Related Threat Clusters
-
Critical Appsmith Vulnerability Enables Account Takeovers
A critical authentication vulnerability in the Appsmith low-code platform, tracked as CVE-2026-22794, has been exploited to facilitate user account takeovers. The flaw allows attackers to manipulate password reset links…
2 articles · Updated January 26, 2026 -
FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation
A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
100 articles · Updated November 15, 2025 -
Critical NGINX UI Vulnerability CVE-2026-33032 Under Active Exploitation
A critical vulnerability in the nginx-ui web server management tool, tracked as CVE-2026-33032, has been actively exploited since March 2026. This flaw allows attackers to bypass authentication on the /mcp_message…
22 articles · Updated April 15, 2026 -
Russian FSB Exploits Vulnerable Routers to Target Critical Infrastructure
A joint advisory from 21 global cybersecurity agencies warns that Russian state hackers from the FSB's Center 16 are exploiting poorly configured routers to infiltrate critical infrastructure networks worldwide. The…
76 articles · Updated July 13, 2026 -
AI-Generated Exploits Target Siemens PLCs in Critical Infrastructure
On August 19, 2026, U.S. agencies issued a joint advisory confirming that threat actors are using AI-generated exploitation scripts to target Siemens S7 Series PLCs across critical infrastructure sectors, including…
37 articles · Updated August 19, 2026 -
FortiBleed Campaign Compromises 75,000+ Fortinet Devices Globally
A credential-harvesting campaign known as 'FortiBleed' has compromised over 75,000 Fortinet firewalls and VPNs across 194 countries. The attackers, suspected to be Russian-speaking cybercriminals, exploited previously…
105 articles · Updated June 17, 2026 -
CameraSwarm Operation Compromises Over 14,500 Dahua IP Cameras
Between June 17 and July 22, 2026, hackers compromised over 14,500 Dahua IP cameras, primarily in Ukraine and Russia, in a campaign dubbed CameraSwarm. The attackers exploited vulnerabilities, brute-forced logins, and…
7 articles · Updated August 19, 2026 -
Critical MOVEit Vulnerabilities Expose Organizations to Data Breaches
Progress Software has issued urgent advisories regarding critical vulnerabilities in its MOVEit Automation platform, specifically CVE-2026-4670 and CVE-2026-5174. These vulnerabilities allow attackers to bypass…
11 articles · Updated May 4, 2026 -
Over 24,000 Servers Expose Password Hashes via BMC Vulnerability
A significant vulnerability in Baseboard Management Controllers (BMCs) has been identified, exposing over 24,000 servers to the internet. This exposure is due to CVE-2013-4786, a flaw in the IPMI 2.0 authentication…
13 articles · Updated July 28, 2026 -
Critical wp2shell Vulnerability Enables Unauthenticated RCE in WordPress
A critical vulnerability chain, dubbed wp2shell, has been identified in WordPress Core, allowing unauthenticated attackers to execute arbitrary code on default installations. This vulnerability is tracked as…
78 articles · Updated July 20, 2026
Recent Intelligence Reports
- ICBC Financial Services — www.resecurity.com · August 20, 2026
- 005 — attack.mitre.org · August 20, 2026
- Hunt.io recovered — hunt.io · August 19, 2026
- Escape DAST — escape.tech · August 12, 2026
- Bmc Exposure Alert — lavahq.io · July 29, 2026
- Federal Agencies Warn of Ongoing PLC Exploitation Against Critical U.S. Infrastructure — Trendmicro · July 24, 2026
- wp2shell: WordPress RCE (CVE-2026-63030) — Secra.Es · July 20, 2026
- NadMesh Uses Shodan to Find and Hijack Exposed AI and MCP Infrastructure — Cybersecuritynews · July 19, 2026