Newsletter

All Editions

Every Decryption Digest edition, catalogued. Deep-dive threat briefings covering the zero-days, ransomware campaigns, and nation-state operations that matter most to security teams.

Get the latest edition in your inbox

Free daily briefings. No spam, no vendor pitches.

236 editions published

RSS Feed
#236
ACTIVE CAMPAIGN

JFrog Artifactory Supply Chain Attack: 3 CVEs Chained to Plant Backdoors Across Dev Pipelines

JFrog Artifactory supply chain attack chained 3 CVEs. Attackers forge admin tokens, plant Rust backdoors. Patching alone won't revoke their access.

September 15, 202611 min read
#235
ZERO-DAY

GitLab CVE-2026-85706: Unauthenticated Path Traversal Exposes SSH Keys and CI/CD Secrets

GitLab CVE-2026-85706 CVSS 10.0 path traversal lets unauthenticated attackers read any server file -- SSH keys, CI/CD tokens, deploy credentials. CISA deadline is today. Patch to 19.3.2 now.

September 14, 202610 min read
#234
ZERO-DAY

MikroTrick Exploited: 122,500 RouterOS Devices Exposed to SSH Auth Bypass Chain

MikroTrick SSH auth bypass CVE-2026-67276 chains with CVE-2026-86060 for unauthenticated root on 122,500 RouterOS devices. CISA KEV confirmed. Patch to 7.24.2 now.

September 13, 202610 min read
#233
ACTIVE CAMPAIGN

WatchGuard Firebox CVE-2025-14733: Ransomware Gangs Actively Exploiting 9,000 Unpatched Devices

WatchGuard Firebox CVE-2025-14733 IKEv2 pre-auth RCE is now confirmed ransomware-exploited. 9,000 devices still unpatched 9 months on. Patch or disable IKEv2 today.

September 12, 202610 min read
#232
CLOSE THIS GAP

CVE-2025-25249: 178 FortiGate Devices Compromised by AI-Built PivotC2 RAT

CVE-2025-25249 in FortiOS lets attackers drop PivotC2 RAT via CAPWAP. 178 devices confirmed hit. Patch to 7.6.4 or 7.4.9 now.

September 11, 202611 min read
#231
ZERO-DAY

CVE-2026-20079: Cisco FMC Pre-Auth Root RCE Exploited by Sandworm and Qilin Ransomware

CVE-2026-20079 in Cisco FMC lets attackers get root without credentials. Sandworm and Qilin are already inside. Patch to FMC 7.0.0 before Sept 12.

September 10, 202611 min read
#230
ZERO-DAY

CVE-2026-75650 StyleSmuggler: No-Auth Magento RCE Hit Stores 3 Days Before Adobe's Fix

CVE-2026-75650 StyleSmuggler hit Adobe Commerce 2.4.4-2.4.9 with no-auth RCE 3 days before any patch. Apply VULN-39341 and rotate all credentials now.

September 9, 202610 min read
#229
ACTIVE CAMPAIGN

BigBear PhaaS Bypasses Microsoft 365 MFA at 258 Organizations, Stealing 5,137 Credentials

Microsoft 365 AiTM phishing service BigBear bypassed MFA at 258 organizations, stealing 5,137 credentials via session-cookie theft. Enforce FIDO2 WebAuthn now.

September 8, 202611 min read
#228
ZERO-DAY

CVE-2026-86218 Gives Attackers Root on 1,500 N-central RMM Servers

CVE-2026-86218 is a CVSS 10.0 pre-auth RCE in N-able N-central. Patch to build 2026.3.1.14 now. Third attack wave in six weeks targets ~1,500 exposed MSP servers.

September 7, 202610 min read
#227
ACTIVE CAMPAIGN

CVE-2026-81578 PaperCut Active Campaign Hits Schools Across U.S. and Europe

CVE-2026-81578 PaperCut auth bypass chains with CVE-2026-82078 to steal AD credentials from K-12 and university print servers. Patch to 24.1.10 now.

September 6, 202610 min read
#226
ZERO-DAY

CVE-2026-19490 Citrix NetScaler Auth Bypass Exploited on 22,000 Exposed Gateways

CVE-2026-19490 Citrix NetScaler auth bypass is under active exploitation with 22,000+ exposed gateways. Patch to 14.1-73.32 now. The prior CVE-2026-8452 hotfix is insufficient.

September 5, 202610 min read
#225
CLOSE THIS GAP

Thomson Reuters C-Track Breach Exposes SSNs and Sealed Court Records Across 11 States

Thomson Reuters C-Track breach exposed SSNs, sealed court records, and medical data from 24 courts in 11 states. Verify exposure and enroll by December 31.

September 4, 202610 min read
#224
ACTIVE CAMPAIGN

The Gentlemen Ransomware Hits 483 Victims With BYOVD EDR Kill and Ethereum C2

The Gentlemen ransomware confirmed 483 victims in 66 countries using GentleKiller BYOVD to kill 48 security vendors and EtherRAT for blockchain-based C2. Block IOCs now.

September 3, 202611 min read
#223
ZERO-DAY

SonicWall SMA1000 Zero-Day Chain: 400 Appliances Exposed to Unauthenticated RCE

SonicWall SMA1000 zero-day CVE-2026-83548 chains SSRF with command injection for unauthenticated RCE on 400+ exposed appliances. Apply hotfix now.

September 2, 202610 min read
#222
ZERO-DAY

CVE-2026-62911: Public PoC Released for Microsoft Exchange Pre-Auth RCE Chain

CVE-2026-62911 PoC chains NTLM relay to Exchange MRSProxy to drop ASPX webshells as SYSTEM. Apply August 2026 update before mass exploitation begins.

September 1, 202611 min read
#221
ACTIVE CAMPAIGN

20 Chrome Extensions Hijacked to Steal Crypto and Inject ClickFix: Audit Your Browser Now

Hijacked Chrome extensions deploy a 19-module malware framework to 70,000+ users, stealing crypto wallet seed phrases and all browser credentials. Audit extensions and rotate credentials now.

August 31, 202612 min read
#220
ZERO-DAY

ServiceNow AI Platform CVE-2026-18885: Three CVSS 10.0 Flaws Enable Unauthenticated RCE and SQL Injection

ServiceNow CVE-2026-18885 unauthenticated RCE: three CVSS 10.0 flaws enable GraphQL injection, privilege escalation, and SQL injection. Patch self-hosted Xanadu, Yokohama, and Zurich now.

August 30, 202610 min read
#219
ZERO-DAY

CVE-2026-8452: Citrix NetScaler SAML Heap Overflow Enables Unauthenticated RCE

CVE-2026-8452 Citrix NetScaler SAML RCE: pre-auth heap overflow exploited in 24 hours after PoC. Webshells x.php and z.php active. CISA KEV deadline is today. Patch to 14.1-73.32 now.

August 29, 202610 min read
#218
PATCH BEFORE EOD

regreSSHion: OpenSSH CVE-2024-6387 Puts 14 Million Servers at Risk of Unauthenticated Root RCE

CVE-2024-6387 regreSSHion is a signal-handler race condition in sshd that gives unauthenticated attackers root-level RCE on 14 million exposed Linux servers. Patch to 9.8p1 or set LoginGraceTime 0 now.

August 28, 202610 min read
#217
CLOSE THIS GAP

Operation CameraSwarm: 14,530 Dahua Cameras Backdoored via P2P Exploit

Dahua camera vulnerability exploited: Operation CameraSwarm backdoored 14,530+ devices via P2P abuse and CVE-2021-33044/33045. Patch and disable P2P now.

August 27, 202611 min read
#216
ZERO-DAY

Zimbra CVE-2026-73570 Exploited: 274 Servers Compromised via SNMP Command Injection

Zimbra CVE-2026-73570 SNMP command injection has compromised 274 servers with 8,200 more at risk. CISA KEV added August 21 with 3-day deadline. Patch to ZCS 10.1.20 now.

August 26, 202610 min read
#215
ZERO-DAY

MLflow SSRF CVE-2026-64849 Exploited: Cloud Credentials Stolen via Webhook Flaw

MLflow SSRF CVE-2026-64849 lets attackers steal cloud IAM credentials without authentication. CISA KEV added Aug 19; federal deadline Sep 2. Patch to 3.15.0 now.

August 25, 202610 min read
#214
MONDAY INTEL DROP

CISA Deadline August 25: Lazarus Zero-Day, AnMed Ransomware, Cl0p Shell

CISA deadline August 25 for Lazarus Windows zero-day CVE-2026-68820. AnMed ransomware, Cl0p Shell, SynkLoader Teams phishing: five threats ranked by urgency.

August 24, 202612 min read
#213
KNOW YOUR ENEMY

Mustang Panda Adds Signed Kernel Rootkit to CoolClient: 4 Governments Compromised

Mustang Panda CoolClient kernel rootkit hides government backdoors in 4 countries. Hunt these file hashes before your tools fail silently.

August 23, 202611 min read
#212
AI WEAPONIZED

AI-Written Exploits Are Attacking Siemens PLCs in 7 Critical Infrastructure Sectors

Five federal agencies warn AI-generated Python scripts are attacking Siemens S7 PLCs in 7 critical sectors. 12+ states hit. Block TCP 102 now.

August 22, 202610 min read
#211
CLOSE THIS GAP

WP2Shell: Pre-Auth WordPress Core RCE Chains SQL Injection to Admin Takeover

WP2Shell WordPress RCE needs zero credentials — attackers chain two core flaws to drop webshells. Patch to 6.9.5 or 7.0.2 before the weekend.

August 21, 202610 min read
#210
PATCH BEFORE EOD

CVE-2026-55040: SharePoint JWT Bypass Exploited: No Password Needed

CVE-2026-55040 SharePoint JWT bypass gives attackers admin access without credentials. CISA KEV-listed and actively exploited: patch KB5002882 today.

August 20, 202610 min read
#209
ACTIVE CAMPAIGN

DeadLock Ransomware Shows Why a Backup Is Not a Recovery Plan

Microsoft's DeadLock ransomware disclosure shows why a data backup is not the same as a working recovery plan. Here is what security teams need to validate before the next incident.

August 19, 202610 min read
#208
PATCH BEFORE EOD

200,000 Ray AI Clusters Exposed to CVE-2025-62593 RCE: CISA Deadline August 20

CVE-2025-62593 in Ray: CISA added it to KEV today with a 48-hour federal patch deadline. ShadowRay 2.0 is mining NVIDIA A100 GPUs on 200,000 exposed clusters right now.

August 18, 202610 min read
#207
MONDAY INTEL DROP

Windows DNS Wormable RCE + SharePoint Ransomware: 5 Threats to Patch This Week

August 2026 Patch Tuesday: 421 CVEs including a CVSS 9.8 wormable DNS RCE and SharePoint actively exploited by ransomware. 5 patches to apply right now.

August 17, 202611 min read
#206
KNOW YOUR ENEMY

Lazarus Group CVE-2026-68820: FudModule 3.1 Rootkit Hits Defense Firms Across 4 Nations

Lazarus Group ran CVE-2026-68820 for 5 undetected weeks against defense firms. Patch Windows now, block 3 C2 domains, and enable HVCI.

August 16, 202610 min read
#205
AI WEAPONIZED

Hermes AI Agent Attack: Autonomous Post-Exploitation Hits Thailand Ministry of Finance

Hermes AI agent ran in YOLO mode to autonomously breach Thailand's Finance Ministry. Block 4 IPs and 6 hashes. Sigma detection rules included.

August 15, 202611 min read
#204
CLOSE THIS GAP

VMware vCenter CVE-2026-59310: 361 Servers Breached Across 47 Countries. Patch Before This Weekend.

VMware vCenter CVE-2026-59310 has compromised 361 servers in 47 countries in 11 days. Patch to 8.0 U3k or 9.x now. No workaround exists.

August 14, 202611 min read
#203
YOUR EXPOSURE TODAY

LiteLLM Supply Chain Attack Exposed 434,000 CI/CD Pipelines: Rotate Your Cloud Credentials Now

TeamPCP's LiteLLM supply chain attack exposed 153GB of cloud credentials from 2,488 orgs. Check for versions 1.82.7/1.82.8 and rotate AWS, GitLab, and AI API keys now.

August 13, 202612 min read
#202
ACTIVE CAMPAIGN

Gunra Ransomware Exploits Fortinet CVE-2024-55591 to Hit 51 Critical Infrastructure Orgs

Gunra ransomware hit 51 critical infrastructure orgs via Fortinet CVE-2024-55591. CISA advisory AA26-222A issued. Patch FortiOS 7.0.17 today.

August 12, 202611 min read
#201
PATCH BEFORE EOD

Progress LoadMaster CVE-2026-8037: Root RCE Exploited 792 Times, Patch Your Load Balancer

CVE-2026-8037 gives unauthenticated attackers root-level command execution on Progress LoadMaster. 792 attempts logged from 65 IPs. CISA KEV deadline: August 10.

August 11, 202610 min read
#200
MONDAY INTEL DROP

Apache Tomcat CVE-2025-24813: Vulnerable Does Not Mean Exploitable

CVE-2025-24813 made CISA's KEV list, but Horizon3's scan of 10,000+ Tomcat endpoints found none in the vulnerable configuration. Here's how to validate exploitability instead of guessing at it.

August 10, 20269 min read
#199
KNOW YOUR ENEMY

UNC6671 Rebrands and Targets Hedge Funds: Vishing MFA Bypass Hits Finance Firms in August 2026

UNC6671 vishing group rebrands, targets Point72 and Citadel -- block 9 AiTM domains and mandate FIDO2 today.

August 9, 202610 min read
#198
AI WEAPONIZED

LLMjacking 2026: Attackers Drain $100K Daily From Stolen AI Accounts, 175K Ollama Servers Exposed

LLMjacking operations stole over $100K per day from a single premium AI account and hit 175K exposed Ollama servers with no auth. Rotate your AI keys today.

August 8, 202610 min read
#197
CLOSE THIS GAP

TeamCity CVE-2026-63077: CVSS 9.8 Unauthenticated RCE Exposes CI/CD Supply Chain, Patch Before August 8

CVE-2026-63077 gives unauthenticated attackers full OS command execution on any internet-facing TeamCity server. CISA deadline August 8 -- patch to 2025.11.7 or 2026.1.3 today.

August 7, 202610 min read
#196
PATCH BEFORE EOD

IBM Langflow CVE-2026-9198: CVSS 9.8 Unauthenticated RCE Exploited, Patch Before August 7

IBM Langflow CVE-2026-9198 scores CVSS 9.8 and gives unauthenticated attackers full Python code execution. CISA deadline tomorrow -- upgrade to 1.10.1 before August 7.

August 6, 202610 min read
#195
ACTIVE CAMPAIGN

CaptiveCrunch: Russia's Midnight Blizzard Hijacks Hotel Wi-Fi to Steal Microsoft 365 Tokens

Russia's Midnight Blizzard compromises hotel Wi-Fi to steal Microsoft 365 tokens. Device code phishing bypasses MFA -- password resets don't revoke stolen tokens. Disable device code flow today.

August 5, 202610 min read
#194
PATCH BEFORE EOD

INC Ransomware Claims 885 Victims Exploiting SonicWall SMA1000: Patch Immediately

INC ransomware SonicWall SMA1000 exploit has claimed 885 victims. CVE-2026-15409 (CVSS 10) chained with CVE-2026-15410 for root-level access. Patch firmware 12.4.3-03453 or later immediately.

August 4, 202610 min read
#193
MONDAY INTEL DROP

N-central CVE-2026-18577 Actively Exploited: 4 Critical Threats to Act on Today

N-central CVE-2026-18577 authentication bypass is actively exploited, giving attackers god-mode RMM access. Plus Qilin PAN-OS ransomware and $88.6M COLDCARD heist.

August 3, 202612 min read
#192
KNOW YOUR ENEMY

STAC4749: Chaos Ransomware Group Encrypts Networks via 2-Minute Microsoft Teams Calls

STAC4749 dials employees on Teams, pretends to be IT support, and encrypts networks with Chaos ransomware in under 17 hours. 100+ North American orgs hit.

August 2, 202610 min read
#191
AI WEAPONIZED

PromptSpy Weaponizes Google Gemini: ESET Finds 3,000+ Malicious AI Skills in H1 2026

Generative AI malware is confirmed active: PromptSpy weaponizes Google Gemini on Android while ESET H1 2026 documents 3,000+ malicious AI skills active in enterprise repositories.

August 1, 202611 min read
#190
CLOSE THIS GAP

CVE-2026-20316: Cisco FMC Backdoor Account Actively Exploited -- Patch Before August 1

Cisco FMC static credential CVE-2026-20316 gives unauthenticated attackers access to your firewall manager and chains with CVSS 10.0 CVE-2026-20079 for root. CISA deadline: August 1.

July 31, 202613 min read
#189
YOUR EXPOSURE TODAY

LeakNet Posts 11TB of NYC Health + Hospitals Patient Data on Dark Web

NYC Health Hospitals data breach: LeakNet posted 11TB of patient records on the dark web, including fingerprints, SSNs, and HIV records from 1.8 million confirmed victims.

July 30, 202612 min read
#188
ACTIVE CAMPAIGN

Cl0p Ransomware Steals Engineering IP from Windchill and FlexPLM: 4 Sectors Under Active Attack

Cl0p ransomware has been inside PTC Windchill and FlexPLM systems since June, stealing engineering IP from manufacturing, automotive, aerospace, and retail via CVE-2026-12569 (CVSS 9.8).

July 29, 202612 min read
#187
PATCH BEFORE EOD

CVE-2026-6875: ServiceNow Pre-Auth RCE Exploited in 5 Days -- Patch Self-Hosted Instances Now

CVE-2026-6875 gives unauthenticated attackers remote code execution on ServiceNow AI Platform. Active exploitation confirmed July 18 -- 85% of Fortune 500 companies run the affected platform.

July 28, 202610 min read
#186
MONDAY INTEL DROP

5 Cyber Threats to Patch Before Tomorrow: AD FS Deadline, ServiceNow RCE, Cl0p Windchill

Two Microsoft zero-days actively exploited, CISA federal deadline tomorrow, ServiceNow RCE in live attacks, and Cl0p stealing Windchill data. Five threats, ranked by urgency.

July 27, 202611 min read
#185
KNOW YOUR ENEMY

Red Menshen's BPFDoor Hides Inside Telecom Networks Across 10 Countries

Red Menshen BPFDoor implants are active inside telecom networks in 10 countries. Here's how the sleeper cells work and what to hunt for now.

July 26, 202610 min read
#184
AI WEAPONIZED

AgentForger: One Phishing Link Plants an Attacker-Controlled AI Agent Inside Your Enterprise

AgentForger ChatGPT CSRF plants a rogue AI agent inside your enterprise with one phishing link, inheriting all workspace connectors instantly.

July 25, 202610 min read
#183
CLOSE THIS GAP

CVE-2026-64600 RefluXFS: 16.4 Million Linux Systems Open to Silent Root Takeover

CVE-2026-64600 Linux kernel privilege escalation exposes 16.4M RHEL systems to silent root takeover. A 9-year-old XFS race -- patch before the weekend.

July 24, 202611 min read
#182
YOUR EXPOSURE TODAY

ShinyHunters Hits Abbott: 30 Million Patient Records and 1 Million SSNs at Dark Web Risk

ShinyHunters claims 30M+ Abbott patient records and 1M SSNs stolen via vishing. Extortion deadline passed — verify your exposure and harden Entra SSO now.

July 23, 202611 min read
#181
ACTIVE CAMPAIGN

Qilin Ransomware Exploits PAN-OS GlobalProtect: 167K Firewalls Targeted

Qilin ransomware exploits CVE-2026-0257 PAN-OS GlobalProtect bypass to breach healthcare and manufacturing. 167K firewalls exposed. Patch to 10.2.10 or 11.0.5 now.

July 22, 202611 min read
#180
PATCH BEFORE EOD

CVE-2026-6875: ServiceNow Pre-Auth RCE Actively Exploited, Patch Now

CVE-2026-6875 lets unauthenticated attackers escape ServiceNow's sandbox and execute code remotely. Exploitation confirmed July 18. 85% of Fortune 500 runs this platform.

July 21, 202610 min read
#179
MONDAY INTEL DROP

FortiBleed Hits 430K Firewalls: 4 Threats to Prioritize This Week

FortiBleed hit 430K FortiGate firewalls this week, feeding stolen credentials into INC ransomware. Plus 3 more urgent threats to act on today.

July 20, 202611 min read
#178
KNOW YOUR ENEMY

FSB Center 16: 13 Nations Warn of Russia's Static Tundra Router Espionage Campaign

FSB Center 16 steals router configs from energy, finance, and government networks globally using default SNMP strings and CVE-2018-0171.

July 19, 202610 min read
#177
AI WEAPONIZED

AI-Generated 'Vibe-Coded' Malware Caught Mapping Active Directory in Live Attack

A threat actor vibe-coded a PowerShell AD recon script using an LLM, mapped an entire domain in 30 minutes, and exfiltrated the data with zero antivirus detections.

July 18, 202610 min read
#176
CLOSE THIS GAP

Microsoft Patch Tuesday July 2026: 2 Zero-Days Exploited in Attacks, 570 Flaws Fixed

Microsoft Patch Tuesday July 2026 patches 570 flaws and 2 actively exploited zero-days. CISA deadline expires today. Patch ADFS and SharePoint before the weekend.

July 17, 202610 min read
#175
YOUR EXPOSURE TODAY

Aflac Japan Data Breach Exposes 4.38 Million Customers: Bank Accounts and PII Stolen

Aflac Japan data breach exposed PII and bank accounts of 4.38 million customers in June 2026. Check exposure and verify your insurance data today.

July 16, 202611 min read
#174
ACTIVE CAMPAIGN

SonicWall SMA1000 Zero-Days CVE-2026-15409 Actively Exploited: Patch Before July 17

SonicWall SMA1000 zero-day CVE-2026-15409 (CVSS 10.0) is actively exploited, chained with CVE-2026-15410 for unauthenticated RCE. CISA deadline July 17 — patch or disconnect now.

July 15, 202611 min read
#173
PATCH BEFORE EOD

CVE-2025-47981: Wormable Windows SPNEGO Flaw Tops Microsoft's July 2026 Patch Tuesday

CVE-2025-47981 (CVSS 9.8) gives attackers wormable unauthenticated RCE via SMB, RDP, and SMTP on all Windows 10 and Server systems — patch July 2026 Patch Tuesday before EOD.

July 14, 202611 min read
#172
MONDAY INTEL DROP

Monday Intel Drop: Russian Router Attacks, RoguePlanet Zero-Day, 5 Threats to Fix Today

Russian FSB targets 6 critical sectors in this Monday cyber threat brief July 2026: 5 active exploits demand immediate action today.

July 13, 202612 min read
#171
KNOW YOUR ENEMY

UAT-7810 LONGLEASH: Chinese APT Hijacks Ruckus Routers to Build Invisible Spy Network

UAT-7810 LONGLEASH malware turns Ruckus routers into covert Chinese spy relay nodes, serving 2+ APT groups with 62+ unique backdoor hashes active.

July 12, 202614 min read
#170
AI WEAPONIZED

AI-Generated Browser Ransomware: DeepSeek Targets 3 Billion Chrome Users

AI-generated browser ransomware built by DeepSeek encrypts Chrome files without installing malware. 1,383 malicious DeepSeek files found in 12 months. No install needed.

