
Fire Ant Hijacks Cisco IOS XR Routers — CVE-2026-0768
Fire Ant APT targets Cisco IOS XR routers and TACACS+ servers. CVE-2026-0768 Langflow RCE and CVE-2026-82329 Artifactory bypass exploited in the wild.
IT, Networking & Security — tutorials, guides, and insights.
Latest Posts

Fire Ant APT targets Cisco IOS XR routers and TACACS+ servers. CVE-2026-0768 Langflow RCE and CVE-2026-82329 Artifactory bypass exploited in the wild.

Infostealers hijack Claude AI session tokens in first major AI identity theft campaign. Plus Claude Code governance gaps and Teams voice phishing hits DCs.

KindaRails2Shell Rails RCE actively exploited via file read chain. Fire Ant targets Cisco IOS XR and TACACS. Claude sessions hijacked by infostealers.

700 rogue AI agents breached Hugging Face via reward hacking. Plus ServiceNow triple CVSS 10.0, Amazon Kiro secret exfil, and NovaCookies AitM.

Three CVSS 10.0 ServiceNow AI Platform flaws patched; ZBT routers ship with factory backdoors CVE-2026-74232; PaperCut zero-day exploited in the wild.

FBI takes down QTFY Chinese state proxy that breached Federal Reserve and DOJ. CVE-2026-8452 NetScaler exploited in the wild.

CVE-2026-73570 breaches 270+ Zimbra servers; CISA flags 100+ water systems targeted via exposed OT; Gitea RCE CVE-2026-60004 hits KEV.

Three weeks ago we told you what to watch at Hacker Summer Camp. Now it's over — and one attack sums up the whole week: Ghostjacking hijacked an AI coding agent

Snowflake forces NHI migration exposing ownership gaps. Keycloak CVE-2026-18963 CVSS 9.1 RCE. NVIDIA NemoClaw AI agent model poisoning via webpage.

CVE-2026-73570 compromises 270+ Zimbra servers with CISA 72-hour deadline. Plus CVE-2026-21962 Oracle WebLogic CVSS 10.0 and Iranian OT attacks.

CVE-2026-18963 allows unauthenticated Keycloak password resets. Plus Iran-linked OT attack shuts UK power plant and Spring ships 91 CVE patches.

CVE-2026-18963 lets unauthenticated attackers reset any Keycloak account. Plus SynkLoader steals creds via fake lock screens and Teams blocks bots.

CVE-2026-69836 Entra ID max-severity RCE exploited in the wild. AI-generated PLC exploits hit US infrastructure. NetScaler auth bypass patched.

CVE-2026-69836 CVSS 10.0 RCE in Microsoft Entra ID exploited in the wild. Russian APTs abuse OAuth consent flows. Phishing moves inside Slack and Teams.

Talos exposes AI-generated Linux rootkit in SPECTRE campaign. NSA confirms AI in OT attacks. Critical Cisco Crosswork and Citrix NetScaler auth bypasses.

81M password-spray attempts exploit legacy auth protocols that bypass MFA. Plus CVE-2026-65400 macOS auth bypass on CISA KEV and TWINLOOT C2 inside M365.

CVE-2026-65xxx Windows IKE Extension RCE now exploited; Cl0p names 40+ Windchill victims; DOJ charges 17 Iranian Mabna Institute hackers.

CVE-2026-19478 GitLab GraphQL RCE hits CI/CD pipelines. Windows Task Host exploited by ransomware. City Forum scrapes 3.6M Azure records.

CVE-2026-59310 vCenter RCE exploited by China-nexus APT for Babuk ransomware. Plus Clop claims GE and Philips, SAP Commerce Cloud hit in 3 days.

White House authorizes private hack-back ops against cybercrime gangs. GeoServer zero-day exploited with no patch. Shell loses 89GB to Clop exfiltration.