threat-intel Remediating Vulnerabilities With LLMs: Inside Ivanti's Automation Push Ivanti is leveraging large language models (LLMs) to automate vulnerability remediation and discovery, a project initially sparked by the surprising effectiveness of the Claude 4.6 model. Daniel Spicer, Ivanti’s CSO, describes how the company is using multiple LLMs, including Anthropic’s models and open-source options,… Dark Reading · Jul 20, 2026 Medium CVE-2026-10520llmvulnerabilityautomation
malware New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos A new remote access trojan (RAT) called ChocoPoC is targeting vulnerability researchers through deceptive proof-of-concept (PoC) repositories on GitHub. The malware, disguised within Python dependencies, steals sensitive… The Hacker News · Jul 2, 2026 High CVE-2025-64446CVE-2025-55182CVE-2025-14847KRproof-of-conceptremote access trojangithub
threat-intel ⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More This week’s cybersecurity recap highlights several active exploits and attacks, including a Chrome 0-day being actively leveraged, a ShinyHunters gang exploiting a PeopleSoft zero-day for lateral movement and data exfilt… The Hacker News · Jun 15, 2026 High CVE-2026-11645CVE-2026-2441CVE-2026-3909UNCHzero-dayphishingsupply-chain
vulnerability Ivanti Sentry Exploitation Attempts Hitting Honeypots A recently patched vulnerability in Ivanti Sentry, CVE-2026-10520, has been observed attempting exploitation on honeypots, according to Ivanti and CISA. The flaw allows for remote code execution with root privileges via… SecurityWeek · Jun 12, 2026 High CVE-2026-10520USvulnerabilitycommand injectionroot privilege
vulnerability CISA orders feds to patch actively exploited Ivanti flaw by Sunday CISA has issued a Binding Operational Directive (BOD) 26-04, mandating that federal agencies patch an actively exploited vulnerability (CVE-2026-10520) in Ivanti Sentry security gateways within three days. This vulnerabi… BleepingComputer · Jun 12, 2026 Critical CVE-2026-10520patchingcisavulnerability
vulnerability Max-Severity Ivanti Flaw Exploited 24 Hours After Disclosure A critical vulnerability (CVE-2026-10520) in Ivanti Sentry was exploited within 24 hours of its disclosure, highlighting the speed at which attackers can react to newly released vulnerabilities. The flaw, an OS command i… Dark Reading · Jun 11, 2026 Critical CVE-2026-10520CVE-2026-10523CVE-2026-1340vulnerabilitycommand injectionroot access
vulnerability Max severity Ivanti Sentry vulnerability now exploited in attacks Attackers are now targeting a recently patched maximum-severity flaw in Ivanti Sentry, enabling them to execute code with root privileges on Internet-exposed secure mobile gateways. BleepingComputer · Jun 11, 2026 Medium CVE-2026-10520
vulnerability Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities This article reports on critical security vulnerabilities recently patched by Fortinet, Ivanti, and SAP. These vulnerabilities, including command injection and authentication bypass flaws, could allow unauthorized code e… The Hacker News · Jun 10, 2026 Critical CVE-2026-25089CVE-2026-10520CVE-2026-10523command injectionremote code executionauthentication bypass
vulnerability Critical Vulnerabilities Patched in Fortinet, Ivanti Products Two OS command injection flaws can be exploited remotely, without authentication, for arbitrary code execution. The post Critical Vulnerabilities Patched in Fortinet, Ivanti Products appeared first on SecurityWeek . SecurityWeek · Jun 10, 2026 CVE-2026-25089CVE-2026-10520CVE-2026-10523
vulnerability Ivanti: Max severity Sentry flaw allows code execution as root Ivanti has patched two critical vulnerabilities in its Sentry secure mobile gateway solution, including a maximum-severity flaw that enables remote attackers to execute code with root privileges. BleepingComputer · Jun 10, 2026 CVE-2026-10520CVE-2026-10523