Related Threat Clusters
-
SonicWall Patches Actively Exploited Zero-Day Vulnerability CVE-2025-40602
SonicWall has released a patch for the actively exploited zero-day vulnerability CVE-2025-40602, which affects the Appliance Management Console (AMC) of their devices. This vulnerability allows for deserialization of…
4 articles · Updated December 17, 2025 -
F5 Issues Critical Patches for NGINX Vulnerabilities Allowing Remote Code Execution
On June 17, 2026, F5 released emergency patches for two critical vulnerabilities in NGINX, CVE-2026-42530 and CVE-2026-42055. These vulnerabilities affect NGINX Open Source, NGINX Plus, and related products, allowing…
24 articles · Updated June 18, 2026 -
Critical NGINX Vulnerability CVE-2026-42945 Exposes Millions to RCE and DoS Attacks
A critical vulnerability, CVE-2026-42945, has been discovered in the NGINX web server's ngx_http_rewrite_module, allowing unauthenticated attackers to execute remote code or crash servers. This heap-based buffer…
51 articles · Updated May 13, 2026 -
TeamPCP's CanisterWorm Targets Iranian Systems with Destructive Kubernetes Wiper
TeamPCP has launched a new cyber campaign deploying a destructive payload that targets Kubernetes clusters configured for Iran. This wiper malware, part of the ongoing CanisterWorm campaign, uses the same…
4 articles · Updated March 23, 2026 -
Red Menshen APT Uses BPFdoor for Long-Term Espionage in Telecom Networks
A China-linked threat actor known as Red Menshen has been conducting a long-term espionage campaign targeting global telecommunications networks using a stealthy Linux kernel backdoor called BPFdoor. This malware…
16 articles · Updated March 26, 2026 -
Exploitation of Remote Services in Cyber Attacks
Adversaries are increasingly leveraging external remote services like VPNs and Citrix to gain unauthorized access to networks. These attacks often involve using valid accounts obtained through credential harvesting or…
2 articles · Updated June 3, 2026 -
TeamPCP Compromises Microsoft DurableTask and GitHub Actions in Supply Chain Attack
The TeamPCP threat group has expanded its supply chain attack campaign, compromising the Microsoft DurableTask Python client with versions v1.4.1, v1.4.2, and v1.4.3 found to contain a credential-stealing worm. This…
11 articles · Updated May 20, 2026 -
Docker Patches Critical AuthZ Bypass Vulnerability CVE-2026-34040
Docker has addressed a critical vulnerability, tracked as CVE-2026-34040, that allows attackers to bypass authorization checks and create containers with excessive privileges. The flaw arises from middleware issues in…
4 articles · Updated April 8, 2026 -
LiteLLM Supply Chain Attack Exposes Critical Credentials
On March 24, 2026, two versions of the LiteLLM Python package (1.82.7 and 1.82.8) were compromised on PyPI, embedding credential-stealing payloads. The attack, linked to the TeamPCP threat actor, exploited a…
3 articles · Updated June 12, 2026 -
CISA Warns of Active Exploitation of Oracle WebLogic Vulnerability CVE-2024-21182
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding the active exploitation of a two-year-old vulnerability in Oracle WebLogic Server, tracked as CVE-2024-21182. This flaw,…
17 articles · Updated June 2, 2026
Recent Intelligence Reports
- Agentic Zero Trust: VMware vDefend & Avi Innovations for AI — Broadcom · August 31, 2026
- Broadcom Delivers End-to-End Security, Identity, and Observability for Agentic AI — Markets.Businessinsider · August 31, 2026
- Broadcom Delivers End-to-End Security, Identity, and Observability for Agentic AI — Stocktitan · August 31, 2026
- Neocloud Security Deep Dive Report: Alarming Infrastructure Configuration Errors, Cross ... — Weex · August 31, 2026
- The Hugging Face Breach: Key Questions Every Security Leader Must Answer — Zscaler · August 31, 2026
- The Rise of AI Civilization: OpenAI Agents Build Self-Evolved "Three — Eu.36Kr · August 31, 2026
- 1200 OpenAI agents colluded to cheat evaluations in lead — Insight.Scmagazineuk · August 31, 2026
- SemiAnalysis releases Neocloud security deep report — Chaincatcher · August 30, 2026