Tag: injection
-
Salt Security adds native AI detection and response to agentic security platform
Salt Security has expanded its Agentic Security Platform with native AI Detection and Response (AI-DR) capabilities designed to connect attacks targeting large language models with subsequent activity across MCP servers, tools and APIs. The new capabilities provide real-time protection against direct and indirect prompt injection, jailbreak attempts, unsafe model behaviour and other threats that emerge…
-
Critical MaxKB AI Agent Flaw Lets Prompt Injection Execute System Commands
A critical vulnerability in the MaxKB AI knowledge-base platform could let attackers exploit prompt injection and run operating system commands on vulnerable deployments, including directly on the underlying host in some configurations. This flaw, tracked as CVE-2026-77521 and GHSA-f36j-f34j-h3rx, affects MaxKB versions up to and including 2.10.3-lts. The issue has received a maximum CVSS v3.1…
-
The Target Is No Longer the Model. It’s the Agent.
AI agents are becoming the new attack surface, exposed to poisoned skills, prompt injection, jailbreaks and attacks through connected tools. I read the AI security research published in a single month, February 2026, and when you put it all together, it’s not a list of curiosities. It’s a field guide to a new attack surface.…
-
New Cache Key Injection Attack Lets Hackers Bypass Access Controls and Poison Nginx Caches
Security researchers have unveiled a cache poisoning technique called cache key injection that lets attackers bypass access controls, expose cached sensitive pages, trigger denial-of-service conditions, and potentially execute stored cross-site scripting (XSS) attacks against vulnerable Nginx deployments. Research by YesWeHack researcher Alex Brumen highlights flaws that occur when web caches create cache keys by directly…
-
New Cache Key Injection Attack Lets Hackers Bypass Access Controls and Poison Nginx Caches
Security researchers have unveiled a cache poisoning technique called cache key injection that lets attackers bypass access controls, expose cached sensitive pages, trigger denial-of-service conditions, and potentially execute stored cross-site scripting (XSS) attacks against vulnerable Nginx deployments. Research by YesWeHack researcher Alex Brumen highlights flaws that occur when web caches create cache keys by directly…
-
New Cache Key Injection Attack Lets Hackers Bypass Access Controls and Poison Nginx Caches
Security researchers have unveiled a cache poisoning technique called cache key injection that lets attackers bypass access controls, expose cached sensitive pages, trigger denial-of-service conditions, and potentially execute stored cross-site scripting (XSS) attacks against vulnerable Nginx deployments. Research by YesWeHack researcher Alex Brumen highlights flaws that occur when web caches create cache keys by directly…
-
New Cache Key Injection Attack Lets Hackers Bypass Access Controls and Poison Nginx Caches
Security researchers have unveiled a cache poisoning technique called cache key injection that lets attackers bypass access controls, expose cached sensitive pages, trigger denial-of-service conditions, and potentially execute stored cross-site scripting (XSS) attacks against vulnerable Nginx deployments. Research by YesWeHack researcher Alex Brumen highlights flaws that occur when web caches create cache keys by directly…
-
Intent injection attacks are a new worry for AI-native 6G networks
Intent-based networking (IBN) lets operators state the outcome they want and leaves its translation into network policy to software, an approach AI-native 6G designs have … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/21/6g-intent-injection-attacks/
-
Intent injection attacks are a new worry for AI-native 6G networks
Intent-based networking (IBN) lets operators state the outcome they want and leaves its translation into network policy to software, an approach AI-native 6G designs have … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/21/6g-intent-injection-attacks/
-
Intent injection attacks are a new worry for AI-native 6G networks
Intent-based networking (IBN) lets operators state the outcome they want and leaves its translation into network policy to software, an approach AI-native 6G designs have … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/21/6g-intent-injection-attacks/
-
Intent injection attacks are a new worry for AI-native 6G networks
Intent-based networking (IBN) lets operators state the outcome they want and leaves its translation into network policy to software, an approach AI-native 6G designs have … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/21/6g-intent-injection-attacks/
-
Aktiv ausgenutzte SQL Injection – Root-Zugriff auf Cisco Secure Email Gateway per E-Mail
First seen on security-insider.de Jump to article: www.security-insider.de/cisco-secure-email-gateway-sql-injection-root-rechte-a-9e285fdd581f2d5e9a7203bf213d3f82/
-
Apache Superset SQL Injection Flaw Gets Public PoC Exploit
A public proof-of-concept exploit has been released for CVE-2026-23980, a SQL injection vulnerability affecting Apache Superset installations running versions earlier than 6.0.0. The Apache Superset project disclosed this issue in February. It classified it as an improper neutralization of special elements in a SQL command. Apache reports that the vulnerability allows an authenticated user with…
-
Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)
Attackers have leveraged a zero-day SQL injection vulnerability (CVE-2026-76461) to compromise Cisco Secure Email Gateway appliances, Cisco confirmed on Monday. The … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/15/cve-2026-76461-cisco-email-gateway-zero-day-exploited/
-
AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process
A five-stage AsyncRAT campaign that chains a socially engineered batch file, hidden PowerShell execution, AutoIt abuse and process injection to conceal a .NET remote-access trojan inside Microsoft’s legitimate charmap.exe process. The infection begins with a lure named “Right-click to open Invoice Details.bat”, which relies on user interaction to trigger execution. While the precise delivery method…
-
The Cyber Express Weekly Roundup: Iranian Bounty, Airline Data Leak, and AI-Model Prompt Injection
