Microsoft IIS is a technology platform tracked across 4 threat clusters and 7 intelligence report mentions on ThreatCluster. First observed December 16, 2025; most recent activity June 3, 2026.
PTC Inc. has disclosed a critical vulnerability, CVE-2026-4681, in its Windchill and FlexPLM software that allows for remote code execution through the deserialization of trusted data. The vulnerability has been…
The HTTP/2 Bomb is a newly discovered denial-of-service (DoS) attack that targets default configurations of major web servers, including NGINX, Apache, Microsoft IIS, Envoy, and Cloudflare Pingora. This attack,…
Construction companies are facing active attacks that exploit a critical SQL injection vulnerability in the Mjobtime application, a widely used labor time-tracking tool. The attacks utilize MSSQL and IIS POST request…
The Ink Dragon Group, linked to China, has infiltrated European government networks by exploiting misconfigured servers to establish relay nodes for cyber-espionage. Check Point reports that this campaign has affected…