Threat Intelligence Report

Generated 2026-08-23 14:55 UTC  ·  3/3 sources live  ·  ← back to cyberassist
1674
KEV catalog total
9
Added last 7 days
352
Ransomware-linked
35
Fresh IOCs / pulses

Latest CISA Known Exploited Vulnerabilities live

CVEVendor / ProductVulnerabilityAddedDue
CVE-2026-73570Synacor
Zimbra Collaboration Suite (ZCS)
Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability2026-08-212026-08-24
CVE-2026-72530TrueConf
Server
TrueConf Server Code Injection Vulnerability2026-08-202026-09-03
CVE-2026-72529TrueConf
Server
TrueConf Server Missing Authentication for Critical Function Vulnerability2026-08-202026-08-23
CVE-2026-64849MLflow
MLflow
MLflow Server-Side Request Forgery Vulnerability2026-08-192026-09-02
CVE-2026-33824Microsoft
Internet Key Exchange (IKE) Service Extensions
Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability2026-08-182026-08-21
CVE-2026-59310Broadcom
VMware vCenter
Broadcom VMware vCenter Path Traversal Vulnerability2026-08-182026-08-21
CVE-2026-55040Microsoft
SharePoint
Microsoft SharePoint Weak Authentication Vulnerability2026-08-182026-08-21
CVE-2026-65400Apple
macOS
Apple macOS Improper Authentication Vulnerability2026-08-182026-08-21
CVE-2025-62593Ray-Project
Ray
Ray-Project Ray Code Injection Vulnerability2026-08-172026-08-20
CVE-2026-20349Cisco
Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability2026-08-112026-08-14
CVE-2026-68820Microsoft
Windows Ancillary Function Driver for WinSock
Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability2026-08-112026-08-25
CVE-2026-72898Metabase
Metabase
Metabase SQL Injection Vulnerability2026-08-112026-08-14
CVE-2026-8037Progress
LoadMaster
Progress LoadMaster Command Injection Vulnerability2026-08-072026-08-10
CVE-2026-63077JetBrains
TeamCity
JetBrains TeamCity Deserialization of Untrusted Data Vulnerability2026-08-052026-08-08
CVE-2026-18556N-able
N-central
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability2026-08-042026-08-07
CVE-2026-34486Apache
Tomcat
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability2026-08-042026-08-07
CVE-2026-9198IBM
Langflow
IBM Langflow Code Injection Vulnerability2026-08-042026-08-07
CVE-2026-18577N-able
N-central
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability2026-08-032026-08-06
CVE-2026-20316Cisco
Secure Firewall Management Center (FMC)
Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability2026-07-292026-08-01
CVE-2025-68686Fortinet
FortiOS
Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability2026-07-272026-08-10
CVE-2026-16812Arista
VeloCloud Orchestrator
Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability2026-07-272026-07-30
CVE-2026-16232Check Point
SmartConsole
Check Point SmartConsole Improper Authentication Vulnerability2026-07-222026-07-25
CVE-2026-50522Microsoft
SharePoint
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability 2026-07-222026-07-25
CVE-2026-60137WordPress
Core
WordPress Core SQL Injection Vulnerability2026-07-212026-08-04
CVE-2026-63030WordPress
Core
WordPress Core Interpretation Conflict Vulnerability2026-07-212026-07-24

Recent Malware IOCs — ThreatFox live

IndicatorTypeMalwareThreatConf.First seen
http://bravplo.click:7713/paymentsurlRemusbotnet_cc75%2026-08-23 14:35:11 UTC
aubretteunemployed.workers.devdomainphp.shin_webshellbotnet_cc50%2026-08-23 14:34:29 UTC
http://cj45439.tw1.ru/3464bd73.phpurlDCRatbotnet_cc100%2026-08-23 14:30:17 UTC
87.76.146.91:6522ip:portNjRATbotnet_cc100%2026-08-23 14:30:14 UTC
211.161.232.30:4782ip:portQuasar RATbotnet_cc100%2026-08-23 14:30:10 UTC
185.53.179.136:443ip:portNanocore RATbotnet_cc100%2026-08-23 14:30:05 UTC
khvzuqji.eng-usa-neurowave.usdomainClearFakepayload_delivery100%2026-08-23 14:19:10 UTC
rexhahmetaj.chdomainUnknown malwarepayload_delivery90%2026-08-23 14:15:16 UTC
81.69.226.164:12345ip:portCobalt Strikebotnet_cc100%2026-08-23 14:05:07 UTC
182.255.91.104:2095ip:portCobalt Strikebotnet_cc100%2026-08-23 14:05:06 UTC
182.255.91.104:8080ip:portCobalt Strikebotnet_cc100%2026-08-23 14:05:05 UTC
pinkcassi.workers.devdomainphp.shin_webshellbotnet_cc50%2026-08-23 13:56:22 UTC
bedataexcellent.chdomainClearFakepayload_delivery90%2026-08-23 13:45:14 UTC
sopuly.workers.devdomainphp.shin_webshellbotnet_cc50%2026-08-23 13:41:33 UTC
123.13.48.131:55210ip:portMiraipayload_delivery75%2026-08-23 13:31:13 UTC
zasetesy.workers.devdomainphp.shin_webshellbotnet_cc50%2026-08-23 13:22:41 UTC
dwc0xv75.eng-usa-synadentix.comdomainClearFakepayload_delivery100%2026-08-23 13:13:53 UTC
eng-usa-synadentix.comdomainClearFakepayload_delivery100%2026-08-23 13:10:42 UTC
immersion-totale.devdomainClearFakepayload_delivery90%2026-08-23 13:10:12 UTC
162.251.92.64:22ip:portCobalt Strikebotnet_cc100%2026-08-23 13:05:07 UTC
119.45.225.53:8080ip:portCobalt Strikebotnet_cc100%2026-08-23 13:05:06 UTC
119.45.225.53:22ip:portCobalt Strikebotnet_cc100%2026-08-23 13:05:06 UTC
182.255.91.104:80ip:portCobalt Strikebotnet_cc100%2026-08-23 13:05:05 UTC
djspe30g.eng-usa-heroup.comdomainClearFakepayload_delivery100%2026-08-23 13:02:44 UTC
my-woe.comdomainClearFakepayload_delivery90%2026-08-23 13:00:36 UTC

Community Threat Pulses — AlienVault OTX live

PulseAuthorTagsIOCsCreated
Security Advisory - Action Required - July 2026 Security UpdateAlienVaultprivilege escalation, cve-2026-62144, cve-2026-62145, active exploitation, firewall, cve-2026-16232, gaiaos, management products42026-07-24
Ongoing PLC Exploitation Against Critical U.S. InfrastructureAlienVaultindustrial control systems, critical infrastructure, water facilities, malpdb, ot security, irgc-cec, plc exploitation, iocontrol102026-07-24
Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant StagedAlienVaultcve-2026-43500, hiveserver2 exploitation, apache hadoop targeting, cve-2026-43284, vshell, cve-2017-7269, suo5, shadowpad232026-07-23
Global Webmail EspionageAlienVaultcyberespionage, laundry bear, cve-2025-66376, zimbra, russian threat actor, zero-click phishing, javascript injection, void blizzard102026-07-23
A New Name in the Data Extortion Ecosystem?AlienVaultdata extortion, identity-based attacks, sharepoint exfiltration, vishing, blackfile, mfa abuse, shinyhunters, device code phishing12026-07-23
Exploitation in the Wild of wp2shellAlienVaultplugin upload, cmsmap, cve-2026-63030, cve-2026-60137, wordpress, pre-authentication, rce, batch api exploitation72026-07-23
Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRATAlienVaultclaude ai, sectoprat, vmprotect, stealc, dll sideloading, malvertising, directx shader encryption, gpu anti-vm132026-07-23
JadeProx: Tracing a China-nexus Operation Through an OPSEC MistakeAlienVaultcve-2021-31755, china-nexus, triback loader, cve-2021-32305, adaptixc2, phishing, southeast asia targeting, xmrig592026-07-23
Supply Chain Attack on arrayref: Significant Overlap with DPRK CampaignsAlienVaultcrates.io, dprk, backdoor, typosquatting, supply chain attack, proc-macro1, mastra campaign, rust82026-08-20
Popular Rust Crates Compromised in Build-Time Supply Chain AttackAlienVaultbackdoor, proc-macro1, typosquatting, supply chain attack, proc-macro-en, build-time execution, rust, credential theft182026-08-20