Related Threat Clusters
-
Critical RCE Vulnerabilities in Joomla Extensions CVE-2026-48907 & CVE-2026-48908
Two critical vulnerabilities affecting Joomla extensions have been reported: CVE-2026-48907 in the Joomla Content Editor (JCE) and CVE-2026-48908 in the SP Page Builder. Both vulnerabilities allow unauthenticated remote…
2 articles · Updated August 4, 2026 -
Critical Joomla JCE Vulnerability Under Active Exploitation
A critical vulnerability in the Joomla Content Editor (JCE), tracked as CVE-2026-48907, allows unauthenticated attackers to execute remote code on affected Joomla sites. This flaw affects JCE versions below 2.9.99.6 and…
33 articles · Updated June 17, 2026 -
Critical NGINX Vulnerability CVE-2026-42945 Exposes Millions to RCE and DoS Attacks
A critical vulnerability, CVE-2026-42945, has been discovered in the NGINX web server's ngx_http_rewrite_module, allowing unauthenticated attackers to execute remote code or crash servers. This heap-based buffer…
51 articles · Updated May 13, 2026 -
Critical RCE Vulnerability in Blocksy Companion Pro Plugin Discovered
A critical vulnerability, CVE-2026-58480, has been identified in the Blocksy Companion Pro plugin for WordPress versions prior to 2.1.47. This unauthenticated arbitrary file upload vulnerability allows attackers to…
2 articles · Updated July 9, 2026 -
Operation Endgame Disrupts Evil Corp's SocGholish Malware Network
On June 18, 2026, international law enforcement agencies launched Operation Endgame, disrupting the SocGholish malware infrastructure linked to the Russian cybercrime group Evil Corp. The operation resulted in the…
67 articles · Updated June 18, 2026 -
Belarusian Hackers Target Yury Hubarevich with Sophisticated Phishing Attack
On May 29, 2026, Yury Hubarevich, a prominent Belarusian politician, was targeted in a phishing attack linked to the Belarusian espionage group UNC1151. The attack involved an email disguised as a Google notification,…
11 articles · Updated June 5, 2026 -
Advanced PHP Web Shell Exploits F5 BIG-IP Systems
A sophisticated Linux implant targeting F5 BIG-IP Access Policy Management (APM) environments has been identified, exploiting CVE-2025-53521, an unauthenticated remote code execution vulnerability. This malware,…
11 articles · Updated September 7, 2026 -
Multiple Critical CVEs Exploited in Cybersecurity Attacks
A series of vulnerabilities, including CVE-2025-49144, CVE-2025-31702, and CVE-2026-46333, have been identified, affecting systems like Notepad++ and FortiWeb devices. These vulnerabilities allow for local privilege…
30 articles · Updated September 7, 2026 -
Critical XSS and Memory Vulnerabilities in Oracle PHP Releases
Oracle has released important security updates for PHP versions 7.4 and 8.0, addressing multiple vulnerabilities including critical cross-site scripting (XSS) flaws and memory management issues. The updates fix…
2 articles · Updated July 6, 2026 -
July 2026 Security Update: Record CVEs and Critical Vulnerabilities
In July 2026, Adobe and Microsoft released significant security updates addressing numerous vulnerabilities. Adobe issued 12 bulletins for 88 unique CVEs, with a focus on ColdFusion and Commerce patches, including a…
3 articles · Updated July 14, 2026
Recent Intelligence Reports
- CVE-2026-86732 - OSV — Osv.Dev · September 9, 2026
- Microsoft patches record 974 CVEs; AI agents steal thousands of credentials; F5 devices breached — Defendwork · September 9, 2026
- CVE Alert: CVE-2026-86727 – WWBN — Redpacketsecurity · September 9, 2026
- GHSA 5664 H9h4 3gwc — github.com · September 9, 2026
- Wwbn Avideo Cross Site Request Forgery Via Deletehistory Json Php — www.vulncheck.com · September 9, 2026
- CVE-2020 — Sploitus · September 8, 2026
- Important Security Update on PHP Denial of Service for Ubuntu 16.04 LTS — Linuxsecurity · September 8, 2026
- CVE Alert: CVE-2026-86435 – thephpleague — Redpacketsecurity · September 8, 2026