Home › Weekly Digests › This Week
LiveThreat Threat Intelligence

Weekly Threat Intelligence Digest — Aug 24 to Aug 31, 2026

Weekly threat intelligence digest from 365 items (49 critical, 239 high).

August 31, 2026 365 articles analyzed
LIVETHREAT WEEKLY THREAT DIGEST August 24 – August 31, 2026 This week the threat landscape crystallized around one simple fact: attackers are bypassing the perimeter by hijacking the privileges of the services we trust. Critical RCE bugs in Zimbra, PaperCut, Keycloak and cPanel were weaponized within days, while supply‑chain poisonings of Gitea, npm and ownCloud turned development pipelines into launch pads. At the same time, credential‑as‑a‑service kits (NovaCookies, leaked Stripe keys) turned a single exposed secret into billions of dollars of fraud. The convergence of privileged‑access abuse, supply‑chain contamination, and secret leakage means every control‑assurance program now faces a multi‑vector exposure. 👉 Access, not just vulnerability, is the dominant risk driver. 🚨 EXECUTIVE RISK SNAPSHOT * Supply‑chain is the entry point → MSPs, CI/CD tools, and SaaS admin consoles were primary compromise paths. * Privilege determines impact → One hijacked admin or service‑account led to >5 TB exfiltrated and ransomware across multiple governments. * Untracked assets = blind spots → OT/IoT devices and third‑party cloud assets remain outside most audit inventories, enabling botnet creation and prolonged dwell. 🔍 WHAT CHANGED THIS WEEK * Critical RCE flaws in widely‑used SaaS (Zimbra, PaperCut, Keycloak, cPanel) are being actively exploited within days of public disclosure. * Open‑source supply‑chain poisoning has scaled – Shai‑Hulud and Gitea exploits affected >1,000 organizations, proving that a compromised dev tool can cascade to production. * Credential‑as‑a‑service kits are commoditized; NovaCookies and public Stripe key dumps translate stolen tokens into immediate financial loss. * AI‑driven autonomous agents (Hugging Face, OpenAI) demonstrated lateral movement, blurring the line between automated testing and real attacks. 🎯 WHERE YOU ARE MOST LIKELY EXPOSED * Unpatched Zimbra Collaboration Suite or other email servers under your domain. * Legacy service‑account passwords or hard‑coded API keys in cloud data‑warehouses (Snowflake) or public GitHub repos (Stripe, Iterable). * Open‑source CI/CD components – Gitea, npm packages, ownCloud – that feed your production pipelines. * Cloud‑hosted SaaS admin consoles (ServiceNow, Keycloak, cPanel) where privileged reset flows are exposed. * Connected IoT/OT devices (Android car head‑units, Chinese‑made routers) still running default firmware or undocumented backdoors. ⚡ WHAT COMPLIANCE & SECURITY LEADERS SHOULD DO THIS WEEK 1. Re‑assess privileged‑access inventory for all third‑party SaaS and cloud service accounts. • Map each account to NIST PR.AC‑1 and SOC 2 CC6.1. 👉 Ask: “Can we produce MFA logs and least‑privilege evidence for every admin today?” #TrustOperations #NISTCSF #ControlAssurance #Cybersecurity #ThreatIntel #ContinuousMonitoring #LiveThreat #VerisqAI

Articles Referenced in This Digest 365 items

Advisory (51)

