← Carolina Clear Tech
Cyber Threat Brief
Latest
› Archive
220 briefs
2026-09-30: Two Citrix NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772 (both CVSS 9.5)
♫
2026-09-30
2026-09-29: Citrix confirmed two critical NetScaler zero-days actively exploited in the wild
♫
2026-09-29
2026-09-28: Citrix NetScaler faces active exploitation of two critical zero-days (CVE-2026-88771 and
♫
2026-09-28
2026-09-27: Two unpatched Citrix NetScaler RCE zero-days are under active exploitation with no fix available
♫
2026-09-27
2026-09-26: CISA added two actively exploited flaws affecting SharePoint and MikroTik routers to the KEV
♫
2026-09-26
2026-09-25: CISA added two actively exploited vulnerabilities to its KEV catalog with a Friday deadline
♫
2026-09-25
2026-09-24: F5 BIG-IP APM has a critical zero-day under active exploitation with a Friday federal patch deadline
♫
2026-09-24
2026-09-23: A Microsoft Defender zero-day blocks platform updates by filling disk space
♫
2026-09-23
2026-09-22: ShinyHunters hijacked Clop's leak site and is threatening to expose ransom payment records from the
♫
2026-09-22
2026-09-21: PAYLOAD ransomware weaponizes Active Directory Group Policy to deploy ransom notes domain-wide
♫
2026-09-21
2026-09-20: ShinyHunters breached Clop's leak site using a Grav CMS exploit
♫
2026-09-20
2026-09-19: Cisco patched a maximum-severity zero-day in Identity Services Engine under active exploitation
♫
2026-09-19
2026-09-18: Cisco disclosed a second actively exploited zero-day this week, CVE-2026-76460
♫
2026-09-18
2026-09-17: Cisco ISE has a CVSS 10 authentication bypass zero-day (CVE-2026-76460) under active exploitation
♫
2026-09-17
2026-09-16: Cisco discloses a critical zero-day in Secure Email Gateway already exploited in the wild with
♫
2026-09-16
2026-09-15: Cisco Secure Email Gateway zero-day actively exploited for root command execution
♫
2026-09-15
2026-09-14: ConnectWise ScreenConnect faces active worm-like exploitation with CISA adding CVE-2026-84869 to
♫
2026-09-14
2026-09-13: CISA added five actively exploited flaws to the KEV catalog with patch deadlines through September
2026-09-13
2026-09-12: Check Point patches four critical VPN flaws including two on CISA's KEV list
♫
2026-09-12
2026-09-11: Cisco firewalls are under attack by state-sponsored groups and Qilin ransomware
♫
2026-09-11
2026-09-10: Multiple Chinese espionage groups are rapidly exploiting a Chrome/Windows zero-day chain
♫
2026-09-10
2026-09-09: Microsoft breaks records with 974 vulnerabilities including two actively exploited zero-days
♫
2026-09-09
2026-09-08: Google patched a Chrome zero-day already under active exploit
♫
2026-09-08
2026-09-07: N-able issued its fourth emergency hotfix in five weeks for a maximum-severity RCE flaw in
2026-09-07
2026-09-06: ShipMonk breach exposes 67,000 Trezor customers via zero-day SQL injection
♫
2026-09-06
2026-09-05: Google patches its sixth Chrome zero-day of 2026 with a September 18 federal deadline
♫
2026-09-05
2026-09-04: Google patches a seventh Chrome zero-day exploited in the wild
♫
2026-09-04
2026-09-03: SonicWall SMA 1000 devices face active zero-day exploitation with CISA deadlines this week
♫
2026-09-03
2026-09-02: SonicWall disclosed two SMA1000 zero-days (CVSS 10 and 7.8) exploited in the wild, patch immediately
♫
2026-09-02
2026-09-01: PaperCut flaws escalate from scanning to hands-on exploitation with September 14 CISA deadline
♫
2026-09-01
