$ research --archive

Source-backed full analyst reports. News without a completed report remains on Today only.

149 of 149 reports
31 Aug 2026 Analyst report New CVE-2019-11510

DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims

The distinction between 'targeted' and 'compromised' has direct consequence for defenders assessing exposure: organizations previously listed as victims may not have suffered confirmed intrusions, but QTFY's ORB botnet …

Confirmed exploited · CISA KEV Public PoC 1 sources medium confidence
31 Aug 2026 Analyst report New

Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets

The group's documented use of an AI coding assistant to plan multi-phase intrusions—including AD CS exploitation and cross-platform encryptor development—signals a maturing capability to accelerate attack planning …

1 sources medium confidence
30 Aug 2026 Analyst report New

Chrome Web Store extensions caught stealing crypto, browser data

Browser extensions represent a high-trust attack surface: users rarely scrutinize post-install updates, and supply-chain acquisition of legitimate extensions lets attackers inherit established user bases and store trust …

1 sources high confidence
29 Aug 2026 Analyst report New CVE-2026-76581CVE-2026-18431CVE-2026-19598 +2 CVEs

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

Any of these flaws can lead to complete site takeover or server-level code execution without authentication, meaning unpatched WordPress installations face immediate, trivial exploitation requiring no credentials or …

1 sources high confidence
28 Aug 2026 Analyst report New CVE-2024-4879CVE-2026-18885CVE-2026-18886 +2 CVEs

ServiceNow warns of three max severity security vulnerabilities

The ServiceNow AI Platform underpins over 100,000 enterprise AI applications across 85% of Fortune 500 companies, making unauthenticated, zero-interaction critical vulnerabilities in this platform a high-priority …

Confirmed exploited · CISA KEV 1 sources high confidence
28 Aug 2026 Analyst report New CVE-2023-49105

ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body

Any ownCloud deployment running versions 10.6.0–10.13.0 without a configured signing key is trivially exploitable with only a valid username, making this a low-barrier, high-impact vector for credential harvesting and …

Confirmed exploited · CISA KEV 1 sources high confidence
28 Aug 2026 Analyst report New CVE-2026-60004

Over 8,300 Gitea servers vulnerable to code execution attacks

Because Gitea's default open registration eliminates the need for pre-existing credentials, any internet-exposed unpatched instance is effectively unauthenticated-exploitable, enabling threat actors to gain OS-level …

Confirmed exploited · CISA KEV 1 sources high confidence
28 Aug 2026 Analyst report New CVE-2026-65643CVE-2026-41940CVE-2026-48172 +3 CVEs

Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server

In shared hosting environments, a single compromised or malicious tenant account could leverage this flaw to seize root-level control of the entire server, endangering all co-hosted customers and their data. Hosting …

Confirmed exploited · CISA KEV ×3 1 sources medium confidence
27 Aug 2026 Analyst report New CVE-2026-75604

Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE

Self-hosted Next.js deployments on Windows have no viable workaround for CVE-2026-75604 and must patch immediately, while the AVIF flaw affects a far wider version range (10.0.0 onward) across all platforms and has a …

Public PoC 1 sources high confidence
27 Aug 2026 Analyst report New CVE-2026-19489CVE-2026-19490CVE-2026-8452

CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday

NetScaler ADC and Gateway appliances sit at the perimeter of many enterprise and government networks handling VPN and authentication traffic, making RCE-as-root on these devices a critical initial-access vector that can …

Confirmed exploited · CISA KEV 1 sources medium confidence
27 Aug 2026 Analyst report New CVE-2019-1068CVE-2015-3246CVE-2015-5287 +3 CVEs

CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs

The mix of network-edge (Citrix NetScaler), OS-level (Linux Kernel, Red Hat), and application-layer (SQL Server, AjaxPro) flaws broadens the attack surface defenders must prioritize simultaneously, with the 48-hour …

Confirmed exploited · CISA KEV ×6 1 sources high confidence
26 Aug 2026 Analyst report New CVE-2026-77537CVE-2026-77550CVE-2026-77554

Ubiquiti patches three max severity security vulnerabilities

With over 100,000 UniFi OS instances indexed by Censys and all three flaws requiring zero privileges and no user interaction, unpatched deployments present an immediately actionable, low-barrier attack surface; Ubiquiti …

1 sources medium confidence
26 Aug 2026 Analyst report New CVE-2026-55040CVE-2026-63520

Hackers target Microsoft SharePoint RCE chain with PoC exploit

The availability of public PoC exploits for both chain components dramatically lowers the bar for attackers, and the rapid weaponization timeline (less than 24 hours post-PoC) means unpatched internet-facing SharePoint …

Confirmed exploited · CISA KEV 1 sources high confidence
26 Aug 2026 Analyst report New CVE-2026-60004

