Related Threat Clusters
-
Critical SonicWall SMA1000 Vulnerabilities Under Active Exploitation
SonicWall has reported two critical vulnerabilities, CVE-2026-15409 and CVE-2026-15410, affecting its SMA1000 Series appliances, which are currently being actively exploited. The first vulnerability, CVE-2026-15409, is…
50 articles · Updated July 15, 2026 -
Critical RCE Vulnerability in Rails Active Storage Disclosed
On July 29, 2026, the Ruby on Rails security team published CVE-2026-66066, a critical arbitrary file read and remote code execution (RCE) vulnerability in Active Storage. Discovered by the Ethiack research team, this…
16 articles · Updated July 30, 2026 -
Critical Vulnerabilities in SonicWall and Fortinet Devices Exploited in the Wild
The inaugural July 2026 InfraTrust Pulse report reveals critical vulnerabilities affecting infrastructure devices, particularly SonicWall's SMA1000 and Fortinet's FortiSandbox. SonicWall's CVE-2026-15409 and…
6 articles · Updated July 22, 2026 -
Critical Tails Linux Vulnerability Exposes Users to Deanonymization Risks
Tails Linux has released an emergency patch for a critical kernel vulnerability (CVE-2026-64560) that could allow malicious websites to deanonymize users. The flaw, present since Linux kernel version 5.7, enables…
2 articles · Updated August 5, 2026 -
Critical Security Updates for Fedora's Quick-XML and Related Packages
On July 3, 2026, Fedora released multiple critical security updates addressing vulnerabilities in the quick-xml library and associated packages across Fedora 43 and 44. These updates include patches for rust-quick-xml,…
13 articles · Updated July 6, 2026 -
CISA Warns of Active Exploitation of CVE-2024-1086 in Ransomware Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert regarding the active exploitation of a critical vulnerability in the Linux kernel, tracked as CVE-2024-1086. This privilege escalation…
5 articles · Updated November 4, 2025 -
Critical Linux Vulnerability 'Copy Fail' Grants Root Access Across Major Distros
A newly disclosed vulnerability in the Linux kernel, tracked as CVE-2026-31431 and named 'Copy Fail', allows unprivileged local users to gain root access on virtually all major Linux distributions released since 2017.…
227 articles · Updated April 30, 2026 -
Critical RefluXFS Flaw Exposes Millions of Linux Systems to Root Takeover
A critical vulnerability in the Linux kernel's XFS filesystem, tracked as CVE-2026-64600, allows local users to gain root access by exploiting a race condition in the copy-on-write path. This flaw affects over 16…
13 articles · Updated July 23, 2026 -
Critical DoS Vulnerability in nghttp2 Affects Multiple Debian Releases
A critical denial-of-service (DoS) vulnerability, CVE-2026-27135, was identified in nghttp2, affecting Debian distributions. The flaw allows attackers to exploit missing iframe state validations, leading to assertion…
2 articles · Updated May 14, 2026 -
Critical GhostLock Vulnerability Allows Root Access on Linux Systems
A severe Linux kernel vulnerability, CVE-2026-43499, known as GhostLock, has been publicly disclosed by Nebula Security's VEGA team. This flaw, present since 2011, allows any logged-in user to gain full root control of…
14 articles · Updated July 8, 2026
Recent Intelligence Reports
- High-Severity MongoDB Driver and BI Connector Flaws Require Immediate Patching Mallory Threat Intelligence Stories / 7h CVE-2026-81532 was published as a high-severity improper-bounds-checking vulnerability in the BI Connector ODBC driver. MongoDB Connector for BI's CVE-2026-77586 was published as a high-severity flaw in which unescaped collection, field, or index names can inject SQL into generated SHOW CREATE output that is later replayed. — mallory.ai · August 29, 2026
- Vulnerability Management — www.action1.com · August 28, 2026
- Debian 12 Swift Security Update DLA-4746 — Linuxsecurity · August 20, 2026
- Debian LTS PostgreSQL 15 Security Update DLA-4740-1 CVE-2026 — Linuxsecurity · August 14, 2026
- The security co-processor in many CPUs is insecure — Heise.De · August 13, 2026
- Debian OpenJDK Information Disclosure Denial of Service Vuln DSA-6431 — Linuxsecurity · August 11, 2026
- Debian Kitty Serious Code Execution Vulnerability DSA-6423 — Linuxsecurity · August 9, 2026
- Known Security Vulnerabilities In 7.10 — tails.net · August 5, 2026