| CVE | Vendor / Product | Vulnerability | Added | Due |
|---|---|---|---|---|
CVE-2026-88779 | Citrix NetScaler | Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability | 2026-10-04 | 2026-10-07 |
CVE-2026-102490 | Zammad GmbH Zammad | Zammad GmbH Zammad Improper Privilege Management Vulnerability | 2026-10-02 | 2026-10-05 |
CVE-2026-102489 | Zammad GmbH Zammad | Zammad GmbH Zammad Session Fixation Vulnerability | 2026-10-02 | 2026-10-05 |
CVE-2026-104286 | Fortinet FortiMail | Fortinet FortiMail Path Traversal Vulnerability | 2026-10-01 | 2026-10-04 |
CVE-2026-76504 | Cisco Catalyst SD-WAN Manager | Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability | 2026-09-30 | 2026-10-03 |
CVE-2026-86950 | Apple Multiple Products | Apple Multiple Products Out-of-Bounds Write Vulnerability | 2026-09-29 | 2026-10-02 |
CVE-2026-88772 | Citrix NetScaler | Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability | 2026-09-27 | 2026-09-30 |
CVE-2026-88771 | Citrix NetScaler | Citrix NetScaler Improper Input Validation Vulnerability | 2026-09-27 | 2026-09-30 |
CVE-2026-67279 | MikroTik RouterOS | Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability | 2026-09-25 | 2026-09-28 |
CVE-2026-65660 | Microsoft SharePoint | Microsoft SharePoint Code Injection Vulnerability | 2026-09-25 | 2026-09-28 |
CVE-2026-87902 | WordPress Core | WordPress Core Remote File Inclusion Vulnerability | 2026-09-25 | 2026-09-28 |
CVE-2026-5430 | WSO2 Multiple Products | WSO2 Multiple Products Path Traversal Vulnerability | 2026-09-24 | 2026-09-27 |
CVE-2026-71362 | Adobe Commerce and Magento | Adobe Commerce and Magento Incorrect Authorization Vulnerability | 2026-09-24 | 2026-09-27 |
CVE-2026-93952 | Arista VeloCloud Orchestrator | Arista VeloCloud Orchestrator Improper Input Validation Vulnerability | 2026-09-22 | 2026-09-25 |
CVE-2026-94127 | F5 BIG-IP APM | F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability | 2026-09-22 | 2026-09-25 |
CVE-2026-93616 | Check Point Multiple Products | Check Point Multiple Products Path Traversal Vulnerability | 2026-09-22 | 2026-09-25 |
CVE-2026-85102 | Check Point Multiple Products | Check Point Multiple Products Improper Certificate Validation Vulnerability | 2026-09-22 | 2026-09-25 |
CVE-2026-7273 | Zyxel GS1900 Series Switches | Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability | 2026-09-21 | 2026-09-24 |
CVE-2025-39964 | Linux Kernel | Linux Kernel Race Condition Vulnerability | 2026-09-18 | 2026-09-21 |
CVE-2026-53266 | Linux Kernel | Linux Kernel Out-of-Bounds Write Vulnerability | 2026-09-18 | 2026-09-21 |
CVE-2025-39682 | Linux Kernel | Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability | 2026-09-18 | 2026-09-21 |
CVE-2026-58704 | Google Pixel | Google Pixel Improper Authorization Vulnerability | 2026-09-16 | 2026-09-19 |
CVE-2026-76460 | Cisco Identity Services Engine | Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability | 2026-09-16 | 2026-09-19 |
CVE-2026-87886 | Acronis Backup | Acronis Backup Incorrect Default Permissions Vulnerability | 2026-09-16 | 2026-09-19 |
CVE-2026-76461 | Cisco Secure Email Gateway | Cisco Secure Email Gateway SQL Injection Vulnerability | 2026-09-14 | 2026-09-17 |
| Indicator | Type | Malware | Threat | Conf. | First seen |
|---|---|---|---|---|---|
4ctohaaw.roseanne.id | domain | ClearFake | payload_delivery | 100% | 2026-10-07 18:47:43 UTC |
91.92.40.209:1300 | ip:port | Unknown malware | botnet_cc | 75% | 2026-10-07 18:43:09 UTC |
85.11.167.105:7000 | ip:port | Unknown malware | botnet_cc | 75% | 2026-10-07 18:39:21 UTC |
sulaf.store | domain | ClearFake | payload_delivery | 100% | 2026-10-07 18:22:49 UTC |
shahabnetco.ir | domain | ClearFake | payload_delivery | 90% | 2026-10-07 18:22:33 UTC |
sportorium.ptumb.com | domain | ClearFake | payload_delivery | 90% | 2026-10-07 18:22:33 UTC |
37.120.206.165:60507 | ip:port | Remcos | botnet_cc | 75% | 2026-10-07 18:22:13 UTC |
a8dd58cca69cff0ca3d6786686ece74e67804e4ea1ce961aab37ee9520fe2998 | sha256_hash | AMOS | payload | 100% | 2026-10-07 18:20:17 UTC |