Hackers now exploit critical Gitea flaw in code injection attacks

Any organization running an internet-exposed Gitea instance on a version prior to 1.27.1 is effectively unauthenticated-exploitable by default, meaning attackers can gain OS-level code execution on the host without any …

Confirmed exploited · CISA KEV Public PoC 1 sources high confidence
26 Aug 2026 Analyst report New CVE-2026-60004

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

Any Gitea instance reachable from the internet with default registration settings is effectively unauthenticated-exploitable, placing self-hosted code repositories and their CI/CD pipelines at immediate risk of full …

Confirmed exploited · CISA KEV Public PoC 1 sources high confidence
26 Aug 2026 Analyst report New CVE-2026-18431

Critical Avada WordPress theme flaw enables zero-click RCE

Successful exploitation could lead to full website compromise, including malware deployment, database access, and admin account creation on a large number of WordPress sites. Defenders must verify and apply updates …

1 sources high confidence
25 Aug 2026 Analyst report New CVE-2026-39987CVE-2026-67618CVE-2026-75149

Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode

Notebook files are routinely shared across teams, repositories, and public platforms, making them a plausible supply-chain vector; an attacker can embed a silent subprocess launch that fires before any cell renders, …

Confirmed exploited · CISA KEV 1 sources high confidence
25 Aug 2026 Analyst report New CVE-2026-73570

Hackers breached over 270 Zimbra servers in ongoing attacks

Zimbra is deployed across hundreds of millions of users including thousands of businesses and hundreds of government agencies globally, making mass exploitation of this unauthenticated RCE a critical threat to email …

Confirmed exploited · CISA KEV 1 sources high confidence
24 Aug 2026 Analyst report New CVE-2026-15981CVE-2026-61979

Hackers target WordPress sites in miniOrange auth bypass attacks

Successful exploitation grants unauthenticated attackers full WordPress administrator access via a forged SAML assertion, bypassing all credential-based controls on sites that delegate login to enterprise identity …

1 sources medium confidence
24 Aug 2026 Analyst report New CVE-2026-73570

CISA orders urgent patching of actively exploited Zimbra flaw

Unauthenticated RCE on a widely deployed enterprise email and collaboration platform gives attackers direct access to sensitive communications and credentials, making unpatched Zimbra servers high-value targets for …

Confirmed exploited · CISA KEV 1 sources high confidence
23 Aug 2026 Analyst report New

ToxicPanda Android malware uses VPN permissions to block Google Play

The VPN-layer interception technique is particularly dangerous because it allows ToxicPanda to neuter Google Play Protect before it can flag or remove the malware, and the wireless ADB abuse grants attackers shell-level …

1 sources high confidence
21 Aug 2026 Analyst report New CVE-2023-34362

SickKids data breach exposes employee and job applicant info

Career portal breaches are high-value for adversaries because applicant data (addresses, employment histories, government IDs) enables targeted social engineering and identity fraud against hospital staff, amplifying …

Confirmed exploited · CISA KEV Public PoC 1 sources medium confidence
21 Aug 2026 Analyst report New CVE-2025-55241CVE-2026-65770CVE-2026-65801 +3 CVEs

Microsoft warns of max severity Entra ID flaw exploited in attacks

Because Entra ID is the identity backbone for Microsoft 365, Azure, and Dynamics CRM tenants globally, pre-patch exploitation of an unauthenticated RCE flaw means defenders should audit Entra ID audit logs and sign-in …

1 sources medium confidence
21 Aug 2026 Analyst report New CVE-2026-68820CVE-2026-69836

Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution

For Entra ID defenders, no patching action is needed, but the incident highlights the risk of blind trust in Microsoft's exploitability metadata — SOC teams should build workflows to cross-validate 'exploited' flags …

Confirmed exploited · CISA KEV 1 sources high confidence
21 Aug 2026 Analyst report New CVE-2026-20030CVE-2026-20231CVE-2026-20315 +7 CVEs

Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0

Five CVSS 10.0 flaws in network orchestration and workload visibility platforms mean unauthenticated attackers could potentially achieve full compromise of the management plane controlling enterprise network …

Confirmed exploited · CISA KEV 1 sources medium confidence
21 Aug 2026 Analyst report New CVE-2026-3502CVE-2026-72529CVE-2026-72530

CISA orders feds to patch actively exploited TrueConf Server flaws

TrueConf Server's on-premises deployment model means vulnerable instances sit inside trusted corporate LANs, giving attackers who exploit these pre-auth RCE flaws direct access to internal network resources with no …

Confirmed exploited · CISA KEV ×3 1 sources high confidence
20 Aug 2026 Analyst report New CVE-2026-19489CVE-2026-19490CVE-2026-3055 +1 CVEs

Citrix urges admins to patch new NetScaler flaws as soon as possible

NetScaler appliances are high-value perimeter targets — over 22,000 ADC and 1,800 Gateway instances are internet-exposed, and Citrix's own recent history shows attackers weaponize these flaws within days of disclosure, …