July 11, 202613 min read
#169
CLOSE THIS GAP

Adobe ColdFusion CVE-2026-48282: 800 Exposed Servers Under Active Attack

Adobe ColdFusion CVE-2026-48282 (CVSS 10.0) enables unauthenticated RCE on 800+ exposed servers. CISA deadline is today. Patch steps and IOCs inside.

July 10, 202612 min read
#168
YOUR EXPOSURE TODAY

81 Million Login Attempts: Microsoft 365 Password Spray Uses Stolen Dark Web Credentials

Microsoft 365 password spray attack used 81 million login attempts to breach 64 organizations using stolen dark web credentials. Detect it now.

July 9, 202611 min read
#167
ACTIVE CAMPAIGN

EtherRAT Targets Finance and Healthcare via Fake Teams IT Support Calls

EtherRAT uses fake Microsoft Teams IT support calls to plant a Node.js RAT with Ethereum blockchain C2 in finance and healthcare organizations.

July 8, 202610 min read
#166
PATCH BEFORE EOD

CVE-2026-8451: Citrix NetScaler SAML Flaw Exploited in 24 Hours

CVE-2026-8451 hit Citrix NetScaler ADC within 24 hours of disclosure. 71 IPs logged 424 exploitation signals targeting SAML session tokens.

July 7, 202611 min read
#165
MONDAY INTEL DROP

JADEPUFFER Agentic Ransomware: 5 Critical Threats for Your Monday Intel Drop

JADEPUFFER agentic ransomware encrypted 1,342 database records without a human operator. Four more confirmed exploits demand Monday morning action.

July 6, 202610 min read
#164
KNOW YOUR ENEMY

Armored Likho: AI-Generated Malware Hits Power Grids in 3 Countries

Armored Likho BusySnake stealer is hitting power grids in 3 countries with AI-generated malware. Here is what you need to detect it.

July 5, 202612 min read
#163
CVE REFERENCE

Claude Mythos Preview: What Security Teams Need to Know

Claude Mythos Preview scored 21/41 on ExploitBench while every other model scored zero, and found over 10,000 high-severity vulnerabilities across Glasswing partners. Here is what security teams need to understand and do.

July 5, 202610 min read
#162
CVE REFERENCE

Project Glasswing CVE List 2026: Every Confirmed Vulnerability

Project Glasswing has disclosed 1,596 vulnerabilities across 281 open-source projects, with 75 patched. This reference covers every publicly confirmed CVE, patch status, and what to do before fixes are available.

July 5, 202610 min read
#161
CLOSE THIS GAP

CVE-2026-5194 wolfSSL: Certificate Forgery Flaw and Patch Guide

CVE-2026-5194 is a CVSS 9.1 wolfSSL vulnerability that allows certificate forgery against IoT, automotive, and embedded systems. A patch is available; teams managing wolfSSL-dependent device fleets need to act now.

July 5, 202610 min read
#160
CLOSE THIS GAP

CVE-2026-4747 FreeBSD NFS RCE: 17-Year-Old Bug Patch Guide

CVE-2026-4747 is a 17-year-old memory corruption flaw in the FreeBSD NFS client that Claude Mythos discovered through Project Glasswing. Unauthenticated attackers with network access can achieve remote code execution as root on any affected FreeBSD system.

July 5, 202610 min read
#159
CVE REFERENCE

AI Autonomous Exploit Development: What Security Teams Must Understand

Claude Mythos can autonomously develop working exploits for real vulnerabilities without human direction at each step, producing results in hours at API costs under $20,000. Security teams need to understand what this threshold means for their defensive operations.

July 5, 202610 min read
#158
CVE REFERENCE

The Patch Window Is Collapsing: AI Exploit Timelines Are Now Hours

WannaCry took 59 days post-patch to weaponize. Claude Mythos produced its first Firefox exploit in 12 minutes. The assumptions underneath every patch SLA, compensating control timeline, and exploitability rating in your vulnerability management program are now wrong.

July 5, 202610 min read
#157
CVE REFERENCE

ExploitBench and ExploitGym: Claude Mythos Benchmark Results Explained

Claude Mythos scored 21/41 on ExploitBench while every other model scored zero. Across four independent benchmarks, the results signal a structural shift in automated exploit development that security teams need to understand.

July 5, 202610 min read
#156
CVE REFERENCE

AI-Enabled Threat Actors 2026: What the MITRE ATT&CK Data Shows

Anthropic analyzed 832 accounts banned for AI-enabled cyberattacks over 12 months. Medium/high-risk actors jumped from 33% to 56% -- and the single differentiator is agentic scaffolding, not technical skill or tool breadth.

July 5, 202610 min read
#155
CVE REFERENCE

How to Defend Against AI-Discovered Vulnerabilities: A Practitioner Guide

AI-discovered vulnerabilities differ from traditional CVEs in scale and novelty. Four specific defensive actions from Anthropic's red team address the gap between existing security operations and what AI-scale vulnerability discovery requires.

July 5, 202610 min read
#154
CVE REFERENCE

Project Glasswing Partners and Findings 2026: Who's In and What They Found

Project Glasswing expanded to 200+ organizations in June 2026. Cloudflare found 2,000 bugs using Claude Mythos. Mozilla found 271 vulnerabilities in Firefox 150. The full partner and findings breakdown for practitioners.

July 5, 202610 min read
#153
CVE REFERENCE

FFmpeg Memory Corruption: The Glasswing-Attributed Vulnerability Explained

Project Glasswing's AI-driven vulnerability discovery program identified a memory corruption flaw in FFmpeg's decoding pipeline. Because FFmpeg is embedded in VLC, Chrome, Firefox, AWS Elemental, and thousands of Linux packages, the supply chain blast radius is substantial. Here is what security teams need to know before a CVE ID is publicly assigned.

July 5, 202611 min read
#152
CVE REFERENCE

Linux Local Privilege Escalation 2026: The Glasswing-Attributed Kernel Vulnerability

Project Glasswing's Claude Mythos AI identified a local privilege escalation (LPE) flaw in the Linux kernel. Any attacker who already has unprivileged shell access to an affected host can use this vulnerability to gain root. Cloud VMs, containers sharing a kernel, and CI/CD runners are all in scope. Here is the full technical and remediation picture for security teams.

July 5, 202610 min read
#151
CVE REFERENCE

V8 ACE Exploit 2026: How Glasswing Achieved Arbitrary Code Execution in Chrome

Project Glasswing's Claude Mythos AI achieved 21 out of 41 arbitrary code execution exploits in the V8 JavaScript engine on Anthropic's ExploitBench evaluation. No other AI model scored above zero. V8 ACE is among the 9 confirmed Glasswing CVEs, meaning a drive-by browser compromise via a malicious webpage is within scope. This post explains the vulnerability class, the benchmark results, and what enterprise Chrome management teams should do now.

July 5, 202612 min read
#150
CVE REFERENCE

VMM Escape Vulnerability 2026: How Glasswing Broke Hypervisor Isolation

Project Glasswing's Claude Mythos AI identified a VMM escape vulnerability that breaks hypervisor isolation, allowing code executing inside a guest virtual machine to reach the host system and adjacent VMs. This is one of the highest-severity vulnerability classes in cloud and enterprise environments. The flaw affects KVM-based cloud infrastructure, VMware ESXi, and Xen deployments. Under coordinated disclosure as of July 5, 2026.

July 5, 202611 min read
#149
CVE REFERENCE

OpenBSD DoS Vulnerability 2026: Glasswing Finds a Bug in the Secure OS

OpenBSD is trusted for firewalls, routers, and hardened servers precisely because remote vulnerabilities are extraordinarily rare. Project Glasswing's Claude Mythos AI found one anyway: a denial-of-service vulnerability currently under coordinated disclosure embargo. Here is what defenders need to know.

July 5, 202610 min read
#148
CVE REFERENCE

Browser JIT Exploitation 2026: How Glasswing Weaponized Just-In-Time Compilation

Just-In-Time compilation is the performance heart of every modern browser JavaScript engine. It is also one of the most complex and historically exploitable attack surfaces in consumer software. Project Glasswing's Claude Mythos identified a JIT vulnerability through coordinated disclosure with browser vendors. This is a technical deep-dive for security engineers who need to understand the attack surface and harden their enterprise browser deployments.

July 5, 202612 min read
#147
AI WEAPONIZED

ConsentFix: AI-Powered OAuth Attack Steals Microsoft 365 Access Without MFA

ConsentFix Microsoft 365 MFA bypass is live: AI-generated OAuth phishing steals enterprise access without a password in 3 seconds.

July 4, 202611 min read
#146
CLOSE THIS GAP

SharePoint RCE CVE-2026-45659: Patch Before the July 4 Deadline

SharePoint RCE CVE-2026-45659 is actively exploited by Storm-2603. Verify your SharePoint Server builds before CISA's July 4 patch deadline.

July 3, 20269 min read
#145
YOUR EXPOSURE TODAY

DHS HSIN Breach Exposes Federal Security Intel: Tens of Thousands of Partners at Risk

DHS HSIN breach compromises federal security intel-sharing servers and SharePoint, exposing sensitive threat data across tens of thousands of agency partners.

July 2, 202612 min read
#144
CLOSE THIS GAP

CVE-2026-31431 FortiOS Impact: CopyFail Patch and Detection Guide

CVE-2026-31431 CopyFail Linux kernel LPE affects FortiOS-based FortiGate appliances. A 732-byte public exploit grants root. Check your FortiOS version and patch.

July 2, 202610 min read
#143
ACTIVE CAMPAIGN

BlueHammer CVE-2026-33825: Ransomware Gangs Exploit Windows Defender in Live Attacks

BlueHammer CVE-2026-33825 ransomware campaigns confirmed by CISA across all Windows versions. Patch Windows Defender before end of business.

July 1, 202610 min read
#142
PATCH BEFORE EOD

Chrome V8 Zero-Day CVE-2026-11645: 5th Actively Exploited Chrome Bug of 2026 Hits 3.5B Users

Chrome V8 zero-day CVE-2026-11645 confirmed active exploitation — CVSS 8.8, CISA KEV listed, 3.5B Chrome users exposed. Patch to 149.0.7827.103 now.

June 30, 202610 min read
#141
MONDAY INTEL DROP

Monday Intel Drop: 5 Active Exploits Your Team Must Address This Week

Weekly cyber threat brief: FortiBleed exposed 73,932 Fortinet firewalls while 24 billion credentials hit dark web markets this week.

June 29, 202611 min read
#140
KNOW YOUR ENEMY

ShinyHunters Breaches 100 Organizations Using Oracle PeopleSoft Zero-Day

ShinyHunters exploited a CVSS 9.8 Oracle PeopleSoft zero-day to compromise 100+ organizations before Oracle knew the flaw existed.

June 28, 202611 min read
#139
AI WEAPONIZED

AI-Built Ransomware Lab Uses Claude Opus 4.5 to Bypass Every EDR Solution

AI-built ransomware toolkit using Claude Opus 4.5 generated 80+ EDR-evasion modules bypassing Sophos, CrowdStrike, and Defender. Sophos confirmed criminal use.

June 27, 202610 min read
#138
CLOSE THIS GAP

Ubiquiti UniFi OS: Three CVSS 10.0 Flaws Enable Unauthenticated Root Access, Patch Now

UniFi OS unauthenticated RCE chain (CVE-2026-34908) gives attackers root on 100,000 exposed devices. CISA patch deadline is today, June 26.

June 26, 202611 min read
#137
YOUR EXPOSURE TODAY

24 Billion Credentials Exposed: Check Your Dark Web Exposure Now

24 billion credentials exposed in a June 12 Elasticsearch breach. Check your dark web exposure before attackers exploit it.

