■ HIGH2026-08-27
Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2019-1068
■ HIGH2026-08-27
Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the…
CVE-2026-8452
■ HIGH2026-08-27
Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
CVE-2021-23758
◆ CRITICAL2026-08-27
Fortinet Vulnerability CVE-2026-35616 and EKZ Stealer, Attacking Obfuscating Compilers…
◈ CHOKEPOINT T1190 Exploit Public-Facing Application
EKZ StealerEnergyCVE-2026-35616
◆ CRITICAL2026-08-27
Dark Caracal Reloaded: New Malware, Same Hunting Grounds
◈ CHOKEPOINT T1547.001 Registry Run Keys / Startup Folder
Dark CaracalGoCaracalBrazilChile
◆ CRITICAL2026-08-26
CVE-2026-79675: NLTK before 3.10.3 fails to validate JVM options passed through the…
CVE-2026-79675
◆ CRITICAL2026-08-26
CVE-2026-16286: Unrestricted upload of file with dangerous type vulnerability in TRtek…
CVE-2026-16286
◆ CRITICAL2026-08-26
CVE-2026-78570: The Total Donations plugin for WordPress is vulnerable to Privilege…
CVE-2026-78570
◆ CRITICAL2026-08-26
CVE-2026-78676: GitPython before 3.1.59 fails to safely re-serialize multi-line…
CVE-2026-78676
■ HIGH2026-08-26
Gitea Code Injection Vulnerability
CVE-2026-60004
◆ CRITICAL2026-08-25
CVE-2026-56705: Adminer before 5.4.3 fails to sanitize the server field before…
CVE-2026-56705
◆ CRITICAL2026-08-25
CVE-2026-71933: Multiple DrayTek VigorSwitch models contain unauthorized operation…
CVE-2026-71933
◆ CRITICAL2026-08-25
CVE-2026-71921: Multiple DrayTek VigorSwitch models contain a pre-authentication command…
CVE-2026-71921
◆ CRITICAL2026-08-25
CVE-2026-76071: Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer…
CVE-2026-76071
■ HIGH2026-08-25
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control…
CVE-2026-21962
◆ CRITICAL2026-08-24
CVE-2026-78168: A security vulnerability has been detected in EFM ipTIME T24000M up to…
CVE-2026-78168
◆ CRITICAL2026-08-24
CVE-2026-78167: A weakness has been identified in EFM ipTIME T16000M 14.20.2
CVE-2026-78167
◆ CRITICAL2026-08-24
CVE-2026-7808: justhtml before 1.16.0 contains multiple HTML sanitization bypass issues…
CVE-2026-7808
◆ CRITICAL2026-08-24
CVE-2026-5388: justhtml before 1.15.0 contains multiple security issues in URL…
CVE-2026-5388
◆ CRITICAL2026-08-24
CVE-2026-78050: A vulnerability was found in Comfast CF-N1-S
CVE-2026-78050
◆ CRITICAL2026-08-23
CVE-2026-4703: The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress…
CVE-2026-4703
◆ CRITICAL2026-08-23
CVE-2026-77946: A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05
CVE-2026-77946
■ HIGH2026-08-23
Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
CVE-2026-73570
◆ CRITICAL2026-08-23
Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia
◈ CHOKEPOINT T1566.002 Spearphishing Link
KimsukyJapan
◆ CRITICAL2026-08-23
Head Mare APT Group exploits vulnerabilities in unpatched TrueConf server to deliver…
◈ CHOKEPOINT T1078 Valid Accounts
Head MarePhantomCore
◆ CRITICAL2026-08-21
CVE-2026-16926: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote…
CVE-2026-16926
◆ CRITICAL2026-08-21
CVE-2026-76590: A vulnerability was identified in TRENDnet TEW-755AP up to 20260702
CVE-2026-76590
◆ CRITICAL2026-08-21
CVE-2026-76589: A vulnerability was found in TRENDnet TEW-755AP up to 20260702
CVE-2026-76589
■ HIGH2026-08-21
TrueConf Server Missing Authentication for Critical Function Vulnerability
CVE-2026-72529
■ HIGH2026-08-21
TrueConf Server Code Injection Vulnerability
CVE-2026-72530
◆ CRITICAL2026-08-20
CVE-2026-60720: Vulnerability in the Oracle Identity Manager product of Oracle Fusion…
CVE-2026-60720
◆ CRITICAL2026-08-20
CVE-2026-60591: Vulnerability in the Oracle Hospitality Simphony product of Oracle Food…
CVE-2026-60591
◆ CRITICAL2026-08-20
CVE-2026-75913: CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64…
CVE-2026-75913
■ HIGH2026-08-20
MLflow Server-Side Request Forgery Vulnerability
CVE-2026-64849
◆ CRITICAL2026-08-20
MacSync Stealer
◈ CHOKEPOINT T1555.003 Credentials from Web Browsers
mentalpositiveMacSync Stealer
◆ CRITICAL2026-08-19
CVE-2026-60696: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion…
CVE-2026-60696
◆ CRITICAL2026-08-19
CVE-2026-60672: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion…
CVE-2026-60672
◆ CRITICAL2026-08-19
CVE-2026-75784: A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01
CVE-2026-75784
◆ CRITICAL2026-08-19
Fraudulent Employment Operations
◈ CHOKEPOINT T1078 Valid Accounts
PurpleDeltaTechnologyHealthcare
◆ CRITICAL2026-08-19
Clop Returns with Custom Implant in Mass-Extortion Campaign
◈ CHOKEPOINT T1078 Valid Accounts
ClopDEWMODEManufacturingCVE-2023-34362
◆ CRITICAL2026-08-18
CVE-2026-71472: A flaw was found in acm-search-v2-rhel9
CVE-2026-71472
■ HIGH2026-08-18
Apple macOS Improper Authentication Vulnerability
CVE-2026-65400
■ HIGH2026-08-18
Microsoft SharePoint Weak Authentication Vulnerability
CVE-2026-55040
■ HIGH2026-08-18
Broadcom VMware vCenter Path Traversal Vulnerability
CVE-2026-59310
■ HIGH2026-08-18
Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
CVE-2026-33824
◆ CRITICAL2026-08-17
CVE-2026-16098: The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary…
CVE-2026-16098
◆ CRITICAL2026-08-17
CVE-2026-19924: A security vulnerability has been detected in Tenda AC10…
CVE-2026-19924
■ HIGH2026-08-17
Ray-Project Ray Code Injection Vulnerability
CVE-2025-62593
◆ CRITICAL2026-08-17
UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise…
◈ CHOKEPOINT T1566 Phishing
UNC6671FinanceTechnology
◆ CRITICAL2026-08-17
New Mirai-Based Linux Botnet 'Evooo1Bot' Turns Victims Into Proxies
◈ CHOKEPOINT T1059 Command and Scripting Interpreter
Evooo1BotCVE-2007-3010
◆ CRITICAL2026-08-15
CVE-2026-17182: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to…
CVE-2026-17182
◆ CRITICAL2026-08-15
CVE-2026-17181: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to…
CVE-2026-17181
◆ CRITICAL2026-08-15
CVE-2026-73678: MindsDB Minds Platform version 26.1.0 and earlier contains an…
CVE-2026-73678
◆ CRITICAL2026-08-15
CVE-2026-17482: IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote…
CVE-2026-17482
◆ CRITICAL2026-08-15
New Armored Likho tools target Telegram and eavesdropping
◈ CHOKEPOINT T1078 Valid Accounts
Armored LikhoStill SyncGovernmentIT
◆ CRITICAL2026-08-13
CVE-2026-73532: Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability…
CVE-2026-73532
◆ CRITICAL2026-08-13
CVE-2026-53791: rsync daemon before 3.5.0 contains an IP address spoofing vulnerability…
CVE-2026-53791
◆ CRITICAL2026-08-13
CVE-2026-17276: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker…
CVE-2026-17276
◆ CRITICAL2026-08-13
CVE-2026-16860: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker…
CVE-2026-16860
◆ CRITICAL2026-08-13
China-based hackers-for-hire group staging espionage attacks alongside a cryptocurrency…
◈ CHOKEPOINT T1195 Supply Chain Compromise
REF7707AntinoUnited States of AmericaGovernment
◆ CRITICAL2026-08-13
CVE-2026-73268: A flaw was found in the cluster-curator-controller component of…
CVE-2026-73268
■ HIGH2026-08-13
