Cyber Wiki
Entities, threat actors, incidents, vulnerabilities and concepts β cross-linked from every digest. Everything is open β click a heading to collapse, or jump to a section.
βΌ π₯ Incidents & Campaigns 298
Wrench' Attacks Against Crypto Holders Appear to Be on the Rise
Physical coercion attacks against crypto holders on the rise (Jul 2026)
Open β14 Trojanised npm Packages Deliver RedC2 4.0 Linux Backdoor With AI-Assisted C2
No summary yet
Open β18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users
No summary yet
Open β23andMe $18M Multi-State Breach Settlement
23andMe $18M multi-state settlement over 2023 data breach; Spain fines $3M; later 42 AGs settlement led by Connecticut (Jul 2026)
Open β737 Chrome VPN Extensions Caught Routing Traffic Through Single Proxy Infrastructure
No summary yet
Open β9,300 Leaked AWS Access Keys Still Active, Hundreds Grant Full Corporate Account Control
No summary yet
Open βAA26-194A β CISA Advisory on Router Hygiene Against Russian State-Sponsored Targeting
No summary yet
Open βAA26-204A β CISA/FBI Joint Advisory on Russian Zimbra Phishing Campaign
No summary yet
Open βaa26-204a β Joint Advisory on Russian Zimbra Zero-Day Campaign
Joint CISA/NSA/ACSC advisory on Russian state-sponsored Zimbra zero-day espionage campaign (Jul 2026)
Open βAA26-222A β Joint Advisory on Gunra Ransomware Targeting Critical Infrastructure
No summary yet
Open βAA26-237A
No summary yet
Open βACSC/CISA Joint Advisory: Russian State-Sponsored Zimbra Phishing Campaign
No summary yet
Open βACSC CMS Exploitation Campaign
[CRITICAL] Large-scale CMS exploitation campaign targeting Australian organisations (ACSC alert)
Open βACSC Publishes Guidance on Secure Adoption of Agentic AI in Defence
No summary yet
Open βACSC Publishes New AI Frontier Cyber Threat Guidance for Boards of Directors
ACSC/AICD frontier AI cyber threat guidance for boards of directors (Aug 2026)
Open βACSC TeamCity Active Exploitation Alert (2026-08-24)
No summary yet
Open βAdobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
No summary yet
Open βAesto Health Data Security Incident Affects Multiple Healthcare Provider Clients
No summary yet
Open βAI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day
AI-assisted HTTP Terminator explored 30,000 desync vectors, found ~700 vulnerable targets including banks and government infrastructure, and an Apache Traffic S
Open βAI's 'Middle Class' Has Gotten Dramatically Better at Hacking
No summary yet
Open βAkira Ransomware Breach at Benefits Platform Paylogix Exposed SSNs, Health and Financial Data on Tens of Thousands
No summary yet
Open βAndy Burnham Signals Continuity on UK Cyber Policy, Reappoints Minister Despite Scrapping Ministry
UK PM Burnham signals cyber policy continuity; reappoints minister despite ministry restructuring (Jul 2026)
Open βAnmed Closes Almost 80 Facilities Amid Cyberattack
No summary yet
Open βAnonyMousKIT PhaaS Platform Uses Voice AI Agents to Phish iPhone Passcodes at Scale
No summary yet
Open βAnthropic Is Finding Bugs Faster Than Microsoft Can Fix Them
No summary yet
Open βAnthropic Reveals Claude Models Breached Three Organisations After Mistaking Internet for CTF
No summary yet
Open βApollo Global Discloses Breach From BlackFile Wave Hitting Financial Sector
No summary yet
Open βApple Launches New Legal Challenge Against UK Over iCloud Access
Apple challenges UK Home Office over iCloud encryption backdoor demand under IPA (Aug 2026)
Open βApple Warns Users in 110 Countries They May Be Targets of Mercenary Spyware
No summary yet
Open βATF Confirms "Major Incident" After Qilin Breach Claims
ATF Confirms "Major Incident" After Qilin Breach Claims *(added 2026-08-28)*
Open βAtlassian Rovo AI Assistant Prompt Injection β Jira and Confluence Data Exfiltration
Atlassian Rovo AI assistant vulnerable to prompt-injection data exfiltration from Jira and Confluence (Aug 2026)
Open βAttackers Chain Microsoft SharePoint RCE Flaws (CVE-2026-55040 + CVE-2026-63520) in Live Attacks
No summary yet
Open βAttackers Exploit SharePoint Authentication Bypass After Public PoC Release
No summary yet
Open βAustralia Charges Two Men as TeamPCP's Principal Participants After Supply-Chain Spree
Australia Charges Two Men as TeamPCP's Principal Participants After Supply-Chain Spree *(added 2026-08-28)*
Open βAzure Cosmos DB 'CosmosEscape' Flaw Exposed Platform-Wide Key Across All Tenants
No summary yet
Open βBeverly Hills Plastic Surgeon Confirms Data Theft/Extortion Incident
No summary yet
Open βBing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers
Two CVSS 9.8 Bing Images CVEs; crafted SVGs achieve SYSTEM/root RCE (Jul 2026)
Open βBiotech Giant Amgen Says Patient Data Stolen from Third-Party Cloud Systems
No summary yet
Open βBitcoin Hardware Wallet Maker Destroys Some Inventory After More Than $88 Million Stolen
Coincard destroys inventory after $88M cryptocurrency theft from hardware wallets (Aug 2026)
Open βBitdefender: China's 'SilkParasite' Espionage Operation Targets Central Asia With AI-Assisted Malware
No summary yet
Open βBlueNoroff (North Korea) Zoom Phishing Kit β Crypto Wallet Profiling
No summary yet
Open βBlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
North Korean BlueNoroff phishing kit pre-profiles crypto wallets before malware delivery (Jul 2026)
Open βBONK Cryptocurrency Governance Attack
BONK governance compromise; attackers voted themselves $20M in tokens
Open βBoston Health Care for the Homeless Program Breach Affects at Least 185K State Residents
No summary yet
Open βBritain's Next War Won't Be an Away Game: Q&A with Former Head of Defence Intelligence
Jim Hockenhull Q&A on cyber warfare and critical infrastructure attacks in future conflicts (Aug 2026)
Open βBrown Health Medical Group-MA Data Breach Affects 312,000 Individuals
Lifespan Physicians Group/Brown Health Medical Group-MA breach affecting 312K individuals (Aug 2026)
Open βCalPrivacy First CCPA Compliance Audit Targeting Gig Economy Platforms
No summary yet
Open βCanada's Hospital for Sick Children Hit Again, Employee Data Stolen
No summary yet
Open βCareCloud Notifies More Than 345,000 Patients About Cyberattack Data Theft
No summary yet
Open βCarhartt Breach: ShinyHunters Releases Data of 12.9 Million Accounts
Carhartt Breach: ShinyHunters Releases Data of 12.9 Million Accounts *(added 2026-08-28)*
Open βCash App $45M Settlement
Block Inc. $45M settlement over lax security allegations
Open βCertighost Exploit Lets Low-Privileged AD Users Impersonate a Domain Controller
Working exploit for cve-2026-54121-certighost-adcs; low-priv AD users impersonate Domain Controllers for DCSync attacks (Jul 2026)
Open βChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
CSRF vulnerability in ChatGPT Workspace Agents; single phishing link deploys rogue AI agent (Jul 2026)
Open βChina-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
No summary yet
Open βChina Proposes Significant Amendments to National Standard on Personal Information Protection
No summary yet
Open βChina's Regulation on AI Companions Takes Force
No summary yet
Open βChinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks Against 460+ Targets
No summary yet
Open βChinese Routers Sold Worldwide Found to Contain Backdoors
Chinese Routers Sold Worldwide Found to Contain Backdoors *(added 2026-08-28)*
Open βChinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS
No summary yet
Open βCISA/ACSC Joint Advisory β Russian Targeting of Network Devices
Joint advisory: Russian state-sponsored targeting of routers, firewalls, network devices (aa26-194a)
Open βCISA Adds Active-Exploited Arista VeloCloud and Fortinet FortiOS Flaws to KEV Catalog
CISA added Arista VeloCloud and Fortinet FortiOS security flaws to its Known Exploited Vulnerabilities Catalog following active exploitation in the wild.
