wget is a tool tracked by ThreatCluster, appearing in 13 threat clusters built from 12 intelligence report mentions.
wget is a tool tracked across 13 threat clusters and 12 intelligence report mentions on ThreatCluster. First observed November 11, 2025; most recent activity July 29, 2026.
A critical vulnerability in the marimo Python notebook platform, tracked as CVE-2026-39987, has been actively exploited to deploy a new variant of NKAbuse malware. The flaw allows for remote code execution without…
In early February 2026, hackers exploited two critical authentication bypass vulnerabilities in the Qinglong task scheduling platform, affecting versions 2.20.1 and earlier. These vulnerabilities, identified as…
Multiple vulnerabilities were discovered in Wget, affecting Ubuntu versions 14.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, 24.04 LTS, and 26.04 LTS. CVE-2024-38428 allows remote attackers to trick users into connecting to…
On July 22, 2026, n8n released a patch for a high-severity sandbox escape vulnerability (GHSA-gv7g-jm28-cr3m) rated 8.7 on CVSS 4.0. This flaw allows authenticated users to execute operating system commands via crafted…
A Linux user attempted to use OpenAI's Codex AI agent for incident response during a cyberattack but faced significant challenges. The user was unaware that at least two threat actors had compromised their system,…
Zscaler ThreatLabz reported a significant increase in cyberattacks, with Android malware rising by 67%. Critical infrastructure sectors, particularly energy and manufacturing, experienced malware activity increases of…
On May 20, 2026, The Oncology Institute, Inc. was notified of unauthorized access to its systems by Kroll, a third-party vendor. The incident, confirmed in an SEC filing on May 22, 2026, involved patient data…
North Korea-linked hackers have exploited a critical flaw in web applications using a new malware called EtherRAT. This remote access trojan employs Ethereum smart contracts for communication and utilizes multiple Linux…
Hackers are actively targeting a command injection vulnerability, CVE-2023-33538, affecting several end-of-life TP-Link router models, including TL-WR940N and TL-WR841N. This vulnerability allows attackers to execute…
Zscaler ThreatLabz reported a significant increase in cyberattacks on IoT and mobile devices, with Android malware rising by 67%. Critical sectors such as energy and manufacturing experienced alarming spikes in malware…
wget is a tool tracked by ThreatCluster, appearing in 13 threat clusters built from 12 intelligence report mentions.
The most recent intelligence report mentioning wget on ThreatCluster is dated July 29, 2026. Activity was first observed November 11, 2025, giving a tracked span from then to July 29, 2026.
Across ThreatCluster reporting, wget most frequently co-occurs with Earth Lamia, Ember Bear, Jackpot Panda, Lazarus, OilRig, among 12 tracked related entities.
The most significant recent cluster is “Attackers Exploit CVE-2026-39987 to Deploy NKAbuse Malware via Hugging Face” (5 articles · Updated April 16, 2026). wget appears across 13 threat clusters in total, listed above with sources.
wget appears in 12 intelligence report mentions across 13 deduplicated threat clusters, aggregated from 17,000+ monitored sources.