Threat Landscape

Feb 26 — May 14 (weekly, 26-week baseline) · Last updated: 2026-05-21 16:00 UTC
Breaking P2Pinfect botnet exploits Kubernetes CVE-2021-25740 to bypass cloud security controls — 8 articles in the last 48h
Happening Now 10 actively exploited vulnerabilities · CVE-2026-20182, CVE-2026-26980, CVE-2026-20133 +7 more
Top Story
Rising Indirect Prompt Injection Threats Target Enterprise AI Agents
Over the past two weeks, cybersecurity reports have highlighted a growing threat to enterprise AI systems: indirect prompt injection attacks. These attacks involve embedding malicious instructions in external content (e.g., emails, documents, or web pages), which AI agents execute with user privileges, often leading to data exfiltration or unauthorized actions. Threat actors, including those leveraging AI-powered tradecraft, are increasingly operationalizing these techniques, with a 32% rise in malicious prompt injection attempts observed between late 2025 and early 2026. Affected systems include AI agents, large language models (LLMs), and Kubernetes-based AI workloads, which suffer from visibility gaps in traditional security tools. Organizations are urged to adopt frameworks like AI TRiSM and MITRE ATLAS, implement least-privilege controls, and extend existing security patterns (e.g., sandboxing, egress restriction) to mitigate risks.
"Prompt Injection" up 3.7x (6 → 22)"Threat Detection" up 3.6x (5 → 18)"Zero Trust" up 3.2x (4 → 13)
Articles (6 most recent) Agentic Governance: Securing Autonomous AI Systems Within the Trust Boundary Emerging Threats in AI: Addressing Prompt Injection and the Visibility Gap in Kubernetes-B Securing LLM Sandboxes: A Guide to Domain Allowlisting for Data Exfiltration Prevention Mitigating Indirect Prompt Injection Risks in Enterprise AI Agents: A Tactical Framework f AI TRiSM: Extending Security and Governance Controls to AI Systems in Production Adversarial AI: Defending Deployed Systems and Countering AI-Enabled Threat Actor Tradecra
Previous highlights (4)
Showing up to 4 most recent biweekly periods
77 articles
Critical Privilege Escalation Flaws and AI Security Gaps Emerge in Major Platforms
Over the past two weeks, multiple critical vulnerabilities have been disclosed across major operating systems and AI-driven platforms, exposing significant security risks. Researchers uncovered high-severity local privilege escalation (LPE) flaws in the Linux kernel (CVE-2026-31431, 'Copy Fail'), FreeBSD (CVE-2026-7270), and Windows RPC (PhantomRPC), enabling attackers to gain root or SYSTEM privileges. These vulnerabilities, some present for nearly a decade, highlight systemic risks in core system functions and architectural weaknesses. Concurrently, security gaps in Microsoft Copilot (CVE-2026-24299) and the broader impact of LLMs on reverse engineering defensive tools underscore the erosion of 'security through obscurity' and the urgent need for robust AI security frameworks. The disclosures emphasize the criticality of timely patching, least privilege principles, and defense-in-depth strategies to mitigate risks of container breakouts, multi-tenant host compromises, and persistent AI-driven attacks.
