Related Threat Clusters
-
Critical SonicWall SMA1000 Vulnerabilities Under Active Exploitation
SonicWall has reported two critical vulnerabilities, CVE-2026-15409 and CVE-2026-15410, affecting its SMA1000 Series appliances, which are currently being actively exploited. The first vulnerability, CVE-2026-15409, is…
50 articles · Updated July 15, 2026 -
Critical Unauthenticated RCE Vulnerability in LiteLLM Exploited in the Wild
A critical command injection vulnerability, CVE-2026-42271, in LiteLLM, an open-source AI gateway, allows unauthenticated remote code execution (RCE) when chained with CVE-2026-48710, a Host header validation bypass in…
17 articles · Updated June 9, 2026 -
Critical Command Injection Vulnerability in Arista VeloCloud Orchestrator Under Active Exploitation
A critical command injection vulnerability, CVE-2026-16812, has been discovered in the Arista VeloCloud Orchestrator On-Prem platform, allowing unauthenticated remote attackers to execute arbitrary commands. This flaw,…
23 articles · Updated July 28, 2026 -
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This…
33 articles · Updated August 12, 2026 -
Critical RCE Vulnerability in IBM Langflow Under Active Exploitation
IBM Langflow OSS is facing a critical remote code execution (RCE) vulnerability, tracked as CVE-2026-9198, which allows unauthenticated attackers to execute arbitrary code on default deployments. The vulnerability…
14 articles · Updated August 5, 2026 -
F5 Issues Critical Patches for NGINX Vulnerabilities Allowing Remote Code Execution
On June 17, 2026, F5 released emergency patches for two critical vulnerabilities in NGINX, CVE-2026-42530 and CVE-2026-42055. These vulnerabilities affect NGINX Open Source, NGINX Plus, and related products, allowing…
24 articles · Updated June 18, 2026 -
Critical RCE Vulnerability in Zimbra Exploited by Attackers
A critical remote code execution vulnerability (CVE-2026-73570) in Zimbra Collaboration Suite is being actively exploited by attackers. The flaw, which affects versions prior to 10.1.20, allows unauthenticated attackers…
35 articles · Updated August 19, 2026 -
Critical Vulnerabilities in SonicWall and Fortinet Devices Exploited in the Wild
The inaugural July 2026 InfraTrust Pulse report reveals critical vulnerabilities affecting infrastructure devices, particularly SonicWall's SMA1000 and Fortinet's FortiSandbox. SonicWall's CVE-2026-15409 and…
6 articles · Updated July 22, 2026 -
Operation Escaneo Targets Latin American Critical Infrastructure
Operation Escaneo is a coordinated cyberattack attributed to the MexicanMafia group, targeting critical infrastructure across Latin America, primarily Mexico. The campaign, which spanned from 2025 to 2026, utilized…
4 articles · Updated June 18, 2026 -
Head Mare Hackers Exploit TrueConf Vulnerabilities to Deploy Backdoors
The Head Mare hacktivist group has breached TrueConf video conferencing servers, exploiting vulnerabilities to replace legitimate client installers with malicious versions containing backdoors. The attackers executed…
23 articles · Updated August 8, 2026
Recent Intelligence Reports
- CVE-2026-75121 CVE Vulnerability Disclosures / 1d PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/dispatcher.cgi. The web_vlan_membership_edit_dialog_post handler incorporates the memberTags POST parameter into a shell command without sanitization. A remote authenticated attacker can send a crafted memberTags value to execute arbitrary operating-system commands on the device. — cve.report · August 30, 2026
- CVE-2026-75121 - Exploits & Severity — Feedly · August 29, 2026
- CVE-2026-19042 — www.teamviewer.com · August 28, 2026
- Sentry MCP Server SSRF Exposes How Agent Trust Chains Become Attack Vectors — Cryptorank · August 28, 2026
- Claude Code Opus 5 Auto Mode Hijacked via Prompt Injection to Execute Malicious Code — Cybersecuritynews · August 28, 2026
- openSUSE Wicked Important Indirect Shell Command Injection Fix 2026-3840 — Linuxsecurity · August 28, 2026
- SUSE Wicked Important Indirect Remote Shell Injection Vuln 2026-3840 — Linuxsecurity · August 28, 2026
- Sentry MCP Server SSRF Exposes How Agent Trust Chains Become Attack Vectors — Forkast.News · August 27, 2026