ProBackend
Active Vulnerability Exploitation

Active Vulnerability Exploitation

Articles on active exploitation of newly disclosed vulnerabilities, including zero-day attacks, memory disclosure bugs, and rapid weaponization of published CVEs by threat actors.

active vulnerability exploitation3 weeks ago4 min

Attackers Exploit Claude AI's Legitimate Domain to Host Malicious Installer in Bing Malvertising Campaign

A malvertising campaign on Bing uses a fake Claude desktop app installer hosted on the legitimate Claude.ai domain to deliver SectopRAT malware, compromising at least 29 organizations.

active vulnerability exploitationJul 24, 20263 min

CVE-2026-50522: How SharePoint's Deserialization Flaw Lets Attackers Steal Machine Keys and Stay Forever

Hackers are actively exploiting CVE-2026-50522, a deserialization flaw in Microsoft SharePoint, to steal machine keys and maintain long-term access to compromised systems.

active vulnerability exploitationJul 24, 20265 min

Check Point Patches SmartConsole Zero-Day as Artificial Intelligence Cybersecurity Threats Escalate

Israeli cybersecurity firm Check Point Software addressed CVE-2026-16232, an authentication bypass vulnerability in the SmartConsole GUI admin panel that allows unauthenticated attackers to obtain administrator credentials, prompting CISA's BOD 26-04 mandate for federal agencies.

active vulnerability exploitationJul 24, 20265 min

AI Cybersecurity Threats: Why InfraTrust Forces You to Stop Chasing CVSS Scores

Eclypsium's InfraTrust report reveals how state-sponsored actors exploit infrastructure flaws before patches ship — and why your patching strategy is already obsolete.

active vulnerability exploitationJul 24, 20265 min

Critical U-Boot Flaws Open Door for Stealthy Firmware Attacks Before OS Boot

Six vulnerabilities in the widely used U-Boot bootloader discovered by Binarly could allow attackers to execute malicious code during device boot before the operating system starts, potentially enabling stealthy firmware attacks that compromise security protections and install persistent malware.

active vulnerability exploitationJul 24, 20263 min

CISA Mandates Immediate Remediation of Actively Exploited Langflow RCE Flaw

CISA has issued an emergency directive to U.S. federal agencies requiring the patching of a critical RCE vulnerability, CVE-2026-0770, in the Langflow framework, which is currently being exploited in the wild.

active vulnerability exploitationJul 24, 20264 min

ServiceNow AI Platform RCE: How CVE-2026-6875 Went From Disclosure to Active Exploitation in Weeks

A critical pre-authentication sandbox-escape vulnerability in the ServiceNow AI Platform is being actively exploited in the wild just one week after patches for self-hosted instances were released, putting Fortune 500 enterprise workflows at risk.

active vulnerability exploitationJul 24, 20263 min

The wp2shell Crisis: AI Cybersecurity Threats Targeting WordPress Core at Scale

Security researchers detail how threat actors are chaining two critical WordPress Core vulnerabilities—CVE-2026-63030 and CVE-2026-60137—to deploy persistent webshells, with AI tools accelerating the exploit development process.

active vulnerability exploitationJul 22, 20267 min

OkoBot's 20-Payload Assault on Crypto Wallets Reveals a New Malware Playbook

A new malware framework called OkoBot is delivering over 20 distinct payloads in attacks targeting cryptocurrency wallet seed phrases, browser credentials, and sensitive data. The campaign, tracked by Kaspersky researchers, has been active for over a year and evolved from the TookPS infostealer. OkoBot reaches victims through ClickFix social engineering or malicious GitHub repositories masquerading as legitimate software tools.

active vulnerability exploitationJul 22, 20265 min

Public Exploits Released for Critical wp2shell RCE Vulnerabilities in WordPress Core — Patch Now

Critical unauthenticated remote code execution vulnerabilities in WordPress Core (CVE-2026-63030 and CVE-2026-60137) have been weaponized in the wild, requiring immediate patching to 7.0.2 or 6.9.5.

active vulnerability exploitationJul 21, 20265 min

AI Cybersecurity Threats: The Human Layer Is the Weak Link

Two Scattered Spider members sentenced to 5.5 years for TfL cyberattack—exposing how AI-enhanced social engineering is the real AI cybersecurity threat.

active vulnerability exploitationJul 11, 20265 min

How a China-Linked Cluster Weaponized Roundcube Flaws Against University Cybersecurity Researchers

A China-aligned espionage group tracked by Proofpoint as UNK_MassTraction has been exploiting two known Roundcube vulnerabilities—CVE-2024-42009 (XSS) and CVE-2025-49113 (deserialization)—to compromise webmail servers at U.S. and Canadian universities, deploying credential-stealing malware and persistent backdoors targeting physics and engineering researchers.