Related Threat Clusters
-
Critical Command Injection Vulnerability in Arista VeloCloud Orchestrator Under Active Exploitation
A critical command injection vulnerability, CVE-2026-16812, has been discovered in the Arista VeloCloud Orchestrator On-Prem platform, allowing unauthenticated remote attackers to execute arbitrary commands. This flaw,…
23 articles · Updated July 28, 2026 -
SonicWall SMA1000 Faces Critical Zero-Day Exploitation
SonicWall disclosed two critical vulnerabilities in its SMA1000 series appliances, CVE-2026-83548 and CVE-2026-83549, which are being actively exploited. CVE-2026-83548 is a pre-authentication server-side request…
31 articles · Updated September 2, 2026 -
Fake Bahrain Civil Defense App Distributes Advanced Surveillance Malware
A malicious Android application masquerading as a Bahrain civil defense alert tool has been identified, targeting users in Bahrain and the Gulf region amid heightened tensions from Iranian missile threats. This app…
9 articles · Updated July 22, 2026 -
QuickFox VPN Supply Chain Attack Delivers FDMTP Backdoor to Windows Users
A supply chain attack targeting the QuickFox VPN application has been uncovered, affecting Windows users. The attack, attributed to the Chinese state-sponsored group Mustang Panda, involved a trojanized version of the…
14 articles · Updated August 6, 2026 -
Iranian APT Groups Target Israeli Organizations with Modular C2 Frameworks
In 2026, Iranian APT groups, notably Cavern Manticore and OilRig, have intensified cyber operations against Israeli organizations, primarily in the IT and government sectors. Cavern Manticore employs a modular…
10 articles · Updated July 6, 2026 -
Critical wp2shell Vulnerability Enables Unauthenticated RCE in WordPress
A critical vulnerability chain, dubbed wp2shell, has been identified in WordPress Core, allowing unauthenticated attackers to execute arbitrary code on default installations. This vulnerability is tracked as…
78 articles · Updated July 20, 2026 -
Critical Vulnerabilities in Kaltura HTML5 Player Expose Organizations to Attacks
Two critical vulnerabilities, CVE-2026-19912 and CVE-2026-19913, have been discovered in the Kaltura HTML5 Player Library (mwEmbed/html5lib). These flaws allow unauthenticated remote attackers to execute arbitrary code…
4 articles · Updated August 26, 2026 -
Gitea Docker Authentication Bypass Vulnerability Under Active Exploitation
CVE-2026-20896 is a critical authentication bypass vulnerability (CVSS 9.8) affecting Gitea Docker images up to version 1.26.2. Discovered on July 3, 2026, the flaw allows unauthenticated remote attackers to impersonate…
16 articles · Updated July 7, 2026 -
Critical GitLab Vulnerability Allows Unauthenticated Data Deletion
GitLab released an emergency patch on August 17, 2026, for a critical vulnerability tracked as CVE-2026-19478. This flaw allows unauthenticated attackers to remotely modify or delete public projects and user data…
30 articles · Updated August 18, 2026 -
Oracle CSPU May 2026: 35 Critical Vulnerabilities Addressed
Oracle released its first Critical Security Patch Update (CSPU) on May 28, 2026, addressing 35 vulnerabilities across multiple product families, including Oracle Database, Oracle REST Data Services, and Oracle…
68 articles · Updated May 29, 2026
Recent Intelligence Reports
- Active Exploitation Alert: SonicWall SMA 1000 Zero-Day Vulnerabilities (CVE-2024 — Rescana · September 2, 2026
- Critical Unpatched Vulnerabilities in Kaltura mwEmbed Expose Organizations to Remote ... — Rescana · August 26, 2026
- CDN Tsunami: Critical HTTP/3 to HTTP/1.1 Protocol Translation Vulnerability Triggers Up to ... — Rescana · August 20, 2026
- CVE-2026-19478: Critical GitLab CE/EE GraphQL Vulnerability Enables Remote Deletion of ... — Rescana · August 18, 2026
- Critical Command Injection Vulnerability in Snowflake snowflake-connector-net GitHub ... — Rescana · August 18, 2026
- SafePal Order — Rescana · August 17, 2026
- Wesco Cloud CRM Data Breach: ExfilSquad Data Theft and Supply Chain Risks Analyzed — Rescana · August 12, 2026
- Active Exploitation Alert: Critical Gitea CVE-2026 — Rescana · August 6, 2026