Confirmed exploited · CISA KEV 1 sources high confidence
20 Aug 2026 Analyst report New CVE-2026-64849

CISA warns of hackers exploiting critical MLflow vulnerability

Any organization running an internet-exposed MLflow tracking server without authentication (the default configuration) is at immediate risk of cloud credential theft, which can lead to full cloud environment compromise …

Confirmed exploited · CISA KEV 1 sources high confidence
20 Aug 2026 Analyst report New CVE-2026-73570CVE-2025-66376

Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution

Organizations running Zimbra with the zimbra-snmp package and SNMP notifications enabled are exposed to unauthenticated RCE, making immediate patching to 10.1.20 critical; defenders should audit /var/log/zimbra.log for …

Confirmed exploited · CISA KEV 1 sources medium confidence
19 Aug 2026 Analyst report New

US warns of AI-powered attacks on Siemens PLCs in critical infrastructure

The actors combine AI-assisted scripting with the public Snap7/python-snap7 industrial automation libraries to produce tools capable of communicating with Siemens controllers through S7comm. Published evidence describes …

1 sources high confidence
19 Aug 2026 Analyst report New CVE-2021-33044CVE-2021-33045CVE-2024-39943 +1 CVEs

Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P

Defenders running Dahua devices must treat firmware updates as urgent given that CVE-2021-33044 and CVE-2021-33045 remain in CISA's KEV catalog and the implanted backdoor account reportedly survives factory resets on …

Confirmed exploited · CISA KEV ×2 1 sources medium confidence
19 Aug 2026 Analyst report New CVE-2021-33044CVE-2021-33045CVE-2024-39943 +1 CVEs

Hackers compromise 14,500 Dahua web cameras in 35-day campaign

Defenders operating Dahua cameras reachable on port 37777 between June and July 2026 should assume compromise and audit for the 'p2pwn' account, but must also recognize that removing it is insufficient—attacker-generated …

Confirmed exploited · CISA KEV ×2 1 sources high confidence
19 Aug 2026 Analyst report New CVE-2026-33824

Critical RCE flaw in Windows IKE Extension now actively exploited

Because the attack requires no credentials and targets the IKE service exposed on standard VPN/IPsec UDP ports, any internet-facing Windows system with IKE enabled is directly reachable by remote attackers — defenders …

Confirmed exploited · CISA KEV 1 sources high confidence
19 Aug 2026 Analyst report New CVE-2026-65400CVE-2026-33824CVE-2026-55040 +1 CVEs

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

Defenders must treat all four as actively weaponized with mature exploit chains—particularly vCenter, where nation-state actors have already pivoted to ransomware deployment at scale—making immediate patching or …

Confirmed exploited · CISA KEV ×4 1 sources medium confidence
19 Aug 2026 Analyst report Recent CVE-2021-27101CVE-2023-34362CVE-2026-12569

Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

Any Windchill or FlexPLM instance exposed to this shell faces near-instant enterprise-wide credential compromise because the LDAP credentials it harvests typically gate Active Directory, VPN, and email, turning a single …

Confirmed exploited · CISA KEV ×3 1 sources high confidence
18 Aug 2026 Analyst report New

Hunting MacSync Stealer infrastructure through behavioral pivots

Defenders gain durable detection opportunities by hunting for the stealer’s consistent process ancestry, command-line patterns, network request traits, and chunked upload parameters even as domains change quickly. These …

1 sources high confidence
18 Aug 2026 Analyst report New CVE-2025-60710CVE-2026-45659

CISA: Windows Task Host flaw now exploited by ransomware gangs

Organizations running unpatched Windows 11 or Windows Server 2025 systems face a confirmed ransomware-stage privilege escalation path, meaning attackers who have achieved any local foothold can reliably gain full system …

Confirmed exploited · CISA KEV ×2 1 sources high confidence
18 Aug 2026 Analyst report New CVE-2025-62593

CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE

Organizations running Ray in development, CI/CD, or internal ML infrastructure should immediately patch to version 2.52.0, as internet-exposed or network-adjacent Ray instances are actively being recruited into botnets …

Confirmed exploited · CISA KEV 1 sources high confidence
18 Aug 2026 Analyst report New CVE-2023-33831CVE-2026-25895CVE-2026-25939 +1 CVEs

Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

MLflow is widely deployed in cloud-based ML/AI pipelines where the Tracking Server often runs with broad IAM permissions, making credential theft via IMDS (e.g., AWS 169.254.169.254) a direct path to cloud account …

1 sources high confidence
17 Aug 2026 Analyst report New CVE-2026-12569

Philips and GE investigating Clop ransomware data theft claims

Organizations running internet-exposed PTC Windchill or FlexPLM instances — especially in aerospace, defense, automotive, and medtech — should treat unpatched systems as compromised and immediately hunt for JSP webshells …

