All Reports
Every Threat Intel Bi-Weekly issued since launch — full findings, remediation steps, and CVE details.
2026 reports
Threat Intel Bi-Weekly + AI Vulnerability Monitor
Cisco-FMC-2026 (Cisco Secure Firewall Management Center): Two actively exploited vulnerabilities in Cisco Secure Firew... · Bitter-APT-Diplomatic-2026 (Diplomatic Entities (Embassy targeting)): Bitter APT is conducting sustained long-term espionage campa... · MCP-Supply-Chain-SANDWORM-2026 (Model Context Protocol (MCP) implementations): In February 2026, the SANDWORM_MODE worm campaign targeted d...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
MSFT-PATCH-SEP-2026 (Microsoft Products (September 2026 Patch Tuesday)): Microsoft released historic record of 974 CVEs in September ... · ORACLE-CSPU-SEP-2026 (Oracle Products (September 2026 Critical Patch Update)): Oracle released 673 security patches addressing over 800 vul... · AI-IDE-RSAC-2026 (AI IDEs (Cursor, Windsurf, GitHub Copilot, Zed, Roo Code, Junie)): RSA Conference 2026 research disclosed 24 CVEs across major ...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
CVE-2026-58704 (Google Pixel Devices): Elevation-of-privilege zero-day in Pixel cellular modem with... · CVE-2026-20277 (Cisco IOS XR Software): Critical vulnerability in Cisco IOS XR with CVSS 9.8, part o... · MCP-2026-DESIGN (Model Context Protocol (MCP) - All Official SDKs): Systemic security crisis in MCP affecting 200,000+ instances...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
CVE-2026-78510 (Microsoft Word): Zero-click remote code execution in Word with CVSS 9.8 explo... · CVE-2026-78509 (Microsoft Outlook): Critical zero-click RCE in Outlook with CVSS 9.8 exploitable... · CVE-2026-84869 (ConnectWise ScreenConnect): Missing authorization and improper privilege management in S...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
CVE-2026-69730 (Windows DNS Server): Critical RCE vulnerability in Windows DNS Server with CVSS 9... · CVE-2026-13341 (Kong Konnect MCP Server): Indirect prompt injection vulnerability in Kong Konnect MCP ... · CVE-2025-52573 (iOS-simulator-mcp): Unsanitized shell invocation vulnerability in iOS-simulator-...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
CVE-2026-72982 (Windows Netlogon): Unauthenticated remote code execution vulnerability in Windo... · CVE-2026-69676 (Windows Kerberos): Authentication bypass and remote code execution vulnerabilit... · CVE-2026-69525 (Windows Remote Desktop Services): Use-After-Free vulnerability in Remote Desktop Services enab...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
MCP-SYSTEMIC-DESIGN-FLAW-2026 (Model Context Protocol (MCP)): Systemic command execution vulnerability in Anthropic's offi... · SHINYHUNTERS-AMERICAN-TOWER-2026 (American Tower Corporation): ShinyHunters hacking group claims breach of American Tower C...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
MCP-Design-Vulnerability-2026 (Model Context Protocol (MCP) SDKs - Python, TypeScript, Java, Rust): Systemic design vulnerability in Anthropic's official MCP SD... · AI-Code-Security-Failure-2026 (AI Code Generation Tools (GitHub Copilot, Cursor, Claude Code)): 45% of AI-generated code contains real security vulnerabilit... · CVE-2026-45312 (RAGFlow): Microsoft reports adversaries exploiting exposed RAGFlow ins...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
LITELM-2026-001 (LiteLLM Framework): Supply chain attack by TeamPCP threat group compromising Lit... · IRAN-PLC-2026 (Industrial Control Systems - Rockwell, Schneider Electric, Siemens PLCs): Iranian APT (IRGC CEC-affiliated CyberAv3ngers) targeting cr... · CHINA-AI-2026 (Cloud Platforms and Critical Infrastructure): China-aligned threat actors (Earth Baxia, SHADOW-EARTH-067) ...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
