#activeexploit

9 posts · Last used 6d

Back to Timeline
BeyondMachines :verified: @beyondmachines1@infosec.exchange · 6d ago

Metabase Patches Critical Zero-Day SQL Injection Exploited in the Wild

Metabase patched a critical zero-day SQL injection vulnerability (GHSA-vwf4-m7j8-wcjf, CVSS 10.0) that is actively exploited to gain administrator access and steal database credentials.

If you run self-hosted Metabase (version 1.58 or newer), this is urgent. Your Metabase is under attack. Update immediately to the patched release for your branch (0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, or 0.63.5). if you can't patch right now, block all traffic to the /api/session/reset_password endpoint as a stopgap. After patching, check your application and ingress logs for a failed password-reset POST followed straight away by a successful /api/user/current request. Tf you see it, treat the instance as breached: clear the core_session table to log everyone out, rotate all connected database passwords, and check your admin accounts for anything you didn't create. #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/metabase-patches-critical-zero-day-sql-injection-exploited-in-the-wild-g-o-s-u-u/gD2P6Ple2L

0
0
0
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Aug 04, 2026

N-able Patches Critical N-central Authentication Bypass Exploited in the Wild

N-able issued an emergency hotfix for N-central after attackers bypassed previous patches to gain administrative control over MSP servers. The flaw allows remote actors to hijack managed endpoints and establish persistent access via Cloudflare tunnels.

If you are using N-able N-central, this is urgent. Upgrade immediately to version 2026.3.1.7. Attackers are already exploiting the product to take over admin accounts on both on-premises and cloud-hosted servers. After patching, run N-able's provided scan templates on your Windows endpoints to check for signs of compromise (especially unexpected Cloudflare tunnel services), turn on multi-factor authentication, and review all user accounts and policy changes for anything you didn't make yourself. #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/n-able-patches-critical-n-central-authentication-bypass-exploited-in-the-wild-7-r-o-r-u/gD2P6Ple2L

0
0
0
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 28, 2026

Arista Patches Critical VeloCloud Orchestrator Zero-Day Under Active Attack

Arista Networks released an emergency advisory for a CVSS 10.0 OS command injection vulnerability in VeloCloud Orchestrator On-Prem that is currently being exploited in the wild. The flaw allows unauthenticated attackers to gain full control over the orchestrator and all managed SD-WAN edge devices.

Make sure all VeloCloud Orchestrator On-Prem devices are isolated from the internet and accessible only from trusted administrative networks. Then immediately upgrade to a fixed release (5.2.3.14, 6.1.3.4, 6.4.2.4, or 7.0.0.1) and block the known malicious IPs (8.19.75.217, 206.72.242.124, 206.72.242.162) at your firewall. After patching rotate all credentials and certificates so attackers can't reuse any potentially stolen data. #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/arista-patches-critical-velocloud-orchestrator-zero-day-under-active-attack-x-b-e-7-y/gD2P6Ple2L

0
0
0
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 28, 2026

CISA Warns of Active Exploitation in Fortinet FortiOS SSL-VPN Patch Bypass

CISA reports active explotation of CVE-2025-68686, a flaw in Fortinet FortiOS that allows attackers to bypass security patches and maintain persistent access on compromised devices.

If you use Fortinet devices, make sure they are isolated from the internet and accessible only from trusted networks. Then update FortiOS ASAP to version 7.6.2, 7.4.7, or later. This flaw is combined with others, so make sure all your Fortinet devices are up-to-date. And check your devices for indicators of compromise, this flaw allowed hackers to maintain access over patch cycles. #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/cisa-warns-of-active-exploitation-in-fortinet-fortios-ssl-vpn-patch-bypass-h-6-5-r-8/gD2P6Ple2L

0
0
0
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 22, 2026

Microsoft SharePoint On-Premises Servers Targeted by Critical Deserialization Exploit

Microsoft SharePoint on-premises servers are under active attack following the release of exploit code for CVE-2026-50522. Attackers are stealing machine keys to maintain persistent access.

If you run on-premises SharePoint, apply Microsoft's July 14 patch immediately to fix CVE-2026-50522. Note that patching alone is not enough, because attackers steal the server's machine keys and keep access afterwards. Rotate all machine keys and related credentials on any exposed server, and check your logs for signs someone already extracted them. #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/microsoft-sharepoint-on-premises-servers-targeted-by-critical-deserialization-exploit-y-l-4-3-b/gD2P6Ple2L

1
0
0
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 21, 2026

Critical ServiceNow AI Platform Flaw Exploited in Remote Code Execution Attacks

ServiceNow AI Platform is facing active exploitation of a critical sandbox escape vulnerability (CVE-2026-6875) that allows unauthenticated attackers to execute remote code.

