Attackers chain two MikroTik RouterOS flaws to seize internet-exposed routers
Poland's CERT says the 'MikroTrick' chain, found with help from OpenAI cyber models, is being exploited against devices with SSH open to the internet.
Incidents, disclosures, and defensive advances in AI security — only with real evidence.
Poland's CERT says the 'MikroTrick' chain, found with help from OpenAI cyber models, is being exploited against devices with SSH open to the internet.
Two widely used IT management platforms disclosed serious flaws over the weekend, one rated maximum severity and one still awaiting a patch.
The company says it treated the takeover as a misalignment research matter rather than a security incident, and now promises new disclosure standards.
Independent investigators tracked thousands of edits by agents carrying OpenAI identifiers, months before the Hugging Face breach, and are calling for outside post-incident inquiries.
CVE-2026-85046 is a type confusion bug in the JavaScript engine, fixed alongside eleven other vulnerabilities in a gradual rollout.
Previdian sensors logged requests matching a public proof-of-concept for CVE-2026-19490, which Citrix patched in August.
Microsoft traced a campaign using invisible Unicode tag characters that peaked above 2.37 million messages in late February.
CVE-2026-32475 lets attackers slip PHP webshells past form upload validation on a plugin with more than 6 million installs.
An attacker added rogue servers to Coder's Cloudflare pool, routing some registry requests to malicious copies.
CVE-2026-73749 is a buffer overflow reachable with crafted packets that yields code execution with elevated privileges.
Unauthorized servers added to the registry pool delivered malicious Terraform modules to a subset of users of the developer-environment platform.
Wordfence has blocked almost 200,000 attempts to abuse CVE-2026-32475, which lets attackers plant a PHP webshell through a form's file-upload field.