| CVE | Vendor / Product | Vulnerability | Added | Due |
|---|---|---|---|---|
CVE-2026-73570 | Synacor Zimbra Collaboration Suite (ZCS) | Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability | 2026-08-21 | 2026-08-24 |
CVE-2026-72530 | TrueConf Server | TrueConf Server Code Injection Vulnerability | 2026-08-20 | 2026-09-03 |
CVE-2026-72529 | TrueConf Server | TrueConf Server Missing Authentication for Critical Function Vulnerability | 2026-08-20 | 2026-08-23 |
CVE-2026-64849 | MLflow MLflow | MLflow Server-Side Request Forgery Vulnerability | 2026-08-19 | 2026-09-02 |
CVE-2026-33824 | Microsoft Internet Key Exchange (IKE) Service Extensions | Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability | 2026-08-18 | 2026-08-21 |
CVE-2026-59310 | Broadcom VMware vCenter | Broadcom VMware vCenter Path Traversal Vulnerability | 2026-08-18 | 2026-08-21 |
CVE-2026-55040 | Microsoft SharePoint | Microsoft SharePoint Weak Authentication Vulnerability | 2026-08-18 | 2026-08-21 |
CVE-2026-65400 | Apple macOS | Apple macOS Improper Authentication Vulnerability | 2026-08-18 | 2026-08-21 |
CVE-2025-62593 | Ray-Project Ray | Ray-Project Ray Code Injection Vulnerability | 2026-08-17 | 2026-08-20 |
CVE-2026-20349 | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability | 2026-08-11 | 2026-08-14 |
CVE-2026-68820 | Microsoft Windows Ancillary Function Driver for WinSock | Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability | 2026-08-11 | 2026-08-25 |
CVE-2026-72898 | Metabase Metabase | Metabase SQL Injection Vulnerability | 2026-08-11 | 2026-08-14 |
CVE-2026-8037 | Progress LoadMaster | Progress LoadMaster Command Injection Vulnerability | 2026-08-07 | 2026-08-10 |
CVE-2026-63077 | JetBrains TeamCity | JetBrains TeamCity Deserialization of Untrusted Data Vulnerability | 2026-08-05 | 2026-08-08 |
CVE-2026-18556 | N-able N-central | N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability | 2026-08-04 | 2026-08-07 |
CVE-2026-34486 | Apache Tomcat | Apache Tomcat Missing Encryption of Sensitive Data Vulnerability | 2026-08-04 | 2026-08-07 |
CVE-2026-9198 | IBM Langflow | IBM Langflow Code Injection Vulnerability | 2026-08-04 | 2026-08-07 |
CVE-2026-18577 | N-able N-central | N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability | 2026-08-03 | 2026-08-06 |
CVE-2026-20316 | Cisco Secure Firewall Management Center (FMC) | Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability | 2026-07-29 | 2026-08-01 |
CVE-2025-68686 | Fortinet FortiOS | Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability | 2026-07-27 | 2026-08-10 |
CVE-2026-16812 | Arista VeloCloud Orchestrator | Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability | 2026-07-27 | 2026-07-30 |
CVE-2026-16232 | Check Point SmartConsole | Check Point SmartConsole Improper Authentication Vulnerability | 2026-07-22 | 2026-07-25 |
CVE-2026-50522 | Microsoft SharePoint | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | 2026-07-22 | 2026-07-25 |
CVE-2026-60137 | WordPress Core | WordPress Core SQL Injection Vulnerability | 2026-07-21 | 2026-08-04 |
CVE-2026-63030 | WordPress Core | WordPress Core Interpretation Conflict Vulnerability | 2026-07-21 | 2026-07-24 |
| Indicator | Type | Malware | Threat | Conf. | First seen |
|---|---|---|---|---|---|
http://bravplo.click:7713/payments | url | Remus | botnet_cc | 75% | 2026-08-23 14:35:11 UTC |
aubretteunemployed.workers.dev | domain | php.shin_webshell | botnet_cc | 50% | 2026-08-23 14:34:29 UTC |
http://cj45439.tw1.ru/3464bd73.php | url | DCRat | botnet_cc | 100% | 2026-08-23 14:30:17 UTC |
87.76.146.91:6522 | ip:port | NjRAT | botnet_cc | 100% | 2026-08-23 14:30:14 UTC |
211.161.232.30:4782 | ip:port | Quasar RAT | botnet_cc | 100% | 2026-08-23 14:30:10 UTC |
185.53.179.136:443 | ip:port | Nanocore RAT | botnet_cc | 100% | 2026-08-23 14:30:05 UTC |
