| CVE | Vendor / Product | Vulnerability | Added | Due |
|---|---|---|---|---|
CVE-2026-82078 | PaperCut NG/MF | PaperCut NG/MF Unsafe Reflection Vulnerability | 2026-08-31 | 2026-09-14 |
CVE-2026-81578 | PaperCut NG/MF | PaperCut NG/MF Missing Authentication for Critical Function Vulnerability | 2026-08-31 | 2026-09-14 |
CVE-2023-49105 | ownCloud ownCloud | ownCloud Improper Authentication Vulnerability | 2026-08-27 | 2026-08-30 |
CVE-2026-53362 | Linux Kernel | Linux Kernel Unspecified Vulnerability | 2026-08-27 | 2026-08-30 |
CVE-2026-66384 | JFrog Artifactory | JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability | 2026-08-27 | 2026-09-10 |
CVE-2021-23758 | Ajax.NET Professional Ajax.NET Professional | Ajax.NET Professional Deserialization of Untrusted Data Vulnerability | 2026-08-26 | 2026-09-09 |
CVE-2015-3246 | Red Hat Libuser | Red Hat Libuser Race Condition Vulnerability | 2026-08-26 | 2026-09-09 |
CVE-2015-5287 | Red Hat Automatic Bug Reporting Tool | Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability | 2026-08-26 | 2026-09-09 |
CVE-2022-0995 | Linux Kernel | Linux Kernel Out-of-Bounds Write Vulnerability | 2026-08-26 | 2026-09-09 |
CVE-2026-8452 | Citrix NetScaler ADC and NetScaler Gateway | Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability | 2026-08-26 | 2026-08-29 |
CVE-2019-1068 | Microsoft SQL Server | Microsoft SQL Server Remote Code Execution Vulnerability | 2026-08-26 | 2026-08-29 |
CVE-2026-60004 | Gitea Gitea | Gitea Code Injection Vulnerability | 2026-08-25 | 2026-08-28 |
CVE-2026-21962 | Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in | Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability | 2026-08-24 | 2026-08-27 |
CVE-2026-73570 | Synacor Zimbra Collaboration Suite (ZCS) | Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability | 2026-08-21 | 2026-08-24 |
CVE-2026-72530 | TrueConf Server | TrueConf Server Code Injection Vulnerability | 2026-08-20 | 2026-09-03 |
CVE-2026-72529 | TrueConf Server | TrueConf Server Missing Authentication for Critical Function Vulnerability | 2026-08-20 | 2026-08-23 |
CVE-2026-64849 | MLflow MLflow | MLflow Server-Side Request Forgery Vulnerability | 2026-08-19 | 2026-09-02 |
CVE-2026-33824 | Microsoft Internet Key Exchange (IKE) Service Extensions | Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability | 2026-08-18 | 2026-08-21 |
CVE-2026-59310 | Broadcom VMware vCenter | Broadcom VMware vCenter Path Traversal Vulnerability | 2026-08-18 | 2026-08-21 |
CVE-2026-55040 | Microsoft SharePoint | Microsoft SharePoint Weak Authentication Vulnerability | 2026-08-18 | 2026-08-21 |
CVE-2026-65400 | Apple macOS | Apple macOS Improper Authentication Vulnerability | 2026-08-18 | 2026-08-21 |
CVE-2025-62593 | Ray-Project Ray | Ray-Project Ray Code Injection Vulnerability | 2026-08-17 | 2026-08-20 |
CVE-2026-20349 | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability | 2026-08-11 | 2026-08-14 |
CVE-2026-68820 | Microsoft Windows Ancillary Function Driver for WinSock | Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability | 2026-08-11 | 2026-08-25 |
CVE-2026-72898 | Metabase Metabase | Metabase SQL Injection Vulnerability | 2026-08-11 | 2026-08-14 |
| Indicator | Type | Malware | Threat | Conf. | First seen |
|---|---|---|---|---|---|
180.76.250.42:1996 | ip:port | Cobalt Strike | botnet_cc | 75% | 2026-09-02 11:48:22 UTC |
bv0rhljc.en-us-theeloncod.com | domain | ClearFake | payload_delivery | 100% | 2026-09-02 11:37:17 UTC |
seasonmber.duckdns.org | domain | Remcos | botnet_cc | 75% | 2026-09-02 11:35:19 UTC |
seasonmberbk.duckdns.org | domain | Remcos | botnet_cc | 75% | 2026-09-02 11:35:19 UTC |
https://raw.githubusercontent.com/frantario/tranday/refs/heads/main/ruty4839 | url | ClearFake | payload_delivery | 100% | 2026-09-02 11:15:54 UTC |
trumpgoldenbadge.net | domain | ClearFake | payload_delivery | 100% | 2026-09-02 11:14:40 UTC |
