Tag

Exploitation

All articles tagged with #exploitation

GeoServer Zero-Day Actively Exploited, Elevating RCE Risk
technology11 days ago

GeoServer Zero-Day Actively Exploited, Elevating RCE Risk

A newly disclosed, unpatched GeoServer SQL injection zero-day is being actively exploited, with potential remote code execution. Researchers report hundreds of attempts from a small IP pool; no CVE yet. Admins should identify exposed instances, restrict public access, and monitor for a vendor patch. GeoServer has a history of severe vulnerabilities, so stay alert for updates.

Windmill path-traversal flaw exploited to read server files; patch issued
technology1 month ago

Windmill path-traversal flaw exploited to read server files; patch issued

A high-severity Windmill vulnerability, CVE-2026-29059, enables unauthenticated path traversal via the get_log_file endpoint to read arbitrary server files; if SUPERADMIN_SECRET is configured, the flaw could expose a Bearer-token for superadmin authentication and code execution, though default setups are limited to file reads. Windmill released a fix (1.603.3) in January 2026 by sanitizing the filename parameter. VulnCheck reports about 170 vulnerable systems across 24 countries and observed exploitation targeting Windmill endpoints and the Nextcloud proxy path. Separately, CISA’s KEV catalog highlights WP2Shell WordPress flaws and Langflow RCE vulnerabilities with widespread PoCs, urging WordPress users to update and noting a July 24, 2026 remediation deadline for Federal Civilian Executive Branch agencies.

WordPress under attack: chained flaws enable pre-auth remote code execution after patches
technology1 month ago

WordPress under attack: chained flaws enable pre-auth remote code execution after patches

After WordPress released patches for CVE-2026-60137 (SQL injection) and CVE-2026-63030 (REST API route confusion), attackers quickly weaponized both flaws to enable unauthenticated remote code execution. Public PoCs and AI-assisted tooling spurred rapid exploitation, with tens of thousands of attempts and hundreds of backdoor admin accounts, fake plugins, and attempts to fetch tools like Overlord RAT. WordPress also forced auto-updates for affected sites. Patches are in WordPress 6.9.5 and 7.1 Beta 2 (6.8.6 for the SQLi; older versions affected differently). Admins should patch immediately and audit for backdoors and suspicious plugins.

Poverty in Iran Drives Children into Hidden Labor Across Sectors
society2 months ago

Poverty in Iran Drives Children into Hidden Labor Across Sectors

Worsening poverty in Iran is pushing more children into labor across sectors such as slaughterhouses, farms, and workshops, including hidden workplaces away from public view. Families rely on their kids’ earnings to survive, exposing them to health risks, malnutrition, violence and exploitation while they miss schooling, underscoring broader welfare weaknesses and rising unemployment.

Court docs allege years of exploitation of young women forced to stream from Bellevue party house
crime-blotter2 months ago

Court docs allege years of exploitation of young women forced to stream from Bellevue party house

King County prosecutors say court documents detail a Bellevue Lakemont residence where a 21-year-old allegedly ran a trafficking operation forcing several young women (one 17) to live there and stream content on OnlyFans and Chaturbate for 10–12 hours daily, confiscating earnings, using violence and threats, and even drugging some with Adderall; one victim says she was pressured to drop out of college. The suspect faces four counts of human trafficking, money laundering, and leading organized crime, with bail set at $5 million and charging decisions pending.

Millions at Risk as NGINX Zero-Day RCE Flaw Sees Real-World Exploitation
cybersecurity3 months ago

Millions at Risk as NGINX Zero-Day RCE Flaw Sees Real-World Exploitation

Security researchers say CVE-2026-42945, a heap buffer overflow in NGINX Open Source and NGINX Plus, is being actively exploited in the wild. The flaw can crash NGINX worker processes via crafted requests, with remote code execution possible only if ASLR is disabled and a specific rewrite configuration is present; despite ASLR generally enabled, estimates show up to 5.7 million internet-facing servers may be affected. Organizations should patch promptly, ensure ASLR remains enabled, and audit rewrite rules to mitigate risk while threat actors rapidly scan for vulnerable systems.

Active cPanel/WHM zero-day exploit prompts rapid patch after PoC release
security3 months ago

Active cPanel/WHM zero-day exploit prompts rapid patch after PoC release

A critical authentication-bypass vulnerability CVE-2026-41940 in cPanel/WHM and WP Squared is being actively exploited in the wild; recent technical details and a PoC show CRLF injection in login/session handling that can grant control without a password. cPanel issued a patch on April 28, while mitigations include restarting cpsrvd, blocking ports 2083/2087/2095/2096 if patching isn’t immediate, and using provided detection scripts to verify compromise.

