Related Threat Clusters
-
Critical Exploitation of Cisco CM and Samsung KNOX Vulnerabilities
Active exploitation of two critical vulnerabilities has been reported: CVE-2026-20230 in Cisco Unified CM and CVE-2026-20971 in Samsung KNOX. The Cisco flaw, a server-side request forgery (SSRF), poses an immediate…
4 articles · Updated June 23, 2026 -
Active Exploitation of GitLab CVE-2026-19478 and Microsoft Entra ID Flaw
GitLab's CVE-2026-19478, a critical code injection vulnerability with a CVSS score of 9.4, is currently under active exploitation just days after its public disclosure on August 17, 2026. Attackers are leveraging this…
2 articles · Updated August 22, 2026 -
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This…
33 articles · Updated August 12, 2026 -
CISA Warns of Critical Exploits in Langflow, Tomcat, and N-central Flaws
CISA has added critical vulnerabilities in IBM Langflow, Apache Tomcat, and N-able N-central to its Known Exploited Vulnerabilities catalog, with a deadline for federal agencies to patch by August 7, 2026. The Langflow…
2 articles · Updated August 7, 2026 -
AI-Generated Exploits Target Siemens PLCs in Critical Infrastructure
On August 19, 2026, U.S. agencies issued a joint advisory confirming that threat actors are using AI-generated exploitation scripts to target Siemens S7 Series PLCs across critical infrastructure sectors, including…
37 articles · Updated August 19, 2026 -
Coldcard Firmware Flaw Leads to $88 Million Bitcoin Theft
A significant vulnerability in Coldcard hardware wallets allowed attackers to exploit weak seed generation, resulting in the theft of approximately 1,367 BTC (around $88.6 million) from 4,585 addresses. The exploit,…
87 articles · Updated August 2, 2026 -
OpenAI Launches GPT-5.4-Cyber Amidst Cybersecurity Arms Race
OpenAI has introduced GPT-5.4-Cyber, a specialized AI model for defensive cybersecurity, available only to vetted professionals through its Trusted Access for Cyber (TAC) program. This model is designed to facilitate…
1370 articles · Updated April 14, 2026
Recent Intelligence Reports
- [SecurityIntel] 22 Aug | GitLab CVE-2026-19478 Under Active Exploitation — Buttondown · August 22, 2026
- [SecurityIntel] 21 Aug | Active Exploitation of Zimbra CVE-2026 — Buttondown · August 21, 2026
- [SecurityIntel] 20 Aug | AI — Buttondown · August 20, 2026
- [SecurityIntel] 12 Aug | Active Zero-Day and SharePoint RCE Patched — Buttondown · August 12, 2026
- [SecurityIntel] 06 Aug | CISA Warns of Exploited Langflow and Tomcat Flaws — Buttondown · August 7, 2026
- [SecurityIntel] 02 Aug | Coldcard Wallet Flaw Leads to $70M Theft — Buttondown · August 2, 2026
- [SecurityIntel] 29 Jul | AI Models Exploit Artifactory Zero-Days to Escape — Buttondown · July 29, 2026
- [SecurityIntel] 28 Jul | Active Zero-Day Exploitation of FastJson and Arista — Buttondown · July 28, 2026