerability in IBM Langflow OSS could allow unauthorized access to sensitive data.
A cryptographic weakness in IBM Langflow OSS allows attackers to reproduce encryption keys, potentially exposing stored API keys and authentication tokens.
A deserialization vulnerability in JetBrains TeamCity is under active exploitation, forcing federal agencies to patch systems by August 8, 2026.
A critical SQL injection vulnerability in Loca Software CMS allows unauthorized attackers to gain full control over affected database systems.
Expert Edna Conway argues that true digital resilience requires moving past checkbox compliance to address complex supply chain risks.
Continuous Threat Exposure Management faces a critical hurdle as organizations struggle to move past theory into active operations.
New research reveals widespread security flaws in baseboard management controllers across major global server manufacturers.
An unauthenticated remote code execution vulnerability in Nuxt DevTools allows attackers to run arbitrary commands on developer machines via the HMR port.
A critical remote code execution vulnerability in Flowise allows low-privileged attackers to gain root access on vulnerable servers via CSV Agent code injection.
A critical remote code execution vulnerability in Flowise's CSVAgent allows attackers to bypass python code filters using pandas read_pickle deserialization.
Security researchers uncovered vulnerabilities in WebKit that allow websites to bypass Apple's Private Relay and view IP addresses.
A Tennessee congressional candidate faces felony vandalism charges after allegedly shooting automated license plate readers.
The Linux Foundation and the Open Secure AI Alliance have proposed the SAFE framework to collect and analyze agentic AI incident data.
New research shows that the choice of AI orchestration framework can increase agent compromise rates by more than 2.6 times.
An appellate court has affirmed that the creation of a web browser does not constitute a violation of the CFAA.
A critical PHP object injection vulnerability in MaxSite CMS allows unauthenticated attackers to execute arbitrary code via a malicious cookie.
A critical remote code execution vulnerability in MaxSite CMS allows unauthenticated attackers to inject malicious PHP code into configuration files.
The integrity of the CVE database is under threat as automated, AI-generated reports exacerbate existing backlogs at NIST.
A report from the Electronic Frontier Foundation examines the implications of mobile ad software and user location data sharing.