Related Threat Clusters
-
China-Linked QTFY Group Targets Critical Infrastructure with Advanced Exploits
The Joint Cybersecurity Advisory JCSA-20260826-01, released on August 26, 2026, details ongoing activities by the China-linked hacking group QTFY, attributed to Nanjing Xinjiuwei Network Technology Co. Active since…
7 articles · Updated September 2, 2026 -
Critical Chrome Zero-Day CVE-2026-85046 Exploited in the Wild
Google has released an emergency update for Chrome to address CVE-2026-85046, a high-severity zero-day vulnerability in the V8 JavaScript and WebAssembly engine, rated 8.8 on the CVSS scale. The flaw, identified as a…
33 articles · Updated September 4, 2026 -
Critical Remote Code Execution Vulnerability Exploited by China-Nexus Actor
On April 3, 2025, Ivanti disclosed CVE-2025-22457, a critical buffer overflow vulnerability affecting Ivanti Connect Secure and other products. The vulnerability allows unauthenticated remote code execution, and…
2 articles · Updated June 17, 2026 -
F5 Issues Critical Patches for NGINX Vulnerabilities Allowing Remote Code Execution
On June 17, 2026, F5 released emergency patches for two critical vulnerabilities in NGINX, CVE-2026-42530 and CVE-2026-42055. These vulnerabilities affect NGINX Open Source, NGINX Plus, and related products, allowing…
24 articles · Updated June 18, 2026 -
Persistent Firestarter Malware Targets Cisco Firepower Devices in US Agencies
A sophisticated backdoor malware named Firestarter has been discovered on Cisco Firepower devices, attributed to the state-sponsored threat actor UAT-4356. The malware exploits two vulnerabilities, CVE-2025-20333 and…
37 articles · Updated April 23, 2026 -
Critical NGINX Vulnerability CVE-2026-42945 Exposes Millions to RCE and DoS Attacks
A critical vulnerability, CVE-2026-42945, has been discovered in the NGINX web server's ngx_http_rewrite_module, allowing unauthenticated attackers to execute remote code or crash servers. This heap-based buffer…
51 articles · Updated May 13, 2026 -
Critical Windows Netlogon Vulnerability (CVE-2026-41089) Under Active Exploitation
A critical vulnerability, CVE-2026-41089, affecting the Windows Netlogon service has been actively exploited. Patched by Microsoft during the May 2026 Patch Tuesday, the vulnerability allows unauthenticated attackers to…
2 articles · Updated June 9, 2026 -
Russian FSB Exploits Vulnerable Routers to Target Critical Infrastructure
A joint advisory from 21 global cybersecurity agencies warns that Russian state hackers from the FSB's Center 16 are exploiting poorly configured routers to infiltrate critical infrastructure networks worldwide. The…
76 articles · Updated July 13, 2026 -
CISA Alerts on Critical Flaws in SimpleHelp, Samsung MagicINFO, and D-Link Devices
On April 24, 2026, CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog. The affected products include SimpleHelp remote management software, Samsung MagicINFO 9 Server, and…
3 articles · Updated April 26, 2026 -
Coordinated Cyberattack Disrupts Water Utilities in Minnesota
A coordinated cyberattack affected water utilities in over 30 Minnesota communities on July 26 and 27, 2026. Key cities impacted include Plymouth, South St. Paul, Braham, and Maple Plain. The attack targeted…
325 articles · Updated July 27, 2026
Recent Intelligence Reports
- HPE patches ArubaOS-CX switches vulnerable to remote code execution | news — Scworld · September 4, 2026
- ACSC warns of critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway — Australiancybersecuritymagazine.Au · September 4, 2026
- HPE Patches ArubaOS-CX: Two Independent No — Techtimes · September 4, 2026
- VMware Workstation and Fusion Updates Patch Critical Vulnerability — Feeds.Feedburner · September 4, 2026
- Two Citrix NetScaler Flaws Put Enterprise Edge Devices at Risk — Thecyberexpress · September 4, 2026
- SUSE Security Update file-roller Fixes Issues Raised by CVE-2026 — Linuxsecurity · September 4, 2026
- Oracle Linux 10 gzip Important Buffer Overflow Vuln ELSA-2026-61625 — Linuxsecurity · September 3, 2026
- Oracle Linux 8 ELSA-2026-62144 — Linuxsecurity · September 3, 2026