"Exploit Techniques" up 2.1x (18 → 37)"Prompt Injection" up 2.8x (8 → 22)"Zero-Day Vulnerabilities" up 2.1x (9 → 19)
Articles (6 most recent) Persistent Exploitation in Microsoft Copilot: Uncovering CVE-2026-24299 and the Copirate A Persistent Exploitation of CVE-2017-9841: A Decade-Old PHPUnit RCE Vulnerability Still Und April 2026 High-Impact Vulnerabilities: A Surge in Exploited CVEs and Emerging Threat Acto The Visibility Gap in AI Agent Security: Why MCP Servers Need Structured Audit Logging The Efficiency Trap: How Centralized SD-WAN Controllers Concentrate Risk and Attract Attac Quantifying Supply Chain Risks in MCP Servers: From Theory to Real-World Compromises
48 articles
AI and State Actors Accelerate Cyber Threats Amid Unpatched Systemic Flaws
Over the past two weeks, a surge in cybersecurity developments has highlighted the dual-edged role of AI in both offensive and defensive operations. Anthropic's Mythos AI demonstrated autonomous zero-day exploitation across major platforms, raising concerns about AI-driven phishing and reconnaissance, which now matches human expert effectiveness. Concurrently, Chinese state-sponsored threat actors, including the MSS and PLA, have industrialized their operations using shared malware frameworks like ShadowPad and compromised edge devices, complicating detection. Architectural vulnerabilities, such as the unpatched PhantomRPC flaw in Windows RPC, persist despite their potential for privilege escalation, reflecting challenges in addressing systemic risks. Meanwhile, AI-assisted discoveries, like the QEMU virtio-gpu heap overflow, underscore the growing sophistication of virtualization exploits. The evolving threat landscape is further strained by shrinking exploitation windows, with attackers leveraging weak credentials and unpatched systems to achieve long-term persistence, while Apple's iOS security model faces scrutiny for its reliance on rapid patching and lack of scalable detection mechanisms.
"Exploit Techniques" up 5.4x (5 → 27)"Cyber Threat Intelligence" up 13.5x (2 → 27)"Zero-Day Vulnerabilities" up 4.3x (3 → 13)
Articles (6 most recent) Critical Authentication Bypass in cPanel & WHM: Deep Dive into CVE-2026-41940 Exploitation CVE-2026-41940: Critical Authentication Bypass in cPanel & WHM Affecting 1.5 Million Serve Persistent Exploitation in Microsoft Copilot: Uncovering CVE-2026-24299 and the Copirate A Critical Authentication Bypass in cPanel & WHM (CVE-2026-41940): Exploitation Observed in Critical cPanel/WHM Pre-Auth Bypass (CVE-2026-41940) Exploited in Large-Scale Mirai and Ra Critical Authentication Bypass Vulnerability in cPanel and WHM Exploited in the Wild
9 articles
State-Aligned APTs Escalate Cyber Ops Amid Global Tensions, Targeting Gov & Critical Sectors
Over the past two weeks, state-aligned advanced persistent threat (APT) groups—primarily linked to Iran (MuddyWater, APT35, APT42, APT34/OilRig) and China (APT41/RedGolf, Emperor Dragonfly)—have intensified cyber operations targeting government agencies, defense contractors, financial institutions, and critical infrastructure across the U.S., Israel, South Korea, Japan, and Southeast Asia. Techniques include pre-positioned C2 infrastructure (e.g., blockchain-based communications, SSH key reuse, domain impersonation), exploitation of Fortinet vulnerabilities, Rust-based loaders delivering Cobalt Strike Cat, and multilingual phishing campaigns leveraging shared ZIP lure infrastructure. Rare exposures of attacker staging servers revealed operational toolkits, target lists (e.g., South Korea’s Ministry of Health, Shiseido), and open-source proxy tools (IOX, FRP, Rakshasa) used to evade detection. These activities, coinciding with geopolitical escalations, underscore a shift toward proactive infrastructure clustering and multi-stage attack workflows, heightening risks of espionage, data exfiltration, and potential kinetic cyber-physical impacts.
"Hunt.io" is new (appeared 11 times)"Open Directory" up 5.0x (1 → 5)"HuntSQL" is new (appeared 6 times)
Articles (6 most recent) Iranian APT Infrastructure Mapping: State-Aligned Clusters and C2 Patterns Amid Geopolitic Cobalt Strike Cat Campaign Targeting South Korean Government and Commercial Organizations KeyPlug-Linked Staging Server Exposes Fortinet Exploits, Webshells, and Reconnaissance Tar APT34-Like Pre-Operational Infrastructure Identified via SSH Key Reuse, Domain Impersonati Detecting Open-Source Proxy Infrastructure: IOX, FRP, and Rakshasa Hunting Techniques Multilingual Phishing Campaigns Targeting Asian Financial and Government Organizations via
29 articles
Critical Fortinet Flaws & AI Vulnerabilities Dominate Recent Cyber Threats
Over the past two weeks, critical vulnerabilities in Fortinet FortiClient EMS (CVE-2026-35616) have been actively exploited in the wild, enabling unauthenticated remote code execution via crafted API requests. Approximately 2,000 internet-exposed instances are at risk, prompting CISA to mandate federal remediation by April 9. Concurrently, AI-driven threats have surged, with Anthropic's Claude.ai facing 'Claudy Day' — a chained attack exploiting prompt injection and data exfiltration flaws — and the Granola AI app exposing indirect prompt injection risks. Additionally, Meta's React framework was found vulnerable to React2DoS (CVE-2026-23869), a denial-of-service flaw in its Server Components. These incidents highlight escalating risks from both traditional enterprise software and emerging AI systems, underscoring the need for rapid patching and robust governance frameworks.
