Zimbra Flaw Exploited Before Disclosure
Microsoft says attackers probed and exploited a Zimbra command injection flaw in the window between patch release and public disclosure.
30 results for “code”
Microsoft says attackers probed and exploited a Zimbra command injection flaw in the window between patch release and public disclosure.
Google's threat intelligence unit reports AI-found vulnerabilities are far more likely to enable remote code execution than other disclosed flaws.
WatchGuard fixed a critical Fireware OS code injection flaw and 13 high-severity bugs, plus three Access Point vulnerabilities disclosed a day earlier.
F5 patched a critical BIG-IP APM zero-day exploited in remote code execution attacks, as CISA ordered federal agencies to secure networks by Friday.
WordPress fixed a critical flaw in versions 4.7.0 through 7.1.1 that can lead to code execution on servers lacking a page-prefixed theme folder and register_argc_argv off.
Microsoft and partners disrupted EvilTokens, an AI-assisted phishing service that compromised 12,000 accounts, seizing domains and prompting arrests.
Microsoft-led coalition seizes 50 phishing sites and disables 150 domains tied to an AI-enabled service that compromised 12,000 inboxes.
Sekoia says the Exvicy framework reuses ErrTraffic's code and has been spotted delivering malware via compromised WordPress sites.
CrowdSec says about 300 repositories were hit and links the theft to a May 2026 TanStack supply chain attack.
Researchers chained an ImageMagick flaw with an OpenAI sign-in issue to reach internal code, earning a bounty.
A new WordPress core flaw lets a crafted link silently install a theme, and researchers chained it to full code execution.
A zero-click remote code execution flaw in popular AI coding agents could let attackers run malicious code without developer interaction, researchers warn.
A new phishing kit abuses Microsoft's device-code flow to bypass MFA and establish persistent access to Microsoft 365 environments.
Two Docker Sandboxes vulnerabilities let malicious guest code read or modify macOS host files, with fixes shipped in version 0.42.0.
A hardcoded Cloudflare key let attackers rewrite Brevo's sites and customer scripts for hours, pushing ClickFix malware at scale.
A heap overflow in Unbound's DNSSEC validator lets attackers who control a malicious DNS zone trigger remote code execution on vulnerable resolvers.
Attackers are exploiting a critical WooCommerce Wholesale Lead Capture vulnerability to upload PHP web shells and achieve remote code execution.
A Zurich court found the 52-year-old Ukrainian developer built LockerGoga, MegaCortex, and Nefilim, though not as the operations' mastermind.
Cisco warns CVE-2026-76461, a CVSS 9.8 flaw in Secure Email Gateway, is being exploited to run commands as root, with a federal patch deadline of September 17.
A new draft code of conduct would block its MAI models from generating working exploit code while opening a review track for defensive security work.
Sysdig says a hand-built toolkit let a human operator exploit a Marimo flaw in eight seconds, without any sign of LLM use.
Security researcher finds a hardcoded admin account in a Temu-bought Wi-Fi extender, giving remote attackers full control.
Microsoft ties passkey-themed social engineering to extortion gangs that blend into Microsoft 365 traffic to steal files and email.
Two 9.8-rated certificate flaws in Check Point gateways carry fixes that some customers say they cannot access.
Google's September 2026 Android updates fix 180 vulnerabilities, including 26 critical flaws, after two consecutive bulletins with no security fixes.
Ivanti addresses critical and high-severity vulnerabilities across Neurons for ITSM, Sentry, and EPMM, urging immediate updates.
Microsoft finds invisible Unicode tags used to hide financial-lure words in a massive email phishing campaign.
Broadcom patched one critical and one high-severity VMware Workstation and Fusion vulnerability, both enabling host code execution.
A campaign hides 'funding' lure words with invisible Unicode tags, splitting keywords to slip past filters.
A 12-year-old PostgreSQL flaw lets low-privilege replication accounts gain superuser access and remote code execution across platforms.