Related Threat Clusters
-
Critical Zero-Day Vulnerability CVE-2026-20182 Exploited in Cisco SD-WAN Systems
Cisco has disclosed a critical authentication bypass vulnerability, CVE-2026-20182, affecting its Catalyst SD-WAN Controller and Manager. This flaw allows unauthenticated remote attackers to bypass authentication and…
131 articles · Updated May 14, 2026 -
Critical Joomla JCE Vulnerability Under Active Exploitation
A critical vulnerability in the Joomla Content Editor (JCE), tracked as CVE-2026-48907, allows unauthenticated attackers to execute remote code on affected Joomla sites. This flaw affects JCE versions below 2.9.99.6 and…
33 articles · Updated June 17, 2026 -
Critical Unauthenticated RCE Vulnerability in LiteLLM Exploited in the Wild
A critical command injection vulnerability, CVE-2026-42271, in LiteLLM, an open-source AI gateway, allows unauthenticated remote code execution (RCE) when chained with CVE-2026-48710, a Host header validation bypass in…
17 articles · Updated June 9, 2026 -
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This…
33 articles · Updated August 12, 2026 -
Critical RCE Vulnerability in IBM Langflow Under Active Exploitation
IBM Langflow OSS is facing a critical remote code execution (RCE) vulnerability, tracked as CVE-2026-9198, which allows unauthenticated attackers to execute arbitrary code on default deployments. The vulnerability…
14 articles · Updated August 5, 2026 -
Head Mare Hackers Exploit TrueConf Vulnerabilities to Deploy Backdoors
The Head Mare hacktivist group has breached TrueConf video conferencing servers, exploiting vulnerabilities to replace legitimate client installers with malicious versions containing backdoors. The attackers executed…
23 articles · Updated August 8, 2026 -
Critical Vulnerability in NASA Ground Control Software Allows Unauthenticated Access
A critical vulnerability in NASA's AMMOS Instrument Toolkit (AIT-GUI) software, tracked as GHSA-p9r8-2q67-fp86, allows unauthenticated attackers to issue commands to spacecraft and execute scripts. The flaw affects…
7 articles · Updated August 20, 2026 -
Critical Flaws in Veeam and Terraform MCP Require Immediate Patching
On August 5, 2026, Veeam and HashiCorp released critical patches addressing 11 vulnerabilities, including a CVSS 10.0 cross-tenant isolation bypass in Terraform MCP Server and a CVSS 9.5 unauthenticated credential…
2 articles · Updated August 5, 2026 -
Critical Vulnerabilities in Veeam Software Expose Systems to Remote Attacks
On August 5, 2026, Veeam disclosed multiple critical vulnerabilities affecting Veeam ONE and Veeam Service Provider Console. The vulnerabilities include remote unauthenticated code execution, file read access, and SQL…
3 articles · Updated August 5, 2026 -
Critical Vulnerabilities in Paperclip AI Platform Enable Unauthenticated Command Execution
Oasis Security identified three critical vulnerabilities in the Paperclip AI agent platform, allowing unauthenticated attackers to execute arbitrary commands on servers and developer machines. The flaws stem from a…
11 articles · Updated August 5, 2026
Recent Intelligence Reports
- ash_ai 6-CVE Cluster Exposes the Full Agent Stack in Elixir's First Coordinated AI ... — Tech.Yahoo · August 31, 2026
- 51001 — github.com · August 31, 2026
- Ubuntu 26.04 LTS util-linux Important Sensitivity Issues USN-8702 — Linuxsecurity · August 31, 2026
- USN-8705-1: OpenZFS vulnerability — Ubuntu · August 31, 2026
- USN-8701-1: UDisks vulnerability — Ubuntu · August 31, 2026
- Plataforma IoT en Rust expone gestión completa de usuarios sin autenticación — Ciberseguridadlatam · August 31, 2026
- Read the article at CryptoPolitan — www.cryptopolitan.com · August 29, 2026
- PSIRT WatchGuard CVE-2026-78174 — psirt.watchguard.com · August 29, 2026