Related Threat Clusters
-
Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign
Since July 2025, Russian state-backed hackers, known as Laundry Bear, have exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite to infiltrate Western government and commercial…
82 articles · Updated July 23, 2026 -
Critical Security Flaws Found in SUSE Node.js Versions 22 and 24
SUSE released important security updates for Node.js versions 22 and 24 on August 6, 2026, addressing multiple vulnerabilities. The updates include fixes for CVE-2026-54272, CVE-2026-56846, CVE-2026-56847,…
2 articles · Updated August 6, 2026 -
Critical RCE Vulnerability in BeyondTrust Software Requires Immediate Patching
BeyondTrust has issued a warning regarding a critical remote code execution (RCE) vulnerability in its Remote Support and Privileged Remote Access software. The flaw, tracked as CVE-2026-1731, allows unauthenticated…
1495 articles · Updated February 9, 2026 -
SSRF Vulnerability in Sentry MCP Server Exposes Security Risks
On July 12, 2026, researcher cccccccti disclosed a Server-Side Request Forgery (SSRF) vulnerability in the raw_sentry_api component of ddfourtwo/sentry-selfhosted-mcp, tracked as CVE-2026-81421. This vulnerability…
2 articles · Updated August 28, 2026 -
Monsta FTP Remote Code Execution Vulnerability CVE-2025-34299 Discovered
A critical remote code execution vulnerability (CVE-2025-34299) has been identified in Monsta FTP, a web-based file transfer client, allowing unauthenticated attackers to execute arbitrary code on affected systems. The…
1 article · Updated November 11, 2025 -
Vulnerabilities Discovered in Forgejo Following Carrot Disclosure
A security researcher identified multiple vulnerabilities in Forgejo, a software platform used by Fedora, including SSRF, cryptographic issues, and authentication flaws. The researcher was able to chain these…
2 articles · Updated April 30, 2026 -
Critical Remote Code Execution Vulnerability in Monsta FTP Discovered
A remote code execution vulnerability, CVE-2025-34299, has been identified in Monsta FTP, affecting versions 2.11 and earlier. This flaw allows unauthenticated users to upload arbitrary files, enabling attackers to…
3 articles · Updated November 11, 2025 -
OpenAI Launches GPT-5.4-Cyber Amidst Cybersecurity Arms Race
OpenAI has introduced GPT-5.4-Cyber, a specialized AI model for defensive cybersecurity, available only to vetted professionals through its Trusted Access for Cyber (TAC) program. This model is designed to facilitate…
1370 articles · Updated April 14, 2026 -
Snyk VulnBench JS 1.0 Reveals Inconsistencies in LLM Security Findings
Snyk conducted 300 vulnerability scans to evaluate the repeatability of LLM security reviews on identical code and prompts. The results showed that while reference-matched findings were stable, extra-model reports…
2 articles · Updated June 29, 2026 -
Critical RCE Vulnerability in BeyondTrust Remote Support and PRA
A critical pre-authentication remote code execution vulnerability, CVE-2026-1731, has been identified in BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA). This vulnerability…
717 articles · Updated February 7, 2026
Recent Intelligence Reports
- Sentry MCP Server SSRF Exposes How Agent Trust Chains Become Attack Vectors — Cryptorank · August 28, 2026
- SUSE Nodejs 24 Important Security Update for Multiple Issues 2026-3520 — Linuxsecurity · August 6, 2026
- CVE-2026-65924 — nvd.nist.gov · July 30, 2026
- Zimbra's November 2025 security release — wiki.zimbra.com · July 24, 2026
- Snyk VulnBench JS 1.0: LLM Bug Repeatability — Snyk · June 29, 2026
- Attackers exploit Cisco Unified CM flaw weeks after patch release — Csoonline · June 24, 2026
- Carrot Disclosure: Forgejo — News.Ycombinator · April 28, 2026
- Codex Security: now in research preview — Openai · March 6, 2026