Related Threat Clusters
-
CISA Warns of Critical Exploits in Langflow, Tomcat, and N-central Flaws
CISA has added critical vulnerabilities in IBM Langflow, Apache Tomcat, and N-able N-central to its Known Exploited Vulnerabilities catalog, with a deadline for federal agencies to patch by August 7, 2026. The Langflow…
2 articles · Updated August 7, 2026 -
Operation Escaneo Targets Latin American Critical Infrastructure
Operation Escaneo is a coordinated cyberattack attributed to the MexicanMafia group, targeting critical infrastructure across Latin America, primarily Mexico. The campaign, which spanned from 2025 to 2026, utilized…
4 articles · Updated June 18, 2026 -
Spring Framework RCE Vulnerability CVE-2022-22965 Exploited in the Wild
On March 30, 2022, a zero-day remote code execution vulnerability in the Spring Framework, dubbed 'Spring4Shell' and assigned CVE-2022-22965, was disclosed. This vulnerability affects Spring MVC and Spring WebFlux…
3 articles · Updated June 17, 2026 -
Ivanti Sentry Vulnerabilities Allow Remote Code Execution and Admin Access
Ivanti has patched two critical vulnerabilities in its Sentry secure mobile gateway, formerly MobileIron Sentry. The first, CVE-2026-10520, is an OS command injection flaw allowing remote code execution with root…
38 articles · Updated June 10, 2026 -
SAP Addresses Critical Vulnerabilities in July 2026 Security Updates
SAP has released security updates addressing 16 vulnerabilities, including three critical flaws in its NetWeaver, Commerce Cloud, and AppRouter products. The most severe, CVE-2026-44747, allows authenticated attackers…
11 articles · Updated July 14, 2026 -
Broadcom Enhances Spring and Java Security Amid AI Threat Surge
On June 8, 2026, Broadcom announced significant investments in security for the Spring and Java ecosystems, which are critical to over half of Fortune 500 companies. This move comes in response to a staggering 1700%…
9 articles · Updated June 8, 2026 -
Critical SAP Vulnerabilities Require Immediate Patching
SAP has released security updates addressing 15 vulnerabilities, including four critical ones affecting SAP NetWeaver and SAP Commerce Cloud. The vulnerabilities include CVE-2026-44748, allowing authenticated attackers…
8 articles · Updated June 9, 2026 -
Critical Vulnerabilities in Apache Commons BeanUtils and mod_jk Affect Ubuntu 18.04 LTS
Recent updates for Ubuntu 18.04 LTS revealed critical vulnerabilities in Apache Commons BeanUtils and mod_jk. The first issue, CVE-2014-0114 and CVE-2019-10086, allows attackers to execute arbitrary code due to improper…
7 articles · Updated July 23, 2026 -
Multiple CVEs Affecting Spring Framework Released on April 27, 2026
On April 27, 2026, three critical vulnerabilities were disclosed for the Spring Framework. CVE-2026-40973 allows local attackers to hijack sessions by exploiting predictable temp directory permissions. CVE-2026-40972…
4 articles · Updated April 27, 2026 -
SQL Injection Attack Enables Malware Deployment in Oracle Database
On July 27, 2026, Huntress detected a SQL injection attack on an Oracle database server leading to credential theft. Attackers exploited a vulnerability in a public-facing Java application, allowing them to upload a…
8 articles · Updated August 6, 2026
Recent Intelligence Reports
- Tr Dprk Apts Ted Backdoor Curlrat Target South Korean Media Automotive Sectors — www.rapid7.com · September 4, 2026
- Cve 2026 59270 — spring.io · August 24, 2026
- CVE 2026 34486 — nvd.nist.gov · August 8, 2026
- Security 9 — tomcat.apache.org · August 8, 2026
- Security 10 — tomcat.apache.org · August 8, 2026
- [SecurityIntel] 06 Aug | CISA Warns of Exploited Langflow and Tomcat Flaws — Buttondown · August 7, 2026
- Toolkit Hidden Inside Oracle Database Evades Endpoint Tools — Infosecurity-Magazine · August 6, 2026
- CISA Adds Langflow, Tomcat, N-central Flaws to KEV Catalog — Aiweekly.Co · August 6, 2026