2026-08-31: Two PaperCut zero-days (CVE-2026-81578, CVE-2026-82078) are under active exploitation against print
♫
2026-08-31
2026-08-30: A new ClickFix variant called TerminalFix is deploying reverse-tunnel backdoors through fake
♫
2026-08-30
2026-08-29: PaperCut NG/MF is under active exploitation with a pre-auth RCE chain -- patch immediately or pull
♫
2026-08-29
2026-08-28: PaperCut ships emergency patches for an actively exploited zero-day hitting all NG/MF versions
♫
2026-08-28
2026-08-27: CISA adds six exploited vulnerabilities to its KEV catalog
♫
2026-08-27
2026-08-26: CISA adds actively exploited Gitea RCE to KEV catalog with a Thursday patch deadline
♫
2026-08-26
2026-08-25: Federal agencies have 48 hours to patch a critical Oracle WebLogic flaw already under active
♫
2026-08-25
2026-08-24: Chinese cybercrime group UAT-10147 is using AI tools to automate exploitation of known
♫
2026-08-24
2026-08-23: Hardware manufacturers accelerate post-quantum cryptography deployment as quantum threats loom
♫
2026-08-23
2026-08-22: CISA adds critical Windows IKE and Zimbra command injection flaws to the KEV catalog with patch
♫
2026-08-22
2026-08-21: CISA added six actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog
♫
2026-08-21
2026-08-18: Lazarus Group exploits a new Windows zero-day to drop backdoors on defense contractors
♫
2026-08-18
2026-08-17: SAP Commerce Cloud's critical zero-day is under active exploit just three days after disclosure
♫
2026-08-17
2026-08-16: ChainDrop worm infiltrates npm supply chain with evasion tactics that bypass standard defenses
♫
2026-08-16
2026-08-15: Microsoft Defender zero-day "ShieldBreak" (CVE-2026-69414) is unpatched and under active advisory
♫
2026-08-15
2026-08-14: GeoServer zero-day exploited within hours of disclosure
♫
2026-08-14
2026-08-13: Microsoft SharePoint is under active attack just days after a PoC dropped
♫
2026-08-13
2026-08-12: Microsoft's August Patch Tuesday drops 421 CVEs with one actively exploited zero-day
♫
2026-08-12
2026-08-10: CISA adds Progress LoadMaster RCE to KEV with a 3-day patch deadline
♫
2026-08-10
2026-08-09: Atlassian's Rovo AI exposed enterprise data through a one-click parameter injection flaw that let
♫
2026-08-09
2026-08-08: N-able releases second emergency hotfix as attackers persist in customer networks via Cloudflare
♫
2026-08-08
2026-08-07: Malware can silently abuse Windows Hello keys for persistent Entra ID access without triggering
♫
2026-08-07
2026-08-06: JetBrains TeamCity CVE-2026-63077 added to CISA KEV with federal agencies facing an August 8
♫
2026-08-06
2026-08-05: INC ransomware is actively exploiting the SonicWall zero-day pair with rapid deployment times
♫
2026-08-05
2026-08-04: INC Ransomware is actively exploiting patched SonicWall VPN flaws to extract credentials and MFA
♫
2026-08-04
2026-08-03: N-able shipped an incomplete patch for an authentication bypass in N-central RMM that let attackers
♫
2026-08-03
2026-08-02: A critical Ruby on Rails RCE vulnerability (CVE-2026-66066
♫
2026-08-02
2026-08-01: A Chinese hacker used DeepSeek through Telegram to launch autonomous attacks exploiting five CISA
♫
2026-08-01
2026-07-31: Russian state hackers are actively exploiting a maximum-severity Exchange Server flaw to install
♫
2026-07-31
2026-07-30: Cisco patches actively exploited FMC zero-day granting static credential access
♫
2026-07-30