This weekly roundup covers a bounty offer targeting an alleged Iranian cyber official, a massive data-exposure incident affecting airline travelers, a breach of an education platform used by students, a flaw exposing ChatGPT users’ Gmail data, and a new EU compliance deadline for connected-product manufacturers. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/weekly-roundup-iran-bounty-airline-leak/
-
Okta Patches Auth0 and Access Gateway Vulnerabilities Let Attackers Enable XSS, Authentication Bypass and SQL Injection
Okta has released security updates for three high-severity vulnerabilities affecting the Auth0 AD/LDAP Connector and Okta Access Gateway. These vulnerabilities could allow authenticated attackers to trigger stored cross-site scripting (XSS), bypass Protected Rule authorization controls, or execute unintended SQL commands against configured backend databases under specific deployment conditions. All three vulnerabilities were disclosed on September…
-
New AI Workflow Identity Hijacking Attack Lets Hackers Exfiltrate Sensitive Data
Security researchers have recently disclosed a new enterprise AI attack technique known as Workflow Identity Hijacking. This method enables external attackers to exfiltrate sensitive corporate information by submitting seemingly harmless requests to AI-powered automations. Research published by Noma Labs researcher Sasi Levi reveals that this attack does not rely on prompt injection, stolen credentials, or…
-
Your AI Didn’t Lie to You: It Was Just Being Manipulated
Hidden AI Activity Creates Security Gaps That Traditional Controls Can’t Detect As AI agents gain access to critical business systems, prompt injection, shadow AI and poisoned data can manipulate decisions without triggering traditional controls. Full-pipeline telemetry and continuous testing can help security teams investigate incidents while maintaining human accountability. First seen on govinfosecurity.com Jump to…
-
Roundcube Fixes 12 Security Flaws Including Zero-Click XSS and SSRF Bypass
Roundcube has released security updates 1.6.19 and 1.7.4, which address 12 vulnerabilities affecting its 1.6 LTS and 1.7 Webmail branches. The flaws include a zero-click stored cross-site scripting (XSS) vulnerability, several bypasses of remote content filtering, email header injection bugs, cross-user contact access issues, and a server-side request forgery (SSRF) bypass. Published on September 6,…
-
Microsoft Finds ASCII Smuggling Repurposed for Phishing Campaign
Attackers have adapted a technique popularized in AI prompt injection research for a high-volume phishing campaign, using invisible Unicode characters to evade email filtering, Microsoft researchers reported Thursday. The finding came from Microsoft Defender for Office 365 prompt injection protection research. A hunting signature built to detect ASCII smuggling in email recorded a surge beginning..…
-
Hackers Abuse AI-Era ASCII Smuggling to Hide Phishing Content in Millions of Emails
Threat actors have repurposed an AI prompt-injection technique known as ASCII smuggling to evade email security controls at massive scale, hiding invisible Unicode characters within financial phishing lures. Microsoft observed the activity reach more than 2.3 million messages per day, demonstrating how techniques first popularized in AI-security research can quickly migrate into conventional phishing operations.…
-
Sangoma Switchvox RCE Flaw Actively Exploited in Wild via Unauthenticated SQL Injection
Tags: cve, cyber, data-breach, exploit, flaw, injection, Internet, rce, remote-code-execution, sql, voip, vulnerabilitySecurity researchers have reported active exploitation attempts targeting a critical vulnerability in Sangoma Switchvox, allowing unauthenticated attackers to execute code remotely via SQL injection. This vulnerability, tracked as CVE-2026-9586, affects internet-exposed Switchvox enterprise VoIP systems and was addressed in Switchvox version 8.4.0.2. Sangoma Switchvox RCE Flaw Zach Hanley, a researcher at Horizon3.ai, revealed that this…
-
WordPress Plugin Flaw Lets Attackers Turn SQL Injection Into Complete Site Takeover
Tags: backup, cve, cyber, exploit, flaw, injection, remote-code-execution, sql, vulnerability, wordpressA high-severity vulnerability affecting over 5 million active WordPress installations could allow unauthenticated attackers to exploit stored SQL injection vulnerabilities, leading to remote code execution and complete website takeover. This issue, tracked as CVE-2026-19949, impacts the widely used All-in-One WP Migration and Backup plugin developed by ServMask. Wordfence has rated the vulnerability 8.8 out of…
-
Critical SQL injection vulnerability in Sangoma Switchvox exploited in the wild
First seen on scworld.com Jump to article: www.scworld.com/brief/critical-sql-injection-vulnerability-in-sangoma-switchvox-exploited-in-the-wild
-
Hackers exploit Sangoma Switchvox flaw to deploy reverse shells
Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-exploit-sangoma-switchvox-flaw-to-deploy-reverse-shells/
-
WordPress backup plugin flaw exposes millions of sites to takeover attacks
An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affected websites. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/wordpress-backup-plugin-flaw-exposes-millions-of-sites-to-takeover-attacks/
-
Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)
A threat actor is actively targeting internet-exposed Sangoma Switchvox instance through a recently patched SQL injection flaw (CVE-2026-9586), and organizations running them … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/02/exploitation-of-sangoma-switchvox-flaw-underway-cve-2026-9586/
-
Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials
Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution.The vulnerability in question is CVE-2026-9586 (CVSS score: 9.3), a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3 (104997) that can allow attackers to remotely execute arbitrary code as First seen…
-
Critical GiveWP Flaw Lets Attackers Run Commands on WordPress Servers
A critical GiveWP flaw lets unauthenticated attackers execute server commands. Version 4.16.7.2 fixes the PHP object injection chain. A critical vulnerability in GiveWP, one of the most widely used WordPress plugins for online donations and fundraising, can let an unauthenticated attacker execute commands on the server. Patchstack disclosed the flaw on August 28, after researcher…

