π€ Desktop AI Supercomputers and Automated Cyberattacks
AI supercomputers now fit on a desk. Combine them with uncensored open models and autonomous agents, and cyberattacks become cheaper, faster, and far easier to scale.
β Why local AI changes the economics of offensive operations
β How model guardrails can be removed or bypassed
β How agents automate reconnaissance, exploitation, and retries
β Why defenders must prepare for same-day, machine-speed attacks
β± 12 min read
π https://netlas.io/blog/desktop_ai_supercomputers_and_automated_attacks/
AI supercomputers now fit on a desk. Combine them with uncensored open models and autonomous agents, and cyberattacks become cheaper, faster, and far easier to scale.
β Why local AI changes the economics of offensive operations
β How model guardrails can be removed or bypassed
β How agents automate reconnaissance, exploitation, and retries
β Why defenders must prepare for same-day, machine-speed attacks
β± 12 min read
π https://netlas.io/blog/desktop_ai_supercomputers_and_automated_attacks/
netlas.io
Desktop AI Supercomputers and Automated Cyberattacks - Netlas Blog
How local AI hardware, uncensored open models, and agent frameworks are lowering the cost and accelerating the scale of automated cyberattacks.
β€5π₯5
CVE-2026-64638: Pre-auth reflected XSS in WordPress, 8.9 rating βπ₯
WordPress is vulnerable to a pre-auth reflected cross-site scripting (XSS) on the login screen, which can be escalated to RCE.
Search at Netlas.io:
π Link: https://nt.ls/SjACB
π Dork: tag.name:"wordpress"
Vendor's advisory:
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-52p2-r8wf-jcrf
WordPress is vulnerable to a pre-auth reflected cross-site scripting (XSS) on the login screen, which can be escalated to RCE.
Search at Netlas.io:
π Link: https://nt.ls/SjACB
π Dork: tag.name:"wordpress"
Vendor's advisory:
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-52p2-r8wf-jcrf
π₯3β€2
0-day SQL Injection in Metabase, no CVE assigned yet, 10.0 rating βπ₯π₯π₯
Recently disclosed vulnerability in Metabase allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. This vulnerability is already being actively exploited in the wild!
Search at Netlas.io:
π Link: https://nt.ls/q4U1I
π Dork: http.favicon.hash_sha256:61c0353e2bde23f74f7febc277df979fbc1017186de060fd9bd8d07b65bcac13 OR http.headers.set_cookie:"metabase.DEVICE" OR http.title:"Metabase"
Vendor's advisory:
https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf
Recently disclosed vulnerability in Metabase allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. This vulnerability is already being actively exploited in the wild!
Search at Netlas.io:
π Link: https://nt.ls/q4U1I
π Dork: http.favicon.hash_sha256:61c0353e2bde23f74f7febc277df979fbc1017186de060fd9bd8d07b65bcac13 OR http.headers.set_cookie:"metabase.DEVICE" OR http.title:"Metabase"
Vendor's advisory:
https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf
π₯4β€2π2
CVE-2026-44945: A privilege escalation vulnerability in Rancher, 9.1 rating βπ₯
An authenticated Rancher low-privileged user can gain full administrative access to the Rancher control plane and transitively to all downstream clusters it manages.
Search at Netlas.io:
π Link: https://nt.ls/FGN75
π Dork: http.favicon.hash_sha256:2d7adbc74e7c8941927d04e702acbff577d219fef8617c8c3014d34ae395525b OR http.body:"<title>Rancher</title>" OR http.unknown_headers.key:"x_api_cattle_auth"
Vendor's advisory:
https://github.com/rancher/rancher/security/advisories/GHSA-v584-7w32-jwpq
An authenticated Rancher low-privileged user can gain full administrative access to the Rancher control plane and transitively to all downstream clusters it manages.
Search at Netlas.io:
π Link: https://nt.ls/FGN75
π Dork: http.favicon.hash_sha256:2d7adbc74e7c8941927d04e702acbff577d219fef8617c8c3014d34ae395525b OR http.body:"<title>Rancher</title>" OR http.unknown_headers.key:"x_api_cattle_auth"
Vendor's advisory:
https://github.com/rancher/rancher/security/advisories/GHSA-v584-7w32-jwpq
π₯4β€3
CVE-2026-44901 and other: Critical bugs in Wazuh Manager, up to 9.1 rating βπ₯
Recently disclosed vulnerabilities in Wazuh Manager allow an attacker to execute arbitrary code, read and write arbitrary files. PoCs exist for all of them!