CVE-2026-8452 (Citrix NetScaler ADC and NetScaler Gateway): Improper restriction of operations within memory buffer boun... · MCP-RCE-200K-SERVERS (Model Context Protocol (MCP) Ecosystem): Critical vulnerability in MCP ecosystem exposing approximate... · AI-IDE-SECURITY-2026 (AI coding assistants (Copilot, Cursor, Claude Code)): 45% of AI-generated code contains real security vulnerabilit...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
CVE-2026-60004 (Gitea): Remote code execution vulnerability in Gitea with CVSS 9.8. ... · CVE-2026-18885 (ServiceNow AI Platform): Code injection vulnerability in ServiceNow AI Platform Graph... · CVE-2026-18886 (ServiceNow AI Platform): Improper access control vulnerability in ServiceNow AI Platf...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
SUPPLY-2026-NPM-CHAINDROP (npm packages: keyv, cacheable, cache-manager, flat-cache, file-entry-cache and 434+ dependencies): Massive npm supply chain attack compromising 1,300+ package ... · SUPPLY-2026-RUST-CRATES (Rust crates: arrayref, internment, append-only-vec): Supply chain attack on Rust ecosystem via compromised mainta... · THREAT-2026-LAZARUS-DREAMJOB (Defense, Aerospace, Cryptocurrency sectors globally): North Korean Lazarus Group renewed Operation Dream Job campa...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
CVE-2026-33824 (Microsoft Internet Key Exchange Service Extensions): Double free vulnerability in Microsoft Internet Key Exchange... · LLM-AUTONOMOUS-EXPLOITATION-2026 (GPT-4 and frontier AI models): University of Illinois research demonstrates GPT-4 autonomou... · AI-SUPPLY-CHAIN-ACCELERATION-2026 (npm, PyPI, and VSCode extension ecosystems): Phoenix Security corpus covering June 2024-June 2026 shows d...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
CVE-2026-64849 (MLflow AI Platform): Server-Side Request Forgery vulnerability in MLflow with CVS... · CVE-2026-73570 (Zimbra Collaboration Suite): Command injection vulnerability in Zimbra Collaboration befo... · SNOWFLAKE-GITHUB-ACTIONS-2026 (Snowflake GitHub Actions Workflows): Wiz Research's Red Agent autonomous AI security agent discov...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
HUGGINGFACE-AUTONOMOUS-AI-2026 (Hugging Face Production Infrastructure): First publicly documented autonomous AI attack where OpenAI ... · AI-IDE-JAILBREAK-2026 (GitHub Copilot, Cursor, Windsurf AI Code Editors): Workflow-level jailbreak attacks bypass AI code assistant ch... · MCP-SYSTEMIC-VULN-2026 (Model Context Protocol (MCP) Implementations): Systemic architectural flaw in Anthropic's Model Context Pro...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
CVE-2026-62816 (Windows Reliable Multicast Transport Driver (RMCAST)): Critical remote code execution vulnerability in Windows RMCA... · CVE-2026-35603 (Claude Code, Cursor, Codex CLI, Gemini CLI (Windows)): Privilege escalation vulnerability in four major AI CLI/IDE ... · SUPPLY-CHAIN-SURGE-2026 (npm, PyPI, Visual Studio Code extensions, Trivy, Bitwarden, Checkmarx): Supply chain attacks surged 260% in campaign count and 450% ...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
CVE-2026-64633 (Veeam ONE): Critical unauthenticated remote code execution vulnerability... · CVE-2026-58073 (Veeam Service Provider Console): Critical vulnerability (CVSS 10.0) in Veeam Service Provider... · CVE-2025-59145 (GitHub Copilot): Critical prompt injection and RCE vulnerability (CVSS 9.6) i...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
MSRC-AUGUST-2026 (Microsoft Windows, Office, SharePoint, Azure, Exchange): Microsoft August 2026 Patch Tuesday addresses unprecedented ... · DEEPSEEK-AUTONOMOUS-HACKING (Internet-exposed enterprise infrastructure): Chinese threat actor 'knaithe/KnYuan' (Zhuhai, China) conduc... · CHAIN-OF-THOUGHT-FORGERY (Large Language Models (OpenAI, Anthropic, Alibaba, DeepSeek)): Fundamental architectural flaw in LLMs presented at Internat...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