Confirmed exploited · CISA KEV 1 sources high confidence
17 Aug 2026 Analyst report New CVE-2007-3010CVE-2016-6277CVE-2018-14558 +15 CVEs

Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies

Defenders should prioritize patching the 18 referenced CVEs on internet-facing edge devices and monitor for unexpected outbound connections on port 443 from OT/IoT assets, since compromised nodes are weaponized as proxy …

Confirmed exploited · CISA KEV ×11 Public PoC 1 sources medium confidence
16 Aug 2026 Analyst report New

SafePal data breach impacts 39,798 customers, stolen info for sale

Defenders should treat this as a high-risk phishing precursor event: the stolen order data (names, addresses, phone numbers, purchase history) provides attackers with highly credible pretexts for spear-phishing and …

1 sources high confidence
14 Aug 2026 Analyst report New CVE-2026-12569

Shell investigates 'potential incident' after Clop data theft claims

Organizations running internet-exposed PTC Windchill or FlexPLM instances should treat CVE-2026-12569 as actively exploited and apply patches immediately, hunting for JSP webshells and reviewing IOCs provided by PTC, as …

Confirmed exploited · CISA KEV 1 sources medium confidence
14 Aug 2026 Analyst report New CVE-2026-22732CVE-2026-34263CVE-2026-44761 +1 CVEs

Max severity SAP Commerce Cloud flaw now targeted in attacks

Organizations running SAP Commerce Cloud must treat patching as an emergency given the zero-authentication requirement, trivial exploitation complexity, and confirmed in-the-wild exploitation within 72 hours of patch …

1 sources medium confidence
14 Aug 2026 Analyst report New

Hackers arrested over €30M bank fraud exploiting service provider flaw

This case illustrates the systemic risk of third-party service provider dependencies: a single faulty software update at a payment processor created a window for mass unauthorized withdrawals across a major bank's …

1 sources medium confidence
13 Aug 2026 Analyst report New CVE-2026-62832

Microsoft patches LegacyHive Windows zero-day vulnerability

Any authenticated local user with credentials to a second account can escalate to administrator without requiring victim interaction, making this a significant lateral movement and privilege escalation vector in shared …

1 sources high confidence
13 Aug 2026 Analyst report New CVE-2026-55040CVE-2026-45659CVE-2026-50522 +2 CVEs

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

Unauthenticated attackers can read files and modify data on unpatched SharePoint servers without any credentials, making this a high-priority patch for organizations using on-premises or hybrid SharePoint deployments. …

Confirmed exploited · CISA KEV ×4 Public PoC 1 sources medium confidence
13 Aug 2026 Analyst report New

Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt

Defenders must treat Safe Mode boot events as high-fidelity attack indicators and ensure critical security tooling (EDR agents, AV) is configured to survive or alert on Safe Mode reboots, since the default behavior of …

1 sources high confidence
12 Aug 2026 Analyst report New CVE-2026-50656CVE-2026-62832CVE-2026-68820 +1 CVEs

ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access

Defenders using Microsoft Defender cannot assume the prior patch fully closes the privilege-escalation path, leaving endpoints exposed to SYSTEM compromise even after applying updates. Organizations should treat …

Confirmed exploited · CISA KEV 1 sources medium confidence
12 Aug 2026 Analyst report New CVE-2026-68820CVE-2025-49113

Lazarus hackers exploited Windows zero-day to target defense firms

Defenders must accelerate patching of Windows AFD.sys and exposed Roundcube instances while monitoring for kernel rootkit behaviors like EDR disabling and web shell activity on legitimate infrastructure, as valid …

Confirmed exploited · CISA KEV ×2 1 sources medium confidence
12 Aug 2026 Analyst report New CVE-2025-49113CVE-2026-68820

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

Defenders must apply Windows kernel-mode driver patches immediately upon release and monitor for DLL side-loading, anomalous PDF viewer behavior, and attempts to disable Smart App Control or inject into SYSTEM processes. …

Confirmed exploited · CISA KEV ×2 1 sources medium confidence
12 Aug 2026 Analyst report New CVE-2026-45659CVE-2026-55040

Hackers leverage new Microsoft SharePoint exploit in attacks

Over 8,500 SharePoint servers remain internet-exposed according to Shadowserver tracking, and prior SharePoint flaws have been chained into ransomware campaigns, so defenders must apply the July updates immediately and …

Confirmed exploited · CISA KEV Public PoC 1 sources medium confidence
12 Aug 2026 Analyst report New CVE-2026-20349

Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

Defenders operating exposed Cisco ASA or FTD appliances face unauthenticated remote reloads that can interrupt VPN connectivity and perimeter security controls, with active exploitation already observed. Immediate …

Confirmed exploited · CISA KEV 1 sources high confidence
11 Aug 2026 Analyst report New CVE-2024-55591CVE-2025-24472

US and South Korea warn of Gunra ransomware targeting govt agencies

Both CVEs cross an authentication boundary and can provide remote super-admin privileges. CVE-2024-55591 involves crafted requests reaching a Node.js WebSocket component, whereas CVE-2025-24472 involves crafted …

Confirmed exploited · CISA KEV ×2 1 sources medium confidence
11 Aug 2026 Analyst report New CVE-2024-5559CVE-2025-24472

Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks

Both confirmed vulnerabilities bypass authentication boundaries in FortiOS or FortiProxy and can yield super-administrator privileges, although CVE-2025-24472 has additional topology and serial-number prerequisites. The …

Confirmed exploited · CISA KEV 1 sources high confidence
11 Aug 2026 Analyst report New CVE-2026-20230CVE-2026-20349

Cisco warns of ASA and FTD VPN flaw exploited to crash devices

Exposed VPN and firewall appliances can be crashed on demand, disrupting remote access and perimeter connectivity for affected organizations. Defenders should treat this as an immediate availability threat and apply the …

Confirmed exploited · CISA KEV ×2 1 sources high confidence
11 Aug 2026 Analyst report New CVE-2026-33825CVE-2026-45659

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks

Defenders must immediately patch affected SharePoint deployments, enable AMSI integration for web applications, and deploy Microsoft Defender detections to identify and block post-exploitation activity before ransomware …

Confirmed exploited · CISA KEV ×2 1 sources high confidence
10 Aug 2026 Analyst report New CVE-2026-3502

TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore

Organizations running TrueConf Server as an internal distribution point face a supply-chain-style risk: employees downloading the client from their own patched server may receive malware, meaning endpoint compromise can …

Confirmed exploited · CISA KEV 1 sources high confidence
10 Aug 2026 Analyst report New CVE-2026-18577

New StormEncryptor ransomware used by former Medusa affiliate

Organizations running self-hosted N-central RMM servers are immediately at risk and must apply hotfix 2026.3 HF1 (build 2026.3.1.7) without delay, as Storm-1175 is known to compress the entire attack timeline from …

Confirmed exploited · CISA KEV 1 sources medium confidence
10 Aug 2026 Analyst report New CVE-2026-8037

Critical Progress LoadMaster flaw now actively exploited in attacks

With over 100,000 deployments across Fortune 500 companies and government entities—including Amazon and the U.S. Air Force—exploitation of this unauthenticated RCE primitive at the network edge could grant attackers a …

Confirmed exploited · CISA KEV 1 sources high confidence
10 Aug 2026 Analyst report New CVE-2025-40602CVE-2026-15409CVE-2026-15410

CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs

SMA1000 appliances serve as the VPN gateway into corporate and government networks, making successful exploitation a direct path to internal network access and lateral movement — precisely the entry point ransomware …

Confirmed exploited · CISA KEV ×3 1 sources high confidence
10 Aug 2026 Analyst report New CVE-2023-37679CVE-2023-43208CVE-2023-48788 +7 CVEs

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

Storm-1175 moves from initial access to ransomware deployment within days, targeting widely used RMM and IT management platforms, meaning organizations running N-able N-central must treat patching as an emergency rather …

Confirmed exploited · CISA KEV ×9 1 sources high confidence
8 Aug 2026 Analyst report New CVE-2026-8037

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

LoadMaster appliances are network-edge load balancers, meaning a successful exploit grants unauthenticated RCE at a critical network chokepoint with broad lateral movement potential. FCEB agencies face a hard patch …

Confirmed exploited · CISA KEV 1 sources high confidence
7 Aug 2026 Analyst report New CVE-2026-64638

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP

Because the XSS requires zero authentication and targets any visitor to the login page, defenders cannot rely on perimeter controls or credential-based detection—any administrator who clicks a single attacker-crafted …

1 sources high confidence
7 Aug 2026 Analyst report New CVE-2026-12537CVE-2026-54316

Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets

Any organization running these coding agents in CI pipelines where external users can influence input—such as through pull requests or issue comments—should treat the harness layer as an untrusted execution boundary and …

1 sources high confidence
6 Aug 2026 Analyst report New CVE-2026-64561CVE-2026-46316CVE-2026-53359

New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts

Any Linux KVM host exposing nested virtualization to untrusted tenants—common in cloud-on-cloud or development infrastructure—faces a guest-to-host escape risk from a compromised or malicious guest root; operators should …

1 sources high confidence
6 Aug 2026 Analyst report New CVE-2026-20200CVE-2026-20267CVE-2026-20268 +12 CVEs

Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs

The IMC vulnerability is particularly dangerous because a root-level compromise of the Integrated Management Controller operates below the OS and can subvert BIOS, SecureBoot, and persist invisibly to EDR tooling, …