178.16.53.56:8080 | ip:port | Aisuru | botnet_cc | 100% | 2026-10-07 18:20:17 UTC |
http://115.55.21.134:49546/Mozi.m | url | Mozi | payload_delivery | 75% | 2026-10-07 18:18:35 UTC |
http://101.53.235.246:49553/Mozi.m | url | Mozi | payload_delivery | 75% | 2026-10-07 18:18:35 UTC |
http://160.250.114.90:55744/Mozi.m | url | Mozi | payload_delivery | 75% | 2026-10-07 18:18:34 UTC |
http://72.255.32.69:55398/Mozi.m | url | Mozi | payload_delivery | 75% | 2026-10-07 18:18:34 UTC |
http://153.117.40.189:37063/Mozi.m | url | Mozi | payload_delivery | 75% | 2026-10-07 18:18:33 UTC |
antimalvareprotect.cc | domain | Unknown malware | payload_delivery | 90% | 2026-10-07 18:12:23 UTC |
217.60.103.154:443 | ip:port | XWorm | botnet_cc | 75% | 2026-10-07 18:10:32 UTC |
217.60.195.112:443 | ip:port | XWorm | botnet_cc | 75% | 2026-10-07 18:10:31 UTC |
102.220.163.105:2754 | ip:port | XWorm | botnet_cc | 75% | 2026-10-07 18:10:31 UTC |
155.103.69.56:4326 | ip:port | XWorm | botnet_cc | 75% | 2026-10-07 18:10:31 UTC |
ellab0098.duckdns.org | domain | XWorm | botnet_cc | 75% | 2026-10-07 18:10:23 UTC |
134.122.155.207:52841 | ip:port | ValleyRAT | botnet_cc | 75% | 2026-10-07 18:05:31 UTC |
134.122.155.207:52843 | ip:port | ValleyRAT | botnet_cc | 75% | 2026-10-07 18:05:31 UTC |
203.202.232.254:1122 | ip:port | XWorm | botnet_cc | 75% | 2026-10-07 18:05:31 UTC |
qymojo.workers.dev | domain | php.shin_webshell | botnet_cc | 50% | 2026-10-07 17:59:56 UTC |
gd4ejm0dwz.workers.dev | domain | php.shin_webshell | botnet_cc | 50% | 2026-10-07 17:53:12 UTC |
| Pulse | Author | Tags | IOCs | Created |
|---|---|---|---|---|
| StyleSmuggler: Magento and Adobe Commerce 0-day RCE under active attack | AlienVault | remote code execution, adobe commerce, rust backdoor, zero-day, stylesmuggler | 25 | 2026-09-07 |
| Tracking BigBear 2.0 Evilginx2 Phishing Campaign | AlienVault | phishing-as-a-service, evilginx2, microsoft 365, bigbear 2.0, bigbear | 27 | 2026-09-07 |
| Behind the Connect Button: The Fake AI Ads Campaign | AlienVault | socket.io, social engineering, phishing campaign, mfa bypass, browser-in-the-browser, credential theft, advertising accounts, ai impersonation | 108 | 2026-10-07 |
| Akira Ransomware Attack Investigation | AlienVault | data exfiltration, antivirus evasion, rclone, ransomware, rdp, persistence, akira, gost tunnel | 3 | 2026-10-07 |
| Iranian State-Aligned Threat Actor Masquerading as Dubai Airports IT Department Delivering Trojanized Coding Challenges - Blinder Tunnel Campaign Targeting Iraqi Critical Infrastructure | AlienVault | appdomainmanager hijacking, blackwood.dll, blinder tunnel, chisel, dll sideloading, shelbyloader v2, iraqi critical infrastructure, runtimebroker.dll | 32 | 2026-10-07 |
| Beyond valid credentials: How exposed AWS keys are tested for Amazon Bedrock access | AlienVault | amazon bedrock, credential validation, anthropic claude, token-jacking, credential harvesting, cloud security, llm, aws | 36 | 2026-10-06 |
| Attackers Target AI Development Platform Langflow | AlienVault | cve-2017-9841, cve-2021-26855, cve-2018-20062, cve-2025-55184, unauthenticated access, cve-2021-34523, credential harvesting, ai platform exploitation | 17 | 2026-10-07 |
| Lunex Uses BYOVD to Disable Security Monitoring and Deploy Persistent Stealer | AlienVault | byovd, lunexstealer, cve-2023-20598, pdfwkrnl.sys, kernel callback manipulation, cryptocurrency wallet theft, native messaging host persistence, amd driver vulnerability | 40 | 2026-10-06 |
| ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure | AlienVault | cve-2024-32314, proxy botnet, cve-2026-87827, cve-2023-41011, cve-2021-35394, cve-2024-21887, cve-2022-35555, cve-2014-8361 | 83 | 2026-10-05 |
| StyleSmuggler: Magento and Adobe Commerce 0-day RCE under active attack | AlienVault | backdoor, stylesmuggler, magento, payment email, remote code execution, graphql, adobe commerce, zero-day | 15 | 2026-09-05 |