Related Threat Clusters
-
China-Linked QTFY Group Targets Critical Infrastructure with Advanced Exploits
The Joint Cybersecurity Advisory JCSA-20260826-01, released on August 26, 2026, details ongoing activities by the China-linked hacking group QTFY, attributed to Nanjing Xinjiuwei Network Technology Co. Active since…
5 articles · Updated September 2, 2026 -
New CVSS 10.0 Vulnerability CVE-2026-29000 Discovered
A new CVSS 10.0 vulnerability, CVE-2026-29000, was published on March 4, 2026, allowing attackers to bypass authentication in the pac4j-jwt library, enabling impersonation of any user, including administrators. This…
2 articles · Updated March 6, 2026 -
Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
753 articles · Updated April 29, 2026 -
Unisoc Modem Vulnerability Allows Remote Code Execution via Video Calls
Researchers have discovered a critical vulnerability in Unisoc modem firmware that allows attackers to gain root access to various Android devices through a video call exploit. This vulnerability affects multiple budget…
10 articles · Updated August 17, 2026 -
Critical React Flaw CVE-2025-55182 Exposes Major Security Risks
A maximum-severity vulnerability in the React JavaScript library, tracked as CVE-2025-55182, allows unauthenticated remote code execution on affected instances. Security researchers report that 39 percent of cloud…
47 articles · Updated December 3, 2025 -
APT41 Cyber-Espionage Tactics Explored in Ransomware Emulations
The article discusses the fifth volume of AttackIQ’s Ransom Tales series, which simulates the tactics of ransomware families REvil, DarkSide, and BlackMatter. These emulations are designed to help organizations validate…
14 articles · Updated January 6, 2026 -
Zero-Knowledge Proofs Enhance Cyber Risk Sharing for Critical Infrastructure
Zero-knowledge proofs (ZKPs) are proposed as a solution for infrastructure operators to share vulnerability information without exposing sensitive data. The U.S. has struggled for over a decade to facilitate effective…
2 articles · Updated August 4, 2026 -
Burp Suite Enhances Scanner for React2Shell Vulnerabilities
Burp Suite has upgraded its scanning capabilities to detect critical React2Shell vulnerabilities in JavaScript applications. Both editions of Burp Suite now include the latest detection logic, allowing users to validate…
4 articles · Updated December 9, 2025 -
CISA Warns of Active Exploitation of Oracle Identity Manager Vulnerability CVE-2025-61757
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that a critical vulnerability in Oracle Identity Manager, tracked as CVE-2025-61757, is being actively exploited in the wild. This flaw…
31 articles · Updated November 26, 2025 -
Oracle Identity Manager RCE Vulnerability Exploited in Active Attacks
A critical vulnerability in Oracle Identity Manager, tracked as CVE-2025-61757, allows remote code execution (RCE) without authentication. Discovered by Searchlight Cyber researchers, the flaw has been actively…
19 articles · Updated November 21, 2025
Recent Intelligence Reports
- Remote Code Execution RCE — www.techtarget.com · September 2, 2026
- Weekly Threat Bulletin – September 2nd, 2026 — F5 · September 2, 2026
- Zero-Knowledge Proofs — Fdd · August 4, 2026
- Cybersecurity PR Agencies - Best Picks 2026 — Analyticsinsight · June 3, 2026
- Cybersecurity PR Agencies - Best Picks 2026 — Analyticsinsight · June 3, 2026
- Hacker hijacks Axios open-source project, used by millions, to push malware — Techcrunch · March 31, 2026
- Cobalt Introduces New AI Capabilities for Continuous Pentesting — Sg.Finance.Yahoo · March 19, 2026
- Why CVSS 10 Vulnerabilities Are So Dangerous (Real Examples) — Codeant.Ai · March 6, 2026