HighTrump Targets Foreign Technology in New U.S. Power Grid Security Order
HighWhite House bans foreign-made equipment for power generation over cyber backdoor concerns
HighCISA Adds Three Known Exploited Vulnerabilities to Catalog
HighNew Instagram and Facebook rules set a default two-hour limit for teens
HighMicrosoft rolls out fix for Windows 11 crashes, gaming issues
HighPaperCut warns of NG, MF flaw exploited in zero-day attacks
HighHow Facebook and Instagram will change after Meta's $18B settlement - and where the money is going
HighPCI DSS 4.0.1: Application Requirements You’re Being Assessed On in 2026
HighMeta to Pay Up to $18B Over Teen Social Media Use
HighUS Navy tells sailors and their families: scrub your social media, enemies are watching
HighCISA Adds Six Known Exploited Vulnerabilities to Catalog
HighCISA Vulnerability Review
HighHow to sideload Android apps on your phone in 2026 - and what's behind the changes
HighA Tale of Two SOCs: Insights From Two Red Team Assessments
HighWhen the Algorithm Fires You: Uber Faces €825M Fine
HighA Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw
HighNew Zealand to pursue social media ban for children under 16
HighGerman Cyber Agency Warns Fingerprints Can Be Spoofed
HighMicrosoft Exchange Server SE CU1 Delayed Amid AI-Assisted Security Reviews
HighMicrosoft: August updates break printing, PDF export in WPF apps
MediumTreasury Launches Quantum Task Force for Financial Sector
MediumWhatsApp Just Added 3 New Ways to Protect Your Account
MediumWho Has Admin Rights in your Entra ID Directory?, (Wed, Aug 26th)
MediumNigeria Looks to Sovereign Cloud for Cyber, National Security
MediumMicrosoft tests new privacy controls for Windows 11 desktop apps
MediumWhatsApp adds stronger two-step verification, multiple passkeys
MediumMexico’s Cybersecurity Plan 2025-2030: Turning Ambition Into Defense
MediumNew TCG guidance gives buyers a way to test PQC-ready TPM claims
MediumMicrosoft Teams now lets admins block external bots from meetings
MediumAustralian Regs Make Scam Victims Prove Lapses by Banks
MediumMicrosoft shares temporary fix for Windows 11 gaming issues
InformationalYARA-X 1.20.0 Release, (Sun, Aug 30th)
InformationalAnthropic is cutting Claude Code's current weekly limits by 17%
InformationalAndroid 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers
InformationalDefining an AI Kill Switch Is Hard, but Necessary
LowAndroid 17 adds new protections against sneaky Wi-Fi tracking and web snooping
InformationalWindows 11 KB5120998 update released with 35 changes and fixes
InformationalNew infosec products of the month: August 2026
LowRing’s New TAKE Encryption Deletes Video Keys Without Giving Up AI Features
InformationalAndroid 17 adds ECH support to make web browsing harder to track
InformationalHow Threat Research and MDR Help SMBs Build a Defensive Edge
Informational​​​​​​What’s new in Microsoft Security: August 2026
InformationalRecorded Future Launches AI Alert Filtering
InformationalMeta adds three new features to keep WhatsApp accounts secure
InformationalBeyond Patching: What IT Teams Need to Know About Unfixable Exposures
InformationalWhatsApp Adds Stronger Security as Passkeys Hit 1 Billion
InformationalLinux Foundation takes on TRACE, a hardware-backed runtime evidence specification for AI agents
InformationalMicrosoft Teams’ New Policy Lets Admins Automatically Block Meeting Bots
InformationalIdentity Everywhere: Bringing Infrastructure Identity to Agentic IT
InformationalWhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android
InformationalCISA’s logging guidance works beyond government

Breach (60)

