CYBERSECURITY INTEL FREE'Dself-hosted CTI

LATEST // SURFACE WEB

Aggregated cybersecurity reporting, advisories and research. 82 matching records.
AUTO-POLL // 2026-08-16 04:50 UTC
SURFACE WEB DARK / DEEP WEB
RESET
2026-07-16 12:00 UTC
Vendor Research
TIER 2

CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities

Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-08-16 02:02 UTC

Four Microsoft SharePoint Server vulnerabilities are under active exploitation, prompting CISA to issue a hardening alert. An additional high-severity flaw recently patched adds pressure for organizations running on-premises deployments.Key TakeawaysCISA confirmed active exploitation of three on-premises SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164), used to gain unauthorized access, establish remote code execution, steal IIS machine keys and deploy malware for persistence.Two additional SharePoint Server vulnerabilities disclosed on July 14, 2026, CVE-202…

Cloud SecurityMalwareMicrosoftRansomwareThreat ActorsVulnerabilities CVE-2026-32201CVE-2026-45659CVE-2026-55040CVE-2026-56164CVE-2026-58644
P95
2026-07-14 19:22 UTC
Independent Research
TIER 2

Microsoft Patches a Record 570 Security Flaws

Krebs on Security · BrianKrebs · indexed 2026-08-16 02:02 UTC

Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.

AI SecurityCloud SecurityMicrosoftVulnerabilities
P0
2026-07-14 14:23 UTC
Vendor Research
TIER 2

Microsoft’s July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164)

Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-08-16 02:02 UTC

56Critical510Important3Moderate0LowMicrosoft addresses 569 CVEs in the largest Patch Tuesday release yet. This month’s release includes three zero-days, two of which were exploited in the wild.Microsoft patched 569 CVEs in its July 2026 Patch Tuesday release, with 56 rated critical, 510 rated as important, and 3 rated as moderate. This marks the largest Patch Tuesday release ever, crushing the previous record of 198 CVEs in June. Last week, Microsoft announced that its multi-model agentic scanning harness (MDASH) is being used to identify vulnerabilities faster and noted that “customers will …

AppleCloud SecurityLinuxMalwareMicrosoftMobile SecurityNetwork SecurityVulnerabilities CVE-2026-56155CVE-2026-56164
P65
2026-07-07 14:00 UTC
Vendor Research
TIER 2

The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-16 02:02 UTC

Written by: Shebin Mathew Introduction The "Golden SAML" technique, first described by CyberArk researchers in 2017, and further detailed by Mandiant researchers in 2021, remains one of the most effective methods for threat actors to forge identity assertions in the Microsoft ecosystem. By obtaining the private key of an ADFS token-signing certificate, an attacker can authenticate as any user to any SAML-federated application, bypassing multifactor authentication (MFA), conditional access, and all identity-based controls. However, during a recent red team engagement, Mandiant discovered that …

AppleCredential ExposureMicrosoftThreat ActorsThreat Intelligence
P0
2026-07-02 20:52 UTC
Vendor Research
TIER 1

ClamAV Vulnerabilities Affecting Cisco Products: July 2026

Cisco Security Advisories · indexed 2026-08-16 02:02 UTC

Multiple vulnerabilities in ClamAV could allow a remote attacker to cause a denial of service (DoS) condition, interrupting scanning operations. For more information about these vulnerabilities, see the Details section of this advisory. For additional information on these vulnerabilities in ClamAV, see the ClamAV blog. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. Notes: The Security Impact Rating (SIR) for these vulnerabilities is High for Windows-based platforms only because those platforms run the ClamAV…

LinuxMicrosoftVulnerabilities CVE-2026-20213CVE-2026-20214CVE-2026-20215CVE-2026-20216CVE-2026-20217CVE-2026-20243CVE-2026-20244
P5
2026-07-02 14:00 UTC
Vendor Research
TIER 2

