4F404 Foundersin404-founders.com·5d ago · 4 min readSAP CVE-2026-44756: CVSS 10.0 Pre-Auth RCE via EPPSAP's ABAP and Java kernels carry a CVSS 10.0 hole in Extended Passport (EPP) deserialization. An unauthenticated attacker on the network can run arbitrary OS commands with SAP admin privileges before00
4F404 Foundersin404-founders.com·5d ago · 2 min readChrome CVE-2026-87491: V8 Zero-Day Exploited in the WildChrome CVE-2026-87491: V8 Zero-Day Exploited in the Wild Google's V8 engine has an out-of-bounds write being exploited against Chrome users right now. Chrome 153 is out with the fix - patch before mor00
4F404 Foundersin404-founders.com·5d ago · 2 min readN-central CVE-2026-86218: CVSS 10.0 RCE Exploited in the WildCVE-2026-86218 is a critical pre-authentication RCE in N-able's N-central RMM platform. N-able's HF4 release notes initially said the company had no confirmation of production exploitation, while a se00
4F404 Foundersin404-founders.com·6d ago · 4 min readSuper Forms and Elementor Pro: 440K+ RCE Attempts Hit WordPress SitesMore than 440,000 exploit attempts have hit two popular WordPress plugins - Super Forms and Elementor Pro - where attackers upload PHP web shells and run arbitrary commands without needing any login c00
4F404 Foundersin404-founders.com·6d ago · 3 min readASCII Smuggling: Od AI istraživanja do phishing kampanjaTehnika popularizovana kroz istraživanja AI prompt injection napada sada se koristi za zaobilaženje phishing filtera. U kampanji koju je dokumentovao Microsoft, AI asistent nije bio potreban za sam me00