Related Threat Clusters
-
CVE-2026-2441: Zero-Day CSS Vulnerability in Chromium-Based Browsers
CVE-2026-2441 is a zero-day CSS vulnerability affecting all Chromium-based browsers, allowing attackers to exploit a use-after-free condition in the Blink rendering engine. This vulnerability enables the theft of…
3 articles · Updated February 21, 2026 -
Critical Joomla JCE Vulnerability Under Active Exploitation
A critical vulnerability in the Joomla Content Editor (JCE), tracked as CVE-2026-48907, allows unauthenticated attackers to execute remote code on affected Joomla sites. This flaw affects JCE versions below 2.9.99.6 and…
33 articles · Updated June 17, 2026 -
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This…
33 articles · Updated August 12, 2026 -
Critical Flaw in Modular DS WordPress Plugin Enables Admin Takeover
A critical vulnerability in the Modular DS WordPress plugin has been actively exploited since January 13, 2026, allowing attackers to gain administrative access. Security researchers have confirmed that this flaw poses…
2 articles · Updated January 16, 2026 -
Critical SQL Injection Vulnerability in GPTranslate Plugin (CVE-2026-49776)
A critical unauthenticated SQL injection vulnerability (CVE-2026-49776) has been identified in the GPTranslate plugin for WordPress, affecting versions 2.32.6 and earlier. This flaw allows attackers to execute arbitrary…
3 articles · Updated June 16, 2026 -
Critical NGINX Vulnerability CVE-2026-42945 Exposes Millions to RCE and DoS Attacks
A critical vulnerability, CVE-2026-42945, has been discovered in the NGINX web server's ngx_http_rewrite_module, allowing unauthenticated attackers to execute remote code or crash servers. This heap-based buffer…
51 articles · Updated May 13, 2026 -
Critical Vulnerability in Ninja Forms Plugin Exposes 50,000 WordPress Sites to RCE
A critical vulnerability (CVE-2026-0740) in the Ninja Forms File Uploads plugin for WordPress allows unauthenticated attackers to upload arbitrary files, potentially leading to remote code execution. This flaw, with a…
6 articles · Updated April 7, 2026 -
Critical RCE Vulnerability in Blocksy Companion Pro Plugin Discovered
A critical vulnerability, CVE-2026-58480, has been identified in the Blocksy Companion Pro plugin for WordPress versions prior to 2.1.47. This unauthenticated arbitrary file upload vulnerability allows attackers to…
2 articles · Updated July 9, 2026 -
Operation Endgame Disrupts Evil Corp's SocGholish Malware Network
On June 18, 2026, international law enforcement agencies launched Operation Endgame, disrupting the SocGholish malware infrastructure linked to the Russian cybercrime group Evil Corp. The operation resulted in the…
67 articles · Updated June 18, 2026 -
Critical Privilege Escalation Vulnerability in ProfileGrid Plugin for WordPress
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is critically vulnerable to privilege escalation via account takeover, affecting all versions up to and including 5.9.9.5. The vulnerability…
2 articles · Updated June 30, 2026
Recent Intelligence Reports
- SecurityAffairs — securityaffairs.co · August 31, 2026
- 2026 08 07 — docs.vulncheck.com · August 31, 2026
- Chinese Speaking Operator Philippine Nuclear Naval Contractor — hunt.io · August 31, 2026
- Critical Ruby on Rails Vulnerability in Attackers' Crosshairs — Securityweek · August 31, 2026
- Philippine Nuclear and Naval Targets Hit by Suspected Chinese Operator — Securityaffairs.Co · August 29, 2026
- Critical vulnerability in GiveWP plugin allows remote code execution | brief — Scmagazine · August 28, 2026
- Critical vulnerability in GiveWP plugin allows remote code execution | brief — Scworld · August 28, 2026
- GiveWP WordPress donation plugin flaw lets hackers execute server commands — Bleepingcomputer · August 28, 2026