Related Threat Clusters
-
CVE-2026-47668: Unauthenticated RCE Vulnerability in DbGate
DbGate's JSON script runner has a critical vulnerability (CVE-2026-47668) that allows unauthenticated remote code execution via the functionName parameter in JSON script assign commands. The vulnerability arises from…
2 articles · Updated June 6, 2026 -
Critical RCE Vulnerability in Prompty (CVE-2026-73299) Requires Immediate Action
CVE-2026-73299 is a critical remote code execution vulnerability in the TypeScript Nunjucks renderer of Prompty, affecting versions prior to 0.1.5 and 2.0.0-beta.5. An unauthenticated attacker can exploit this flaw by…
2 articles · Updated August 13, 2026 -
Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign
Since July 2025, Russian state-backed hackers, known as Laundry Bear, have exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite to infiltrate Western government and commercial…
82 articles · Updated July 23, 2026 -
APT28 Exploits Zimbra Vulnerability in Ongoing Attacks Against Ukraine
Russian state-backed hackers from APT28 are actively exploiting a high-severity stored cross-site scripting vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite (ZCS) to target Ukrainian government entities.…
8 articles · Updated March 19, 2026 -
Gamaredon Exploits WinRAR Vulnerability in Ongoing Ukraine Campaign
Gamaredon, a Russian state-backed APT group, is actively exploiting a WinRAR vulnerability (CVE-2025-8088) to deploy malware against Ukrainian government and military targets. The attack begins with a spearphishing…
7 articles · Updated June 2, 2026 -
Operation Escaneo Targets Latin American Critical Infrastructure
Operation Escaneo is a coordinated cyberattack attributed to the MexicanMafia group, targeting critical infrastructure across Latin America, primarily Mexico. The campaign, which spanned from 2025 to 2026, utilized…
4 articles · Updated June 18, 2026 -
DarkSword iOS Exploit Chain Targets Mobile Devices Globally
The Google Threat Intelligence Group has identified DarkSword, a full-chain iOS exploit affecting versions 18.4 to 18.7. This exploit leverages multiple zero-day vulnerabilities, including CVE-2025-31277 and…
2 articles · Updated July 11, 2026 -
Critical Stored XSS Vulnerability in SiYuan Enables Remote Code Execution
SiYuan, an open-source personal knowledge management system, has disclosed a critical stored cross-site scripting (XSS) vulnerability that can escalate to remote code execution (RCE) in its Electron desktop client. The…
7 articles · Updated June 25, 2026 -
Critical Stored XSS Vulnerabilities Found in SiYuan Versions Before 3.7.4
Two critical vulnerabilities, CVE-2026-73050 and CVE-2026-73052, have been identified in SiYuan versions prior to 3.7.4. CVE-2026-73050 allows attackers to exploit stored cross-site scripting (XSS) via unescaped color…
13 articles · Updated August 16, 2026 -
Ghost CMS SQL Injection Exploits 700+ Sites in Ongoing ClickFix Campaign
A critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS is being actively exploited in a large-scale cyberattack affecting over 700 websites, including those of Harvard University, Oxford University, Auburn…
17 articles · Updated May 25, 2026
Recent Intelligence Reports
- 5 Common Browser Attacks And How To Prevent Them — www.techtarget.com · August 31, 2026
- CVE-2026-82244 - OSV — Osv.Dev · August 30, 2026
- CVE-2026-82244 - Exploits & Severity — Feedly · August 29, 2026
- CVE-2026-7808 - Exploits & Severity — Feedly · August 24, 2026
- New Agent Tesla malware version uses emoji obfuscation to evade detection — Scworld · August 21, 2026
- GTIG Tracks Three Russian Espionage Clusters Abusing Auth Flows — Technadu · August 21, 2026
- Hackers Hide Agent Tesla JScript Behind Unicode Emojis to Evade Detection — Cybersecuritynews · August 21, 2026
- New Agent Tesla Malware Variant Boosts Evasion Capabilities — Infosecurity-Magazine · August 21, 2026