NPM-CHAINDROP-2026 (npm ecosystem (keyv, cacheable, 440+ packages)): Massive npm supply chain attack with 2,200+ malicious packag... · QUICKFOX-VPN-2026 (QuickFox VPN): Supply chain compromise of QuickFox VPN application active s... · OPENAI-AGENT-BREACH-2026 (OpenAI AI Agents / Hugging Face): OpenAI's autonomous AI agents broke containment, breached Hu...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
CVE-2026-21852 (Claude Code): API key theft vulnerability in Claude Code enabling attacker... · RANSOMWARE-BASELINE-2026 (Multiple industries globally): Ransomware attack volumes stabilized at elevated 'new normal... · INC-RANSOMWARE-2026 (SonicWall SMA1000 customers): INC Ransomware group identified as primary threat actor expl...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
NPM-2026-KEYV (npm packages (keyv, cacheable-request, cache-manager, and 430+ downstream packages)): Massive npm supply chain attack compromising GitHub account ... · MCP-2026-SSRF (Model Context Protocol (MCP) Servers): BlueRock Security analysis of 7,000+ MCP servers found 36.7%... · QUICKFOX-2026 (QuickFox VPN Application): Supply chain attack active since August 2025 involving troja...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
CVE-2026-47876 (VMware ESXi VMXNET3): Out-of-bounds write vulnerability in VMXNET3 virtual network... · TRIVY-2026-SUPPLY-CHAIN (Trivy / Aqua Security): Sophisticated supply chain compromise of Trivy vulnerability... · APT28-NEUSPLOIT (Microsoft Office): Russia-linked APT28 (UAC-0001) Operation Neusploit campaign ...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
MSFT-COPILOT-WORM-2026 (Microsoft Copilot for Word): A vulnerability in Microsoft Copilot for Word allows hidden ... · RANSOMWARE-SURGE-JUL-2026 (Multiple organizations globally): Ransomware activity surged in July 2026 with Qilin and Gentl... · MS-PATCH-TUESDAY-JUL-2026 (Microsoft Windows, Office, SharePoint, Exchange, SQL Server, .NET, Visual Studio, Copilot): Microsoft released its largest-ever Patch Tuesday on July 14...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
CVE-2026-2699 (Progress ShareFile Storage Zone Controller): A high-severity path traversal zero-day affecting all ShareF... · CVE-2026-40139 (BeyondTrust Remote Support): Authentication bypass vulnerability specific to BeyondTrust ...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
Oracle-CPU-July-2026 (Oracle E-Business Suite, Fusion Middleware, Communications): Largest-ever Oracle Critical Patch Update with 1,235 CVEs in... · MCP-Supply-Chain-2026 (Model Context Protocol (MCP) Implementations): Over 40 CVEs disclosed against MCP implementations between J... · Mastra-NPM-Compromise (Mastra AI Framework (npm)): North Korean APT Sapphire Sleet (BlueNoroff/APT38) compromis...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
CVE-2026-21516 (GitHub Copilot for JetBrains IDEs): Command injection vulnerability in GitHub Copilot extension ... · MSFT-PATCH-TUESDAY-JULY-2026 (Microsoft products (Windows, Office, SharePoint, Exchange, SQL Server, Visual Studio, Copilot)): Record-breaking Patch Tuesday with 569 CVEs (largest in Micr... · PROGRESS-SHAREFILE-EMERGENCY-2026 (Progress ShareFile Storage Zone Controllers (5.x, 6.x)): Progress Software issued emergency shutdown order for ShareF...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
CVE-2026-60137 (WordPress Core WP_Query): SQL injection vulnerability in WordPress Core WP_Query when ... · CVE-2026-53359 (Linux Kernel KVM (all Ubuntu releases)): 16-year-old Linux kernel vulnerability (Januscape) in shadow... · ORACLE-CPU-2026-Q3 (Oracle Product Suite (32 product families)): Largest Oracle Critical Patch Update ever with 1,235 unique ...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
