SharePoint Flaw Exploited After PoC Release
Threat actors are exploiting a critical SharePoint authentication bypass after Rapid7 released a PoC exploit.
From zero-day disclosures to routine patch Tuesdays, this is Xploitwire's feed on the vulnerabilities and advisories that security teams actually need to act on — what's exploitable, what's patched, and what to prioritize first.
Threat actors are exploiting a critical SharePoint authentication bypass after Rapid7 released a PoC exploit.
A researcher's PoC bypasses Microsoft's Defender patch, granting system-level access to attackers with initial foothold.
Signal launches Automatic Key Verification to detect man-in-the-middle attacks, but users must still verify contacts manually.
New WindRelay malware works with SpyNote RAT to steal card data and approve loans during a 13-minute call.
Researchers show fake USB devices can trigger Windows to install vulnerable vendor software, granting SYSTEM privileges.
New Lazarus campaign abuses Windows zero-day and fake job lures to breach defense firms, fooling Google's filters.
State and FBI warnings highlight how fake remote workers bypass hiring controls to gain network access.
Researchers uncover 'City-Forum' campaign using a custom toolset to exploit unauthenticated guest access in Salesforce and ServiceNow.
ACRO's unpatched Kentico CMS exposed sensitive data of up to 10,920 people, with alerts unread for months.
Malwarebytes finds fake CCleaner downloads installing GhostDesk Chrome extension for credential theft and surveillance.
CloudSEK details how a Trivy compromise cascaded into LiteLLM, affecting 2,500+ orgs and 434,000 pipelines.
Attacks exploiting CVE-2026-59310 target hundreds of victims, deploying reverse_ssh for persistent access.
Intel and AMD release combined patches for more than 80 vulnerabilities, including high-severity issues in processors and software.
Ivanti releases updates for Endpoint Manager and Neurons for MDM addressing remotely exploitable vulnerabilities.
August 2026 ICS Patch Tuesday advisories from Siemens, Schneider Electric, Phoenix Contact address critical vulnerabilities, including a maximum-severity flaw in Siemens IoT devices.
Google says Chrome's layered defenses cut unwanted Android notifications by over 7 billion daily in Q1 2026.
DeadLock ransomware stores config data on Polygon blockchain, complicating infrastructure takedowns by law enforcement.
Passengers on Delta 591 reportedly spoofed onboard Wi-Fi after DEF CON, prompting an FBI inquiry.
A high-severity ASA and FTD vulnerability is being exploited to crash devices remotely; hot fixes are available.
August's Patch Tuesday addresses 398 vulnerabilities, including an actively exploited zero-day, as AI-driven discovery swells update volumes.