vulnerability

Concerns Raised Over CISA’s Silent Ransomware Updates in KEV Catalog

Concerns Raised Over CISA’s Silent Ransomware Updates in KEV Catalog 2026-02-06 at 08:00 By Eduard Kovacs CISA updated 59 KEV entries in 2025 to specify that the vulnerabilities have been exploited in ransomware attacks. The post Concerns Raised Over CISA’s Silent Ransomware Updates in KEV Catalog appeared first on SecurityWeek. This article is an excerpt […]

Concerns Raised Over CISA’s Silent Ransomware Updates in KEV Catalog Read More »

CISA confirms exploitation of VMware ESXi flaw by ransomware attackers

CISA confirms exploitation of VMware ESXi flaw by ransomware attackers 2026-02-05 at 18:17 By Zeljka Zorz CVE-2025-22225, a VMware ESXi arbitrary write vulnerability, is being used in ransomware campaigns, CISA confirmed on Wednesday by updating the vulnerability’s entry in its Known Exploited Vulnerabilities (KEV) catalog. Researchers linked VMware ESXi zero-day trio to single exploit toolkit

CISA confirms exploitation of VMware ESXi flaw by ransomware attackers Read More »

VS Code Configs Expose GitHub Codespaces to Attacks

VS Code Configs Expose GitHub Codespaces to Attacks 2026-02-05 at 16:59 By Ionut Arghire VS Code-integrated configuration files are automatically executed in Codespaces when the user opens a repository or pull request. The post VS Code Configs Expose GitHub Codespaces to Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

VS Code Configs Expose GitHub Codespaces to Attacks Read More »

Critical N8n Sandbox Escape Could Lead to Server Compromise

Critical N8n Sandbox Escape Could Lead to Server Compromise 2026-02-05 at 14:02 By Ionut Arghire The vulnerability could allow attackers to execute arbitrary commands and steal credentials and other secrets. The post Critical N8n Sandbox Escape Could Lead to Server Compromise appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical N8n Sandbox Escape Could Lead to Server Compromise Read More »

Cisco, F5 Patch High-Severity Vulnerabilities

Cisco, F5 Patch High-Severity Vulnerabilities 2026-02-05 at 12:06 By Ionut Arghire The security defects can lead to DoS conditions, arbitrary command execution, and privilege escalation. The post Cisco, F5 Patch High-Severity Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Cisco, F5 Patch High-Severity Vulnerabilities Read More »

Vulnerabilities Allowed Full Compromise of Google Looker Instances

Vulnerabilities Allowed Full Compromise of Google Looker Instances 2026-02-04 at 15:45 By Eduard Kovacs The flaws dubbed LookOut can be exploited for remote code execution and data exfiltration. The post Vulnerabilities Allowed Full Compromise of Google Looker Instances appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Vulnerabilities Allowed Full Compromise of Google Looker Instances Read More »

DockerDash Flaw in Docker AI Assistant Leads to RCE, Data Theft

DockerDash Flaw in Docker AI Assistant Leads to RCE, Data Theft 2026-02-04 at 13:48 By Ionut Arghire The critical vulnerability exists in the contextual trust in MCP Gateway architecture, as instructions are passed without validation. The post DockerDash Flaw in Docker AI Assistant Leads to RCE, Data Theft appeared first on SecurityWeek. This article is

DockerDash Flaw in Docker AI Assistant Leads to RCE, Data Theft Read More »

Major vulnerabilities found in Google Looker, putting self-hosted deployments at risk

Major vulnerabilities found in Google Looker, putting self-hosted deployments at risk 2026-02-04 at 13:25 By Help Net Security Researchers at Tenable have disclosed two vulnerabilities, collectively referred to as “LookOut,” affecting Google Looker. Because the business intelligence platform is deployed by more than 60,000 organizations in 195 countries, the flaws could give attackers a path

Major vulnerabilities found in Google Looker, putting self-hosted deployments at risk Read More »

Cryptominers, Reverse Shells Dropped in Recent React2Shell Attacks

Cryptominers, Reverse Shells Dropped in Recent React2Shell Attacks 2026-02-04 at 12:02 By Ionut Arghire Two IP addresses accounted for the majority of the 1.4 million exploitation attempts observed over the past week. The post Cryptominers, Reverse Shells Dropped in Recent React2Shell Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Cryptominers, Reverse Shells Dropped in Recent React2Shell Attacks Read More »

Fresh SolarWinds Vulnerability Exploited in Attacks

Fresh SolarWinds Vulnerability Exploited in Attacks 2026-02-04 at 11:56 By Ionut Arghire The critical-severity SolarWinds Web Help Desk flaw could lead to unauthenticated remote code execution. The post Fresh SolarWinds Vulnerability Exploited in Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Fresh SolarWinds Vulnerability Exploited in Attacks Read More »

Security Analysis of Moltbook Agent Network: Bot-to-Bot Prompt Injection and Data Leaks

Security Analysis of Moltbook Agent Network: Bot-to-Bot Prompt Injection and Data Leaks 2026-02-04 at 10:47 By Eduard Kovacs Wiz and Permiso have analyzed the AI agent social network and found serious security issues and threats. The post Security Analysis of Moltbook Agent Network: Bot-to-Bot Prompt Injection and Data Leaks appeared first on SecurityWeek. This article

Security Analysis of Moltbook Agent Network: Bot-to-Bot Prompt Injection and Data Leaks Read More »

Russian hackers are exploiting recently patched Microsoft Office vulnerability (CVE-2026-21509)

Russian hackers are exploiting recently patched Microsoft Office vulnerability (CVE-2026-21509) 2026-02-03 at 17:21 By Zeljka Zorz Russian state-sponsored hackers Fancy Bear (aka APT 28) are exploiting CVE-2026-21509, a Microsoft Office vulnerability for which Microsoft released an emergency fix last week. The exploitation CVE-2026-21509 allows unauthorized attackers to bypass a security feature (OLE mitigations in Microsoft

Russian hackers are exploiting recently patched Microsoft Office vulnerability (CVE-2026-21509) Read More »

Critical React Native Vulnerability Exploited in the Wild

Critical React Native Vulnerability Exploited in the Wild 2026-02-03 at 16:01 By Ionut Arghire Albeit mainly considered a theoretical risk, the flaw has been exploited to disable protections and deliver malware. The post Critical React Native Vulnerability Exploited in the Wild appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical React Native Vulnerability Exploited in the Wild Read More »

Vulnerability Allows Hackers to Hijack OpenClaw AI Assistant 

Vulnerability Allows Hackers to Hijack OpenClaw AI Assistant  2026-02-03 at 15:49 By Eduard Kovacs OpenClaw (aka Moltbot and Clawdbot) is vulnerable to one-click remote code execution attacks. The post Vulnerability Allows Hackers to Hijack OpenClaw AI Assistant  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Vulnerability Allows Hackers to Hijack OpenClaw AI Assistant  Read More »

The Week in Vulnerabilities: Open-Sources Fixes Urged by Cyble

The Week in Vulnerabilities: Open-Sources Fixes Urged by Cyble 2026-02-03 at 15:15 By Ashish Khaitan Cyble Vulnerability Intelligence researchers tracked 1,147 vulnerabilities in the last week, and more than 128 of the disclosed vulnerabilities already have a publicly available Proof-of-Concept (PoC), significantly increasing the likelihood of real-world attacks.  A total of 108 vulnerabilities were rated as critical under the CVSS v3.1 scoring system, while 54 received a critical severity rating

The Week in Vulnerabilities: Open-Sources Fixes Urged by Cyble Read More »

Aisy Launches Out of Stealth to Transform Vulnerability Management

Aisy Launches Out of Stealth to Transform Vulnerability Management 2026-01-30 at 17:19 By Kevin Townsend Aisy has emerged from stealth mode with $2.3 million in seed funding for its AI-assisted platform. The post Aisy Launches Out of Stealth to Transform Vulnerability Management appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Aisy Launches Out of Stealth to Transform Vulnerability Management Read More »

Ivanti Patches Exploited EPMM Zero-Days

Ivanti Patches Exploited EPMM Zero-Days 2026-01-30 at 10:33 By Eduard Kovacs The critical-severity vulnerabilities could allow unauthenticated attackers to execute arbitrary code remotely. The post Ivanti Patches Exploited EPMM Zero-Days appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Ivanti Patches Exploited EPMM Zero-Days Read More »

ShadowHS: A Fileless Linux Post‑Exploitation Framework Built on a Weaponized hackshell

ShadowHS: A Fileless Linux Post‑Exploitation Framework Built on a Weaponized hackshell 2026-01-30 at 07:09 By rohansinhacyblecom Executive Summary Cyble Research & Intelligence Labs (CRIL) has identified a Linux intrusion chain leveraging a highly obfuscated, fileless loader that deploys a weaponized variant of hackshell entirely from memory. Cyble tracks this activity under the name ShadowHS, reflecting

ShadowHS: A Fileless Linux Post‑Exploitation Framework Built on a Weaponized hackshell Read More »

N8n Vulnerabilities Could Lead to Remote Code Execution

N8n Vulnerabilities Could Lead to Remote Code Execution 2026-01-29 at 17:29 By Ionut Arghire The two bugs impacted n8n’s sandbox mechanism and could be exploited via weaknesses in the AST sanitization logic. The post N8n Vulnerabilities Could Lead to Remote Code Execution appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

N8n Vulnerabilities Could Lead to Remote Code Execution Read More »

SolarWinds Patches Critical Web Help Desk Vulnerabilities

SolarWinds Patches Critical Web Help Desk Vulnerabilities 2026-01-29 at 15:49 By Ionut Arghire The four critical flaws could be exploited without authentication for remote code execution or authentication bypass. The post SolarWinds Patches Critical Web Help Desk Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

SolarWinds Patches Critical Web Help Desk Vulnerabilities Read More »

Scroll to Top