Related Threat Clusters
-
CISA Warns of Exploitation of 17-Year-Old Excel Vulnerability
The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding active exploitation of CVE-2009-0238, a critical remote code execution vulnerability in Microsoft Excel, first identified in…
4 articles · Updated April 15, 2026 -
Microsoft Edge and SharePoint Server Vulnerabilities Under Active Exploitation
On April's Patchday, Microsoft addressed over 160 security vulnerabilities, including critical issues in Edge and SharePoint Server. Attackers are actively exploiting CVE-2026-32201 in SharePoint for spoofing attacks,…
71 articles · Updated April 15, 2026 -
Malicious LLM Proxy Routers Compromise AI Security
A recent study identified 28 malicious LLM proxy routers that can modify AI service responses and access sensitive credentials. The research tested 28 paid routers and 400 free routers, revealing that nine injected…
2 articles · Updated April 15, 2026 -
New Windows Zero-Day Vulnerabilities: YellowKey and GreenPlasma Exploits Released
Security researcher Nightmare-Eclipse has disclosed two critical zero-day vulnerabilities affecting Windows 11 and Windows Server 2022/2025. The first, YellowKey, allows attackers to bypass BitLocker encryption,…
42 articles · Updated May 13, 2026 -
Russian Hackers Use CTRL Toolkit for RDP Hijacking via FRP Tunnels
Russian hackers have deployed a new remote access toolkit named 'CTRL' to hijack Remote Desktop Protocol (RDP) sessions. This toolkit utilizes FRP-based reverse tunnels to gain stealthy access to compromised Windows…
11 articles · Updated March 30, 2026 -
Critical RCE Vulnerability in BeyondTrust Software Requires Immediate Patching
BeyondTrust has issued a warning regarding a critical remote code execution (RCE) vulnerability in its Remote Support and Privileged Remote Access software. The flaw, tracked as CVE-2026-1731, allows unauthenticated…
1495 articles · Updated February 9, 2026 -
BlueHammer Zero-Day Exploit Released, Exposing Windows Users to Privilege Escalation
A security researcher, known as Chaotic Eclipse, has publicly released exploit code for a zero-day vulnerability in Windows, dubbed BlueHammer, allowing local privilege escalation to SYSTEM or elevated administrator…
130 articles · Updated April 7, 2026
Recent Intelligence Reports
- Mystery Microsoft bug leaker keeps the zero — Theregister · May 13, 2026
- Microsoft Nisan 2026 Patch Tuesday: 2 Zero-Day, 167 Zafiyet - ÇözümPark — Cozumpark · April 15, 2026
- CC-4770 — Digital.Nhs.Uk · April 15, 2026
- Ancient Excel bug comes out of retirement for active attacks — Theregister · April 15, 2026
- Ancient Excel bug comes out of retirement for active attacks — Theregister · April 15, 2026
- Malicious LLM proxy routers found in the wild — News.Risky.Biz · April 15, 2026
- Microsoft Fixes Two Zero — Infosecurity-Magazine · April 15, 2026
- Warning of attacks on 17-year-old Excel vulnerability — Heise.De · April 15, 2026