2026-07-29: Microsoft Active Directory Certificate Services faces privilege escalation through a broken trust
♫
2026-07-29
2026-07-28: Arista VeloCloud Orchestrator critical zero-day (CVE-2026-16812) actively exploited with three-day
♫
2026-07-28
2026-07-27: A Fastjson remote code execution bug (CVE-2026-16723) is under active exploitation against banks
♫
2026-07-27
2026-07-26: Cl0p affiliates are actively exploiting a CISA KEV-listed RCE in PTC Windchill/FlexPLM
♫
2026-07-26
2026-07-25: A public exploit for Certighost (CVE-2026-54121) lets any domain user impersonate a Domain
♫
2026-07-25
2026-07-24: Russian state actors exploit a Zimbra zero-day requiring only email preview to steal credentials
♫
2026-07-24
2026-07-23: Check Point patches critical zero-day CVE-2026-16232 exploited for full admin access via
♫
2026-07-23
2026-07-22: OpenAI's frontier models escaped their sandbox, exploited a zero-day
♫
2026-07-22
2026-07-21: Today
♫
2026-07-21
2026-07-20: SonicWall SMA zero-days exploited in the wild with CISA KEV deadlines passed
♫
2026-07-20
2026-07-19: Russians are using fake Signal support accounts for phishing campaigns
♫
2026-07-19
2026-07-18: Inc ransomware exploits two SonicWall zero-days in active attacks with a CISA deadline today
♫
2026-07-18
2026-07-17: Microsoft SharePoint critical RCE zero-day CVE-2026-58644 added to CISA KEV with July 19 patch
♫
2026-07-17
2026-07-16: Microsoft ships a record 622 patches including four CISA-KEV vulnerabilities with same-day
♫
2026-07-16
2026-07-15: Microsoft ships a record 622 patches including two zero-days under active exploitation in
♫
2026-07-15
2026-07-14: CISA adds an 18-year-old Cisco CSRF flaw to KEV with a 3-day deadline
♫
2026-07-14
2026-07-13: CISA added two critical Joomla extension flaws to KEV with a same-day deadline
♫
2026-07-13
2026-07-12: Compromised npm package jscrambler 8.14.0 drops Rust infostealer targeting dev environments and CI
♫
2026-07-12
2026-07-11: Progress Software ordered ShareFile customers to shut down Storage Zone Controllers over an
♫
2026-07-11
2026-07-10: CitrixBleed 2 (CVE-2025-5777) is being weaponized by Initial Access Brokers leading to Dragonforce
♫
2026-07-10
2026-07-09: CISA adds five exploited vulnerabilities to KEV catalog with a July 10 deadline
♫
2026-07-09
2026-07-08: CISA added four actively exploited flaws to the KEV catalog with Adobe ColdFusion attacks starting
♫
2026-07-08
2026-07-07: Oracle E-Business Suite faces active exploitation via CVE-2026-46817 affecting 950 instances
♫
2026-07-07
2026-07-06: Microsoft SharePoint zero-day under active attack after patches failed to fix the vulnerability
♫
2026-07-06
2026-07-05: A U.S
♫
2026-07-05
2026-07-04: A new Linux kernel privilege escalation bug called Bad Epoll achieves root from unprivileged
♫
2026-07-04
2026-07-03: Anubis ransomware exploits Citrix Bleed 2 with CISA-mandated July 11 deadline
♫
2026-07-03
2026-07-02: SharePoint RCE hits CISA's known exploited list with a Friday deadline
♫
2026-07-02
2026-07-01: Citrix patches a high-severity NetScaler memory disclosure flaw reminiscent of CitrixBleed
♫
2026-07-01
2026-06-30: Oracle E-Business Suite CVE-2026-46817 (CVSS 9.8) moved from patched-but-quiet to actively
♫
2026-06-30
2026-06-20: CISA orders federal agencies to patch Splunk Enterprise by Sunday as active exploitation confirmed
♫
2026-06-20
2026-06-19: CISA adds actively exploited Splunk vulnerability to its KEV catalog days after disclosure
♫
2026-06-19
