Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'exploit'

View all threats tagged with 'exploit'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: exploit

Threats Tagged 'exploit'

Click on any threat for detailed analysis and mitigation recommendations

Exploiting Zero Touch Provisioning (ZTP)
0

Research has disclosed 15 new vulnerabilities in TP-Link's Omada ecosystem related to Zero Touch Provisioning (ZTP), with some affecting other TP-Link product lines. These vulnerabilities enable exploitation at a fleet scale rather than individual devices. TP-Link has fixed these vulnerabilities. The research will be presented at Black Hat and DEF CON conferences.

Join the discussion
AMA Today: Yuhang Wu (Ex-Tesla & TikTok) Red Team Engineer & Exploit Developer
0

This entry describes an Ask Me Anything (AMA) event featuring Yuhang Wu, a former red team engineer and exploit developer with experience at Tesla and TikTok. The AMA focuses on topics such as enterprise infrastructure hacking, Linux kernel exploitation, and AI security innovations. No specific vulnerability or exploit details are provided in the content. There is no indication of an active security threat or vulnerability disclosed in this event announcement.

Join the discussion
AMA Today: Yuhang Wu - Security Researcher, Red Team Engineer & Exploit Developer
0

This entry describes an Ask Me Anything (AMA) session with Yuhang Wu, a security researcher and exploit developer known for work on Linux kernel exploitation and AI security. The post highlights Wu's background and achievements but does not detail any specific vulnerability or exploit. No technical vulnerability information or affected software versions are provided.

Join the discussion
Vulnrichment Viewer: Search, filter, and track exploitation status
0

Vulnrichment Viewer: Search, filter, and track exploitation status Source: https://cyberdivemaster.github.io/vulnviewer/

Join the discussion
Exploiting the order of operations (Pwnable)
0

This is a tutorial-style demonstration of exploiting a binary vulnerability caused by incorrect handling of the order of operations in code. It is presented as an educational resource for exploit development, focusing on a specific type of bug in a pwnable challenge binary. No specific software product or version is identified as affected. The content is primarily instructional and does not describe an active, widespread threat or vulnerability with known exploits in the wild.

Join the discussion
Attack server staging 7 exploits with curated gov/finance target lists across 11 countries
0

A threat campaign was observed staging exploits on a Singapore VPS targeting curated government, university, healthcare, and financial sector entities across 11 countries. The attack server hosted multiple exploits ranging from a 2017 WebLogic vulnerability to recent ones including NGINX Rift (CVE-2026-42945) and Ghost CMS (CVE-2026-26980). The campaign used organized target lists by country and sector and included an AdaptixC2 server for command and control. The campaign is notable for its targeted approach and use of recent vulnerabilities.

Join the discussion
WP2Shell WordPress Vulnerabilities Exploited in the Wild
0

Two critical WordPress vulnerabilities, CVE-2026-60137 (SQL injection) and CVE-2026-63030 (arbitrary code execution), collectively known as WP2Shell, have been exploited in the wild shortly after their disclosure. These vulnerabilities affect WordPress versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. The exploit requires no preconditions and can be executed by an anonymous user on a stock WordPress installation without plugins. WordPress has released patches in versions 6.9.5 and 7.0.2 and enabled forced auto-updates for affected versions. Cloudflare and other security firms have implemented protective measures. Exploitation attempts have been observed by multiple cybersecurity companies, with some incident responses already underway.

Join the discussion
New Exploitable BOLA Found in Immich (self-hosted media platform)
0

A Broken Access Control vulnerability was discovered in Immich, a self-hosted media platform. The flaw allows any user to access photos stored in a locked folder without entering the required PIN. This occurs because one of the search endpoints (POST /search/random) does not enforce the PIN protection, exposing locked assets of the caller and their partners. Immich uses a PIN-elevated session to protect sensitive media, but this endpoint bypasses that control.

Join the discussion
Exploiting Random Number Generation
0

This content discusses exploiting weaknesses in random number generation as a binary exploitation challenge tutorial aimed at beginners. It highlights that some enterprise environments still use flawed random number generation methods that can be exploited. The tutorial covers concepts such as random number generation in C, XOR operations, and source code analysis without using a debugger. No specific vulnerability or affected software versions are identified.

Join the discussion
Nightmare Eclipse could be dropping his big promised exploit today
0

A threat actor known as Nightmare Eclipse has indicated plans to release a significant exploit on July 14th, 2026. A new repository was created on the announced date but currently contains no exploit code, only a license and a placeholder README. The actor previously suggested constraints might have prevented release but the timing suggests a potential imminent drop. No technical details or affected software versions are currently available. The situation is being monitored for further developments.

Join the discussion

Showing 1 to 10 of 10 results

Filters:Tag: exploit
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses