Find a story
Search Spins
Search titles, summaries, and missing voices across published articles — press releases, announcements, and media coverage.
31 results for “exploitation”
Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
CISA added four critical vulnerabilities — affecting macOS, SharePoint, vCenter, and Microsoft IKE — to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild.
Aug 19, 2026
Critical GitLab Zero-Click Flaw Poses Mitigation Challenges
A critical zero-click vulnerability (CVE-2026-19478) in self-managed GitLab instances lacks public technical details, hindering detection and mitigation for affected organizations.
Aug 19, 2026
CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE
CISA added a critical, actively exploited vulnerability in the Ray distributed computing framework to its Known Exploited Vulnerabilities catalog, signaling immediate risk to AI/ML infrastructure relying on Ray.
Aug 18, 2026
Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS
Evooo1Bot, a Linux-based botnet, extends Mirai's original DDoS-focused design by integrating exploitation modules, credential theft, and reverse SOCKS relays—transforming infected devices into long-term, multi-purpose attacker infrastructure.
Aug 17, 2026
Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers
A cybersecurity research team disclosed a post-exploitation technique exploiting Chrome DevTools Protocol (CDP) in live Windows browser processes to hijack authenticated sessions, requiring prior code execution on the host.
Published Aug 14, 2026 · Analyzed Aug 17, 2026
Global Threat Campaign Hits Critical VMware vCenter Flaw
A global threat campaign is actively exploiting CVE-2026–59310, a critical vulnerability in VMware vCenter, and patching alone may not fully mitigate the risk.
Aug 14, 2026
GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE
A zero-day SQL injection vulnerability in the open-source GeoServer platform is under active exploitation, enabling remote code execution, with no patch yet available and no assigned CVE identifier.
Published Aug 13, 2026 · Analyzed Aug 17, 2026
Mechanism Design for Generative Engines: From Exploitation toward Win-Win Outcomes
Researchers propose VCR, a new mechanism for generative engines that rewards verifiable content rewrites to align platform and creator incentives and mitigate 'citation wars' driven by model optimization.
Aug 13, 2026
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
Lazarus Group exploited an unpatched Windows vulnerability to deploy a novel backdoor against defense and aerospace firms in four countries, as identified by Check Point Research.
Aug 13, 2026
Progressive Content Refinement with Decaying Reward Joint LinUCB
Researchers introduced a new contextual bandit algorithm called Decaying Reward Joint LinUCB that models reward decay to prevent over-exploitation in LLM iterative refinement, showing improved performance on Sentiment Reversal and GSM8K benchmarks.
Aug 10, 2026
N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
N-able issued Hotfix 2 for its N-central RMM platform to address active exploitation of a recently disclosed security vulnerability, following observed attacker persistence in managed environments.
Aug 8, 2026
Barry Gosin quittera ses fonctions de CEO de Newmark Group Inc. à la fin de l'année ; il restera président du conseil d'administration de Newmark & Co. Real Estate, la société d'exploitation de Newmark
Barry Gosin will step down as CEO of Newmark Group Inc. at year-end but remain Chairman of the Board of Newmark & Co. Real Estate, the operating subsidiary.
Aug 8, 2026
CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild
CISA added CVE-2026-63077 — a critical remote code execution vulnerability in on-premise JetBrains TeamCity — to its Known Exploited Vulnerabilities catalog due to confirmed active exploitation.
Aug 6, 2026
Hackers run khunt post-exploitation toolkit from Oracle database
Attackers leveraged a SQL injection flaw to deploy the Khunt post-exploitation toolkit inside an Oracle database, enabling lateral movement and persistence within a corporate network.
Aug 6, 2026
Rethinking Self-Evolution: A Constrained Exploration-Exploitation Process for Mitigating Skill Overfitting
A new research paper introduces SkillBoost, a three-stage framework to reduce skill overfitting in LLM agents by constraining exploration-exploitation during self-evolution of skills using prior-guided candidate generation and regression-bounded acceptance.
Jul 31, 2026
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
Russian threat actors exploited an unpatched vulnerability in Microsoft Outlook Web Access (OWA) to maintain persistent mailbox access after credential rotation, targeting government and critical infrastructure entities across the U.S., Europe, and multiple sectors.
Jul 30, 2026
Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
A zero-day vulnerability (CVE-2026-20316) in Cisco Secure Firewall Management Center (FMC) software is actively exploited, allowing unauthenticated remote access via static credentials — posing a material risk to organizations relying on this critical network security infrastructure.
Jul 30, 2026
Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
A critical authentication bypass vulnerability (CVE-2026-16232, CVSS 9.3) in Check Point’s SmartConsole login process has been actively exploited in the wild, and researchers have now released a public proof-of-concept exploit.
Jul 29, 2026
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
A critical command injection vulnerability (CVE-2026-16812, CVSS 10.0) in Arista’s on-premises VeloCloud Orchestrator is being actively exploited, enabling remote arbitrary code execution.
Jul 28, 2026
Hermes AI agent used to automate attack on Thai Finance Ministry
A threat actor allegedly used the open-source Hermes AI agent in autonomous 'YOLO' mode to automate post-exploitation actions during a cyber intrusion targeting Thailand's Ministry of Finance.
Jul 25, 2026
Russian hackers exploit Zimbra zero-click flaw for email theft
A Russian state-sponsored hacking group exploited a zero-click vulnerability in Zimbra Collaboration email servers to steal emails, prompting a CISA advisory and remediation guidance.
Jul 23, 2026
Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
Check Point released emergency patches for an actively exploited authentication bypass vulnerability (CVE-2026-16232, CVSS 9.3) in SmartConsole that grants full administrative access without credentials.
Jul 23, 2026
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
A high-severity unauthenticated path traversal vulnerability (CVE-2026-29059, CVSS 7.5) in Windmill’s get_log_file endpoint is actively exploited in the wild, enabling attackers to read arbitrary server files without authentication.
Jul 22, 2026
N-day is Becoming N-Hour. Patching Faster Won't Save You.
N-day exploitation is accelerating from days to hours as attackers reverse-engineer patches to build exploits faster than defenders can deploy updates, undermining traditional patch-based security models.
Jul 21, 2026