Category: Vulnerability

WeChat zero-click worm exploiting WeChat VoIP memory corruption 0

WeChat Zero-Click Worm Exposed in New Security Advisory

Researchers at Calif developed the first zero-click worm for WeChat. This WeChat zero-click worm spreads through automated calls across iOS and Android platforms. Tencent has already mitigated this critical threat on their servers. Why...

Active N-central vulnerability exploitation showing remote N-central vulnerability attacks 0

CVE-2026-86218 Pre-Auth RCE CVSS 10 Exploited in Wild

TL;DR On September 6, 2026, N-able released an urgent security update fixing an actively exploited zero-day flaw. The critical N-central vulnerability allows remote unauthenticated attackers to execute arbitrary code with root privileges. Consequently, administrators...

Citrix NetScaler Gateway authentication bypass attack diagram 0

Citrix NetScaler Targeted in Rapid Exploitation Campaign

Malicious actors have commenced active attacks against Citrix NetScaler infrastructure. They are exploiting the critical vulnerability designated as CVE-2026-19490. This severe flaw enables remote adversaries to circumvent authentication protocols entirely. Consequently, they gain illicit...

A conceptual image showing an AI coding agent executing a hidden malicious command from a compromised Git repository. 0

GitSpawn Exposes AI Coding Agents

A seemingly ordinary project folder can transform into a dangerous trap. This trap springs before the developer even executes their first command. Manifold Security researchers recently discovered a critical vulnerability class named GitSpawn. These...

An abstract visual representation of the powerful OpenAI Astra model independently identifying vulnerabilities and constructing zero-day exploits. 0

OpenAI Classifies Astra as Critical Threat

Artificial intelligence recently breached a crucial internal OpenAI boundary. Basic safeguards against malicious requests simply no longer suffice. The company officially recognized Astra as its first model possessing critical cybersecurity capabilities. During rigorous testing,...

Langflow CVE-2026-0768 exploitation harvesting OpenAI and AWS keys from an exposed AI application server 0

Langflow Flaw Exploited to Steal OpenAI and AWS Keys

Servers for developing AI applications have become vaults of valuable secrets, accessible through a single unprotected request. Attackers have begun exploiting the critical vulnerability CVE-2026-0768 in Langflow to extract OpenAI and AWS keys, administrator...

A conceptual image representing malicious code hidden within image pixels exploiting a Ruby on Rails server 0

KindaRails2Shell Strikes Ruby Servers

A critical Ruby on Rails vulnerability rapidly escalated from a theoretical threat into an active weapon. VulnCheck recently detected active exploitation of CVE-2026-66066. The cybersecurity community commonly refers to this severe flaw as KindaRails2Shell....

Hacker attacking a vulnerable Gitea server through an open registration portal 0

Critical Gitea RCE Vulnerability Under Attack

Open registration on developer platforms generally streamlines onboarding processes. However, concerning Gitea, this convenience inadvertently transformed a critical vulnerability into an easily accessible intrusion point. The Shadowserver Foundation recently identified a staggering 8,393 internet-facing...