Related Threat Clusters
-
Critical Authorization Vulnerability in SiYuan (CVE-2026-66012)
A critical missing authorization vulnerability (CVE-2026-66012) has been identified in SiYuan versions prior to 3.7.2, allowing remote unauthenticated attackers to bypass authentication on the POST /mcp kernel endpoint.…
2 articles · Updated July 26, 2026 -
PATCHCORD Malware Targets Afghan Telecom and South Asian Infrastructure
Acronis Threat Research Unit has identified a new malware campaign named PATCHCORD, targeting Afghan telecom providers and critical infrastructure in South Asia. The malware, a custom backdoor written in C/C++, is…
10 articles · Updated August 13, 2026 -
Dell PowerFlex Security Updates Address Multiple Vulnerabilities
Dell has released two security updates (DSA-2025-434 and DSA-2025-435) addressing multiple vulnerabilities in PowerFlex Rack and Appliance systems. The updates cover numerous CVEs, including critical vulnerabilities in…
2 articles · Updated May 23, 2026 -
North Korean ClickFake Campaign Targets Web3 Professionals with RATs
Researchers at SOCRadar have identified a new social engineering campaign by North Korea's Famous Chollima group, targeting Web3 and cryptocurrency professionals. The operation, dubbed ClickFake, employs fraudulent job…
2 articles · Updated July 22, 2026 -
Gogs Vulnerability Allows Remote Code Execution via Path Traversal
Gogs, a self-hosted Git service, has a vulnerability allowing path traversal in organization names. This flaw permits attackers to create nested Git repositories, leading to the potential for Remote Code Execution (RCE)…
3 articles · Updated June 24, 2026 -
SUSE and openSUSE Azure Storage AzCopy Security Update Addresses Critical Vulnerabilities
An important security update for azure-storage-azcopy has been released, addressing two critical vulnerabilities: CVE-2026-39821 and CVE-2026-56852. CVE-2026-39821 allows for validation bypass and privilege escalation…
2 articles · Updated August 8, 2026 -
Critical React2Shell RCE Vulnerability Disclosed by Meta
On December 3, 2025, Meta disclosed CVE-2025-55182, a critical remote code execution vulnerability dubbed React2Shell, affecting React Server Components. The flaw arises from improper type validation in the Flight…
2 articles · Updated May 9, 2026 -
Gambling Goblin Targets Brazilian Government Sites for SEO Fraud
A Chinese-speaking cybercrime group, dubbed Gambling Goblin, has been targeting Brazilian government and educational institutions since mid-2025. This group is connected to the previously documented Earth Berberoka and…
4 articles · Updated September 2, 2026 -
Gentlemen Ransomware Uses Advanced Techniques for Network Attacks
The Gentlemen ransomware, a Go-based RaaS, has been active since mid-2025 and employs aggressive propagation methods. It utilizes 21 remote execution techniques, including PsExec, WMIC, and PowerShell Remoting, to…
3 articles · Updated July 6, 2026 -
Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
753 articles · Updated April 29, 2026
Recent Intelligence Reports
- Gaming the system: how a Chinese — Research.Checkpoint · September 2, 2026
- High-Severity MongoDB Driver and BI Connector Flaws Require Immediate Patching Mallory Threat Intelligence Stories / 7h CVE-2026-81532 was published as a high-severity improper-bounds-checking vulnerability in the BI Connector ODBC driver. MongoDB Connector for BI's CVE-2026-77586 was published as a high-severity flaw in which unescaped collection, field, or index names can inject SQL into generated SHOW CREATE output that is later replayed. — mallory.ai · August 29, 2026
- PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure — Acronis · August 13, 2026
- GitHub Expands Dependabot Malware Alerts to Detect Malicious Packages Across 8 Ecosystems — Gbhackers · August 10, 2026
- GitHub Dependabot malware alerts now cover eight ecosystems — Feeds2.Feedburner · August 10, 2026
- openSUSE Azure Storage AzCopy Important Buffer Overflow Threat 2026-3528 — Linuxsecurity · August 8, 2026
- MCP as a Backdoor: CVE-2026-66012 — How a Missing Authorization Check in SiYuan's MCP Endpoint Turns Anonymous Readers into Administrators HB - Tailored Software Solutions / 1h The vulnerability, disclosed via GitHub Security Advisory GHSA-cvhv-7xhj-xjp8 on July 13, 2026, chains three independent defects in SiYuan’s kernel into an unauthenticated, network-reachable path to arbitrary workspace file read/write/delete, plaintext credential exfiltration, and remote code execution via plugin planting — www.hunt-benito.com · July 26, 2026
- Google Makes CodeMender Available as Managed AI Security Agent — Infosecurity-Magazine · July 22, 2026