Related Threat Clusters
-
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This…
33 articles · Updated August 12, 2026 -
FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation
A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
100 articles · Updated November 15, 2025 -
July 2026 Security Update: Record CVEs and Critical Vulnerabilities
In July 2026, Adobe and Microsoft released significant security updates addressing numerous vulnerabilities. Adobe issued 12 bulletins for 88 unique CVEs, with a focus on ColdFusion and Commerce patches, including a…
3 articles · Updated July 14, 2026 -
Amazon Q Developer Vulnerability Enables Cloud Credential Theft
A high-severity vulnerability (CVE-2026-12957) in Amazon Q Developer for Visual Studio Code allowed attackers to execute arbitrary code and steal AWS credentials by automatically loading malicious MCP server…
11 articles · Updated June 26, 2026 -
Microsoft's Record Patch Tuesday in June 2026 Addresses 206 Vulnerabilities
In June 2026, Microsoft released its largest Patch Tuesday update, addressing 206 vulnerabilities, including critical flaws in Windows kernel and BitLocker. Notable CVEs include a zero-day in Visual Studio Code that…
229 articles · Updated July 1, 2026 -
GhostApproval Vulnerability Exposes AI Coding Assistants to Remote Code Execution
A vulnerability named GhostApproval has been discovered in six major AI coding assistants, including Amazon Q Developer, Anthropic Claude Code, Augment, Cursor, Google Antigravity, and Windsurf. This flaw allows…
17 articles · Updated July 8, 2026 -
Anthropic's Claude Mythos Preview Sparks Cybersecurity Revolution
Anthropic has announced the launch of Project Glasswing, utilizing its unreleased AI model, Claude Mythos Preview, to identify and exploit thousands of critical software vulnerabilities across major operating systems…
1402 articles · Updated April 7, 2026 -
ToddyCat Exploits OAuth to Compromise Gmail Accounts Using Umbrij Malware
ToddyCat, an advanced persistent threat group, has adapted its tactics to exploit OAuth-based authorization flows, allowing them to compromise Gmail accounts without stealing user credentials. The group utilizes a…
4 articles · Updated July 2, 2026 -
End of Support for Windows 10 Raises Security Risks
Support for Windows 10 ended on October 14, 2025, leaving users without security updates. Microsoft is cutting off Secure Boot certificates for Windows 10 in June 2026, complicating the situation for users unable to…
3 articles · Updated March 30, 2026 -
Vulnerabilities in GitHub Copilot and Visual Studio Enable Security Bypass
Recent vulnerabilities in GitHub Copilot and Visual Studio have been identified, allowing attackers to bypass security features. These flaws pose risks to users relying on these platforms for secure coding practices.…
3 articles · Updated November 12, 2025
Recent Intelligence Reports
- ZDI August 2026 analysis — www.zerodayinitiative.com · August 13, 2026
- The July 2026 Security Update Review — www.zerodayinitiative.com · July 30, 2026
- The July 2026 Security Update Review — Thezdi · July 14, 2026
- 2026 047 Aws — aws.amazon.com · July 9, 2026
- ToddyCat APT uses remote debugging to hijack Gmail OAuth tokens — Feeds.4Sysops · July 2, 2026
- Amazon Q Developer extension vulnerability could have exposed cloud credentials — Feeds.Feedburner · June 26, 2026
- Amazon Q Developer flaw let malicious repos steal AWS credentials via rogue MCP servers — Thenextweb · June 26, 2026
- Still on Windows 10? Do This Now to Reduce Your Risk of Getting Hacked — Au.Pcmag · March 30, 2026