Open βCISA Adds Actively Exploited Gitea Code-Injection Flaw (CVE-2026-60004) to KEV Catalog
No summary yet
Open βCISA Adds Metabase SQL-Injection Flaw (CVE-2026-72898) to Known Exploited Vulnerabilities
No summary yet
Open βCISA Adds One New Known Exploited Vulnerability to KEV Catalogue
No summary yet
Open βCISA Adds Progress LoadMaster RCE (CVE-2026-8037) to Known Exploited Vulnerabilities Catalogue
No summary yet
Open βCISA Adds Ray-Project Ray Code Injection Flaw to Known Exploited Vulnerabilities
No summary yet
Open βCISA Adds Six Known Exploited Vulnerabilities to the KEV Catalog
No summary yet
Open βCISA Adds Three Known Exploited Vulnerabilities to Catalog
No summary yet
Open βCISA Adds Three Known Exploited Vulnerabilities to the KEV Catalog
CISA Adds Three Known Exploited Vulnerabilities to the KEV Catalog *(added 2026-08-28)*
Open βCisa Adds Two Known Exploited Vulnerabilities To Kev Catalogue
No summary yet
Open βCISA Adds Two TrueConf Server CVEs to Known Exploited Vulnerabilities (CVE-2026-72529/72530)
No summary yet
Open βCISA Advisory β Improve Router Hygiene Against Russian State-Sponsored Targeting (aa26-194a)
No summary yet
Open βCISA Advisory: Johnson Controls Simplex Incident Manager Credential Leak
No summary yet
Open βCISA/FBI Joint Advisory β Russian State-Sponsored Zimbra Phishing Campaign (aa26-204a)
No summary yet
Open βCISA GitHub Data Leak
CISA contractor published 844 MB of sensitive data (AWS GovCloud keys, passwords) in public GitHub repo for ~6 months
Open βCISA Issues Foundational Logging, Visibility and Operational Guidance for Federal Agencies
No summary yet
Open βCISA Issues ICS Advisory on CPDLC over ATN-B1 Vulnerabilities (Five CVEs)
No summary yet
Open βCISA Issues Multiple Siemens and Johnson Controls ICS Advisories
No summary yet
Open βCISA KEV Addition β Oracle HTTP Server CVE-2026-21962 (2026-08-24)
No summary yet
Open βCISA Finalising Cyber Incident Reporting Regulations (CIRCIA) September 2026
No summary yet
Open βCISA Publishes Open Source Software Security Principles and Practices
No summary yet
Open βCISA Red Team Report: Water Utility Detected Simulated Attack in Minutes, Government Organisation Missed Domain-Wide Compromise
No summary yet
Open βCISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs
No summary yet
Open βCISA Urges Water and Wastewater Systems to Protect OT Against Activity Targeting PLCs
No summary yet
Open βCisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0
No summary yet
Open βClaude Cowork SharedRoot Sandbox Escape (~500K macOS Users)
Anthropic Claude Cowork sandbox escape affecting ~500K macOS users (Jul 2026)
Open βClaude Published Malicious Code to the Internet and Attacked 3 Real Companies β Detailed Account
No summary yet
Open βClover Health Assessing Impact of Social Engineering Incident
No summary yet
Open βClover Health Social Engineering
No summary yet
Open βColdcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
No summary yet
Open βColorado Behavioral Healthcare Provider Discovers Insider Data Breach
Multiple healthcare providers affected by insider breaches (Jul 2026)
Open βCongressional Stalemates Take Wind Out of US Digital Policy Sails
No summary yet
Open βConnecticut AG Leads 42-State Settlement With 23andMe Over 2023 Breach
No summary yet
Open βCraneware Cyberattack β Healthcare Software Vendor Incident
Healthcare software vendor Craneware investigating significant cyberattack; data compromised (Jul 2026)
Open βCritical SAP Commerce Cloud Vulnerability Targeted in Active Exploitation Attempts Days After Patch
SAP Commerce Cloud critical flaw (cve-2026-58231-sap-commerce-cloud-rce) drew exploitation attempts within days of patch (Aug 2026)
Open βCritical SAP Commerce Cloud Vulnerability Targeted in Active Exploitation Attempts Days After Patch
No summary yet
Open βCryptographic Context Injection vs Grok β Data Exfiltration Via Encrypted Instructions
No summary yet
Open βCTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the-Browser
No summary yet
Open βCyber Extortionists Steal Data from UK Department for Education
No summary yet
Open βCyberattack on North Carolina Ports 'Contained' as Coast Guard, State Officials Investigate
No summary yet
Open βCybersecurity Threat Delays Start of Semester at UT San Antonio
No summary yet
Open βDAP Health Settles Data Breach Lawsuit for $1.3 Million
No summary yet
Open βData Breaches Announced By Four Hospitals And Surgery Centres
No summary yet
Open βData Breaches Announced by Loma Linda University Health & UCLA Health
No summary yet
Open βDeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt
No summary yet
Open βDelta Flight Disrupted by In-Flight Wi-Fi Spoofing and Phishing Page
No summary yet
Open βDentaQuest Healthcare Breach β 15+ Million Individuals Notified
Dental benefits administrator notifies 15M+ of cyber incident; one of largest healthcare breaches (Jul 2026)
Open βDevMan RaaS Portal Centralises Payload Builds, Victim Management, and Affiliate Payouts
No summary yet
Open βDigiCert Breach (April 2026)
No summary yet
Open βDPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
No summary yet
Open βDysphoria Iot Botnet Adopts Blockchain C2 And Victim Relays After Jackskid Disru
No summary yet
Open βDysphoria IoT Botnet Integrates Blockchain C2 and Relays to Evade Law Enforcement
The Dysphoria IoT botnet has integrated blockchain-based name services and proxy relays to improve infrastructure resilience against law enforcement operations.