Google’s Continued Disruption of Malicious Residential Proxy Networks

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-16 02:02 UTC

Background Today, in coordination with the FBI, Lumen, and others, Google took action against the NetNut residential proxy network, also known as Popa. This action builds on our disruption of the IPIDEA proxy network that took place in January 2026, and is a continuation of Google’s objective to dismantle malicious residential proxy networks. Actions Taken As a part of this disruption we took the following actions: Disabled Google accounts and associated Google services used by NetNut for malware command and control (C2), which directly violates Google’s Terms of Service and Acceptable Use Po…

APT / Nation-StateLaw EnforcementMalwareMicrosoftMobile SecurityNetwork SecurityThreat Intelligence
P0
2026-06-29 14:00 UTC
Vendor Research
TIER 2

The Bear Necessities: A Look at the Drivers, Dynamics, and Applications of the Pro-Russia Influence Ecosystem

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-16 02:02 UTC

Written by: James Sadowski, Alden Wahlstrom Introduction Four years into Russia’s full-scale invasion of Ukraine, the pro-Russia influence ecosystem has evolved from a tool of war back into a global strategic asset. Since the mobilization of this ecosystem to support frontline objectives, we have witnessed the expedited development of new influence assets linked to multiple, expansive, covert information operations (IO) campaigns and a revitalization of pro-Russia hacktivism at an unprecedented scale. While this threat activity initially adapted to encompass Ukraine-related priorities, it is …

APT / Nation-StateMicrosoft
P0
2026-06-25 14:00 UTC
Vendor Research
TIER 2

STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-16 02:02 UTC

Written by: Jordan Jones Introduction Google Threat Intelligence Group (GTIG) has conducted an in-depth analysis of a .NET backdoor, tracked as STOCKSTAY, that has been continually developed and deployed by the Russia-linked threat actor Turla (aka SUMMIT, Secret Blizzard, VENOMOUS BEAR, UAC-0194) since at least December 2022. Turla has deployed STOCKSTAY against government and military organizations in Ukraine, as well as entities with an interest in Italian foreign policy. Used for ongoing cyber espionage, this backdoor shares significant code and functional overlaps with KAZUAR, a successf…

APT / Nation-StateMalwareMicrosoftThreat ActorsThreat Intelligence
P0
2026-06-24 11:00 UTC
Vendor Research
TIER 2

Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-16 02:02 UTC

Written by: Chester Sng, Pete Boonyakarn, Logeswaran Nadarajan, Lukasz Lamparski Introduction In early 2026, Mandiant identified a threat actor targeting SD-WAN infrastructure at a service provider. After gaining initial access, the threat actor exploited a zero-day vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN to escalate privileges from a compromised administrative account to root-level access. The vulnerability stems from the device’s file upload feature lacking the ability to properly filter malicious data. Throughout the intrusion, to maintain operational security and avoid det…

Initial AccessMicrosoftNetwork SecurityThreat ActorsVulnerabilities CVE-2026-20127CVE-2026-20182CVE-2026-20245
P40
2026-06-15 14:00 UTC
Vendor Research
TIER 2

Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-16 02:02 UTC

Written by: Patrick Whitsell, John McGuiness, Muhammad Umair Google Threat Intelligence Group (GTIG) has identified a sophisticated campaign attributed to UNC6508, a People's Republic of China (PRC)-nexus threat actor, targeting institutions in the North American academic, medical, and military research community. While remaining undetected for over a year, the threat actor compromised externally facing web applications, deployed bespoke malware, pivoted to sensitive internal systems, and abused enterprise administrative tools for covert data exfiltration. The threat actor had broad collectio…

AI SecurityCloud SecurityDFIRInitial AccessMalwareMicrosoftPhishingThreat ActorsThreat Intelligence
P0
2026-06-11 14:00 UTC
Vendor Research
TIER 2

ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-16 02:02 UTC

Introduction Mandiant and Google Threat Intelligence Group (GTIG) have identified an active compromise and extortion campaign attributed to UNC6240 (ShinyHunters) targeting Oracle PeopleSoft application infrastructure. The activity was observed between May 27, 2026, and June 9, 2026 and is consistent with the exploitation of CVE-2026-35273, a critical remote code execution vulnerability (CVSS 9.8) in the Environment Management component. The exploitation of this vulnerability directly aligns with the observed targeting of Environment Management Hub (PSEMHUB) endpoints. Because this activity p…