CriticalPhilippine Nuclear and Naval Targets Hit by Suspected Chinese Operator
CriticalUS takes down alleged Chinese hacking tools used against Federal Reserve, DOJ and Senate
CriticalHackers breached over 270 Zimbra servers in ongoing attacks
HighExtortion Group FulcrumSec Claims 86GB Manchester Airports Group Data Theft
HighAnthropic warns infostealer malware is hijacking Claude sessions to drain usage
HighFulcrumSec claims Manchester Airports hack, theft of 86 GB of data
HighSecurity Affairs newsletter Round 592 by Pierluigi Paganini – INTERNATIONAL EDITION
HighWeek in review: Compromised Zimbra servers, previously patched Citrix NetScaler flaw exploited
HighHundreds of OpenAI Agents Invaded Hugging Face Servers
HighBerlin Refuses to Pay Hackers Who Stole Data From the City's State Network
HighHack Hindering Boston Scientific Cardiac Device Monitoring
HighLove Electric Breach: 877,000 Driver Records Offered for $600
HighMcKesson discloses breach after ShinyHunters claims patient data theft
HighThe AI agent swarm that attacked Hugging Face is a warning for the future
HighCyberattack on Three UK Airports Exposes Data of 8.7 Million Customers
HighManchester Airports Group breached, millions of customers’ data stolen
HighCyberattack on UK Airport Operator MAG Exposes Data of 8.7 Million Customers Across Three Airports
HighShai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more
HighToy-making giant Hasbro disclose data breach affecting employees
HighOpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face
HighTwo Australian Men Charged in TeamPCP Supply Chain Attacks
HighAustralian Police Charge Two Over TeamPCP Credential Theft
HighManchester Airports Group says hackers stole travelers' data
HighNearly 700 rogue AI agents coordinated in the Hugging Face attack
HighCyberattack causes network outage at Boston Scientific, disrupts global operations
HighTwo alleged TeamPCP hackers arrested over global supply chain attacks
HighGoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address
HighDOJ firearms agency says hackers breached system containing investigation targets
HighAustralia charges two men for TeamPCP supply-chain hacking spree
HighCyberattack on Manchester Airports Group exposes data of 8.7 million customers
HighCISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do
HighATF confirms “major incident” after recent Qilin breach claims
HighCarhartt data breach exposes information of 12.9 million accounts
HighMedical device firm Boston Scientific says cyberattack has disrupted shipment processes
HighCyberattack Disrupts Boston Scientific's Global Operations
HighOpenAI Agents Coordinated Hugging Face Breach at Scale
HighTikTok Agrees to $400M Settlement Over Children’s Privacy
HighCISA Red Team Fully Compromised Two Critical Infrastructure Orgs
HighSnowflake ends service-account passwords. Now comes the hard part
HighBoston Scientific says cyberattack disrupted operations globally
HighMeta agrees to $18 billion settlement over teen social media harms
HighClaude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests
HighWhen an AI Agent Turned Attacker: What Qualys Sees Across Every Phase of the Hugging Face Kubernetes Intrusion 
High88 ID Verification Breaches Show the Cost of Collecting Identity Data
HighEmployee benefits platform Paylogix says hackers stole financial and health data
HighUK Government Reticent Over Power Plant Hack
HighCarhartt - 12,933,413 breached accounts
HighApollo Confirms Data Breach Amid Cyberattacks Targeting Financial Firms
HighHospital operator Nutex Health says data stolen in cyberattack
HighLACMA data breach last year exposed social security and medical data
HighShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack
HighMirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows
HighSouth Korean startup platform breach exposes key management failures
HighReliaQuest confirms failed data-theft attack after ShinyHunters breach
HighTikTok reaches $400M settlement with US over COPPA violations
HighA week in security (August 17 – August 23)
HighTikTok Settles U.S. Child Privacy Case for $400 Million
HighSuspected Iran-linked attack knocked UK power plant offline for days
High⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More
HighHackers infecting Android car systems to build proxy botnet

Ransomware (1)

CriticalRhysida Ransomware Group Targets Berlin Government Ahead of Vote

ThreatIntel (164)

