critical
79
high
21
medium
0
low
0
New CRITICAL Threat: Apache Log4j Remote Code Execution
This vulnerability remains a highly prevalent threat, with over 150 million exploitation attempts recorded in the last 24 hours, allowing attackers to execute arbitrary code.
New CRITICAL Threat: Emperador Ransomware Attack
The Emperador ransomware group has recently targeted government infrastructure, compromising sensitive financial and healthcare data.
New CRITICAL Threat: Orkes Conductor Critical Vulnerability
A critical vulnerability impacting Orkes Conductor is currently being actively exploited in the wild, posing a significant risk to affected systems.
Outdated OpenSSL Version Detected
Systems running OpenSSL versions vulnerable to CVE-2023-XXXX
New CRITICAL Threat: Apache Log4j Remote Code Execution
An ongoing, highly prevalent threat where attackers exploit the Log4j vulnerability to execute arbitrary code on remote servers, with over 150 million attempts recorded in the last 24 hours.
New CRITICAL Threat: Emperador Ransomware Attack
The Emperador ransomware group has actively targeted and compromised the Cassias MG Government in Brazil, leading to the theft of sensitive financial and healthcare data.
New CRITICAL Threat: N-central Authentication Bypass
Two severe vulnerabilities (CVE-2026-86206 and CVE-2026-86207) in N-able N-central allow unauthorized parties to bypass authentication controls and gain full access to the platform.
New CRITICAL Threat: N-central Authentication Bypass (CVE-2026-86206/86207)
Severe vulnerabilities in N-able N-central that allow unauthorized parties to bypass authentication controls and gain full administrative access to the platform.
New CRITICAL Threat: Emperador Ransomware Campaign
The Emperador ransomware group is actively targeting government entities, such as the Cassias MG Government in Brazil, to exfiltrate sensitive financial and healthcare data.
New CRITICAL Threat: Apache Log4j Remote Code Execution
An active, high-volume exploit targeting the Log4j logging library, allowing remote attackers to execute arbitrary code on affected systems.
Outdated OpenSSL Version Detected
Systems running OpenSSL versions vulnerable to CVE-2023-XXXX
New CRITICAL Threat: N-central Authentication Bypass (CVE-2026-86206 and CVE-2026-86207)
Two severe vulnerabilities in N-able's N-central platform allow unauthorized parties to bypass authentication controls, potentially granting attackers full administrative access to the platform.
New CRITICAL Threat: TheGentlemen Ransomware Attack on ACA Pescara
The ransomware group TheGentlemen has successfully breached the Italian public housing agency ACA Pescara, putting sensitive citizen and agency data at risk of exfiltration and encryption.
New CRITICAL Threat: N-central Authentication Bypass (CVE-2026-86206/86207)
Two severe vulnerabilities in N-able N-central that allow unauthorized parties to bypass authentication controls and gain full administrative access to the platform.
New HIGH Threat: TheGentlemen Ransomware Campaign
The ransomware group 'TheGentlemen' is actively targeting public sector organizations, such as the ACA Pescara housing agency, to exfiltrate and encrypt sensitive data.
New CRITICAL Threat: Apache Log4j Remote Code Execution
An active, high-volume exploit targeting the Log4j logging library, allowing remote attackers to execute arbitrary code on affected systems.
Outdated OpenSSL Version Detected
Systems running OpenSSL versions vulnerable to CVE-2023-XXXX
New CRITICAL Threat: Orkes Conductor Vulnerability
A critical security flaw in Orkes Conductor that is currently being actively exploited in the wild, posing a significant risk to affected infrastructure.
New CRITICAL Threat: Emperador Ransomware Campaign
The Emperador ransomware group is actively targeting government entities, such as the Cassias MG Government in Brazil, compromising sensitive financial and healthcare data.
New CRITICAL Threat: Apache Log4j Remote Code Execution
A highly prevalent vulnerability involving remote code execution via error logs, which continues to see massive exploitation attempts globally.
