
Section
Threats, page 3
Vulnerability intelligence, exploited CVEs, malware families and live campaigns — with the detection guidance and mitigations defenders need first.
231 articles
ThreatsIndustrial & OTCriticalCST Newsroom
ThreatsCloud & SaaSHighAmazon Ion-C Library Recursion Flaw Triggers Cloud Service Stack Exhaustion Crashes CVE-2026-84851
CST Newsroom
ThreatsCloud & SaaSHighAmazon OpenSearch SQL Plugin Cursor Deserialization Flaw Enables Remote Code Execution CVE-2026-83497
CST Newsroom
ThreatsCloud & SaaSHighAzure AI Foundry Server-Side Request Forgery Flaw Exposes Internal Agent Infrastructure CVE-2026-85917
CST Newsroom
ThreatsIndustrial & OTHighCritical lwIP Embedded TCP/IP Stack Double Free Flaw Exposes Industrial Controllers to Remote Hijacking CVE-2026-91018
CST Newsroom
ThreatsCloud & SaaSCriticalCritical Azure Cosmos DB Downstream Injection Flaw Enabled Cloud Privilege Escalation CVE-2026-87701
CST Newsroom
ThreatsCloud & SaaSCriticalCritical Check Point Security Management Server Path Traversal Flaw Exploited to Gain Root System Access CVE-2026-93616
CST Newsroom
ThreatsCloud & SaaSCriticalCritical Arista VeloCloud Orchestrator Zero-Day Exploited to Hijack SD-WAN Edge Gateways CVE-2026-93952
CST Newsroom
ThreatsCloud & SaaSHighCritical OCI Artifact Library Flaw in ORAS-Go Enables Symlink Path Traversal and Supply Chain Compromise CVE-2026-85731
CST Newsroom
ThreatsIndustrial & OTCriticalSiemens Siveillance Control Arbitrary File Upload Flaw Grants Unauthenticated Root Access to Physical Security Systems CVE-2026-50093
CST Newsroom
ThreatsCloud & SaaSCriticalCritical F5 BIG-IP APM Heap Overflow Weaponized to Hijack Enterprise Gateway Data Planes CVE-2026-94127
CST Newsroom
ThreatsCloud & SaaSCriticalGoogle Cloud Patches Critical GKE Multi-Cloud Flaw Enabling Cross-Project Cluster Hijack and Service Account Impersonation
CST Newsroom
ThreatsCloud & SaaSHighBragJack Prompt Forcing Flaws in Chrome and Edge Allow Malicious Extensions to Seize Agentic Browser Control Planes
Mei-Lin Chen
ThreatsIndustrial & OTHighOpenPLC Runtime Stored XSS Flaw Enables Operator Session Hijacking and Unauthorized Physical Process Control CVE-2026-88020
CST Newsroom
ThreatsIndustrial & OTHighCareCam CM2507 IP Cameras Exposed to Video Stream Interception and Privileged Access Takeover CVE-2026-88259
CST Newsroom
ThreatsCloud & SaaSHighOpenNext Cloudflare Adapter Flaw Enables Server-Side Request Forgery and Private Cache Disclosure CVE-2026-3125
CST Newsroom
ThreatsIndustrial & OTHighSiemens Teamcenter Authentication Redirect Flaw Exposes Industrial PLM Blueprints to Session Hijacking CVE-2026-58113
CST Newsroom
ThreatsCloud & SaaSHighStrands Agents Tools HTTP Request Authorization Flaw Enables Indirect Prompt Injection Credential Theft CVE-2026-18394
CST Newsroom
ThreatsCloud & SaaSHighAWS SDK for Go v2 Event Stream Header Decoder Flaw Triggers Remote Denial of Service Panic CVE-2026-89090
CST Newsroom
ThreatsIndustrial & OTHighBransys Electronic Logging Devices Exposed to Fleet Telemetry Hijack via Hardcoded MQTT Credentials Flaw CVE-2026-86520
CST Newsroom
ThreatsCloud & SaaSHighZyxel GS1900 Smart Managed Switches Exploited in the Wild via CGI Stack Buffer Overflow Flaw CVE-2026-7273
Daniel Okafor
ThreatsCloud & SaaSHighCrewAI Multi-Agent Framework Flaw CVE-2026-37007 Allows Remote Code Execution via Path Traversal Tool Poisoning
Mei-Lin Chen
ThreatsCloud & SaaSCriticalCritical Oracle WebLogic Server Flaw CVE-2026-83021 Allows Unauthenticated Remote Code Execution Across Enterprise Java Clusters
Priya Raman
ThreatsCloud & SaaSHighMicrosoft Azure CLI Command Injection Vulnerability CVE-2026-83948 Exposes Cloud CI/CD Automation Runners
Aisha Noor