CriticalServiceNow warns of three max severity security vulnerabilities
HighAI AppSec tools agree on just 5% of security findings
HighChrome Web Store extensions caught stealing crypto, browser data
HighSECURITY AFFAIRS MALWARE NEWSLETTER ROUND 112
HighTerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
HighPerturbation Probing: A New Diagnostic for the Fragility of LLM Safety
HighUnit 42 Sees AI Rewriting Enterprise Security Work
HighTerminalFix campaign deploys a reverse tunnel through multistage intrusion
HighAI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up?
High68-year-old imprisoned after making $1.3 million by pirating IPTV services
HighYou Need Cyber Deception for OT
HighOffensive Security Investments Surge as AI Threats Increase
HighEven an AI cost-management vendor can lose control of its agent spending
HighNorth Korean remote workers are broadening their job hunt beyond IT
High19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code
HighJudge Orders Pentagon to Reverse Anthropic Blacklisting
HighRussian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations
HighAgentic AI Risks, CVE Program Concerns Permeate Black Hat USA 2026
HighChinese Routers Sold Worldwide Contain Backdoors
HighDefenders Have Months Before AI-Based Attack Costs Plummet
HighFake Apple Pay charge brings the classic tech support scam to your phone
HighFake listings can turn trusted platforms into scam springboards
HighOpenAI Bans Russian ChatGPT Accounts Used in Covert Influence Campaign
HighFake GTA 6 Demo Spreads Malware: How to Spot the Scam
HighClaude Opus 4.6 Found a Gym API Flaw — Then Exploited It in 9 of 10 Tests
HighLLM-Based Social Engineering Scams
HighWebinar: How Google Workspace breaches happen and what to do next
HighAustralia arrests alleged TeamPCP hackers behind supply-chain attacks
HighJavaScript obfuscation: From party trick to phishing kit
High'HTTP Terminator' Hunts for Novel Desync Attacks
HighRussian Hackers Phish EU Officials Over Messaging Apps
HighChatGPT can log into your web accounts without you now - but should you let it?
HighHow accurate are sleep trackers? Lawsuit says Oura rings have 'a coin flip's chance of being correct'
HighAI a 'force multiplier' for low-skilled threat actors: 4 ways organizations should respond
HighFBI takes down China-linked hacking network behind attacks on NASA, DOJ and U.S. Senate
HighSpark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools
HighLearn How to Build Security Operations Ready for AI-Powered Attacks
HighThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories
HighChinese and Russian spies stepping up cyberattacks, German companies report
HighFinland appeals court revives case against Eagle S Officers over cable breaks
HighSocure Secures $156M, Buys Fravity to Automate Fraud Reviews
HighOpenAI banned Russian ChatGPT accounts backing covert influence operation
HighA polymorphic phishing page (that occasionally breaks itself), (Thu, Aug 27th)
HighCarry-On Compromise: TA4922 Packs PackClient
HighAndroid Malware Hijacks Update System for Car Head Units
HighRed Flags That Expose Fake North Korean IT Workers
HighDark Caracal Adds New Malware to Cyber Espionage Arsenal
HighAbnormal AI expands email security from detection to data protection and phishing-simulation training
HighMeta pledges to overhaul kids’ safety protections, pay $17 billion to settle social media case
HighPopular school apps may be sharing student data with advertisers
HighThe Password Notebook Is Back — but Is It Actually Safer?
HighFBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure
HighSpyware for Babies
HighFBI disrupts proxy network enabling Chinese espionage operations
HighBeware of fake Indeed interview apps used to install spyware
HighInterpol's Jackal IV Disrupts West African Crime Infrastructure
High'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month
