Related Threat Clusters
-
Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign
Since July 2025, Russian state-backed hackers, known as Laundry Bear, have exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite to infiltrate Western government and commercial…
82 articles · Updated July 23, 2026 -
APT28 Exploits Roundcube Vulnerabilities in Targeted Cyber Espionage Campaign
APT28 (Fancy Bear) has been linked to Operation Roundish, utilizing a comprehensive Roundcube exploitation toolkit against Ukrainian government targets. The toolkit, discovered in January 2026, includes XSS payloads, a…
3 articles · Updated July 23, 2026 -
ComfyUI Servers Compromised for Cryptomining and Botnet Operations
A significant wave of cyberattacks has targeted ComfyUI servers, converting them into a botnet for cryptomining and proxy operations. Researchers from Censys reported that since March 12, 2026, over 1,000 publicly…
3 articles · Updated April 8, 2026 -
Critical Vulnerabilities in pgAdmin 4 Expose Databases to Remote Code Execution
pgAdmin 4 version 9.16 was released to patch seven vulnerabilities, including critical issues tracked as CVE-2026-12044 to CVE-2026-12050. These vulnerabilities could allow attackers to execute arbitrary commands, gain…
9 articles · Updated June 22, 2026 -
PraisonAI Vulnerability Exploited Hours After Disclosure
A critical authentication bypass vulnerability in PraisonAI, tracked as CVE-2026-44338, was publicly disclosed on May 8, 2026, and has already been exploited by threat actors within hours of its announcement. The flaw…
4 articles · Updated May 15, 2026 -
Credential Stuffing Botnet Exposed with Full Access to Attack Infrastructure
A credential stuffing botnet targeting Twitter/X accounts has been discovered fully exposed online, allowing unrestricted access to its command-and-control infrastructure. The botnet, named 'Twitter Checker Master Panel…
2 articles · Updated April 14, 2026 -
Flask Vulnerability Exposes Sensitive Information in Ubuntu Releases
A security vulnerability identified as CVE-2026-27205 affects Flask, a micro web framework used in Ubuntu 24.04 LTS, 22.04 LTS, and 20.04 LTS. Discovered by Shourya Jaiswal, the issue arises from Flask's failure to mark…
2 articles · Updated March 18, 2026 -
Google Launches CodeMender to Automate Code Vulnerability Remediation
On July 21, 2026, Google announced the preview release of CodeMender, a managed AI security agent designed to identify and remediate software vulnerabilities. Integrated into the Gemini Enterprise Agent Platform and AI…
8 articles · Updated July 21, 2026
Recent Intelligence Reports
- Operation Roundish — hunt.io · July 24, 2026
- Google Makes CodeMender Available as Managed AI Security Agent — Infosecurity-Magazine · July 22, 2026
- CVE 2026 12046 — nvd.nist.gov · June 23, 2026
- PraisonAI vulnerability gets scanned within 4 hours of disclosure — Csoonline · May 14, 2026
- Botnet Exposed: Hackers Leave Worker Access and Root Passwords Wide Open — Gbhackers · April 14, 2026
- ComfyUI instances hijacked for cryptomining and proxy botnet | brief — Scworld · April 8, 2026
- ComfyUI servers: Attackers turn instances into a cryptominer proxy botnet — Heise.De · April 8, 2026
- USN-8104-1: Flask vulnerability — Ubuntu · March 18, 2026