fk0ds5tz4n.workers.dev | domain | php.shin_webshell | botnet_cc | 50% | 2026-09-02 11:12:57 UTC |
marthenacertain.workers.dev | domain | php.shin_webshell | botnet_cc | 50% | 2026-09-02 11:08:42 UTC |
visionaryhomesandinvestments.com | domain | ClearFake | payload_delivery | 90% | 2026-09-02 10:57:40 UTC |
thevictorytoken.us | domain | ClearFake | payload_delivery | 100% | 2026-09-02 10:56:19 UTC |
shootartphotografie.ch | domain | ClearFake | payload_delivery | 90% | 2026-09-02 10:47:39 UTC |
saas-stash.beer | domain | ClearFake | payload_delivery | 90% | 2026-09-02 10:47:06 UTC |
https://raw.githubusercontent.com/frantario/tropa47/refs/heads/main/lytkc14 | url | ClearFake | payload_delivery | 100% | 2026-09-02 10:46:03 UTC |
43.198.116.85:443 | ip:port | AdaptixC2 | botnet_cc | 100% | 2026-09-02 10:05:04 UTC |
https://raw.githubusercontent.com/Loolu2846/ruta3742/refs/heads/main/rita80 | url | ClearFake | payload_delivery | 100% | 2026-09-02 09:50:31 UTC |
glycomutee.com | domain | ClearFake | payload_delivery | 100% | 2026-09-02 09:49:21 UTC |
91.92.47.214:6666 | ip:port | PureRAT | botnet_cc | 75% | 2026-09-02 09:47:09 UTC |
93.114.183.130:8711 | ip:port | PureRAT | botnet_cc | 75% | 2026-09-02 09:47:09 UTC |
85.120.216.8:4321 | ip:port | AdaptixC2 | botnet_cc | 75% | 2026-09-02 09:46:57 UTC |
56.69.248.141:443 | ip:port | PureRAT | botnet_cc | 75% | 2026-09-02 09:46:41 UTC |
56.69.232.66:443 | ip:port | PureRAT | botnet_cc | 75% | 2026-09-02 09:46:40 UTC |
5.21.239.104:1723 | ip:port | AsyncRAT | botnet_cc | 75% | 2026-09-02 09:46:36 UTC |
45.158.116.86:7443 | ip:port | Unknown malware | botnet_cc | 75% | 2026-09-02 09:46:24 UTC |
45.139.104.204:443 | ip:port | PureRAT | botnet_cc | 75% | 2026-09-02 09:46:21 UTC |
43.133.164.200:9090 | ip:port | Unknown malware | botnet_cc | 75% | 2026-09-02 09:46:17 UTC |
| Pulse | Author | Tags | IOCs | Created |
|---|---|---|---|---|
| The Crypto Wallet That Never Opened: Tampered Exodus Installer Hides a Modular RAT | AlienVault | dll4_script, javascript dropper, dll4_cmd, azure table storage, credential theft, dll4_vnc, dll4_fileman, exodus wallet | 47 | 2026-09-01 |
| Counterfeit installers to system compromise: Tracking a deceptive software download campaign | AlienVault | scheduled tasks, silver fox, counterfeit installers, command-and-control, fake software, chinese-speaking targets, yinhu, defense evasion | 49 | 2026-09-02 |
| Hackers Weaponize Microsoft Teams Help Desk Calls for Malware and Network Lateral Movement | AlienVault | 12 | 2026-09-02 | |
| Sality's P2P Network Turned Against Itself, Cutting Off New Malware Payloads | AlienVault | botnet takedown, law enforcement operation, p2p network, peer list manipulation, ddos campaigns, cryptocurrency theft, clipper, eggjagger | 8 | 2026-09-02 |
| A China-Nexus Campaign Against Government Infrastructure | AlienVault | spray-and-check, meterpreter, cobalt-strike, multi-platform, gocs, loader, neo-regeorg, snowlight | 32 | 2026-08-03 |
| A Deep Dive Into the Latest XCSSET Version | AlienVault | xcode, south asia, telegram trojanizer, macos, netwire, developer targeting, polymorphic malware, osx.dubrobber | 64 | 2026-08-03 |
| Reversing a Windows Kernel Driver Rootkit | AlienVault | sakdriver, dkom, nsi hooking, kernel rootkit, registry callback c2, crackerdrv, etw patching, wfp manipulation | 4 | 2026-08-03 |
| Switches to Node.js and JavaScript malware | AlienVault | aviation sector, azure infrastructure, pollcat, noderabbit, trojanized coding challenge, retrograde, cross-platform rat, minifast | 37 | 2026-09-01 |
| Anatomy of BraZetsu: How Cybercriminals Fuel the Underground Ecosystem | AlienVault | brazetsu, python malware, ai-powered cybercrime, initial access broker, latam, cnab, ousaban, cnabhunter | 32 | 2026-08-31 |
| Shai-Hulud Trinitite Hits @7nohe/openapi-react-query-codegen | AlienVault | shai-hulud, trinitite, credential-theft, github-actions, supply-chain, worm, persistence, oidc | 4 | 2026-08-31 |