Threats Tagged 'remote'
View all threats tagged with 'remote'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'remote'
Click on any threat for detailed analysis and mitigation recommendations
Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix 0 NMFTA research shows a Bendix EC80 brake controller safety recall also patched remote code execution and DoS vulnerabilities. The post Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix appeared first on SecurityWeek . Join the discussion | SecurityWeek | 08/07/2026, 10:00:00 UTC Added: 08/07/2026, 10:11:13 UTC |
ZDI-26-525: (0Day) PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability 0 This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PAX Technology Q80. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. Join the discussion | Zero Day Initiative | 08/05/2026, 05:00:00 UTC Added: 08/05/2026, 18:45:38 UTC |
ZDI-26-526: (0Day) PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution Vulnerability 0 This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PAX Technology Q80. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. Join the discussion | Zero Day Initiative | 08/05/2026, 05:00:00 UTC Added: 08/05/2026, 18:45:38 UTC |
COLDCARD security audit phishing attack installs remote access tool 0 A phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software. [...] Join the discussion | Bleeping Computer | 08/05/2026, 17:49:41 UTC Added: 08/05/2026, 18:41:14 UTC |
CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities 0 The flaws can be exploited for remote code execution, authentication bypass, and EncryptInterceptor bypass. The post CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities appeared first on SecurityWeek . Join the discussion | SecurityWeek | 08/05/2026, 09:44:50 UTC Added: 08/05/2026, 09:56:11 UTC |
TP-Link patches Omada ZTP flaws allowing hackers to breach networks 0 TP-Link has released patches for 15 vulnerabilities in the zero-touch provisioning (ZTP) feature of its Omada network devices. These vulnerabilities could be chained with previously disclosed flaws to enable remote code execution (RCE) by attackers. The vulnerabilities affect the ZTP mechanism, which is used to simplify device deployment and configuration. No known exploits are reported in the wild at this time. Join the discussion | Bleeping Computer | 08/04/2026, 22:18:20 UTC Added: 08/04/2026, 22:26:14 UTC |
VU#326070: SGLang contains a vulnerable pickle deserialization vulnerability through the expert-parallel subsystemCVE-2026-14890 0 A pickle deserialization vulnerability (CVE-2026-14890) exists in the SGLang open-source framework's expert-parallel backup subsystem. This vulnerability allows unauthenticated remote code execution if the subsystem is enabled and reachable over the network. The issue arises because a ZeroMQ PULL socket binds to an external IP without authentication or deserialization safeguards, allowing malicious pickle payloads to be processed. No patch is currently available, and the maintainers have not responded to coordination efforts. Mitigations include disabling the pickle IPC feature and restricting network access to the vulnerable interface. Join the discussion | CERT/CC | 07/16/2026, 14:43:27 UTC Added: 08/04/2026, 13:00:07 UTC |
VU#305509: OPeNDAP Hyrax is vulnerable to SSRF and Credential DisclosureCVE-2026-16637 0 OPeNDAP Hyrax contains a Server Side Request Forgery (SSRF) vulnerability that allows an attacker to bypass the allowed hosts restriction via unvalidated HTTP redirects. This flaw can cause the application to communicate with unauthorized internal or external systems. Additionally, user authentication headers, including a legacy Echo-Token credential, may be leaked to attacker-controlled endpoints during these redirects. Exploitation could enable unauthenticated attackers to access internal services and, if a user is authenticated, disclose credentials that grant access to protected datasets. No official patch is confirmed yet, but a fix is expected in Hyrax version 1.18.0 or later. Administrators are advised to restrict gateway exposure to trusted networks until a patch is available. Join the discussion | CERT/CC | 08/07/2026, 13:14:10 UTC Added: 08/04/2026, 13:00:06 UTC |
Fake Roblox Xeno script launcher pushes infostealer, RAT malware 0 Fake Xeno Executor installers are infecting unsuspecting Roblox players with malware that provides remote access and steals sensitive information. [...] Join the discussion | Bleeping Computer | 08/03/2026, 19:25:10 UTC Added: 08/03/2026, 20:03:03 UTC |
New DOUBLECUP ClickFix service hides malware in browser cache images 0 A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems. [...] Join the discussion | Bleeping Computer | 08/03/2026, 20:01:22 UTC Added: 08/03/2026, 20:03:03 UTC |
Showing 1 to 10 of 107 results