"Vulnerability Research" up 2.0x (8 → 16)"Anthropic" up 3.2x (4 → 13)"Responsible Disclosure" up 3.3x (3 → 10)
Articles (6 most recent) Claudy Day: Chained Prompt Injection and Data Exfiltration Vulnerabilities Discovered in C Shadow Agents: Enterprise Security Risks of Uncontrolled 'Claw' AI Agent Framework Adoptio Claude Mythos and the AI-Driven Vulnpocalypse: What AppSec Teams Need to Know Node.js Module Resolution Flaw Enables Local Privilege Escalation on Windows: npm CLI and BlueHammer: Zero-Day Local Privilege Escalation Vulnerability in Microsoft Defender DNS Tunneling and Metadata Service Vulnerabilities in Amazon Bedrock AgentCore Sandbox Env
Detailed Analysis
Ad fraud
▲ ELEVATED
3 this week
▶ Stable (-5.0%/w) Shift: +25.0%
Details
Mean: 1.1/w Z-score: 1.63 Recent 3w avg: 1.7/w Prior 3w avg: 1.3/w Total: 18
Influence operations
▲ ELEVATED
2 this week
▲ Rising (36.4%/w) Shift: -42.9%
Details
Mean: 0.5/w Z-score: 1.57 Recent 3w avg: 1.3/w Prior 3w avg: 2.3/w Total: 14
Data exposure
⇋ SHIFTING
3 this week
▲ Rising (50.9%/w) Shift: +175.0%
Details
Mean: 0.8/w Z-score: 1.27 Recent 3w avg: 3.7/w Prior 3w avg: 1.3/w Total: 20
DDoS
⇋ SHIFTING
1 this week
▼ Falling (-15.5%/w) Shift: -66.7%
Details
Mean: 0.9/w Z-score: 0.08 Recent 3w avg: 0.3/w Prior 3w avg: 1.0/w Total: 13
Credential theft
● NORMAL
22 this week
▶ Stable (-0.8%/w) Shift: +47.1%
Details
Mean: 15.9/w Z-score: 0.56 Recent 3w avg: 25.0/w Prior 3w avg: 17.0/w Total: 277
Prepositioning
● NORMAL
23 this week
▲ Rising (33.5%/w)
Details
Mean: 7.8/w Z-score: 1.28 Recent 3w avg: 24.3/w Prior 3w avg: 24.3/w Total: 202
Wiper / Sabotage
● NORMAL
1 this week
▼ Falling (-23.2%/w) Shift: -28.6%
Details
Mean: 2.0/w Z-score: -0.47 Recent 3w avg: 1.7/w Prior 3w avg: 2.3/w Total: 40
BEC / Wire fraud
● NORMAL
3 this week
▲ Rising (12.7%/w)
Details
Mean: 1.9/w Z-score: 0.64 Recent 3w avg: 4.0/w Prior 3w avg: 4.0/w Total: 36

Low Volume

< 10 articles — limited statistical significance
Sextortion
▲ ELEVATED
4 total (12w)
Cryptojacking
⇋ SHIFTING
9 total (12w)
Payment card theft
⇋ SHIFTING
9 total (12w)
Defacement
● NORMAL
2 total (12w)
Archetype Status This Week Mean Z-Score Total (12w) Trend Shift
Ransomware significant 12 4.2 2.44 68 +12.6%/w +56.3%
Initial access brokering elevated 28 9.5 1.83 202 +25.3%/w +49.1%
Espionage elevated 17 5.1 1.55 132 +34.7%/w +57.1%
Crypto theft elevated 5 1.3 1.62 34 +31.6%/w -40.0%
Account takeover (ATO) elevated 5 1.2 1.94 31 +44.9%/w +8.3%
Ad fraud elevated 3 1.1 1.63 18 -5.0%/w +25.0%
Influence operations elevated 2 0.5 1.57 14 +36.4%/w -42.9%
Sextortion elevated 1 0.2 1.68 4 +40.0%/w +100.0%
Data exposure shifting 3 0.8 1.27 20 +50.9%/w +175.0%
DDoS shifting 1 0.9 0.08 13 -15.5%/w -66.7%
Cryptojacking shifting 0 0.8 -0.89 9 -15.3%/w -100.0%
