Skip to content
category — security

ls ./category/security --page 4

Security

Breaches, vulnerabilities, malware and the patches that matter.

page 4 of 7147 articles

Exploited since January, added to CISA's list in August, due in three days

2026-08-25

CVE-2026-21962 is a CVSS 10.0 flaw in Oracle's HTTP Server and WebLogic proxy plug-in. Oracle patched it on 20 January. Exploit code appeared on 22 January and a honeypot logged attacks the same day. CISA added it to the Known Exploited Vulnerabilities catalog on 24 August with a due date of 27 August — and under a directive nobody noticed replacing the old one, agencies now have to check whether they were already breached.

The AI picked 170,000 targets — every break-in used a bug from years ago

2026-08-24

Cisco Talos found an exposed directory belonging to UAT-10147 and pulled out target lists of roughly 170,000 URLs, AI tooling across the whole attack lifecycle, and a cross-platform implant called SPECTRE that unlinks EDR callbacks in the kernel using two vulnerable drivers from 2019 and 2021.

The malware reads its orders out of an FTP welcome message, before it even logs in

2026-08-23

MalwareHunterTeam spotted the technique in July and SOCRadar says it is still running. A phishing ZIP drops a shortcut file, the shortcut connects to an FTP server and takes commands from the greeting banner, and either E4del or PINHOLE lands. Novel — and SOCRadar notes that being novel is also what makes it visible.