ProBackend
Vulnerabilities & Exploits

Vulnerabilities & Exploits

CVEs, zero-days, patching and exploited weaknesses.

active vulnerability exploitationJul 25, 20264 min

Last-Mile Vulnerabilities: Analyzing the OnTrac Network Breach

OnTrac has confirmed a network breach occurring between March 20 and 22, 2026. This analysis explores the risks logistics companies face from evolving AI-cybersecurity threats and the necessity of robust IAM security and autonomous defense practices.

agentic ai security risksJul 25, 20264 min

Agentic Exploitation: How 'YOLO' Mode Turned the Hermes AI Into a Cyber Threat

An analysis of how an open-source AI agent named Hermes, operating in an unattended 'YOLO' mode, automated post-exploitation tasks in an attempted breach against the Thai Ministry of Finance.

active vulnerability exploitationJul 25, 20264 min

Urgent Security Update: Critical XSS Vulnerability Identified in Zimbra Classic Web Client

Investigation into a critical stored XSS vulnerability identified in the Zimbra Collaboration Suite's Classic Web Client. The flaw requires an urgent update to ZCS v10.1.19 to prevent potential unauthorized access to user session data. Reported by Google's Threat Analysis Group (TAG).

active vulnerability exploitationJul 24, 20264 min

Clop Exploited Oracle Flaw to Steal Estée Lauder’s HR Data — And It’s Been Happening Since August

Estée Lauder’s year-long data breach was enabled by a zero-day in Oracle E-Business Suite, exploited by the Clop ransomware gang since August 2025 — a failure that mirrors systemic neglect across enterprise IT.

active vulnerability exploitationJul 20, 20266 min

LegacyHive Zero-Day: How Nightmare Eclipse's Windows Exploit Exposes AI Cybersecurity Threats in Patch Management

A security researcher known as Nightmare Eclipse has published a proof-of-concept for LegacyHive, a Windows zero-day that escalates privileges through the User Profile Service on patched systems. The exploit, which has no CVE and no available patch, lets standard users load an administrator's registry hive—enabling code execution when the admin next logs in.

cloud security incidentsJul 18, 20264 min

BeyondTrust Warned Customers to Patch Two Critical Security Flaws in Its Remote Support (RS) and Privileged Remote Access

BeyondTrust issued emergency patches for two critical authentication bypass flaws in Remote Support and Privileged Remote Access, with two high-severity DoS flaws. Here's why your patch calendar just got crowded—and why ignoring this is a gamble with your incident response plan.

ai cybersecurity threatsJul 9, 20265 min

The Exploitarium Dump: A Solo Researcher's Zero-Day Shotgun Blast

An anonymous security researcher known as bikini published working exploit code for 15 zero-day vulnerabilities across libssh2, Gitea, Splunk, and more — without warning a single vendor. Two are already under active attack.

ai vulnerability disclosuresJul 7, 20263 min

The Tenda Backdoor Nobody Knew Existed — And Why It Matters

A hidden authentication backdoor in Tenda router firmware (CVE-2026-11405) grants admin access to anyone who knows the secret password. No patch exists. Here's what you need to know before attackers find it first.

software vulnerabilities patch managementJul 5, 20264 min

F5 Just Patched Two NGINX Flaws That Could Let Attackers Take Over Your Servers

Emergency out-of-band updates for NGINX address critical memory corruption flaws—here’s what actually breaks if you don’t patch, and how to survive until you can.

cybersecurity vulnerabilitiesJun 29, 20265 min

New macOS Privilege Escalation Technique Exploits XPC Service Trust

Researchers at XM Cyber have discovered a macOS vulnerability that allows standard-privileged users to disable security tools and perform privileged operations by exploiting faulty XPC service trust validation.

cloud security incidentsJun 21, 20264 min

How ShinyHunters Turned a PeopleSoft Zero-Day Into the Biggest University Heist of 2026

Oracle PeopleSoft zero-day CVE-2026-35273 exploited by ShinyHunters against 300+ university instances.

cybersecurityJun 17, 20265 min

Patch Tuesday Just Exposed How Broken Windows Security Really Is

Microsoft patched three zero-days on Tuesday—two that hand attackers SYSTEM access, one that opens BitLocker drives. But the real story is what came after: a researcher named Nightmare Eclipse kept leaking exploits because Microsoft wouldn't listen.