Offensive Sequence
- NightmareStresser DDoS Service Disrupted in International Operation [13m]
- A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity [19m]
- Brevo Supply Chain Attack Injects Malware Into 100,000 Websites [28m]
- CVE-2026-40538: Improper Restriction of Excessive Authentication Attempts in Synology DiskStation Manager (DSM) [43m]
- CVE-2026-90884: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in brechtvds WP Recipe Maker [43m]
- CVE-2026-87915: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in danieliser Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [43m]
- CVE-2026-18405: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in jegtheme Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress [43m]
- CVE-2026-15797: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in danieliser Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [43m]
- CVE-2026-87743: Incorrect Behavior Order: Authorization Before Parsing and Canonicalization in Red Hat Exploit Intelligence [43m]
- CVE-2026-15579: CWE-787: Out-of-bounds Write in Moxa TN-4500B Series [43m]
- New Check Point flaw lets hackers execute code with root privileges [43m]
- BlackCore’s Influence Operations for Hire [1h]
- Beware the SparroWock: The backdoor that bites, the commands that catch [1h]
- Ready, Settra, Go: New Settra Ransomware Variant Deploys MeshAgent RMM [1h]
- T-Mobile rewards points expiry texts are a phishing scam [1h]
- Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware [1h]
- CVE-2026-93493: Improper Check for Certificate Revocation in Red Hat Red Hat build of Apache Camel for Spring Boot 4 [2h]
- CVE-2026-11757: CWE-79 Improper neutralization of input during web page generation ('cross-site scripting') in KA Informatics Technologies Ltd. Co. Bar Association Website [2h]
- HEAVYGRAM: A Telegram-based Surveillance Backdoor Linked to Handala Hack [2h]
- CVE-2026-67101: CWE-918 Server-Side Request Forgery (SSRF) in HCL Software HCL BigFix Service Management [2h]
- CVE-2026-12384: CWE-639 Authorization bypass through User-Controlled key in TECHIN2B TECHIN2B Application [2h]
- CVE-2026-75157: CWE-863: Incorrect Authorization in Apache Software Foundation Apache Airflow [2h]
- CVE-2026-67103: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in HCL Software HCL BigFix Service Management [2h]
- CVE-2026-67102: CWE-285 Improper Authorization in HCL Software HCL BigFix Service Management [2h]
- CVE-2026-67100: CWE-89 Improper neutralization of special elements used in an SQL command ('SQL injection') in HCL Software HCL BigFix Service Management [2h]
VulDB
- CVE-2026-93559 | Forget-C Jellyfish AI Short Drama Studio up to 0.3.2 FastAPI dependencies.py missing authentication (Issue 37) [41m]
- CVE-2026-83561 | Complianz GDPR/CCPA Cookie Consent Banner Plugin up to 7.5.4 on WordPress Elementor Cookie Blocker Regex cross site scripting (EUVD-2026-82792) [1h]
- CVE-2026-56597 | HCL BigFix Service Management 27 information disclosure [1h]
- CVE-2026-56590 | HCL BigFix Service Management 27 unrestricted upload [1h]
- CVE-2026-21822 | HCL AppScan ASReportService path traversal [1h]
- CVE-2026-93534 | spatie Scotty up to 1.4.2 Self Update SelfUpdater.php SelfUpdater::update code download (Issue 21) [1h]
- CVE-2026-93533 | spatie Scotty up to 1.4.4 Doctor Command DoctorCommand.php checkRemoteTools host os command injection (Issue 20) [1h]
- CVE-2026-56595 | HCL BigFix Service Management 27 cross-domain policy [1h]
- CVE-2026-6205 | Synology DiskStation Manager up to 7.4-90074 Upload API unrestricted upload [1h]
- CVE-2026-56592 | HCL BigFix Service Management 27 Login Interface improper authentication [1h]
- CVE-2026-85410 | pixarlabs Master Addons for Elementor Plugin up to 3.2.2 on WordPress popup_id authorization (EUVD-2026-82793) [1h]
- CVE-2026-93532 | gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8 Password Change password.php simpan kode_user/username improper authentication [1h]
- CVE-2026-93531 | gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8 cross-site request forgery [1h]
- CVE-2026-40537 | Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 PersonMail API server-side request forgery [1h]
- CVE-2026-40534 | Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 Video API cross site scripting [1h]
- CVE-2026-4036 | Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 Sharing API sql injection [1h]
- CVE-2026-40539 | Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 Email API certificate validation (EUVD-2026-82797) [1h]
- CVE-2026-40533 | Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 Desktop API information disclosure (EUVD-2026-82794) [1h]
- CVE-2026-40530 | Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 User API crlf injection [1h]
- CVE-2026-21848 | HCL BigFix Service Management 23 access control [1h]
- CVE-2026-40536 | Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 Audio API path traversal [1h]
- CVE-2026-40535 | Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 Desktop API path traversal (EUVD-2026-82795) [1h]
- CVE-2026-40532 | Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 Wallpaper Path information disclosure [1h]
- CVE-2026-40531 | Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 File Operation integer overflow [1h]
- CVE-2026-13623 | Synology DiskStation Manager Theme API cross site scripting [1h]
Zero Day Initiative
- ZDI-26-714: Samsung rlottie Stack-based Buffer Overflow Remote Code Execution Vulnerability [1d]
- ZDI-26-708: (0Day) Microsoft Windows HTTP Proxy Privilege Escalation Vulnerability [2d]
- ZDI-26-707: (0Day) MindsDB OpenBBtable Code Injection Remote Code Execution Vulnerability [2d]
- ZDI-26-706: (0Day) CrewAI crewAI Framework Agent Loading Unsafe Reflection Remote Code Execution Vulnerability [2d]
- ZDI-26-705: (0Day) BusyBox libarchive Symlink Directory Traversal Arbitrary File Creation Vulnerability [2d]
- ZDI-26-704: (0Day) Airbyte OneDrive Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure Vulnerability [2d]
- ZDI-26-703: (0Day) Airbyte SharePoint Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure Vulnerability [2d]
- ZDI-26-713: GIMP APNG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability [2d]
- ZDI-26-712: NoMachine nxhtd Server-Side Request Forgery Information Disclosure Vulnerability [2d]
- ZDI-26-711: NoMachine Redis Improper Authentication Local Privilege Escalation Vulnerability [2d]
- ZDI-26-710: NoMachine mDNS Heap-based Buffer Overflow Remote Code Execution Vulnerability [2d]
- ZDI-26-709: Cisco Secure Firewall Management Center CommandSinkRmi Deserialization of Untrusted Data Remote Code Execution Vulnerability [2d]