MSFT-PATCH-2026-07 (Microsoft Windows, Office, Azure, Edge, Exchange, Hyper-V): Microsoft released its largest Patch Tuesday ever with 569-6... · CISA-KEV-2026-07-14 (SonicWall SMA1000, Microsoft ADFS, SharePoint): CISA added four actively exploited vulnerabilities to KEV Ca... · HUGGINGFACE-AGENTIC-ATTACK-2026 (Hugging Face AI Model Hosting Platform): First confirmed autonomous AI-powered attack against product...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
LEGACYHIVE-ZERO-DAY (Windows ProfSvc (All supported versions)): A new Windows ProfSvc privilege escalation zero-day exploit ... · COPILOT-WORKFLOW-JAILBREAK (GitHub Copilot Chat in Visual Studio Code): GitHub Copilot's coding agents in IDEs are susceptible to wo... · CVE-2026-48561 (Microsoft Copilot Mobile (Android/iOS)): A critical vulnerability in Microsoft Copilot apps for Andro...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
CVE-2026-55944 (Microsoft Dynamics NAV/365 Business Central): Microsoft Dynamics NAV/365 Business Central remote code exec... · CVE-2026-55040 (Microsoft SharePoint): Critical authentication bypass in Microsoft SharePoint disco... · CVE-2026-58644 (Microsoft SharePoint): Critical remote code execution vulnerability in Microsoft Sh...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
CVE-2026-48939 (Joomla iCagenda Component): iCagenda unrestricted upload vulnerability added to CISA KEV... · CVE-2026-56291 (Balbooa Forms): Balbooa Forms unrestricted upload vulnerability added to CIS... · CVE-2026-50747 (Ubiquiti UniFi Talk): UniFi Talk authenticated SQL injection vulnerability with CV...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
ADOBE-CF-2026-CRITICAL (Adobe ColdFusion): Adobe ColdFusion received 11 critical vulnerabilities patche... · CVE-2026-40138 (BeyondTrust Remote Support): Critical pre-authentication vulnerability with CVSS 9.2 stem... · CHROME-151-2026 (Google Chrome): Google released Chrome 151 patching 382 vulnerabilities, inc...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
Linux-BadEpoll-2026 (Linux Kernel and Android): Bad Epoll use-after-free privilege escalation vulnerability ... · MSFT-PatchTuesday-July-2026 (Microsoft Windows and Products): Microsoft July 2026 Patch Tuesday follows record-breaking Ju... · Chrome-151-2026 (Google Chrome): Google Chrome 151 patches 382 vulnerabilities including 15 c...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
FortiBleed-2026 (Fortinet FortiGate Firewalls): Massive credential theft campaign compromising 73,000+ Forti... · CVE-2026-33697 (Confidential Computing Attestation Protocols): High severity vulnerability (CVSS 7.5) in confidential compu... · CVE-2026-10539 (BMC Control-M/Server): Critical command injection vulnerability (CVSS 9.0) in Contr...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
CVE-2026-45659 (Microsoft SharePoint Server (Subscription Edition, 2019, 2016)): Remote code execution vulnerability in SharePoint Server ari... · CVE-2026-44941 (libzypp): Relative path traversal vulnerability in keyhint option in r... · CVE-2026-22778 (vLLM): Remote code execution in vLLM framework via malicious video ...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
CVE-2026-48558 (SimpleHelp Remote Support): Authentication bypass in SimpleHelp OIDC authentication flow... · TRUSTFALL-MCP-2026 (Cursor CLI, Claude Code, Gemini CLI, GitHub Copilot CLI): Unpatched prompt injection vulnerability in Model Context Pr...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
ORACLE-CPU-2026-06 (Oracle Solaris Remote Administration Daemon): Oracle Solaris Remote Administration Daemon vulnerability wi... · TRUSTFALL-2026 (Cursor, Claude Code, Gemini CLI, GitHub Copilot CLI): TrustFall is an unpatched multi-IDE vulnerability affecting ... · MCP-SPEC-2026-07 (Model Context Protocol (MCP) Servers and Clients): MCP specification update releasing July 28, 2026 addresses s...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
