CVE-2026-59726 (CVSS 10.0) in Ruflo exposed 233 MCP tools without authentication. The novel vector: attackers can poison the AgentDB learning store, and a software patch alone doesn't remove the ...
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals ...