Cve
Curated coverage and analysis in this editorial area.

Langflow RCE Exploited for Miner Worm: 19-Day Campaign
CVE-2026-33017: Commodity operators exploit exposed AI endpoints to deploy Lambsys, an SSH worm that compromises entire enterprise inf…

CISA Confirms: BlueHammer Now Exploited by Ransomware
CISA has elevated CVE-2026-33825 to a confirmed ransomware vector. Microsoft has not updated its advisory, creating an intelligence ga…

Nissan Payroll Breach via Oracle PeopleSoft Zero-Day CVE-2026-35273
Nissan Americas confirmed a breach exposing employee payroll data and Social Security numbers across four countries through CVE-2026-3…

CVE-2026-48558: Djinn Stealer Exploited In-the-Wild on SimpleHelp
Threat actors exploit CVE-2026-48558 to deploy Djinn Stealer and TaskWeaver. The new infostealer targets AI and cloud credentials. Rou…

CVE-2026-46817: Oracle EBS Under Attack, 450+ Servers Exposed
Defused detects active exploitation of CVE-2026-46817 on Oracle EBS honeypots. CVSS 9.8, patch available since May, over 450 instances…

Gamaredon 2025: 35 Spear-Phishing Campaigns and 6 PowerShell Tools Target Ukraine
The Gamaredon APT group, attributed by Ukraine's SSU to the FSB's 18th Center for Information Security, launched 35 distinct spear-phi…

Public PoC for CVE-2026-55200: libssh2 at Risk of RCE
A working proof-of-concept for CVE-2026-55200, a critical CVSS 9.2 vulnerability in libssh2, was released on June 23, 2026. The pre-au…

ATEN Unizon: Authenticated Bug Deletes Files, CVSS 5.5 Understates Risk
Directory traversal in ATEN Unizon's uploadSSL lets an authenticated attacker delete arbitrary files. The CVSS 5.5 rating masks real o…

ZDI-26-397: Use-After-Free in X.Org Server Opens Door to Local Privilege Escalation
A Use-After-Free flaw in X.Org Server's CreateSaverWindow function (CVE-2026-50263) lets a local low-privilege attacker leak sensitive…

CVE-2026-12957: Cloud Credential Theft via Amazon Q Developer
A high-severity vulnerability (CVSS 8.5) in the Amazon Q Developer extension for VS Code allowed automatic execution of malicious MCP…

CVE-2026-46331: Linux 'pedit COW' Exploit Gains Root in 24 Hours
A Linux kernel bug corrupts the page cache of setuid binaries such as /bin/su without touching disk, bypassing all integrity checks.

DirtyClone: The Fourth Variant in the DirtyFrag Family
CVE-2026-43503, the fourth variant in the DirtyFrag family, exploits cloned packets to corrupt file-backed memory. JFrog published a f…