Exploit
Curated coverage and analysis in this editorial area.

Cloud Atlas Upgrades Arsenal: Novel Backdoors and Stealth RDP Patching for Cyber-Espionage
Between 2025 and 2026, the Cloud Atlas APT deployed previously undocumented backdoors, VBCloud and PowerShower, alongside modified sys…

Unit 42: Frontier AI Models Exploiting Open-Source Transparency to Automate Supply Chain Attacks
Frontier AI models are demonstrating the autonomous reasoning required to identify vulnerabilities in open-source code and orchestrate…

Ransomware 2026: Extortion Tactics Pivot Beyond File Encryption
Kaspersky’s May 12, 2026 report reveals a fundamental shift in the threat landscape: as encryption loses its leverage, attackers are p…

Mirai Variant Targets EOL TP-Link Routers via Flawed Exploit for Valid Vulnerability
Unit 42 has identified active exploitation attempts targeting CVE-2023-33538 on end-of-life TP-Link routers. While current in-the-wild…

Frontier AI: The Shift from Coding Assistant to Autonomous Threat Agent
Research from Unit 42 reveals that frontier AI models now possess the autonomous reasoning capabilities of full-spectrum security rese…

BitLocker Bypassed: New Zero-Day Trio Targets Windows Following Patch Tuesday
An analysis of the YellowKey, GreenPlasma, and MiniPlasma vulnerabilities disclosed shortly after the May 2026 Patch Tuesday, impactin…

Verizon DBIR 2026: Vulnerability Exploitation Overtakes Credentials as Patching Cycles Falter
The 2026 Verizon DBIR marks a structural shift in the threat landscape: vulnerability exploitation (31%) has surpassed credential abus…

SEPPMail Security Crisis: Seven Critical Flaws Grant Full Access to Corporate Email
A cluster of seven vulnerabilities in the SEPPMail Secure E-Mail Gateway, including flaws with CVSS scores up to 10.0, enables unauthe…

18-Year-Old NGINX Bug CVE-2026-42945 Under Active Attack
Exploitation attempts are underway for CVE-2026-42945, an 18-year-old heap buffer overflow in the NGINX rewrite module. The flaw enabl…

NGINX Rift: Active Exploitation of CVE-2026-42945 Detected In the Wild
In-the-wild attacks targeting CVE-2026-42945 (NGINX Rift) began on May 16, 2026. Security researchers analyze the critical heap buffer…

Ollama Flaws Expose Local LLM Memory and Enable Windows Malware Persistence
Three critical CVEs in Ollama allow unauthenticated remote attackers to leak LLM process memory via crafted GGUF files and achieve per…

CVE-2026-42945: Active Exploitation of NGINX Servers Underway
CVE-2026-42945 is being actively exploited in the wild, targeting NGINX rewrite modules to trigger immediate DoS or conditional RCE. C…