Confirmed exploited · CISA KEV 1 sources high confidence
6 Aug 2026 Analyst report New CVE-2026-63077

CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild

TeamCity servers sit at the heart of CI/CD pipelines, meaning a successful compromise can expose stored credentials, tamper with build artifacts, and enable downstream supply chain attacks against any software built on …

Confirmed exploited · CISA KEV 1 sources high confidence
5 Aug 2026 Analyst report New CVE-2026-14869CVE-2026-15307CVE-2026-16496 +6 CVEs

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

MSPs and hosting providers running Veeam VSPC should treat CVE-2026-58073 as urgent — unauthenticated credential theft against backup agents in a multi-tenant environment can cascade to full customer environment …

1 sources high confidence
5 Aug 2026 Analyst report New CVE-2026-64531

New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch

Local attackers can reliably escalate to root on systems where the openvswitch module loads and unprivileged user namespaces remain enabled, including from inside containers. Defenders must apply patched vendor kernels …

1 sources high confidence
5 Aug 2026 Analyst report New CVE-2025-68613

Leaked n8n API Tokens Exposed Live Instances to Credential Theft

Any organization self-hosting n8n should immediately audit public repositories for committed API tokens, rotate all keys, and enforce token expiration policies, since a single leaked token can pivot to every downstream …

Confirmed exploited · CISA KEV Public PoC 1 sources high confidence
5 Aug 2026 Analyst report New CVE-2026-9198CVE-2026-18556CVE-2026-18577 +6 CVEs

CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited

The confirmed use of AI-driven autonomous exploit chaining—where the agent self-directed pivot from one CVE to alternatives in real time—marks a qualitative shift in attacker capability that defenders must account for in …

Confirmed exploited · CISA KEV ×8 2 sources high confidence
4 Aug 2026 Analyst report New CVE-2025-15544CVE-2025-15627CVE-2025-15631 +4 CVEs

TP-Link patches Omada ZTP flaws allowing hackers to breach networks

Organizations using Omada for managed or MSP-driven network deployments face a realistic multi-stage attack path requiring no initial credentials, with over 1,800 controllers already exposed to the internet; defenders …

1 sources high confidence
4 Aug 2026 Analyst report New

New XCSSET variant targets macOS devs via compromised Xcode projects

Any macOS developer who clones open-source or shared Xcode projects without vetting dependencies is a viable entry point, and a single infection can laterally compromise an entire local development ecosystem and poison …

1 sources high confidence
4 Aug 2026 Analyst report New CVE-2026-58048CVE-2026-58047

New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

Shared hosting providers are the highest-risk targets: any tenant account — including phished or resold ones — can pivot from a sandboxed cPanel user to full database root, threatening all databases on the server and …

Public PoC 1 sources high confidence
4 Aug 2026 Analyst report New CVE-2026-18556CVE-2026-18577CVE-2025-8875 +1 CVEs

CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild

N-central is an RMM platform with broad access to managed environments, meaning a single compromised server can serve as a launchpad into dozens or hundreds of downstream customer networks—making this a high-leverage …

Confirmed exploited · CISA KEV ×4 2 sources high confidence
4 Aug 2026 Analyst report New

128 Seconds to disruption: Microsoft Defender stops ransomware at QNET

Device isolation provides automated containment for endpoint-initiated attacks where identity-based responses are insufficient, cutting off C2, credential theft, and lateral movement without manual triage. Defenders gain …

1 sources medium confidence
3 Aug 2026 Analyst report New CVE-2026-18577CVE-2026-18556

N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete

MSPs and IT teams running self-hosted N-central must immediately upgrade to build 2026.3.1.7, as all prior versions—including the previously 'patched' 2026.2 branch—remain vulnerable; upgrading the server alone does not …

Confirmed exploited · CISA KEV 2 sources high confidence
3 Aug 2026 Analyst report New CVE-2026-15409CVE-2026-15410

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

Defenders running SonicWall SMA 1000 appliances must treat patching as insufficient on its own—because TOTP MFA seeds were stolen pre-patch, any accounts authenticated through these devices should be considered fully …

Confirmed exploited · CISA KEV ×2 Public PoC 1 sources high confidence
3 Aug 2026 Analyst report New CVE-2026-44513CVE-2026-44827CVE-2026-45804

Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code

Any pipeline, CI/CD system, or container image calling DiffusionPipeline.from_pretrained with a custom_pipeline pointing at a Hub repository is a potential initial-access vector, meaning a malicious or compromised model …

1 sources high confidence
1 Aug 2026 Analyst report New CVE-2026-48449CVE-2026-48374CVE-2026-48390 +7 CVEs

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

A CVSS 10.0 no-interaction RCE in a widely deployed enterprise marketing platform represents an immediately exploitable attack surface for unauthenticated or low-privilege attackers to fully compromise ACC servers; …

