Tag

#VulnCheck

6 stories taggedVulnCheck.

Photoreal editorial image, 16:9 full frame edge to edge
Vulnerabilities

Hackers Are Actively Exploiting a Critical Flaw in the AI Builder Langflow

A software vulnerability scored at near-maximum severity is being used right now to break into Langflow servers and steal credentials. Over 360 attacks hit tracking sensors in the UK in a single day.

3 min read
Full-frame 16:9 photoreal editorial image of a dimly lit server rack in a data center, focused on a single rack unit with a glowing amber status LED, shallow de
Vulnerabilities

Hackers Are Actively Exploiting a Near-Perfect-Score Flaw in Ruby on Rails

A critical vulnerability in the popular web framework lets criminals read files off a server and, in some cases, run their own code on it, and patches are not fully closing the door.

3 min read
Macro photograph of dense server rack cable management inside a data center, cables in deep blue and orange running in organized bundles between black rack unit
Vulnerabilities

ZBT Routers Found With Two Hidden Factory Backdoors Handing Attackers Full Control

Researchers at VulnCheck say firmware shipped by Shenzhen Zhibotong Electronics contains two undocumented implants that let anyone on the internet run commands as root.

3 min read
A dimly lit server room with a single open container shipping crate glowing from within, padlock lying broken on the floor beside it
Vulnerabilities

Marimo Patches Notebook Flaw That Let Hidden Commands Run on Open

A high-severity bug in the Marimo notebook app could quietly run attacker-supplied commands when a user opened a booby-trapped file in edit mode.

3 min read
Photoreal news-editorial aerial view of a vast network of illuminated fiber-optic cables converging on a central node that has gone dark, surrounding nodes stil
Threat Intelligence

Twenty Chinese Router Models Ship From The Factory With A Hidden Backdoor

Researchers at VulnCheck say every current Zbtlink firmware image contains an implant that phones home to Chinese servers and hands attackers root access.

4 min read
Photoreal editorial image of a dimly lit server rack in a data centre, one blue status LED glowing, a faint reflection of scrolling log text on the glass door,
Vulnerabilities

Windmill Path Traversal Flaw Under Active Attack, VulnCheck Warns

CVE-2026-29059 lets unauthenticated attackers read files from servers running the open-source developer platform. Patch guidance and exploitation details below.

3 min read
© 2026 Threat Vectr