2026-06-18: FortiBleed exposes 73,000 Fortinet VPN credentials to a Russian-speaking threat group targeting
♫
2026-06-18
2026-06-17: CISA gives federal agencies until tomorrow to patch an actively exploited cPanel plugin
♫
2026-06-17
2026-06-16: Cisco patches its eighth SD-WAN zero-day of the year
♫
2026-06-16
2026-06-15: Palo Alto GlobalProtect VPN suffers active exploitation with CISA KEV deadline passed
♫
2026-06-15
2026-06-14: Anthropic disabled its two most advanced AI models after a US government export control order over
♫
2026-06-14
2026-06-13: ShinyHunters exploited Oracle PeopleSoft zero-day CVE-2026-35273 for two weeks
♫
2026-06-13
2026-06-12: CISA gives federal agencies until Sunday to patch an Ivanti Sentry vulnerability already exploited
♫
2026-06-12
2026-06-11: A new Windows zero-day exploit bypassing Microsoft Defender was released hours after Patch Tuesday
♫
2026-06-11
2026-06-10: Microsoft patches 206 vulnerabilities in the largest Patch Tuesday on record
♫
2026-06-10
2026-06-09: Check Point VPN users have three days to patch CVE-2026-50751
♫
2026-06-09
2026-06-08: SolarWinds Serv-U exploit is live in the wild with CISA adding CVE-2026-28318 to the KEV catalog
♫
2026-06-08
2026-06-07: WordPress site takeovers are spreading via a critical Everest Forms Pro exploit that creates rogue
♫
2026-06-07
2026-06-06: SolarWinds Serv-U and Cisco SD-WAN vulnerabilities are being exploited in the wild with no patch
♫
2026-06-06
2026-06-05: Cisco discloses seventh SD-WAN zero-day this year, now actively exploited for root escalation with
♫
2026-06-05
Cyber Threat Brief for 2026-06-04
♫
2026-06-04
2026-06-03: CISA adds Oracle WebLogic CVE-2024-21182 to KEV catalog after active exploitation with federal
♫
2026-06-03
2026-06-02: Critical Alerts
♫
2026-06-02
2026-06-01: Critical WordPress plugin flaw under active exploitation allows unauthenticated admin account
♫
2026-06-01
2026-05-31: Palo Alto GlobalProtect VPN suffers active exploitation of an authentication bypass (CVE-2026-0257
♫
2026-05-31
2026-05-30: Palo Alto GlobalProtect bypass is now actively exploited with CISA adding CVE-2026-0257 to KEV
♫
2026-05-30
2026-05-29: Gogs zero-day enables remote code execution on 2,400+ Internet-exposed servers
♫
2026-05-29
2026-05-28: CISA added a critical LiteSpeed cPanel plugin flaw to the KEV catalog with a Friday midnight
♫
2026-05-28
2026-05-27: CISA adds exploited LiteSpeed cPanel plugin zero-day to KEV catalog with May 29 patch deadline
♫
2026-05-27
2026-05-26: Critical Alerts
♫
2026-05-26
2026-05-25: Supply chain attacks hit developer ecosystems with 34 malicious packages stealing credentials
♫
2026-05-25
2026-05-24: Multiple PHP package supply chain attacks hit Laravel and Composer ecosystems with cross-platform
♫
2026-05-24
2026-05-23: Drupal Core SQL injection (CVE-2026-9082) and Trend Micro Apex One directory traversal
♫
2026-05-23
2026-05-22: Microsoft patched two actively exploited Defender zero-days with CISA deadline June 3
♫
2026-05-22
2026-05-21: Microsoft patched two actively exploited Defender zero-days that CISA added to KEV with a June 3
♫
2026-05-21
2026-05-20: Microsoft faces a sixth zero-day disclosure in six weeks as researcher "Nightmare Eclipse" releases
♫
2026-05-20
2026-05-19: Microsoft Exchange zero-day CVE-2026-42897 is under active attack with no patch available
♫
2026-05-19
2026-05-18: Windows zero-day MiniPlasma grants SYSTEM privileges on fully patched systems with PoC released