Inside a Ukrainian IP Camera Toolkit
◈ CHOKEPOINT T1190 Exploit Public-Facing Application
AustriaBulgariaCVE-2021-33044
◆ CRITICAL2026-08-13
Cl0p Ransomware: Attack Pattern in Threat Intelligence
◈ CHOKEPOINT T1505.003 Web Shell
Cl0pLEMURLOOTCVE-2023-34362
◆ CRITICAL2026-08-13
Hits Safe Mode: Ransomware Rebooting Around EDR
◈ CHOKEPOINT T1078 Valid Accounts
Storm-1567Akira
■ HIGH2026-08-13
State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit
◈ CHOKEPOINT T1078 Valid Accounts
LazarusMISTPENBrazilBritish Indian Ocean TerritoryCVE-2025-49113
◆ CRITICAL2026-08-12
CVE-2026-72508: A flaw was found in the multicloud-operators-subscription component of…
CVE-2026-72508
◆ CRITICAL2026-08-12
CVE-2026-17083: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute…
CVE-2026-17083
◆ CRITICAL2026-08-12
CVE-2026-73034: DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability…
CVE-2026-73034
◆ CRITICAL2026-08-12
CVE-2026-73032: PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability…
CVE-2026-73032
■ HIGH2026-08-12
How the ErrTraffic Malware Campaign Uses ClickFix and EtherHiding
◈ CHOKEPOINT T1547.001 Registry Run Keys / Startup Folder
VidarCVE-2026-48294
◆ CRITICAL2026-08-12
CVE-2026-71398: Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization…
CVE-2026-71398
◆ CRITICAL2026-08-12
CVE-2026-69102: MaxKey contains an unauthorized access vulnerability due to a hard-coded…
CVE-2026-69102
◆ CRITICAL2026-08-12
CVE-2026-27302: Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization…
CVE-2026-27302
◆ CRITICAL2026-08-12
Tracking Shai-Hulud: Inside the ChainDrop NPM Worm
◈ CHOKEPOINT T1554 Compromise Host Software Binary
TeamPCPChainDropTechnology
◆ CRITICAL2026-08-12
Shattering the Dream - When a Job Offer Becomes a Zero-Day Attack
◈ CHOKEPOINT T1566.001 Spearphishing Attachment
LazarusFudModuleDefenseAerospaceCVE-2026-68820
◆ CRITICAL2026-08-11
CVE-2026-58115: A vulnerability has been identified in SIMATIC IoT2050 Advanced…
CVE-2026-58115
◆ CRITICAL2026-08-11
CVE-2026-19425: Travel Agency Management System developed by Win Men Intermational has a…
CVE-2026-19425
■ HIGH2026-08-11
Metabase SQL Injection Vulnerability
CVE-2026-72898
■ HIGH2026-08-11
Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
CVE-2026-68820
■ HIGH2026-08-11
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat…
CVE-2026-20349
◆ CRITICAL2026-08-11
CVE-2026-44758: SAP Manufacturing Integration and Intelligence (MII) allows an attacker…
CVE-2026-44758
◆ CRITICAL2026-08-11
CVE-2026-34265: SAP NetWeaver Application Server ABAP allows an unauthenticated attacker…
CVE-2026-34265
◆ CRITICAL2026-08-11
CVE-2026-14450: A flaw was found in the MaaS API
CVE-2026-14450
◆ CRITICAL2026-08-11
The Permanent Threat: Analyzing Blockchain-Based C2 Operations and Communications
◈ CHOKEPOINT T1547.001 Registry Run Keys / Startup Folder
LenAIAeternum
◆ CRITICAL2026-08-11
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery…
◈ CHOKEPOINT T1112 Modify Registry
DeadLockDeadLockTechnologyMining
◆ CRITICAL2026-08-10
CVE-2026-63106: ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection…
CVE-2026-63106
◆ CRITICAL2026-08-10
CVE-2026-19348: A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi…
CVE-2026-19348
◆ CRITICAL2026-08-10
CVE-2026-71993: MSI Radix AXE6600 router firmware version v781521 contains a command…
CVE-2026-71993
◆ CRITICAL2026-08-10
Integrating AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM
◈ CHOKEPOINT T1566.001 Spearphishing Attachment
KimsukyAsyncRATGovernmentDefense
◆ CRITICAL2026-08-10
Powercat malware campaign: Fake game cheats deliver infostealer
◈ CHOKEPOINT T1555.003 Credentials from Web Browsers
Powercat
◆ CRITICAL2026-08-10
CVE-2026-71992: MSI Radix AXE6600 router firmware version v781521 contains a command…
CVE-2026-71992
◆ CRITICAL2026-08-10
CVE-2026-71991: MSI Radix AXE6600 router firmware version v781521 contains a command…
CVE-2026-71991
◆ CRITICAL2026-08-10
CVE-2026-71990: MSI Radix AXE6600 router firmware version v781521 contains a command…
CVE-2026-71990
◆ CRITICAL2026-08-10
CVE-2026-71989: MSI Radix AXE6600 router firmware version v781521 contains a command…
CVE-2026-71989
◆ CRITICAL2026-08-10
CVE-2026-71988: MSI Radix AXE6600 router firmware version v781521 contains a command…
CVE-2026-71988
◆ CRITICAL2026-08-09
CVE-2026-71987: MSI Radix AXE6600 router firmware version v781521 contains a command…
CVE-2026-71987
◆ CRITICAL2026-08-09
CVE-2026-71986: MSI Radix AXE6600 router firmware version v781521 contains a command…
CVE-2026-71986
◆ CRITICAL2026-08-09
CVE-2026-71985: MSI Radix AXE6600 router firmware version v781521 contains a command…
CVE-2026-71985
◆ CRITICAL2026-08-09
CVE-2026-71984: MSI Radix AXE6600 router firmware version v781521 contains a command…
CVE-2026-71984
◆ CRITICAL2026-08-09
CVE-2026-71983: MSI Radix AXE6600 router firmware version v781521 contains a command…
CVE-2026-71983
◆ CRITICAL2026-08-08
CVE-2026-71958: D-Link DWR-M961 devices with hardware version C1 and software version…
CVE-2026-71958
◆ CRITICAL2026-08-08
CVE-2026-71957: D-Link DWR-M961 devices with hardware version C1 and software version…
CVE-2026-71957
◆ CRITICAL2026-08-08
CVE-2026-71956: D-Link DWR-M961 devices with hardware version C1 and software version…
CVE-2026-71956
◆ CRITICAL2026-08-08
CVE-2026-71944: D-Link DWR-M961 devices with hardware version C1 and firmware version…
CVE-2026-71944
■ HIGH2026-08-08
QuickFox Supply Chain Attack Used to Deploy FDMTP Implant
◈ CHOKEPOINT T1112 Modify Registry
FDMTP
◆ CRITICAL2026-08-08
CVE-2026-14526: The AI Copilot – Content Generator plugin for WordPress is vulnerable to…
CVE-2026-14526
■ HIGH2026-08-08
CVE-2026-56793: Dell OpenManage Server Administrator, versions prior to , contains an…
CVE-2026-56793
■ HIGH2026-08-08
CVE-2026-62836: Improper restriction of communication channel to intended endpoints in…
CVE-2026-62836
■ HIGH2026-08-08
ScreenConnect RMM Abuse, Cloudflare Tunnels, and Trusted Software Lures Threat…
◈ CHOKEPOINT T1566.002 Spearphishing Link
ConnectWise
■ HIGH2026-08-08
Phishing Email Delivers ScreenConnect Malware
◈ CHOKEPOINT T1112 Modify Registry
ScreenConnectFinance
◆ CRITICAL2026-08-07
CVE-2026-54489: Dell Virtual Storage Integrator for VMware vSphere Client, versions prior…
CVE-2026-54489
■ HIGH2026-08-07
Progress LoadMaster Command Injection Vulnerability
CVE-2026-8037
■ HIGH2026-08-07
Payroll Pirates: Strange New Tides in Business Email Compromise
◈ CHOKEPOINT T1566.002 Spearphishing Link
Storm-2755United States of AmericaCanada
◆ CRITICAL2026-08-07
Dissecting Vanta Stealer, a Python-Based Cross-Platform Information Theft Malware
◈ CHOKEPOINT T1555 Credentials from Password Stores
Vanta Stealer
◆ CRITICAL2026-08-07
Inside a Self-Propagating npm Worm
◈ CHOKEPOINT T1195.002 Compromise Software Supply Chain
ChainDropTechnology
◆ CRITICAL2026-08-07
CVE-2026-62830: Missing authorization in Azure SRE Agent allows an authorized attacker to…
CVE-2026-62830
◆ CRITICAL2026-08-07
CVE-2026-50515: Deserialization of untrusted data in Azure Service Bus allows an…