Search at Netlas.io:
π Link: https://nt.ls/COx2Y
π Dork: certificate.issuer_dn:"Wazuh" OR http.headers.server:"Wazuh" OR raw.banner:"Unable to add agent"
Vendor's advisory:
https://github.com/wazuh/wazuh/security/advisories/GHSA-8c6v-7g3w-prrq
Recently disclosed vulnerabilities in Wazuh Manager allow an attacker to execute arbitrary code, read and write arbitrary files. PoCs exist for all of them!
Search at Netlas.io:
π Link: https://nt.ls/COx2Y
π Dork: certificate.issuer_dn:"Wazuh" OR http.headers.server:"Wazuh" OR raw.banner:"Unable to add agent"
Vendor's advisory:
https://github.com/wazuh/wazuh/security/advisories/GHSA-8c6v-7g3w-prrq
β€2π2π₯2
Chaining two vulnerabilities could allow RCE in MariaDB, no CVE assigned yet βπ₯
Recently disclosed vulnerabilities in MariaDB allow a low-privileged attacker to run arbitrary commands as the mariadb process. PoC is already available!
Search at Netlas.io:
π Link: https://nt.ls/Dp2Ed
π Dork: tag.name:"mariadb"
Read more:
https://github.com/v12-security/pocs/tree/main/mariadb
Recently disclosed vulnerabilities in MariaDB allow a low-privileged attacker to run arbitrary commands as the mariadb process. PoC is already available!
Search at Netlas.io:
π Link: https://nt.ls/Dp2Ed
π Dork: tag.name:"mariadb"
Read more:
https://github.com/v12-security/pocs/tree/main/mariadb
π₯4β€3π2
CVE-2026-65640: Authenticated RCE in WordPress, 8.8 rating βπ₯
A recently disclosed vulnerability in WordPress allows an attacker with an Author-level privileges to upload malicious Postscript files, which could lead to RCE. This issue affects sites that use Imagick and Ghostscript.
Search at Netlas.io:
π Link: https://nt.ls/LrDYt
π Dork: tag.name:"wordpress"
Vendor's advisory:
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-8vr3-7mxf-gx8w
A recently disclosed vulnerability in WordPress allows an attacker with an Author-level privileges to upload malicious Postscript files, which could lead to RCE. This issue affects sites that use Imagick and Ghostscript.
Search at Netlas.io:
π Link: https://nt.ls/LrDYt
π Dork: tag.name:"wordpress"
Vendor's advisory:
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-8vr3-7mxf-gx8w
β€1π₯1
CVE-2026-71479: Integer overflow in New API, 9.1 rating βπ₯
A recently disclosed integer overflow vulnerability in New API allows low-privileged accounts with a positive balance or an active subscription to credit themselves an arbitrarily large amount. This vulnerability is already being actively exploited in the wild!
Search at Netlas.io:
π Link: https://nt.ls/XoA0U
π Dork: http.favicon.hash_sha256:32132a307cad98d7f93b0384de87411f087bb34c148c932dcd5eea92101cbec3 OR http.unknown_headers.key:"x_new_api_version" OR http.title:"New API"
Vendor's advisory:
https://github.com/QuantumNous/new-api/security/advisories/GHSA-8r8v-xf7q-rcpr
A recently disclosed integer overflow vulnerability in New API allows low-privileged accounts with a positive balance or an active subscription to credit themselves an arbitrarily large amount. This vulnerability is already being actively exploited in the wild!
Search at Netlas.io:
π Link: https://nt.ls/XoA0U
π Dork: http.favicon.hash_sha256:32132a307cad98d7f93b0384de87411f087bb34c148c932dcd5eea92101cbec3 OR http.unknown_headers.key:"x_new_api_version" OR http.title:"New API"
Vendor's advisory:
https://github.com/QuantumNous/new-api/security/advisories/GHSA-8r8v-xf7q-rcpr
β€2π₯2
CVE-2026-60702 and other: Vulnerabilities in Oracle WebLogic Server, up to 9.9 rating βπ₯
A recently disclosed vulnerabilities in Oracle WebLogic Server allow low-privileged or unauthenticated attacker to compromise the server.
Search at Netlas.io:
π Link: https://nt.ls/jX2A4
π Dork: tag.name:"weblogic"
Vendor's advisory:
https://www.oracle.com/security-alerts/cspuaug2026.html#AppendixFMW
A recently disclosed vulnerabilities in Oracle WebLogic Server allow low-privileged or unauthenticated attacker to compromise the server.
