Tag

#SSRF

8 stories taggedSSRF.

Illustration: a physical combination lock left open
AI Security

AWS Says Its AI Agent Handing Over Passwords Is Working as Designed

Palo Alto Networks researchers found that Amazon's AI agent platform exposes plaintext credentials by default. AWS closed the report as 'informative'. Security teams carry the risk.

5 min read
Illustration: a rack-mounted network security appliance in a dim server room, status LEDs glowing amber and red
Vulnerabilities

Rapid7 Caught Hackers Hitting SonicWall Remote Access Boxes Before the Patch

A perfect-10 flaw in SonicWall's SMA1000 gateways was already under attack when the vendor shipped its July 14 hotfix. Here is what the filing actually says.

3 min read
A network security technician working at a control station with VPN authentication systems displayed, emergency patches being deployed to remote-access boxes sh
Vulnerabilities

SonicWall Patches Two VPN Zero-Days Already Being Used by Hackers

A perfect-10 flaw in SonicWall's SMA 1000 remote-access boxes lets attackers slip past the login screen, and it's being paired with a second bug in real attacks.

3 min read
A computer screen displaying code and error messages in red, with overlaid visualization of data packets being intercepted and diverted, representing active exp
Cloud Security

Hackers Are Actively Attacking MLflow and FUXA to Steal Cloud Secrets

Two open-source tools used by AI teams and factory operators are being scanned and broken into in the wild, with attackers using one flaw to grab cloud login keys.

4 min read
Illustration: a rack-mounted network security appliance in a dim server room, blue and amber status LEDs glowing
Vulnerabilities

SonicWall says two SMA1000 flaws are being used in live attacks

One bug scores a perfect 10 on the severity scale. Federal agencies have until 17 July 2026 to patch or pull the plug.

3 min read
Illustration for the story: Cisco admits hackers are breaking into its phone system software — here's what that means
Vulnerabilities

Cisco admits hackers are breaking into its phone system software — here's what that means

A flaw in Cisco Unified Communications Manager, the software that runs office phone systems, is now being actively abused after a patch and public exploit code lit the fuse.

4 min read
Illustration: A rack of glowing server hardware in a dimly lit data centre, cables trailing neatly into patch panels
Vulnerabilities

Cisco Phone System Flaw Now Being Actively Exploited — Patch Immediately

A security hole in Cisco's business phone software is being used in real attacks. Millions of offices run this software. The fix has existed since June.

3 min read
Illustration: a dense rack of enterprise networking and telephony hardware
Vulnerabilities

Cisco Unified CM SSRF Flaw Hits Active Exploitation Three Weeks After Patch Drop

A file-write chain rooted in CVE-2026-20230 is now being probed in the wild. PoC was already public when Cisco shipped the fix.

3 min read
© 2026 Threat Vectr