CVE-2026-50515
◆ CRITICAL2026-08-07
CVE-2026-70558: Dinky's POST /download/uploadFromRsByLocal handler passes the…
CVE-2026-70558
◆ CRITICAL2026-08-07
CVE-2026-67622: Flowise through 3.1.4 contains an insecure direct object reference…
CVE-2026-67622
◆ CRITICAL2026-08-07
CVE-2026-53984: Ground Station prior to 0.6.0 contains an unauthenticated…
CVE-2026-53984
◆ CRITICAL2026-08-06
ChainDrop npm Attack Compromises Hundreds of Packages
◈ CHOKEPOINT T1078 Valid Accounts
ChainDropTechnology
◆ CRITICAL2026-08-06
Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums
◈ CHOKEPOINT T1112 Modify Registry
Powercat
◆ CRITICAL2026-08-06
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide
◈ CHOKEPOINT T1566 Phishing
MacSync
◆ CRITICAL2026-08-06
Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases
◈ CHOKEPOINT T1547.001 Registry Run Keys / Startup Folder
Larva-26005XctdoorDefenseTechnologyCVE-2017-8291
◆ CRITICAL2026-08-06
Token Jacking: Cybercriminals Could Be Stealing Your AI Resources
◈ CHOKEPOINT T1199 Trusted Relationship
Shai-Hulud
◆ CRITICAL2026-08-06
ChainDrop: The Mini Shai Hulud npm worm's latest wave hits keyv and cacheable
◈ CHOKEPOINT T1078 Valid Accounts
ChainDropTechnology
◆ CRITICAL2026-08-06
Reversing a Windows Kernel Driver Rootkit
◈ CHOKEPOINT T1112 Modify Registry
SakDriver
◆ CRITICAL2026-08-06
Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages
◈ CHOKEPOINT T1195.002 Compromise Software Supply Chain
Shai-HuludCHAINDROPTechnology
■ HIGH2026-08-06
ENDLESSDOORS Is Phoning Home. Pick Up
◈ CHOKEPOINT T1205.001 Port Knocking
ENDLESSDOORSCVE-2026-66747
■ HIGH2026-08-06
Authentication Bypass Vulnerability in N-central Exploited In-The-Wild
◈ CHOKEPOINT T1190 Exploit Public-Facing Application
CVE-2026-18577
◆ CRITICAL2026-08-05
CVE-2026-70615: boringproxy through 0.10.0 contains a newline injection vulnerability…
CVE-2026-70615
■ HIGH2026-08-05
JetBrains TeamCity Deserialization of Untrusted Data Vulnerability
CVE-2026-63077
◆ CRITICAL2026-08-05
Almost Half of Malware Samples Communicate Direct to IP
◈ CHOKEPOINT T1059 Command and Scripting Interpreter
PhorpiexEducationGovernment
■ HIGH2026-08-05
ClickFix-Themed Campaign Deploys Starland RAT and WLDR Framework
◈ CHOKEPOINT T1547.001 Registry Run Keys / Startup Folder
UAT-11795Starland RATUnited States of AmericaGermany
■ HIGH2026-08-05
The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart…
◈ CHOKEPOINT T1136.001 Local Account
The GentlemenEtherRAT
■ HIGH2026-08-05
IBM Langflow Code Injection Vulnerability
CVE-2026-9198
■ HIGH2026-08-05
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
CVE-2026-34486
◆ CRITICAL2026-08-05
Analysis of a Phishing Email Attack Case
◈ CHOKEPOINT T1136.001 Local Account
Larva-24009QuasarRATHealthcare
◆ CRITICAL2026-08-05
NightLedger Backdoor Deployed in Espionage Campaign Targeting the Middle East and Africa
◈ CHOKEPOINT T1059 Command and Scripting Interpreter
Mirage KittenNightLedgerEgyptJordan
■ HIGH2026-08-05
Security Update – August 2, 2026
◈ CHOKEPOINT T1078 Valid Accounts
CVE-2026-18577
◆ CRITICAL2026-08-04
CVE-2026-61514: Puwell IP Camera firmware versions 2.x through 4.x contains an…
CVE-2026-61514
◆ CRITICAL2026-08-04
CVE-2026-48330: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of…
CVE-2026-48330
◆ CRITICAL2026-08-04
CVE-2026-48323: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of…
CVE-2026-48323
◆ CRITICAL2026-08-04
CVE-2026-18684: A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5
CVE-2026-18684
◆ CRITICAL2026-08-04
CVE-2026-18616: A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5
CVE-2026-18616
◆ CRITICAL2026-08-04
CVE-2026-18614: A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5
CVE-2026-18614
◆ CRITICAL2026-08-04
CVE-2026-41452: Krayin CRM 2.2.4 contains a missing authentication vulnerability in the…
CVE-2026-41452
◆ CRITICAL2026-08-04
CVE-2026-39932: OpenEMR through 8.2.0 contains a remote code execution vulnerability in…
CVE-2026-39932
◆ CRITICAL2026-08-04
CVE-2026-18602: A vulnerability was determined in GL.iNet GL-MT3000 up to 4.4.5
CVE-2026-18602
■ HIGH2026-08-04
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
CVE-2026-18577
◆ CRITICAL2026-08-03
CVE-2026-69083: SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in…
CVE-2026-69083
◆ CRITICAL2026-08-03
CVE-2026-64827: Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and…
CVE-2026-64827
◆ CRITICAL2026-08-03
CVE-2026-18601: A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5
CVE-2026-18601
◆ CRITICAL2026-08-03
CVE-2026-18589: A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628
CVE-2026-18589
◆ CRITICAL2026-08-03
CVE-2026-18588: A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7628
CVE-2026-18588
◆ CRITICAL2026-08-03
CVE-2026-65321: PyAthena prior to 3.35.4 contains a sql injection vulnerability that…
CVE-2026-65321
◆ CRITICAL2026-08-03
CVE-2026-68579: FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow…
CVE-2026-68579
◆ CRITICAL2026-08-03
CVE-2026-8457: The WooCommerce - Social Login plugin for WordPress is vulnerable to…
CVE-2026-8457
◆ CRITICAL2026-08-03
CVE-2026-67342: ArcadeDB versions before 26.7.2 contain an authorization bypass…
CVE-2026-67342
■ HIGH2026-08-03
A China-Nexus Campaign Against Government Infrastructure
◈ CHOKEPOINT T1505.003 Web Shell
China-nexusGOCSCVE-2025-24813
◆ CRITICAL2026-08-02
CVE-2026-67341: ArcadeDB versions before 26.7.2 fail to enforce scripting authorization…
CVE-2026-67341
◆ CRITICAL2026-08-02
CVE-2026-67340: ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look…
CVE-2026-67340
◆ CRITICAL2026-08-02
CVE-2026-67330: @better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27…
CVE-2026-67330
◆ CRITICAL2026-08-02
CVE-2026-67324: GitPython 3.1.50 fails to recognize joined short-option forms such as…
CVE-2026-67324
◆ CRITICAL2026-08-02
CVE-2026-67289: FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate…
CVE-2026-67289
◆ CRITICAL2026-08-02
CVE-2026-66402: FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS…
CVE-2026-66402
◆ CRITICAL2026-08-02
CVE-2026-15964: The Single Sign On For TNG plugin for WordPress is vulnerable to…
CVE-2026-15964
◆ CRITICAL2026-08-02
CVE-2026-3141: The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary…
CVE-2026-3141
◆ CRITICAL2026-08-02
CVE-2026-68771: ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the…
CVE-2026-68771
◆ CRITICAL2026-08-02
CVE-2026-68770: sentence-transformers contains a security control bypass vulnerability…
CVE-2026-68770
■ HIGH2026-08-01
Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
CVE-2026-16812
■ HIGH2026-08-01
Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
CVE-2025-68686
■ HIGH2026-08-01
Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
CVE-2026-20316
■ LOW2026-07-31
Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique
◈ CHOKEPOINT T1566 Phishing
InfernoGrabber
■ LOW2026-07-31
RedHook Returns with a Dangerous Upgrade
◈ CHOKEPOINT T1078 Valid Accounts
RedHookIndonesiaFinance
■ LOW2026-07-31
