Latest updates for Active Exploitation

Fresh curated links around Active exploitation are collected here so marketers can spot useful updates and turn timely ideas into posts faster.

Recent items include:

  • Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability
  • Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit
  • Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer

Post angles to try

Share the most useful takeaway for your audience.
Turn one article into a quick practical checklist.
Ask your audience how this shift affects their work.
Turn angles into scheduled posts

Fresh articles and ideas

Recent curated links from global sources. Generate one free draft from any story, then use SocialBu to schedule and refine your content calendar.

cloud.google.com /5 days ago

Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability

Written by: Takahiro Sugiyama, Peter Revelant, Mathew Potaczek Introduction In late 2025, Mandiant responded to a security incident involving a compromised web server running Know...

Read source
thehackernews.com /1 day ago

Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit

An unknown threat actor has been observed using a large language model (LLM) agent to conduct post-compromise actions after obtaining initial access following the exploitation of a...

Read source
thehackernews.com /2 days ago

Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer

Threat actors are continuing to exploit a critical, now-patched security flaw impacting FortiClient Endpoint Management Server (EMS) deployments to deliver credential-stealing malw...

Read source
go.theregister.com /1 month ago

Claude Opus wrote a Chrome exploit for $2,283

Pause your Mythos panic because mainstream models anyone can use already pick holes in popular software Anthropic withheld its Mythos bug-finding model from public release due to c...

Read source
vmblog.com /3 days ago

Proofpoint Introduces Active Exploits Protection to Help Organizations Prioritize Vulnerability Patching for Real-World...

Proofpoint, Inc. announced Active Exploits Protection, a new solution that empowers organizations to defend against the growing exposure to AI-accelerated cyber

Read source
cofense.com /1 month ago

Weaponizing Apathy: How Threat Actors Exploit Vulnerabilities and Legitimate Software

Threat actors increasingly exploit legitimate software and known vulnerabilities to evade detection and deliver attacks. Tools like Microsoft Office and Remote Access Tools enable...

Read source
thehackernews.com /1 month ago

LMDeploy CVE-2026-33626 Flaw Exploited Within 13 Hours of Disclosure

A high-severity security flaw in LMDeploy, an open-source toolkit for compressing, deploying, and serving LLMs, has come under active exploitation in the wild less than 13 hours af...

Read source
thehackernews.com /1 month ago

Microsoft Confirms Active Exploitation of Windows Shell CVE-2026-32202

Microsoft on Monday revised its advisory for a now-patched, high-severity security flaw impacting Windows Shell to acknowledge that it has been actively exploited in the wild. The...

Read source
theregister.com /3 weeks ago

Attackers are cashing in on fresh 'CopyFail' Linux flaw

Researchers dropped a reliable root exploit and it didn’t sit idle for long

Read source
thehackernews.com /3 weeks ago

Ivanti EPMM CVE-2026-6973 RCE Under Active Exploitation Grants Admin-Level Access

Ivanti is warning that a new security flaw impacting Endpoint Manager Mobile (EPMM) has been explored in limited attacks in the wild. The high-severity vulnerability, CVE-2026-6973...

Read source
thehackernews.com /3 weeks ago

PAN-OS RCE Exploit Under Active Use Enabling Root Access and Espionage

Palo Alto Networks has disclosed that threat actors may have attempted to unsuccessfully exploit a recently disclosed critical security flaw as early as April 9, 2026. The vulnerab...

Read source
cryptoslate.com /4 days ago

The next big DeFi exploit will start before the code is deployed

Socket's May 24 disclosure of TrapDoor found more than 34 malicious packages and over 384 related versions spread across npm, PyPI, and Crates.io, each targeting the developers who...

Read source
gbhackers.com /2 weeks ago

PraisonAI Vulnerability Actively Exploited Within Hours of Being Made Public

A high-severity vulnerability in PraisonAI is drawing urgent attention after security researchers observed exploitation attempts within hours of public disclosure. The flaw, tracke...

Read source
techcrunch.com /1 month ago

Hackers are actively exploiting a bug in cPanel, used by millions of websites

Web hosts are scrambling to fix the bug under active attack by hackers. One company said hackers have been abusing the bug for months.

Read source
thehackernews.com /3 weeks ago

Weaver E-cology RCE Flaw CVE-2026-22679 Actively Exploited via Debug API

A critical security vulnerability in Weaver (Fanwei) E-cology, an enterprise office automation (OA) and collaboration platform, has come under active exploitation in the wild. The...

Read source
thehackernews.com /1 month ago

LiteLLM CVE-2026-42208 SQL Injection Exploited within 36 Hours of Disclosure

In yet another instance of threat actors quickly jumping on the exploitation bandwagon, a newly disclosed critical security flaw in BerriAI's LiteLLM Python package has come under...

Read source
gbhackers.com /1 month ago

Attackers Exploit LMDeploy Flaw in the Wild Within 12 Hours of Advisory

A critical Server-Side Request Forgery (SSRF) vulnerability in LMDeploy’s vision-language module was exploited in active attacks just 12 hours and 31 minutes after its public discl...

Read source
gbhackers.com /1 month ago

Hackers Target Adobe Reader Users With Sophisticated Zero-Day Exploit

Security researchers at EXPMON have uncovered a highly sophisticated, unpatched zero-day vulnerability actively targeting Adobe Reader users. The exploit, first detected in the wil...

Read source
thehackernews.com /3 weeks ago

Palo Alto PAN-OS Flaw Under Active Exploitation Enables Remote Code Execution

Palo Alto Networks has released an advisory warning that a critical buffer overflow vulnerability in its PAN-OS software has been exploited in the wild. The vulnerability, tracked...

Read source
thehackernews.com /4 days ago

KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike

A now-patched high-severity security flaw affecting Digital Knowledge KnowledgeDeliver, a Learning Management System (LMS) popular in Japan, was exploited as a zero-day to deliver...

Read source
techcrunch.com /3 weeks ago

Hackers are mass-exploiting the cPanel bug to gain control of thousands of websites

Days after the disclosure of a critical vulnerability in popular web hosting software cPanel and WHM, hackers are now targeting and hacking thousands of vulnerable websites.

Read source
thehackernews.com /1 month ago

EtherRAT Distribution Spoofing Administrative Tools via GitHub Facades

Intro A sophisticated, high-resilience malicious campaign was identified by Atos Threat Research Center (TRC) in March 2026. This operation specifically targets the high-privilege...

Read source
gbhackers.com /3 weeks ago

Critical Weaver E-cology RCE Exploit Raises Alarm for Enterprise Systems

A critical unauthenticated remote code execution vulnerability in Weaver (Fanwei) E-cology is being actively exploited in the wild, with real-world intrusion activity traced back t...

Read source
smartermsp.com /1 month ago

Cybersecurity Threat Advisory: Active exploitation of Fortinet SQL injection vulnerability

Fortinet has issued urgent security guidance following the active exploitation of a critical SQL injection vulnerability affecting FortiClient Enterprise Management Server (EMS). T...

Read source

Turn fresh research into a full content calendar

Use SocialBu to discover ideas, generate post drafts, and schedule them across your social channels.

Sources covering Active Exploitation

smartermsp.com

Recent coverage from public sources
Public source

blogs.vmware.com

Recent coverage from public sources
Public source

cloudblog.withgoogle.com

Recent coverage from public sources
Public source

cofense.com

Recent coverage from public sources
Public source

cryptoslate.com

Recent coverage from public sources
Public source

feeds.feedburner.com

Recent coverage from public sources
Public source