In The News

Blog Archive Category

the exploit blog logo
The Exploit: Penetration Testing Insights From The Frontlines

The Exploit articles categorized as In The News

  • Smart Slider 3 Pro WordPress/Joomla Plugin Supply Chain Compromise

    Smart Slider 3 Pro WordPress/Joomla Plugin Supply Chain Compromise

    By Jason Taylor Last week’s supply chain attack caused many users of the WordPress and Joomla plugin Smart Slider 3 Pro to inadvertently patch to a malicious version. April 15, 2026
  • Two Critical Telnet Flaws in 2026 Allow Unauthenticated Root Access

    Two Critical Telnet Flaws in 2026 Allow Unauthenticated Root Access

    By Ryan Chaplin Lead Penetration Ryan Chaplin explains how to protect your network against CVE-2026-24061 and CVE-2026-32746, two critical Telnet flaws released this year. April 10, 2026
  • Raxis at RSAC 2026

    Raxis at RSAC 2026: A Week Well Spent in San Francisco

    By Mark Puckett The Raxis team reflects on RSAC 2026 from organizations looking to secure their systems with pentesting to PTaaS and partners looking to secure their customers. April 1, 2026
  • BYOVD Attacks and EDR Evasion: Why Your Endpoint Security May Not Be Enough

    BYOVD Attacks and EDR Evasion: Why Your Endpoint Security May Not Be Enough

    By Brian Tant With Reynolds Ransomware in the wild, Brian Tant dives into BYOVD attacks, how they evade enterprise defense like EDRs, and what your organization can do. March 18, 2026
  • Reynolds Ransomware BYOVD Eludes EDR Tools

    Reynolds Ransomware BYOVD Eludes EDR Tools

    By Nathan Anderson Reynolds poses a new type of threat by including a Bring Your Own Vulnerable Driver (BYOVD) in the ransomware bundle, making it harder for EDR tools to catch. February 20, 2026
  • BeyondTrust RCE Vulnerability Exploited: Critical 9.9 CVSS Flaw Under Active Attack

    BeyondTrust RCE Vulnerability Exploited: Critical 9.9 CVSS Flaw Under Active Attack

    By Ryan Chaplin While BeyondTrust patched cloud-hosted Remote Support customers earlier this month, on-premises deployments of BeyondTrust must manually patch to remediate. February 17, 2026