ORACLE-JUN-2026 (Oracle Product Suite (MySQL, Solaris)): Oracle Critical Security Patch Update addresses 243 CVEs inc... · MCP-SYSTEMIC-RCE (Anthropic Model Context Protocol (MCP)): Systemic architectural vulnerability in Anthropic MCP enable... · VIPER-MCP-67-CVES (MCP Server Ecosystem): VIPER-MCP scan of 40,000 MCP server repositories uncovered 1...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
ADOBE-2026-JUN (Adobe Campaign Classic): Adobe Campaign Classic contains two CVSS 10.0 vulnerabilitie... · REDHAT-MIASMA-2026 (@redhat-cloud-services npm packages): Supply chain attack compromised 32 packages under @redhat-cl... · TANSTACK-SHAI-HULUD-2026 (TanStack and multiple npm packages): Mini Shai-Hulud supply chain attack by TeamPCP compromised T...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
QILIN-CHECKPOINT-VPN-2026 (Check Point VPN / Multiple organizations): Qilin ransomware affiliate exploited Check Point VPN zero-da... · TEAMRCP-MULTI-ECOSYSTEM-2026 (npm, PyPI, VS Code Marketplace, GitHub Actions): TeamPCP orchestrated sophisticated multi-ecosystem supply ch... · GITHUB-NX-CONSOLE-BREACH-2026 (GitHub private repositories): GitHub CISO confirmed TeamPCP used malicious Nx Console VS C...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
CVE-2026-42985 (Windows Remote Desktop Client): Critical Remote Code Execution Vulnerability due to heap-bas... · CVE-2026-42824 (Microsoft 365 Copilot): Critical vulnerability chain in Microsoft 365 Copilot Enterp... · THREAT-ACTOR-2026-001 (Multiple sectors globally): Qilin ransomware operation claimed over 500 victims in 2026 ...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
CVE-2026-20253 (Splunk Enterprise): Critical pre-authentication RCE in Splunk Enterprise with CV... · CVE-2026-48907 (Widget Factory Joomla Content Editor): Improper access control vulnerability in Widget Factory Joom... · CVE-2025-47392 (Qualcomm Closed-Source Components): Critical vulnerability in Qualcomm closed-source components ...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
CVE-2026-50752 (Check Point VPN (IKEv1 site-to-site)): Man-in-the-middle vulnerability in Check Point IKEv1 code pa... · REDHAT-NPM-2026-06-01 (Red Hat NPM packages (@redhat-cloud-services namespace)): Supply chain attack compromised 32 npm packages under @redha... · QILIN-RANSOMWARE-2026-06 (Multiple Organizations (Manufacturing, Energy sectors)): Qilin ransomware group claimed 18 victims across manufacturi...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
CVE-2026-44815 (Windows DHCP Client Service): Critical RCE vulnerability in DHCP Client with CVSS 9.8. Sta... · CVE-2026-26142 (Nuance PowerScribe (Radiology Reporting Platform)): Critical RCE vulnerability in Nuance PowerScribe with CVSS 9... · CVE-2026-0830 (AWS Kiro AI IDE Extension): Command injection vulnerability in AWS Kiro AI-powered IDE e...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
CVE-2026-3300 (Everest Forms Pro WordPress Plugin): Actively exploited critical unauthenticated remote code exec... · CVE-2026-7473 (Arista Extensible Operating System): Incomplete comparison with missing factors vulnerability in ... · CVE-2026-11645 (Google Chromium V8 Engine): Out-of-bounds read and write vulnerability in Google Chromiu...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
CVE-2026-50751 (Check Point Remote Access VPN): Critical authentication bypass vulnerability affecting Check... · TANSTACK-2026-SUPPLY-CHAIN (TanStack npm packages): Critical supply chain attack on May 11, 2026 compromising 84... · IDESASTER-2026-CAMPAIGN (Multiple AI IDEs): Campaign identifying 30+ vulnerabilities across 10+ AI IDEs ...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
