Related Threat Clusters
-
Critical SonicWall SMA1000 Vulnerabilities Under Active Exploitation
SonicWall has reported two critical vulnerabilities, CVE-2026-15409 and CVE-2026-15410, affecting its SMA1000 Series appliances, which are currently being actively exploited. The first vulnerability, CVE-2026-15409, is…
62 articles · Updated July 15, 2026 -
Critical Zero-Day Vulnerability CVE-2026-20182 Exploited in Cisco SD-WAN Systems
Cisco has disclosed a critical authentication bypass vulnerability, CVE-2026-20182, affecting its Catalyst SD-WAN Controller and Manager. This flaw allows unauthenticated remote attackers to bypass authentication and…
131 articles · Updated May 14, 2026 -
Critical Joomla JCE Vulnerability Under Active Exploitation
A critical vulnerability in the Joomla Content Editor (JCE), tracked as CVE-2026-48907, allows unauthenticated attackers to execute remote code on affected Joomla sites. This flaw affects JCE versions below 2.9.99.6 and…
33 articles · Updated June 17, 2026 -
Critical Unauthenticated RCE Vulnerability in LiteLLM Exploited in the Wild
A critical command injection vulnerability, CVE-2026-42271, in LiteLLM, an open-source AI gateway, allows unauthenticated remote code execution (RCE) when chained with CVE-2026-48710, a Host header validation bypass in…
17 articles · Updated June 9, 2026 -
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This…
33 articles · Updated August 12, 2026 -
Critical RCE Vulnerability in Windows IKE Actively Exploited
A critical remote code execution vulnerability in Microsoft Windows Internet Key Exchange (IKE), tracked as CVE-2026-33824, is being actively exploited. This double-free memory corruption issue affects all supported…
4 articles · Updated August 19, 2026 -
Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign
Since July 2025, Russian state-backed hackers, known as Laundry Bear, have exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite to infiltrate Western government and commercial…
82 articles · Updated July 23, 2026 -
GRU Compromises Home Routers in 23 States to Steal Outlook Credentials
The FBI and partners disrupted a covert network of compromised TP-Link and MikroTik routers exploited by the Russian GRU (APT28) to steal Outlook credentials. This operation, known as Operation Masquerade, revealed that…
6 articles · Updated May 22, 2026 -
SonicWall SMA1000 Faces Third Zero-Day Exploitation in 2026
SonicWall's SMA1000 VPN appliances are under active exploitation due to two newly discovered zero-day vulnerabilities, CVE-2026-83548 and CVE-2026-83549, which were confirmed on September 1, 2026. The first…
23 articles · Updated September 2, 2026 -
Chinese Operator Breaches Philippine Nuclear and Naval Entities
A suspected Chinese-speaking operator has compromised a Philippine nuclear research body and a marine engineering company supporting the Philippine Navy by exploiting known vulnerabilities. The attacker utilized…
5 articles · Updated August 31, 2026
Recent Intelligence Reports
- Inside Sality Botnet Disruption Operation — www.crowdstrike.com · September 3, 2026
- Thousands of Dropbox accounts breached via Lenovo flaw — Computing · September 3, 2026
- SonicWall reports two major security holes under active exploit — Networkworld · September 3, 2026
- From the frontline: Ukraine's cyber security learnings for EU founders | EU — Eu-Startups · September 3, 2026
- Iran's cyber attack strategy is 'perfect weapon' against US — Thenationalnews · September 3, 2026
- Legacy Lenovo login opens 5,000 Dropbox accounts to attackers — Theregister · September 3, 2026
- SonicWall reports two major security holes under active exploit — Csoonline · September 2, 2026
- Remote access Sonicwall SMA1000: Attackers are manipulating internal services — Heise.De · September 2, 2026