Active Vulnerability Exploitation
Articles on active exploitation of newly disclosed vulnerabilities, including zero-day attacks, memory disclosure bugs, and rapid weaponization of published CVEs by threat actors.
AI Cybersecurity Threats: Lessons from the Ivanti EPMM Zero-Day Breach in Norway
Comprehensive expanded analysis of the Ivanti EPMM zero-day exploit against Norwegian ministries, contextualized within AI cybersecurity threats, agentic security, and CISA best practices.
Calix GS7 XGS Routers Still Exposed After Public NAT Bypass Disclosure
CVE-2026-75501 leaves Calix GS5239XG gateways open to unauthenticated UPnP port-forwarding on TCP 5000, letting remote attackers bypass NAT with no patch available.
Log4Shell: How a Logging Bug Became an Enterprise Emergency
Proof-of-concept code for CVE-2021-44228 hit GitHub and triggered mass scanning, forcing urgent patches and workarounds across Java stacks.
New Windows Zero-Day Lets Attackers Seize Full Admin Control
Expanded article for twentyTaskId
Ultimate Member Plugin Zero-Day Enables Unauthenticated Admin Takeover
CVE-2023-3460 is a critical privilege escalation in the Ultimate Member WordPress plugin with over 200,000 installs. Attackers abuse registration forms to create rogue administrator accounts.
NVIDIA NEMO CLAW Networking Vulnerability Enables Ollama API Access for AI Agent Corruption
Research on NVIDIA's NEMO CLAW vulnerability that allows attackers to exploit a flaw to gain unauthenticated access to local model servers through the Ollama API, paving the way for AI agent corruption.
CERT Polska Warns of Active Zimbra RCE Exploitation as Attackers Target CVE-2026-73570
Polish Computer Emergency Response Team CERT Polska has warned that threat actors are actively exploiting a critical remote code execution vulnerability (CVE-2026-73570) in Zimbra Collaboration Suite, affecting SNMP monitoring components with enabled notifications.
PaperCut issues second emergency patch for two chained exploits
PaperCut NG and MF print management software receives Emergency Patch Release 2 for two chained vulnerabilities allowing unauthenticated remote code execution, with CVE-2026-81578 (authentication bypass, CVSS 8.8) and CVE-2026-82078 (unsafe class-loading, CVSS 9.4).
Third-Party Breach Impacts Lidl Online Customers Across Europe
Discount retailer Lidl reveals that a security breach at an external service provider has resulted in the exposure of personal customer information in Germany, Belgium, and the Netherlands. The company reports the online shop's core systems remain secure.
The wp2shell Crisis: AI Cybersecurity Threats Targeting WordPress Core at Scale
Security researchers detail how threat actors are chaining two critical WordPress Core vulnerabilities—CVE-2026-63030 and CVE-2026-60137—to deploy persistent webshells, with AI tools accelerating the exploit development process.
GodDamn Ransomware Hijacks Microsoft-Signed Driver to Kill Security Software with PoisonX BYOVD Attack
A deep technical breakdown of how the GodDamn ransomware group abused a Microsoft-signed kernel driver named PoisonX via Bring-Your-Own-Vulnerable-Driver (BYOVD) to disable endpoint protection before encrypting files—plus what defenders can actually do about it.
How a China-Linked Cluster Weaponized Roundcube Flaws Against University Cybersecurity Researchers
A China-aligned espionage group tracked by Proofpoint as UNK_MassTraction has been exploiting two known Roundcube vulnerabilities—CVE-2024-42009 (XSS) and CVE-2025-49113 (deserialization)—to compromise webmail servers at U.S. and Canadian universities, deploying credential-stealing malware and persistent backdoors targeting physics and engineering researchers.