Threat Intelligence Report

Generated 2026-09-02 11:51 UTC  ·  3/3 sources live  ·  ← back to cyberassist
1687
KEV catalog total
5
Added last 7 days
352
Ransomware-linked
35
Fresh IOCs / pulses

Latest CISA Known Exploited Vulnerabilities live

CVEVendor / ProductVulnerabilityAddedDue
CVE-2026-82078PaperCut
NG/MF
PaperCut NG/MF Unsafe Reflection Vulnerability2026-08-312026-09-14
CVE-2026-81578PaperCut
NG/MF
PaperCut NG/MF Missing Authentication for Critical Function Vulnerability2026-08-312026-09-14
CVE-2023-49105ownCloud
ownCloud
ownCloud Improper Authentication Vulnerability2026-08-272026-08-30
CVE-2026-53362Linux
Kernel
Linux Kernel Unspecified Vulnerability2026-08-272026-08-30
CVE-2026-66384JFrog
Artifactory
JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability2026-08-272026-09-10
CVE-2021-23758Ajax.NET Professional
Ajax.NET Professional
Ajax.NET Professional Deserialization of Untrusted Data Vulnerability2026-08-262026-09-09
CVE-2015-3246Red Hat
Libuser
Red Hat Libuser Race Condition Vulnerability2026-08-262026-09-09
CVE-2015-5287Red Hat
Automatic Bug Reporting Tool
Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability2026-08-262026-09-09
CVE-2022-0995Linux
Kernel
Linux Kernel Out-of-Bounds Write Vulnerability2026-08-262026-09-09
CVE-2026-8452Citrix
NetScaler ADC and NetScaler Gateway
Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability2026-08-262026-08-29
CVE-2019-1068Microsoft
SQL Server
Microsoft SQL Server Remote Code Execution Vulnerability2026-08-262026-08-29
CVE-2026-60004Gitea
Gitea
Gitea Code Injection Vulnerability2026-08-252026-08-28
CVE-2026-21962Oracle
HTTP Server and Oracle Weblogic Server Proxy Plug-in
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability2026-08-242026-08-27
CVE-2026-73570Synacor
Zimbra Collaboration Suite (ZCS)
Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability2026-08-212026-08-24
CVE-2026-72530TrueConf
Server
TrueConf Server Code Injection Vulnerability2026-08-202026-09-03
CVE-2026-72529TrueConf
Server
TrueConf Server Missing Authentication for Critical Function Vulnerability2026-08-202026-08-23
CVE-2026-64849MLflow
MLflow
MLflow Server-Side Request Forgery Vulnerability2026-08-192026-09-02
CVE-2026-33824Microsoft
Internet Key Exchange (IKE) Service Extensions
Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability2026-08-182026-08-21
CVE-2026-59310Broadcom
VMware vCenter
Broadcom VMware vCenter Path Traversal Vulnerability2026-08-182026-08-21
CVE-2026-55040Microsoft
SharePoint
Microsoft SharePoint Weak Authentication Vulnerability2026-08-182026-08-21
CVE-2026-65400Apple
macOS
Apple macOS Improper Authentication Vulnerability2026-08-182026-08-21
CVE-2025-62593Ray-Project
Ray
Ray-Project Ray Code Injection Vulnerability2026-08-172026-08-20
CVE-2026-20349Cisco
Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability2026-08-112026-08-14
CVE-2026-68820Microsoft
Windows Ancillary Function Driver for WinSock
Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability2026-08-112026-08-25
CVE-2026-72898Metabase
Metabase
Metabase SQL Injection Vulnerability2026-08-112026-08-14