New HIGH Threat: Anubis Ransomware Attack on Quest Group
The Anubis ransomware group compromised internal files and employee data at the US-based Quest Group, highlighting weaknesses in corporate security defenses.
New HIGH Threat: TheGentlemen Ransomware Attack on ACA Pescara
The ransomware group known as TheGentlemen targeted the Italian public housing agency ACA Pescara, putting sensitive citizen and agency data at risk.
New CRITICAL Threat: Emperador Ransomware Attack on Cassias MG Government
The Emperador ransomware group successfully breached the Cassias MG Government in Brazil, compromising sensitive data across the finance and healthcare sectors.
Unpatched Log4j Vulnerability
Critical Log4Shell vulnerability detected in application servers
New HIGH Threat: TheGentlemen Ransomware Breach of ACA Pescara
The ransomware group TheGentlemen targeted the Italian public housing agency ACA Pescara, putting sensitive citizen and agency data at risk.
New CRITICAL Threat: Emperador Ransomware Attack on Cassias MG Government
The Emperador ransomware group successfully breached the Cassias MG Government in Brazil, compromising sensitive data across the finance and healthcare sectors.
New CRITICAL Threat: Emperador Ransomware Attack
The Emperador ransomware group has recently targeted government infrastructure, compromising sensitive data across financial and healthcare sectors.
New CRITICAL Threat: Orkes Conductor Critical Vulnerability
A critical vulnerability in Orkes Conductor is currently being actively exploited in the wild, potentially allowing unauthorized access or control over affected systems.
New CRITICAL Threat: Orkes Conductor Critical Vulnerability
A critical vulnerability impacting Orkes Conductor that is currently being actively exploited in the wild.
New CRITICAL Threat: CVE-2025-8821 Zero-Day Exploit Chain
An active zero-day exploit chain currently being utilized in cyber operations, posing a significant risk to perimeter security and system integrity.
New CRITICAL Threat: Oracle Payments Component Vulnerability (CVE-2026-46817)
A critical flaw in the Oracle E-Business Suite's Payments component that allows unauthenticated attackers to gain full control over the application and access sensitive financial data.
New HIGH Threat: X Money Phishing Campaign
A surge in fraudulent password-reset emails targeting X users following the launch of X Money, designed to facilitate account takeover through credential harvesting.
New CRITICAL Threat: Apache Log4j Remote Code Execution
A persistent and highly prevalent vulnerability in the Apache Log4j logging library that allows unauthenticated remote code execution, frequently targeted by automated botnets.
Outdated OpenSSL Version Detected
Systems running OpenSSL versions vulnerable to CVE-2023-XXXX
New CRITICAL Threat: Identity-Based Ransomware Campaigns
Modern ransomware actors are shifting focus to identity compromise as an initial access vector, using stolen credentials to escalate privileges and move laterally before deploying encryption.
New CRITICAL Threat: Orkes Conductor Active Exploitation
A critical vulnerability in Orkes Conductor is currently being actively exploited in the wild, potentially allowing unauthorized actors to gain control over affected systems.
New HIGH Threat: X Money Launch Phishing Campaign
Following the launch of X Money, users are being flooded with fraudulent password reset emails, indicating a coordinated effort to facilitate account takeovers through social engineering.
New HIGH Threat: Google Pixel Improper Authorization Vulnerability (CVE-2026-58704)
An improper authorization vulnerability in Google Pixel devices that has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog.
New CRITICAL Threat: CVE-2026-70416
A critical vulnerability with a CVSS score of 10.0, identified as a high-priority target for exploitation in the wild.
New CRITICAL Threat: CVE-2026-73453
A critical vulnerability with a CVSS score of 10.0 that is currently being tracked as an active threat with high exploit probability.
Outdated OpenSSL Version Detected
Systems running OpenSSL versions vulnerable to CVE-2023-XXXX
New CRITICAL Threat: Orkes Conductor Active Exploitation
A critical vulnerability impacting Orkes Conductor that is currently being actively exploited in the wild, posing a significant risk of system compromise.
