Related Threat Clusters
-
Critical Exploitation of Cisco CM and Samsung KNOX Vulnerabilities
Active exploitation of two critical vulnerabilities has been reported: CVE-2026-20230 in Cisco Unified CM and CVE-2026-20971 in Samsung KNOX. The Cisco flaw, a server-side request forgery (SSRF), poses an immediate…
4 articles · Updated June 23, 2026 -
Critical NGINX UI Vulnerability CVE-2026-33032 Under Active Exploitation
A critical vulnerability in the nginx-ui web server management tool, tracked as CVE-2026-33032, has been actively exploited since March 2026. This flaw allows attackers to bypass authentication on the /mcp_message…
22 articles · Updated April 15, 2026 -
Critical Authorization Vulnerability in SiYuan (CVE-2026-66012)
A critical missing authorization vulnerability (CVE-2026-66012) has been identified in SiYuan versions prior to 3.7.2, allowing remote unauthenticated attackers to bypass authentication on the POST /mcp kernel endpoint.…
2 articles · Updated July 26, 2026 -
Critical RCE Vulnerability in Marimo Exploited Within 10 Hours of Disclosure
A critical pre-authentication remote code execution (RCE) vulnerability in Marimo, an open-source Python notebook platform, was disclosed on April 8, 2026, and exploited within 9 hours and 41 minutes. The vulnerability,…
16 articles · Updated April 12, 2026 -
Harvester APT Group Unveils New GoGra Linux Backdoor Using Microsoft Graph API
The Harvester APT group has launched a Linux variant of its GoGra backdoor, utilizing the Microsoft Graph API and Outlook mailboxes for covert command-and-control operations. This malware is designed to evade…
13 articles · Updated April 22, 2026 -
Critical CVE-2026-0768 Exploited in Langflow Attacks
Hackers are actively exploiting a critical vulnerability in Langflow, tracked as CVE-2026-0768, which allows unauthenticated remote code execution. The flaw affects all versions up to 1.4.2 of the AI-focused low-code…
4 articles · Updated September 2, 2026 -
HOLLOWGRAPH Malware Exploits Microsoft 365 Calendars for Espionage
Group-IB has identified HOLLOWGRAPH, a sophisticated Windows malware that abuses the Microsoft Graph API to covertly exfiltrate files and receive commands through compromised Microsoft 365 calendar events. The malware…
10 articles · Updated July 20, 2026 -
Jscrambler npm Package Compromised in Supply Chain Attack
On July 11, 2026, multiple malicious versions of the jscrambler npm package were published, exploiting a compromised npm publishing credential. The affected versions (8.14.0, 8.16.0, 8.17.0, 8.18.0, and 8.20.0) included…
18 articles · Updated July 12, 2026 -
TeamPCP Compromises Microsoft DurableTask and GitHub Actions in Supply Chain Attack
The TeamPCP threat group has expanded its supply chain attack campaign, compromising the Microsoft DurableTask Python client with versions v1.4.1, v1.4.2, and v1.4.3 found to contain a credential-stealing worm. This…
11 articles · Updated May 20, 2026 -
Critical Langflow RCE Vulnerability Exploited Within 20 Hours
A critical vulnerability in Langflow, tracked as CVE-2026-33017, allows unauthenticated remote code execution (RCE) via the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint. This flaw was exploited within 20 hours…
17 articles · Updated March 20, 2026
Recent Intelligence Reports
- Ai Coding Agents Git Hijack — www.manifold.security · September 4, 2026
- Hacker uses AI agents for entire attack chain, mocks victim with detailed security audit — Cybernews · September 3, 2026
- Agentic Ransomware Took Down Enterprise in Ten Hours: AI Left 80 — Techtimes · September 3, 2026
- AI agents help compress ransomware intrusion to under 10 hours, raising stakes for CISOs — Csoonline · September 3, 2026
- An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation | Wendi Whitmore — Linkedin · September 2, 2026
- Langflow Remote Code Execution Vulnerability Exploited in Attacks (CVE-2026-0768) — Threatprotect.Qualys · September 2, 2026
- Lunar Cyber Launches Token Exposure Monitoring as Infostealers Target Developer and AI ... — Cybersecurity-Insiders · August 31, 2026
- Lunar Cyber Launches Token Exposure Monitoring as Infostealers Target Developer and AI ... — Devops · August 31, 2026