ZombieAgent: The Agentic Revolution Comes with Malicious Gifts Newly uncovered advanced forms of indirect prompt injection (IPI) allow attackers not only to extract information but to implant persistent logic into an agent’s long-term memory, effectively taking over the agent and turning it into a silent insider. January 8, 2026 06:00 AM Threat Alert
MongoBleed vulnerability - extracting sensitive data from the MongoDB server memory without authentication Radware’s Cyber Threat Intelligence (CTI) team is monitoring the active exploitation of CVE-2025-14847, nicknamed "MongoBleed." December 29, 2025 09:45 AM Threat Alert
React2Shell, a CVSS 10.0 RCE Vulnerability in React Server Components (CVE-2025-55182) A critical remote code execution (RCE) vulnerability affecting the widely used web development frameworks React and Next.js was disclosed on December 3. December 5, 2025 07:45 AM Threat Alert
Everything You Need to Know About the Cloudflare Outage On November 18, 2025, a widespread service disruption impacted Cloudflare’s global network, rendering a significant portion of the internet inaccessible for approximately six hours. November 20, 2025 10:35 AM Threat Alert
The AI Identity Dilemma: Malicious Bots in Disguise Radware’s CTI team has identified a critical security gap in bot mitigation systems related to the emergence of AI agent modes from OpenAI, Google and Anthropic that now require POST request permissions. November 6, 2025 03:47 PM Threat Alert
October 7: Post-Threat Analysis The anniversary of October 7 continues to serve as a rallying point for global hacktivists, transforming political symbolism into coordinated cyber campaigns. October 13, 2025 01:43 PM Threat Alert
Elevated Risk Surrounding October 7 October 7 anniversaries have become focal points for pro-Palestinian hacktivist messaging and calls for coordinated attack campaigns such as DDoS, data leaks and defacements. October 6, 2025 12:02 PM Threat Alert
ShadowLeak: The First Service-Side Leaking, Zero-click Indirect Prompt Injection Vulnerability ShadowLeak is a newly discovered zero‑click indirect prompt injection (IPI) vulnerability that occurs when OpenAI’s ChatGPT is connected to enterprise Gmail and allowed to browse the web. An attack takes advantage of the vulnerability by sending a legitimate‑looking email that quietly embeds malicious instructions in invisible or non‑obvious HTML. September 18, 2025 10:30 AM Threat Alert