New CRITICAL Threat: CVE-2026-70416
A critical security flaw currently being tracked with high exploit probability, requiring urgent attention to prevent unauthorized system access.
New CRITICAL Threat: CVE-2026-73453
A critical vulnerability recently identified and added to the CISA Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild.
New CRITICAL Threat: Orkes Conductor Active Exploitation
A critical vulnerability impacting Orkes Conductor that is currently being actively exploited in the wild, as reported by security researchers.
New CRITICAL Threat: CVE-2026-70416
A critical vulnerability with a CVSS score of 10.0 that has been identified as actively exploited, requiring urgent attention for systems running affected vendor software.
New CRITICAL Threat: CVE-2026-73453
A critical vulnerability recently added to the CISA Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild.
Outdated OpenSSL Version Detected
Systems running OpenSSL versions vulnerable to CVE-2023-XXXX
Outdated OpenSSL Version Detected
Systems running OpenSSL versions vulnerable to CVE-2023-XXXX
New CRITICAL Threat: Orkes Conductor Active Exploitation
A critical vulnerability impacting Orkes Conductor that is currently being actively exploited in the wild, as reported by security researchers.
New CRITICAL Threat: CVE-2026-70416
A critical vulnerability with a CVSS score of 10.0 that has been flagged for immediate prioritization due to its inclusion in the CISA KEV catalog.
New CRITICAL Threat: CVE-2026-73453
A critical vulnerability recently identified and added to the CISA Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild.
New CRITICAL Threat: CVE-2026-75616
A command injection vulnerability in TP-Link Archer C20 routers that allows remote attackers to execute arbitrary commands, leading to full device compromise.
New CRITICAL Threat: CVE-2026-46817
A vulnerability in the Oracle Payments component of Oracle E-Business Suite that allows unauthenticated attackers to take over the application, potentially compromising financial data and payment workflows.
New CRITICAL Threat: CVE-2026-59310
A critical remote code execution (RCE) vulnerability in VMware vCenter that is currently being actively exploited by ransomware gangs to gain unauthorized access and deploy malicious payloads.
New CRITICAL Threat: StyleSmuggler (Magento/Adobe Commerce Zero-Day)
A zero-day exploit targeting Magento and Adobe Commerce platforms, currently being actively leveraged by threat actors to compromise e-commerce environments.
New CRITICAL Threat: CVE-2026-59310 (VMware vCenter RCE)
A critical Remote Code Execution vulnerability in VMware vCenter that is currently being actively exploited by ransomware gangs to compromise enterprise infrastructure.
New CRITICAL Threat: CVE-2026-86218 (N-central RCE)
A pre-authentication Remote Code Execution (RCE) vulnerability in N-able N-central software with a CVSS score of 10, allowing attackers to gain full control over affected MSP environments.
New HIGH Threat: TanStack npm Supply Chain Attack
A supply chain attack involving a compromised npm package that resulted in the unauthorized access and cloning of 170 private GitHub repositories.
New CRITICAL Threat: CVE-2026-70416
A critical vulnerability with a CVSS score of 10.0 that has been identified as a high-priority threat due to active exploitation and inclusion in the CISA KEV catalog.
New CRITICAL Threat: CVE-2026-73453
A critical vulnerability recently added to the CISA Known Exploited Vulnerabilities (KEV) catalog, indicating it is currently being actively exploited in the wild.
Unpatched Log4j Vulnerability
Critical Log4Shell vulnerability detected in application servers
New HIGH Threat: AI-Automated Phishing and Exploitation
Threat actors are increasingly utilizing AI models like Claude and DeepSeek to automate the development of sophisticated phishing campaigns and exploit code, significantly reducing the time required to launch attacks.
New CRITICAL Threat: CVE-2026-46817 (Oracle Payments)
A vulnerability in the Oracle Payments component of Oracle E-Business Suite that allows unauthenticated attackers to take over the application, potentially leading to the compromise of sensitive financial data and payment workflows.