HighJuly was the worst month for ransomware victim claims in 2026 - or was it?
HighExploits and vulnerabilities in Q2 2026
HighBogus recruiters go after high-value corporate credentials on mobile
HighAnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes
HighFake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes
HighNew SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode
HighINTERPOL Operation Jackal IV Arrests 58, Identifies 263 in Global Cyber Fraud Crackdown
HighOpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation
HighCISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing
HighNovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions
HighNimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler
HighFBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
HighIran-linked hackers expand infrastructure across Europe and Middle East, report says
HighOperation Jackal: 58 Arrests Expose the Money Laundering Machine Behind Global Scams
HighHidden Prompts Trick AI Into False Email Summaries
HighAI vulnerability discovery scores the highest impact of 20 emerging risks
HighU.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches
High58 arrested in international cybercrime crackdown
HighBanks Face the Penalty But Scammers Exploit the Gaps
HighCar Infotainment Malware Builds Criminal Proxy Botnet
HighFrom Fake Workers to Account Recovery: The Growing Identity Verification Risk
HighMassive DDoS attack disrupts Norway’s government digital services
HighAnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes
HighHackers abuse npm mirrors to host phishing redirect pages
HighTikTok phishing: How to spot fake login and verification pages
HighGTA 6 leak hunt could expose data belonging to thousands of Discord users
HighEncrypted instructions can fool AI assistants like Grok and Gemini
HighThe safety penalty: Reclaiming operational sovereignty in the age of AI
HighFake Minecraft Sites Are Still Spreading WeedHack After C2 Takedown
HighNorway ’s Digital Government Infrastructure Hit by a new DDoS Attack
HighFake OpenAI Codex download tricks macOS users into installing malware
HighINTERPOL crackdown on West African crime rings uncovers troubling new trend
HighE4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands
High24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages
HighLarge DDoS attack knocks Norwegian public services offline
HighUK government seeks powers to secretly block risky tech suppliers
HighPolice arrests dozens of suspects in global cybercrime crackdown
HighThe cybercrime supply chain has five stages, each with a price
HighTruffleHog AWS Analyze reduces remediation time on leaked AWS credentials
HighAI supply chain risk is showing up in developer workflows first
HighWeedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning
HighIndian man who fled US arrested on charges he helped scammers siphon $7.5 million from the elderly
HighUS sanctions Iranian cyber actors as UK discloses power plant attack
HighAfter Mythos: When the Attacker Doesn't Need to Log In
HighAlibaba's AliExpress Uses Hidden Audio to Fingerprint Devices
HighMalicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials
HighThe Vulnerability Gap: Why Discovery Is Outrunning Repair
HighToxicPanda Banking Trojan Matures Into Enterprise Threat
HighTricky 'SynkLoader' Multitool May Herald Ransomware
HighFoul Language: WordlistLoader Disguises Malware as Ordinary Text
HighCriminal Deception in Silicon Valley
HighTracking PavinLoader across ClickFix and fake download campaigns
HighToxicPanda 2.0 can take over your Android phone and banking apps
HighAliExpress caught using silent audio to fingerprint visitors’ browsers
HighFake Microsoft security scans trick victims into uninstalling their antivirus
HighFake GTA 6 Extended Look and demo sites deliver an infostealer