Brand Admits Exploitative Sex With 16-Year-Old at 30 Amid Legal Battles
entertainment4 months ago

Brand Admits Exploitative Sex With 16-Year-Old at 30 Amid Legal Battles

Russell Brand said on The Megyn Kelly Show that he had exploitative but consensual sex with a 16-year-old when he was 30, a claim raised as he faces rape and sexual assault charges dating from 1999–2009, with his trial now scheduled for October; he argues the relationships reflected a power imbalance and his past selfish behavior.

Brand: past relationship with a 16-year-old called exploitative as rape trial looms
uk-news4 months ago

Brand: past relationship with a 16-year-old called exploitative as rape trial looms

Russell Brand told Megyn Kelly that he had an exploitative, consensual sexual encounter with a 16-year-old when he was 30 and described his past behavior as selfish. He is facing a autumn trial at Southwark Crown Court on six accusations from six women—three rape charges, three sexual assaults and one indecent assault—while he denies all charges and remains on bail.

Brand admits sleeping with 16-year-old at 30 and calls it exploitative
entertainment4 months ago

Brand admits sleeping with 16-year-old at 30 and calls it exploitative

On the Megyn Kelly Show, Russell Brand says he slept with a 16-year-old when he was 30, calling it legal where he is from but exploitative due to power dynamics; he faces ongoing sexual assault and rape charges in London and has pleaded not guilty to multiple counts from 1999–2005, framing his past promiscuity as something to redeem while noting his sobriety and faith.

Brand's Past Confession: A 16-Year-Old Encounter At 30 Labeled Exploitative
entertainment4 months ago

Brand's Past Confession: A 16-Year-Old Encounter At 30 Labeled Exploitative

Russell Brand told Megyn Kelly that he slept with a 16-year-old when he was 30, calling the act exploitative and acknowledging a power imbalance. He noted that in Europe and the UK the age of consent is 16 and described his past behavior as selfish and immature. The piece also references rape and sexual assault charges Brand faced in 2025, for which he has pleaded not guilty.

Active Exploit Targets Nginx UI Flaw, Enables Full Server Takeover
security4 months ago

Active Exploit Targets Nginx UI Flaw, Enables Full Server Takeover

A critical vulnerability in Nginx UI with MCP support (CVE-2026-33032) leaves the /mcp_message endpoint unauthenticated, allowing attackers to invoke privileged MCP actions, modify or reload nginx configuration, and take over the server. Exploitation is active in the wild; patches were released (2.3.4, followed by 2.3.6 as the latest) and thousands of exposed instances have been identified, so admins should update immediately.

From Fame to Fallout: The Dark Side of 90s Boy Bands
entertainment4 months ago

From Fame to Fallout: The Dark Side of 90s Boy Bands

Investigation Discovery's Boy Band Confidential pulls back the curtain on how the 1990s boy-band phenomenon thrived on predatory contracts and revenue skimming, with Lou Pearlman’s empire extracting control and money from groups like NSYNC and the Backstreet Boys. The documentary covers exploitation in contracts (high manager take, hefty recoupables), the industry’s racial and marketing biases, mental-health struggles among members, and disturbing abuse allegations against figures tied to the scene, including Pearlman and manager Joby Harte, along with the lawsuits, fraud charges, and eventual collapse that reshaped the era.

Jayme Lawson Calls BAFTAs Exploitative, Urges Real Inclusion
entertainment5 months ago

Jayme Lawson Calls BAFTAs Exploitative, Urges Real Inclusion

Sinners star Jayme Lawson praised Michael B. Jordan and Delroy Lindo for how they handled a slur at the BAFTAs, but she denounced the event as exploitative rather than inclusive, arguing that inviting people into spaces without real safety and resources isn’t true inclusion. She also criticized the BBC for cutting or censoring moments in their coverage (and referenced censorship of a separate “Free Palestine” moment), saying such edits undermine dignity and protection for Black artists who contributed to the night.

Sinners Star Jayme Lawson Calls BAFTA Incident Exploitation, Urges Real Inclusion
entertainment5 months ago

Sinners Star Jayme Lawson Calls BAFTA Incident Exploitation, Urges Real Inclusion

Jayme Lawson criticized the BAFTA incident in which a guest with Tourette’s shouted the N-word at Michael B. Jordan and Delroy Lindo, calling it exploitation and urging true inclusion with safety resources; she praised how the onstage duo handled the moment, condemned the BBC and BAFTA for carelessness in coverage, and tied the event to broader issues of dignity, safety, and representation highlighted at the NAACP Image Awards.