Tag

#SSRF

8 stories taggedSSRF.

Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Cloud Security

Hackers Are Actively Attacking MLflow and FUXA to Steal Cloud Secrets

Two open-source tools used by AI teams and factory operators are being scanned and broken into in the wild, with attackers using one flaw to grab cloud login keys.

4 min read
Full-frame photoreal editorial image of a rack-mounted network security appliance in a dimly lit server room, blue and amber status LEDs glowing, ethernet cable
Vulnerabilities

SonicWall Rushes to Patch Two Live Attacks on Remote Access Boxes

One of the flaws scores a perfect 10 out of 10 for severity, and attackers are already using both in real intrusions.

3 min read
Photoreal news-editorial shot of a rack-mounted network security appliance in a dim server room, blue and amber status LEDs glowing, ethernet cables neatly bund
Vulnerabilities

SonicWall says two SMA1000 flaws are being used in live attacks

One bug scores a perfect 10 on the severity scale. Federal agencies have until July 17, 2026 to patch or pull the plug.

3 min read
Photoreal editorial image, full frame 16:9, of a modern office desk IP phone glowing softly in a dim server-room setting, with faint blue network cable light tr
Vulnerabilities

Cisco admits hackers are breaking into its phone system software — here's what that means

A flaw in Cisco Unified Communications Manager, the software that runs office phone systems, is now being actively abused after a patch and public exploit code lit the fuse.

4 min read
Photoreal news-editorial style, 16:9 framing, edge-to-edge composition
Vulnerabilities

Cisco Phone System Flaw Now Being Actively Exploited — Patch Immediately

A security hole in Cisco's business phone software is being used in real attacks. Millions of offices run this software. The fix has existed since June.

3 min read
Vulnerabilities

Cisco Unified CM SSRF Flaw Hits Active Exploitation Three Weeks After Patch Drop

A file-write chain rooted in CVE-2026-20230 is now being probed in the wild. PoC was already public when Cisco shipped the fix.

2 min read
Vulnerabilities

Public PoC Lands for Cisco Unified CM Root-Write Bug CVE-2026-20230

An unauthenticated SSRF in Cisco Unified Communications Manager opens a path to root. Cisco's PSIRT hasn't observed in-the-wild use — yet.

2 min read
Vulnerabilities

One Bad Character in a Host Header Breaks Auth for Thousands of FastAPI Apps

A parsing gap in Starlette lets unauthenticated requests reach protected routes — and the blast radius runs deep into the AI inference stack.

3 min read
© 2026 Threat Vectr