Recent Malware IOCs — ThreatFox live

IndicatorTypeMalwareThreatConf.First seen
180.76.250.42:1996ip:portCobalt Strikebotnet_cc75%2026-09-02 11:48:22 UTC
bv0rhljc.en-us-theeloncod.comdomainClearFakepayload_delivery100%2026-09-02 11:37:17 UTC
seasonmber.duckdns.orgdomainRemcosbotnet_cc75%2026-09-02 11:35:19 UTC
seasonmberbk.duckdns.orgdomainRemcosbotnet_cc75%2026-09-02 11:35:19 UTC
https://raw.githubusercontent.com/frantario/tranday/refs/heads/main/ruty4839urlClearFakepayload_delivery100%2026-09-02 11:15:54 UTC
trumpgoldenbadge.netdomainClearFakepayload_delivery100%2026-09-02 11:14:40 UTC
fk0ds5tz4n.workers.devdomainphp.shin_webshellbotnet_cc50%2026-09-02 11:12:57 UTC
marthenacertain.workers.devdomainphp.shin_webshellbotnet_cc50%2026-09-02 11:08:42 UTC
visionaryhomesandinvestments.comdomainClearFakepayload_delivery90%2026-09-02 10:57:40 UTC
thevictorytoken.usdomainClearFakepayload_delivery100%2026-09-02 10:56:19 UTC
shootartphotografie.chdomainClearFakepayload_delivery90%2026-09-02 10:47:39 UTC
saas-stash.beerdomainClearFakepayload_delivery90%2026-09-02 10:47:06 UTC
https://raw.githubusercontent.com/frantario/tropa47/refs/heads/main/lytkc14urlClearFakepayload_delivery100%2026-09-02 10:46:03 UTC
43.198.116.85:443ip:portAdaptixC2botnet_cc100%2026-09-02 10:05:04 UTC
https://raw.githubusercontent.com/Loolu2846/ruta3742/refs/heads/main/rita80urlClearFakepayload_delivery100%2026-09-02 09:50:31 UTC
glycomutee.comdomainClearFakepayload_delivery100%2026-09-02 09:49:21 UTC
91.92.47.214:6666ip:portPureRATbotnet_cc75%2026-09-02 09:47:09 UTC
93.114.183.130:8711ip:portPureRATbotnet_cc75%2026-09-02 09:47:09 UTC
85.120.216.8:4321ip:portAdaptixC2botnet_cc75%2026-09-02 09:46:57 UTC
56.69.248.141:443ip:portPureRATbotnet_cc75%2026-09-02 09:46:41 UTC
56.69.232.66:443ip:portPureRATbotnet_cc75%2026-09-02 09:46:40 UTC
5.21.239.104:1723ip:portAsyncRATbotnet_cc75%2026-09-02 09:46:36 UTC
45.158.116.86:7443ip:portUnknown malwarebotnet_cc75%2026-09-02 09:46:24 UTC
45.139.104.204:443ip:portPureRATbotnet_cc75%2026-09-02 09:46:21 UTC
43.133.164.200:9090ip:portUnknown malwarebotnet_cc75%2026-09-02 09:46:17 UTC

Community Threat Pulses — AlienVault OTX live

PulseAuthorTagsIOCsCreated
The Crypto Wallet That Never Opened: Tampered Exodus Installer Hides a Modular RATAlienVaultdll4_script, javascript dropper, dll4_cmd, azure table storage, credential theft, dll4_vnc, dll4_fileman, exodus wallet472026-09-01
Counterfeit installers to system compromise: Tracking a deceptive software download campaignAlienVaultscheduled tasks, silver fox, counterfeit installers, command-and-control, fake software, chinese-speaking targets, yinhu, defense evasion492026-09-02
Hackers Weaponize Microsoft Teams Help Desk Calls for Malware and Network Lateral MovementAlienVault122026-09-02
Sality's P2P Network Turned Against Itself, Cutting Off New Malware PayloadsAlienVaultbotnet takedown, law enforcement operation, p2p network, peer list manipulation, ddos campaigns, cryptocurrency theft, clipper, eggjagger82026-09-02
A China-Nexus Campaign Against Government InfrastructureAlienVaultspray-and-check, meterpreter, cobalt-strike, multi-platform, gocs, loader, neo-regeorg, snowlight322026-08-03
A Deep Dive Into the Latest XCSSET VersionAlienVaultxcode, south asia, telegram trojanizer, macos, netwire, developer targeting, polymorphic malware, osx.dubrobber642026-08-03
Reversing a Windows Kernel Driver RootkitAlienVaultsakdriver, dkom, nsi hooking, kernel rootkit, registry callback c2, crackerdrv, etw patching, wfp manipulation42026-08-03
Switches to Node.js and JavaScript malwareAlienVaultaviation sector, azure infrastructure, pollcat, noderabbit, trojanized coding challenge, retrograde, cross-platform rat, minifast372026-09-01
Anatomy of BraZetsu: How Cybercriminals Fuel the Underground EcosystemAlienVaultbrazetsu, python malware, ai-powered cybercrime, initial access broker, latam, cnab, ousaban, cnabhunter322026-08-31
Shai-Hulud Trinitite Hits @7nohe/openapi-react-query-codegenAlienVaultshai-hulud, trinitite, credential-theft, github-actions, supply-chain, worm, persistence, oidc42026-08-31