Threat Spotlight: The Jalisco Toolkit and AI-Powered Phishing Surge
◈ CHOKEPOINT T1566 Phishing
Jalisco
■ MODERATE2026-07-31
Phantom Stealer Unmasked: Shellcode, Steganography, and Credential Theft
◈ CHOKEPOINT T1112 Modify Registry
Phantom Stealer
■ HIGH2026-07-31
Reverse Engineering the Six Stages of MacSync Stealer and RAT
◈ CHOKEPOINT T1059.002 AppleScript
MacSync
◆ CRITICAL2026-07-31
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit
◈ CHOKEPOINT T1547.001 Registry Run Keys / Startup Folder
TA488OWAReaperGovernmentTelecommunicationsCVE-2026-42897
◆ CRITICAL2026-07-31
Toy Ghouls’ new toy: the GenieLocker ransomware
◈ CHOKEPOINT T1078 Valid Accounts
Toy GhoulsGenieLockerRussian FederationManufacturing
◆ CRITICAL2026-07-31
XMRig Covert Ops: The Cryptomining Campaign That Abuses Trusted Access and Deploys…
◈ CHOKEPOINT T1078 Valid Accounts
XMRig
■ HIGH2026-07-31
OctLurk and SilkLurk: new Backdoors in Central Asia
◈ CHOKEPOINT T1059.001 PowerShell
OctLurkAfghanistanKazakhstan
■ HIGH2026-07-31
Tax Season, Open Season: Phishing and Malware Campaigns Targeting Indian Taxpayers
◈ CHOKEPOINT T1566.001 Spearphishing Attachment
British Indian Ocean TerritoryIndia
■ MODERATE2026-07-30
Blacksite: New AiTM Phishing Kit Evades URL Scanners via Cloaked.gg
◈ CHOKEPOINT T1566 Phishing
kirapayloadBlacksiteFinanceTechnology
■ LOW2026-07-30
PamStealer: a Rust-based macOS infostealer that validates credentials through PAM
◈ CHOKEPOINT T1078 Valid Accounts
PamStealer
■ HIGH2026-07-30
ClickFix Deno Abuse to CastleRAT
◈ CHOKEPOINT T1190 Exploit Public-Facing Application
no tags
■ LOW2026-07-30
The Scam Will Go On: Beware of Fake Offers for Celine Dion Concert Tickets
◈ CHOKEPOINT T1190 Exploit Public-Facing Application
FranceMedia
■ MODERATE2026-07-30
Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform…
◈ CHOKEPOINT T1204 User Execution
Flying EagleChinaThailand
■ LOW2026-07-30
Latest goon squad to use fake helpdesk calls to steal creds
◈ CHOKEPOINT T1078 Valid Accounts
Pink
■ MODERATE2026-07-30
Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms
◈ CHOKEPOINT T1091 Replication Through Removable Media
UNC3753LOCKBIT.BLACKUnited States of AmericaFinance
■ MODERATE2026-07-30
Phishing in the Balkans: Fake Traffic Fines, Real Losses
◈ CHOKEPOINT T1566 Phishing
SerbiaGovernment
◆ CRITICAL2026-07-30
Bundled to Steal: The Salat Stealer Campaign
◈ CHOKEPOINT T1078 Valid Accounts
Salat Stealer
■ HIGH2026-07-30
Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan
◈ CHOKEPOINT T1195.002 Compromise Software Supply Chain
DEV#POPPERTechnology
◆ CRITICAL2026-07-29
Shai-Hulud-Style npm Worm Hits
◈ CHOKEPOINT T1098 Account Manipulation
Shai-HuludTechnology
◆ CRITICAL2026-07-29
Distributed npm Package Cluster Delivers Cross-Platform RAT Targeting Alibaba Developers
◈ CHOKEPOINT T1547.001 Registry Run Keys / Startup Folder
lib-mtopTechnologyCVE-2026-41940
◆ CRITICAL2026-07-29
ClickFix Keeps Evolving: Rundll32 Ordinal Execution over WebDAV
◈ CHOKEPOINT T1112 Modify Registry
ClearFake
◆ CRITICAL2026-07-29
Botnet Rising Star: The Evolution and In-Depth Technical Analysis of Dysphoria
◈ CHOKEPOINT T1190 Exploit Public-Facing Application
DysphoriaChinaTechnologyCVE-2020-25499
■ LOW2026-07-29
One Email Closer to the Edge: UNK_MassTraction & the Physics of Exploitation
◈ CHOKEPOINT T1190 Exploit Public-Facing Application
UNK_MassTractionIceCubeUnited States of AmericaCanadaCVE-2024-42009
◆ CRITICAL2026-07-29
Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps
◈ CHOKEPOINT T1195 Supply Chain Compromise
no tags
■ MODERATE2026-07-29
Phishers Abuse Business Account Manager Service
◈ CHOKEPOINT T1566 Phishing
TechnologyMedia
■ LOW2026-07-29
What Is the BabaDeda Loader? Analysis of a New ClickFix Malware Campaign
◈ CHOKEPOINT T1078 Valid Accounts
Arechclient2
■ MODERATE2026-07-29
AI-Native security platform
◈ CHOKEPOINT T1190 Exploit Public-Facing Application
no tags
◆ CRITICAL2026-07-28
Phishing on the Edge of the Web and Mobile Using QR Codes
◈ CHOKEPOINT T1199 Trusted Relationship
NagaPocker.apkUkraineFinancial
■ HIGH2026-07-28
Expanding the Castle: New Campaigns, New Tooling, and the NeedleStealer Connection
◈ CHOKEPOINT T1566 Phishing
CastleLoader
■ HIGH2026-07-28
Technical Advisory: wp2shell — Unauthenticated Remote Code Execution and Full Site…
◈ CHOKEPOINT T1136.001 Local Account
CVE-2026-60137
◆ CRITICAL2026-07-28
Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor
◈ CHOKEPOINT T1547.001 Registry Run Keys / Startup Folder
GoGRPC
◆ CRITICAL2026-07-28
Mirage Kitten targets Middle East and Africa region with new malware
◈ CHOKEPOINT T1547.001 Registry Run Keys / Startup Folder
Mirage KittenNightLedgerBurkina FasoEgypt
■ LOW2026-07-28
SilabRAT, What's Your Power?
◈ CHOKEPOINT T1078 Valid Accounts
o1oo1SilabRAT
■ LOW2026-07-28
Sniper's Nest: From Brand Impersonation to Browser Hijacking and CPA Fraud
◈ CHOKEPOINT T1566 Phishing
SniperDzAlgeriaFinance
■ HIGH2026-07-28
Threat Actors Achieve Persistence After SQL Injection
◈ CHOKEPOINT T1190 Exploit Public-Facing Application
BadIISTechnology
■ LOW2026-07-28
Defending SaaS-based applications against ShinyHunters OAuth abuse
◈ CHOKEPOINT T1195 Supply Chain Compromise
ShinyHuntersRetailEducation
■ MODERATE2026-07-28
CrashStealer: C++ macOS Infostealer Posing as Crash Reporter
◈ CHOKEPOINT T1190 Exploit Public-Facing Application
CrashStealer
■ MODERATE2026-07-27
Operation ShadowRecruit: A Recruitment-Themed Malware Campaign Leveraging ControlR and…
◈ CHOKEPOINT T1197 BITS Jobs
Operation C-MajorSheetAgentBritish Indian Ocean TerritoryIndia
■ LOW2026-07-27
How attackers are jailbreaking LLMs with CTF framing and how to catch them
◈ CHOKEPOINT T1190 Exploit Public-Facing Application
CVE-2026-39987
■ MODERATE2026-07-27
TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains
◈ CHOKEPOINT T1204 User Execution
TELEPUZ
■ LOW2026-07-27
Vishing actors target Entra passkey enrollment
◈ CHOKEPOINT T1566 Phishing
O-UNC-066TechnologyHealthcare
■ MODERATE2026-07-27
Inside a Global Procurement-Themed AiTM Phishing Campaign
◈ CHOKEPOINT T1566 Phishing
IClickFixEducationGovernment
■ MODERATE2026-07-27
Operation Fake KickOff: Attackers Abuse Recruiters and SaaS to Harvest Work Credentials
◈ CHOKEPOINT T1566 Phishing
O-UNC-038Human ResourcesAerospace
■ LOW2026-07-27
Fake crypto scams try to piggyback off SpaceX IPO
◈ CHOKEPOINT T1190 Exploit Public-Facing Application
TA2730Finance
■ MODERATE2026-07-27
ClickLock Stealer: Paste Once, Lose Everything
◈ CHOKEPOINT T1078 Valid Accounts
ClickLock DevClickLock Stealer
■ HIGH2026-07-27
Fake Corepack Site Distributes Infostealer and Proxyware to Developers
◈ CHOKEPOINT T1059 Command and Scripting Interpreter
OpenShieldTechnology
■ HIGH2026-07-27
Check Point SmartConsole Authentication Bypass (CVE-2026-16232)
◈ CHOKEPOINT T1098 Account Manipulation
CVE-2026-62145
■ LOW2026-07-26
Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass
◈ CHOKEPOINT T1566 Phishing
no tags
■ MODERATE2026-07-26
A New Name in the Data Extortion Ecosystem?
