Related Threat Clusters
-
CVE-2026-2441: Zero-Day CSS Vulnerability in Chromium-Based Browsers
CVE-2026-2441 is a zero-day CSS vulnerability affecting all Chromium-based browsers, allowing attackers to exploit a use-after-free condition in the Blink rendering engine. This vulnerability enables the theft of…
3 articles · Updated February 21, 2026 -
Critical Stored XSS Vulnerability in SiYuan Enables Remote Code Execution
SiYuan, an open-source personal knowledge management system, has disclosed a critical stored cross-site scripting (XSS) vulnerability that can escalate to remote code execution (RCE) in its Electron desktop client. The…
7 articles · Updated June 25, 2026 -
Critical Authorization Vulnerability in SiYuan (CVE-2026-66012)
A critical missing authorization vulnerability (CVE-2026-66012) has been identified in SiYuan versions prior to 3.7.2, allowing remote unauthenticated attackers to bypass authentication on the POST /mcp kernel endpoint.…
2 articles · Updated July 26, 2026 -
Ghost CMS SQL Injection Exploits 700+ Sites in Ongoing ClickFix Campaign
A critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS is being actively exploited in a large-scale cyberattack affecting over 700 websites, including those of Harvard University, Oxford University, Auburn…
17 articles · Updated May 25, 2026 -
Lazarus Group Escalates Attacks with Fileless RemotePE Trojan Targeting Crypto and Banks
The Lazarus Group, a North Korea-linked cybercrime organization, has intensified its operations against financial and cryptocurrency sectors using a sophisticated fileless Remote Access Trojan (RAT) called RemotePE.…
12 articles · Updated May 25, 2026 -
QuickFox VPN Supply Chain Attack Delivers FDMTP Backdoor to Windows Users
A supply chain attack targeting the QuickFox VPN application has been uncovered, affecting Windows users. The attack, attributed to the Chinese state-sponsored group Mustang Panda, involved a trojanized version of the…
14 articles · Updated August 6, 2026 -
Jscrambler npm Package Compromised in Supply Chain Attack
On July 11, 2026, multiple malicious versions of the jscrambler npm package were published, exploiting a compromised npm publishing credential. The affected versions (8.14.0, 8.16.0, 8.17.0, 8.18.0, and 8.20.0) included…
18 articles · Updated July 12, 2026 -
Critical RCE Vulnerability in SiYuan Bazaar Exposes Users to Malicious Packages
SiYuan disclosed CVE-2026-56395, a critical remote code execution vulnerability affecting versions before 3.6.1. The flaw arises from improper sanitization of Bazaar marketplace package metadata, allowing malicious…
5 articles · Updated June 22, 2026 -
Critical Zoom Vulnerabilities Enable Remote Code Execution via AI-Driven Exploits
A critical zero-click vulnerability in Zoom's annotation feature, dubbed 'Zoomsday,' allows attackers to remotely execute code on participants' devices during meetings without user interaction. Discovered by A Security…
46 articles · Updated August 11, 2026 -
PhantomEnigma Campaign Hijacks Brazilian Gov Websites for Malware Delivery
The PhantomEnigma malware campaign has compromised over 20 Brazilian government websites, using them to deliver malware targeting banking and public-sector organizations. Attackers exploited legitimate government email…
2 articles · Updated July 22, 2026
Recent Intelligence Reports
- Four REVSTEALER — Thehackernews · September 6, 2026
- RevStealer malware spread through fake Claude Opus 5 download | news — Scworld · September 1, 2026
- RevStealer Is Built to Be Silent — Morphisec · August 31, 2026
- Hackers abuse FTP server banners to deliver new Windows malware — Bleepingcomputer · August 21, 2026
- Hackers abuse FTP server banners to deliver new Windows malware — Bleepingcomputer · August 21, 2026
- Projextor Shows How Malware Can Hide Behind Trusted Electron Executables — Cybersecuritynews · August 18, 2026
- Projextor Abuses Cross — Gbhackers · August 18, 2026
- Projextor: Abusing Electron in Trojanized Productivity Applications — Feeds.Feedburner · August 17, 2026