Attackers Abuse Open RDP Ports to Gain Initial Access Into Business Networks
Huntress documents multiple real-world incidents where attackers exploited exposed RDP ports to breach business networks, often without needing any exploit.
Stories cluster related articles into a single narrative, linked to the underlying CVEs and affected products. 3,771 stories synthesized.
Huntress documents multiple real-world incidents where attackers exploited exposed RDP ports to breach business networks, often without needing any exploit.
A zero-click WhatsApp account takeover attack targeting iOS 16 users has been uncovered, chaining an Apple ImageIO flaw with a WhatsApp linked-device sync vulnerability to silently hijack sessions.
Vigolium, a new open-source vulnerability scanner that merges deterministic scanning with AI-driven auditing, has been released with over 235 scanner modules and an autonomous agent runtime.
GitLab suspended the account of Windows exploit researcher Nightmare-Eclipse on May 26, 2026, days after GitHub banned the researcher for publishing three Windows Defender zero-day tools.
Hitachi published six coordinated advisories covering XXE injection, credential exposure, and buffer overflow flaws across four product lines.
A wave of vulnerabilities in ISC BIND 9, including a critical use-after-free in DNS-over-HTTPS and an unbounded resend loop, puts millions of resolvers and authoritative servers at risk of remote exploitation.
Anthropic released a free security-guidance plugin for its Claude Code terminal tool that reviews code edits, model outputs, and commits in real time to catch vulnerabilities before they reach production.
Ten vulnerabilities — nine SQL injection and one cross-site scripting — were disclosed across three Itsourcecode PHP applications between May 24 and May 27, 2026, with public exploit code already available.
GitHub released GHES 3.20.3 fixing a critical pre-authentication SSRF vulnerability (CVE-2026-9312) and two high-severity Linux kernel privilege-escalation bugs collectively known as 'Dirty Frag.'
GitLab has issued urgent security updates to address multiple vulnerabilities in its Community and Enterprise Editions that could lead to unauthorized access and privilege escalation.
Israeli cybersecurity firm Gambit Security attributes the March 2025 LA Metro payment disruption to Iranian state hackers posing as hacktivists.
Four improper-access-control vulnerabilities were disclosed in JeecgBoot on May 26, 2026, affecting versions up to 3.9.1, with public exploits available and a fix in version 3.9.2.
Apple shipped fixes for three medium-severity CVEs on May 26, addressing logic and permissions flaws that could let an app access sensitive user data across macOS Tahoe, Sequoia, and Sonoma.
Apple patched seven CVEs across macOS Tahoe 26, Sequoia 15.7, and Sonoma 14.8 on May 26, including two high-severity bugs that could let a malicious app gain root privileges.
The Oncology Institute, a publicly traded cancer care provider, notified the SEC that patient data was compromised in a 2025 breach involving a third-party billing software vendor.
Microsoft Defender Experts uncovered a targeted cryptojacking campaign that uses SEO poisoning and AI chatbot interactions to deliver malware disguised as system utilities, then abuses ScreenConnect for persistent remote access.
A wave of 19 vulnerabilities spanning six Sourcecodester products — including SQL injection, XSS, CSRF, and unrestricted upload flaws — was disclosed between May 23 and May 26, 2026, with public exploits already available.
Charter Communications confirmed a data breach after the ShinyHunters extortion group threatened to leak stolen customer data unless a ransom is paid.
Apple released its quantum-resistant cryptographic implementations and the formal verification tools used to prove their correctness, making them publicly available for industry-wide review.
Analysis of the TeamPCP threat actor behind the Shai-Hulud worm reveals a group whose success stems more from opportunistic targeting of weak configurations than from advanced technical skill.
A batch of 15 CVEs was disclosed against the open-source DDoS detection tool FastNetmon Community Edition, including three critical-severity BGP parsing bugs and unauthenticated command injection.
Microsoft released an out-of-band security patch for SharePoint Server addressing a critical privilege escalation vulnerability that could expose sensitive enterprise data.
CrowdStrike disrupted the Glassworm botnet, which targeted software developers by distributing malware through fake npm packages to steal credentials and mine cryptocurrency.
IBM disclosed eight CVEs for HTTP Server 8.5 and 9.0 on May 26, including a Critical unauthenticated RCE bug and six High-severity flaws spanning buffer overflows, DoS, and mTLS-specific code execution.