June 25, 202611 min read
#136
ACTIVE CAMPAIGN

Sapphire Sleet Backdoors 144 npm Packages in 88 Minutes to Steal Cryptocurrency Wallets

Sapphire Sleet npm supply chain attack hit 144 Mastra packages with 8M weekly downloads. Check your dependencies and rotate secrets now.

June 24, 202611 min read
#135
PATCH BEFORE EOD

Splunk CVE-2026-20253: 1,400 Exposed Instances Under Active Unauthenticated RCE Attack

Splunk CVE-2026-20253 unauthenticated RCE has 1,400+ exposed instances and a missed CISA deadline. Upgrade to 10.2.4 today.

June 23, 202611 min read
#134
KNOW YOUR ENEMY

APT34 OilRig Hits US Critical Infrastructure After Iran Nuclear Strike

APT34 OilRig surged US infrastructure attacks within 72 hours of Iran's nuclear strike. Here are their TTPs and how to detect them.

June 21, 202612 min read
#133
CLOSE THIS GAP

Joomla JCE CVE-2026-48907: 2.5 Million Sites Open to Unauthenticated Code Execution

Joomla JCE CVE-2026-48907 is a CVSS 10.0 unauthenticated RCE hitting 2.5M sites. Patch to JCE 2.9.99.5 before the weekend.

June 19, 202611 min read
#132
YOUR EXPOSURE TODAY

FortiBleed: 73,932 Fortinet Firewall Passwords Leaked Across 194 Countries

Fortinet VPN credential leak FortiBleed exposes 73,932 firewall passwords across 194 countries. Check your exposure with Hudson Rock's free lookup tool today.

June 18, 202610 min read
#131
ACTIVE CAMPAIGN

DragonForce Ransomware Hides C2 in Microsoft Teams: 579 Victims and Counting

DragonForce ransomware hides C2 in Microsoft Teams via Backdoor.Turn. 579 victims, full IOCs, BYOVD drivers, and defensive steps.

June 17, 202610 min read
#130
PATCH BEFORE EOD

3 Critical FortiSandbox Flaws Actively Exploited: Patch to 5.0.6 Now

FortiSandbox unauthenticated RCE CVE-2026-39813 exploited in the wild. Three CVSS 9.1 flaws, no auth needed. Upgrade to 5.0.6 or 4.4.9 to close the gap.

June 16, 202611 min read
#129
MONDAY INTEL DROP

Google Sues Chinese AI Phishing Ring: Gemini Used to Steal $1.9B

Outsider Enterprise used Gemini AI to steal 3.87M cards and $1.9B. Iranian banks hit, 152 Chrome spies caught, ransomware laundering busted.

June 15, 202611 min read
#128
AI WEAPONIZED

Agentjacking: Fake Sentry Errors Hijack AI Coding Agents at 2,388 Organizations

Agentjacking attacks hijack Claude Code, Cursor, and Codex via fake Sentry errors, achieving 85% exploit rate at 2,388 exposed organizations.

June 13, 202610 min read
#127
CLOSE THIS GAP

Oracle PeopleSoft CVE-2026-35273: 100 Organizations Breached, Close PSEMHUB Now

Oracle PeopleSoft CVE-2026-35273 zero-day: ShinyHunters breaches 100+ orgs, CVSS 9.8. Block PSEMHUB and apply Oracle emergency advisory before the weekend.

June 12, 202610 min read
#126
PATCH BEFORE EOD

June 2026 Patch Tuesday: Exchange OWA Zero-Day Exploited 28 Days Before the Patch

June 2026 Patch Tuesday fixes 200 CVEs. CVE-2026-42897 Exchange OWA zero-day was actively exploited for 28 days; RoguePlanet CVSS 9.6 drops same day.

June 11, 202611 min read
#125
YOUR EXPOSURE TODAY

ServiceNow Data Breach: Unauthenticated API Exposes Customer Instance Tables

ServiceNow data breach exposed IT tickets, credentials, and employee records via unauthenticated API queries June 2-3. Audit logs for 51.159.98.241 now.

June 10, 202610 min read
#124
PATCH BEFORE EOD

Check Point VPN Authentication Bypass CVE-2026-50751 Exploited by Qilin Ransomware

Check Point VPN authentication bypass CVE-2026-50751 scores CVSS 9.3. Qilin ransomware is actively exploiting it. Patch before EOD.

June 9, 202610 min read
#123
MONDAY INTEL DROP

44,000 cPanel Servers Compromised: 5 Critical Vulnerabilities to Patch This Monday

cPanel CVE-2026-41940 has compromised 44,000 servers worldwide. Four more critical vulnerabilities demand your Monday morning action.

June 8, 202611 min read
#122
AI WEAPONIZED

LAMEHUG: APT28 Deploys Live LLM to Generate Attack Commands Mid-Operation

LAMEHUG malware gives APT28 a live LLM that generates reconnaissance commands in real time, defeating signature-based detection entirely.

June 6, 202611 min read
#121
CLOSE THIS GAP

Cisco SD-WAN Zero-Day CVE-2026-20245: No Patch, Root Access Active

Cisco SD-WAN zero-day CVE-2026-20245 confirmed actively exploited with no patch. Mandiant found root access attacks on all deployment types. Mitigations inside.

June 5, 202610 min read
#120
YOUR EXPOSURE TODAY

Grindr Dark Web Breach: 15 Million Records Include HIV Status and Location

Grindr data breach dark web listing exposes 15M records including HIV status, GPS coordinates, and password hashes. Check your exposure now.

June 4, 202611 min read
#119
ACTIVE CAMPAIGN

AI-Built Ransomware Toolkit Bypasses 70+ EDR Controls in Live Campaign

AI ransomware toolkit with 80 modules evades Sophos, CrowdStrike, and Defender in a confirmed active campaign. TTPs, IOCs, and defenses inside.

June 3, 202611 min read
#118
PATCH BEFORE EOD

CVE-2026-41089: Windows Netlogon RCE Now Exploited in the Wild

Windows Netlogon RCE CVE-2026-41089 (CVSS 9.8) is actively exploited. Unpatched domain controllers on Server 2012-2025 face SYSTEM-level code execution.

June 2, 202610 min read
#117
MONDAY INTEL DROP

4 CISA Patch Deadlines Expire This Week: PAN-OS, Defender, Langflow, and Apex One Actively Exploited

CISA patch deadlines for 4 actively exploited products expire June 1-4. PAN-OS CVE-2026-0257 deadline is today. Here is what to fix first this week.

June 1, 202610 min read
#116
AI WEAPONIZED

Autonomous LLM Agent Drained an Internal Database in 2 Minutes via Marimo CVE-2026-39987

LLM agent post-exploitation via Marimo CVE-2026-39987 exfiltrated a full database in 113 seconds. See the 4-pivot attack chain and detection guidance.

May 30, 202610 min read
#115
CLOSE THIS GAP

CVE-2026-48172: LiteSpeed cPanel Plugin Privilege Escalation Gives Any Tenant Root, CISA Deadline Is Today

LiteSpeed cPanel plugin privilege escalation CVE-2026-48172 lets any tenant run scripts as root. CISA deadline today. Patch to WHM v5.3.1.0 now.

May 29, 202610 min read
#114
ACTIVE CAMPAIGN

JINX-0164 Hits Crypto Firms: AUDIOFIX Steals 51 Wallet Extensions via Fake Recruiter Lures

JINX-0164 cryptocurrency malware targets crypto firms with fake LinkedIn recruiter lures deploying AUDIOFIX to steal 51 wallet extensions. IOCs inside.

May 28, 202611 min read
#113
ACTIVE CAMPAIGN

ShinyHunters Vishing: 40 Million Records Stolen From Charter and 400 Organizations

ShinyHunters vishing SaaS extortion campaign confirmed Charter breach: 40M records stolen. Get TTPs, IOCs, and defensive steps now.

May 27, 202613 min read
#112
PATCH BEFORE EOD

SonicWall SSL-VPN CVE-2024-12802: Your Firmware Update Left 6 Steps Undone

SonicWall SSL-VPN MFA bypass CVE-2024-12802 persists on Gen6 after firmware update. Akira operators reach file servers in 30 min. Fix all 6 steps now.

May 26, 202611 min read
#111
MONDAY INTEL DROP

Megalodon Supply Chain Attack Hit 5,561 GitHub Repos: Your Monday Intel Rundown

Megalodon supply chain attack infected 5,561 GitHub repos in 6 hours. MiniPlasma Windows zero-day, Defender CISA KEV June 3, and 120-CVE Patch Tuesday.

May 25, 202610 min read
#110
AI WEAPONIZED

Silver Fox AI Phishing Deploys ABCDoor: 1,600+ Attacks Confirmed

Silver Fox AI phishing attack used tax-themed lures to deploy ABCDoor backdoor across industrial and retail sectors. 1,600+ emails confirmed.

May 23, 202611 min read
#109
CLOSE THIS GAP

Microsoft Defender Zero-Day CVE-2026-41091: Close This Gap Now

Microsoft Defender zero-day CVE-2026-41091 lets attackers reach SYSTEM. CISA added both CVEs to KEV on May 20. Patch now.

May 22, 202611 min read
#108
YOUR EXPOSURE TODAY

TanStack Supply Chain Attack: 160 npm Packages Expose Developer Credentials to Dark Web

TanStack npm supply chain attack stole developer credentials from 160 packages. AWS, GitHub, and Kubernetes secrets are on the dark web now.

May 21, 202610 min read
#107
ACTIVE CAMPAIGN

The Gentlemen Ransomware: 332 Victims in 5 Months and Your FortiGate Is the Target

The Gentlemen ransomware active campaign has hit 332 victims in 5 months via FortiGate CVE exploitation. Get full IOCs, TTPs, and defensive steps.

May 20, 202611 min read
#106
PATCH BEFORE EOD

CVE-2026-20182: Cisco SD-WAN CVSS 10 Authentication Bypass Exploited in the Wild

Cisco SD-WAN authentication bypass CVE-2026-20182 scores CVSS 10.0 with CISA KEV status and active exploitation by UAT-8616. No workaround, patch now.

May 19, 202610 min read
#105
MONDAY INTEL DROP

Weekly Cybersecurity Threat Roundup May 2026: 5 Active Exploits Demand Monday Action

Weekly cybersecurity threat roundup May 18: Palo Alto root RCE, Exchange CISA KEV, Linux privesc, and 275M Canvas breach demand Monday action.

May 18, 202611 min read
#104
KNOW YOUR ENEMY

CyberAv3ngers: The IRGC Unit Operating Inside US Water and Energy Infrastructure Right Now

CyberAv3ngers IRGC group exploits Rockwell PLCs across US critical infrastructure. Here is how they operate and how to detect them.

May 17, 202611 min read
#103
AI WEAPONIZED

AI Built the First Zero-Day That Bypasses 2FA: Inside Google's Interception of a Mass Attack

AI-built zero-day exploit targeting 2FA intercepted by Google GTIG before mass deployment. Here is what every security team must check today.

May 16, 202611 min read
#102
CLOSE THIS GAP

NGINX Rift CVE-2026-42945: 18-Year Flaw Opens Every Rewrite Server to Root-Level RCE

NGINX Rift CVE-2026-42945 exposes every nginx server running rewrite rules to unauthenticated heap corruption. Patch to 1.30.1 now.

May 15, 202611 min read
#101
YOUR EXPOSURE TODAY

16 Billion Credentials Leaked: Check Your Dark Web Exposure Before Attackers Do

16 billion stolen credentials circulate across 30 dark web databases covering Google, Apple, Facebook, and enterprise VPNs. Check your corporate exposure now.

May 14, 202610 min read
#100
ACTIVE CAMPAIGN

Nitrogen Ransomware Hits Foxconn: 8TB of Supply Chain Schematics Stolen from North American Factories

Nitrogen ransomware breached Foxconn's North American factories, stealing 8TB of hardware schematics for Apple, NVIDIA, Google, and Intel. Active campaign confirmed May 2026.