Payment card theft shifting 1 0.3 0.84 9 +21.2%/w +50.0%
Credential theft normal 22 15.9 0.56 277 -0.8%/w +47.1%
Prepositioning normal 23 7.8 1.28 202 +33.5%/w
Wiper / Sabotage normal 1 2.0 -0.47 40 -23.2%/w -28.6%
BEC / Wire fraud normal 3 1.9 0.64 36 +12.7%/w
Defacement normal 0 0.2 -0.4 2 -21.8%/w
Actor Articles Associated Archetypes
TeamPCP
crime-syndicate
aka Team PCP, Mini Shai-Hulud, Mini Shai-Hulud campaign, Mini Shai-Hulud threat actor, TeamPCP (behind the Trivy breach and subsequent operations), TeamPCP (cyber criminal operation), TeamPCP (implied attribution)
Compromised an employee’s developer device using a malicious Visual Studio Code extension to steal and clone GitHub’s internal repositories (approximately 3,800) for monetization, listing the stolen data for sale on a cybercrime forum. Known for backdooring open-source security and development tools, credential harvesting, and abusing valid accounts for lateral access.
74 Credential theft (29) Initial access brokering (23) Prepositioning (7)
Lazarus Group
nation-state
aka UNC1069, Kimsuky, Lazarus, Contagious Interview, Sapphire Sleet, BlueNoroff, PolinRider, STARDUST CHOLLIMA
A threat actor involved in a cryptocurrency theft campaign uncovered by Google, using social engineering tactics to direct victims to fraudulent video calls and execute malicious scripts.
37 Espionage (13) Crypto theft (10) Prepositioning (8)
Qilin
crime-syndicate
aka Qilin ransomware operators
Ransomware operators maintaining the ransomware, recruiting affiliates, and providing business infrastructure such as leak sites, payment portals, and legal support. Affiliates handle initial access and deployment in victim environments.
17 Ransomware (13) Credential theft (1) DDoS (1)
LockBit
crime-syndicate
aka LockBit affiliates, LockBit 5.0
Ransomware operators providing ransomware-as-a-service (RaaS), with affiliates deploying the ransomware in varied intrusion chains and victim environments.
14 Ransomware (11) Credential theft (2) DDoS (1)
fraudsters
criminal
aka criminals, Organized scam call centers, scammers, bad actors, online fraudsters, organized crime groups
Individuals or small groups engaging in opportunistic fraud such as bonus abuse, chargeback disputes, and multi-accounting. Uses automation, shared data, and behavioral simulation to evade detection and blend into legitimate user activity.
13 BEC / Wire fraud (5) Credential theft (3) Ransomware (2)
ShinyHunters
crime-syndicate
aka Bling Libra
Mentioned as a distinct cluster utilizing similar SaaS data-theft techniques. UNC6671 co-opted the ShinyHunters brand in at least one instance to inject artificial credibility into their threats, though operations are assessed to be independent.