1 sources medium confidence
31 Jul 2026 Analyst report New CVE-2025-68613CVE-2026-21858CVE-2026-3055 +2 CVEs

Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks

This represents a documented, real-world case of an LLM-driven autonomous attack loop requiring only a single human trigger, lowering the operational cost and skill barrier for multi-target exploitation campaigns at …

Confirmed exploited · CISA KEV ×4 Public PoC 1 sources high confidence
30 Jul 2026 Analyst report New CVE-2025-2894CVE-2025-35027

FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risks

Defenders managing OT/ICS environments or enterprise robotics fleets should audit deployed foreign-produced robots and power inverters against the FCC's technical thresholds now, since already-authorized hardware remains …

1 sources high confidence
30 Jul 2026 Analyst report New CVE-2026-20316

Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data

Organizations running Cisco FMC should treat this as urgent: unauthenticated remote access to a firewall management plane means an attacker can potentially view, modify, or exfiltrate firewall policies, network topology, …

Confirmed exploited · CISA KEV 1 sources high confidence
29 Jul 2026 Analyst report New CVE-2026-59309CVE-2026-41703CVE-2026-41709 +2 CVEs

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

The vCenter auth bypass and RCE (CVE-2026-59309/59310) are unauthenticated network-reachable, meaning any exposed vCenter management plane is a full-compromise risk without credentials; teams should treat patching to the …

1 sources high confidence
29 Jul 2026 Analyst report New CVE-2025-66376CVE-2026-42897

Russian hackers exploit Exchange OWA zero-day for long-term mailbox access

Defenders cannot rely on credential resets or endpoint reimaging as recovery actions because persistence is established at the Exchange/mailbox-permission layer, requiring explicit auditing and revocation of folder-level …

Confirmed exploited · CISA KEV ×2 1 sources high confidence
29 Jul 2026 Analyst report New CVE-2026-10702CVE-2026-43499

Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser

The public exploit code dramatically lowers attacker barrier for a no-interaction drive-by compromise, meaning any unpatched Firefox or Tor Browser user is at risk simply by loading an attacker-controlled page; updating …

Public PoC 1 sources medium confidence
29 Jul 2026 Analyst report Recent CVE-2026-16232

Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass

With a public PoC now available, exploitation attempts will almost certainly broaden beyond the initial handful of targeted customers, making immediate application of Check Point's July 22, 2026 Jumbo Hotfix critical for …

Confirmed exploited · CISA KEV Public PoC 1 sources high confidence
29 Jul 2026 Analyst report New CVE-2026-20316CVE-2026-20079

Cisco warns of FMC static credential flaw exploited in zero-day attacks

Organizations running on-premises Cisco Secure FMC should apply the available hot fixes immediately across versions 7.0–10.0 and audit /var/log/messages for the /var/tmp/license.tmp IOC, as exploitation requires no user …

Confirmed exploited · CISA KEV 1 sources high confidence
28 Jul 2026 Analyst report New CVE-2026-53264CVE-2026-50522

Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit

The public exploit code elevates urgency for any Linux system running a vulnerable kernel with unprivileged user namespaces enabled, as a local or container-escape attacker can reliably achieve root in under two minutes …

Confirmed exploited · CISA KEV Public PoC 1 sources high confidence
28 Jul 2026 Analyst report New CVE-2026-50522CVE-2026-65618CVE-2026-65923 +1 CVEs

JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

Any organization running self-hosted JFrog Artifactory should treat this as an emergency patching event—unauthenticated or low-privilege exploitation paths in a package registry proxy can serve as a silent …

Confirmed exploited · CISA KEV 1 sources medium confidence
28 Jul 2026 Analyst report New CVE-2026-63077CVE-2026-50522

Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

TeamCity servers frequently store CI/CD credentials, source code access tokens, and deployment configurations, making unauthenticated RCE here a potential pivot point into software supply chains. Defenders running …

Confirmed exploited · CISA KEV 1 sources high confidence
28 Jul 2026 Analyst report New CVE-2026-16232

Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)

An unauthenticated network-adjacent attacker can gain full admin access to Check Point's central policy management plane — enabling them to modify firewall rules, security policy, or configuration across the entire …

Confirmed exploited · CISA KEV Public PoC 1 sources high confidence
27 Jul 2026 Analyst report New CVE-2026-50522

TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments

Defenders cannot rely on network-layer blocking of Telegram to catch this C2 channel without significant collateral impact, and standard sandbox detonation will fail to surface the final-stage payload due to …

Confirmed exploited · CISA KEV 1 sources high confidence
27 Jul 2026 Analyst report New CVE-2025-48827CVE-2025-48828CVE-2026-50522 +1 CVEs

Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw

Self-hosted vBulletin forums that have not upgraded to 6.2.2 or applied the branch-specific patches are fully exposed to unauthenticated OS command execution with no mitigation short of patching, and the historical …

