Related Threat Clusters
-
CISA Warns U.S. After Cyberattack on Poland's Energy Grid Linked to Russian Hackers
A cyberattack targeting Poland's energy grid in December has been linked to a Russian government-affiliated hacking group. The attack affected 30 wind and photovoltaic farms and prompted the Cybersecurity and…
9 articles · Updated February 10, 2026 -
Critical SonicWall SMA1000 Vulnerabilities Under Active Exploitation
SonicWall has reported two critical vulnerabilities, CVE-2026-15409 and CVE-2026-15410, affecting its SMA1000 Series appliances, which are currently being actively exploited. The first vulnerability, CVE-2026-15409, is…
50 articles · Updated July 15, 2026 -
Critical Zero-Day Vulnerability CVE-2026-20182 Exploited in Cisco SD-WAN Systems
Cisco has disclosed a critical authentication bypass vulnerability, CVE-2026-20182, affecting its Catalyst SD-WAN Controller and Manager. This flaw allows unauthenticated remote attackers to bypass authentication and…
131 articles · Updated May 14, 2026 -
Critical Joomla JCE Vulnerability Under Active Exploitation
A critical vulnerability in the Joomla Content Editor (JCE), tracked as CVE-2026-48907, allows unauthenticated attackers to execute remote code on affected Joomla sites. This flaw affects JCE versions below 2.9.99.6 and…
33 articles · Updated June 17, 2026 -
Critical WebLogic RCE Vulnerability Exploited in the Wild
Hackers are actively exploiting a critical Remote Code Execution (RCE) vulnerability in Oracle WebLogic Server, tracked as CVE-2026-21962, which has a maximum CVSS score of 10.0. This unauthenticated flaw allows…
2 articles · Updated April 1, 2026 -
Critical Exploitation of Cisco CM and Samsung KNOX Vulnerabilities
Active exploitation of two critical vulnerabilities has been reported: CVE-2026-20230 in Cisco Unified CM and CVE-2026-20971 in Samsung KNOX. The Cisco flaw, a server-side request forgery (SSRF), poses an immediate…
4 articles · Updated June 23, 2026 -
Critical Unauthenticated RCE Vulnerability in LiteLLM Exploited in the Wild
A critical command injection vulnerability, CVE-2026-42271, in LiteLLM, an open-source AI gateway, allows unauthenticated remote code execution (RCE) when chained with CVE-2026-48710, a Host header validation bypass in…
17 articles · Updated June 9, 2026 -
Critical OpenSSL Vulnerability CVE-2025-15467 Patched
OpenSSL has patched a high-severity stack buffer overflow vulnerability, tracked as CVE-2025-15467. This flaw allows unauthenticated attackers to trigger denial-of-service conditions and potentially execute remote code…
5 articles · Updated January 29, 2026 -
Critical Command Injection Vulnerability in Arista VeloCloud Orchestrator Under Active Exploitation
A critical command injection vulnerability, CVE-2026-16812, has been discovered in the Arista VeloCloud Orchestrator On-Prem platform, allowing unauthenticated remote attackers to execute arbitrary commands. This flaw,…
23 articles · Updated July 28, 2026 -
Critical SQL Injection Vulnerability in NocoBase (CVE-2026-52887)
CVE-2026-52887 is a critical SQL injection vulnerability affecting NocoBase, an AI-powered no-code/low-code platform. The flaw allows unauthenticated remote attackers to execute arbitrary SQL queries via the…
2 articles · Updated July 16, 2026
Recent Intelligence Reports
- Chinese Speaking Operator Philippine Nuclear Naval Contractor — hunt.io · August 31, 2026
- July 30 blog post — www.anthropic.com · August 31, 2026
- Plataforma IoT en Rust expone gestión completa de usuarios sin autenticación — Ciberseguridadlatam · August 31, 2026
- PSIRT WatchGuard CVE-2026-19315 — psirt.watchguard.com · August 29, 2026
- Philippine Nuclear and Naval Targets Hit by Suspected Chinese Operator — Securityaffairs.Co · August 29, 2026
- Critical vulnerability in GiveWP plugin allows remote code execution | brief — Scmagazine · August 28, 2026
- Critical vulnerability in GiveWP plugin allows remote code execution | brief — Scworld · August 28, 2026
- Critical Pre-Authentication RCE Flaws Expose WatchGuard Fireware VPNs Mallory Threat Intelligence Stories / 13h WatchGuard released fixes for five **critical** vulnerabilities in Fireware OS and WatchGuard Dimension, all rated CVSS v4 9.3. Three flaws in the internet-exposed `iked` IKE/VPN daemon—including the pre-authentication stack buffer overflow tracked as `CVE-2026-19318`—could allow unauthenticated attackers to execute code by sending crafted VPN traffic, creating a direct perimeter-compr — mallory.ai · August 28, 2026