khvzuqji.eng-usa-neurowave.us | domain | ClearFake | payload_delivery | 100% | 2026-08-23 14:19:10 UTC |
rexhahmetaj.ch | domain | Unknown malware | payload_delivery | 90% | 2026-08-23 14:15:16 UTC |
81.69.226.164:12345 | ip:port | Cobalt Strike | botnet_cc | 100% | 2026-08-23 14:05:07 UTC |
182.255.91.104:2095 | ip:port | Cobalt Strike | botnet_cc | 100% | 2026-08-23 14:05:06 UTC |
182.255.91.104:8080 | ip:port | Cobalt Strike | botnet_cc | 100% | 2026-08-23 14:05:05 UTC |
pinkcassi.workers.dev | domain | php.shin_webshell | botnet_cc | 50% | 2026-08-23 13:56:22 UTC |
bedataexcellent.ch | domain | ClearFake | payload_delivery | 90% | 2026-08-23 13:45:14 UTC |
sopuly.workers.dev | domain | php.shin_webshell | botnet_cc | 50% | 2026-08-23 13:41:33 UTC |
123.13.48.131:55210 | ip:port | Mirai | payload_delivery | 75% | 2026-08-23 13:31:13 UTC |
zasetesy.workers.dev | domain | php.shin_webshell | botnet_cc | 50% | 2026-08-23 13:22:41 UTC |
dwc0xv75.eng-usa-synadentix.com | domain | ClearFake | payload_delivery | 100% | 2026-08-23 13:13:53 UTC |
eng-usa-synadentix.com | domain | ClearFake | payload_delivery | 100% | 2026-08-23 13:10:42 UTC |
immersion-totale.dev | domain | ClearFake | payload_delivery | 90% | 2026-08-23 13:10:12 UTC |
162.251.92.64:22 | ip:port | Cobalt Strike | botnet_cc | 100% | 2026-08-23 13:05:07 UTC |
119.45.225.53:8080 | ip:port | Cobalt Strike | botnet_cc | 100% | 2026-08-23 13:05:06 UTC |
119.45.225.53:22 | ip:port | Cobalt Strike | botnet_cc | 100% | 2026-08-23 13:05:06 UTC |
182.255.91.104:80 | ip:port | Cobalt Strike | botnet_cc | 100% | 2026-08-23 13:05:05 UTC |
djspe30g.eng-usa-heroup.com | domain | ClearFake | payload_delivery | 100% | 2026-08-23 13:02:44 UTC |
my-woe.com | domain | ClearFake | payload_delivery | 90% | 2026-08-23 13:00:36 UTC |
| Pulse | Author | Tags | IOCs | Created |
|---|---|---|---|---|
| Security Advisory - Action Required - July 2026 Security Update | AlienVault | privilege escalation, cve-2026-62144, cve-2026-62145, active exploitation, firewall, cve-2026-16232, gaiaos, management products | 4 | 2026-07-24 |
| Ongoing PLC Exploitation Against Critical U.S. Infrastructure | AlienVault | industrial control systems, critical infrastructure, water facilities, malpdb, ot security, irgc-cec, plc exploitation, iocontrol | 10 | 2026-07-24 |
| Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged | AlienVault | cve-2026-43500, hiveserver2 exploitation, apache hadoop targeting, cve-2026-43284, vshell, cve-2017-7269, suo5, shadowpad | 23 | 2026-07-23 |
| Global Webmail Espionage | AlienVault | cyberespionage, laundry bear, cve-2025-66376, zimbra, russian threat actor, zero-click phishing, javascript injection, void blizzard | 10 | 2026-07-23 |
| A New Name in the Data Extortion Ecosystem? | AlienVault | data extortion, identity-based attacks, sharepoint exfiltration, vishing, blackfile, mfa abuse, shinyhunters, device code phishing | 1 | 2026-07-23 |
| Exploitation in the Wild of wp2shell | AlienVault | plugin upload, cmsmap, cve-2026-63030, cve-2026-60137, wordpress, pre-authentication, rce, batch api exploitation | 7 | 2026-07-23 |
| Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT | AlienVault | claude ai, sectoprat, vmprotect, stealc, dll sideloading, malvertising, directx shader encryption, gpu anti-vm | 13 | 2026-07-23 |
| JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake | AlienVault | cve-2021-31755, china-nexus, triback loader, cve-2021-32305, adaptixc2, phishing, southeast asia targeting, xmrig | 59 | 2026-07-23 |
| Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns | AlienVault | crates.io, dprk, backdoor, typosquatting, supply chain attack, proc-macro1, mastra campaign, rust | 8 | 2026-08-20 |
| Popular Rust Crates Compromised in Build-Time Supply Chain Attack | AlienVault | backdoor, proc-macro1, typosquatting, supply chain attack, proc-macro-en, build-time execution, rust, credential theft | 18 | 2026-08-20 |