Search at Netlas.io:
π Link: https://nt.ls/jX2A4
π Dork: tag.name:"weblogic"
Vendor's advisory:
https://www.oracle.com/security-alerts/cspuaug2026.html#AppendixFMW
β€2π₯2π1
CVE-2026-73570: Unauthenticated RCE in Zimbra, 8.9 rating βπ₯
A Zimbra vulnerability disclosed last week is now being actively exploited in the wild. It allows an unauthenticated attacker to execute arbitrary OS commands as the Zimbra user via specially crafted requests. Successful exploitation requires the optional zimbra-snmp package and enabled SNMP notifications.
Search at Netlas.io:
π Link: https://nt.ls/RfXS9
π Dork: tag.name:"zimbra"
Vendor's advisory:
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
A Zimbra vulnerability disclosed last week is now being actively exploited in the wild. It allows an unauthenticated attacker to execute arbitrary OS commands as the Zimbra user via specially crafted requests. Successful exploitation requires the optional zimbra-snmp package and enabled SNMP notifications.
Search at Netlas.io:
π Link: https://nt.ls/RfXS9
π Dork: tag.name:"zimbra"
Vendor's advisory:
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
β€3π₯3
CVE-2026-19490: Authentication bypass in Citrix NetScaler ADC and NetScaler Gateway, 9.3 rating βπ₯
A recently disclosed authentication bypass vulnerability affects customer-managed NetScaler ADC and NetScaler Gateway. The appliance must be configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server.
Search at Netlas.io:
π Link: https://nt.ls/Ebg2V
π Dork (NetScaler ADC): http.headers.set_cookie:"citrix_ns_id" OR http.headers.set_cookie:"ns_af" OR http.headers.set_cookie:"NSC_" OR http.headers.set_cookie:"NSC_ESNS"
π Dork (NetScaler Gateway): http.title:"citrix gateway" OR http.headers.set_cookie:"pwcount" OR http.favicon.hash_sha256:7b2fe2b7235b6645998edcae988ce1edaac40764c202abc3a4766db1b8ae6360 OR http.favicon.hash_sha256:3e8f8b98d8fe34a5e627c3033f0940777144effe4b5f588c67bfc6ba3bf106fa
Vendor's advisory:
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939
A recently disclosed authentication bypass vulnerability affects customer-managed NetScaler ADC and NetScaler Gateway. The appliance must be configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server.
Search at Netlas.io:
π Link: https://nt.ls/Ebg2V
π Dork (NetScaler ADC): http.headers.set_cookie:"citrix_ns_id" OR http.headers.set_cookie:"ns_af" OR http.headers.set_cookie:"NSC_" OR http.headers.set_cookie:"NSC_ESNS"
π Dork (NetScaler Gateway): http.title:"citrix gateway" OR http.headers.set_cookie:"pwcount" OR http.favicon.hash_sha256:7b2fe2b7235b6645998edcae988ce1edaac40764c202abc3a4766db1b8ae6360 OR http.favicon.hash_sha256:3e8f8b98d8fe34a5e627c3033f0940777144effe4b5f588c67bfc6ba3bf106fa
Vendor's advisory:
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939
π₯4β€3
CVE-2026-77806: Unauthenticated RCE in SPIP with public exploit and active exploitation, 9.8 rating βπ₯
A recently disclosed vulnerability in SPIP allows unauthenticated remote attackers to execute arbitrary code. Public exploit code has been added to the Metasploit framework. This vulnerability is being actively exploited in the wild!
Search at Netlas.io:
π Link: https://nt.ls/SeHVc
π Dork: tag.name:"spip"
Vendor's advisory:
https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-4-21.html?lang=fr
A recently disclosed vulnerability in SPIP allows unauthenticated remote attackers to execute arbitrary code. Public exploit code has been added to the Metasploit framework. This vulnerability is being actively exploited in the wild!
Search at Netlas.io:
π Link: https://nt.ls/SeHVc
π Dork: tag.name:"spip"
Vendor's advisory:
https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-4-21.html?lang=fr
π₯3β€2
This media is not supported in your browser
VIEW IN TELEGRAM
πΊ Netlas v1.9 β Rebuild Your Attack Surface
Attack surfaces change over time β infrastructure appears, disappears, and moves. With the new interactive rebuild in Netlas Discovery, you can update an existing attack surface using the latest Netlas data.