13 Ransomware (7) Data exposure (2) Espionage (1)
Fancy Bear
nation-state
aka APT28, Forest Blizzard, APT 28, FancyBear, GRU Military Unit 26165
Russia-nexus intrusion set attributed to Russia’s General Staff Main Intelligence Directorate (GRU). Known for hybrid operations, modular and disposable implants (e.g., MASEPIE, STEELHOOK, OCEANMAP), stealthy delivery and persistence mechanisms, and use of frameworks like Covenant for reconnaissance and espionage. Targets include military networks, diplomatic crises, and utilizes advanced techniques such as steganography, COM hijacking, and custom C2 protocols leveraging cloud services like Koofr or Filen.
12 Espionage (7) Credential theft (3) Ransomware (1)
advanced persistent threat (APT) actor
crime-syndicate
aka Threat Actor A, Threat Actor B, a threat actor, Operation GriefLure Threat Actor, PRC-nexus threat actor (associated with UNC6201), Suspected China-linked Threat Actor, Threat actor behind DigiCert support portal hack, threat actor exploiting CVE-2024-55224 and CVE-2024-55225
Conducted a large-scale poisoning campaign targeting Ghost CMS by exploiting CVE-2026-26980 to inject malicious JavaScript loaders into articles. The campaign involved automated bulk vulnerability scanning, Admin API key extraction, and dynamic C2 distribution to deliver malware such as stealer trojans via ClickFix social engineering attacks. The group used cloaking domains and updated payloads to evade detection and maintain persistence.
12 Initial access brokering (4) Prepositioning (4) Credential theft (3)
Akira
crime-syndicate
aka Akira ransomware group, Conti ransomware group
Ransomware operators providing ransomware-as-a-service (RaaS), maintaining the ransomware variant, infrastructure, and managing ransom negotiations. Affiliates deploy the ransomware in victim environments.
11 Ransomware (11)
Handala
nation-state
aka Handala Hack Team, Homeland Justice, Banished Kitten, Handala Hack, Handala Hacking Team, Ministry of Intelligence and Security (MOIS), MOIS Linked Cyber Influence Ecosystem, The Handala Popular Resistance Front (HPR)
Participates in hacktivist campaigns targeting financial services, possibly aligned with political or ideological motives.
11 Espionage (3) Influence operations (3) Wiper / Sabotage (2)
MuddyWater
nation-state
aka Seedworm, APT34, Dark Scepter, Helix Kitten, Iranian-aligned group connected to the Ministry of Intelligence and Security (MOIS), OilRig, TA402, MuddyWater APT
Conducted a global espionage campaign targeting organizations across multiple sectors (industrial and electronics manufacturing, education, public-sector, financial services, and professional services) to steal sensitive information, including intellectual property, research data, and intelligence on rival governments. The group used advanced tradecraft such as DLL sideloading with signed binaries, Node.js-based orchestration, PowerShell scripting, credential theft, and data exfiltration via public file-transfer services. The campaign is linked to the Iranian Ministry of Intelligence and Security (MOIS).
10 Espionage (6) Prepositioning (2) Wiper / Sabotage (2)
Shai-Hulud
crime-syndicate
aka Shai-Hulud attacker, Shai-Hulud threat actor, Shai-Hulud worm campaign, Shai-Hulud 2.0, Shai-Hulud malware, Shai-Hulud worm
Conducted a large-scale supply chain attack on the npm ecosystem by compromising the 'atool' npm account, which owns popular packages like timeago.js. The attack involved publishing malicious versions of over 300 packages across Alibaba's AntV data visualization ecosystem, exfiltrating credentials, and establishing persistence via backdoors in developer tools like VS Code and Claude Code. The attacker used advanced techniques such as memory scraping to extract unmasked secrets from CI runners, GitHub API dead-drops for exfiltration, and OpenTelemetry impersonation for command and control (C2). The attack was well-orchestrated, with deliberate signaling via GitHub repository descriptions using Dune-universe terminology.