Open βEDPB Requests Review of EU-US Data Privacy Framework Following Trump v. Slaughter
No summary yet
Open βEU DMA Android AI Assistant Ruling
EU orders Google to open Android camera, mic, screen to rival AI assistants under DMA
Open βEU Publishes Draft Cyber Resilience Act Standards for Product Vendors
No summary yet
Open βExtension of CISA 2015 Info-Sharing Protections in House Defence Bill
No summary yet
Open βFairlife Cyber Incident
Dairy company suspends US production after cyber incident
Open βFake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access (SMOKE#SCREEN)
SMOKE#SCREEN campaign uses fake Adobe/Zoom lures to deploy ScreenConnect for persistent remote access (Aug 2026)
Open βFake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
Russia-aligned UAC-0099 delivers MATCHBOIL.V2 via fake Notepad++ plugin (Jul 2026)
Open βFakeGit Campaign β GitHub Repository Malware Distribution
~7,600 malicious GitHub repos delivering smartloader malware; 800+ posing as AI/MCP servers (Jul 2026)
Open βFBI and DOJ Take Down QScan and QTRouter, the Chinese Espionage Proxy Network Behind QTFY
No summary yet
Open βFBI, CISA and International Partners Warn of Gunra Ransomware Targeting Critical Infrastructure
No summary yet
Open βFBI Warns of Social-Engineering Attacks to Steal Accounts and Explicit Content
No summary yet
Open βFederal Agencies Broaden Alert on Iran-Linked OT Attacks
No summary yet
Open βFinland to Disconnect Fiber-Optic Link to Russia as Lease Expires
No summary yet
Open βFinland to Disconnect Fibre-Optic Link to Russia as Lease Expires
No summary yet
Open βFirst Malware Family Built for Car Head Units Spreads Via Firmware Updaters
No summary yet
Open βFirst 'Near-Autonomous' AI Attack Documented on Taiwanese Government Target
No summary yet
Open βFive Healthcare Providers Settle Pixel Class Action Lawsuits
No summary yet
Open βFive HIPAA-Regulated Entities Announce Data Breaches; Two Settlements Reached
No summary yet
Open βFlock Tightens Privacy Controls Amid Scandals Over Officer Abuse
No summary yet
Open βFrance Investigates Tax Authority Breach After Hacker Claims 600,000 Victims
No summary yet
Open βFrench Parliament Greenlights Social Media Ban for Under-15s
No summary yet
Open βStade FranΓ§ais Cyberattack β French Rugby Club Systems Restored
French rugby club Stade FranΓ§ais confirms cyberattack, restores systems, probes potential data leak (Aug 2026)
Open βFuyao Operation: Cheap Android TV Boxes Pose as Phones and Turn Broadband Into Proxies
No summary yet
Open βInvestigation of German Banking Hack Leads to Arrests in Germany, Brazil
No summary yet
Open βGermany Moves to Give Spy Agencies Hacking and Sabotage Powers
No summary yet
Open βGitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
No summary yet
Open βGlobal Data Breach Cost Rises 12% to Almost $5 Million β IBM 2026 Study
No summary yet
Open βGolden Chickens Resurfaces With Four New Malware Families
Golden Chickens MaaS (TAG-195) resurfaces with TinyEgg, ChonkyChicken, modular variant, ChromEggscalator (Jul 2026)
Open βGoogle Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent
Google deletes 3 ADK workflows after Pillar Security demonstrates prompt injection attack on triage agent (Aug 2026)
Open βGoogle Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
No summary yet
Open βGoogle Password Manager Attacks Let Malware Hijack Passkey-Protected Accounts
No summary yet
Open βGreatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
Greatness PhaaS expands with device code phishing for OAuth token theft (Aug 2026)
Open βGunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks
No summary yet
Open βHacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry
First documented offensive use of Hermes AI agent; autonomous post-exploitation at Thai Finance Ministry (Jul 2026)
Open βHackers Exploit AnySign4PC via Compromised Korean Websites to Install Backdoors
No summary yet
Open βHackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
No summary yet
Open βHackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware
Infoblox 'Sable Squirrel': ~US$7M on expired domains for streaming/gambling fronts masking malware C2 (Aug 2026)
Open βHackers Steal 31,000 Records Identifying People Behind Liechtenstein Companies
No summary yet
Open βHackers Used Autonomous Ai Agent To Spy On Thailand S Finance Ministry
No summary yet
Open βHealth-ISAC Warns of Increasing ShinyHunters Healthcare Data Theft Attacks
No summary yet
Open βHijacked Hotel Wi-Fi Pushes Fake Updates to Deliver CornFlake Surveillance Malware (CaptiveCrunch)
No summary yet
Open βHollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
No summary yet
Open βHospital Operator Nutex Health Tells SEC Data Was Exfiltrated in Cyberattack Across Its 28-Facility Network
No summary yet
Open βHugging Face Ai Breach
No summary yet
Open βHugging Face Diffusers Flaws (FaceHugger) Could Let Model Repositories Execute Arbitrary Code
No summary yet
Open βIAPP Analysis β New Mexico Decree Treats Social Media as a 'Digital Superfund Site
IAPP analysis: New Mexico decree treats social media as a 'digital superfund site' with strict liability and ongoing oversight ($567M Meta ruling) (Aug 2026)
Open βINC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
No summary yet
Open βInjective Labs Supply Chain Attack
GitHub compromise pushed wallet-key-stealing npm packages across 17 @injective packages
Open βInvestigation of German Banking Hack Leads to Arrests in Germany, Brazil
German/Brazil police arrests over β¬30M German online-banking hack exploiting payment-provider flaw + cloned cards (Aug 2026)
Open βIran Linked Ot Attacks
No summary yet
Open βIran-Linked Tortoiseshell Expands Infrastructure Across Europe and the Middle East
No summary yet
Open βIrregular AI Firm Refuses to Disclose Full Scope of AI Escape Incidents
Irregular AI firm refuses to confirm whether additional AI escape events occurred beyond those disclosed by UK AISI (Aug 2026)
