Topic: code injection
-
SAP S/4HANA Vulnerability Actively Exploited in Attacks
A critical vulnerability (CVE-2025-42957) in SAP S/4HANA allows attackers to execute unauthorized code and gain administrative control. Despite a patch being available since August 2025, many systems remain unpatched, leading to active exploitation in the wild. Successful attacks can result in se...
Read More » -
Patch Now: Critical SAP S/4HANA Bug Actively Exploited
A critical vulnerability (CVE-2025-42957) in SAP S/4HANA cloud services is under active exploitation, allowing attackers to gain full administrative control with minimal user rights. The flaw, which has no workarounds, poses a severe risk to organizations across multiple sectors due to SAP's cent...
Read More » -
Beware: Malicious npm Package Impersonates Email Library
A malicious npm package named "nodejs-smtp" impersonates the legitimate nodemailer library, compromising cryptocurrency wallets by altering transaction details to redirect funds to attackers. The package uses Electron-based tools to secretly modify the Atomic Wallet application on Windows, replac...
Read More » -
CISA Warns: Malware Kits Found in Ivanti EPMM Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified malware exploiting two vulnerabilities in Ivanti Endpoint Manager Mobile, enabling remote command execution. A China-linked espionage group has been actively using these vulnerabilities as zero-days since mid-May to e...
Read More » -
Cisco Flaw (CVE-2026-20045) Actively Exploited for RCE Attacks
A critical code injection vulnerability (CVE-2026-20045) in Cisco's unified communications products is being actively exploited, allowing attackers to execute malicious code and gain full system control. The flaw impacts several core enterprise collaboration platforms, including Cisco Unified Com...
Read More » -
SonicWall zero-days exploited weeks before disclosure
Two critical SonicWall SMA 1000 zero-day vulnerabilities (CVE-2026-15409 and CVE-2026-15410) were exploited in the wild from at least June 22, 2026, allowing attackers to establish stealthy, persistent access to unpatched VPN appliances by chaining an SSRF bug with a code-injection flaw to gain r...
Read More » -
CISA Warns Hackers Exploit Langflow AI Flaw
A critical vulnerability (CVE-2026-33017) in the Langflow AI framework enables unauthenticated remote code execution, prompting an urgent CISA warning and a federal patching deadline of April 8. Exploitation began rapidly on March 19, with attackers scanning for and compromising systems to steal ...
Read More » -
Operant AI Endpoint Protector secures AI agents and MCP tools
Operant AI launched the Operant Endpoint Protector, a new capability within its AI Defense Platform that helps enterprise teams discover, detect, and defend against threats across all AI tools, coding agents, and Model Context Protocol (MCP)-connected workflows at the endpoint. The solution addre...
Read More » -
Malicious NuGet Packages Deploy Destructive Time Bombs
Malicious packages on NuGet, uploaded by shanhai666, contain hidden payloads set to activate between 2027 and 2028, targeting database systems and Siemens industrial devices, with nearly 9,500 downloads before removal. The packages, including Sharp7Extend, mimic legitimate libraries to evade dete...
Read More » -
Why This Star Wars Game Sells for Hundreds
A PlayStation 4 port of *Star Wars Racer Revenge* has become extremely valuable because hackers discovered its code contains a critical, unpatched security flaw, enabling a jailbreak for the PS5. The game's scarcity is a major factor, as it was produced in a limited run of only about 8,500 physic...
Read More » -
CISA Alerts: 2 New Dassault Flaws Under Active Attack
CISA warns that two new security flaws in Dassault Systèmes' DELMIA Apriso platform are being actively exploited, posing risks to manufacturing operations management. The vulnerabilities include CVE-2025-6205, allowing unauthenticated remote access, and CVE-2025-6204, enabling code injection, wit...
Read More » -
Ghost CMS SQL injection exploited in widespread ClickFix attacks
A critical SQL injection vulnerability in Ghost CMS (CVE-2026-26980) is being actively exploited, allowing attackers to inject malicious JavaScript that initiates a ClickFix attack chain to compromise visitors and steal sensitive data. The attack tricks users with a fake "click to fix" prompt tha...
Read More » -
Theori Launches Xint Code for Large-Scale AI Security Analysis
Theori has launched Xint Code, an LLM-native SAST platform that rapidly analyzes millions of lines of code to bridge the scale gap in cybersecurity defenses. It combines large language models with a proprietary engine to drastically reduce false positives and identify critical, context-driven vul...
Read More »