10 Initial access brokering (4) Credential theft (4) Account takeover (ATO) (1)
LAPSUS$
crime-syndicate
aka Scattered Lapsus$ Hunters, LAPSUS$ (new group), Scattered Lapsus$
Published multiple screenshots indicating they gained access into Okta's corporate systems, specifically into Okta's customer support environment through internal admin access. The compromise involved a support engineer's endpoint being compromised for five days, allowing potential access to Jira tickets and user lists associated with customer accounts, as well as the ability to reset passwords and MFA factors for customer accounts.
9 Data exposure (4) Account takeover (ATO) (3) Credential theft (2)
The Gentlemen
crime-syndicate
aka Hastala, zeta88, hastalamuerte, The Gentlemen RaaS, The Gentlemen RaaS administrator, The Gentlemen Ransomware-as-a-Service
An emerging ransomware group that surpassed the activity levels of established groups like Akira and INC Ransom, accounting for 9.25% of victims published on data leak sites in Q1 2026.
8 Ransomware (8)
Scattered Spider
crime-syndicate
aka Octo Tempest
Affiliate group associated with Qilin RaaS, involved in initial access, hands-on-keyboard activity, data theft, and deploying ransomware in victim environments.
7 Espionage (3) Ransomware (2) Credential theft (2)
BlackCat
crime-syndicate
aka ALPHV/BlackCat, BlackCat/Alphv, ALPHV, ALPHV BlackCat
A ransomware-as-a-service (RaaS) operation linked to a negotiator who colluded with the group to share privileged insights into ransomware negotiations and allegedly participated as an affiliate.
7 Ransomware (5) Credential theft (2)
VECT
crime-syndicate
aka Vect ransomware group, Vect (ransomware group), VECT Ransomware
Announced a partnership with TeamPCP, suggesting involvement in large-scale extortion and ransomware operations as part of the Shai-Hulud supply chain campaign.
7 Data exposure (2) Prepositioning (1) Credential theft (1)
EvilTokens
crime-syndicate
aka EvilTokens affiliates, EvilToken, eviltokensadmin, EvilTokens (related infrastructure), EvilTokens administrator, EvilTokens PhaaS
Operates a phishing-as-a-service (PhaaS) platform designed to capture authentication tokens via device code phishing. The platform offers various landing pages and themes, automates attack chains, and provides tools like the 'Portal Browser' for managing compromised Microsoft 365 accounts to scale business email compromise (BEC) operations.
7 Account takeover (ATO) (5) BEC / Wire fraud (2) Initial access brokering (1)
Islamic Revolutionary Guard Corps (IRGC)
nation-state
aka Iran's Islamic Revolutionary Guard Corps Cyber Electronic Command, Islamic Revolutionary Guard Corps
Uses Iranian Cultural Centers for intelligence gathering, recruitment, radicalization, and logistical support. Engages in espionage, terrorist plots, propaganda dissemination, and collaboration with criminal networks (e.g., drug cartels, guerrilla groups) for funding and operational support. Implicated in assassination plots, money laundering, and cyber disinformation campaigns across Latin America.
7 Prepositioning (4) Espionage (2) Crypto theft (1)
malicious actors
criminal
aka malicious actor
Use tokenization-specific attacks such as invisible Unicode payloads to evade code review or content moderation systems, manipulate tokenization to bypass prompt injection detectors, and disrupt model behavior for data leakage or instruction hijacking.
7 Prepositioning (3) Espionage (3) Initial access brokering (2)

State-Sponsored Activity

Attributed nation-state operations (12w)
Iran 31 articles
Active Actors
Handala (20) MuddyWater (16) APT34 (9) OilRig (9) Charming Kitten (6) Mint Sandstorm (6) APT42 (6) APT33 (5)
Operations
Wiper / Sabotage (52) DDoS (12) Espionage (11) Credential theft (4) Prepositioning (3)
Targeted Sectors
Telecommunications (7) Computer Systems Design and Related Services (6) Electric Power Generation, Transmission and Distribution (6) Manufacturing (5) Oil and Gas Extraction (5) Medical Device Manufacturing (4)
Recent articles Seedworm: Iran-Linked APT Group Expands Global Espionage Campaign Using DLL Side Iranian-Nexus Cyber Espionage Campaign Targets Oman: 11 Ministries Compromised a Top Cyber Threat Groups Targeting Organizations: Profiling OilRig, Cozy Bear, La DinDoor Deno-Based Backdoor: Execution Chain Analysis and Active C2 Infrastructu MOIS-Aligned Cyber Influence Ecosystem: Unified Analysis of Homeland Justice, Ka
North Korea 29 articles
Active Actors
Lazarus Group (19) Contagious Interview (7) Famous Chollima (4) Kimsuky (2) APT38 (2) APT37 (2) Lazarus (1)
Operations
Espionage (14) Crypto theft (10) Credential theft (7) Initial access brokering (2) Prepositioning (2)
Targeted Sectors
Information Technology (4) Software Publishers (3) Computer Systems Design and Related Services (3) Data Processing, Hosting, and Related Services (2) Energy (1) Aerospace Product and Parts Manufacturing (1)
Recent articles Analysis of Kimsuky's Multi-Themed Spear Phishing Campaigns: Exploiting Legitima North Korea's Cybercrime Operations: Funding Military Ambitions and Evading Sanc Inside DPRK’s npm Malware Factory: A 31-Day Campaign of 108 Packages and 261 Ver noon-contracts: Sophisticated DeFi-Targeted npm Supply Chain RAT with Triple Per Top Cyber Threat Groups Targeting Organizations: Profiling OilRig, Cozy Bear, La
Russia 19 articles
Active Actors
APT28 (10) Fancy Bear (8) Forest Blizzard (5) APT29 (4) Sandworm (2) Midnight Blizzard (1) Cozy Bear (1) Secret Blizzard (1)
Operations
Espionage (20) Credential theft (7) Ransomware (3) Account takeover (ATO) (2) Wiper / Sabotage (1)
Targeted Sectors
National Security / Military (1) Executive, Legislative, and Other General Government Support (1) Justice, Public Order, and Safety Activities (1) Air Transportation / Air Force (1) Computer Security / Cybersecurity Services (1)
Recent articles Midnight Blizzard Attack on Microsoft: A Deep Dive into Nation-State Espionage a Evolution of Kazuar: From Monolithic Backdoor to Modular P2P Botnet Ecosystem Sandworm Unmasked: Operational Patterns, Escalation Tactics, and Defensive Strat Automating .NET Malware Analysis: Tooling and Techniques for Scalable Reverse En Spring Cleaning Your Browser: Reducing Attack Surfaces Through Digital Hygiene
China 16 articles
Active Actors
Volt Typhoon (5) Mustang Panda (5) Salt Typhoon (4) APT41 (3) APT31 (3) APT40 (1) APT27 (1) Silk Typhoon (1)
Operations
Espionage (13) Prepositioning (3) Wiper / Sabotage (3) Initial access brokering (2) Credential theft (2)
Targeted Sectors
Electric Power Generation, Transmission and Distribution (2) Water, Sewage and Other Systems (2) Finance and Insurance (2) Government (2) Industrial Machinery Manufacturing (1) Other Heavy and Civil Engineering Construction (1)
Recent articles SHADOW-EARTH-053: China-Aligned Cyberespionage Campaign Exploits Legacy Microsof State-Sponsored Cyber Threats: Redefining Incident Response for Advanced Persist AI-Powered Vulnerability Discovery and Exploit Development: The Rise of Mythos P Network Telemetry Unveils Nation-State Pre-Positioning in the Defense Industrial LOTUSLITE v1.1: Mustang Panda Evolves Backdoor Targeting India's Banking Sector
Tracking 698 unique CVEs over the window. Found: new 7persistent 9active 8
CVE-2026-26980
9.4 NEW
Ghost is a Node.js content management system. Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform arbitrary reads from the database. This issue has been fixed in version 6.19.1.
