Related Threat Clusters
-
SonicWall SMA1000 Faces Critical Zero-Day Exploitation
SonicWall disclosed two critical vulnerabilities in its SMA1000 series appliances, CVE-2026-83548 and CVE-2026-83549, which are being actively exploited. CVE-2026-83548 is a pre-authentication server-side request…
40 articles · Updated September 2, 2026 -
Chinese Operator Breaches Philippine Nuclear and Naval Entities
A suspected Chinese-speaking operator has compromised a Philippine nuclear research body and a marine engineering company supporting the Philippine Navy by exploiting known vulnerabilities. The attacker utilized…
7 articles · Updated August 31, 2026 -
Critical RCE Vulnerability in IBM Langflow Under Active Exploitation
IBM Langflow OSS is facing a critical remote code execution (RCE) vulnerability, tracked as CVE-2026-9198, which allows unauthenticated attackers to execute arbitrary code on default deployments. The vulnerability…
14 articles · Updated August 5, 2026 -
Critical Vulnerability in NASA Ground Control Software Allows Unauthenticated Access
A critical vulnerability in NASA's AMMOS Instrument Toolkit (AIT-GUI) software, tracked as GHSA-p9r8-2q67-fp86, allows unauthenticated attackers to issue commands to spacecraft and execute scripts. The flaw affects…
7 articles · Updated August 20, 2026 -
TeamPCP's CanisterWorm Targets Iranian Systems with Destructive Kubernetes Wiper
TeamPCP has launched a new cyber campaign deploying a destructive payload that targets Kubernetes clusters configured for Iran. This wiper malware, part of the ongoing CanisterWorm campaign, uses the same…
4 articles · Updated March 23, 2026 -
ShinyHunters Exploits Oracle PeopleSoft Zero-Day Vulnerability
A critical zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft has been exploited by the ShinyHunters group, leading to breaches of over 100 organizations, primarily in the education sector. The vulnerability…
65 articles · Updated June 11, 2026 -
Iranian Hackers Breach Los Angeles Transit System, Steal 700GB of Data
In March 2026, Iranian hackers linked to the Ministry of Intelligence and Security (MOIS) breached the Los Angeles County Metropolitan Transportation Authority (LACMTA), stealing at least 700 gigabytes of sensitive…
25 articles · Updated May 26, 2026 -
PEEP Chrome Extension Turns Browsers Into Remote Access Tools
Cybersecurity researchers have uncovered a sophisticated post-exploitation toolkit named PEEP, which masquerades as a 'Smart Bookmarks' Chrome extension. This malware requires prior administrative access to be…
7 articles · Updated September 7, 2026 -
Chinese APT VerdantBamboo Exploits Brickstorm Malware for Long-term Network Access
The Chinese espionage group UNC5221, also known as VerdantBamboo, has been using the Brickstorm backdoor and new malware variants Plenet and AgentPSD to maintain access to compromised Microsoft 365 environments.…
5 articles · Updated June 5, 2026 -
VerdantBamboo's 18-Month Cyber Campaign Targets Managed Service Providers
A Chinese threat actor known as VerdantBamboo compromised a company's network through a managed service provider (MSP) over 18 months. The initial breach involved a Linux-based Egnyte Storage Sync appliance, which was…
2 articles · Updated June 5, 2026
Recent Intelligence Reports
- cybernoz.com — cybernoz.com · September 8, 2026
- CVE-2026-86169 - OSV — Osv.Dev · September 6, 2026
- CVE-2026-86169 — Cve · September 5, 2026
- CVE-2026-85694 CVE Vulnerability Disclosures / 15h LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language model output derived from web page content. Attackers can inject malicious Python code through web pages using indirect prompt injection to execute arbitrary code on the operator's host without review. — cve.report · September 5, 2026
- CVE-2026-85694 - Exploits & Severity — Feedly · September 5, 2026
- Postgreshell The Database Powering Much Of The Internet Had An Open Door For 12 Years — www.cyera.com · September 4, 2026
- Jadepuffer Agentic Ransomware For Automated Database Extortion — www.sysdig.com · September 3, 2026
- ZDI 26 034 — www.zerodayinitiative.com · September 3, 2026