Attackers Exploit Critical Langflow and Rails Flaws to Hunt Cloud Secrets
Attackers are actively exploiting critical flaws in Langflow and Ruby on Rails, with observed activity focused on credentials, application secrets and paths to remote code execution. Defenders should...
UniBLEed Flaws Put Unitree G1 Humanoid Robots at Risk of Root Takeover
Researchers demonstrated a multi-stage attack that can give a nearby adversary root-level control of Unitree G1 humanoid robots. The UniBLEed chain combines unauthenticated Bluetooth writes, a cloud authorization...
Old Microsoft SQL Server RCE Returns in Active Attacks, Triggering CISA Forensic Mandate
CISA says attackers are exploiting CVE-2019-1068, a Microsoft SQL Server remote-code execution flaw, and has ordered both remediation and forensic triage. Database owners should patch exposed systems, review...
Critical Next.js Flaws Put Windows Servers and AVIF Image Processing at Risk of RCE
Two critical Next.js vulnerabilities may enable unauthenticated remote code execution through Windows path handling and AVIF image processing. Vercel fixed both issues in Next.js 15.5.24 and 16.3.3, with...
Legacy VNC Login on macOS Screen Sharing Could Hand Attackers a Root Shell
Researchers found that macOS's Screen Sharing service kept its file-transfer helpers running as root even when a session was authenticated with nothing more than a shared VNC password....
Citrix NetScaler Root-Level RCE Flaw Goes Public With Working Exploit Code
A publicly released proof-of-concept shows how a pre-authentication heap overflow in Citrix NetScaler ADC and Gateway can be turned into unauthenticated, root-level remote code execution. There is no...
Unpatched GeoServer Zero-Day Under Active Attack as Researchers Warn of RCE Risk
A newly disclosed, unpatched SQL injection flaw in the open-source mapping platform GeoServer is already being probed by attackers just hours after it went public. Under certain database...
New WordPress Flaw Turns a Failed Login Attempt Into Full Server Takeover
A newly disclosed WordPress vulnerability, dubbed XSS2Shell and tracked as CVE-2026-64638, chains a decade-old parsing quirk in the login page into full remote code execution, putting an estimated...