Active Vulnerability Exploitation
Articles on active exploitation of newly disclosed vulnerabilities, including zero-day attacks, memory disclosure bugs, and rapid weaponization of published CVEs by threat actors.
ServiceNow's AI Platform Under Fire: How CVE-2026-6875 Became an Active Exploitation Target
Threat intelligence firm Defused has confirmed in-the-wild exploitation of CVE-2026-6875, a critical unauthenticated remote code execution flaw in ServiceNow's AI Platform. Attackers are using a sandbox-escape gadget that reaches code-execution via a different route than the published proof-of-concept, raising urgent patching pressure on the 85% of Fortune 500 companies that run the platform.
InfraTrust: Why Infrastructure Vulnerabilities Deserve a Different Patching Priority
Eclypsium has launched InfraTrust, a new infrastructure cybersecurity knowledge base and monthly InfraTrust Pulse report designed to help organizations prioritize vulnerabilities affecting infrastructure, firmware, networking, and edge devices based on exploitability, exposure, and real-world risk rather than CVSS scores alone.
Attackers Exploit Claude AI's Legitimate Domain to Host Malicious Installer in Bing Malvertising Campaign
A malvertising campaign on Bing uses a fake Claude desktop app installer hosted on the legitimate Claude.ai domain to deliver SectopRAT malware, compromising at least 29 organizations.
CVE-2026-50522: How SharePoint's Deserialization Flaw Lets Attackers Steal Machine Keys and Stay Forever
Hackers are actively exploiting CVE-2026-50522, a deserialization flaw in Microsoft SharePoint, to steal machine keys and maintain long-term access to compromised systems.
Check Point Patches SmartConsole Zero-Day as Artificial Intelligence Cybersecurity Threats Escalate
Israeli cybersecurity firm Check Point Software addressed CVE-2026-16232, an authentication bypass vulnerability in the SmartConsole GUI admin panel that allows unauthenticated attackers to obtain administrator credentials, prompting CISA's BOD 26-04 mandate for federal agencies.
AI Cybersecurity Threats: Why InfraTrust Forces You to Stop Chasing CVSS Scores
Eclypsium's InfraTrust report reveals how state-sponsored actors exploit infrastructure flaws before patches ship — and why your patching strategy is already obsolete.
Critical U-Boot Flaws Open Door for Stealthy Firmware Attacks Before OS Boot
Six vulnerabilities in the widely used U-Boot bootloader discovered by Binarly could allow attackers to execute malicious code during device boot before the operating system starts, potentially enabling stealthy firmware attacks that compromise security protections and install persistent malware.
CISA Mandates Immediate Remediation of Actively Exploited Langflow RCE Flaw
CISA has issued an emergency directive to U.S. federal agencies requiring the patching of a critical RCE vulnerability, CVE-2026-0770, in the Langflow framework, which is currently being exploited in the wild.
ServiceNow AI Platform RCE: How CVE-2026-6875 Went From Disclosure to Active Exploitation in Weeks
A critical pre-authentication sandbox-escape vulnerability in the ServiceNow AI Platform is being actively exploited in the wild just one week after patches for self-hosted instances were released, putting Fortune 500 enterprise workflows at risk.
OkoBot's 20-Payload Assault on Crypto Wallets Reveals a New Malware Playbook
A new malware framework called OkoBot is delivering over 20 distinct payloads in attacks targeting cryptocurrency wallet seed phrases, browser credentials, and sensitive data. The campaign, tracked by Kaspersky researchers, has been active for over a year and evolved from the TookPS infostealer. OkoBot reaches victims through ClickFix social engineering or malicious GitHub repositories masquerading as legitimate software tools.
Public Exploits Released for Critical wp2shell RCE Vulnerabilities in WordPress Core — Patch Now
Critical unauthenticated remote code execution vulnerabilities in WordPress Core (CVE-2026-63030 and CVE-2026-60137) have been weaponized in the wild, requiring immediate patching to 7.0.2 or 6.9.5.
AI Cybersecurity Threats: The Human Layer Is the Weak Link
Two Scattered Spider members sentenced to 5.5 years for TfL cyberattack—exposing how AI-enhanced social engineering is the real AI cybersecurity threat.