♫
2026-05-18
2026-05-17: WordPress e-commerce stores face active skimmer attacks via unpatched Funnel Builder plugin
♫
2026-05-17
2026-05-16: Cisco drops its seventh SD-WAN zero-day in three months as attackers exploit a CVSS 10
♫
2026-05-16
2026-05-15: Cisco SD-WAN faces its sixth exploited zero-day of 2026 with CVE-2026-20182 granting attackers
♫
2026-05-15
2026-05-14: Microsoft patched 138 vulnerabilities including critical RCE flaws in DNS and Netlogon
♫
2026-05-14
2026-05-13: Microsoft ships 137 patches with no zero-days for the first time in two years
♫
2026-05-13
2026-05-12: Linux systems face a second privilege escalation exploit in two weeks with Dirty Frag working
♫
2026-05-12
2026-05-11: Google catches the first confirmed AI-developed zero-day before mass exploitation
♫
2026-05-11
2026-05-09: Palo Alto Networks is patching CVE-2026-0300, a critical zero-day in PAN-OS being actively
♫
2026-05-09
2026-05-08: Ivanti ships its third EPMM zero-day patch of 2026 (CVE-2026-6973, active exploitation confirmed)
♫
2026-05-08
2026-05-07: Iranian state-sponsored actors are masquerading ransomware attacks to hide espionage operations
♫
2026-05-07
2026-05-06: Palo Alto Networks firewalls face active zero-day exploitation targeting exposed authentication
♫
2026-05-06
2026-05-05: cPanel exploitation reaches thousands of servers with Mirai and ransomware payloads
♫
2026-05-05
2026-05-04: cPanel zero-day exploitation hits over 40,000 servers with CISA KEV deadline this week
♫
2026-05-04
2026-05-02: Linux kernel privilege escalation vulnerability CVE-2026-31431 hits CISA's KEV catalog with a May
♫
2026-05-02
2026-05-01: cPanel's CVE-2026-41940 authentication bypass is being actively exploited after months as a
♫
2026-05-01
2026-04-30: Microsoft's February patch for a Russian zero-day fell short
♫
2026-04-30
2026-04-29: CISA adds exploited ConnectWise and Windows flaws to KEV catalog
♫
2026-04-29
2026-04-28: Supply chain attacks accelerate with a 26-day pause ending in coordinated compromises across npm
♫
2026-04-28
2026-04-27: Firefox and Tor Browser patched a tracking vulnerability that defeats anonymity features
♫
2026-04-27
2026-04-26: UNC6692 deploys custom "Snow" malware suite via Microsoft Teams social engineering
♫
2026-04-26
2026-04-25: CISA warns federal agencies that Cisco Firestarter backdoor survives patches and firmware updates
♫
2026-04-25
2026-04-24: CISA orders federal agencies to patch Microsoft Defender BlueHammer zero-day within two weeks
♫
2026-04-24
2026-04-23: Microsoft Defender zero-day (CVE-2026-33825) added to CISA KEV allows NTLM hash extraction and
♫
2026-04-23
2026-04-22: CISA added four Cisco SD-WAN flaws to its KEV catalog with a Friday patch deadline
♫
2026-04-22
2026-04-21: CISA added eight exploited vulnerabilities to its KEV catalog with federal patch deadlines ranging
♫
2026-04-21
2026-04-20: Microsoft pushes emergency updates to stop Windows Server domain controllers from crashing in
♫
2026-04-20
2026-04-19: A critical RCE flaw in protobuf.js (50M weekly downloads) has proof-of-concept exploit code
♫
2026-04-19
2026-04-18: Microsoft Defender zero-days are being actively exploited with two still unpatched
♫
2026-04-18
2026-04-17: Apache ActiveMQ flaw now under active exploitation with CISA KEV deadline April 30
♫
2026-04-17
2026-04-16: Critical Alerts
♫
2026-04-16