May 13, 202610 min read
#99
PATCH BEFORE EOD

SAP Commerce Cloud RCE and S/4HANA SQLi (CVSS 9.6): Patch Before EOD Today

SAP Commerce Cloud CVE-2026-34263 allows unauthenticated RCE via Spring Security misconfiguration. SAP S/4HANA CVE-2026-34260 SQL injection under active attack. Both CVSS 9.6.

May 12, 202610 min read
#98
MONDAY INTEL DROP

3 Critical Threats This Week: Ivanti EPMM Zero-Day, DAEMON Tools Supply Chain, Trellix Breach

Ivanti EPMM zero-day CVE-2026-6973 actively exploited, CISA deadline passed May 10. DAEMON Tools RAT and Trellix source code breach complete this week.

May 11, 202612 min read
#97
KNOW YOUR ENEMY

Water Saci's TCLBANKER Worm Hits 59 Financial Platforms via WhatsApp and Outlook

Water Saci TCLBANKER banking trojan targets 59 Brazilian financial platforms via WhatsApp and Outlook worms. Full threat actor profile, IOCs, and detection guide.

May 10, 202610 min read
#96
AI WEAPONIZED

AI-Assisted OT Attack: How Claude Guided Hackers to Water Utility SCADA Systems

AI-assisted OT attack used Claude AI to identify SCADA systems in Mexico water utility. BACKUPOSINT's 49 modules show how LLMs enable OT intrusions.

May 9, 202611 min read
#95
CLOSE THIS GAP

CVE-2026-0300: Palo Alto PAN-OS Root RCE Actively Exploited, Patches Arrive May 13

CVE-2026-0300 allows unauthenticated root RCE on PAN-OS firewalls. 67 instances exposed on Shodan. No patch until May 13.

May 8, 202610 min read
#94
YOUR EXPOSURE TODAY

ShinyHunters Canvas LMS Breach: 275 Million Students' Data at Risk of Public Leak Tomorrow

ShinyHunters breached Canvas LMS and stole 3.65 TB of data from 275 million students at 9,000 schools, full public release threatened May 8.

May 7, 202610 min read
#93
PATCH BEFORE EOD

Android CVE-2026-0073: Zero-Click RCE Threatens 3.9 Billion Devices, Patch Now

Android CVE-2026-0073 is a critical zero-click RCE in the ADB daemon affecting Android 14, 15, and 16. Apply the May 2026 patch before exploitation begins.

May 5, 202610 min read
#92
MONDAY INTEL DROP

CVE-2026-31431 Copy Fail Exploit Is Public: 5 Threats to Patch This Week

CVE-2026-31431 Linux privilege escalation hits CISA KEV with May 15 deadline. Fortinet CVSS 9.1, Liberty Mutual breach, Chrome exploit covered.

May 4, 202612 min read
#91
KNOW YOUR ENEMY

UNC5221 BRICKSTORM: China's APT Hides 393 Days Inside Law Firms and SaaS Providers

UNC5221 BRICKSTORM backdoor averages 393 days undetected in US legal firms and SaaS providers. Full TTP profile and VMware vCenter detection guide inside.

May 3, 202610 min read
#90
AI WEAPONIZED

AI-Generated Slopoly Malware: Hive0163 Maintains 7-Day Dwell in Live Ransomware Attacks

AI-generated malware Slopoly proves Hive0163 weaponized LLMs for a live ransomware C2. 7-day dwell before Interlock payload. Here's how to detect it.

May 2, 202610 min read
#89
CLOSE THIS GAP

cPanel Zero-Day Exploits 1.5M Servers: 5 Critical Threats to Patch This Week

cPanel CVE-2026-41940 authentication bypass hits 1.5M exposed servers. Plus Snow malware via Teams, LiteLLM SQL injection, ShinyHunters at 40 orgs. Patch now.

May 1, 202612 min read
#88
ACTIVE CAMPAIGN

BlueNoroff Deepfake Zoom Attack: 100 Crypto Executives Compromised in 5 Minutes

BlueNoroff's fake Zoom campaign has compromised 100 crypto and Web3 executives using AI deepfakes and ClickFix. Full IOC list and detection guide inside.

April 30, 202610 min read
#87
ACTIVE CAMPAIGN

ShinyHunters Hit Medtronic and ADT: 14.5M Records Stolen via AI Vishing and Salesforce

ShinyHunters stole 14.5M records from Medtronic and ADT this week using AI vishing to bypass MFA then pivoting through Salesforce. Here's how to protect your org now.

April 29, 202610 min read
#86
PATCH BEFORE EOD

APT28 Exploits Windows Shell Flaw to Steal NTLMv2 Hashes in Zero-Click Attacks

CVE-2026-32202 Windows Shell spoofing lets APT28 steal NTLMv2 hashes via zero-click LNK files, patch now or block outbound SMB.

April 28, 202610 min read
#85
ACTIVE CAMPAIGN

BlackFile Extortion Group: 7-Figure Ransoms Hit Retail Via Vishing MFA Bypass

BlackFile ransomware vishing hits retail with MFA bypass and Salesforce API theft, seven-figure ransoms, 21 IOCs, and defense playbook inside.

April 27, 202611 min read
#84
KNOW YOUR ENEMY

GopherWhisper: China's New APT Hides 7 Backdoors Inside Slack, Discord and Outlook

GopherWhisper APT: China-aligned group routes all C2 through Slack, Discord and Outlook, 7 Go backdoors, government targets, dozens of victims.

April 26, 202612 min read
#83
YOUR EXPOSURE TODAY

France's ID Agency Breach: 11.7M Citizens' Identity Records Now for Sale

France Titres ANTS data breach confirmed: 11.7M citizen identity records stolen and listed for sale on dark web. What was taken and what to do.

April 25, 202610 min read
#82
MONDAY INTEL DROP

FIRESTARTER Backdoor Survives Patches: 5 Critical Threats This Week

FIRESTARTER backdoor persists on Cisco ASA past patches, 6+ months undetected. Plus BlueHammer zero-day and 8 CISA KEV additions this week.

April 24, 202612 min read
#81
CLOSE THIS GAP

Cisco SD-WAN Manager: 3 CVEs Chain to Full Credential Theft, CISA Deadline Was Today

Cisco SD-WAN Manager CVE-2026-20133 chains with 2 more CVEs to expose credentials unauthenticated, 500+ devices reachable. CISA deadline was today.

April 23, 202610 min read
#80
YOUR EXPOSURE TODAY

ShinyHunters Breached Amtrak via Salesforce, 2.1M Passenger Records Confirmed in HIBP

ShinyHunters stole 9.4M records from Amtrak's Salesforce via infostealer credentials. Ransom deadline passed April 14, 2.1M passenger emails now confirmed in Have I Been Pwned.

April 19, 202610 min read
#79
ACTIVE CAMPAIGN

Anubis RaaS Stole 2TB from Brockton Hospital, Chemo Canceled, ER on Divert

Anubis RaaS hit Signature Healthcare April 6, 2TB stolen, ER diverted, chemo canceled. 70+ victims globally. Full TTPs and defense playbook.

April 18, 202611 min read
#78
KNOW YOUR ENEMY

CyberAv3ngers Breached 75+ US Water & Energy PLCs, And They're Still Inside

CyberAv3ngers: Iran's IRGC-linked APT inside US water, energy and government PLCs, CVE-2021-22681 CVSS 9.8 has no patch and they are escalating.

April 18, 202612 min read
#77
PATCH BEFORE EOD

Adobe Acrobat Zero-Day Silently Exploited for 5 Months Before Emergency Patch

Adobe Acrobat Reader CVE-2026-34621: prototype pollution zero-day exploited by APT for 5 months before emergency patch APSB26-43.

April 18, 20269 min read
#76
AI WEAPONIZED

5 APT Groups Deploy AI Malware That Writes Its Own Code Mid-Attack

Google GTIG confirms HONESTCUE and PROMPTSTEAL in active deployment, AI malware that generates fileless code via Gemini mid-execution, evading every static signature.

April 18, 202610 min read
#75
MONDAY INTEL DROP

5 Threats Defenders Can't Ignore This Week: Two Unpatched Windows LPEs Already Being Exploited

Two unpatched Windows LPE zero-days are actively exploited with no patch. Plus Payouts King QEMU ransomware, CISA's 6 new KEVs, and Cisco 9.9 flaws.

April 17, 202614 min read
#74
YOUR EXPOSURE TODAY

Booking.com Breach Exposes Millions: Storm-1865 ClickFix Attack Hit 170 Hotel Partners

Storm-1865 used ClickFix malware to compromise 170+ hotel partners and steal Booking.com reservation data. Reservation hijack scams surge.

April 17, 20269 min read
#73
MONDAY INTEL DROP

This Week's 4 Must-Patch Threats: FortiClient EMS Zero-Day to Rockstar's 78M Breach

FortiClient EMS CVE-2026-35616 pre-auth RCE exploited before advisory. Plus Rockstar 78M breach, Operation PowerOFF, and CISA KEV additions.

April 17, 202614 min read
#72
CLOSE THIS GAP

CVE-2026-33032: 2,689 nginx Servers Exposed to Full Takeover Without a Password

CVE-2026-33032 (MCPwn) gives unauthenticated attackers full nginx server takeover via a missing middleware call. 2,689 instances exposed.

April 16, 202610 min read
#71
CLOSE THIS GAP

108 Chrome Extensions in Google's Official Store Are Stealing OAuth2 Tokens. All of Them Are Still Available to Download.

108 malicious Chrome extensions steal Google OAuth2 tokens from 20,000 users. All linked to one C2. All still live in the Chrome Web Store.

April 16, 202611 min read
#70
YOUR EXPOSURE TODAY

ShinyHunters Listed 45 Million Salesforce Records From McGraw-Hill on a Dark Web Portal. The Deadline Passed Yesterday.

ShinyHunters listed McGraw-Hill on their dark web extortion portal claiming 45 million Salesforce records containing PII. McGraw-Hill confirmed the breach on April 14, 2026, the same day the ransom deadline expired, characterising it as 'limited and non-sensitive.' ShinyHunters also hit Rockstar Games, Hims & Hers, and the European Commission in 2026. The root cause: a Salesforce misconfiguration affecting multiple tenants. Full breakdown of the attack model, ShinyHunters' 2026 campaign, and what organisations on Salesforce need to do today.

April 15, 202612 min read
#69
PATCH BEFORE EODFeatured

Microsoft Patched 167 Vulnerabilities Today. One CVE Has Been Exploited Since December.

April 2026 Patch Tuesday is the second-largest in Microsoft's history: 167 CVEs, 2 zero-days, and an Adobe Acrobat Reader flaw actively exploited by an APT-linked actor since at least November 2025. CVE-2026-34621 and CVE-2026-32201 are on CISA's KEV catalog today. BlueHammer (CVE-2026-33825) had a working public PoC before the patch. Here's the full priority triage, attack chain details, and a six-step action list.

April 14, 202616 min read
#68
ACTIVE CAMPAIGN

North Korea Hid 1,700 Malicious Packages Inside Your Dev Team's Tools

Socket Security has documented 1,700+ malicious packages tied to North Korea's Contagious Interview campaign across five package ecosystems. Separately, UNC1069 compromised the Axios npm maintainer via social engineering, injecting a backdoor into a library present in an estimated 80% of cloud environments. Here's the full attack chain, WAVESHAPER.V2 IOCs, and what to do now.

April 10, 202614 min read
#67
PATCH BEFORE EOD

Chrome's 4th Zero-Day of 2026 Was Already in the Wild

Google shipped an emergency patch for CVE-2026-5281, a use-after-free in Chrome's Dawn/WebGPU component confirmed exploited in the wild. CISA added it to KEV the next day with an April 15 deadline. Here's what happened, why renderer-compromise-required is not reassuring, and what your fleet needs right now.