β Replay the complete discovery history step by step
β Decide whether to add newly discovered nodes
β Keep or remove data no longer found in current indices
β Preserve graph layout and comments
β New scanner protocols: BACnet and MSRPC
β New API endpoints for single and bulk rescans
β 20+ security fixes
Full changelog: https://docs.netlas.io/changelog/
Attack surfaces change over time β infrastructure appears, disappears, and moves. With the new interactive rebuild in Netlas Discovery, you can update an existing attack surface using the latest Netlas data.
β Replay the complete discovery history step by step
β Decide whether to add newly discovered nodes
β Keep or remove data no longer found in current indices
β Preserve graph layout and comments
β New scanner protocols: BACnet and MSRPC
β New API endpoints for single and bulk rescans
β 20+ security fixes
Full changelog: https://docs.netlas.io/changelog/
π₯6β€4πΎ2
CVE-2026-19632: Account takeover vulnerability in TranslatePress WordPress plugin, 9.8 rating βπ₯
A recently disclosed vulnerability in the TranslatePress WordPress plugin allows unauthenticated attackers to extract an administratorβs password reset link, reset the accountβs password, and log in as that administrator, leading to complete site takeover.
Search at Netlas.io:
π Link: https://nt.ls/oe1hr
π Dork: http.body:"plugins/translatepress-multilingual"
Vendor's advisory:
https://www.wordfence.com/blog/2026/08/400000-wordpress-sites-affected-by-account-takeover-vulnerability-in-translatepress-wordpress-plugin/
A recently disclosed vulnerability in the TranslatePress WordPress plugin allows unauthenticated attackers to extract an administratorβs password reset link, reset the accountβs password, and log in as that administrator, leading to complete site takeover.
Search at Netlas.io:
π Link: https://nt.ls/oe1hr
π Dork: http.body:"plugins/translatepress-multilingual"
Vendor's advisory:
https://www.wordfence.com/blog/2026/08/400000-wordpress-sites-affected-by-account-takeover-vulnerability-in-translatepress-wordpress-plugin/
π₯5β€3
Zero-day vulnerability in PaperCut Software with active exploitation, no CVE assigned yet βπ₯
PaperCut disclosed an emergency alert about a vulnerability in PaperCut NG/MF. No details have been disclosed, but it is known that it is being actively exploited in the wild.
Search at Netlas.io:
π Link: https://nt.ls/n7oWU
π Dork (PaperCut MF): http.favicon.hash_sha256:fab4df1b834bf0ff6389d2315cc0d639d55cf6daef8e0880302150d1d48b3576 OR http.favicon.hash_sha256:ce5cefdb0b9c7fbf8d204660447db9878316dbfe5d56f47455419f435ebd6464 OR http.meta:"PaperCut MF is a print management system"OR http.body:"<title>PaperCut Login"
Vendor's advisory:
https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/
PaperCut disclosed an emergency alert about a vulnerability in PaperCut NG/MF. No details have been disclosed, but it is known that it is being actively exploited in the wild.
Search at Netlas.io:
π Link: https://nt.ls/n7oWU
π Dork (PaperCut MF): http.favicon.hash_sha256:fab4df1b834bf0ff6389d2315cc0d639d55cf6daef8e0880302150d1d48b3576 OR http.favicon.hash_sha256:ce5cefdb0b9c7fbf8d204660447db9878316dbfe5d56f47455419f435ebd6464 OR http.meta:"PaperCut MF is a print management system"OR http.body:"<title>PaperCut Login"
Vendor's advisory:
https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/
β€4π₯1
CVE-2026-62911: Pre-auth RCE in Microsoft Exchange with public PoC, 8.0 rating βπ₯
Disclosed at the August Patch Tuesday, this pre-auth RCE vulnerability allows unauthenticated attackers on local networks to achieve remote code execution as SYSTEM. And now a PoC exists!
Search at Netlas.io:
π Link: https://nt.ls/rnLCg
π Dork: tag.name:"microsoft_exchange"
Read more:
https://github.com/hypnguyen1209/CVE-2026-62911
Disclosed at the August Patch Tuesday, this pre-auth RCE vulnerability allows unauthenticated attackers on local networks to achieve remote code execution as SYSTEM. And now a PoC exists!
Search at Netlas.io:
π Link: https://nt.ls/rnLCg
π Dork: tag.name:"microsoft_exchange"
Read more:
https://github.com/hypnguyen1209/CVE-2026-62911
π₯3β€1
Authentication bypass in Proxmox VE with public exploit and active exploitation, no CVE assigned yet βοΈ
A recently disclosed vulnerability in EOL releases of Proxmox VE allows unauthenticated remote attackers to log in as root without a password. Public PoC now exists! This vulnerability is being actively exploited in the wild!
