Autonomous AI Weaponization at Scale
Researchers have identified a threat actor using the DeepSeek AI model to automate the lifecycle of cyberattacks on exposed servers.
30 results for “exploit”
Researchers have identified a threat actor using the DeepSeek AI model to automate the lifecycle of cyberattacks on exposed servers.
A static credential vulnerability in Cisco Secure FMC Software is undergoing active exploitation in the wild, according to the company.
New data from VulnCheck reveals that AI-assisted vulnerability discovery is not yet driving a surge in real-world exploitation.
New research shows AI-discovered flaws are exploited at the same rate as traditional ones, debunking 'vulnpocalypse' fears.
A critical OS command injection vulnerability in Arista VeloCloud Orchestrator is now confirmed to be exploited in the wild.
Threat actors are exploiting technical support discussions on Steam to trick gamers into executing malicious PowerShell cryptominers.
A critical vulnerability in Auth.js and NextAuth allows attackers to intercept magic-link sign-in flows by exploiting improper Unicode normalization.
A newly public exploit targeting GitLab reveals how silent patches for library bugs can leave critical vulnerabilities exposed.
Threat actors are exploiting a severe vulnerability in PTC Windchill and FlexPLM to exfiltrate sensitive enterprise product data.
A critical vulnerability in Budibase allows attackers to hijack existing user accounts by exploiting improper email validation in the OIDC login process.
A newly uncovered intrusion suggests threat actors are leveraging autonomous AI tools to streamline lateral movement and enumeration.
A sophisticated campaign by the threat group Laundry Bear has bypassed user interaction to harvest sensitive government data.
A red teamer exploited human behavior to gain unauthorized access to a hospital records room, highlighting significant security gaps.
A critical remote code execution vulnerability identified in SolarWinds Serv-U requires domain administrator access to exploit.
WordPress Core is under active attack via an interpretation conflict vulnerability that allows for SQL injection and remote code execution.
WordPress Core is currently under active exploitation via a SQL injection vulnerability that can be chained to achieve remote code execution.
Enterprise AI systems face active exploitation of a high-complexity remote code execution flaw following a recent patch release.
A pair of newly identified vulnerabilities dubbed WP2Shell are being actively exploited in the wild, triggering forced site updates.
A sophisticated threat actor utilized zero-day exploits to gain deep access to SonicWall VPN appliances before official patches existed.
ACR Stealer exploits user-executed commands to siphon session tokens and files, bypassing traditional software vulnerabilities.
Federal agencies must address an actively exploited OS command injection vulnerability in Fortinet products by July 19, 2026.
A critical deserialization vulnerability in Microsoft SharePoint is currently being exploited in the wild, requiring immediate action from federal agencies.
CISA has confirmed active exploitation of an OS command injection vulnerability in Fortinet FortiSandbox, mandating urgent remediation for federal agencies.
A deserialization vulnerability in Microsoft SharePoint is currently being exploited in the wild, prompting an urgent remediation deadline for federal agencies.
A critical account lockout vulnerability in KNX Association products is now under active exploitation, requiring immediate remediation by federal agencies.
An improper privilege management flaw in Oracle E-Business Suite is being actively exploited, potentially allowing unauthorized access to Oracle Payments.
A critical account lockout vulnerability in the KNX Protocol Connection Authorization Option 1 is currently being exploited in the wild.
An improper privilege management vulnerability in Oracle E-Business Suite is currently being exploited in the wild, risking full takeover of Oracle Payments.
A modular, C-based threat is weaponizing social engineering tactics to gain administrative control over compromised Windows systems.
Researchers demonstrated that a frontier language model can navigate a full attack chain to reach admin-level access in under 40 minutes.