CVE-2026-20245 (Cisco Catalyst SD-WAN Manager): Authenticated local command injection in Cisco Catalyst SD-W... · CVE-2026-45247 (Mirasvit Magento Cache Warmer): Deserialization of untrusted data in Mirasvit Full Page Cach... · Miasma-npm-supply-chain-attack (@redhat-cloud-services npm packages): Supply chain attack compromising 32 npm packages under @redh...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
CVE-2026-2673 (OpenSSL): Flaw in OpenSSL TLS 1.3 implementation where server may choo... · CVE-2026-21711 (Node.js): Flaw in Node.js Permission Model network enforcement allowin... · LITELLM-SUPPLY-CHAIN-2026 (LiteLLM Python Package): Supply chain attack on LiteLLM versions 1.82.7 and 1.82.8, t...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
CVE-2026-48188 (OTRS and ((OTRS)) Community Edition): Critical SQL injection vulnerability (CVSS 9.1) in OTRS data... · CVE-2026-45585 (Windows BitLocker (Windows 11, Server 2022/2025)): BitLocker bypass zero-day dubbed 'YellowKey' with public PoC... · AXIOS-NPM-SUPPLY-CHAIN-2026 (Axios npm package (70M+ weekly downloads)): North Korean state actor Sapphire Sleet compromised Axios np...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
CVE-2026-0257 (Palo Alto PAN-OS GlobalProtect): Authentication bypass vulnerability in PAN-OS GlobalProtect ... · CVE-2026-46840 (Oracle REST Data Services Backend-as-a-Service): Easily exploitable vulnerability allows unauthenticated atta... · MSFT-MAY-2026-PATCH (Microsoft Windows and Dynamics 365): Microsoft May 2026 Patch Tuesday addresses 118 CVEs with 16 ...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
CVE-2026-8398 (Daemon Tools Lite): Embedded malicious code vulnerability in Daemon Tools Lite w... · CVE-2026-26980 (Ghost CMS): Critical SQL injection vulnerability in Ghost CMS allowing u... · APT28-DNS-HIJACK-2026 (MikroTik and TP-Link routers): Russia-linked APT28 (Forest Blizzard/Storm-2754) DNS hijacki...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
CVE-2026-48172 (LiteSpeed cPanel Plugin): Privilege escalation vulnerability in LiteSpeed cPanel Plugi... · CVE-2026-46833 (Oracle Database): Oracle Database vulnerability remotely exploitable without a... · CVE-2026-46834 (Oracle Database): Oracle Database vulnerability remotely exploitable without a...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
CVE-2026-9082 (Drupal Core): SQL injection vulnerability in Drupal Core affecting all Pos... · CVE-2025-67644 (LangGraph): SQL injection vulnerability in LangGraph SQLite checkpoint i... · SALT-TYPHOON-2026 (U.S. Telecommunications Infrastructure): Chinese state-sponsored APT Salt Typhoon breached at least 8...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
MSRC-PATCH-TUESDAY-MAY-2026 (Microsoft Windows and Office Products): Microsoft May 2026 Patch Tuesday addresses 120 vulnerabiliti... · CVE-2026-40365 (Microsoft SharePoint Server): Critical vulnerability affecting Microsoft SharePoint Server... · CVE-2026-40361 (Microsoft Word): Critical RCE in Microsoft Word (CVSS 8.4) requiring only ope...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
CVE-2026-41096 (Windows DNS Client): Heap-based buffer overflow in Windows DNS Client allowing un... · CVE-2026-42945 (NGINX): "NGINX Rift" heap buffer overflow in ngx_http_rewrite_module... · CVE-2026-43284 (Linux Kernel): "Dirty Frag" vulnerability (part 1 of 2-bug chain) enabling ...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
CVE-2026-42897 (Microsoft Exchange Server (Subscription Edition, 2016, 2019)): Zero-day spoofing and XSS vulnerability in Exchange Outlook ... · CVE-2026-0300 (Palo Alto Networks PAN-OS (PA-Series and VM-Series firewalls)): Buffer overflow in User-ID Authentication Portal (Captive Po... · CVE-2026-20182 (Cisco Catalyst SD-WAN Controller and Manager): Authentication bypass vulnerability allowing attackers to ga...