April 9, 202610 min read
#66
ACTIVE CAMPAIGN

Qilin Found a Way to Blind Your EDR Before You Know They're Inside

Cisco Talos and Trend Micro confirm Qilin ransomware is using BYOVD to systematically disable 300+ EDR products before deploying ransomware. Here's the full attack chain and what to do about it.

April 8, 202612 min read
#65
CVE REFERENCE

CVE-2025-0282: Ivanti Connect Secure Stack Overflow Zero-Day RCE

CVE-2025-0282 is a critical stack-based buffer overflow in Ivanti Connect Secure (versions before 22.7R2.5), Policy Secure, and Neurons for ZTA Gateways, disclosed January 2025. Exploited as a zero-day by UNC5337 (linked to the 2024 ArcaneDoor actor UNC5221), the flaw allows unauthenticated remote code execution on the VPN gateway. Mandiant confirmed exploitation in the wild beginning mid-December 2024. CVSS 9.0.

January 8, 202510 min read
#64
CVE REFERENCE

CVE-2024-12356: BeyondTrust PRA and RS Command Injection, Used to Breach the US Treasury

CVE-2024-12356 is a critical command injection vulnerability in BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) patched in December 2024. An unauthenticated attacker can inject operating system commands via a vulnerable API endpoint. The flaw was exploited by a Chinese state-sponsored actor to compromise a BeyondTrust SaaS instance and subsequently breach the US Treasury Department's Office of Foreign Assets Control (OFAC). CVSS 9.8.

December 17, 202410 min read
#63
CVE REFERENCE

CVE-2024-47575 Explained: Fortinet FortiManager Missing Authentication, FortiJump

CVE-2024-47575 is a CVSS 9.8 missing authentication vulnerability in Fortinet FortiManager (FortiManager Cloud also affected) that allows an unauthenticated remote attacker to execute arbitrary code or commands via specially crafted requests to the FGFM (FortiGate to FortiManager) daemon. Dubbed 'FortiJump' by Mandiant. Exploited as a zero-day by UNC5820, a suspected Chinese state-sponsored actor, targeting managed service providers and enterprise FortiManager deployments. CISA added it to the KEV catalog on October 23, 2024.

October 23, 202411 min read
#62
CVE REFERENCE

CVE-2024-38094: Microsoft SharePoint RCE via Deserialization

CVE-2024-38094 is a deserialization remote code execution vulnerability in Microsoft SharePoint Server patched in July 2024. Site Owner-authenticated attackers can execute arbitrary code on the SharePoint server. Real-world campaigns chained it with a privilege escalation bug to achieve full domain compromise. CISA added it to the Known Exploited Vulnerabilities catalog in October 2024.

July 9, 20249 min read
#61
CVE REFERENCE

CVE-2024-6387 Explained: regreSSHion OpenSSH Signal Handler Race Condition

CVE-2024-6387, dubbed regreSSHion by Qualys, is a signal handler race condition in OpenSSH's sshd daemon affecting versions 8.5p1 through 9.7p1 on glibc-based Linux. An unauthenticated attacker can exploit the race condition to achieve remote code execution as root. The vulnerability is a regression of CVE-2006-5051, which was fixed in 2006 and inadvertently reintroduced in OpenSSH 8.5p1 in 2021.

July 1, 202412 min read
#60
CVE REFERENCE

CVE-2024-37085 Explained: VMware ESXi Active Directory Authentication Bypass

CVE-2024-37085 is an authentication bypass (CVSS 6.8) in VMware ESXi that allows a domain user who is a member of an Active Directory group named 'ESX Admins' to gain full administrative access to the ESXi hypervisor, regardless of whether that group was explicitly configured for ESXi access. Exploited by at least five ransomware groups (Black Basta, Akira, Medusa, RansomHub, and Scattered Spider) to target ESXi hosts directly, encrypting VM storage files and achieving mass disruption across virtualised environments.

June 25, 202411 min read
#59
CVE REFERENCE

CVE-2024-30078: Windows Wi-Fi Driver Over-The-Air RCE

CVE-2024-30078 is a remote code execution vulnerability in the Windows Wi-Fi driver patched in June 2024. An unauthenticated attacker on the same Wi-Fi network, or operating a rogue access point the device connects to, can send a crafted wireless frame to achieve kernel-mode code execution with no user interaction. Every unpatched Wi-Fi-capable Windows device in any shared network environment is in scope.

June 11, 20249 min read
#58
CVE REFERENCE

CVE-2024-4577: PHP CGI Argument Injection on Windows

CVE-2024-4577 is a critical PHP argument injection flaw affecting Windows servers running PHP in CGI mode. A Unicode best-fit character mapping quirk allowed attackers to bypass the CVE-2012-1823 patch and execute arbitrary OS commands without authentication. TellYouThePass ransomware operators weaponized it within hours of the June 2024 PoC release. CVSS 9.8.

June 7, 202410 min read
#57
CVE REFERENCE

CVE-2024-20353 & CVE-2024-20359: ArcaneDoor, State-Sponsored Cisco ASA Zero-Days

CVE-2024-20353 and CVE-2024-20359 are two Cisco ASA and FTD zero-day vulnerabilities exploited in the ArcaneDoor espionage campaign by a suspected Chinese state-sponsored actor. The flaws enabled persistent backdoor implants (Line Dancer and Line Runner) on perimeter VPN devices protecting government and critical infrastructure networks across multiple countries. First exploitation observed in November 2023, five months before public disclosure.

April 24, 202412 min read
#56
CVE REFERENCE

CVE-2024-3400 Explained: Palo Alto PAN-OS GlobalProtect Command Injection (CVSS 10.0)

CVE-2024-3400 is a CVSS 10.0 OS command injection in Palo Alto Networks PAN-OS affecting devices with the GlobalProtect gateway or portal enabled. An unauthenticated attacker sends a crafted HTTP request with a malicious SESSID cookie value, achieving root-level remote code execution. Discovered and disclosed April 12, 2024, it was being actively exploited as a zero-day by a state-sponsored threat actor (UTA0218) since at least March 26, 2024.

April 12, 202413 min read
#55
CVE REFERENCE

CVE-2024-1709 Explained: ConnectWise ScreenConnect Authentication Bypass (CVSS 10.0)

CVE-2024-1709 is a CVSS 10.0 authentication bypass in ConnectWise ScreenConnect (< 23.9.8). An extra trailing slash in the URL path bypasses authentication middleware, allowing an unauthenticated attacker to execute the setup wizard and create a new administrator account. Exploited by LockBit, Black Basta, and multiple ransomware groups within 48 hours of disclosure. Affects all ScreenConnect on-premises deployments below version 23.9.8.

February 19, 202411 min read
#54
CVE REFERENCE

CVE-2024-21413: Outlook MonikerLink NTLM Credential Theft

CVE-2024-21413, dubbed 'MonikerLink' by Checkpoint Research, is a critical Microsoft Outlook vulnerability patched in February 2024. A crafted file:// hyperlink with an exclamation mark suffix bypasses Outlook's Protected View, causing Windows to silently authenticate to an attacker's server via NTLMv2, transmitting the victim's Net-NTLMv2 hash with no user interaction beyond opening or previewing the email. CISA added it to KEV after confirmed wild exploitation.

February 13, 202410 min read
#53
CVE REFERENCE

CVE-2024-21762 Explained: Fortinet FortiOS SSL VPN Out-of-Bounds Write (CVSS 9.6)

CVE-2024-21762 is a CVSS 9.6 out-of-bounds write in Fortinet FortiOS and FortiProxy SSL VPN. An unauthenticated remote attacker sends specially crafted HTTP requests to the SSL VPN web management interface, achieving arbitrary code or command execution. CISA added it to the Known Exploited Vulnerabilities catalog on February 9, 2024, one day after disclosure, confirming active exploitation. Over 150,000 Fortinet devices were estimated to be running vulnerable firmware at time of disclosure.

February 8, 202411 min read
#52
CVE REFERENCE

CVE-2024-23897: Jenkins CLI Arbitrary File Read Leading to RCE

CVE-2024-23897 is a critical Jenkins CLI vulnerability allowing unauthenticated arbitrary file reads via the args4j argument parser's @ file expansion feature. Disclosed January 2024, the flaw exposed Jenkins controller filesystems including credential stores and cryptographic keys. In certain configurations, key material exposure escalated to full remote code execution. CISA added it to KEV in February 2024.

January 24, 202410 min read
#51
CVE REFERENCE

CVE-2023-46805 and CVE-2024-21887 Explained: Ivanti Connect Secure Zero-Day Chain

CVE-2023-46805 is an authentication bypass (CVSS 8.2) in Ivanti Connect Secure and Policy Secure. Chained with CVE-2024-21887, a command injection (CVSS 9.1), it produces unauthenticated remote code execution on the VPN gateway. Exploited as a zero-day by suspected Chinese state-sponsored actor UNC5221 for at least two weeks before disclosure. CISA issued Emergency Directive 24-01 ordering federal agencies to disconnect or mitigate within 48 hours. Over 2,100 devices were compromised globally before patches were available.

January 10, 202414 min read
#50
CVE REFERENCE

CVE-2023-46604 Explained: Apache ActiveMQ Remote Code Execution (CVSS 10.0)

CVE-2023-46604 is a CVSS 10.0 deserialization / remote class loading vulnerability in Apache ActiveMQ's OpenWire protocol. An unauthenticated attacker sends a specially crafted ClassInfo message to port 61616, causing the broker to load and execute a Java class from an attacker-controlled HTTP server. Active exploitation by HelloKitty ransomware and Kinsing cryptominer began within days of the advisory. Affects ActiveMQ versions up to 5.15.16, 5.16.7, 5.17.6, and 5.18.3.

October 25, 202311 min read
#49
CVE REFERENCE

CVE-2023-20198 Explained: Cisco IOS XE Web UI Zero-Day and the 50,000-Device Compromise

CVE-2023-20198 is a critical unauthenticated privilege escalation vulnerability in Cisco IOS XE software's web UI feature. Exploited as a zero-day before Cisco published any advisory, attackers used it to create administrator accounts and then chained it with CVE-2023-20273 to deploy a persistent Lua-based implant on over 50,000 network devices. No authentication or user interaction required.

October 16, 202310 min read
#48
CVE REFERENCE

CVE-2023-4966: Citrix Bleed NetScaler Session Hijacking Explained and Fix

CVE-2023-4966, named Citrix Bleed, is a buffer over-read vulnerability in Citrix NetScaler ADC and Gateway that leaks memory contents, including active user session tokens, via unauthenticated HTTP requests. Stolen tokens bypass MFA because they represent already-authenticated sessions. Exploited as a zero-day by LockBit ransomware against Boeing, Comcast Xfinity, and others.

October 10, 202310 min read
#47
CVE REFERENCE

CVE-2023-44487 Explained: HTTP/2 Rapid Reset, The Record-Breaking DDoS Vulnerability

CVE-2023-44487 is the HTTP/2 Rapid Reset vulnerability, a flaw in HTTP/2's stream cancellation mechanism that allows a relatively small number of clients to generate HTTP/2 DDoS attacks far exceeding any previously observed scale. Google sustained a peak of 398 million requests per second; Cloudflare 201 million RPS; AWS observed similar records. The vulnerability affects all HTTP/2 server implementations. Coordinated disclosure on October 10, 2023 was accompanied by patches across major web server projects.

October 10, 202310 min read
#46
CVE REFERENCE

CVE-2023-22515: Atlassian Confluence Broken Access Control Zero-Day Explained and Fixed

CVE-2023-22515 is a maximum-severity broken access control vulnerability in Atlassian Confluence Data Center and Server. An unauthenticated external attacker can reach Confluence's setup endpoint on a fully configured instance and create a new administrator account, gaining complete control without credentials. Microsoft attributed active exploitation to Storm-0062 (a Chinese state-sponsored threat actor) beginning September 14, 2023, three weeks before Atlassian's advisory.

