Related Threat Clusters
-
AWS Strands Agents Tools Exposed to Multiple CVEs in 23 Days
Between July 15 and August 6, 2026, AWS Strands Agents Tools received four CVEs due to a design flaw exposing security-sensitive parameters as LLM-controllable inputs. The vulnerabilities include CVE-2026-15746…
2 articles · Updated August 22, 2026 -
Mass Exploitation of Gravity SMTP Plugin Vulnerability CVE-2026-4020
CVE-2026-4020 is an information disclosure vulnerability in the Gravity SMTP WordPress plugin, published on March 31, 2026. The flaw allows unauthenticated visitors to access sensitive system reports, including SMTP…
15 articles · Updated June 17, 2026 -
Critical Vulnerabilities in Spring Boot's SSL Configuration for Elasticsearch and RabbitMQ
Two critical vulnerabilities have been identified in Spring Boot's auto-configuration for Elasticsearch and RabbitMQ. CVE-2026-40970 affects Elasticsearch, while CVE-2026-40971 impacts RabbitMQ. Both vulnerabilities…
2 articles · Updated April 27, 2026 -
Massive Data Leak Exposes 24 Billion Credentials: Urgent Security Risks Identified
Cybernews researchers uncovered an exposed Elasticsearch database containing 24 billion records, including usernames, email addresses, and plaintext passwords. The data is primarily sourced from infostealer malware logs…
12 articles · Updated June 17, 2026 -
Massive Data Leak Allegedly Affects 223 Million Brazilians
A hacker claims to have stolen 1.8 terabytes of sensitive data from Serasa Experian, affecting 223 million individuals, which exceeds Brazil's population of approximately 213.5 million. The leaked data includes CPF…
2 articles · Updated April 11, 2026 -
Threat Actor Exploits Vulnerabilities to Abuse Elastic Cloud SIEM for Data Theft
Cybersecurity researchers from Huntress have uncovered a campaign where a threat actor exploited multiple software vulnerabilities, including the SolarWinds Web Help Desk, to exfiltrate data to a free trial instance of…
2 articles · Updated March 9, 2026 -
Vulnerabilities in Fluent Bit Disrupt Major Cloud Services
A series of vulnerabilities in Fluent Bit, an open source log collection tool, were discovered by Oligo Security. These 'trivial-to-exploit' bugs, which allow attackers to bypass authentication and execute remote code,…
4 articles · Updated November 24, 2025 -
Intellexa's Spyware Access and Evasion of Sanctions Revealed
Intellexa, a spyware maker known for its Predator software, has been found to have remote access to the surveillance systems of its government clients, allowing staff to view personal data of hacked individuals. Despite…
11 articles · Updated December 4, 2025 -
Critical Vulnerabilities Found in Fluent Bit Logging Tool
Fluent Bit, a widely used log-processing tool, has been found vulnerable to multiple critical security flaws that could allow attackers to bypass authentication, execute remote code, and disrupt cloud services.…
6 articles · Updated November 25, 2025 -
CyberSentinel AI Launches Open-Source Cybersecurity Platform with 33 Tools
CyberSentinel AI has released version 3.0 of its open-source cybersecurity platform, integrating 33 penetration testing and threat intelligence tools. The platform features a provider-agnostic AI engine that supports…
2 articles · Updated June 20, 2026
Recent Intelligence Reports
- AWS Strands Agents Tools Received Four CVEs in 23 Days — Cryptorank · August 22, 2026
- AWS Strands Agents Tools Received Four CVEs in 23 Days — And They All Share the Same Root Cause — Forkast.News · August 22, 2026
- CyberSentinel AI launches autonomous cybersecurity platform | Let's Data Science — Letsdatascience · June 20, 2026
- 24 Billion Records Exposed: The Credential Leak That Changes Everything — Philiphall · June 17, 2026
- Most of the CVE-2026 — News.Ycombinator · June 17, 2026
- 24B records exposed in colossal data leak: What does that mean for you? — Cybernews · June 17, 2026
- CVE-2026-40970: Elasticsearch auto-configuration with an SSL bundle disables TLS hostname verification — spring.io · April 27, 2026
- Brazil Experian data leak claim raises questions over 223 million records — Cybernews · April 9, 2026