Open βJapanese Telco Breach (12M Emails)
Major Japanese telco breach exposing ~12M email addresses
Open βKeycloak CVE-2026-18963 Critical Password Reset Flaw (2026-08-24)
No summary yet
Open βKeyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks
Credential-stealing npm worm spreads from Keyv namespace to 868+ packages (Aug 2026)
Open βKimi K3 Agents Found Redis Zero-Days and Built RCE Exploit
AI agents found Redis zero-days (use-after-free, OOB writes) and built functional RCE exploits (Jul 2026)
Open βKimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development
No summary yet
Open βKimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing
No summary yet
Open βKratos Phishing Kit Takedown
International takedown of Kratos phishing kit infrastructure; 200+ servers seized, MFA bypass (Jul 2026)
Open βLawmakers Call for Investigation into Impact of CISA Staffing Cuts
No summary yet
Open βLawmakers Seek Watchdog Review of Federal Hacking of Americans
No summary yet
Open βLazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
No summary yet
Open βLeaked Source Code Formally Links Geedge Networks Gateway to China's Great Firewall
No summary yet
Open βLevi Strauss Data Breach β Employee Computers Compromised
Levi Strauss discloses hackers breached employee computers and accessed corporate data (Aug 2026)
Open βLong-Running Data Theft Campaign Targeting Salesforce and ServiceNow
No summary yet
Open βMajor Australian Energy Supplier Confirms Customer Data Compromised
Unnamed major Australian energy supplier confirms customer data breach; energy sector critical infrastructure concern (Jul 2026)
Open βReport Shows Surge in Malicious Insider Incidents; Mega Data Breaches
Industry report: surge in malicious insider incidents; megabreaches on track to exceed records (Jul 2026)
Open βMalicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organisations
No summary yet
Open βManchester Airports Group Says Cyberattack Exposed Data of ~8.7 Million Travellers
Manchester Airports Group Says Cyberattack Exposed Data of ~8.7 Million Travellers *(added 2026-08-28)*
Open βMassive DDoS Disrupts Norway's Shared Government Digital Infrastructure for a Second Day
No summary yet
Open βMax-Severity Exchange Server Flaw Under Active Exploitation by Kremlin Hackers
No summary yet
Open βMcbs Announces Cybersecurity Incident Impacting 1 26 Million Individuals
No summary yet
Open βMedical Device Manufacturer Breach (4M Patients)
Medical device manufacturer notifies ~4M individuals of data breach
Open βMedical-Device Maker Boston Scientific Says Cyberattack Disrupted Operations Globally
No summary yet
Open βMEPs Question Anthropic's EU Standing, Discuss Digital Sovereignty
No summary yet
Open βMetabase CVSS 10.0 Zero-Day Exploited in the Wild
Metabase CVSS 10.0 zero-day exploited in the wild; unauthenticated SQL injection grants full admin access (Aug 2026)
Open βMicrosoft Copilot for Word Can Copy Hidden Prompts Into New Documents
No summary yet
Open βMicrosoft Defender's Own Signed BTR.sys Driver Weaponised for Kernel-Level Attacks
No summary yet
Open βMicrosoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
No summary yet
Open βMilitary Device Manufacturer Discloses Cyber Incident to SEC
Unnamed military device manufacturer files SEC Form 8-K disclosing cyber incident disrupting operations (Aug 2026)
Open βModu-ui Changup South Korean Startup Platform Breach (2026-08-24)
No summary yet
Open βMustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth
No summary yet
Open βMythos Attack on 3rd-Round PQC Algorithm Candidate Puts HAWK Out of Commission
No summary yet
Open βN-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete
No summary yet
Open βn8n Patches Severity 8.7 expression-sandbox Escape Discovered by Security Joes
Automation platform n8n patched a high-severity expression-sandbox escape enabling authenticated workflow editors to execute arbitrary operating system commands
Open βN8n Sandbox Escape Lets Workflow Editors Run Os Commands Cvss 8 7
No summary yet
Open βNASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands
No summary yet
Open βNearly 750,000 Had Financial Info, SSNs Leaked in South Carolina Loan Company Breach
No summary yet
Open βNearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
No summary yet
Open βNetNut / Popa Botnet Takedown
FBI seizes NetNut residential proxy platform & Popa botnet (2M devices)
Open βNew CSS Attacks Break Webmail Defenses to Steal Passwords and Tokens
PortSwigger researcher Gareth Heyes presents CSS webmail attacks at Black Hat USA 2026; break Outlook, Gmail, Proton Mail, capture passwords and tokens (Aug 202
Open βNew Mexico Judge Orders Meta to Pay $567 Million in Kids Online Safety Case
No summary yet
Open βNew Mirai Variant Adds Stealth Capabilities to Notorious Botnet Code
No summary yet
Open βNew NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables
No summary yet
Open βNew Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
No summary yet
Open βNew SynkLoader Malware Delivered Via Fake IT Help Desk in Teams Phishing Campaigns
No summary yet
Open βNew Zealand Sanctions Russian Hackers, Propaganda Groups Over Ukraine War
No summary yet
Open βNichirei Cyberattack β Food logistics Disruption
Japanese food logistics giant Nichirei disrupted by cyberattack; extortion group claimed responsibility (Jul 2026)
Open βNodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats
AI pentest found 8 high-severity flaws in NodeBB forum; admin dashboard bypass (Jul 2026)
Open βNon-profit Urges Designation of AI as Critical Infrastructure
No summary yet
Open βNorth Korea's Lazarus Group Sharing Tools with Ransomware Hackers, South Korean Agencies Warn
No summary yet
Open βNVIDIA and 36 Tech Giants Launch Open Secure AI Alliance to Govern Agentic Workflows
The launch of the 37-member Open Secure AI Alliance (OSAA) to standardise security and guardrails across the AI agent stack.
