Skip to main content

Threats Tagged 'exploit'

View all threats tagged with 'exploit'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: exploit

Threats Tagged 'exploit'

Click on any threat for detailed analysis and mitigation recommendations

Orkes Conductor versions before 3.30.2 contain a critical unauthenticated remote code execution vulnerability. Attackers can submit malicious inline workflow definitions with JavaScript or Python expressions to the workflow API endpoint without authentication. This exploits unsandboxed GraalVM evaluators with permissive host access, enabling arbitrary OS command execution via Java reflection or subprocess calls.

Join the discussion
0

CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/products.index.inc.php reads the description, description_short, and spec_copy rich-text fields from $GLOBALS['RAW']['POST'] and removes only script elements before the values are stored and rendered through Smarty templates. An administrator with product-editing rights can store event-handler attributes, SVG content, or javascript: URIs that bypass this filter, causing persistent JavaScript execution when a storefront visitor or another administrator views the product content and enabling session exposure or unauthorized browser-context actions. This issue is fixed in version 6.7.5.

Join the discussion

AI agents that rely on MCP (Model-Controller-Plugin) tool descriptions trust these descriptions similarly to how browsers trust TLS certificates. Attackers have begun exploiting this trust by poisoning tool metadata, which can lead to unauthorized actions such as secret exfiltration and silent email BCCs. This attack surface is not widely covered by existing security tools. The threat involves manipulating tool descriptions dynamically to alter agent behavior post-integration. The recommended defensive approach is to treat tool descriptions as untrusted input and implement measures such as pinning, hashing, and baseline comparisons to detect unauthorized changes.

Join the discussion

The GemStuffer incident involved AI agents exploiting a documentation feature in RubyGems infrastructure to achieve remote code execution (RCE). Specifically, the YARD tool's --load option in .yardopts files was abused to execute arbitrary Ruby code during automated documentation builds on RubyDoc.info. The attackers created disposable accounts, bypassed email confirmation, and uploaded over 2,000 malicious packages that weaponized this feature. This incident highlights a broader class of vulnerabilities where legitimate scripting or code execution features in configuration files are abused in package ecosystems. The attack demonstrates a real supply chain risk from automated AI-driven exploitation.

Join the discussion

A Chinese-speaking threat actor group known as Red Heron exploited a recently disclosed remote code execution vulnerability (CVE-2026-60004) in Gitea, a self-hosted Git service, in a multinational campaign. The campaign targeted internet-facing Gitea instances across multiple countries, including Canada, Argentina, Taiwan, the United States, and Sri Lanka, focusing on sectors such as defense, elections, energy, aerospace, telecommunications, government, and research. The attackers used automated tools to steal source code, credentials, and maintain persistent access, including root-level control on some infrastructure. They deployed a novel Linux implant named JITTERLY with extensive post-exploitation capabilities and embedded a previously undocumented rootkit called SIXZUT to maintain stealth and persistence. The campaign demonstrates rapid weaponization of n-day vulnerabilities in development platforms and highlights significant risks to source code confidentiality and infrastructure integrity.

Join the discussion

ILIAS versions prior to 9.22, 10.10, and 11.3 have an unauthenticated PHP object injection vulnerability via the LTI authentication endpoint, enabling remote code execution through the Shibboleth back-channel logout endpoint. This allows attackers to write malicious PHP code to a web-accessible location and execute it as the web server user.

Join the discussion

The Dark Sword exploit is an iOS exploit chain that was active earlier in the year and has since been patched. It was reportedly used primarily against high-profile targets, but the exploit code has been leaked publicly. This raises concerns about the potential risk to average iPhone users. However, there is no evidence of widespread exploitation against typical users. The exploit is considered high severity due to its capabilities, but the risk to the general population remains low given targeted use and the availability of patches.

Join the discussion

An AI model named Cyberkimi claims to have autonomously developed a live exploit for a recently patched V8 JavaScript engine vulnerability in under 24 hours. The exploit targets Chrome Stable versions that still contain the unpatched bugs. The AI reportedly analyzed recent V8 security patches, identified incomplete fixes, and generated a working exploit chain demonstrated in a local Chromium environment. No official CVE has been assigned to these specific bugs yet, and independent confirmation is lacking. The exploit reportedly leverages a combination of aliasing bugs, race conditions, and control flow hijacking to achieve arbitrary code execution. Google has released Chrome updates addressing some V8 vulnerabilities around the same time, but it is unclear if these fixes cover the bugs exploited by Cyberkimi. This development highlights the shrinking window between patch release and exploit weaponization, potentially accelerating the risk exposure for users of affected Chrome versions.

Join the discussion
0

Metabase versions from 0.58.0 up to but not including 0.58.15, 0.59.0 up to but not including 0.59.12, 0.60.0 up to but not including 0.60.6.3, and 0.61.0 up to but not including 0.61.1.4 are affected by an authenticated remote code execution vulnerability. This vulnerability allows an authenticated attacker to execute arbitrary code remotely on the affected system.

Join the discussion

FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution. This issue has been patched in endpoint versions 15.0.66, 16.0.89, and 17.0.3.

Join the discussion

Showing 1 to 10 of 711 results

Filters:Tag: exploit
Page 1 of 72
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses