appsec.fyi · Sources

bleepingcomputer.com

24 curated AppSec resources from bleepingcomputer.com across 8 topics on appsec.fyi.

bleepingcomputer.com

Resources curated from this publisher and indexed across appsec.fyi topic pages. Last item added: 2026-04-24.

Date Added Resource Excerpt
2026-04-24 2026Over 10000 Zimbra servers vulnerable to ongoing XSS attacksXSSOver 10,000 Zimbra servers vulnerable to ongoing XSS attacks https://ift.tt/Ay2mKgb
2026-04-23 2026New Checkmarx supply-chain breach affects KICS analysis toolSupply ChainNew Checkmarx supply-chain breach affects KICS analysis tool https://ift.tt/p2R0T8O
2026-04-22 2026Microsoft releases emergency patches for critical ASP.NET flawAPI SecMicrosoft releases emergency patches for critical ASP.NET flaw https://ift.tt/C9a1UoS
2026-04-22 2026New npm supply-chain attack self-spreads to steal auth tokensSupply ChainNew npm supply-chain attack self-spreads to steal auth tokens https://ift.tt/jx1785i
2026-04-21 2026Actively exploited Apache ActiveMQ flaw impacts 6400 serversRCEActively exploited Apache ActiveMQ flaw impacts 6,400 servers https://ift.tt/TMZ4gHl
2026-04-19 2026LiteLLM PyPI Package Compromised in TeamPCP Supply Chain AttackPythonLiteLLM PyPI Package Compromised in TeamPCP Supply Chain Attack
2026-04-18 2026Critical flaw in Protobuf library enables JavaScript code executionRCECritical flaw in Protobuf library enables JavaScript code execution https://ift.tt/4DbZmA7
2026-04-16 2026Hackers exploit Marimo flaw to deploy NKAbuse malware from Hugging FaceRCEHackers exploit Marimo flaw to deploy NKAbuse malware from Hugging Face https://ift.tt/TgFiunY
2026-04-14 2026Microsoft April 2026 Patch Tuesday fixes 167 flaws 2 zero-daysRCEMicrosoft April 2026 Patch Tuesday fixes 167 flaws, 2 zero-days https://ift.tt/nLAl5mZ
2026-04-13 2026OpenAI rotates macOS certs after Axios attack hit code-signing workflowSupply ChainOpenAI rotates macOS certs after Axios attack hit code-signing workflow https://ift.tt/lXVxymj
2026-04-12 2026Critical Marimo pre-auth RCE flaw now under active exploitationRCECritical Marimo pre-auth RCE flaw now under active exploitation https://ift.tt/EFsl5Bx
2026-04-11 202610,000+ Docker Hub Images Leaking CredentialsSecrets10,000+ Docker Hub Images Leaking Credentials
2026-04-10 2026Supply chain attack at CPUID pushes malware with CPU-Z/HWMonitorSupply ChainSupply chain attack at CPUID pushes malware with CPU-Z/HWMonitor https://ift.tt/X5jt3Jc
2026-04-10 2026Dangerous runC Flaws Allow Hackers to Escape Docker ContainersRCEDangerous runC Flaws Allow Hackers to Escape Docker Containers
2026-04-10 2026Max Severity Flowise RCE Vulnerability Now Exploited in AttacksRCEMax Severity Flowise RCE Vulnerability Now Exploited in Attacks
2026-04-08 202613-year-old bug in ActiveMQ lets hackers remotely execute commandsRCE13-year-old bug in ActiveMQ lets hackers remotely execute commands https://ift.tt/DqRSxdX
2026-04-07 2026Hackers exploit critical flaw in Ninja Forms WordPress pluginRCEHackers exploit critical flaw in Ninja Forms WordPress plugin https://ift.tt/u0UvZxk
2026-04-02 2026Hackers exploiting critical F5 BIG-IP flaw in attacks patch nowRCEHackers exploiting critical F5 BIG-IP flaw in attacks, patch now https://ift.tt/v4Mxyoj
2026-03-18 2026CISA orders feds to patch Zimbra XSS flaw exploited in attacksXSSCISA orders feds to patch Zimbra XSS flaw exploited in attacks https://ift.tt/AV9sfJM
2026-02-20 2026Microsoft says bug causes Copilot to summarize confidential emailsAIMicrosoft says a Microsoft 365 Copilot bug has been causing the AI assistant to summarize confidential emails since late January, bypassing data loss prevention (DLP) policies that organizations rely ...
2026-02-04 2026CISA warns of five-year-old GitLab flaw exploited in attacksSSRFCISA has issued a warning about a five-year-old vulnerability in GitLab that is being exploited in attacks. The flaw poses a security risk and has been actively targeted by threat actors. Organizations using GitLab are advised to update their systems to protect against potential exploitation.
2025-10-21 2025CISA confirms hackers exploited Oracle E-Business Suite SSRF flawSSRFThe Cybersecurity and Infrastructure Security Agency (CISA) has verified that hackers exploited a Server-Side Request Forgery (SSRF) vulnerability in Oracle E-Business Suite. This flaw allowed attackers to manipulate the server into making requests to other systems, potentially leading to unauthorized access or data breaches. It is crucial for organizations using Oracle E-Business Suite to promptly address this vulnerability to prevent exploitation by malicious actors.
2025-04-09 2025Hackers target SSRF bugs in EC2-hosted sites to steal AWS credentialsSSRFHackers are exploiting Server-Side Request Forgery (SSRF) vulnerabilities in Amazon EC2-hosted websites to steal AWS credentials. SSRF bugs allow attackers to send requests from the server to other internal resources, potentially accessing sensitive information like AWS credentials. This type of attack poses a significant risk to organizations hosting their sites on EC2 instances. It is crucial for website owners to regularly update and secure their systems to prevent such attacks and protect their AWS credentials from being compromised.
2024-11-04 2024Microsoft SharePoint RCE bug exploited to breach corporate networkRCEA recently disclosed Microsoft SharePoint remote code execution (RCE) vulnerability tracked as CVE-2024-38094 is being exploited to gain initial access to corporate networks.