- Exploits and vulnerabilities in Q2 2026by Alexander Kolesnikov on August 26, 2026 at 10:00 am
This report covers statistics on vulnerabilities, exploits, and C2 frameworks in Q2 2026. For the first time ever, we aggregate data on vulnerabilities in open-source AI agents and AI frameworks.
- Missed incidents, persistent threats, and response gaps: Insights from compromise assessment projectsby Victor Sergeev, Amged Wageh, Kaspersky Security Services on July 2, 2026 at 9:00 am
Kaspersky Compromise Assessment specialists analyze trends from the service’s 2025 projects and provide tips on how to enhance your organization’s security.
- OpenClaw: risks for the users and how to mitigate themby Kaspersky on July 1, 2026 at 6:42 am
Researching OpenClaw vulnerabilities, malicious skills, and other security issues with the popular agent, and providing tips on how to mitigate them.
- What’s in the container? Analyzing vulnerabilities, risks and protection with Kaspersky Container Security and the KIRA AI assistantby Yaroslav Shmelev, Anton Kivva, Denis Parinov, Vladimir Kuskov, Yanina Balandyuk-Opalinskaya on May 29, 2026 at 7:00 am
What are the main risks for container environments: vulnerabilities, supply chain attacks, configuration errors; how to improve container security and how Kaspersky Container Security with the KIRA AI assistant can help.
- How an image could compromise your Mac: understanding an ExifTool vulnerability (CVE-2026-3102)by Lucas Tay on May 20, 2026 at 9:02 am
We explain how a flaw in ExifTool allows attackers to compromise macOS systems via a malicious image (CVE-2026-3102).
- CVE-2025-68670: discovering an RCE vulnerability in xrdpby Denis Skvortsov, Dmitry Shmoylov on May 8, 2026 at 8:00 am
During a security assessment of Kaspersky USB Redirector, we discovered CVE-2025-68670: a pre-auth RCE in the xrdp server component. Project maintainers promptly patched the vulnerability.
- Exploits and vulnerabilities in Q1 2026by Alexander Kolesnikov on May 7, 2026 at 10:00 am
This report provides statistical data on published vulnerabilities and exploits we researched during Q1 2026. It also includes summary data on the use of C2 frameworks in APT attacks.
- PhantomRPC: A new privilege escalation technique in Windows RPCby Haidar Kabibo, Kaspersky Security Services on April 24, 2026 at 8:00 am
Kaspersky researcher discovered a vulnerability in RPC architecture that enables an attacker to create a fake RPC server and escalate their privileges.
- Coruna: the framework used in Operation Triangulationby Boris Larin on March 26, 2026 at 8:00 am
Kaspersky GReAT experts look into the Coruna exploit kit targeting iPhones. We discovered that the kernel exploit for CVE-2023-32434 and CVE-2023-38606 is an updated version of the Operation Triangulation exploit.
- Exploits and vulnerabilities in Q4 2025by Alexander Kolesnikov on March 6, 2026 at 10:00 am
This report provides statistical data on published vulnerabilities and exploits we researched during Q4 2025. It also includes summary data on the use of C2 frameworks in APT attacks.
Vulnerabilities and Exploits
We are an ethical website cyber security team and we perform security assessments to protect our clients.














