Related Threat Clusters
-
Critical SonicWall SMA1000 Vulnerabilities Under Active Exploitation
SonicWall has reported two critical vulnerabilities, CVE-2026-15409 and CVE-2026-15410, affecting its SMA1000 Series appliances, which are currently being actively exploited. The first vulnerability, CVE-2026-15409, is…
62 articles · Updated July 15, 2026 -
Critical Zero-Day Vulnerability CVE-2026-20182 Exploited in Cisco SD-WAN Systems
Cisco has disclosed a critical authentication bypass vulnerability, CVE-2026-20182, affecting its Catalyst SD-WAN Controller and Manager. This flaw allows unauthenticated remote attackers to bypass authentication and…
131 articles · Updated May 14, 2026 -
Operation Highland: Velvet Ant's Decade-Long Espionage Campaign
Operation Highland, attributed to the Velvet Ant cyberespionage group, involved a sophisticated attack that began in 2016 and persisted undetected for a decade. The attackers hijacked the authentication stack of a major…
9 articles · Updated June 13, 2026 -
Critical Buffer Overflow Vulnerability in Silex Devices (CVE-2026-32956)
Silex Technology, Inc. has reported a critical heap-based buffer overflow vulnerability in its SD-330AC devices and AMC Manager software, identified as CVE-2026-32956. This vulnerability allows unauthenticated remote…
2 articles · Updated April 20, 2026 -
Head Mare Hackers Exploit TrueConf Vulnerabilities to Deploy Backdoors
The Head Mare hacktivist group has breached TrueConf video conferencing servers, exploiting vulnerabilities to replace legitimate client installers with malicious versions containing backdoors. The attackers executed…
23 articles · Updated August 8, 2026 -
Russian FSB Exploits Vulnerable Routers to Target Critical Infrastructure
A joint advisory from 21 global cybersecurity agencies warns that Russian state hackers from the FSB's Center 16 are exploiting poorly configured routers to infiltrate critical infrastructure networks worldwide. The…
76 articles · Updated July 13, 2026 -
Exploitation of WinRAR CVE-2025-8088 Threatens Ukrainian Organizations
Two Russia-aligned cyber campaigns are exploiting the WinRAR vulnerability CVE-2025-8088 against Ukrainian targets nearly a year after it was patched. The flaw, a path traversal vulnerability, allows attackers to write…
19 articles · Updated June 8, 2026 -
New Vulnerabilities Discovered in Serial-to-IP Converters Threaten Critical Infrastructure
Forescout Technologies has identified 22 new vulnerabilities in serial-to-IP converters from Lantronix and Silex, which are widely used in critical sectors like healthcare and utilities. These vulnerabilities,…
9 articles · Updated April 21, 2026 -
CISA Alerts on Critical Flaws in SimpleHelp, Samsung MagicINFO, and D-Link Devices
On April 24, 2026, CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog. The affected products include SimpleHelp remote management software, Samsung MagicINFO 9 Server, and…
3 articles · Updated April 26, 2026 -
Critical Vulnerabilities in Yarbo Robot Firmware Expose Devices to Remote Attacks
AHA! disclosed three critical vulnerabilities in Yarbo robot firmware v2.3.9, identified as CVE-2026-7413, CVE-2026-7414, and CVE-2026-7415. The vulnerabilities include a hidden backdoor, hardcoded credentials, and an…
3 articles · Updated May 7, 2026
Recent Intelligence Reports
- [AURORA] – Ransomware Victim: Benshaw, Inc[.] — Redpacketsecurity · September 7, 2026
- Dissecting a PHP web server rootkit — News.Sophos · September 7, 2026
- Darktrace & OpenAI: Advancing Incident Investigation with Daybreak — Darktrace · September 3, 2026
- HPE patches critical ArubaOS-CX remote code execution flaw — Bleepingcomputer · September 3, 2026
- LLMjacking Attack Uses Leaked AWS IAM Key to Steal Paid AI Model Access — Cybersecuritynews · September 3, 2026
- Iranian Hackers Are Probing U.S. Water Systems by Finding Unlocked Front Doors — Gadgetreview · September 3, 2026
- AI 'Machine Speed' Cuts 2 — Darkreading · September 3, 2026
- Jadepuffer Agentic Ransomware For Automated Database Extortion — www.sysdig.com · September 3, 2026