June 26, 2026
- CVE-2025-52465 ("GeoLocate") in GeoServer is being exploited in the wild — admins can dump plaintext master passwords, enabling JSP webshell injection and (on Windows with UNC paths) NTLM credential leakage. partywave.site · Vulnerabilities & Exploits
in Malware Weaponizes Prompt Injection to Sabotage AI Analysis as Gamaredon Retools Against Ukraine