Tag

#command-injection

8 stories taggedcommand-injection.

Illustration: a dimly lit server rack in a data centre, blue and amber status LEDs glowing
Vulnerabilities

Zimbra mail server flaw exploited in the wild, Microsoft warns after weeks of quiet attacks

Microsoft Threat Intelligence says attackers used a specially crafted email to hijack Zimbra Collaboration Suite mail servers, drop web shells and steal mailbox data, before the flaw was patched.

3 min read
A network load balancer device with warning indicator lights illuminated, surrounded by cascading alert notifications on nearby monitors
Vulnerabilities

CISA Flags Kemp LoadMaster Flaw After Nearly 800 Exploit Attempts

A critical command-injection bug in Progress Kemp LoadMaster is being actively abused. Federal agencies have three weeks to patch.

3 min read
Network infrastructure diagram on a monitor displaying VeloCloud Orchestrator nodes under attack, with active exploitation indicators spreading across the syste
Vulnerabilities

Arista rushes fix for VeloCloud flaw already being used in attacks

A perfect-10 command injection bug in on-premises VeloCloud Orchestrator lets anyone on the network take over the box. Attackers found it first.

3 min read
A business email server room with technicians performing emergency maintenance and applying patches, with Zimbra interface screens visible displaying the comman
Vulnerabilities

Zimbra Patches Six Security Flaws, Including a Bug That Lets Strangers Run Commands on Your Email Server

The business email platform Zimbra has released a batch of fixes covering a serious command-injection flaw and five other vulnerabilities. No attacks in the wild have been confirmed, but the company is urging every customer to update immediately.

3 min read
Illustration: a dark server rack in a data centre with a single amber warning light glowing on one rack unit
Vulnerabilities

CISA gives federal agencies a weekend to patch two Fortinet flaws already under attack

Two critical bugs in Fortinet's FortiSandbox let intruders run code without a password. Attackers are already trying them. Federal agencies have until Sunday to install the fix.

3 min read
Illustration: a modern laptop on a dark wooden desk
AI Security

Three flaws in OpenClaw AI assistant let attackers steal passwords and run code on your computer

A researcher chained three now-patched bugs in the OpenClaw personal AI assistant into a full takeover of the host machine, starting from a single WhatsApp message.

3 min read
Illustration: A wall of modern black dome security cameras mounted on a concrete ceiling in a large
Vulnerabilities

80,000 Hikvision Security Cameras Left Wide Open — and Criminals Are Selling the Keys

A critical flaw in one of the world's most popular surveillance cameras has sat unpatched for nearly a year on tens of thousands of devices. Hackers are now trading access on underground forums.

3 min read
Illustration: a developer laptop screen showing a blurred terminal with green and amber shell prompt glyphs
AI Security

GuardFall: A 1970s Shell Trick Walks Past AI Coding Agent Safety Checks

Adversa AI says ten of eleven open-source coding agents fall to a command-substitution bypass that any sysadmin would recognize on sight.

3 min read
© 2026 Threat Vectr