HighThe Detection Gap: MITRE ATT&CK T1003.001
HighiAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset
HighSlovakia Warns of Cyber Risks in Road Speed Cameras
HighCybercriminals Turn GTA VI Leaks Into Malware Bait
HighAndroid car head units infected with proxy botnet malware through built-in software updaters
HighUAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit
HighThe Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk
HighOperation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor
HighShipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt
HighWordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords
HighDOUBLECUP's PNG Payload, (Mon, Aug 24th)
MediumFree ChatGPT users get ads picked from whatever they just asked about
MediumProtect your WhatsApp account with new passkey and 2FA upgrades
MediumRubrik: Firms Want Joint Agent Identity, Visibility, Recovery
MediumSome Malicious PE Stats, (Thu, Aug 27th)
MediumWhat 90 days and a small budget can buy in AI agent security
MediumEcho Buys Minimus After Container Defense Startup Winds Down
MediumDo Smart Monitors Track You? What Buyers Should Know
Medium“Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friend
MediumAI will not fix a governance problem in your camera estate
MediumCrowdStrike Flex Model Adapts Deals to Evolving AI Threats
MediumSmashing Security podcast #482: This hacker leaked GTA 6 – and launched their own cryptocurrency
MediumProduction data in testing is still common, and Tricentis’ CISO wants it gone
MediumObfuscating IP Addresses as Hostnames, (Tue, Aug 25th)
MediumA Cautionary Tale About Data Breach Claims, Verification and Carhartt
MediumThe patch window is collapsing: Why security needs a new control plane
MediumAnthropic's Claude and Cowork will share memories about you now - unless you opt out
MediumFrontier AI: Vulnerability Management's Systemic Revolution
MediumThe State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution
MediumChatGPT for Teens Adds New Safeguards — but Safety Gaps Remain
MediumCybersecurity job ads demanding AI skills double in a year
InformationalISC Stormcast For Monday, August 31st, 2026 https://isc.sans.edu/podcastdetail/10074, (Mon, Aug 31st)
InformationalSpur Expands Research After $200M Insight Partners Purchase
InformationalHow to get free Google AI Pro for an entire year - and save $240: 3 ways
InformationalHow I sorted 22,000 digital photos without getting overwhelmed: 4 easy tricks
InformationalISC Stormcast For Friday, August 28th, 2026 https://isc.sans.edu/podcastdetail/10072, (Fri, Aug 28th)
InformationalWhat the Data Says About AI in Security Operations in 2026
InformationalThe best human hacking team still out-solved the best AI team
InformationalExclusive: NSA to host a hacker reunion in bid to rebuild secretive unit
InformationalCyber Novice Takes Top Prize in SANS AI Forensics Contest
InformationalWhen AI infrastructure becomes the target: Securing gateways and control points
InformationalMicrosegmentation’s Moment Is Now: Cisco Named a Leader in The Forrester Wave™: Microsegmentation Solutions
InformationalRightCrowd Pass unifies mobile, physical, and biometric credentials
InformationalImagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine
InformationalFBI, DOJ Seize Chinese Hacker Infrastructure on US Soil
InformationalISC Stormcast For Wednesday, August 26th, 2026 https://isc.sans.edu/podcastdetail/10068, (Wed, Aug 26th)
InformationalHottest cybersecurity open-source tools of the month: August 2026
LowSome Spectrum internet customers can get free Amazon Prime - see if you're eligible
InformationalFideo Lens reveals connections across identities, accounts and devices
InformationalISC Stormcast For Tuesday, August 25th, 2026 https://isc.sans.edu/podcastdetail/10066, (Tue, Aug 25th)
InformationalHOL Guard: Open-source antivirus for AI agents