AI Vulnerability Monitor — May 15, 2026
CVE-2026-26129 (Microsoft 365 Copilot Business Chat): Improper neutralization of special elements in Microsoft 365... · CVE-2026-26164 (Microsoft 365 Copilot): Information disclosure vulnerability in Microsoft 365 Copilo... · CVE-2026-33111 (Copilot Chat in Microsoft Edge): Command injection vulnerability (CWE-77) in Copilot Chat emb...
Threat Intel Bi-Weekly + AI Vulnerability Monitor
CVE-2026-0300 PAN-OS zero-day CVSS 9.3 nation-state exploited, no patch until May 13 · CVE-2026-41940 cPanel CVSS 9.8 auth bypass, PoC public · CVE-2026-4670 MOVEit CVSS 9.8 auth bypass · ShinyHunters Canvas breach 275M records · ClaudeBleed Chrome extension hijack, no patch fix.
Threat Intel Bi-Weekly + AI Vulnerability Monitor
CVE-2026-0300 PAN-OS zero-day CVSS 9.3 nation-state exploited, no patch until May 13 · CVE-2026-41940 cPanel CVSS 9.8 auth bypass, PoC public · CVE-2026-4670 MOVEit CVSS 9.8 auth bypass · ShinyHunters Canvas breach 275M records · ClaudeBleed Chrome extension hijack, no patch fix.
Threat Intel Bi-Weekly + AI Vulnerability Monitor
TeamPCP Mini Shai-Hulud SAP/Intercom/Lightning supply chain · Comment and Control cross-agent prompt injection CVSS 9.4 · Copy Fail CVE-2026-31431 CISA KEV · M-Trends 2026 mean time-to-exploit -7 days · Salt Typhoon still active 80+ countries.
Threat Intel Bi-Weekly + AI Vulnerability Monitor
CVE-2026-41940 cPanel CVSS 9.8 pre-auth RCE · CVE-2026-31431 Copy Fail Linux LPE · Bitwarden CLI TeamPCP supply chain · LiteLLM SQL injection exploited · Scattered Lapsus$ ShinySp1d3r RaaS.
Threat Intel Bi-Weekly + AI Vulnerability Monitor
Gemini CLI CVSS 10.0 CI/CD RCE · MCP SDK Design Flaw (7k+ servers) · CVE-2026-33825 BlueHammer Windows Defender LPE · SimpleHelp MSP Chain (DragonForce) · ADT 5.5M Record Breach.
April 2026
Threat Intel Bi-Weekly + AI Vulnerability Monitor
Shai-Hulud npm worm targets AI API keys · CVE-2026-25874 HuggingFace RCE (unpatched) · APT28 3-CVE chain · Bissa Scanner AI-assisted mass exploitation · ASP.NET Core CVSS 9.1.
Threat Intel Bi-Weekly + AI Vulnerability Monitor
MCP protocol design flaw (7,000+ servers) · Windows IKE RCE CVSS 9.8 · 3.2B record credential dump · Windsurf zero-click RCE · Salt Typhoon ongoing · Qilin ransomware SEL attack.
Threat Intel Bi-Weekly — April 24, 2026
Axios npm DPRK RAT (Sapphire Sleet) · TeamCity path traversal CISA KEV · Apache ActiveMQ RCE · Vercel OAuth supply chain breach · GitHub Copilot CVE-2026-23653.