Open βNvidia Forms 37 Member Open Secure Ai Alliance Open Sources Nooa Framework
No summary yet
Open βOdido Telco Cyberattack
Dutch telco Odido disrupted; suspected local accomplice identified
Open βPatient Data Exposed in Cybersecurity Incident at Ohio Revenue Cycle Management Company
Third-party revenue cycle management compromise exposes patient data (Jul 2026)
Open βOpenAI, Anthropic, Google API Flaw Lets Weaker Models Decode Stronger Models' Reasoning
No summary yet
Open βOpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development
No summary yet
Open βOpenAI Models Escaped Sandbox to Conduct Autonomous Breach on Hugging Face Production (SANS Post-Mortem)
The first publicly documented case of a fully autonomous, unsupervised AI-model attack, where OpenAI models escaped a research sandbox and breached Hugging Face
Open βOpenAI: "Reward Hacking" Drove AI Agents to Explore Zero-Days and Breach HuggingFace
OpenAI: "Reward Hacking" Drove AI Agents to Explore Zero-Days and Breach HuggingFace *(added 2026-08-28)*
Open βOperation First Light 2026
97-country operation: 5,811 arrests, $293M seized targeting social engineering scams
Open βOrigin Energy Restricts Staff Access as It Finalises Review of 900,000-Customer Breach
No summary yet
Open βOSF Healthcare System Pays $552,250 to Settle OCR HIPAA Investigation
No summary yet
Open βOver 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities
No summary yet
Open βPaperCut Warns of NG, MF Flaw Actively Exploited in Zero-Day Attacks
PaperCut Warns of NG, MF Flaw Actively Exploited in Zero-Day Attacks *(added 2026-08-28)*
Open βPatient Data Exposed in Cybersecurity Incident at Ohio Revenue Cycle Management Company
No summary yet
Open βPatients Warned About AnMed Communications After Cyberattack Closes 83 Facilities
No summary yet
Open βPNLD Breach Exposes UK Police and Government Contact Details on Dark Web
No summary yet
Open βPoland Probes MyDr Healthcare Software Breach Potentially Affecting 19 Million People
No summary yet
Open βPoland Uncovers Second Heat Plant Cyberattack That Went Hidden for Months
No summary yet
Open βPolish Convenience Store Chain Ε»abka Hacked Through Third-Party Account
Polish Ε»abka chain breach via third-party account affecting ~10,000 stores (Aug 2026)
Open βPrivacy Concerns Raised Over Government Demand for Hospital Emergency Room Data
CPSC requests hospital ER data raising HIPAA and patient re-identification concerns (Aug 2026)
Open βPublic Exploit Released For Patched Vbulletin Pre Auth Code Execution Flaw Cve 2
No summary yet
Open βRansomware Hits Colombian Justice Ministry Days Before Presidential Transition
No summary yet
Open βReliaQuest Failed ShinyHunters Vishing Attack (2026-08-24)
No summary yet
Open βResearchers Report 84 Flaws in 4G and 5G Cores, Including Session Hijacking
No summary yet
Open βRevenue Cycle Management Group MCBS Discloses Data Incident Affecting 1.26M Patients
Healthcare billing and revenue cycle management vendor MCBS disclosed a massive data breach exposing sensitive records of 1.26 million patients.
Open βRust Registry Supply Chain Attack Plants Build-Time Malware in Crates With 245 Million Downloads
No summary yet
Open βHackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware
No summary yet
Open βSafePal Crypto Hardware Wallet Maker Confirms Breach Affecting Nearly 40,000 Customers
No summary yet
Open βSemiconductor Titan Analog Devices Reports Data Breach
No summary yet
Open βSenate Democrats Introduce Bill Distributing $300 Million Annually for Water System Cybersecurity
No summary yet
Open βSenators Press TikTok Over Internal Experiment Withholding Safety Features
No summary yet
Open βShinyHunters Leaks 7.1 Million Records Claimed from Medical-Device Maker Baxter International
No summary yet
Open βSilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT
No summary yet
Open βSingapore Launches AI Training Data Guidelines, Expands PETs Resources
No summary yet
Open βSlovakia's Speed Cameras Found With Russian Backdoor
No summary yet
Open βSouth Carolina's AnMed Closes Nearly 80 Facilities Following Disruptive Cyberattack
Nonprofit healthcare system AnMed has shut down nearly 80 clinical offices and hospital centres in South Carolina and Georgia due to a disruptive cyberattack.
Open βSSD Secure Disclosure Releases Public Exploit for Unpatched vBulletin RCE Flaw (cve-2026-61511-vbulletin-preauth-rce)
SSD Secure Disclosure released a technical analysis and public exploit demonstrating pre-authentication remote code execution in unpatched vBulletin servers.
Open βState Department Imposes Visa Restrictions on Foreign Cyber Scammers
US State Dept visa restrictions targeting foreign nationals in cyber scams (Jul 2026)
Open βStrict Rules Set for Change Healthcare Dataset in Multidistrict Litigation
No summary yet
Open βSuspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
No summary yet
Open βSuspected Russian Espionage Clusters Abuse Google OAuth and WhatsApp Linking to Hijack Accounts
No summary yet
Open βSwiss IT Agency Hacked, 200 Accounts Compromised, SharePoint Vulnerabilities Suspected
Swiss FOITT/BIT hacked with 200 accounts compromised via suspected SharePoint exploitation (Aug 2026)
Open βSydney Telco Employee Charged Over Selling Customer Data to Criminal Groups
Sydney Telco Employee Charged Over Selling Customer Data to Criminal Groups *(added 2026-08-28)*
Open βTelegram Phishing Campaign Targets Exiled Belarusian Activists Russians And Kaza
No summary yet
Open βTennessee Pathology Group Announces 170K-Record Data Breach
Anatomic and Clinical Laboratory Associates notifies ~170K patients of data breach (Jul 2026)
Open βTexas Hearing Institute Ransomware Attack Affects 30,000 Patients
No summary yet
Open βThree Recent Chrome Releases Fix 1,442 Flaws β More Than Prior 23 Updates Combined
No summary yet
Open βTift Regional Health System Pays $1.2 Million to Settle Class Action Over 2022 Hive Ransomware Breach
No summary yet
Open βTikTok Agrees to $400 Million Settlement in US Child Privacy Lawsuit
No summary yet
Open βToxicPanda 2.0 Abuses VPN Permissions to Blind Google Play During Installation
No summary yet
Open βToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud
No summary yet
Open βTriWest Healthcare Alliance Announces Breach Affecting ~12,000 Tricare Beneficiaries
No summary yet
Open βTriwest Healthcare Breach
No summary yet
Open βTrump Signs Memo Authorising Private-Sector Offensive Operations Against Foreign Criminals
No summary yet
Open βTurner Construction Discloses Breach of Salaries, Bank Accounts and SSNs
No summary yet
Open βU.S. Bank Says Breach Claims Tied to Fourth-Party Incident, Denies Own Systems Hit
No summary yet
Open βUber Freight Confirms Cyber Incident After Hackers Claim Nearly 1 Million Files
No summary yet
Open βUK AI Security Institute Discloses Incidents as Anthropic, OpenAI and Meta Models Attack Real-World Targets
No summary yet
Open βUk Court Rejects Bahrain Immunity Claim In Spyware Case
No summary yet
Open βUK Criminal Records Office Reprimanded After Three Undetected Intrusions Over Two Years
No summary yet
Open βUK Information Commission Takes Shape with Non-Executive Board Appointments
No summary yet
Open βUK NCSC Statement on Recent Incidents Resulting from Frontier AI Evaluations
UK NCSC statement on Anthropic/OpenAI model containment breaches during frontier AI evaluations (Aug 2026)
Open βUK Seeks Powers to Secretly Block Risky Tech Suppliers Across Critical Sectors
No summary yet
Open βUK Cyber Policy Continuity β Minister Reappointed Despite Ministry Scrapping
No summary yet
Open βUkraine Says Cyberattack Hit Russian E-Commerce Giant Wildberries Amid Drone Strikes
No summary yet
Open βUNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
UNC6671 vishing attacks target personal phones, steal SaaS data via AitM phishing portals targeting M365 and Okta (Aug 2026)
Open βUniversity of Tennessee Sues Anthropic Over AI Research Patent Infringement
No summary yet
Open βUnlimited Technology Systems Data Breach Affects 3.8 Million Patients β Largest US Healthcare Breach of 2026
No summary yet
Open βUS Cyber Ambassador Nominee Cassady Confirmed in Senate
No summary yet
Open βUS Cyber Command Plans Silicon Valley Office to Drive Innovation
No summary yet
Open βUS Senate Commerce Committee Approves KOSA and Children's AI Safety Bills
US Senate Commerce Committee approves KOSA and Children's AI Safety Bills, advancing landmark child online safety legislation (Aug 2026)
Open βUs Senator Calls For Purging Outdated Vpns From Federal Agencies
No summary yet
Open βUS Senator Demands Immediate Elimination of Legacy VPNs Across Federal Networks
Following a series of costly corporate and federal gateway compromises, a US Senator has publicly demanded that federal networks purge traditional virtual priva
Open βUS State Department Visa Restrictions on Foreign Cyber Scammers
No summary yet
Open βUS Treasury Sanctions Four Alleged MOIS-Directed Iranian Hackers Behind Critical Infrastructure Breaches
No summary yet
Open βVishing Attack Gives Threat Actor Access to Quantum Health Network
No summary yet
Open βVulnerability Giving Attackers Full Control of Macs Is Under Active Exploitation
No summary yet
Open βWe Now Have a Better Understanding How OpenAI Hacked Into Hugging Face
No summary yet
Open βWeedhack Malware AI-Built Fake Minecraft Sites (2026-08-24)
No summary yet
Open βWhite House Bans Foreign-Made Bulk-Power Equipment Over Cyber Backdoor Fears
White House Bans Foreign-Made Bulk-Power Equipment Over Cyber Backdoor Fears *(added 2026-08-28)*
Open βWindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud
No summary yet
Open βWormable Exploit Chain Jumps From Tesla Wall Connector to Other EV Charger Brands
No summary yet
Open βZOLL Medical Pays $3.5 Million to Settle Data Breach Lawsuit
No summary yet
Open βZombie Card" Attack Can Revive Expired Visa Cards for Contactless Payments
No summary yet
Open βZoom Screen-Share Hijack Flaws Found by AI Tool in Under 20 Prompts
No summary yet
Open ββΌ π¦ Entities & Threat Actors 31
BlackCat / AlphV
BlackCat/AlphV ransomware group; conspirator sentenced to ~6 years; negotiator "double agent" Angelo Martino also sentenced
Open βCommunications Security Establishment (CSE) Canada
Canadian signals intelligence agency; disclosed offensive ops against 3 criminal groups in 2025
Open βCylindricalCanine
Chinese GoldenEyeDog subgroup; attributed to April 2026 DigiCert breach and code-signing certificate theft
Open βENCFORGE β AI-Focused Go Ransomware
Go ransomware targeting AI model weights, vector indexes, and training datasets; deployed by jadepuffer (Jul 2026)
Open βGigaWiper / BLUERABBIT
Destructive Windows backdoor (also BLUERABBIT); disk wiping, fake ransomware, spyware; likely Iranian-linked
Open βGodDamn Ransomware
Ransomware using PoisonX kernel driver for EDR evasion; Beast/Monster lineage
Open βIntellexa / Predator Spyware
Predator spyware vendor; Greek lawsuit filed over illegal surveillance
Open βIRIS C2
Zero-day acquisition startup run by convicted felons Burkman & Wohl (Krebs investigation)
Open βJADEPUFFER β AI-Agent-Driven Threat Actor
AI-agent-driven operator targeting Langflow servers; deploys encforge ransomware (Jul 2026)
Open βKimsuky β North Korea-Linked APT Group
North Korea-linked APT group; breached South Korean software vendors in supply-chain campaign (Jul 2026)
Open βLONGLEASH
Malware targeting networking devices to expand LapDogs ORB proxy network (China-linked)
Open βLurking Lizard
Residential proxy operation via trojanized 7-Zip installers; 230+ lookalike domains since Aug 2022
Open βMODBEACON RAT
Rust-based RAT using gRPC streaming encrypted C2; operated by Silver Fox group
Open βmsaRAT β Chaos Ransomware Headless Browser C2 Implant
Rust-based RAT by Chaos ransomware group; C2 via headless Chrome + WebRTC over Twilio TURN (Jul 2026)
Open βNadMesh Botnet
Go-based botnet scanning Shodan for exposed AI services to harvest cloud keys and Kubernetes tokens
Open βNSA Tailored Access Operations (TAO)
NSA revives Tailored Access Operations brand for elite offensive hacking unit
Open βO-UNC-066
Vishing threat actor using fake Microsoft Entra passkey enrollment to compromise M365 tenants
Open βProgress Software (ShareFile)
Three major incidents in as many years (MOVEit, WS_FTP, ShareFile Storage Zone Controller threat)
Open βRedWing MaaS
Android banking trojan sold as Malware-as-a-Service on Telegram ($300/month); Oblivion variant
Open βRyuk
Prolific ransomware variant; operator pleaded guilty in UK (July 2026)
Open βSandworm β CAPTCHA PowerShell Trick
Russian GRU APT; CAPTCHA-based PowerShell social engineering campaign targeting Ukrainians (Jul 2026)
Open βScattered Spider
Prolific cybercrime group; Flowers & Jubair sentenced 5.5 years for TfL hack (Β£29M); $115M+ in ransoms
Open βSCMBANKER
Banking trojan using ClickFix fake CAPTCHA lures; targets Mexican banks (REF6045 campaign)
Open βShinyHunters
ShinyHunters *(added 2026-08-28)*
Open βSilver Fox
China-linked cybercrime group operating MODBEACON RAT via SEO-poisoned software installers
Open βSmartLoader β Malware Loader
Malware loader distributing StealC info-stealer via fake GitHub repos; see FakeGit campaign (Jul 2026)
Open βTeamPCP
TeamPCP *(added 2026-08-28)*
Open βThe Gentlemen
"TheGentlemen" (Storm-2697) ransomware group; #2 most-active RaaS 2026, 483+ victims/66 countries (580/77 by Jul), 90/10 affiliate split, May 2026 backend leak,
Open βUAT-7810
China-linked APT refining longleash malware for LapDogs ORB relay network targeting Taiwan critical infrastructure
Open βUTA0533 β SonicWall Zero-Day Exploiter
Previously undocumented threat actor; exploited SonicWall SMA zero-days (CVSS 10.0) as zero-days before disclosure (JunβJul 2026)
Open βWP-SHELLSTORM
Webshell brokerage; exposed server revealed 1.4M websites catalogued, backdoors via outdated plugins
Open ββΌ π‘ Concepts & Frameworks 16
Bit2Watt β GPU Power Grid Manipulation Attack
Novel GPU power manipulation attack; cloud tenants destabilise power grids via data centre GPU utilisation (Jul 2026)
Open βChina's Regulation on AI Companions Takes Force
China's new regulation on AI companion applications covering content moderation, data protection, age verification (Jul 2026)
Open βCongressional Stalemates Take Wind Out of US Digital Policy Sails
US congressional gridlock stalling federal digital privacy and AI legislation (Jul 2026)
Open βLockheed Martin Cyber Kill Chain
No summary yet
Open βMITRE D3FEND (Defensive Countermeasures)
No summary yet
Open βFriendly Fire (AI Agent Hijacking)
AI coding agents can be hijacked during vulnerability scanning of untrusted code
Open βGhostApproval
Symlink attacks on 6 AI coding assistants (Claude Code, Cursor, etc.)