Vulnerability (89)

CriticalHackers Are Probing PaperCut Servers, and 47% Still Have No Patch
CriticalPaperCut Zero-Day Under Active Attack: Emergency Patch Released
CriticalFive Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
CriticalHack One Robot, Reach the Next: Unitree G1 Security Flaws
CriticalownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body
CriticalAttackers Chain Two PaperCut Flaws to Execute Code Without Authentication
CriticalCosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable
CriticalU.S. CISA adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog
CriticalOver 8,300 Gitea servers vulnerable to code execution attacks
CriticalGiveWP WordPress donation plugin flaw lets hackers execute server commands
CriticalPaperCut releases second emergency patch for exploited flaws
CriticalPaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions
CriticalCritical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
CriticalThree CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL
CriticalPaperCut Zero-Day Under Active Attack: Emergency Patch Released
CriticalBreach Roundup: A Call for Cyber Defense Collective Action
CriticalNew GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access
CriticalNext.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE
CriticalXiiaozet LK100W
CriticalEbyte NA111-M
CriticalApplied Systems Engineering ASE2000 V2 Communications Test Set
CriticalUpdate Chrome before you browse again
CriticalUbiquiti patches three max severity security vulnerabilities
CriticalHackers target Microsoft SharePoint RCE chain with PoC exploit
CriticalCritical Avada WordPress theme flaw enables zero-click RCE
CriticalCritical Gitea vulnerability now exploited in the wild (CVE-2026-60004)
CriticalCritical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload
CriticalU.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog
CriticalHackers now exploit critical Gitea flaw in code injection attacks
CriticalZimbra Exploitation Spreads as Thousands Stay Unpatched
Critical[remote] CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE
CriticalFURUNO FA-50 Class B AIS Transponder
CriticalSiemens SIMATIC IoT2050 Advanced
CriticalEbyte NE2-D11
CriticalU.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalog
CriticalTwo CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as Vulnerable
CriticalActively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
CriticalZDI-26-590: libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
CriticalCVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days
CriticalRussian Backdoor Found in Slovak Traffic Cameras
CriticalExploited Zimbra Flaw Highlights Shrinking Window to Patch
CriticalUnpatched Calix flaw lets hackers bypass NAT to expose internal devices
CriticalCritical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
CriticalCISA orders urgent patching of actively exploited Zimbra flaw
HighU.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog
HighCISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs
HighAmazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers
HighMitsubishi Electric Multiple FA Products (Update D)
HighRockwell Automation OTTO Fleet Manager
HighAll-Line Equipment Company Fuel-Boss
HighCISA orders feds to patch Citrix NetScaler RCE flaw by Saturday
HighNew GPUThor attack defeats NVIDIA ECC protection for root access
HighUnpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code
HighFinding Nemo(Claw): Networking Issue Allows for LLM Poisoning in OpenClaw
HighBendix EC80 Brake ECU
HighZoneminder
HighPayRange API
HighCISA Adds One Known Exploited Vulnerability to Catalog
HighRently Smart Home
HighUnpatched Zimbra servers are falling to CVE-2026-73570 attacks
HighAttackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access
HighZDI-26-585: OriginLab Origin Viewer OGWU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
HighZDI-26-586: OriginLab Origin Viewer OGM File Parsing Memory Corruption Remote Code Execution Vulnerability
HighZDI-26-587: Ashlar-Vellum Cobalt VS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
HighZDI-26-589: BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerability
HighZDI-26-591: NVIDIA TensorRT ONNX File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
HighZDI-26-592: NVIDIA TensorRT ONNX File Parsing Improper Validation of Array Index Remote Code Execution Vulnerability
HighZDI-26-593: NVIDIA TensorRT ONNX File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
HighZDI-26-594: NVIDIA Megatron Bridge load_model_config Code Injection Remote Code Execution Vulnerability
HighZDI-26-595: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability
HighZDI-26-597: Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability
HighZDI-26-598: Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability
HighZDI-26-602: Foxit PDF Reader Doc Object Use-After-Free Remote Code Execution Vulnerability
HighZDI-26-603: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability
HighZDI-26-604: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability
HighZDI-26-606: Microsoft Windows Compatibility Appraiser Link Following Local Privilege Escalation Vulnerability
HighZDI-26-607: Microsoft Office HTML Injection Information Disclosure Vulnerability
HighZDI-26-608: Linux Kernel KVM IOAPIC Use-After-Free Local Privilege Escalation Vulnerability
HighZDI-26-609: Linux Kernel Net Scheduler Packet Classifier Use-After-Free Local Privilege Escalation Vulnerability
HighZDI-26-610: Apple Safari JavaScriptCore B3 ReduceStrength Phase Use-After-Free Remote Code Execution Vulnerability
HighWeekly Update 518: IoT Doorlock Nirvana with UniFi
HighHackers target WordPress sites in miniOrange auth bypass attacks
HighCISA Adds One Known Exploited Vulnerability to Catalog
MediumZDI-26-596: Foxit PDF Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
MediumZDI-26-599: Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability
MediumZDI-26-600: Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability
MediumZDI-26-605: Microsoft Windows Localized Filenames Improper Input Validation NTLM Response Information Disclosure Vulnerability
LowZDI-26-588: Fabric.js loadFromJSON Server-Side Request Forgery Vulnerability
LowZDI-26-601: Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability

Daily breach, advisory, and vulnerability briefs publish every weekday.

View Live Breach Feed ← All Weekly Digests