Related Threat Clusters
-
Critical RCE Vulnerability in n8n Affects Over 100K Servers
A critical remote code execution vulnerability (CVE-2025-68613) in the n8n workflow automation platform has been disclosed, potentially impacting over 100,000 servers, primarily in the United States. The flaw, which has…
4 articles · Updated December 24, 2025 -
Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign
Since July 2025, Russian state-backed hackers, known as Laundry Bear, have exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite to infiltrate Western government and commercial…
82 articles · Updated July 23, 2026 -
Critical RCE Vulnerability in Rails Active Storage Disclosed
On July 29, 2026, the Ruby on Rails security team published CVE-2026-66066, a critical arbitrary file read and remote code execution (RCE) vulnerability in Active Storage. Discovered by the Ethiack research team, this…
16 articles · Updated July 30, 2026 -
Critical NGINX UI Vulnerability CVE-2026-33032 Under Active Exploitation
A critical vulnerability in the nginx-ui web server management tool, tracked as CVE-2026-33032, has been actively exploited since March 2026. This flaw allows attackers to bypass authentication on the /mcp_message…
22 articles · Updated April 15, 2026 -
Malware Spread via Fake Polymarket Trading Bot Targets DeFi Developers
On July 1, 2026, security firm SlowMist identified a fake trading bot on GitHub designed to spread malware targeting Polymarket users and DeFi developers. The bot, named 'polymarket-arbitrage-bot', was promoted as a…
2 articles · Updated July 1, 2026 -
Critical Authorization Vulnerability in SiYuan (CVE-2026-66012)
A critical missing authorization vulnerability (CVE-2026-66012) has been identified in SiYuan versions prior to 3.7.2, allowing remote unauthenticated attackers to bypass authentication on the POST /mcp kernel endpoint.…
2 articles · Updated July 26, 2026 -
TeamPCP's CanisterWorm Targets Iranian Systems with Destructive Kubernetes Wiper
TeamPCP has launched a new cyber campaign deploying a destructive payload that targets Kubernetes clusters configured for Iran. This wiper malware, part of the ongoing CanisterWorm campaign, uses the same…
4 articles · Updated March 23, 2026 -
Critical Remote Code Execution Flaw Discovered in Flowise MCP Server
Flowise has disclosed a critical remote code execution vulnerability, tracked as CVE-2026-56274, affecting versions prior to 3.1.2 of its Custom MCP Server feature. The flaw allows attackers to exploit multiple OS…
2 articles · Updated June 23, 2026 -
Fedora Skopeo Security Fix for CVE-2025-58189 and CVE-2025-61725
Fedora has released security updates for the Skopeo command line utility addressing critical vulnerabilities CVE-2025-58189 and CVE-2025-61725. The updates were made available for Fedora 42 and Fedora 43, with the…
2 articles · Updated November 13, 2025 -
Exploitation of Remote Services in Cyber Attacks
Adversaries are increasingly leveraging external remote services like VPNs and Citrix to gain unauthorized access to networks. These attacks often involve using valid accounts obtained through credential harvesting or…
2 articles · Updated June 3, 2026
Recent Intelligence Reports
- 2026 08 07 — docs.vulncheck.com · August 31, 2026
- Neocloud Security Deep Dive Report: Alarming Infrastructure Configuration Errors, Cross ... — Weex · August 31, 2026
- SemiAnalysis releases Neocloud security deep report — Chaincatcher · August 30, 2026
- SemiAnalysis Discovers Critical Security Vulnerabilities in Neocloud Infrastructure — Kucoin · August 30, 2026
- Cloud Security — securis360.com · August 26, 2026
- Critical Unpatched Vulnerabilities in Kaltura mwEmbed Expose Organizations to Remote ... — Rescana · August 26, 2026
- Research published August 25 by Cyera — www.cyera.com · August 26, 2026
- Truffle Security says — trufflesecurity.com · August 21, 2026