Related Threat Clusters
-
Head Mare Hackers Exploit TrueConf Vulnerabilities to Deploy Backdoors
The Head Mare hacktivist group has breached TrueConf video conferencing servers, exploiting vulnerabilities to replace legitimate client installers with malicious versions containing backdoors. The attackers executed…
23 articles · Updated August 8, 2026 -
CVE-2026-55879: Critical XSS Vulnerability in OpenReplay Leads to Account Takeover
CVE-2026-55879 is a critical vulnerability affecting OpenReplay versions 1.24.0 to 1.25.0, allowing unauthenticated attackers to execute stored XSS in the dashboard. The flaw arises from the OpenReplay tracking SDK's…
3 articles · Updated July 11, 2026 -
Vibe Coding Tools Found to Generate Critical Security Flaws
A study by security startup Tenzai revealed that popular vibe coding platforms produce insecure code, including critical vulnerabilities, when responding to common programming prompts. The assessment, conducted in…
3 articles · Updated January 14, 2026 -
Critical Vulnerabilities in Splunk Enterprise Expose Systems to Attacks
Multiple high and critical vulnerabilities have been identified in Splunk Enterprise, allowing attackers to execute malicious scripts and exfiltrate sensitive data. The most severe vulnerability, CVE-2026-20253, has a…
36 articles · Updated June 12, 2026 -
Critical justhtml Sanitization Bypass Vulnerabilities Discovered
Multiple critical vulnerabilities have been identified in the justhtml library, specifically CVE-2026-5388, CVE-2026-7808, and CVE-2026-8445, all published on 2026-08-23. These vulnerabilities allow attackers to bypass…
11 articles · Updated August 23, 2026 -
Critical SPIP Vulnerabilities Discovered in Ubuntu 16.04 LTS
Multiple vulnerabilities have been identified in the SPIP website engine affecting Ubuntu 16.04 LTS and its derivatives. These vulnerabilities include cross site scripting (CVE-2022-28959), PHP injection…
2 articles · Updated April 6, 2026 -
CISA Warns of Active Exploitation of Ivanti EPM Vulnerability CVE-2026-1603
CISA has identified a high-severity vulnerability in Ivanti Endpoint Manager (EPM), tracked as CVE-2026-1603, which is currently being exploited in attacks. The flaw allows remote threat actors to bypass authentication…
1 article · Updated March 10, 2026 -
SQL Injection Vulnerability in Elementor Ally Plugin Affects 250,000+ WordPress Sites
A critical SQL injection vulnerability, tracked as CVE-2026-2313, has been discovered in the Ally WordPress plugin, which is used on over 400,000 sites. This flaw allows unauthenticated attackers to inject SQL commands…
10 articles · Updated March 12, 2026 -
SAP Patch Day Addresses Critical Vulnerabilities
On March 10, 2026, SAP released 15 security notes, including two critical vulnerabilities that could allow remote code execution and system compromise. Administrators are urged to apply the patches promptly to protect…
10 articles · Updated March 10, 2026 -
Multiple Vulnerabilities in Microsoft Office Excel (CVE-2026)
Microsoft Office Excel has multiple vulnerabilities that allow unauthorized attackers to execute code locally. These include an out-of-bounds read, use after free, untrusted pointer dereference, heap-based buffer…
14 articles · Updated March 10, 2026
Recent Intelligence Reports
- USN-8703-1: WebKitGTK vulnerabilities — Ubuntu · August 31, 2026
- CVE-2026-8445 - Exploits & Severity — Feedly · August 23, 2026
- Security Fixes Updates And Advisories — trueconf.com · August 21, 2026
- More than half of AI — Cyberscoop · August 7, 2026
- Evo Continuous Offensive Security Is Here — Snyk · August 4, 2026
- What Is AI Pentesting and How Does It Works? — Snyk · July 28, 2026
- What Is AI Pentesting and How Does It Works? — Snyk · July 27, 2026
- The AI code vulnerabilities that grow with your app — Feeds2.Feedburner · July 23, 2026