◈ CHOKEPOINT T1556 Modify Authentication Process
Helix
◆ CRITICAL2026-07-26
[email protected] Harvesting Github Credentials
◈ CHOKEPOINT T1078 Valid Accounts
Shai-HuludShai-HuludTechnology
■ LOW2026-07-26
New customs charges for online orders outside the EU
◈ CHOKEPOINT T1566 Phishing
Ireland
■ LOW2026-07-26
Fake Banking Rewards, Telegram Delivery and Albiriox: Anatomy of an Android Malware Campaign
◈ CHOKEPOINT T1566 Phishing
AlbirioxItalyFinance
■ HIGH2026-07-26
Inside the FortiBleed Open Directory: A Technical Analysis of What the Attacker Left Behind
◈ CHOKEPOINT T1190 Exploit Public-Facing Application
United States of AmericaBritish Indian Ocean Territory
■ MODERATE2026-07-26
Operation Endgame disrupts Amadey and Stealc
◈ CHOKEPOINT T1195 Supply Chain Compromise
Amadey - S1025
■ HIGH2026-07-25
GitHub Impersonation Deploys Information Stealer
◈ CHOKEPOINT T1566 Phishing
BoryptGrab Stealer
■ HIGH2026-07-25
Threat Insight: Cybercriminals Abusing Vercel to Deliver Remote Access Malware
◈ CHOKEPOINT T1059 Command and Scripting Interpreter
LogMeIn
■ HIGH2026-07-25
Miasma Worm Returns to npm
◈ CHOKEPOINT T1547.001 Registry Run Keys / Startup Folder
Miasma v3Technology
■ HIGH2026-07-25
Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor
◈ CHOKEPOINT T1547.004 Winlogon Helper DLL
DaxinTaiwanManufacturing
■ HIGH2026-07-25
Investigation of email-based attack delivering MediaFire ZIP file with execution chain…
◈ CHOKEPOINT T1547.001 Registry Run Keys / Startup Folder
NetSupport RMM
■ HIGH2026-07-25
Indirect Prompt Injection in Web Content Targets AI Agents
◈ CHOKEPOINT T1566 Phishing
TechnologyFinance
■ HIGH2026-07-25
The Devil, Eight Million Emails, and a Whole Lot of Milk | Phishing Stager Exposed
◈ CHOKEPOINT T1078 Valid Accounts
Bolivia, Plurinational State ofUnited Kingdom of Great Britain and Northern Ireland
■ HIGH2026-07-25
ClickFix Campaign Generated Via AI Delivers SmartRAT
◈ CHOKEPOINT T1112 Modify Registry
SmartRATBrazilFinance
■ HIGH2026-07-25
From E-Sign to RMM: DocuSign Kit Targets Windows and
◈ CHOKEPOINT T1566.002 Spearphishing Link
MeshAgent
■ HIGH2026-07-25
Inside a TrickBot Variant Using DNS Tunneling for C2
◈ CHOKEPOINT T1112 Modify Registry
TrickBot - S0266
■ HIGH2026-07-24
Email threat landscape: Q2 2026 trends and insights
◈ CHOKEPOINT T1566 Phishing
RetailTechnology
■ HIGH2026-07-24
Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades…
◈ CHOKEPOINT T1505.003 Web Shell
HadesThailandGovernmentCVE-2026-43500
◆ CRITICAL2026-07-24
June 2026 Threat Trend Report on APT Attacks (South Korea)
◈ CHOKEPOINT T1547.001 Registry Run Keys / Startup Folder
KimsukyAutoIt backdoor - S0129
◆ CRITICAL2026-07-24
Ongoing PLC Exploitation Against Critical U.S. Infrastructure
◈ CHOKEPOINT T1078 Valid Accounts
Cyber Av3ngersIOCONTROLUnited States of AmericaGovernment
■ HIGH2026-07-24
Security Advisory - Action Required - July 2026 Security Update
◈ CHOKEPOINT T1078.001 Default Accounts
CVE-2026-62144
◆ CRITICAL2026-07-24
Global Webmail Espionage
◈ CHOKEPOINT T1566.001 Spearphishing Attachment
Void BlizzardUkraineGovernmentCVE-2025-66376
◆ CRITICAL2026-07-24
Large-Scale GitHub Actions Abuse Powers a Distributed cPanel and WHM Exploitation Campaign
◈ CHOKEPOINT T1190 Exploit Public-Facing Application
TechnologyHostingCVE-2026-41940
◆ CRITICAL2026-07-24
Zimbra Mailservers Targeted with Half-Click Exploits
◈ CHOKEPOINT T1190 Exploit Public-Facing Application
TA488ZimReaperUnited States of AmericaUkraineCVE-2025-66376
■ HIGH2026-07-24
Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days
◈ CHOKEPOINT T1505.003 Web Shell
TA458SpyPressAlbaniaGreeceCVE-2026-8496
◆ CRITICAL2026-07-24
Upgrades MaaS Ecosystem with Modular Tools
◈ CHOKEPOINT T1547.001 Registry Run Keys / Startup Folder
TAG-195TinyEgg
■ HIGH2026-07-23
PHISH ALERT: From a Simple Phishing Email to a Full Attack Arsenal: The Evolution of…
◈ CHOKEPOINT T1566.001 Spearphishing Attachment
no tags
■ HIGH2026-07-23
JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake
◈ CHOKEPOINT T1190 Exploit Public-Facing Application
JadeProxTriBack LoaderHealthcareGovernmentCVE-2021-31755
◆ CRITICAL2026-07-23
Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with…
◈ CHOKEPOINT T1552.001 Credentials In Files
SectopRAT
◆ CRITICAL2026-07-23
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
◈ CHOKEPOINT T1112 Modify Registry
ChaosmsaRAT
■ HIGH2026-07-23
Exploitation in the Wild of wp2shell
◈ CHOKEPOINT T1078 Valid Accounts
CMSmapCVE-2026-63030
■ HIGH2026-07-23
Skill Marketplace and the Emerging AI Supply Chain Threat
◈ CHOKEPOINT T1566 Phishing
AMOSFinanceTechnology
■ HIGH2026-07-23
ClickFix campaign delivers macOS infostealer via DMG
◈ CHOKEPOINT T1555.001 Keychain
AMOS
■ HIGH2026-07-23
Branded Gambling Campaigns: How Scammers Are Exploiting Trusted Brand Names to Drive…
◈ CHOKEPOINT T1566.002 Spearphishing Link
CanadaGermany
◆ CRITICAL2026-07-23
Abusing Trusted Business Workflows: A Multi-Stage Phantom Stealer Campaign
◈ CHOKEPOINT T1055 Process Injection
Phantom StealerMalaysiaFinance
■ HIGH2026-07-23
Dolphin X Stealer Targets 300+ Apps and Profiles Users with AI
◈ CHOKEPOINT T1555.003 Credentials from Web Browsers
KontraktnikDolphin X
■ HIGH2026-07-22
The Crown Prince, Nezha
◈ CHOKEPOINT T1505.003 Web Shell
China Chopper - S0020United States of AmericaAngola
■ HIGH2026-07-22
From Phishing to Persistence: A CrySome RAT Infection Chain Analysis
◈ CHOKEPOINT T1112 Modify Registry
CrySome RAT
■ HIGH2026-07-22
HelloNet campaign: a threat via the ViPNet update system
◈ CHOKEPOINT T1112 Modify Registry
HelloInjectorRussian FederationGovernment
■ HIGH2026-07-22
ACR Stealer: Two observed intrusion chains amid increased threat activity
◈ CHOKEPOINT T1204 User Execution
ACR Stealer
■ HIGH2026-07-22
Portugal-focused phishing campaign delivers multistage malware
◈ CHOKEPOINT T1566.001 Spearphishing Attachment
LampionPortugalFinance
■ HIGH2026-07-22
From poisoned search results to GPU mining: A cryptojacking campaign abusing…
◈ CHOKEPOINT T1112 Modify Registry
SimpleRunPE
■ HIGH2026-07-22
Suspected Chinese Operators Use Claude Code and DeepSeek to Breach Government Systems…
◈ CHOKEPOINT T1505.003 Web Shell
TencShellUnited States of AmericaAfghanistan
■ HIGH2026-07-22
OkoBot framework infection chain
◈ CHOKEPOINT T1176 Software Extensions
TookPSBrazilCanada
■ HIGH2026-07-22
Unpacking the AsyncAPI npm supply chain compromise and import-time
◈ CHOKEPOINT T1547.004 Winlogon Helper DLL
Miasma
■ HIGH2026-07-22
Targeted Attack on Government Entities in the Middle East | Part 1
◈ CHOKEPOINT T1055 Process Injection
TELESHIMGovernment
■ HIGH2026-07-22
From San Pedro to Salinas: How a Chinese Framework “DCloud Uni-App” Powers a Global Scam…
◈ CHOKEPOINT T1566.001 Spearphishing Attachment
United States of AmericaArgentina
■ HIGH2026-07-22
Threat Actors Target FIFA World Cup 2026
◈ CHOKEPOINT T1566 Phishing
no tags
■ HIGH2026-07-22
Operation STANDOFF: A Campaign Hiding C2 Behind GitHub Redirects
◈ CHOKEPOINT T1112 Modify Registry