Search at Netlas.io:
π Link: https://nt.ls/qLCVL
π Dork: tag.name:"proxmox_ve"
Vendor's advisory:
https://forum.proxmox.com/threads/proxmox-virtual-environment-security-advisories.149331/page-4#-subject-psa-2026-00043-1-authentication-bypass-in-eol-proxmox-ve-7-release
A recently disclosed vulnerability in EOL releases of Proxmox VE allows unauthenticated remote attackers to log in as root without a password. Public PoC now exists! This vulnerability is being actively exploited in the wild!
Search at Netlas.io:
π Link: https://nt.ls/qLCVL
π Dork: tag.name:"proxmox_ve"
Vendor's advisory:
https://forum.proxmox.com/threads/proxmox-virtual-environment-security-advisories.149331/page-4#-subject-psa-2026-00043-1-authentication-bypass-in-eol-proxmox-ve-7-release
π₯3β€1
CVE-2026-84645: RCE in Jenkins, 8.8 rating βπ₯
Jenkins disclosed numerous vulnerabilities in its security advisory. The most dangerous one allows remote code execution through unsafe deserialization.
Search at Netlas.io:
π Link: https://nt.ls/7bpLG
π Dork: tag.name:"jenkins"
Vendor's advisory :
https://www.jenkins.io/security/advisory/2026-09-02/
Jenkins disclosed numerous vulnerabilities in its security advisory. The most dangerous one allows remote code execution through unsafe deserialization.
Search at Netlas.io:
π Link: https://nt.ls/7bpLG
π Dork: tag.name:"jenkins"
Vendor's advisory :
https://www.jenkins.io/security/advisory/2026-09-02/
π₯2β€1
CVE-2026-85602: Grav Form Plugin reCAPTCHA v3 Authentication Bypass, 9.3 rating βπ₯
The Grav Form plugin selects which reCAPTCHA version to use for validation based solely on the presence of a specific response field key in the submitted payload. This allows an anonymous attacker to bypass reCAPTCHA v3 bot protection.
Search at Netlas.io:
π Link: https://nt.ls/VcB4a
π Dork: tag.name:"grav"
Vendor's advisory :
https://github.com/getgrav/grav/security/advisories/GHSA-89j6-8h38-2cc3
The Grav Form plugin selects which reCAPTCHA version to use for validation based solely on the presence of a specific response field key in the submitted payload. This allows an anonymous attacker to bypass reCAPTCHA v3 bot protection.
Search at Netlas.io:
π Link: https://nt.ls/VcB4a
π Dork: tag.name:"grav"
Vendor's advisory :
https://github.com/getgrav/grav/security/advisories/GHSA-89j6-8h38-2cc3
π₯4β€1
CVE-2026-67276 and others: MikroTik RouterOS vulnerabilities exploited in the wild (MikroTrick), up to 9.2 rating βπ₯
Recently disclosed vulnerabilities in MikroTik RouterOS allow an attacker to take full control of the device without authentication if the device supports remote access via the SSH protocol. These vulnerabilities are being actively exploited in the wild!
Search at Netlas.io:
π Link: https://nt.ls/318sx
π Dork: tag.name:"mikrotik"
Vendor's advisory :
https://mikrotik.com/supportsec/september-2026-vulnerability/
Recently disclosed vulnerabilities in MikroTik RouterOS allow an attacker to take full control of the device without authentication if the device supports remote access via the SSH protocol. These vulnerabilities are being actively exploited in the wild!
Search at Netlas.io:
π Link: https://nt.ls/318sx
π Dork: tag.name:"mikrotik"
Vendor's advisory :
https://mikrotik.com/supportsec/september-2026-vulnerability/
π₯2β€1
CVE-2026-75650: Adobe Commerce and Magento Open Source RCE vulnerability (StyleSmuggler) exploited in the wild, 10.0 rating βπ₯
Recently disclosed vulnerability in Adobe Commerce and Magento Open Source allows an unauthenticated attacker to execute arbitrary code. This vulnerability is being actively exploited in the wild!
Search at Netlas.io:
π Link: https://nt.ls/bX5dx
π Dork: tag.name:"magento"
Read more :
https://sansec.io/research/stylesmuggler-0day
Recently disclosed vulnerability in Adobe Commerce and Magento Open Source allows an unauthenticated attacker to execute arbitrary code. This vulnerability is being actively exploited in the wild!
Search at Netlas.io:
π Link: https://nt.ls/bX5dx
π Dork: tag.name:"magento"
Read more :
https://sansec.io/research/stylesmuggler-0day
β€1π₯1