Confirmed exploited · CISA KEV 1 sources high confidence
27 Jul 2026 Analyst report New CVE-2026-54121

New Certighost PoC exploit lets attackers hijack Windows domains

Any domain user can achieve full domain takeover in default AD CS configurations where ms-DS-MachineAccountQuota is non-zero, making this a critical patch priority; defenders should apply the July 2026 Patch Tuesday …

Public PoC 1 sources high confidence
27 Jul 2026 Analyst report New CVE-2026-27577CVE-2026-50522

n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process

Any user account with workflow-edit access becomes a path to full host-level code execution, credential decryption via `N8N_ENCRYPTION_KEY` exposure, and lateral movement into connected databases, internal services, and …

Confirmed exploited · CISA KEV 1 sources medium confidence
23 Jul 2026 Analyst report New CVE-2018-11511CVE-2021-24139CVE-2021-31755 +1 CVEs

China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

Defenders should prioritize patching internet-facing Java applications and any public systems carrying the four named CVEs (especially CVE-2021-31755, on CISA's KEV catalog since 2021), and implement detection for signed …

Confirmed exploited · CISA KEV 1 sources high confidence
23 Jul 2026 Analyst report New CVE-2024-24919CVE-2026-16232CVE-2026-50751

Check Point warns of SmartConsole zero-day exploited in attacks

Organizations running Check Point Security Management Servers or MDS instances with internet-facing management access should patch immediately, restrict Trusted Clients to specific IP allowlists, and audit SmartConsole …

Confirmed exploited · CISA KEV ×3 1 sources high confidence
22 Jul 2026 Analyst report New CVE-2026-48294

Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data

With over 314 million installs, this extension represented a massive passive attack surface: defenders should audit browser extension permissions and CSP configurations across web applications, as extensions with broad …

1 sources high confidence
19 Jul 2026 Analyst report New

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

Defenders protecting Ukrainian government and military personnel must add ClickFix CAPTCHA lures to user awareness programs and monitor for PowerShell executing from browser-spawned processes, VBS writes to Startup …

1 sources high confidence
19 Jul 2026 Analyst report New

Hackers abuse ViPNet software to target Russian govt agencies

Organizations running ViPNet—particularly Russian government and critical infrastructure entities—should immediately audit the ViPNet Update System directory for unexpected DLLs and monitor for anomalous traffic on ports …

1 sources high confidence
18 Jul 2026 Analyst report New CVE-2026-60137CVE-2026-63030

WordPress Core "wp2shell" RCE flaws get public exploits, patch now

With over 500 million WordPress sites potentially exposed and weaponized PoCs already public, defenders must immediately patch to 6.9.5 or 7.0.2 (forced auto-updates are enabled); organizations that cannot patch …

1 sources high confidence
18 Jul 2026 Analyst report New CVE-2025-8088

Update now: 7-Zip fixes RCE flaw exploitable with malicious archives

Because 7-Zip is ubiquitous on Windows endpoints and lacks automatic updates, a large fraction of the installed base will remain vulnerable until users or administrators push the update manually, making it a high-value …

Confirmed exploited · CISA KEV 1 sources medium confidence
18 Jul 2026 Analyst report New

Microsoft warns of surge in ACR Stealer attacks on customers

Enterprise defenders should prioritize blocking execution of remote content via rundll32.exe, mshta.exe, Python, and PowerShell from user-writable or WebDAV paths, and monitor for scheduled tasks masquerading as software …

1 sources high confidence
16 Jul 2026 Analyst report Recent CVE-2026-53412CVE-2026-53409CVE-2026-53410 +1 CVEs

Zoom Patches Critical Windows Flaw That Could Enable Account Takeover

The critical unauthenticated account takeover flaw (CVE-2026-53412) requires no user interaction and is network-reachable, making it a high-priority patch for any enterprise running Zoom on Windows — particularly in VDI …

1 sources high confidence
16 Jul 2026 Analyst report Recent

New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands

The combination of ClickFix social engineering, aggressive defense evasion (AMSI/ETW unhooking, anti-VM/sandbox checks, CIS geofencing), and blockchain-based C2 fallback makes TELEPUZ resilient to both endpoint controls …

1 sources high confidence
16 Jul 2026 Analyst report Recent CVE-2026-54305CVE-2026-59208

n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer

Organizations running n8n Enterprise in OEM/embedded configurations with multiple trusted JWT issuers should treat this as a potential full account takeover path requiring immediate upgrade to 2.27.4+/2.28.1+ or …

1 sources high confidence
16 Jul 2026 Analyst report Recent

Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor

Stupig's pre-login SYSTEM execution via a trojanized keyboard-layout DLL is a novel persistence technique that sits outside the visibility of standard logon auditing and EDR coverage focused on authenticated sessions, …

1 sources high confidence