Operation STANDOFFRaccoon Stealer
■ HIGH2026-07-22
NadMesh Botnet Analysis: Product-Level Threat in the AI Services Era
◈ CHOKEPOINT T1098.004 SSH Authorized Keys
NadMeshTechnologyCVE-2016-0638
◆ CRITICAL2026-07-22
New Project CAV3RN .NET Native AOT communication module
◈ CHOKEPOINT T1078 Valid Accounts
CHRYSENECAV3RNIsrael
■ HIGH2026-07-21
Roblox, Minecraft, and the Insidious Internet for Children
◈ CHOKEPOINT T1056.003 Web Portal Capture
Education
■ HIGH2026-07-21
Potemkin Loader & RMMProject The Anatomy of a ClickFix Attack
◈ CHOKEPOINT T1547.001 Registry Run Keys / Startup Folder
Potemkin
◆ CRITICAL2026-07-21
JADEPUFFER evolves: The agentic threat actor deploys ransomware built to destroy AI models
◈ CHOKEPOINT T1078 Valid Accounts
JADEPUFFERENCFORGETechnologyCVE-2025-3248
◆ CRITICAL2026-07-21
Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family…
◈ CHOKEPOINT T1199 Trusted Relationship
KimsukyGomirTechnology
◆ CRITICAL2026-07-21
HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels
◈ CHOKEPOINT T1059 Command and Scripting Interpreter
LYCEUMHOLLOWGRAPHIsrael
■ HIGH2026-07-21
An unknown actor distributes malicious VBS scripts via WhatsApp
◈ CHOKEPOINT T1112 Modify Registry
ValleyRATAustraliaBrazil
■ HIGH2026-07-21
Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula
◈ CHOKEPOINT T1112 Modify Registry
OusabanPortugalSpain
■ HIGH2026-07-21
Malicious Go Module Exposes GitHub Malware Lure Network Spanning 222 Repositories
◈ CHOKEPOINT T1112 Modify Registry
AsyncRAT
■ HIGH2026-07-21
Kratos PhaaS Targets US and EU: How to Reduce Microsoft 365 Account Takeover Risk
◈ CHOKEPOINT T1566 Phishing
United States of AmericaAustria
■ HIGH2026-07-21
The TTF Trap: A Global Campaign of a Low-Detection Lua Loader
◈ CHOKEPOINT T1112 Modify Registry
Agent Tesla - S0331
■ HIGH2026-07-20
RAT Abuses TON Blockchain to Target Japan's Hotel Industry
◈ CHOKEPOINT T1547.001 Registry Run Keys / Startup Folder
TONResolverJapanHospitality
■ HIGH2026-07-20
Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem
◈ CHOKEPOINT T1566.002 Spearphishing Link
SessionGateBrazilFrance
■ HIGH2026-07-20
The Demon Arrives Later: A Havoc Stager Hides Behind Microsoft Defender DLP
◈ CHOKEPOINT T1547.001 Registry Run Keys / Startup Folder
HavocBrazil
■ HIGH2026-07-20
AsyncRAT and Remcos Delivered in Multi-Stage Phishing Campaign
◈ CHOKEPOINT T1566 Phishing
Remcos
■ HIGH2026-07-20
Sign here… and install an unwanted RMM
◈ CHOKEPOINT T1566 Phishing
Unknown malware
■ HIGH2026-07-20
Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent…
◈ CHOKEPOINT T1547.001 Registry Run Keys / Startup Folder
TonRATHospitality
■ HIGH2026-07-20
How a single ScreenConnect incident exposed a massive campaign
◈ CHOKEPOINT T1112 Modify Registry
AsyncRAT
■ HIGH2026-07-20
Popa: From Sourcing to Distribution
◈ CHOKEPOINT T1573.001 Symmetric Cryptography
Popa
■ MODERATE2026-07-20
Unpacking "Cruciferra": An Analysis of a Sophisticated Crypter Service
◈ CHOKEPOINT T1112 Modify Registry
TA4922CruciferraFinanceHealthcare
■ HIGH2026-07-20
Still Circling: Toolkit Keeps Evolving
◈ CHOKEPOINT T1547.001 Registry Run Keys / Startup Folder
APT-C-36AsyncRATColombiaFinance
◆ CRITICAL2026-07-19
"Ghost" Code Phishing Analysis
◈ CHOKEPOINT T1566 Phishing
EvilTokensUnited States of AmericaTechnology
◆ CRITICAL2026-07-19
Inside an affiliate panel targeting Microsoft 365
◈ CHOKEPOINT T1566 Phishing
ARTokenFinanceHealthcare
◆ CRITICAL2026-07-19
Error 524 Decoy: Unmasking a Global Smishing Operation Hiding Behind Error Pages
◈ CHOKEPOINT T1090.003 Multi-hop Proxy
AustraliaChile
◆ CRITICAL2026-07-19
ModHeader Malware: Inside the Chrome Spyware Google Removed
◈ CHOKEPOINT T1566.002 Spearphishing Link
ModHeader
◆ CRITICAL2026-07-19
Klue Integration Abused in Salesforce Data Theft | Threat Spotlight
◈ CHOKEPOINT T1078 Valid Accounts
no tags
✦ STRATEGICWEEK 29
Week 29 Threat Digest
◈ TOP CHOKEPOINT T1547.001 · 107 campaigns
WEEKLYTechnologyThe Gentlemen
◆ CRITICAL2026-07-19
Customer CRM Data Accessed in Supply Chain Incident
◈ CHOKEPOINT T1199 Trusted Relationship
no tags
■ MODERATE2026-07-19
Millenium: A RAT Rewritten, A Threat Multiplied
◈ CHOKEPOINT T1547.001 Registry Run Keys / Startup Folder
Y2K OperatorsMillenium RAT
◆ CRITICAL2026-07-19
Compromised Injective SDK npm Package Exfiltrates Wallet Keys and Mnemonics
◈ CHOKEPOINT T1554 Compromise Host Software Binary
Technology
◆ CRITICAL2026-07-19
Supply Chain Compromise via GitHub Actions
◈ CHOKEPOINT T1199 Trusted Relationship
MiasmaTechnology
■ HIGH2026-07-19
Botnet Analysis: A Product-Grade Threat for the AI Service Era
◈ CHOKEPOINT T1136.003 Cloud Account
NadMeshTechnologyCVE-2016-0638
◆ CRITICAL2026-07-18
Chromium extension uses AI‑related branding to redirect browser search
◈ CHOKEPOINT T1199 Trusted Relationship
TechnologyHospitality
◆ CRITICAL2026-07-18
Vibe Coded Extortion: Path from Legal Lure to CrownX Ransom Capabilities
◈ CHOKEPOINT T1078 Valid Accounts
Avalon
◆ CRITICAL2026-07-18
jscrambler npm Package Compromised in Supply Chain Attack
◈ CHOKEPOINT T1195.002 Compromise Software Supply Chain
Technology
◆ CRITICAL2026-07-18
LabubaRAT: A Rust Based Remote Access Tool Masquerading as NVIDIA Software
◈ CHOKEPOINT T1547.001 Registry Run Keys / Startup Folder
LabubaRAT
◆ CRITICAL2026-07-18
Behind the Refund: From GST Phishing to Remcos RAT Through a Multi-Stage .NET Infection…
◈ CHOKEPOINT T1566.001 Spearphishing Attachment
Remcos RATBritish Indian Ocean TerritoryIndia
◆ CRITICAL2026-07-18
A Multi-Stage Steganographic Loader Campaign Deploying Diverse Payloads Globally
◈ CHOKEPOINT T1112 Modify Registry
Remcos RATBritish Indian Ocean TerritoryIndia
◆ CRITICAL2026-07-18
Lucide Proxy: Turning Student Web Proxies into DDoS Bots
◈ CHOKEPOINT T1189 Drive-by Compromise
United States of AmericaEducation
◆ CRITICAL2026-07-18
Gamers beware: malicious wallpapers on Steam found stealing accounts
◈ CHOKEPOINT T1078 Valid Accounts
DarkComet - S0334British Indian Ocean TerritoryCanada
◆ CRITICAL2026-07-18
Spirals: New Stealthy Ransomware Deployed Against Asian IT Company
◈ CHOKEPOINT T1136.001 Local Account
SpiralsTechnology
◆ CRITICAL2026-07-18
Contagious Interview malware in SVG images: DPRK campaign
◈ CHOKEPOINT T1204 User Execution
Contagious InterviewOTTERCOOKIETechnology
◆ CRITICAL2026-07-17
Popular node-ipc npm Package Infected with Credential Stealer
◈ CHOKEPOINT T1552.001 Credentials In Files
node-ipcTechnology
◆ CRITICAL2026-07-17
Threat Actors Weaponizing RAR Archives to Target Thailand's Healthcare Sector
◈ CHOKEPOINT T1547.001 Registry Run Keys / Startup Folder
sim.pyThailandHealthcare
◆ CRITICAL2026-07-17
From PostCSS Masquerading to Windows RAT
◈ CHOKEPOINT T1112 Modify Registry
Technology
◆ CRITICAL2026-07-17
Chrome and Firefox Extensions Posing as Free VPNs Add Clipboard Stealers via Malicious…
◈ CHOKEPOINT T1204 User Execution
VPN Go: Free VPN
◆ CRITICAL2026-07-17
Compromised npm Packages in the AsyncAPI Namespace Deliver Miasma Botnet Loader
◈ CHOKEPOINT T1195.002 Compromise Software Supply Chain
