| CVE | Vendor / Product | Vulnerability | Added | Due |
|---|---|---|---|---|
CVE-2026-73570 | Synacor Zimbra Collaboration Suite (ZCS) | Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability | 2026-08-21 | 2026-08-24 |
CVE-2026-72530 | TrueConf Server | TrueConf Server Code Injection Vulnerability | 2026-08-20 | 2026-09-03 |
CVE-2026-72529 | TrueConf Server | TrueConf Server Missing Authentication for Critical Function Vulnerability | 2026-08-20 | 2026-08-23 |
CVE-2026-64849 | MLflow MLflow | MLflow Server-Side Request Forgery Vulnerability | 2026-08-19 | 2026-09-02 |
CVE-2026-33824 | Microsoft Internet Key Exchange (IKE) Service Extensions | Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability | 2026-08-18 | 2026-08-21 |
CVE-2026-59310 | Broadcom VMware vCenter | Broadcom VMware vCenter Path Traversal Vulnerability | 2026-08-18 | 2026-08-21 |
CVE-2026-55040 | Microsoft SharePoint | Microsoft SharePoint Weak Authentication Vulnerability | 2026-08-18 | 2026-08-21 |
CVE-2026-65400 | Apple macOS | Apple macOS Improper Authentication Vulnerability | 2026-08-18 | 2026-08-21 |
CVE-2025-62593 | Ray-Project Ray | Ray-Project Ray Code Injection Vulnerability | 2026-08-17 | 2026-08-20 |
CVE-2026-20349 | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability | 2026-08-11 | 2026-08-14 |
CVE-2026-68820 | Microsoft Windows Ancillary Function Driver for WinSock | Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability | 2026-08-11 | 2026-08-25 |
CVE-2026-72898 | Metabase Metabase | Metabase SQL Injection Vulnerability | 2026-08-11 | 2026-08-14 |
CVE-2026-8037 | Progress LoadMaster | Progress LoadMaster Command Injection Vulnerability | 2026-08-07 | 2026-08-10 |
CVE-2026-63077 | JetBrains TeamCity | JetBrains TeamCity Deserialization of Untrusted Data Vulnerability | 2026-08-05 | 2026-08-08 |
CVE-2026-18556 | N-able N-central | N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability | 2026-08-04 | 2026-08-07 |
CVE-2026-34486 | Apache Tomcat | Apache Tomcat Missing Encryption of Sensitive Data Vulnerability | 2026-08-04 | 2026-08-07 |
CVE-2026-9198 | IBM Langflow | IBM Langflow Code Injection Vulnerability | 2026-08-04 | 2026-08-07 |
CVE-2026-18577 | N-able N-central | N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability | 2026-08-03 | 2026-08-06 |
CVE-2026-20316 | Cisco Secure Firewall Management Center (FMC) | Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability | 2026-07-29 | 2026-08-01 |
CVE-2025-68686 | Fortinet FortiOS | Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability | 2026-07-27 | 2026-08-10 |
CVE-2026-16812 | Arista VeloCloud Orchestrator | Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability | 2026-07-27 | 2026-07-30 |
CVE-2026-16232 | Check Point SmartConsole | Check Point SmartConsole Improper Authentication Vulnerability | 2026-07-22 | 2026-07-25 |
CVE-2026-50522 | Microsoft SharePoint | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | 2026-07-22 | 2026-07-25 |
CVE-2026-60137 | WordPress Core | WordPress Core SQL Injection Vulnerability | 2026-07-21 | 2026-08-04 |
CVE-2026-63030 | WordPress Core | WordPress Core Interpretation Conflict Vulnerability | 2026-07-21 | 2026-07-24 |
| Indicator | Type | Malware | Threat | Conf. | First seen |
|---|---|---|---|---|---|
rf65356zl4.workers.dev | domain | php.shin_webshell | botnet_cc | 50% | 2026-08-23 15:41:18 UTC |
smtp.coralbridge.cc | domain | Vidar | botnet_cc | 100% | 2026-08-23 15:38:49 UTC |
http://115.54.128.38:41331/Mozi.m | url | Mozi | payload_delivery | 75% | 2026-08-23 15:21:13 UTC |
http://221.14.14.113:44549/Mozi.m | url | Mozi | payload_delivery | 75% | 2026-08-23 15:21:12 UTC |
http://103.65.30.142:38983/Mozi.m | url | Mozi | payload_delivery | 75% | 2026-08-23 15:21:11 UTC |
http://110.38.240.188:46981/Mozi.m | url | Mozi | payload_delivery | 75% | 2026-08-23 15:21:11 UTC |
http://110.38.250.142:50982/Mozi.m | url | Mozi | payload_delivery | 75% | 2026-08-23 15:21:10 UTC |
