Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'remote'

View all threats tagged with 'remote'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: remote

Threats Tagged 'remote'

Click on any threat for detailed analysis and mitigation recommendations

WhatsApp phishing attack uses fake business docs to hack PCs
0

A malware campaign is targeting WhatsApp users globally by sending deceptive VBScript files disguised as business and financial documents from compromised contacts. When executed on Windows, the VBScript disables User Account Control (UAC) protections and silently installs ManageEngine Endpoint Central software configured to connect to attacker-controlled servers, granting remote access to the victim's PC. The campaign affects multiple countries and uses localized filenames to increase effectiveness. The exact method of WhatsApp account compromise is unknown. Users are advised to verify files received via WhatsApp and scan them before execution.

Join the discussion
FFmpeg fixes PixelSmash flaw in widely used video decoder
0

The PixelSmash vulnerability (CVE-2026-8461) is a heap out-of-bounds write flaw in the MagicYUV decoder of FFmpeg's libavcodec library. It affects video files in AVI, MKV, and MOV formats and can be triggered by opening or scanning such files. This flaw can cause denial-of-service conditions in multiple media applications and potentially enable remote code execution (RCE) on Jellyfin and Nextcloud servers under specific conditions. Exploitation for RCE requires Address Space Layout Randomization (ASLR) to be disabled or chained with another vulnerability to bypass this protection. FFmpeg version 8.1.2 addresses this issue, and some applications have implemented mitigations such as disabling vulnerable decoders or adding file format blocklists.

Join the discussion
AutoJack: How a single page can RCE the host running your AI agent
0

AutoJack is a novel exploit chain showing how a single malicious webpage can turn an AI browsing agent into a remote code execution vector on the host machine. By abusing trust in localhost, missing authentication, and unsafe parameter handling, attackers can trigger arbitrary process execution through AutoGen Studio’s MCP WebSocket. The research highlights a broader pattern - when agents can browse untrusted content and access local services, traditional boundaries like localhost are no longer secure. The post AutoJack: How a single page can RCE the host running your AI agent appeared first on Microsoft Security Blog .

Join the discussion
CryptoBandits Malware Doubles as a Backdoor, Abuses Tor
0

CryptoBandits uses a local SOCKS5 proxy for traffic routing, blending data theft with remote code execution. The post CryptoBandits Malware Doubles as a Backdoor, Abuses Tor appeared first on SecurityWeek .

Join the discussion
F5 Patches Critical, High-Severity NGINX Vulnerabilities
0

Critical flaws in NGINX could allow remote, unauthenticated attackers to cause a restart and potentially execute arbitrary code. The post F5 Patches Critical, High-Severity NGINX Vulnerabilities appeared first on SecurityWeek .

CriticalVulnerability#remote
Join the discussion
Microsoft - NTLMv2 Hash Capture
0

Microsoft - NTLMv2 Hash Capture

Join the discussion
Grav CMS 2.0.0-beta.2 - Remote Code Execution
0

Grav CMS 2.0.0-beta.2 - Remote Code Execution

Join the discussion
scramble - Remote Code Execution
0

scramble - Remote Code Execution

Join the discussion
MixPHP Framework 2.2.17 - Unsafe Deserialization Remote Code Execution
0

MixPHP Framework 2.2.17 - Unsafe Deserialization Remote Code Execution

Join the discussion
Quick Playground for WordPress 1.3.1 - Unauthenticated Remote Code Execution
0

Quick Playground for WordPress 1.3.1 - Unauthenticated Remote Code Execution

Join the discussion

Showing 1 to 10 of 92 results

Filters:Tag: remote
Page 1 of 10
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses