GreyNoise Intelligence has released a report indicating that spikes in malicious activity often precede the disclosure of new vulnerabilities in edge devices. The study tracked 147.8 million sessions over 103 days,…
In a recent cybersecurity incident, attackers exploited an exposed Spring Boot Actuator endpoint to harvest credentials from leaked configuration data. They utilized the OAuth2 Resource Owner Password Credentials (ROPC)…
A recent analysis of Apache and ModSecurity logs revealed a surge in internet-wide reconnaissance targeting Model Context Protocol (MCP) servers and AI assistant configuration files. Over a 14-day period, approximately…
Two critical vulnerabilities (CVE-2025-34025 and CVE-2025-34026) have been identified in the Versa Concerto SD-WAN orchestration platform, affecting versions 12.1.2 through 12.2.0. CVE-2025-34026 allows unauthorized…
In a study conducted by Irregular in collaboration with Wiz, AI agents successfully solved nine out of ten web security capture-the-flag (CTF) challenges. The challenges were based on real-world vulnerabilities,…