October 4, 202310 min read
#45
CVE REFERENCE

CVE-2023-42793 Explained: JetBrains TeamCity Authentication Bypass (CVSS 9.8)

CVE-2023-42793 is a CVSS 9.8 authentication bypass in JetBrains TeamCity (< 2023.05.4) allowing an unauthenticated attacker to generate an admin-level API token with a single HTTP request. Full remote code execution follows via plugin upload. Exploited by North Korea's Lazarus Group, Russia's COZY BEAR (APT29), and multiple ransomware operators for CI/CD pipeline compromise and software supply chain attacks.

September 6, 202312 min read
#44
CVE REFERENCE

CVE-2023-38831 Explained: WinRAR Remote Code Execution via Crafted Archive

CVE-2023-38831 is a code execution vulnerability in WinRAR (< 6.23). An attacker creates a ZIP archive that displays an innocent filename, such as a PDF or image, but actually maps double-click to a hidden script. When the victim double-clicks the apparent document inside WinRAR, a script executes on their system. Exploited by Russian APT28 (Fancy Bear) and North Korean APT40 in targeted spear-phishing campaigns against financial traders and government officials. Affects all WinRAR versions prior to 6.23.

August 23, 202310 min read
#43
CVE REFERENCE

CVE-2023-3519 Explained: Citrix NetScaler ADC and Gateway Unauthenticated RCE

CVE-2023-3519 is a CVSS 9.8 unauthenticated remote code execution vulnerability in Citrix NetScaler ADC and NetScaler Gateway (formerly Citrix ADC / Citrix Gateway). Exploited as a zero-day before any patch was available, it was used to compromise a US critical infrastructure organization. After patches were released, mass exploitation resulted in over 2,000 backdoored appliances within days. Requires the device to be configured as a Gateway or AAA virtual server.

July 18, 202311 min read
#42
CVE REFERENCE

CVE-2023-36884: Windows Search RCE Used in NATO Summit Attacks

CVE-2023-36884 is a remote code execution vulnerability in Windows Search and Microsoft Office exploited as a zero-day by Russian-nexus group Storm-0978 (RomCom) during the July 2023 NATO summit. Malicious Office documents triggered the flaw without macros or Protected View bypass, targeting NATO member governments. Microsoft disclosed it without a same-day patch, the fix arrived a month later.

July 11, 202311 min read
#41
CVE REFERENCE

CVE-2023-27997: Fortinet FortiGate SSL-VPN Heap Overflow Zero-Day Explained and Fixed

CVE-2023-27997 is a pre-authentication heap buffer overflow in the Fortinet FortiOS SSL-VPN component enabling unauthenticated remote code execution on FortiGate VPN appliances. Exploited as a zero-day before Fortinet's June 2023 advisory, it affects FortiOS 6.0 through 7.2.4 with SSL-VPN enabled. CISA linked related Fortinet exploitation to Chinese state-sponsored actor Volt Typhoon targeting US critical infrastructure.

June 12, 202310 min read
#40
CVE REFERENCE

CVE-2023-34362: MOVEit Transfer SQL Injection, CLOP's Mass Data Extortion Campaign

CVE-2023-34362 is a critical SQL injection vulnerability in Progress MOVEit Transfer that enables unauthenticated remote code execution. Exploited as a zero-day by the CLOP ransomware group beginning May 27, 2023, it was used to breach over 1,000 organizations simultaneously through data exfiltration without encryption. Victims include the US Department of Energy, Shell, British Airways, the BBC, Maximus, and hundreds more.

June 1, 202311 min read
#39
CVE REFERENCE

CVE-2023-32315: Openfire Authentication Bypass Leading to RCE

CVE-2023-32315 is a critical path traversal vulnerability in the Openfire XMPP messaging server admin console (versions 3.10.0 through 4.7.4), patched in May 2023. An unauthenticated attacker can access the admin console setup wizard by bypassing the authentication filter via a URL path traversal, then upload a malicious Openfire plugin containing arbitrary Java code. Over 3,000 servers were compromised in active exploitation campaigns observed through mid-2023.

May 23, 20239 min read
#38
CVE REFERENCE

CVE-2023-28252 Explained: Windows CLFS Driver Zero-Day Used by Nokoyawa Ransomware

CVE-2023-28252 is a zero-day elevation of privilege vulnerability in the Windows Common Log File System (CLFS) kernel driver. A low-privileged attacker exploits a flaw in CLFS log file parsing to escalate to SYSTEM privileges. Discovered being actively used by the Nokoyawa ransomware gang as part of their pre-ransomware deployment privilege escalation chain. Patched on April 11, 2023 Patch Tuesday as a zero-day. CVSS 7.8.

April 11, 202310 min read
#37
CVE REFERENCE

CVE-2023-23397 Explained: The Outlook Zero-Click NTLM Hash Theft Vulnerability

CVE-2023-23397 is a critical privilege escalation and credential theft vulnerability in Microsoft Outlook for Windows. A specially crafted calendar invitation with a UNC path in the reminder sound field causes Outlook to automatically connect to an attacker-controlled SMB server, leaking the victim's NTLM authentication hash. No user interaction is required, the exploit fires when the reminder triggers, even if the meeting invitation is never opened.

March 14, 20239 min read
#36
CVE REFERENCE

CVE-2023-0669 Explained: GoAnywhere MFT Pre-Authentication RCE and the Cl0p Zero-Day Campaign

CVE-2023-0669 is a pre-authentication remote code execution vulnerability in Fortra GoAnywhere MFT (Managed File Transfer). The Cl0p ransomware group exploited it as a zero-day for approximately 10 days before any advisory was published, claiming over 130 victim organisations. The vulnerability allows unauthenticated attackers to execute commands on the GoAnywhere server via a Java deserialization attack against the administrative console. Affected versions: GoAnywhere MFT prior to 7.1.2.

February 1, 202312 min read
#35
CVE REFERENCE

CVE-2022-47966 Explained: Zoho ManageEngine Unauthenticated RCE via SAML (CVSS 9.8)

CVE-2022-47966 is a CVSS 9.8 unauthenticated RCE vulnerability affecting up to 24 Zoho ManageEngine products. It exploits a vulnerable Apache Santuario (XML Security for Java) component in the SAML SSO implementation, allowing an attacker to execute arbitrary code on any ManageEngine server where SAML-based single sign-on is or was enabled. Exploited by APT41 and other nation-state actors within weeks of the January 2023 disclosure. Affects products widely deployed in enterprise IT management: ServiceDesk Plus, Desktop Central, OpManager, and more.

January 10, 202311 min read
#34
CVE REFERENCE

CVE-2022-41040 and CVE-2022-41082 Explained: ProxyNotShell, the Microsoft Exchange Chain

CVE-2022-41040 and CVE-2022-41082, collectively called ProxyNotShell, are chained vulnerabilities in Microsoft Exchange Server 2013, 2016, and 2019. CVE-2022-41040 is a server-side request forgery flaw that, when chained with CVE-2022-41082, enables an authenticated attacker to achieve remote code execution. Both were exploited in the wild before Microsoft released patches.

September 29, 202210 min read
#33
CVE REFERENCE

CVE-2022-3236: Sophos Firewall Code Injection Zero-Day

CVE-2022-3236 is a critical code injection vulnerability in the User Portal and Webadmin interfaces of Sophos Firewall versions 19.5 MR3 and older. Exploited as a zero-day by a Chinese APT (Storm Cloud / Volt Typhoon cluster), the flaw enabled unauthenticated root-level code execution on internet-facing firewall appliances. Sophos delivered an automatic hotfix but it required manual intervention on restricted networks, leaving many deployments exposed.

September 23, 20229 min read
#32
CVE REFERENCE

CVE-2022-30190 Explained: Follina, the Zero-Click Microsoft Office RCE

CVE-2022-30190 (Follina) is a critical RCE vulnerability in the Microsoft Support Diagnostic Tool (MSDT) triggered via the ms-msdt:// URI scheme from within a malicious Office document. Attackers achieve code execution with no macro prompts, and in some configurations previewing the file in Windows Explorer alone triggers the exploit.

June 14, 20228 min read
#31
CVE REFERENCE

CVE-2022-26134 Explained: Confluence Server Critical OGNL Zero-Day

CVE-2022-26134 is a critical OGNL injection vulnerability in Atlassian Confluence Server and Data Center, enabling unauthenticated remote code execution. Disclosed as a zero-day on June 2, 2022 with active exploitation already confirmed, this vulnerability scores 10.0 CVSS. Within hours of technical details becoming public, mass scanning and exploitation began across the internet.

June 2, 20229 min read
#30
CVE REFERENCE

CVE-2022-26923: Certifried, AD Certificate Services Domain Privilege Escalation

CVE-2022-26923 (Certifried) is a privilege escalation vulnerability in Active Directory Certificate Services (AD CS) patched in May 2022. A domain user with the ability to create or modify machine accounts can request a certificate that impersonates a Domain Controller, then use that certificate in a Kerberos PKINIT authentication to obtain a TGT with domain admin-equivalent privileges. CVSS 8.8.

May 10, 202210 min read
#29
CVE REFERENCE

CVE-2022-1388: F5 BIG-IP iControl REST Authentication Bypass Explained and Fix

CVE-2022-1388 is a critical authentication bypass vulnerability in the F5 BIG-IP iControl REST management API. Unauthenticated attackers with network access to the management interface can execute arbitrary OS commands as root by manipulating HTTP headers to bypass the API authentication layer. Mass exploitation began within 24 hours of F5's advisory. CISA and FBI issued a joint advisory warning of active exploitation.

May 4, 20229 min read
#28
CVE REFERENCE

CVE-2022-22965 Explained: Spring4Shell, the Spring Framework RCE Vulnerability

CVE-2022-22965 (Spring4Shell) is a critical remote code execution vulnerability in the Spring Framework's data binding component. By manipulating HTTP request parameters to abuse Java's ClassLoader mechanism, an attacker can write a JSP web shell to a Tomcat-served directory and achieve persistent remote code execution. Affects Spring Framework 5.3.x before 5.3.18 and 5.2.x before 5.2.20 running on JDK 9+.

March 31, 202210 min read
#27
CVE REFERENCE

CVE-2022-0847: Dirty Pipe Linux Kernel Vulnerability Explained and How to Fix It

CVE-2022-0847, named Dirty Pipe, is a Linux kernel vulnerability allowing any unprivileged local user to write to arbitrary read-only files and achieve root privilege escalation. Unlike the 2016 Dirty Cow vulnerability it resembles, Dirty Pipe requires no race condition, it is deterministic and reliable. Affects Linux kernels 5.8 through 5.16.10 and was quickly weaponized for container escapes and Android rooting.

March 7, 20229 min read
#26
CVE REFERENCE

CVE-2021-4034: PwnKit Polkit Vulnerability Explained, Root Access on Every Linux System for 12 Years

CVE-2021-4034, named PwnKit by Qualys, is an out-of-bounds write vulnerability in pkexec, a SUID-root binary part of the polkit framework installed by default on virtually every Linux distribution. Any local unprivileged user can exploit it to gain root without any sudo permissions, without knowing any password, and without triggering standard auth log entries. Present since May 2009.

January 25, 20229 min read
#25
CVE REFERENCE

CVE-2021-44228 Explained: Log4Shell, the Most Critical Vulnerability in a Decade

CVE-2021-44228, Log4Shell, is a critical remote code execution vulnerability in Apache Log4j 2 scoring a perfect 10.0 CVSS. A single malicious string sent to any log field triggers JNDI injection, allowing an attacker to execute arbitrary code on the vulnerable server with no authentication required.

