CODEREDVTA
Vulnerability and Threat Advisories
“Security rules and techniques that helping you stay ahead of cyber threats”
Autonomous AI Agent Conducts Espionage Campaign Against Thai Government Finance Ministry
Autonomous AI Agent Conducts Espionage Campaign Against Thai Government Finance Ministry Credited by Unsplash VTA-000192 – Autonomous AI Agent Conducts Espionage Campaign Against Thai Government Finance Ministry Attackers breached Thailand's Ministry of Finance using Hermes, an open-source AI agent framework, …
Critical Fastjson Flaw Enables Unauthenticated Remote Code Execution
Critical Fastjson Flaw Enables Unauthenticated Remote Code Execution Credited by Unsplash VTA-000191 – Critical Fastjson Flaw Enables Unauthenticated Remote Code Execution Security researchers have observed active exploitation of a critical vulnerability, CVE-2026-16723 (CVSS 9.0), affecting Fastjson 1.2.68 through 1.2.83. The …
OAuth Client ID Spoofing Enables Silent Account Enumeration in Microsoft Entra ID Environments
OAuth Client ID Spoofing Enables Silent Account Enumeration in Microsoft Entra ID Environments Credited by Unsplash VTA-000189 – OAuth Client ID Spoofing Enables Silent Account Enumeration in Microsoft Entra ID Environments Researchers have identified a growing attack technique where threat actors …
Fake Maccy Clipboard Manager Delivers Rust Infostealer to macOS Users
Fake Maccy Clipboard Manager Delivers Rust Infostealer to macOS Users Credited by Unsplash VTA-000187 – Fake Maccy Clipboard Manager Delivers Rust Infostealer to macOS Users A sophisticated macOS credential-theft campaign is targeting users through a fake version of the legitimate Maccy …