Related Threat Clusters
-
Critical SonicWall SMA1000 Vulnerabilities Under Active Exploitation
SonicWall has reported two critical vulnerabilities, CVE-2026-15409 and CVE-2026-15410, affecting its SMA1000 Series appliances, which are currently being actively exploited. The first vulnerability, CVE-2026-15409, is…
50 articles · Updated July 15, 2026 -
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This…
33 articles · Updated August 12, 2026 -
Critical RCE Vulnerability in Windows IKE Actively Exploited
A critical remote code execution vulnerability in Microsoft Windows Internet Key Exchange (IKE), tracked as CVE-2026-33824, is being actively exploited. This double-free memory corruption issue affects all supported…
4 articles · Updated August 19, 2026 -
F5 Issues Critical Patches for NGINX Vulnerabilities Allowing Remote Code Execution
On June 17, 2026, F5 released emergency patches for two critical vulnerabilities in NGINX, CVE-2026-42530 and CVE-2026-42055. These vulnerabilities affect NGINX Open Source, NGINX Plus, and related products, allowing…
24 articles · Updated June 18, 2026 -
Gamaredon Exploits WinRAR Vulnerability in Ongoing Ukraine Campaign
Gamaredon, a Russian state-backed APT group, is actively exploiting a WinRAR vulnerability (CVE-2025-8088) to deploy malware against Ukrainian government and military targets. The attack begins with a spearphishing…
7 articles · Updated June 2, 2026 -
Critical Oracle WebLogic Flaw Under Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-21962, a critical vulnerability affecting Oracle HTTP Server and WebLogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities…
17 articles · Updated August 25, 2026 -
Critical CVE-2026-48768 Vulnerability in TypeBot Exposes Users to File Upload Attacks
A critical vulnerability, CVE-2026-48768, was disclosed affecting TypeBot versions 3.16.1 and earlier. The flaw allows unauthenticated users to exploit the POST /api/blocks/file-input/v3/generate-upload-url endpoint,…
2 articles · Updated June 18, 2026 -
Head Mare Hackers Exploit TrueConf Vulnerabilities to Deploy Backdoors
The Head Mare hacktivist group has breached TrueConf video conferencing servers, exploiting vulnerabilities to replace legitimate client installers with malicious versions containing backdoors. The attackers executed…
23 articles · Updated August 8, 2026 -
Critical Vulnerability in NASA Ground Control Software Allows Unauthenticated Access
A critical vulnerability in NASA's AMMOS Instrument Toolkit (AIT-GUI) software, tracked as GHSA-p9r8-2q67-fp86, allows unauthenticated attackers to issue commands to spacecraft and execute scripts. The flaw affects…
7 articles · Updated August 20, 2026 -
Operation Endgame Disrupts Evil Corp's SocGholish Malware Network
On June 18, 2026, international law enforcement agencies launched Operation Endgame, disrupting the SocGholish malware infrastructure linked to the Russian cybercrime group Evil Corp. The operation resulted in the…
67 articles · Updated June 18, 2026
Recent Intelligence Reports
- Ubuntu 26.04 LTS GNU cpio Important Input Sanitization Flaws USN-8704 — Linuxsecurity · August 31, 2026
- USN-8704-1: GNU cpio vulnerabilities — Ubuntu · August 31, 2026
- 2026 08 07 — docs.vulncheck.com · August 31, 2026
- USN-8702-1: util — Ubuntu · August 31, 2026
- Critical Ruby on Rails Vulnerability in Attackers' Crosshairs — Securityweek · August 31, 2026
- The Hugging Face Breach: Key Questions Every Security Leader Must Answer — Zscaler · August 31, 2026
- TeamViewer patches code injection vulnerability — Heise.De · August 28, 2026
- SUSE python36-pip Moderate URL Handling Arbitrary File Issue 2026-3846 — Linuxsecurity · August 28, 2026