Ghost
2 this week 2 total 1w active
Articles Large-Scale Compromise of Ghost CMS via CVE-2026-26980 Fuels ClickFix Malware Ca Mass Exploitation of Ghost CMS via CVE-2026-26980: A ClickFix Malware Campaign A
CVE-2026-9082
6.5 NEW
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.1
DrupalDrupal CorePostgreSQL
2 this week 2 total 1w active
Articles Highly Critical SQL Injection Vulnerability in Drupal Core (CVE-2026-9082): Anal Highly Critical SQL Injection Vulnerability in Drupal Core Affecting PostgreSQL
CVE-2026-3102
2.1 NEW
A vulnerability was determined in exiftool up to 13.49 on macOS. This issue affects the function SetMacOSTags of the file lib/Image/ExifTool/MacOS.pm of the component PNG File Parser. This manipulatio
Exiftool Project Exiftool
1 this week 1 total 1w active
Articles Analysis of CVE-2026-3102: Command Injection Vulnerability in ExifTool on macOS
CVE-2026-44578
8.6 NEW
Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server
Vercel Next.Js
1 this week 1 total 1w active
Articles Critical SSRF Vulnerability in Self-Hosted Next.js Applications (CVE-2026-44578)
CVE-2026-45829
10.0 NEW
A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a maliciou
ChromaDBPython FastAPI serverRust-based deployment path
1 this week 1 total 1w active
Articles Pre-Authentication Remote Code Execution Vulnerability in ChromaDB's Python Fast
mcp-server-kubernetesClaude
1 this week 1 total 1w active
Articles High-Severity Access Control Bypass in mcp-server-kubernetes Enables Full Cluste
KubeflowKubeflow ManifestsIstio
1 this week 1 total 1w active
Articles Critical Authorization Token Theft Vulnerability in Kubeflow Enables Account Tak
CVE-2025-55182
10.0 PERSISTENT
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-
Facebook ReactVercel Next.Js
1 this week 13 total 7w active
Articles P2Pinfect Botnet: Expansion of Exploitation Vectors and Persistent Threats in Cl PCPJack: A Credential Theft Framework Targeting Exposed Cloud Infrastructure and Comprehensive Cyber Threat Landscape: Global Cyber Operations, Espionage, and Em ShadowLink: Connecting Residential Proxy Networks on Compromised IoT Devices to Kubernetes Under Siege: How Threat Actors Exploit Container Identities to Compro
CVE-2026-20127
10.0 PERSISTENT
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, r
Cisco Catalyst Sd-Wan ManagerCisco Sd-Wan Vsmart Controller
1 this week 9 total 6w active
Articles Critical Authentication Bypass Vulnerability in Cisco Catalyst SD-WAN Controller Active Exploitation of Critical Cisco Catalyst SD-WAN Vulnerabilities: A Deep Di Active Exploitation of Cisco Catalyst SD-WAN Vulnerabilities: CVE-2026-20182 and The Efficiency Trap: How Centralized SD-WAN Controllers Concentrate Risk and Att Critical Unauthenticated Buffer Overflow Vulnerability in PAN-OS (CVE-2026-0300)
CVE-2026-1731
9.9 PERSISTENT
BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted req
Beyondtrust Privileged Remote AccessBeyondtrust Remote Support
0 this week 6 total 4w active
CVE-2026-33017
9.3 PERSISTENT
Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows withou
Langflow
0 this week 6 total 4w active
CVE-2026-1281
9.8 PERSISTENT
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
Ivanti Endpoint Manager Mobile
0 this week 4 total 4w active
CVE-2026-43284
8.8 ACTIVE
In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks
Linux Linux Kernel
2 this week 8 total 3w active
CVE-2026-43500
7.8 ACTIVE
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present The DATA-packet handler in rxrpc_input_call_event() and the
Linux Linux Kernel
2 this week 8 total 3w active
CVE-2026-20182
10.0 ACTIVE
May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vu
Cisco Catalyst Sd-Wan ManagerCisco Sd-Wan Vsmart Controller
2 this week 5 total 2w active
1 this week 3 total 2w active
CVE-2025-49844
9.9 ACTIVE
Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to manipulate the garbage collector, trigg
RedisLfprojects Valkey
1 this week 2 total 2w active
CVE-2026-41613
8.8 ACTIVE
Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
Microsoft Visual Studio Code
1 this week 2 total 2w active