Ghidra is a tool tracked across 6 threat clusters and 7 intelligence report mentions on ThreatCluster. First observed May 7, 2026; most recent activity July 3, 2026.
A critical vulnerability in the nginx-ui web server management tool, tracked as CVE-2026-33032, has been actively exploited since March 2026. This flaw allows attackers to bypass authentication on the /mcp_message…
An anonymous researcher known as Bikini has released exploit code for over a dozen zero-day vulnerabilities affecting 15 popular open-source projects, including the Linux kernel and Libssh2. The exploits were disclosed…
A new banking trojan named TCLBANKER has emerged, targeting 59 Brazilian banking, fintech, and cryptocurrency platforms. Discovered by Elastic Security Labs, the malware utilizes a trojanized MSI installer of Logitech's…
CVE-2024-47575, known as FortiJump, has been actively exploited since June 2024, affecting over 50 FortiManager devices across various industries. The vulnerability allows unauthorized control of FortiManager…
Anthropic's research reveals that its model, Mythos Preview, can autonomously develop exploits for N-day vulnerabilities within hours, significantly reducing the time historically needed for exploit development. N-days…
Hackers are impersonating well-known security tools like Ghidra, dnSpy, and SpiderFoot to distribute malware through convincing fake download sites. These sites mimic legitimate project portals, complete with…