New CRITICAL Threat: CVE-2026-59310 (VMware vCenter RCE)
A critical remote code execution vulnerability in VMware vCenter that is currently being actively exploited by ransomware gangs to gain unauthorized access and control over enterprise systems.
New HIGH Threat: StyleSmuggler (Adobe Commerce/Magento Zero-day)
A zero-day exploit targeting Adobe Commerce and Magento platforms, currently being actively exploited in the wild to compromise e-commerce environments.
New CRITICAL Threat: CVE-2026-59310 (VMware vCenter RCE)
A critical Remote Code Execution vulnerability in VMware vCenter that is currently being actively exploited by ransomware gangs to compromise enterprise infrastructure.
New CRITICAL Threat: CVE-2026-86218 (N-central RCE)
A pre-authentication Remote Code Execution (RCE) vulnerability in N-able N-central servers with a CVSS score of 10, allowing attackers to gain full control over MSP environments.
New CRITICAL Threat: Apache Log4j Remote Code Execution
An ongoing, highly prevalent threat where attackers attempt to exploit the Log4j logging library to execute arbitrary code on target servers, consistently appearing as a top threat in global telemetry.
New CRITICAL Threat: CVE-2026-46817 (Oracle Payments)
A vulnerability in the Oracle Payments component of Oracle E-Business Suite that allows unauthenticated attackers to take over the application, potentially leading to the theft of sensitive financial data and compromise of payment workflows.
New CRITICAL Threat: CVE-2026-59310 (VMware vCenter RCE)
A critical remote code execution vulnerability in VMware vCenter that is currently being actively exploited by ransomware gangs to gain unauthorized access and control over virtualized environments.
New CRITICAL Threat: CVE-2026-75616 (TP-Link Archer C20 Command Injection)
A command injection vulnerability in TP-Link Archer C20 routers that allows attackers to execute arbitrary commands, potentially leading to full device compromise.
New CRITICAL Threat: CVE-2026-46817 (Oracle Payments)
A vulnerability in the Oracle Payments component of Oracle E-Business Suite that allows unauthenticated attackers to take over the application, potentially compromising financial data and payment workflows.
New CRITICAL Threat: CVE-2026-59310 (VMware vCenter RCE)
A critical remote code execution vulnerability in VMware vCenter that is currently being actively exploited by ransomware gangs to gain unauthorized access and control over enterprise systems.
Outdated OpenSSL Version Detected
Systems running OpenSSL versions vulnerable to CVE-2023-XXXX
New CRITICAL Threat: StyleSmuggler (Magento/Adobe Commerce Zero-Day)
A zero-day exploit targeting Magento and Adobe Commerce platforms, currently being actively leveraged by threat actors to compromise e-commerce environments.
New CRITICAL Threat: CVE-2026-86218 (N-central RCE)
A pre-authentication remote code execution vulnerability in N-able N-central servers that allows attackers to gain full control over affected MSP environments.
New CRITICAL Threat: CVE-2026-59310 (VMware vCenter RCE)
A critical remote code execution vulnerability in VMware vCenter that is currently being actively exploited by ransomware gangs to compromise systems.
New HIGH Threat: Echelon Stealer
An active infostealer malware distributed as an open-source tool on GitHub, designed to exfiltrate sensitive user data and credentials from infected systems.
New CRITICAL Threat: CVE-2026-75616 (TP-Link Archer C20 Command Injection)
A command injection vulnerability in TP-Link Archer C20 routers that allows remote attackers to execute arbitrary commands, potentially leading to full device compromise.
New CRITICAL Threat: CVE-2026-59310 (VMware vCenter RCE)
A critical remote code execution vulnerability in VMware vCenter that is currently being actively exploited by ransomware gangs to gain unauthorized access and deploy malicious payloads.
Outdated OpenSSL Version Detected
Systems running OpenSSL versions vulnerable to CVE-2023-XXXX
New HIGH Threat: CVE-2026-75616 (TP-Link Archer C20 Command Injection)
A command injection vulnerability in TP-Link Archer C20 routers that allows unauthenticated attackers to execute arbitrary commands, potentially leading to full device compromise.