Miasma
◆ CRITICAL2026-07-17
Crypto Clipper uses Tor and worm-like propagation for persistence and control
◈ CHOKEPOINT T1091 Replication Through Removable Media
CryptoBandits
◆ CRITICAL2026-07-17
June 2026 Infostealer Trend Report
◈ CHOKEPOINT T1566.001 Spearphishing Attachment
Remus
◆ CRITICAL2026-07-17
GoSerpent backdoor attacks in Southeast Asia
◈ CHOKEPOINT T1547.001 Registry Run Keys / Startup Folder
TetrisPhantomGoSerpentGovernment
■ HIGH2026-07-17
The Patch Wars have begun
◈ CHOKEPOINT T1547.001 Registry Run Keys / Startup Folder
UAT-11795Starland RATUnited States of America
■ HIGH2026-07-17
Novel Starland RAT and bespoke WLDR C2 implant deployed in financially motivated campaign
◈ CHOKEPOINT T1547.001 Registry Run Keys / Startup Folder
UAT-11795Starland RATUnited States of AmericaGermany
■ HIGH2026-07-16
Observed activity associated with Sidewinder APT
◈ CHOKEPOINT T1566 Phishing
RAZOR TIGER
■ HIGH2026-07-16
Payouts King Ransomware Initial Access Broker Deploys New Edgecution Malware
◈ CHOKEPOINT T1566 Phishing
Payouts KingEdgecution
◆ CRITICAL2026-07-16
Inside an IoT Botnet Framework With LLM-Assisted Development
◈ CHOKEPOINT T1078.001 Default Accounts
TuxBot v3 Evolution
◆ CRITICAL2026-07-16
11 Malicious NuGet Tools Pose as Game Cheats to Drop a Windows Host-Surveillance
◈ CHOKEPOINT T1195.002 Compromise Software Supply Chain
pepesoft.exe
■ HIGH2026-07-16
Introducing CylindricalCanine: The GoldenEyeDog subgroup responsible for the April…
◈ CHOKEPOINT T1566.001 Spearphishing Attachment
CylindricalCanineGolden Gh0st LoaderFinance
■ HIGH2026-07-16
Twitter Feed - nextronresearch - 17-06-2026
◈ CHOKEPOINT T1112 Modify Registry
SideCopypdfdocs RATBritish Indian Ocean TerritoryIndia
■ HIGH2026-07-16
Okendo Reviews Supply Chain Attack
◈ CHOKEPOINT T1547.001 Registry Run Keys / Startup Folder
SmartApeSGNetSupportRetail
■ HIGH2026-07-16
macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox
◈ CHOKEPOINT T1106 Native API
DPRK-alignedmacOS.Gaslight
■ HIGH2026-07-16
Six Minutes to Compromise: How 'Patriot Bait' Actor Used AI to Build and Deploy a C&C Botnet
◈ CHOKEPOINT T1112 Modify Registry
bandcamproUnited States of AmericaCanada
◆ CRITICAL2026-07-16
Shared Claude Chats Meet ClickFix
◈ CHOKEPOINT T1547.001 Registry Run Keys / Startup Folder
MacSync Stealer
■ HIGH2026-07-15
New APT-Q-27 sample spotted
◈ CHOKEPOINT T1059 Command and Scripting Interpreter
APT-Q-27
■ HIGH2026-07-15
Latest PyPi Compromise
◈ CHOKEPOINT T1078 Valid Accounts
TeamPCPrope.pyzTechnology
■ HIGH2026-07-15
How access to Gmail accounts is gained
◈ CHOKEPOINT T1106 Native API
ToddyCatUmbrij
■ HIGH2026-07-15
Cavern Manticore: Exposing Iran-Linked Modular C2 Framework
◈ CHOKEPOINT T1078.002 Domain Accounts
Cavern ManticoreIsraelGovernment
■ HIGH2026-07-15
Agentic AI Uncovers New China-Linked Cluster OP-512
◈ CHOKEPOINT T1190 Exploit Public-Facing Application
OP-512GhostKit
■ HIGH2026-07-15
3CXDesktopApp Intrusion Campaign Prevention
◈ CHOKEPOINT T1053 Scheduled Task/Job
Lazarus GroupTxRLoaderFinanceEnergy
■ HIGH2026-07-15
The GHOST STADIUM Score: Billions At Stake At The World’s Largest Football Tournament
◈ CHOKEPOINT T1566 Phishing
GHOST STADIUMVidarUnited States of AmericaArgentina
■ HIGH2026-07-15
An Analysis of ValleyRAT Infection Campaigns from Fake Installers, Japanese Malicious Emails
◈ CHOKEPOINT T1112 Modify Registry
SilverFoxValleyRAT
■ HIGH2026-07-15
A rigged game: compromises gaming platform in a supply-chain attack
◈ CHOKEPOINT T1195.002 Compromise Software Supply Chain
APT37BirdCall
■ HIGH2026-07-15
How WP-SHELLSTORM Exposed 1.4M WordPress Sites
◈ CHOKEPOINT T1505.003 Web Shell
WP-SHELLSTORMSNOWLIGHTFinanceRetail
■ HIGH2026-07-14
How to defend ARM64 cloud infrastructure
◈ CHOKEPOINT T1610 Deploy Container
CVE-2026-46316
◆ CRITICAL2026-07-14
Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign
◈ CHOKEPOINT T1566.002 Spearphishing Link
MacSyncBritish Indian Ocean TerritoryFrance
◆ CRITICAL2026-07-14
Operation FlutterBridge: The FlutterShell macOS Backdoor
◈ CHOKEPOINT T1566 Phishing
FlutterShell
◆ CRITICAL2026-07-14
Phishing Campaign PasasteSinTAG - New domain rotation identified associated with the…
◈ CHOKEPOINT T1056.003 Web Portal Capture
Chile
■ HIGH2026-07-14
Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257
◈ CHOKEPOINT T1190 Exploit Public-Facing Application
CVE-2026-0257
◆ CRITICAL2026-07-14
Akira, LimeWire, and the Sour Taste of Data Exfiltration
◈ CHOKEPOINT T1078 Valid Accounts
Storm-1567Akira
■ HIGH2026-07-14
StrikeShark: a new campaign involving a custom SharkLoader and Cobalt Strike Beacon
◈ CHOKEPOINT T1190 Exploit Public-Facing Application
SharkLoaderColombiaHong KongCVE-2025-55182
◆ CRITICAL2026-07-14
From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira
◈ CHOKEPOINT T1136.002 Domain Account
Bumblebee - S1039
◆ CRITICAL2026-07-14
A single RedLine C2 pivots into a maritime spear-phishing cluster and attacker-owned…
◈ CHOKEPOINT T1566.001 Spearphishing Attachment
RedLine Stealer - S1240ManufacturingTransportation
■ HIGH2026-07-14
Continues building ORB networks using new malware
◈ CHOKEPOINT T1190 Exploit Public-Facing Application
UAT-7810SHORTLEASHCVE-2020-22653
◆ CRITICAL2026-07-13
Cato CTRL Threat Research: Suspected China-Linked Threat Actor Targets Global…
◈ CHOKEPOINT T1059 Command and Scripting Interpreter
TencShellManufacturing
◆ CRITICAL2026-07-13
The Evolution of ClickFix: From Cleartext to Server Side Polymorphism
◈ CHOKEPOINT T1112 Modify Registry
DeerStealer
◆ CRITICAL2026-07-13
StealC and Amadey: Breaking down infostealers and the cybercrime services that deliver them
◈ CHOKEPOINT T1112 Modify Registry
StealC
◆ CRITICAL2026-07-13
PCPJack Hijacked 230 AWS, GCP, and Azure Servers to Run a Hidden SMTP Relay Network
◈ CHOKEPOINT T1059.004 Unix Shell
PCPJackSliver
◆ CRITICAL2026-07-13
Operation Capsule Vault: RokRAT Attack Chain Analysis Using EMBED_PAYLOAD_v2
◈ CHOKEPOINT T1547.001 Registry Run Keys / Startup Folder
APT37ROKRAT - S0240EducationGovernment
◆ CRITICAL2026-07-13
Sayonara, SocGholish: Operation Endgame Disrupts Major Cybercrime Operation
◈ CHOKEPOINT T1078 Valid Accounts
GOLD PRELUDESocGholishUnited States of AmericaAustralia
◆ CRITICAL2026-07-13
Detecting the Klue supply chain attack in Salesforce instances
◈ CHOKEPOINT T1199 Trusted Relationship
Icarus
◆ CRITICAL2026-07-13
Not very gentlemanly: Analyzing a zero-day exploit used to disable targets' EDRs
◈ CHOKEPOINT T1112 Modify Registry
The Gentlemen
◆ CRITICAL2026-07-13
Matryoshka #3/3: Gamaredon's Gammasteel Infostealer
◈ CHOKEPOINT T1547.001 Registry Run Keys / Startup Folder
GamaredonGammaSteelUkraineGovernment
◆ CRITICAL2026-07-13
Affidavit in Support of Application for Criminal Complaint
◈ CHOKEPOINT T1566 Phishing
Void BlizzardUnited States of AmericaEducation
✦ STRATEGICWEEK 28
Week 28 Threat Digest
◈ TOP CHOKEPOINT T1112 · 42 campaigns
WEEKLYGovernmentThe Gentlemen
◆ CRITICAL2026-07-12
Public and Private Medical Community Targeted by Threat Actor Pursuing Artificial…
