News archive

All published intel.

Every published Unpatched Intel article, sorted from newest to oldest. Search or filter by topic.

All stories

criticalExploited VulnerabilitiesAug 25, 2026·2 min read

Attackers can alter settings on Furuno FA-50 AIS transponders via hard-coded credentials

Hard-coded credentials and missing authentication in Furuno FA-50 AIS transponders allow attackers on the internal vessel network to alter device settings and identification numbers.

highAPT / Nation-StateAug 25, 2026·2 min read

Attackers exploit Gitea code injection flaw to execute shell commands via API

Attackers are actively exploiting a code injection flaw in Gitea to run shell commands with service account privileges. This vulnerability requires repository write access to succeed.

criticalExploited VulnerabilitiesAug 25, 2026·3 min read

Unauthenticated attackers can hijack WordPress administrator accounts via miniOrange SAML 2.0 plugin flaws

Attackers are exploiting critical flaws in the miniOrange SAML 2.0 Single Sign-On plugin to hijack WordPress accounts, including administrators.

criticalAPT / Nation-StateAug 25, 2026·3 min read

Unauthenticated attackers exploit remote code execution flaws in Oracle WebLogic and HTTP Server plug-ins

Critical remote code execution flaws in Oracle HTTP Server and WebLogic Server Proxy plug-ins are being actively exploited. Attackers can compromise these systems without authentication.

criticalExploited VulnerabilitiesAug 13, 2026·3 min read

Attackers exploit VMware vCenter Syslog directory traversal flaw for remote code execution

Attackers are actively exploiting a critical directory traversal vulnerability in the VMware vCenter Syslog server to gain remote code execution.

highAPT / Nation-StateAug 13, 2026·2 min read

Hard-coded credentials and unauthenticated flaws expose ANDRITZ HIPASE-250 process data and workstations

Critical vulnerabilities in the ANDRITZ HIPASE-250 system allow unauthenticated attackers to steal passwords, view live process data, and suppress audit logs.

highDefensive GuidanceAug 13, 2026·2 min read

Remote file reading and root privilege escalation vulnerabilities found in Siemens License Server

Critical flaws in the Siemens License Server (SLS) could allow attackers to read arbitrary files remotely or gain full root access via local privilege escalation.

highDefensive GuidanceAug 13, 2026·2 min read

Specially crafted X_T files trigger arbitrary code execution in Siemens Parasolid software

A high-severity out of bounds read vulnerability in Siemens Parasolid could allow an attacker to execute arbitrary code or crash the application.

highExploited VulnerabilitiesAug 12, 2026·2 min read

Ivanti releases critical patches for Endpoint Manager vulnerabilities targeting credentials and S3 buckets

Ivanti has released critical updates to address multiple high-severity vulnerabilities in Endpoint Manager (EPM) that could lead to credential theft and unauthorized S3 bucket control.

highExploited VulnerabilitiesAug 12, 2026·4 min read

Lazarus Group exploits Windows kernel vulnerability to escalate privileges via fake job offers

Lazarus Group is exploiting a Windows kernel vulnerability to escalate privileges and deploy backdoors via fake job offers.

criticalExploited VulnerabilitiesAug 12, 2026·2 min read

Unauthenticated attackers can achieve full system compromise via critical Adobe ColdFusion flaws

🚨 Critical flaw in Adobe ColdFusion 2025 enables full system compromise. Attackers can execute arbitrary commands without any user interaction or authentication.

highExploited VulnerabilitiesAug 12, 2026·3 min read

Unauthenticated attackers exploit SharePoint vulnerability to bypass authentication and hijack administrative accounts

Attackers are actively exploiting a critical authentication bypass in Microsoft SharePoint. This flaw allows unauthenticated remote users to impersonate site users or administrators and modify data.