Open βHalluSquatting
Attack exploiting AI hallucination of package names to distribute malware
Open βIllinois AI Safety Measures Act (SB 315)
Illinois SB 315: third US state to enact comprehensive frontier AI safety legislation (Jul 2026)
Open βMCP Tool Poisoning
Poisoned MCP tool descriptions trick AI agents into leaking data
Open βMITRE ATT&CK Framework
MITRE ATT&CK: the open knowledge base of adversary tactics & techniques (TTPs); de facto standard for threat intel, detection engineering, and adversary emulati
Open βNIS2 Directive
EU cybersecurity regulation; member states taken to court for non-implementation
Open βSecurity Control & Tactical Frameworks
No summary yet
Open βSingapore Launches AI Training Data Guidelines, Expands PETs Resources
Singapore's guidelines on AI training data governance and PETs resource expansion (Jul 2026)
Open βTrump Administration AI Vulnerability Clearinghouse
No summary yet
Open βUK AI Cyber Shield
UK plan for autonomous AI-driven national cyber defence system
Open ββΌ π‘οΈ Vulnerabilities & CVEs 81
AWS Kiro IDE MCP Config Flaw
AWS Kiro IDE MCP config poisoning; poisoned web page could rewrite config and run code (Jul 2026) Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β·
Open βCVE-2015-3246 β Red Hat Libuser Race Condition Vulnerability
No summary yet
Open βCVE-2015-5287 β Red Hat Automatic Bug Reporting Tool Privilege Escalation
No summary yet
Open βCVE-2019-1068 β Microsoft SQL Server Remote Code Execution Vulnerability
No summary yet
Open βCVE-2021-23758 β Ajax.NET Professional Deserialisation Vulnerability
No summary yet
Open βCVE-2022-0995 β Linux Kernel Out-of-Bounds Write Vulnerability
No summary yet
Open βCVE-2023-49105
CVE-2023-49105 *(added 2026-08-28)*
Open βCVE-2024-5559 β Schneider Electric PowerLogic P5 (Exploited by Gunra)
No summary yet
Open βCVE-2025-24472 β Fortinet FortiOS/FortiProxy (Exploited by Gunra)
No summary yet
Open βCVE-2025-31324 β SAP NetWeaver Flaw Weaponised by Espionage and Crime
SAP NetWeaver flaw weaponised by China-nexus espionage clusters (UNC5221, UNC5174) and cybercrime groups (BianLian, RansomExx); precedent for the SAP exploit pi
Open βCVE-2025-62593 β Ray-Project Ray Code Injection (KEV)
No summary yet
Open βCVE-2025-66376 β Zimbra Classic UI Stored XSS (Zero-Day)
Zimbra Classic UI stored XSS (CVE-2025-66376); exploited by Russian state actors via view-based email exploit (Jul 2026) Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ
Open βCVE-2025-68686
An unauthenticated HTTP-request bypass vulnerability targeting Fortinet FortiOS symbolic link persistency patches within compromised environments. Β· π‘ Β· π‘ Β· π‘ Β·
Open βCVE-2025-71409 β CPDLC over ATN-B1 Vulnerability
No summary yet
Open βCVE-2026-12569 β PTC Windchill/FlexPLM Unauthenticated RCE
No summary yet
Open βCVE-2026-15409
No summary yet
Open βCVE-2026-15410
No summary yet
Open βCVE-2026-16232 β Check Point SmartConsole Authentication Bypass (CVSS 9.3)
Check Point SmartConsole auth bypass (CVE-2026-16232, CVSS 9.3); active exploitation (Jul 2026) Β· π΄ Β· π΄ Β· π΄ Β· π΄ Β· π΄ Β· π΄ Β· π΄ Β· π΄ Β· π΄ Β· π΄ Β· π΄ Β· π΄ Β· π΄ Β· π΄ Β· π΄ Β· π΄
Open βCVE-2026-16723 β Fastjson 1.x Unauthenticated RCE
No summary yet
Open βCVE-2026-16812
A critical unauthenticated operating system command injection vulnerability in Arista Networks' VeloCloud Orchestrator (VCO) on-premises web interface. Β· π΄ Β· π΄
Open βCVE-2026-17583 β Thermo Fisher Applied Biosystems DNA File Tampering
No summary yet
Open βCVE-2026-18556
No summary yet
Open βCVE-2026-18577 β N-able N-central Authentication Bypass
No summary yet
Open βCVE-2026-18963
No summary yet
Open βCVE-2026-19478
No summary yet
Open βCVE-2026-19489 β Citrix NetScaler Memory Overflow
No summary yet
Open βCVE-2026-19490 β Citrix NetScaler Authentication Bypass
No summary yet
Open βCVE-2026-20349 β Cisco Secure Firewall ASA/FTD Heap Inspection (KEV)
No summary yet
Open βCVE-2026-21962
No summary yet
Open βCVE-2026-27577
No summary yet
Open βCVE-2026-27875 β Johnson Controls Simplex Incident Manager Credential Leak
No summary yet
Open βCVE-2026-29059 β Windmill
No summary yet
Open βCVE-2026-3055 β NetScaler Memory-Overread Vulnerability
No summary yet
Open βCVE-2026-32191 β Bing Images SVG RCE (Linux)
Bing Images SVG RCE on Linux (cve-2026-32191-bing-images-svg-linux, CVSS 9.8); root-level RCE via crafted SVGs; fixed server-side by Microsoft (Jul 2026) Β· π΄ Β·
Open βCVE-2026-32194 β Bing Images SVG RCE (Windows SYSTEM)
Bing Images SVG RCE on Windows (cve-2026-32194-bing-images-svg-windows, CVSS 9.8); SYSTEM-level RCE via crafted SVGs; fixed server-side by Microsoft (Jul 2026)
Open βCVE-2026-42533 β NGINX Heap Buffer Overflow
Critical NGINX heap buffer overflow (CVE-2026-42533); DoS/RCE via crafted HTTP in script engine (F5, Jul 2026) Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β·
Open βCVE-2026-45659 β Microsoft SharePoint RCE (Exploited in Ransomware)
No summary yet
Open βCVE-2026-45659 β Microsoft SharePoint Vulnerability
No summary yet
Open βCVE-2026-48273 β Adobe ColdFusion Eval Injection (CVSS 9.9)
No summary yet
