#SSRF
8 stories taggedSSRF.

AWS Says Its AI Agent Handing Over Passwords Is Working as Designed
Palo Alto Networks researchers found that Amazon's AI agent platform exposes plaintext credentials by default. AWS closed the report as 'informative'. Security teams carry the risk.

Rapid7 Caught Hackers Hitting SonicWall Remote Access Boxes Before the Patch
A perfect-10 flaw in SonicWall's SMA1000 gateways was already under attack when the vendor shipped its July 14 hotfix. Here is what the filing actually says.

SonicWall Patches Two VPN Zero-Days Already Being Used by Hackers
A perfect-10 flaw in SonicWall's SMA 1000 remote-access boxes lets attackers slip past the login screen, and it's being paired with a second bug in real attacks.

Hackers Are Actively Attacking MLflow and FUXA to Steal Cloud Secrets
Two open-source tools used by AI teams and factory operators are being scanned and broken into in the wild, with attackers using one flaw to grab cloud login keys.

SonicWall says two SMA1000 flaws are being used in live attacks
One bug scores a perfect 10 on the severity scale. Federal agencies have until 17 July 2026 to patch or pull the plug.

Cisco admits hackers are breaking into its phone system software — here's what that means
A flaw in Cisco Unified Communications Manager, the software that runs office phone systems, is now being actively abused after a patch and public exploit code lit the fuse.

Cisco Phone System Flaw Now Being Actively Exploited — Patch Immediately
A security hole in Cisco's business phone software is being used in real attacks. Millions of offices run this software. The fix has existed since June.

Cisco Unified CM SSRF Flaw Hits Active Exploitation Three Weeks After Patch Drop
A file-write chain rooted in CVE-2026-20230 is now being probed in the wild. PoC was already public when Cisco shipped the fix.