New CRITICAL Threat: Apache Log4j Remote Code Execution
An ongoing, highly prevalent exploit targeting the Log4j logging library, allowing attackers to execute arbitrary code on vulnerable servers. It remains one of the most active threats globally.
New CRITICAL Threat: CVE-2026-59310 (VMware vCenter RCE)
A critical remote code execution vulnerability in VMware vCenter that is currently being actively exploited by ransomware gangs to gain unauthorized access and control over enterprise systems.
New CRITICAL Threat: Apache Log4j Remote Code Execution
An active, high-volume threat involving the exploitation of the Apache Log4j library, allowing attackers to execute arbitrary code remotely on vulnerable systems.
New CRITICAL Threat: miniOrange OAuth SSO Authentication Bypass (CVE-2026-57807)
An authentication bypass vulnerability in the miniOrange OAuth Single Sign On (SSO) plugin allows remote, unauthenticated attackers to compromise systems, steal data, or install malware.
New CRITICAL Threat: PyAthena SQL Injection (CVE-2026-65321)
A vulnerability in PyAthena versions prior to 3.35.4 allows unauthenticated attackers to perform SQL injection attacks due to improper quote escaping in the DefaultParameterFormatter.
Unpatched Log4j Vulnerability
Critical Log4Shell vulnerability detected in application servers
New CRITICAL Threat: CVE-2026-65321
An unauthenticated SQL injection vulnerability in PyAthena (prior to version 3.35.4) caused by improper quote escaping, allowing attackers to inject arbitrary SQL commands.
New CRITICAL Threat: CVE-2026-59310
A critical Remote Code Execution (RCE) vulnerability in VMware vCenter that is currently being actively exploited by ransomware gangs to gain unauthorized access.
New CRITICAL Threat: CVE-2026-85046
A type confusion flaw within Google Chromium's V8 JavaScript engine that allows for arbitrary code execution within the context of the sandboxed renderer process.
New CRITICAL Threat: Apache.Log4j.Error.Log.Remote.Code.Execution
A persistent and highly prevalent remote code execution exploit targeting the Log4j logging library, which continues to see massive volumes of daily exploitation attempts.
New CRITICAL Threat: CVE-2026-85046
A type confusion flaw in Google Chromium's V8 JavaScript engine that is currently being actively exploited in the wild, potentially leading to arbitrary code execution.
New CRITICAL Threat: CVE-2026-65321
An unauthenticated SQL injection vulnerability in PyAthena (prior to 3.35.4) caused by improper quote escaping, allowing attackers to inject arbitrary SQL commands.
New CRITICAL Threat: Apache Log4j Remote Code Execution
An ongoing, highly prevalent threat involving the exploitation of the Apache Log4j library, allowing attackers to execute arbitrary code remotely on vulnerable servers.
New CRITICAL Threat: CVE-2026-57807 (miniOrange OAuth SSO Authentication Bypass)
An authentication bypass vulnerability in the miniOrange OAuth Single Sign-On (SSO) plugin allows remote, unauthenticated attackers to compromise systems, potentially leading to data theft or malware installation.
New CRITICAL Threat: CVE-2026-65321 (PyAthena SQL Injection)
A critical SQL injection vulnerability in PyAthena (prior to version 3.35.4) allows unauthenticated attackers to inject arbitrary SQL commands due to improper quote escaping.
New CRITICAL Threat: CVE-2026-75616 (TP-Link Archer C20 Command Injection)
A command injection vulnerability in TP-Link Archer C20 routers that allows remote attackers to execute arbitrary system commands, potentially leading to full device compromise.
New CRITICAL Threat: CVE-2026-57807 (miniOrange OAuth SSO)
An authentication bypass vulnerability in the miniOrange OAuth Single Sign-On plugin that allows unauthenticated remote attackers to compromise systems, steal data, or install malware.