Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with heightened geopolitical tensions in the Middle East. MuddyWater utilized a previousl...
CVE-2026-21514 is a security feature bypass vulnerability in Microsoft Word, disclosed on February 10, 2026. This flaw allows attackers to exploit nearly 14 million assets across seven Tier 1 countries, primarily in the United States. The vulnerability enables malware deployment without triggering u...
Recent cybersecurity reports detail the exploitation of software vulnerabilities in client applications, particularly targeting web browsers and Microsoft Office. Adversaries utilize techniques such as Drive-by Compromise and Phishing to execute malicious code, often without user interaction. Notabl...