Related Threat Clusters
-
Critical SonicWall SMA1000 Vulnerabilities Under Active Exploitation
SonicWall has reported two critical vulnerabilities, CVE-2026-15409 and CVE-2026-15410, affecting its SMA1000 Series appliances, which are currently being actively exploited. The first vulnerability, CVE-2026-15409, is…
50 articles · Updated July 15, 2026 -
Critical Zero-Day Vulnerability CVE-2026-20182 Exploited in Cisco SD-WAN Systems
Cisco has disclosed a critical authentication bypass vulnerability, CVE-2026-20182, affecting its Catalyst SD-WAN Controller and Manager. This flaw allows unauthenticated remote attackers to bypass authentication and…
131 articles · Updated May 14, 2026 -
Critical Joomla JCE Vulnerability Under Active Exploitation
A critical vulnerability in the Joomla Content Editor (JCE), tracked as CVE-2026-48907, allows unauthenticated attackers to execute remote code on affected Joomla sites. This flaw affects JCE versions below 2.9.99.6 and…
33 articles · Updated June 17, 2026 -
Critical Unauthenticated RCE Vulnerability in LiteLLM Exploited in the Wild
A critical command injection vulnerability, CVE-2026-42271, in LiteLLM, an open-source AI gateway, allows unauthenticated remote code execution (RCE) when chained with CVE-2026-48710, a Host header validation bypass in…
17 articles · Updated June 9, 2026 -
Critical Zero-Day Vulnerability in LiteSpeed cPanel Plugin Actively Exploited
A critical zero-day privilege escalation vulnerability in the LiteSpeed User-End cPanel plugin is being exploited in the wild, allowing authenticated cPanel users to execute arbitrary scripts as root. This flaw, tracked…
17 articles · Updated May 23, 2026 -
CVE-2026-47668: Unauthenticated RCE Vulnerability in DbGate
DbGate's JSON script runner has a critical vulnerability (CVE-2026-47668) that allows unauthenticated remote code execution via the functionName parameter in JSON script assign commands. The vulnerability arises from…
2 articles · Updated June 6, 2026 -
Critical RCE Vulnerability in Prompty (CVE-2026-73299) Requires Immediate Action
CVE-2026-73299 is a critical remote code execution vulnerability in the TypeScript Nunjucks renderer of Prompty, affecting versions prior to 0.1.5 and 2.0.0-beta.5. An unauthenticated attacker can exploit this flaw by…
2 articles · Updated August 13, 2026 -
Critical Command Injection Vulnerability in Arista VeloCloud Orchestrator Under Active Exploitation
A critical command injection vulnerability, CVE-2026-16812, has been discovered in the Arista VeloCloud Orchestrator On-Prem platform, allowing unauthenticated remote attackers to execute arbitrary commands. This flaw,…
23 articles · Updated July 28, 2026 -
Akira Ransomware Group Targets Critical Infrastructure, Extracts $42 Million
The Akira ransomware group has been identified as a significant threat to critical infrastructure, with the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the FBI warning of its active ransomware…
9 articles · Updated November 14, 2025 -
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This…
33 articles · Updated August 12, 2026
Recent Intelligence Reports
- openSUSE yast2-samba-client Important Command Injection Issue 2026-3887 — Linuxsecurity · September 1, 2026
- openSUSE Yast2-Samba-Client Important Command Injection Fix 2026-3888 — Linuxsecurity · September 1, 2026
- openSUSE yast2-samba-client Important Command Injection Vuln 2026-3889 — Linuxsecurity · September 1, 2026
- openSUSE yast2-auth-client Important OS Command Injection Fix 2026-3901 — Linuxsecurity · September 1, 2026
- Fire Ant Evolves From Hypervisors To Trusted Infrastructure — www.sygnia.co · August 31, 2026
- ash_ai 6-CVE Cluster Exposes the Full Agent Stack in Elixir's First Coordinated AI ... — Forkast.News · August 31, 2026
- Chinese Fire Ant hackers turn Cisco routers into spying platforms — Bleepingcomputer · August 31, 2026
- 2026 08 07 — docs.vulncheck.com · August 31, 2026