Related Threat Clusters
-
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This…
33 articles · Updated August 12, 2026 -
Critical Chrome Zero-Day CVE-2026-85046 Exploited in the Wild
Google has released an emergency update for Chrome to address CVE-2026-85046, a high-severity zero-day vulnerability in the V8 JavaScript and WebAssembly engine, rated 8.8 on the CVSS scale. The flaw, identified as a…
26 articles · Updated September 4, 2026 -
Critical Remote Code Execution Vulnerability Exploited by China-Nexus Actor
On April 3, 2025, Ivanti disclosed CVE-2025-22457, a critical buffer overflow vulnerability affecting Ivanti Connect Secure and other products. The vulnerability allows unauthenticated remote code execution, and…
2 articles · Updated June 17, 2026 -
F5 Issues Critical Patches for NGINX Vulnerabilities Allowing Remote Code Execution
On June 17, 2026, F5 released emergency patches for two critical vulnerabilities in NGINX, CVE-2026-42530 and CVE-2026-42055. These vulnerabilities affect NGINX Open Source, NGINX Plus, and related products, allowing…
24 articles · Updated June 18, 2026 -
Critical Buffer Overflow Vulnerability in Silex Devices (CVE-2026-32956)
Silex Technology, Inc. has reported a critical heap-based buffer overflow vulnerability in its SD-330AC devices and AMC Manager software, identified as CVE-2026-32956. This vulnerability allows unauthenticated remote…
2 articles · Updated April 20, 2026 -
Persistent Firestarter Malware Targets Cisco Firepower Devices in US Agencies
A sophisticated backdoor malware named Firestarter has been discovered on Cisco Firepower devices, attributed to the state-sponsored threat actor UAT-4356. The malware exploits two vulnerabilities, CVE-2025-20333 and…
37 articles · Updated April 23, 2026 -
Critical NGINX Vulnerability CVE-2026-42945 Exposes Millions to RCE and DoS Attacks
A critical vulnerability, CVE-2026-42945, has been discovered in the NGINX web server's ngx_http_rewrite_module, allowing unauthenticated attackers to execute remote code or crash servers. This heap-based buffer…
51 articles · Updated May 13, 2026 -
Russian FSB Exploits Vulnerable Routers to Target Critical Infrastructure
A joint advisory from 21 global cybersecurity agencies warns that Russian state hackers from the FSB's Center 16 are exploiting poorly configured routers to infiltrate critical infrastructure networks worldwide. The…
76 articles · Updated July 13, 2026 -
CISA Alerts on Critical Flaws in SimpleHelp, Samsung MagicINFO, and D-Link Devices
On April 24, 2026, CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog. The affected products include SimpleHelp remote management software, Samsung MagicINFO 9 Server, and…
3 articles · Updated April 26, 2026 -
AI-Generated Exploits Target Siemens PLCs in Critical Infrastructure
On August 19, 2026, U.S. agencies issued a joint advisory confirming that threat actors are using AI-generated exploitation scripts to target Siemens S7 Series PLCs across critical infrastructure sectors, including…
37 articles · Updated August 19, 2026
Recent Intelligence Reports
- SUSE libvirt Important Buffer Overflow Priv Escalation Vuln 2026-23445 — Linuxsecurity · September 4, 2026
- SUSE postgresql16 Important Security Update 2026-3963 — Linuxsecurity · September 4, 2026
- Oracle Linux 10 gzip Important Buffer Overflow Vuln ELSA-2026-61625 — Linuxsecurity · September 3, 2026
- HPE patches critical ArubaOS-CX remote code execution flaw — Bleepingcomputer · September 3, 2026
- openSUSE apr-util Serious Buffer Overflow SQL Injection Risks 2026-3937 — Linuxsecurity · September 3, 2026
- SUSE apr-util Critical Buffer Overflow SQL Injection Vulnern 2026-3937 — Linuxsecurity · September 3, 2026
- openSUSE apr-util Critical Buffer Overflow SQL Injection Vuln 2026-3938 — Linuxsecurity · September 3, 2026
- SUSE 2026-3938-1 Important Security Update for apr — Linuxsecurity · September 3, 2026