Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
Progress Software has issued urgent advisories regarding critical vulnerabilities in its MOVEit Automation platform, specifically CVE-2026-4670 and CVE-2026-5174. These vulnerabilities allow attackers to bypass authentication and escalate privileges, potentially leading to unauthorized access and da...
FortiGuard Labs has identified a new Linux botnet named Evooo1Bot, which is based on the Mirai malware framework. This botnet targets internet-facing edge devices, exploiting multiple vulnerabilities since July 2026. The botnet utilizes a loader script at 91.92.40[.]118/wget.sh to download and execu...
The Hospital for Sick Children (SickKids) reported a cybersecurity incident exposing personal information of current and former employees and job applicants. The breach was linked to a vulnerability in a third-party software application, affecting the hospital's external Careers website, which has s...
Security debt is accumulating as organizations delay necessary security fixes, leading to increased cyber risks. This phenomenon, highlighted in ISACA's research, includes unresolved vulnerabilities, unsupported software, and postponed upgrades. As IT environments grow more complex with cloud servic...