Nuclei is a tool tracked across 17 threat clusters and 22 intelligence report mentions on ThreatCluster. First observed November 17, 2025; most recent activity July 24, 2026.
A critical zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft has been exploited by the ShinyHunters group, leading to breaches of over 100 organizations, primarily in the education sector. The vulnerability…
The China-aligned APT group Webworm has shifted its focus from Asia to Europe, targeting government organizations in Belgium, Italy, Poland, Serbia, and Spain during 2025. ESET researchers identified new backdoors,…
A China-linked cyber espionage operation has compromised a Vietnamese public hospital's imaging systems, infiltrated Malaysia's Ministry of Foreign Affairs, and targeted Honduras's National Congress using a new malware…
A critical vulnerability in Langflow, tracked as CVE-2026-33017, allows unauthenticated remote code execution (RCE) via the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint. This flaw was exploited within 20 hours…
Between March and May 2026, Zenity researchers observed three distinct campaigns where attackers hijacked exposed AI endpoints from Ollama and LiteLLM for offensive operations. The attackers exploited inference…
The RondoDox botnet is exploiting the unpatched XWiki remote code execution vulnerability CVE-2025-24893, which has a CVSS score of 9.8. Despite patches released in February 2025, many servers remain vulnerable,…
A hacker known as 'Trim' has created a commercial offensive AI pentesting platform by jailbreaking Claude Opus models. Trim first posted detailed jailbreak techniques on a Russian-language forum on March 31, 2026, and…
The RondoDox botnet is exploiting the unpatched XWiki remote code execution (RCE) flaw CVE-2025-24893, which has a CVSS score of 9.8. Despite patches released in February 2025, the botnet continues to infect servers,…
Fedora has released security updates addressing critical vulnerabilities in the Nuclei scanner. CVE-2026-5160, published on April 15, 2026, involves cross-site scripting due to improper URL validation, affecting…
A forum thread titled 'Hacking for Profit. Working method' authored by a hacker named 'Hercules' provides a simplified guide for novice hackers on exploiting vulnerabilities. The tutorial outlines methods for scanning,…