Related Threat Clusters
-
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This…
33 articles · Updated August 12, 2026 -
Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign
Since July 2025, Russian state-backed hackers, known as Laundry Bear, have exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite to infiltrate Western government and commercial…
82 articles · Updated July 23, 2026 -
Critical RCE Vulnerability in Zimbra Exploited by Attackers
A critical remote code execution vulnerability (CVE-2026-73570) in Zimbra Collaboration Suite is being actively exploited by attackers. The flaw, which affects versions prior to 10.1.20, allows unauthenticated attackers…
22 articles · Updated August 19, 2026 -
Critical CVE-2026-48768 Vulnerability in TypeBot Exposes Users to File Upload Attacks
A critical vulnerability, CVE-2026-48768, was disclosed affecting TypeBot versions 3.16.1 and earlier. The flaw allows unauthenticated users to exploit the POST /api/blocks/file-input/v3/generate-upload-url endpoint,…
2 articles · Updated June 18, 2026 -
Operation Escaneo Targets Latin American Critical Infrastructure
Operation Escaneo is a coordinated cyberattack attributed to the MexicanMafia group, targeting critical infrastructure across Latin America, primarily Mexico. The campaign, which spanned from 2025 to 2026, utilized…
4 articles · Updated June 18, 2026 -
Head Mare Hackers Exploit TrueConf Vulnerabilities to Deploy Backdoors
The Head Mare hacktivist group has breached TrueConf video conferencing servers, exploiting vulnerabilities to replace legitimate client installers with malicious versions containing backdoors. The attackers executed…
23 articles · Updated August 8, 2026 -
Critical Stored XSS Vulnerability in SiYuan Enables Remote Code Execution
SiYuan, an open-source personal knowledge management system, has disclosed a critical stored cross-site scripting (XSS) vulnerability that can escalate to remote code execution (RCE) in its Electron desktop client. The…
7 articles · Updated June 25, 2026 -
Critical Stored XSS Vulnerabilities Found in SiYuan Versions Before 3.7.4
Two critical vulnerabilities, CVE-2026-73050 and CVE-2026-73052, have been identified in SiYuan versions prior to 3.7.4. CVE-2026-73050 allows attackers to exploit stored cross-site scripting (XSS) via unescaped color…
13 articles · Updated August 16, 2026 -
CVE-2026-55879: Critical XSS Vulnerability in OpenReplay Leads to Account Takeover
CVE-2026-55879 is a critical vulnerability affecting OpenReplay versions 1.24.0 to 1.25.0, allowing unauthenticated attackers to execute stored XSS in the dashboard. The flaw arises from the OpenReplay tracking SDK's…
3 articles · Updated July 11, 2026 -
Critical SSTI Vulnerability in FOSSBilling Exposes Databases to RCE Attacks
A critical server-side template injection (SSTI) vulnerability in FOSSBilling, tracked as CVE-2026-28496, was disclosed on June 23, 2026. This flaw affects all versions up to 0.7.2 and allows attackers to exploit unsafe…
2 articles · Updated June 26, 2026
Recent Intelligence Reports
- Fedora 43 Nextcloud Security Advisory XSS Security Bypass 2026 — Linuxsecurity · August 25, 2026
- Fedora 44 Nextcloud 34.0.3 Important Security Advisories for 2026 — Linuxsecurity · August 25, 2026
- Wordpress 3com Asesor De Cookies Plugin 3 4 3 Auth Stored Cross Site Scripting Xss Vulnerability — patchstack.com · August 24, 2026
- CVE-2026-7808 - Exploits & Severity — Feedly · August 24, 2026
- CVE-2022-40697 Detail - NVD — Nvd.Nist · August 24, 2026
- CVE 2026 5388 — nvd.nist.gov · August 23, 2026
- CVE-2026-5388: Critical justhtml Sanitizer Bypass (CVSS 9.8) — Detection, Patching, and ... — Securityarsenal · August 23, 2026
- CVE-2026-8445 - Exploits & Severity — Feedly · August 23, 2026