If you self-host ServiceNow, apply the July 13th security patches ASAP. This being actively exploited and lets attackers take over your instance without login. After patching, check your logs for suspicious activity around the /assessment_thanks.do endpoint and review the Guarded Scripts list for any custom code that needs updating. #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/critical-servicenow-ai-platform-flaw-exploited-in-remote-code-execution-attacks-0-w-8-n-6/gD2P6Ple2L

0
0
0
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 15, 2026

CISA Issues Urgent Warning on SharePoint Server Exploitation

CISA warns of active exploitation of three SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164) used by threat actors to deploy malware and steal IIS machine keys. The agency also reports two additional critical flaws (CVE-2026-55040 and CVE-2026-58644) that pose a high risk for remote code execution and authentication bypass.

If you run on-premise SharePoint Server (2016, 2019, or Subscription Edition), apply the latest Microsoft security updates immediately. Three of these flaws are being actively exploited to deploy ransomware. Then check your servers for signs of breach before rotating your IIS machine keys, and block direct internet access to SharePoint (especially the Central Administration interface) by placing it behind a reverse proxy. #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/cisa-issues-urgent-warning-on-sharepoint-server-exploitation-o-9-u-8-x/gD2P6Ple2L

0
0
0
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 09, 2026

Critical RCE Vulnerabilities Exploited in Joomla Page Builder Extensions

CISA has warned of active exploitation of two critical RCE vulnerabilities in Joomla's SP Page Builder and Page Builder CK extensions. Attackers are using these flaws to upload web shells and create rogue Super Administrator accounts to maintain persistent access.

If you run Joomla with SP Page Builder or Page Builder CK, update SP Page Builder to 6.6.2 and Page Builder CK to 3.6.0 immediately. Both have critical flaws under active attack. Then check your user list for any accounts using the @secure.local email domain, delete any you find, scan the /images/ and /media/ folders for suspicious PHP files, and if anything looks compromised, change all database passwords and secret keys. #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/critical-rce-vulnerabilities-exploited-in-joomla-page-builder-extensions-v-v-q-9-p/gD2P6Ple2L

0
0
0
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 09, 2026

Langflow AI Framework Targeted by Critical IDOR and RCE Exploits

CISA and Sysdig researchers report active exploitation of two critical Langflow vulnerabilities, including a 9.9-rated IDOR and a 9.3-rated RCE, used to steal AI credentials and deploy malware.

If you are using Langflow, this is important and urgent. Make sure all Langflow instances are isolated from the internet and accessible only from trusted networks, then immediately update to Langflow version 1.9.1 or later to patch these actively exploited flaws. Check your system logs for connections to the malicious IP 45.207.216.55 or the /tmp/lang_pwn marker. If you find any indicators of compromise, rotate any API keys or credentials that were stored in your Langflow flows. #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/langflow-ai-framework-targeted-by-critical-idor-and-rce-exploits-i-0-s-2-w/gD2P6Ple2L

0
0
0
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 07, 2026
Gitea Docker Images Vulnerable to Critical Authentication Bypass, Already Attacked Gitea patched a critical authentication bypass vulnerability (CVE-2026-20896) in its Docker images that allows attackers to impersonate any user with a single HTTP header. The flaw is being exploited in the wild. **If you self-host Gitea, first make sure it's isolated from the internet and reachable only from trusted networks, then update to version 1.26.3 or later ASAP. If you can't update immediately, edit your app.ini to change REVERSE_PROXY_TRUSTED_PROXIES from * to your actual reverse proxy's specific IP address, and rotate all credentials and secrets stored in your repositories.** #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/gitea-docker-images-vulnerable-to-critical-authentication-bypass-already-attacked-c-9-8-p-p/gD2P6Ple2L
0
0
0
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jun 30, 2026

Attackers Exploit Critical Takeover Flaw in Oracle E-Business Suite

Researchers report actively exploit of a critical vulnerability (CVE-2026-46817) in Oracle E-Business Suite's financial module.

If you run Oracle E-Business Suite (versions 12.2.3 through 12.2.15), make sure your EBS instances are isolated from the public internet and reachable only from trusted networks via a VPN or secure gateway. Then apply the May 2026 Critical Security Patch Update ASAP. #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/attackers-exploit-critical-takeover-flaw-in-oracle-e-business-suite-v-f-z-k-l/gD2P6Ple2L

1
0
0

You've seen all posts