Public HardBreacher Code Claims Kaspersky Privilege Escalation, but Evidence Remains Unverified
A public proof of concept called HardBreacher claims a local privilege-escalation weakness in Kaspersky Endpoint Security on Windows 11. The report remains unconfirmed, has no CVE, and is...
AI Gateways Under Fire: Attackers Chain LiteLLM and MCP Flaws for Remote Code Execution
A 90-day honeypot study shows attackers systematically probing AI proxies, MCP servers, and agent frameworks like LangChain and Langflow, chaining authentication bypass and command-injection bugs into remote code...
Critical ServiceNow AI Flaws Expose Enterprise Data and Code Execution Paths
ServiceNow has patched three critical AI-platform vulnerabilities and a high-severity Now Platform sandbox escape. Self-hosted customers should urgently verify fixed releases and investigate signs of unauthorized code execution...
UniBLEed Flaws Put Unitree G1 Humanoid Robots at Risk of Root Takeover
Researchers demonstrated a multi-stage attack that can give a nearby adversary root-level control of Unitree G1 humanoid robots. The UniBLEed chain combines unauthenticated Bluetooth writes, a cloud authorization...
Emergency PaperCut Fix Targets Actively Exploited Flaw Affecting Every Supported Release
PaperCut has issued emergency builds after confirming real-world attacks against PaperCut NG and MF servers. Administrators should isolate internet-facing application servers, install the appropriate update and investigate for...
Critical Veeam ONE Flaw Lets Unauthenticated Attackers Steal Backup Credentials (CVSS 9.3)
A newly disclosed flaw in Veeam ONE, tracked as CVE-2026-65641 with a CVSS score of 9.3, lets a remote attacker with no credentials trick the monitoring service into...
CISA Orders Rapid Action as Citrix NetScaler Flaw Is Exploited in the Wild
CISA has placed CVE-2026-8452 in its Known Exploited Vulnerabilities catalog following confirmed attacks against Citrix NetScaler products. The memory-safety flaw can disrupt critical gateway services, and organizations should...
Old Microsoft SQL Server RCE Returns in Active Attacks, Triggering CISA Forensic Mandate
CISA says attackers are exploiting CVE-2019-1068, a Microsoft SQL Server remote-code execution flaw, and has ordered both remediation and forensic triage. Database owners should patch exposed systems, review...