Topic: in-the-wild exploitation
-
OpenAI GPT Used to Create WordPress Exploit by Researchers
OpenAI's GPT-5.6 Sol Ultra autonomously built a complete exploit chain, named WP2Shell, targeting two critical WordPress Core vulnerabilities, achieving pre-authentication remote code execution in just over ten hours at a cost of $25. The exploit chain combines CVE-2026-63030 (a critical REST API...
Read More » -
Active Exploit of Unauthenticated RCE in Splunk Enterprise (CVE-2026-20253)
CISA added CVE-2026-20253, a critical unauthenticated remote code execution vulnerability in Splunk Enterprise, to its Known Exploited Vulnerabilities catalog, requiring federal agencies to apply mitigations by June 21, 2026. The vulnerability, confirmed actively exploited in the wild, allows att...
Read More » -
Linux hit by second critical security flaw in two weeks
The newly discovered "Dirty Frag" vulnerability allows containers and unprivileged users to escalate to full root access on Linux systems, posing an immediate and severe threat, especially in shared hosting environments. The leaked exploit is deterministic, stealthy, and works reliably across nea...
Read More » -
Microsoft Defender zero-days exploited after researcher disclosure
A security researcher has disclosed two new proof-of-concept exploits, RedSun and UnDefend, targeting Microsoft Defender, building on a previously patched flaw and already seen in active attacks. Cybersecurity firm Huntress confirms all three related exploits have been used in real incidents, wit...
Read More » -
Adobe Fixes Critical Acrobat Reader Flaw Under Active Attack
Adobe has urgently patched a critical zero-day vulnerability (CVE-2026-34621) in Acrobat Reader, actively exploited since last year, which allows arbitrary code execution via a malicious PDF. The in-the-wild exploit, discovered via a malicious PDF sample, performs system fingerprinting and commun...
Read More » -
Exploit Alert: Critical Adobe Experience Manager Flaw (CVE-2025-54253)
A critical security flaw (CVE-2025-54253) in Adobe Experience Manager Forms allows unauthenticated attackers to execute remote code, prompting CISA to flag it due to active exploitation. The vulnerability arises from Apache Struts "devMode" being enabled in the administrative interface combined w...
Read More »