Related Threat Clusters
-
Critical SonicWall SMA1000 Vulnerabilities Under Active Exploitation
SonicWall has reported two critical vulnerabilities, CVE-2026-15409 and CVE-2026-15410, affecting its SMA1000 Series appliances, which are currently being actively exploited. The first vulnerability, CVE-2026-15409, is…
50 articles · Updated July 15, 2026 -
Critical Zero-Day Vulnerability CVE-2026-20182 Exploited in Cisco SD-WAN Systems
Cisco has disclosed a critical authentication bypass vulnerability, CVE-2026-20182, affecting its Catalyst SD-WAN Controller and Manager. This flaw allows unauthenticated remote attackers to bypass authentication and…
131 articles · Updated May 14, 2026 -
Critical Zero-Day Vulnerability in LiteSpeed cPanel Plugin Actively Exploited
A critical zero-day privilege escalation vulnerability in the LiteSpeed User-End cPanel plugin is being exploited in the wild, allowing authenticated cPanel users to execute arbitrary scripts as root. This flaw, tracked…
17 articles · Updated May 23, 2026 -
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This…
33 articles · Updated August 12, 2026 -
Persistent Firestarter Malware Targets Cisco Firepower Devices in US Agencies
A sophisticated backdoor malware named Firestarter has been discovered on Cisco Firepower devices, attributed to the state-sponsored threat actor UAT-4356. The malware exploits two vulnerabilities, CVE-2025-20333 and…
37 articles · Updated April 23, 2026 -
Operation Escaneo Targets Latin American Critical Infrastructure
Operation Escaneo is a coordinated cyberattack attributed to the MexicanMafia group, targeting critical infrastructure across Latin America, primarily Mexico. The campaign, which spanned from 2025 to 2026, utilized…
4 articles · Updated June 18, 2026 -
Head Mare Hackers Exploit TrueConf Vulnerabilities to Deploy Backdoors
The Head Mare hacktivist group has breached TrueConf video conferencing servers, exploiting vulnerabilities to replace legitimate client installers with malicious versions containing backdoors. The attackers executed…
23 articles · Updated August 8, 2026 -
Critical Authorization Vulnerability in SiYuan (CVE-2026-66012)
A critical missing authorization vulnerability (CVE-2026-66012) has been identified in SiYuan versions prior to 3.7.2, allowing remote unauthenticated attackers to bypass authentication on the POST /mcp kernel endpoint.…
2 articles · Updated July 26, 2026 -
Critical Vulnerabilities in Veeam Software Expose Systems to Remote Attacks
On August 5, 2026, Veeam disclosed multiple critical vulnerabilities affecting Veeam ONE and Veeam Service Provider Console. The vulnerabilities include remote unauthenticated code execution, file read access, and SQL…
3 articles · Updated August 5, 2026 -
Critical Privilege Escalation Vulnerability in ProfileGrid Plugin for WordPress
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is critically vulnerable to privilege escalation via account takeover, affecting all versions up to and including 5.9.9.5. The vulnerability…
2 articles · Updated June 30, 2026
Recent Intelligence Reports
- USN-8705-2: OpenZFS vulnerability — Ubuntu · August 31, 2026
- SUSE Micro 6.1 Advisory 2026-23351-1 Highlights CVE-2026 — Linuxsecurity · August 31, 2026
- 51002 — github.com · August 31, 2026
- HardBreacher PoC Claims Kaspersky Endpoint 0 — Cybersecuritynews · August 31, 2026
- Ubuntu 26.04 LTS OpenZFS Key Admin Access Bypass 8705-1 CVE-2026 — Linuxsecurity · August 31, 2026
- Ubuntu 26.04 UDisks Significant Local Privilege Escalation Issue USN-8701 — Linuxsecurity · August 31, 2026
- CVE-2026 — Api.Msrc.Microsoft · August 31, 2026
- CVE-2026 — Api.Msrc.Microsoft · August 31, 2026