December 15, 202112 min read
#24
CVE REFERENCE

CVE-2021-42287 & CVE-2021-42278: noPac, Domain User to Domain Admin in Seconds

CVE-2021-42287 and CVE-2021-42278 are Active Directory privilege escalation vulnerabilities patched in November 2021. Chained together in the 'noPac' exploit, they allowed any authenticated domain user to impersonate a Domain Controller via Kerberos, obtaining a TGT with domain admin-equivalent privileges, a complete Active Directory takeover from a standard user account with no additional tooling beyond a domain login.

December 14, 202111 min read
#23
CVE REFERENCE

CVE-2021-22005: VMware vCenter Unauthenticated File Upload RCE

CVE-2021-22005 is a critical unauthenticated file upload vulnerability in VMware vCenter Server's CEIP analytics service. Disclosed September 2021, it allowed any attacker with network access to the vCenter HTTPS interface to upload an arbitrary file and achieve remote code execution as the vCenter service account, effectively granting control of every managed virtual machine. Mass exploitation began within 48 hours of disclosure.

September 21, 202110 min read
#22
CVE REFERENCE

CVE-2021-40444 Explained: The MSHTML Remote Code Execution Vulnerability

CVE-2021-40444 is a remote code execution vulnerability in the MSHTML (Trident) browser engine built into Windows. A malicious Office document embedding a specially crafted ActiveX control causes MSHTML to download and execute a malicious DLL from an attacker-controlled server. No macros are used. No Enable Content prompt appears. The exploit was used in targeted attacks before Microsoft patched it.

September 7, 20219 min read
#21
CVE REFERENCE

CVE-2021-40539: ManageEngine ADSelfService Plus Authentication Bypass and RCE

CVE-2021-40539 is a critical authentication bypass and remote code execution vulnerability in ManageEngine ADSelfService Plus (versions before build 6114), patched in September 2021. The flaw allowed unauthenticated attackers to access protected REST API endpoints and upload a JSP webshell, achieving code execution on the server. APT41 and at least two other threat actor clusters exploited it against U.S. defense contractors, academic institutions, and critical infrastructure. CVSS 9.8.

September 7, 202110 min read
#20
CVE REFERENCE

CVE-2021-26084 Explained: Confluence Server OGNL Injection and Mass Exploitation

CVE-2021-26084 is a server-side template injection vulnerability in Atlassian Confluence Server and Data Center. An unauthenticated attacker can inject OGNL expressions via query parameters, achieving remote code execution on the Confluence server. The vulnerability was exploited at mass scale within hours of public PoC release, with ransomware groups and nation-state actors among the first adopters.

August 25, 20219 min read
#19
CVE REFERENCE

CVE-2021-34473 Explained: ProxyShell, the Pre-Auth Exchange RCE Chain

CVE-2021-34473 is the first link in the ProxyShell exploit chain, three Microsoft Exchange Server vulnerabilities that together enable unauthenticated remote code execution. Chained with CVE-2021-34523 and CVE-2021-31207, an attacker can reach Exchange's backend PowerShell endpoint without credentials, impersonate any mailbox user, and write arbitrary files to Exchange's web root to deploy a web shell.

July 13, 202111 min read
#18
CVE REFERENCE

CVE-2021-34527 Explained: PrintNightmare and RCE via Windows Print Spooler

CVE-2021-34527 (PrintNightmare) is a critical vulnerability in the Windows Print Spooler service enabling remote code execution with SYSTEM privileges. A proof-of-concept was accidentally published publicly on June 29, 2021, triggering emergency out-of-band patches and immediate mass exploitation.

July 2, 20218 min read
#17
CVE REFERENCE

CVE-2021-21985 Explained: VMware vCenter Server Remote Code Execution

CVE-2021-21985 is a critical remote code execution vulnerability in VMware vCenter Server's vSphere Client web interface. An unauthenticated attacker with network access to vCenter's HTTPS port can send a specially crafted request to the Virtual SAN Health Check plugin, enabled by default, to achieve RCE with root or SYSTEM privileges on the vCenter server. Compromise of vCenter means control over every virtual machine in the managed infrastructure.

May 25, 20219 min read
#16
CVE REFERENCE

CVE-2021-26855 Explained: ProxyLogon and the Microsoft Exchange Mass Exploitation Event

CVE-2021-26855 is a server-side request forgery (SSRF) vulnerability in Microsoft Exchange Server allowing an unauthenticated attacker to bypass authentication and impersonate the Exchange server. Chained with CVE-2021-27065, it achieves pre-authentication RCE. Over 250,000 Exchange servers were compromised within days of public disclosure.

March 10, 202110 min read
#15
CVE REFERENCE

CVE-2021-3156: Baron Samedit Sudo Heap Overflow, Any Local User to Root

CVE-2021-3156, named Baron Samedit, is a heap-based buffer overflow in the sudo utility that allows any unprivileged local user to gain root privileges without authentication, without being listed in the sudoers file, and without any race condition. Present in sudo for nearly 10 years, it affects every major Linux distribution. Qualys developed working exploits for Ubuntu 20.04, 18.04, Debian 10, and Fedora 33 default installations.

January 26, 20219 min read
#14
CVE REFERENCE

CVE-2021-27101 Explained: Accellion FTA SQL Injection and the CLOP Ransomware Campaign

CVE-2021-27101 is a critical SQL injection vulnerability in Accellion FTA (File Transfer Appliance) that allows unauthenticated remote code execution. Exploited by the CLOP ransomware group beginning in December 2020, the vulnerability was used to steal sensitive files from over 100 organizations including government agencies, universities, law firms, and financial institutions, without deploying ransomware encryption.

January 23, 202110 min read
#13
CVE REFERENCE

CVE-2020-14882: Oracle WebLogic Console Authentication Bypass and RCE Explained

CVE-2020-14882 is a critical authentication bypass in the Oracle WebLogic Server web-based administration console. Chained with CVE-2020-14883, it enables unauthenticated remote code execution on one of the most widely deployed Java EE application servers in enterprise environments. Exploitation began within days of Oracle's October 2020 Critical Patch Update and was adopted by nation-state actors and ransomware operators.

October 20, 202010 min read
#12
CVE REFERENCE

CVE-2020-1472 Explained: Zerologon and Instant Active Directory Domain Compromise

CVE-2020-1472 (Zerologon) is a 10.0 CVSS critical vulnerability in the Windows Netlogon Remote Protocol. A cryptographic flaw allows an attacker with network access to a domain controller to set the machine account password to empty, then impersonate the DC to achieve instant domain compromise in approximately 10 seconds.

September 14, 20209 min read
#11
CVE REFERENCE

CVE-2020-1350: SigRed, The Wormable Windows DNS Server RCE

CVE-2020-1350 (SigRed) is a critical wormable remote code execution vulnerability in Windows DNS Server discovered by Check Point Research and patched in July 2020. A crafted DNS response can trigger a heap overflow in dns.exe, granting SYSTEM-level code execution on any Windows Server configured as a DNS resolver, with no authentication and no user interaction required. CVSS 10.0.

July 14, 202010 min read
#10
CVE REFERENCE

CVE-2020-5902 Explained: F5 BIG-IP TMUI Remote Code Execution

CVE-2020-5902 is a critical remote code execution vulnerability in the F5 BIG-IP Traffic Management User Interface (TMUI). An unauthenticated attacker with network access to the TMUI can execute arbitrary system commands, create or delete files, enable or disable services, and fully compromise the BIG-IP device. With a CVSS score of 10.0, this vulnerability was exploited within hours of F5's advisory.

July 1, 20209 min read
#09
CVE REFERENCE

CVE-2020-0796 Explained: SMBGhost, the Wormable Windows 10 Kernel Vulnerability

CVE-2020-0796 (SMBGhost) is an integer overflow vulnerability in the SMBv3 compression feature introduced in Windows 10 1903. An unauthenticated attacker can achieve remote code execution in kernel context by sending a specially crafted compressed SMBv3 packet. No credentials or user interaction are required, making it wormable across any network where port 445 is reachable.

March 12, 202010 min read
#08
CVE REFERENCE

CVE-2019-19781 Explained: Citrix ADC and Gateway Path Traversal RCE

CVE-2019-19781 is a pre-authentication path traversal vulnerability in Citrix ADC (NetScaler ADC) and Citrix Gateway that allows unauthenticated attackers to execute arbitrary OS commands. Exploited at mass scale before patches were released, it was used by nation-state APT groups and ransomware operators to compromise enterprise and government VPN gateways worldwide.

December 17, 201910 min read
#07
CVE REFERENCE

CVE-2019-11510 Explained: Pulse Secure VPN Arbitrary File Read and Credential Theft

CVE-2019-11510 is a pre-authentication arbitrary file read vulnerability in Pulse Connect Secure VPN appliances. An unauthenticated attacker can retrieve the VPN's configuration file and stored credentials, including plaintext passwords and cached Active Directory credentials, from any affected device reachable on the internet. Widely exploited by ransomware groups, APTs, and credential brokers.

August 22, 201910 min read
#06
CVE REFERENCE

CVE-2018-13379 Explained: Fortinet FortiGate VPN Path Traversal and Credential Exposure

CVE-2018-13379 is a pre-authentication path traversal vulnerability in the Fortinet FortiOS SSL VPN web portal. An unauthenticated attacker can read system files from the VPN appliance by crafting a malicious URL, including session files that contain plaintext credentials. Credentials from over 87,000 FortiGate devices were published publicly in 2021, many from devices patched but with credentials never rotated.

May 24, 20199 min read
#05
CVE REFERENCE

CVE-2019-0708 Explained: BlueKeep, the Wormable RDP Vulnerability in Legacy Windows

CVE-2019-0708 (BlueKeep) is a critical pre-authentication RCE vulnerability in Windows Remote Desktop Services affecting Windows XP, Vista, 7, and Server 2003/2008. Like EternalBlue, it is wormable, requiring no credentials or user interaction, and was rated 9.8 CVSS by NVD.

May 14, 20198 min read
#04
CVE REFERENCE

CVE-2017-0144 Explained: EternalBlue, the NSA Exploit Behind WannaCry and NotPetya

CVE-2017-0144 is the SMBv1 remote code execution vulnerability exploited by the EternalBlue exploit, originally developed by the NSA and leaked by the Shadow Brokers in April 2017. It powered both WannaCry and NotPetya, two attacks that caused a combined $30+ billion in global damages.

May 15, 201711 min read
#03
CVE REFERENCE

CVE-2017-5638 Explained: The Apache Struts Flaw Behind the Equifax Breach

CVE-2017-5638 is a remote code execution vulnerability in Apache Struts 2's Jakarta Multipart parser. By injecting an OGNL expression into the Content-Type header of an HTTP POST request, an unauthenticated attacker can execute arbitrary OS commands. The vulnerability was actively exploited to breach Equifax, exposing 147 million records.

March 7, 201711 min read
#02
CVE REFERENCE

CVE-2014-6271: Shellshock Bash Vulnerability Explained, Exploit, and Mitigation

CVE-2014-6271, known as Shellshock, is a remote code execution vulnerability in GNU Bash where function definitions stored in environment variables execute appended commands at shell startup. Any service passing attacker-controlled data through environment variables into Bash, primarily CGI-based web applications, is exploitable without authentication via a single HTTP request. Affected an estimated 500 million systems at disclosure.

September 24, 201411 min read
#01
CVE REFERENCE

CVE-2014-0160 Explained: Heartbleed and the Vulnerability That Broke the Internet

CVE-2014-0160 (Heartbleed) is a critical information disclosure vulnerability in OpenSSL 1.0.1 through 1.0.1f. It allows attackers to read up to 64KB of server memory per request, including private SSL keys, session cookies, and credentials, with zero authentication and no server-side logging.

April 7, 201410 min read