Related Threat Clusters
-
Massive Data Breach at US Social Security Administration and Cyberattacks on European Infrastructure
In 2026, significant cybersecurity incidents have emerged, including a data breach at the US Social Security Administration (SSA) linked to the Department of Government Efficiency (DOGE) led by Elon Musk. Reports…
2 articles · Updated July 7, 2026 -
Nuxt Security Vulnerabilities Require Immediate Attention
Nuxt has released security patches for versions 4.5.1 and 3.21.10, addressing multiple vulnerabilities including a high-severity server-side remote code execution (RCE) risk. The RCE vulnerability occurs when the Vue…
4 articles · Updated July 27, 2026 -
2026 Cyberattacks Target Critical Infrastructure and Data Breaches
In 2026, cyberattacks have escalated from data theft to targeting critical infrastructure, affecting government systems, educational platforms, and medical technology companies. The U.S. Department of Government…
2 articles · Updated June 7, 2026 -
Critical Vulnerabilities Discovered in CrowdStrike LogScale and Other Security Tools
CrowdStrike disclosed a critical vulnerability (CVE-2026-40050) in its LogScale product, allowing unauthenticated attackers to exploit a path traversal flaw to access sensitive files. This vulnerability affects…
4 articles · Updated April 27, 2026 -
High-Risk Phishing Campaign Targets TRON Wallet Users via Fake Chrome Extension
A phishing campaign targeting TRON wallet users has been identified, involving a fake Chrome extension masquerading as the TronLink wallet. This malicious extension employs Unicode bidirectional control characters and…
6 articles · Updated May 11, 2026 -
Malicious AI Skills Campaign Targets 1.7 Million Users, Exposes Major Vulnerabilities
Zenity Labs revealed a malicious skills campaign that has affected over 1.7 million installs through Vercel's skills.sh. The campaign involved credential-stealing skills that were initially benign but later weaponized.…
4 articles · Updated August 6, 2026 -
Critical Vulnerabilities in React and Next.js Require Immediate Updates
Multiple critical vulnerabilities affecting React Server Components and .js have been disclosed, including denial of service, server-side request forgery, and middleware bypass issues. These flaws impact versions 13.x…
10 articles · Updated May 8, 2026 -
Next.js Security Release Addresses Critical Remote Code Execution Vulnerabilities
Vercel disclosed two critical vulnerabilities in Next.js affecting applications using the AVIF image format and Windows servers. The first vulnerability, tracked as GHSA-2xp9-vwfh-vxw4, allows unauthenticated remote…
9 articles · Updated August 27, 2026 -
Supply Chain Attack on node-ipc npm Package Exposes 822K Downloads to Credential Theft
A supply chain attack on the node-ipc npm package has compromised three versions (9.1.6, 9.2.3, 12.0.1) with credential-stealing malware. The attack exploited an expired domain to hijack a dormant maintainer account,…
11 articles · Updated May 15, 2026 -
CoreBreak Vulnerability Exposes AI Agent Frameworks to Unauthorized Tool Use
Security researchers revealed multiple vulnerabilities in AI agent frameworks, allowing unauthorized tool use and potential remote code execution (RCE). The CoreBreak vulnerability affects Amazon Web Services (AWS),…
9 articles · Updated August 7, 2026
Recent Intelligence Reports
- Nextjs August 2026 Security Release — vercel.com · August 28, 2026
- AWS Fixed Its Managed Agent Service but Left Strands Python SDK Unpatched — Techtimes · August 7, 2026
- Zenity Labs Uncovers 1.7 Million-Install Malicious Skills Campaign and Dozens of ... — Businesswire · August 6, 2026
- How AI — Bleepingcomputer · August 5, 2026
- How AI — Bleepingcomputer · August 5, 2026
- Nuxt July 2026 security advisory — Vercel · July 27, 2026
- SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts — Aikido.Dev · July 19, 2026
- Hacked, leaked, and held for ransom: The worst breaches of 2026 so far — Techcrunch · July 7, 2026