http://119.73.19.38:45279/Mozi.m | url | Mozi | payload_delivery | 75% | 2026-08-23 15:21:10 UTC |
http://110.38.240.183:34521/Mozi.m | url | Mozi | payload_delivery | 75% | 2026-08-23 15:21:09 UTC |
http://223.123.42.238:59720/Mozi.m | url | Mozi | payload_delivery | 75% | 2026-08-23 15:21:09 UTC |
http://80.83.230.144:53523/Mozi.m | url | Mozi | payload_delivery | 75% | 2026-08-23 15:21:08 UTC |
http://153.117.33.131:55231/Mozi.a | url | Mozi | payload_delivery | 75% | 2026-08-23 15:21:07 UTC |
http://103.237.157.188:60261/Mozi.m | url | Mozi | payload_delivery | 75% | 2026-08-23 15:21:07 UTC |
http://223.123.73.169:35385/Mozi.m | url | Mozi | payload_delivery | 75% | 2026-08-23 15:21:06 UTC |
http://shhsift.click:7647/permissions | url | Remus | botnet_cc | 75% | 2026-08-23 15:15:25 UTC |
ipekwgai.eng-usa-us-menbalancepro.com | domain | ClearFake | payload_delivery | 100% | 2026-08-23 15:15:03 UTC |
qfbxg48239.workers.dev | domain | php.shin_webshell | botnet_cc | 50% | 2026-08-23 15:13:46 UTC |
eng-usa-us-menbalancepro.com | domain | ClearFake | payload_delivery | 100% | 2026-08-23 15:10:56 UTC |
https://espossto.lol/api/v1/verify | url | KongTuke | payload_delivery | 100% | 2026-08-23 15:08:20 UTC |
https://espossto.lol/api/v1/session | url | KongTuke | payload_delivery | 100% | 2026-08-23 15:08:19 UTC |
espossto.lol | domain | KongTuke | payload_delivery | 100% | 2026-08-23 15:08:18 UTC |
epquo73102.workers.dev | domain | php.shin_webshell | botnet_cc | 50% | 2026-08-23 15:08:07 UTC |
http://kupzovo.shop:7567/teams | url | Remus | botnet_cc | 75% | 2026-08-23 15:05:16 UTC |
http://bravplo.click:7713/tags | url | Remus | botnet_cc | 75% | 2026-08-23 15:05:13 UTC |
81.69.226.164:22 | ip:port | Cobalt Strike | botnet_cc | 100% | 2026-08-23 15:05:07 UTC |
| Pulse | Author | Tags | IOCs | Created |
|---|---|---|---|---|
| Security Advisory - Action Required - July 2026 Security Update | AlienVault | privilege escalation, cve-2026-62144, cve-2026-62145, active exploitation, firewall, cve-2026-16232, gaiaos, management products | 4 | 2026-07-24 |
| Ongoing PLC Exploitation Against Critical U.S. Infrastructure | AlienVault | industrial control systems, critical infrastructure, water facilities, malpdb, ot security, irgc-cec, plc exploitation, iocontrol | 10 | 2026-07-24 |
| Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged | AlienVault | cve-2026-43500, hiveserver2 exploitation, apache hadoop targeting, cve-2026-43284, vshell, cve-2017-7269, suo5, shadowpad | 23 | 2026-07-23 |
| Global Webmail Espionage | AlienVault | cyberespionage, laundry bear, cve-2025-66376, zimbra, russian threat actor, zero-click phishing, javascript injection, void blizzard | 10 | 2026-07-23 |
| A New Name in the Data Extortion Ecosystem? | AlienVault | data extortion, identity-based attacks, sharepoint exfiltration, vishing, blackfile, mfa abuse, shinyhunters, device code phishing | 1 | 2026-07-23 |
| Exploitation in the Wild of wp2shell | AlienVault | plugin upload, cmsmap, cve-2026-63030, cve-2026-60137, wordpress, pre-authentication, rce, batch api exploitation | 7 | 2026-07-23 |
| Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT | AlienVault | claude ai, sectoprat, vmprotect, stealc, dll sideloading, malvertising, directx shader encryption, gpu anti-vm | 13 | 2026-07-23 |
| JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake | AlienVault | cve-2021-31755, china-nexus, triback loader, cve-2021-32305, adaptixc2, phishing, southeast asia targeting, xmrig | 59 | 2026-07-23 |
| Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns | AlienVault | crates.io, dprk, backdoor, typosquatting, supply chain attack, proc-macro1, mastra campaign, rust | 8 | 2026-08-20 |
| Popular Rust Crates Compromised in Build-Time Supply Chain Attack | AlienVault | backdoor, proc-macro1, typosquatting, supply chain attack, proc-macro-en, build-time execution, rust, credential theft | 18 | 2026-08-20 |