Vulnerability Management3 September 2026
CISA Adds Seven Actively Exploited Flaws to KEV — Shells and Miners Follow
A fresh CISA KEV batch spans SonicWall, Sangoma, JFrog, Kestra and LiteLLM — and in several cases the exploitation has already moved past initial access to reverse shells and cryptomining.
cisa-kevvulnerability-managementsonicwall
4 min readRead
Vulnerability Management18 August 2026
CISA KEV Alert: Ray's Browser-Triggered RCE Flaw Is Now Actively Exploited
A critical Ray vulnerability lets a malicious webpage hijack a developer's local AI cluster through DNS rebinding — CISA's KEV listing confirms it's no longer theoretical.
raycisa-kevai-infrastructure
4 min readRead