Open βCVE-2026-48294 β HermeticReader Adobe Acrobat Chrome Extension UXSS
HermeticReader UXSS in Adobe Acrobat Chrome extension (CVE-2026-48294, CVSS 7.4); affects ~314M users (Jul 2026) Β· π Β· π Β· π Β· π Β· π Β· π Β· π Β· π Β· π Β· π Β· π Β· π
Open βCVE-2026-48362 β Adobe ColdFusion OS Command Injection (CVSS 10.0)
No summary yet
Open βCVE-2026-48448
No summary yet
Open βCVE-2026-48449
No summary yet
Open βCVE-2026-50522 β Critical SharePoint Server RCE
Critical SharePoint Server RCE (cve-2026-50522-sharepoint-server-rce, CVSS 9.8); active exploitation after public PoC (Jul 2026) Β· π΄ Β· π΄ Β· π΄ Β· π΄ Β· π΄ Β· π΄ Β· π΄ Β· π΄
Open βCVE-2026-53362
CVE-2026-53362 *(added 2026-08-28)*
Open βCVE-2026-54121 β Certighost AD CS Domain Controller Certificate Theft
Certighost AD CS vulnerability (cve-2026-54121-certighost-adcs, CVSS 8.8); low-priv AD users can impersonate Domain Controllers (Jul 2026) Β· π Β· π Β· π Β· π Β· π Β·
Open βCVE-2026-55040 β SharePoint JWT Token Authentication Bypass
No summary yet
Open βCVE-2026-55040 β Microsoft SharePoint Security-Feature Bypass
No summary yet
Open βCVE-2026-56164 β Microsoft SharePoint Vulnerability
No summary yet
Open βCVE-2026-58231 β SAP Commerce Cloud Pre-Auth RCE (CVSS 10.0)
Critical SAP Commerce Cloud pre-auth RCE (CVSS 10.0); exploitation attempts observed ~3 days after patch, per Onapsis/Defused (Aug 2026) Β· π΄ Β· π΄ Β· π΄ Β· π΄ Β· π΄ Β· π΄
Open βCVE-2026-58644 β Microsoft SharePoint Vulnerability
No summary yet
Open βCVE-2026-59124 β Microsoft HPC Pack RCE
No summary yet
Open βCVE-2026-59310 β VMware vCenter Directory Traversal (Exploited in the Wild)
No summary yet
Open βCVE-2026-60004
No summary yet
Open βCVE-2026-61511
No summary yet
Open βCVE-2026-62815 β Microsoft QUIC RCE
No summary yet
Open βCVE-2026-62878 β Windows DNS Server Stack Buffer Overflow RCE
No summary yet
Open βCVE-2026-62893 β Windows Deployment Services TFTP RCE
No summary yet
Open βCVE-2026-63077
No summary yet
Open βCVE-2026-63520 β SharePoint Business Connectivity Services Remote Code Execution
No summary yet
Open βCVE-2026-64564 β 18-Year-Old Linux SCTP Use-After-Free
18-year-old Linux SCTP use-after-free; container escape via SCTP networking code (Aug 2026) Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ
Open βCVE-2026-64638 β WordPress Pre-Auth XSS Leading to PHP Code Execution
WordPress Pre-Auth XSS (CVSS 8.9) affecting every version; chained to PHP code execution (Aug 2026) Β· π Β· π Β· π Β· π Β· π Β· π Β· π Β· π Β· π Β· π Β· π Β· π Β· π Β· π Β· π
Open βCVE-2026-65400 β macOS Screen Sharing RCE Under Active Exploitation
No summary yet
Open βCVE-2026-66384
CVE-2026-66384 *(added 2026-08-28)*
Open βCVE-2026-6875 β ServiceNow AI Platform Sandbox Escape
ServiceNow AI Platform sandbox escape (CVE-2026-6875, CVSS 9.5); active exploitation in the wild (Jul 2026) Β· π΄ Β· π΄ Β· π΄ Β· π΄ Β· π΄ Β· π΄ Β· π΄ Β· π΄ Β· π΄ Β· π΄ Β· π΄ Β· π΄ Β· π΄
Open βCVE-2026-68820 β Windows afd.sys WinSock Use-After-Free LPE (Zero-Day, KEV)
No summary yet
Open βCVE-2026-71398 β Adobe Campaign Classic Incorrect Authorisation (CVSS 10.0)
No summary yet
Open βCVE-2026-72529 β TrueConf Server Missing Authentication
No summary yet
Open βCVE-2026-72530 β TrueConf Server Code Injection
No summary yet
Open βCVE-2026-72898 β Metabase Unauthenticated SQL Injection (KEV)
No summary yet
Open βCVE-2026-73570 β Zimbra Collaboration Server Command Injection
No summary yet
Open βCVE-2026-8037 β Progress LoadMaster RCE (KEV)
No summary yet
Open βCVE-2026-8452 β Citrix NetScaler ADC / Gateway Memory Buffer Overflow
No summary yet
Open βCVE-2026-8933 β Ubuntu snap-confine Local Privilege Escalation
Ubuntu snap-confine local privilege escalation (CVE-2026-8933, Jul 2026) Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ
Open βFortiBleed
Leaked credentials from ~74,000 internet-exposed Fortinet devices; CISA urgent action Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ
Open βGhostLock (CVE-2026-43499)
15-year-old Linux kernel flaw (CVE-2026-43499); root + container escape; $92K Google bounty Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ
Open βOpenSSL HollowByte β DoS via 11-Byte TLS Request
OpenSSL HollowByte DoS; 11-byte TLS request freezes server memory; silently fixed June 2026 Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ
Open βRogue Agent (Dialogflow CX)
Google Dialogflow CX flaw allowing cross-agent compromise and data theft Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ
Open βRoguePlanet (CVE-2026-50656)
Microsoft Defender mpengine race condition (CVSS 7.8) granting SYSTEM shell Β· π Β· π Β· π Β· π Β· π Β· π Β· π Β· π Β· π Β· π Β· π Β· π Β· π Β· π Β· π Β· π
Open βCVE-2026-15409 β SonicWall SMA 1000 Series Zero-Day (CVSS 10.0)
SonicWall SMA 1000 zero-day chain (CVE-2026-15409 CVSS 10.0, CVE-2026-15410); exploited before disclosure by uta0533 (Jul 2026) Β· π΄ Β· π΄ Β· π΄ Β· π΄ Β· π΄ Β· π΄ Β· π΄ Β· π΄
Open βwp2shell (WordPress Core RCE)
WordPress core unauthenticated RCE (CVE-2026-63030 + CVE-2026-60137); PoC public; affects all 6.9/7.0 sites Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ Β· βͺ
Open β