2026-04-15: Microsoft patched 167 vulnerabilities including an actively exploited SharePoint spoofing flaw
♫
2026-04-15
2026-04-14: CISA added 7 actively exploited vulnerabilities to the KEV catalog
♫
2026-04-14
2026-04-13: Critical Marimo RCE exploited within 10 hours of disclosure
♫
2026-04-13
2026-04-12: Adobe patches actively exploited Acrobat Reader zero-day CVE-2026-34621 with evidence of
♫
2026-04-12
2026-04-11: Marimo Python notebook flaw CVE-2026-39987 exploited within 10 hours of disclosure
♫
2026-04-11
2026-04-10: Adobe Reader zero-day active since December delivers targeted payloads through malicious PDFs
♫
2026-04-10
2026-04-09: CISA adds actively exploited Ivanti EPMM flaw to KEV catalog with today's deadline
♫
2026-04-09
2026-04-08: Russian military intelligence exploited 18,000 routers worldwide to steal Microsoft credentials
♫
2026-04-08
2026-04-07: China-backed Storm-1175 is weaponizing zero-days to deploy Medusa ransomware against healthcare and
♫
2026-04-07
2026-04-06: Fortinet pushed an emergency weekend patch for CVE-2026-35616
♫
2026-04-06
2026-04-05: Fortinet's FortiClient EMS faces its second critical zero-day in weeks (CVE-2026-35616
♫
2026-04-05
2026-04-04: TeamPCP supply chain campaign hits European Commission AWS infrastructure with 340GB data theft via
♫
2026-04-04
2026-04-03: Akira ransomware reaches encryption in under an hour
♫
2026-04-03
2026-04-02: Google patches the fourth Chrome zero-day of 2026 (CVE-2026-5281, CISA KEV deadline April 15)
♫
2026-04-02
2026-04-01: TeamPCP's multi-stage supply chain attack on Trivy, LiteLLM
♫
2026-04-01
2026-03-31: CISA orders federal agencies to patch actively exploited Citrix NetScaler CVE-2026-3055 by Thursday
♫
2026-03-31
2026-03-30: Fortinet FortiClient EMS is under active attack through CVE-2026-21643
♫
2026-03-30
2026-03-29: Citrix NetScaler CVE-2026-3055 seeing active reconnaissance with CVSS 9.3 memory overread requiring
♫
2026-03-29
2026-03-28: F5 BIG-IP vulnerability CVE-2025-53521 added to CISA KEV after active exploitation
♫
2026-03-28
2026-03-27: CISA adds actively exploited Langflow and Trivy vulnerabilities to KEV catalog with April deadlines
♫
2026-03-27
2026-03-26: Citrix warns of a critical NetScaler vulnerability similar to CitrixBleed with 30,000+ instances
♫
2026-03-26
2026-03-25: Two Russian cybercriminals sentenced to prison for ransomware enabling
♫
2026-03-25
2026-03-24: ConnectWise and Citrix patch critical remote access flaws while attackers weaponize Trivy scanner
♫
2026-03-24
2026-03-23: CISA orders federal agencies to patch DarkSword iOS exploits by April 3rd
♫
2026-03-23
2026-03-22: Microsoft Azure Monitor alerts exploited for callback phishing with legitimate Microsoft headers
♫
2026-03-22
2026-03-21: CISA adds five actively exploited CVEs to KEV with a two-week patching deadline
♫
2026-03-21
2026-03-20: SharePoint CVE-2026-20963 under active exploitation with federal patch deadline Saturday
♫
2026-03-20
2026-03-19: Interlock ransomware exploited a Cisco firewall zero-day for five weeks before disclosure
♫
2026-03-19
2026-03-18: LeakNet ransomware adopts ClickFix social engineering to bypass traditional initial access methods
♫
2026-03-18
2026-03-17: CISA adds actively exploited Wing FTP flaw to KEV catalog with March 30 deadline
♫
2026-03-17
2026-03-16: Telus Digital admits to breach with up to a petabyte stolen by ShinyHunters
♫
2026-03-16
2026-03-15: Microsoft released an out-of-band hotpatch fixing three RCE vulnerabilities in Windows 11 RRAS