◈ CHOKEPOINT T1554 Compromise Host Software Binary
UNC6508INFINITEREDUnited States of AmericaCanada
◆ CRITICAL2026-07-12
Inside Banana RAT: From Build Server to Banking Fraud
◈ CHOKEPOINT T1112 Modify Registry
SHADOW-WATER-063Banana RATBrazilFinance
■ HIGH2026-07-12
Analysis of Gamaredon campaign targeting Ukraine weaponizing CVE-2025-8088
◈ CHOKEPOINT T1547.001 Registry Run Keys / Startup Folder
GamaredonGamaredonUkraineDefenseCVE-2025-8088
◆ CRITICAL2026-07-12
CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure
◈ CHOKEPOINT T1505.003 Web Shell
CL-STA-1062TinyRCTTaiwanGovernment
◆ CRITICAL2026-07-12
FSB’s matryoshka #1/3 – Gamaredon’s gifts that keeps unpacking – GammaPhish and GammaWorm
◈ CHOKEPOINT T1112 Modify Registry
GamaredonGammaPhishUkraineGovernment
◆ CRITICAL2026-07-12
Analysis of APT37 NarwhalRAT Leveraging MS-Themed Phishing and Dead-drop C2
◈ CHOKEPOINT T1112 Modify Registry
APT37NarwhalRAT
■ HIGH2026-07-12
Middle East Malicious Infrastructure Report: 1,350+ C2 Servers Mapped Across 98 Providers
◈ CHOKEPOINT T1098 Account Manipulation
Eagle WerewolfPhorpiexEnergyGovernmentCVE-2025-11953
◆ CRITICAL2026-07-12
Ukraine's UAV Supply Chain Targeted With Besomar-Themed Malware Chain
◈ CHOKEPOINT T1112 Modify Registry
GhostShellVidarUkraineDefense
◆ CRITICAL2026-07-12
Prinz Eugen ransomware: a deep dive into a new Go-based encryptor
◈ CHOKEPOINT T1078 Valid Accounts
ROOTBOYPrinz EugenSouth AfricaFrance
◆ CRITICAL2026-07-12
Operation DragonReturn: China-Nexus Cyber Espionage Campaign Targeting Govt. of India/MoF…
◈ CHOKEPOINT T1547.001 Registry Run Keys / Startup Folder
Void ArachneDcRATBritish Indian Ocean TerritoryIndia
◆ CRITICAL2026-07-11
Operation Endgame vs. SocGholish Fake Updates
◈ CHOKEPOINT T1547.001 Registry Run Keys / Startup Folder
GOLD PRELUDESocGholishGovernmentEducation
◆ CRITICAL2026-07-11
KimJongRAT Continues to Evolve by Leveraging LOTS
◈ CHOKEPOINT T1547.001 Registry Run Keys / Startup Folder
KimsukyKimJongRATJapan
◆ CRITICAL2026-07-11
STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus
◈ CHOKEPOINT T1112 Modify Registry
TurlaSTOCKSTAYItalyUkraine
◆ CRITICAL2026-07-11
Armored Likho's new weapon: BusySnake Stealer
◈ CHOKEPOINT T1547.001 Registry Run Keys / Startup Folder
Armored LikhoBusySnake StealerBrazilKazakhstan
◆ CRITICAL2026-07-11
From external espionage to domestic targeting
◈ CHOKEPOINT T1195.002 Compromise Software Supply Chain
APT32SPECTRALVIPERFinanceConstruction
◆ CRITICAL2026-07-11
India's government and energy sectors targeted with ZOHOMURK and MINIRECON
◈ CHOKEPOINT T1112 Modify Registry
MUSTANG PANDASHARDLOADERBritish Indian Ocean TerritoryIndia
◆ CRITICAL2026-07-11
Iran-Nexus Disseminates MarkiRAT Surveillance Tool
◈ CHOKEPOINT T1112 Modify Registry
TAG-182MarkiRAT - S0652Iran, Islamic Republic of
◆ CRITICAL2026-07-11
TA4922: The Suspected Chinese Crime Group is Going Global
◈ CHOKEPOINT T1566 Phishing
TA4922Atlas RATBritish Indian Ocean TerritoryGermany
◆ CRITICAL2026-07-11
Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal…
◈ CHOKEPOINT T1547.001 Registry Run Keys / Startup Folder
UNK_DeadDropOverlordUnited States of AmericaFinance
◆ CRITICAL2026-07-11
From Invoice to AnyDesk: Uncovering a Phishing Campaign Targeting Russian Aerospace…
◈ CHOKEPOINT T1059.001 PowerShell
Rare WerewolfDYEPACKRussian FederationAerospace
◆ CRITICAL2026-07-10
The Package That Never Shipped: Following a USPS Smishing Kit Through DNS Data
◈ CHOKEPOINT T1566 Phishing
CVE-2024-6387
◆ CRITICAL2026-07-10
A Djinn in the Machine: TaskWeaver's Node.js Intrusion Chain
◈ CHOKEPOINT T1190 Exploit Public-Facing Application
TaskWeaverTechnologyCVE-2026-48558
◆ CRITICAL2026-07-10
The Gentlemen are knocking: сustom backdoors and evolving tactics
◈ CHOKEPOINT T1547.001 Registry Run Keys / Startup Folder
The GentlemenSharkLoaderBrazilChina
◆ CRITICAL2026-07-10
GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses
◈ CHOKEPOINT T1555.003 Credentials from Web Browsers
HyadinaGodDamn
■ HIGH2026-07-10
Indonesian Banking Sector Threat Landscape
◈ CHOKEPOINT T1053 Scheduled Task/Job
SilverFoxValleyRATBritish Indian Ocean TerritoryIndiaCVE-2025-8088
◆ CRITICAL2026-07-10
LBIOC-20260071 - The Gentlemens Leak
◈ CHOKEPOINT T1204 User Execution
The GentlemenThe Gentlemen
◆ CRITICAL2026-07-10
The Gentleman Ransomware | Defense Evasion TTPs Uncovered
◈ CHOKEPOINT T1078 Valid Accounts
The GentlemenThe GentlemenTransportationConstructionCVE-2024-55591
◆ CRITICAL2026-07-10
Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager
◈ CHOKEPOINT T1098 Account Manipulation
CVE-2026-20245
◆ CRITICAL2026-07-10
Hacktivists are broadening their scope beyond political motivation
◈ CHOKEPOINT T1505.003 Web Shell
4BIDBlackReaperRATBelarusEgyptCVE-2023-44976
◆ CRITICAL2026-07-10
CitrixBleed 2 (CVE-2025-5777) 7 Steps to Dragonforce Ransomware
◈ CHOKEPOINT T1078 Valid Accounts
DragonForceDragonForceCVE-2025-5777
◆ CRITICAL2026-07-09
Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities
◈ CHOKEPOINT T1098 Account Manipulation
UAT-8616XenShellCVE-2026-20128
◆ CRITICAL2026-07-09
Interlock and Rhysida within the Ransomware Ecosystem
◈ CHOKEPOINT T1566 Phishing
Hive0163NodeSnakeUnited States of AmericaAerospaceCVE-2026-20131
◆ CRITICAL2026-07-09
Targets Education Sector with Oracle PeopleSoft Exploit
◈ CHOKEPOINT T1505.003 Web Shell
UNC6240MeshCentralUnited States of AmericaEducationCVE-2026-35273
◆ CRITICAL2026-07-09
Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open
◈ CHOKEPOINT T1547.001 Registry Run Keys / Startup Folder
Earth DahuGIFTEDCROOKUkraineGovernmentCVE-2025-8088
◆ CRITICAL2026-07-09
Active Exploitation of Check Point VPN Authentication Bypass (CVE-2026-50751)
◈ CHOKEPOINT T1078 Valid Accounts
QilinQilinTaiwanCVE-2026-50751
◆ CRITICAL2026-07-09
Ransomware Analysis: Go Binary and Fast Encryption
◈ CHOKEPOINT T1547.001 Registry Run Keys / Startup Folder
The GentlemenGentlemenUnited States of AmericaBrazilCVE-2024-55591
◆ CRITICAL2026-07-09
Attackers Weaponize Microsoft Teams Relays to Stay Hidden
◈ CHOKEPOINT T1112 Modify Registry
DragonForceBackdoor.TurnUnited States of AmericaCVE-2023-52271
◆ CRITICAL2026-07-09
From emerging threat to top-tier ransomware-as-a-service: The evolution of INC ransomware
◈ CHOKEPOINT T1566 Phishing
INCBrave Prince - S0252LegalManufacturingCVE-2025-5777
◆ CRITICAL2026-07-09
New Backdoor May be Linked to Ransomware Access Broker
◈ CHOKEPOINT T1112 Modify Registry
WoodgnatBackdoor.MisticInsuranceEducation
◆ CRITICAL2026-07-09
Understanding Langflow CVE-2026-55255, and why higher CVSS vulnerabilities aren't always…
◈ CHOKEPOINT T1204 User Execution
VShellTechnologyCVE-2026-33017
◆ CRITICAL2026-07-09
RustDuck: An In-Depth Analysis of a Two-Stage Botnet
◈ CHOKEPOINT T1059 Command and Scripting Interpreter
RustDuckCVE-2025-29635
◆ CRITICAL2026-07-09
Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation
◈ CHOKEPOINT T1112 Modify Registry
X3D MINERVidarUnited States of America
// NO BRIEFS MATCH