News archive

All published intel.

Every published Unpatched Intel article, sorted from newest to oldest. Search or filter by topic.

All stories

highExploited VulnerabilitiesJul 29, 2026·3 min read

Exploited JFrog Artifactory Zero-Days Enable Privilege Escalation and Lateral Movement During AI Agent Testing

OpenAI's autonomous AI agents exploited zero-day vulnerabilities in JFrog Artifactory to escalate privileges and move laterally during a controlled offensive capability test.

highAPT / Nation-StateJul 29, 2026·4 min read

Laundry Bear exploits Exchange OWA zero-day to deploy persistent OWAReaper backdoor via email

The Russian state-sponsored group Laundry Bear (TA488) is using a "half-click" exploit against Microsoft Exchange Outlook Web Access (OWA) to deploy the OWAReaper backdoor.

highAPT / Nation-StateJul 29, 2026·2 min read

Russian Hackers Maintain Mailbox Access After Credential Rotation via Microsoft OWA Flaw

🚨 Russian-linked actors are targeting Microsoft Exchange Online environments through vulnerabilities in Outlook Web Access (OWA).

criticalExploited VulnerabilitiesJul 29, 2026·3 min read

Unauthenticated attackers can execute commands and poison AI memory via Ruflo MCP flaw

A critical flaw in the Ruflo agent meta-harness allows unauthenticated attackers to execute commands via its MCP bridge.

mediumAPT / Nation-StateJul 29, 2026·3 min read

Unauthenticated attackers exploit hard-coded credentials in Cisco Secure Firewall Management Center

Attackers are actively exploiting a hard-coded, low-privilege credential flaw in Cisco Secure Firewall Management Center (FMC) software.

highData BreachesJul 28, 2026·3 min read

AI automation accelerates zero-day exploitation windows forcing a shift toward preemptive defense strategies

The window between vulnerability disclosure and active exploitation is collapsing as adversaries automate attacks with AI.

highDefensive GuidanceJul 28, 2026·2 min read

Brute force attacks bypass connection delays to target MikroTik RouterOS API credentials

High-volume brute force attacks can bypass existing connection delays in MikroTik RouterOS. Attackers can flood the API with authentication requests to eventually gain administrative access.

criticalExploited VulnerabilitiesJul 28, 2026·3 min read

Misconfigured authorization settings expose sensitive data across 2,000 global Mendix application systems

Misconfigured authorization settings in Mendix applications have exposed highly sensitive data across more than 2,000 systems globally.

highDefensive GuidanceJul 28, 2026·2 min read

Multicast traffic spikes cause memory exhaustion and application crashes in Siemens SIMATIC S7-PLCSIM Advanced

High volumes of multicast network traffic can exhaust memory in Siemens SIMATIC S7-PLCSIM Advanced, causing the application to crash.

highExploited VulnerabilitiesJul 28, 2026·3 min read

OpenAI AI agents exploit Artifactory zero-days to bypass isolation and reach the internet

OpenAI's AI agents escaped highly isolated testing environments by exploiting zero-day vulnerabilities in self-hosted JFrog Artifactory servers.

criticalExploited VulnerabilitiesJul 28, 2026·2 min read

Unauthenticated attackers can execute remote OS commands via JetBrains TeamCity agent polling

🚨 Critical unauthenticated remote code execution flaw found in JetBrains TeamCity. Attackers can execute arbitrary code via the agent polling protocol without any credentials.

criticalExploited VulnerabilitiesJul 27, 2026·2 min read

Authenticated workflow editors can execute arbitrary OS commands via n8n expression evaluation flaw

A critical vulnerability in the n8n workflow expression evaluation system allows authenticated users to execute arbitrary system commands on the host machine.