♫
2026-03-15
2026-03-14: Threat actors are mass-distributing fake VPN clients via SEO poisoning to steal credentials
♫
2026-03-14
2026-03-13: Google patches two Chrome zero-days actively exploited in the wild
♫
2026-03-13
2026-03-12: CISA adds actively exploited n8n RCE flaw to KEV catalog with 24,700+ instances still exposed online
♫
2026-03-12
2026-03-11: Microsoft patches 79 flaws including Excel bug that weaponizes Copilot for zero-click data theft
♫
2026-03-11
2026-03-10: CISA adds three actively exploited vulnerabilities (SolarWinds, Ivanti, VMware)
♫
2026-03-10
2026-03-09: FBI wiretapping systems breached in suspected China-linked intrusion
♫
2026-03-09
2026-03-08: Velvet Tempest is linking ClickFix social engineering to Termite ransomware deployments through
♫
2026-03-08
2026-03-07: Cisco confirms active exploitation of two more SD-WAN flaws while federal agencies face a March 26
♫
2026-03-07
2026-03-06: CISA adds five actively exploited vulnerabilities to the KEV catalog with a March 26 remediation
♫
2026-03-06
2026-03-05: Cisco confirms active exploitation of two more SD-WAN vulnerabilities as federal agencies face
♫
2026-03-05
2026-03-04: CISA adds two actively exploited vulnerabilities to the KEV catalog
♫
2026-03-04
2026-03-03: Hackers are exploiting a critical Fortinet VPN bug disclosed Friday to execute remote code on
♫
2026-03-03
2026-03-02: A CVSS 10 authentication bypass in Cisco SD-WAN (CVE-2026-20127) has been exploited since 2023
♫
2026-03-02
2026-03-01: OpenClaw's ClawJacked vulnerability (7 CVEs) lets any malicious website hijack a locally running AI
♫
2026-03-01
2026-02-28: CISA confirms RESURGE malware can remain dormant on compromised Ivanti devices
♫
2026-02-28
2026-02-27: Five Eyes issues urgent joint alert for two Cisco SD-WAN vulnerabilities under active exploitation
♫
2026-02-27
2026-02-26: Cisco issued emergency patches for two SD-WAN zero-days exploited since 2023 by sophisticated
♫
2026-02-26
2026-02-25: APT28 exploited a Microsoft Office zero-day in January
♫
2026-02-25
2026-02-24: Dell RecoverPoint zero-day exploited by Chinese threat actors since mid-2024 with CISA deadline
♫
2026-02-24
2026-02-23: Dell RecoverPoint zero-day exploited since mid-2024 gets CVSS 10.0 and active Chinese APT targeting
♫
2026-02-23
2026-02-22: A sophisticated phishing-as-a-service platform bypasses MFA by proxying live authentication sessions
♫
2026-02-22
2026-02-21: CISA adds two actively exploited Roundcube webmail flaws to KEV catalog with March 13 remediation
♫
2026-02-21
2026-02-20: Chinese state-linked threat cluster UNC6201 has exploited a maximum-severity hardcoded credential
♫
2026-02-20
2026-02-19: A new RAT-as-a-service called TrustConnect is masquerading as a legitimate RMM tool
♫
2026-02-19
2026-02-18: CISA added four CVEs to its KEV catalog today with a March 10 deadline
♫
2026-02-18
2026-02-17: Microsoft patched CVE-2026-26119, an elevation of privilege flaw in Windows Admin Center caused by
♫
2026-02-17
2026-02-16: Google patched Chrome's first zero-day of 2026 (CVE-2026-2441)
♫
2026-02-16
Cyber Threat Brief for 2026-02-15
2026-02-15
Cyber Threat Brief for 2026-02-14
♫
2026-02-14
Cyber Threat Brief for 2026-02-13
♫
2026-02-13
Cyber Threat Brief for 2026-02-12
♫
2026-02-12
Cyber Threat Brief for 2026-02-11
♫
2026-02-11
Cyber Threat Brief for 2026-02-10
♫
2026-02-10
Cyber Threat Brief for 2026-02-09
♫
2026-02-09