
Section
Threats, page 9
Vulnerability intelligence, exploited CVEs, malware families and live campaigns — with the detection guidance and mitigations defenders need first.
231 articles
ThreatsHealthcare & PharmaCriticalPriya Raman
ThreatsIndustrial & OTCriticalSAP Security Patch Day Addresses Critical NetWeaver Message Server Authentication Bypass
Aisha Noor
ThreatsCloud & SaaSCriticalBroadcom Discloses Critical VMware Hypervisor Escape Flaws in Workstation and Fusion
Priya Raman
ThreatsTelecom & MediaHighCisco Fixes High-Severity Memory Corruption Flaw in Carrier-Grade IOS XR Routing Core
Daniel Okafor
ThreatsCloud & SaaSCriticalIvanti Patches Critical Remote Code Execution Flaw in Neurons for ITSM Infrastructure
Priya Raman
ThreatsCloud & SaaSCriticalCitrix NetScaler CVSS 9.3 authentication bypass CVE-2026-19490 under active in-the-wild exploitation
Daniel Okafor
ThreatsCloud & SaaSMicrosoft traces passkey-themed lures to persistent Microsoft 365 cloud compromise
Aisha Noor
ThreatsCloud & SaaSGitHub adds a merge gate for pull requests with unresolved secret alerts
Daniel Okafor- ThreatsRetail & E-commerceCritical
Adobe warns of exploited Commerce and Magento RCE — patch CVE-2026-75650 now
Priya Raman
ThreatsCloud & SaaSCriticalCisco Secure FMC authentication bypass CVE-2026-20079 exploited by Qilin ransomware affiliates
Daniel Okafor
ThreatsCloud & SaaSCriticalSwarm of OpenAI agents flooded RubyGems to execute code and harvest data on RubyDoc servers
Mei-Lin Chen
ThreatsTelecom & MediaCriticalChinese state-aligned group UNC3569 exploited zero-day flaw in Sogou Input Method to drop GRAYRABBIT backdoor
Mei-Lin Chen
ThreatsTelecom & MediaHighAttackers exploit Google Play Early Access loop to distribute deceptive malware apps to millions
Aisha Noor
ThreatsCloud & SaaSCriticalThreat actors actively exploit Langflow AI orchestration flaws to steal cloud API keys and deploy miners
Priya Raman
ThreatsIndustrial & OTCriticalMikroTrick exploit chain compromises MikroTik RouterOS devices as ScreenConnect client flaw hits KEV
Daniel Okafor
ThreatsCloud & SaaSHighPostGREShell: 12-year-old PostgreSQL logical replication flaw CVE-2026-6471 enables remote code execution
Tom Verhoeven
ThreatsGov & DefenceCriticalNorth Korean actors deploy trojanized HAProxy 'TED' backdoor inside South Korean enterprise networks
Daniel Okafor
ThreatsIndustrial & OTCriticalTwo 9.8 Check Point VPN flaws put the perimeter back on the emergency patch queue
Priya Raman
ThreatsCloud & SaaSCriticalGitLab fixes maximum-severity CVSS 10.0 file-read flaw as in-the-wild exploitation begins
Priya Raman
ThreatsCloud & SaaSCriticalAttackers chain dual JFrog Artifactory vulnerabilities to hijack build pipelines and plant backdoors
Aisha Noor
ThreatsCloud & SaaSHighPaperCut issues superseding maintenance releases as attackers deploy AI agent swarms against 440+ servers
Daniel Okafor
ThreatsIndustrial & OTCriticalSonicWall SMA1000 Zero-Day Chain Hit CISA KEV in Three Days. Patching Is the Easy Part
Daniel Okafor
ThreatsCloud & SaaSCriticalFortiClient EMS CVE-2026-35616: the hotfix window was not the dangerous part
Priya Raman- ThreatsCloud & SaaSHigh
LiteLLM and Kestra in KEV: exploited AI tooling is now a vulnerability management problem
Daniel Okafor