AppleCloud SecurityData BreachesLinuxMicrosoftThreat ActorsThreat IntelligenceVulnerabilities CVE-2026-35273
P45
2026-06-10 06:47 UTC
Government
TIER 1

2026-007: Critical Vulnerability in Windows Netlogon

CERT-EU Security Advisories · indexed 2026-08-16 02:02 UTC

On 12 May 2026, Microsoft published a security advisory addressing a critical vulnerability affecting Windows Server when acting as a domain controller. This vulnerability allows an unauthenticated attacker to execute arbitrary code over a network. According to The Centre for Cybersecurity Belgium (CCB), this vulnerability is currently exploited by threat actors. It is strongly recommended updating affected Windows servers as soon as possible.

MicrosoftThreat ActorsVulnerabilities
P10
2026-06-09 14:19 UTC
Vendor Research
TIER 2

Microsoft’s June 2026 Patch Tuesday Addresses 198 CVEs ( CVE-2026-49160, CVE-2026-50507)

Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-08-16 02:02 UTC

32Critical166Important0Moderate0LowMicrosoft addresses 198 CVEs in the largest Patch Tuesday release, including three zero-days.Microsoft patched 198 CVEs in its June 2026 Patch Tuesday release, with 32 rated critical and 166 rated as important. Our counts omitted 6 CVEs that were already addressed by Microsoft via servicing and do not require additional customer action to resolve as well as 2 CVEs that were disclosed by other CNAs (CVE-2025-10263 and CVE-2026-8863). This Patch Tuesday release is the largest release since the Patch Tuesday program began, smashing the previous record of 167 CV…

Cloud SecurityLinuxMicrosoftMobile SecurityVulnerabilities CVE-2025-10263CVE-2026-33825CVE-2026-41091CVE-2026-42909CVE-2026-42913CVE-2026-42985CVE-2026-42992CVE-2026-42993CVE-2026-44799CVE-2026-44801CVE-2026-47289CVE-2026-47653CVE-2026-47654CVE-2026-48563CVE-2026-49160CVE-2026-50507CVE-2026-8863
P95
2026-06-05 14:00 UTC
Vendor Research
TIER 2

Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-16 02:02 UTC

Written by: Chad Reams, Tufail Ahmed, Keith Knapp, Ashley Frazer, Tyler McLellan Introduction From January through May 2026, Mandiant identified a financially motivated data theft extortion campaign executed by the threat cluster UNC3753 (also tracked as "Luna Moth," “Chatty Spider,” and "Silent Ransom Group") targeting dozens of organizations across professional, legal, and financial services in the United States. UNC3753 leverages voice phishing (vishing) and social engineering deception techniques to achieve remote access into corporate environments. Using pretexts such as data migration o…

Data BreachesDFIRInitial AccessMicrosoftPhishingThreat ActorsThreat Intelligence
P0
2026-05-29 13:56 UTC
Vendor Research
TIER 1

Microsoft Entra ID 1-Click Open Redirection via OAuth Error Handling Abuse

Tenable Research Advisories · Ben Smith · indexed 2026-08-16 02:02 UTC

Microsoft Entra ID 1-Click Open Redirection via OAuth Error Handling Abuse Researchers associated with Tenable have discovered new techniques to trigger 1-click open redirection attacks in Microsoft Entra ID by abusing the OAuth error-handling mechanism. The attack relies on an initial setup phase where a threat actor registers an OAuth application in an actor-controlled tenant and configures its redirect_uri to point to an attacker-controlled domain. When a victim clicks on a specifically crafted authorization link on the trusted login.microsoftonline.com domain, combinations of malformed pa…

AppleMalwareMicrosoftPhishingSecurity ResearchThreat Actors
P0
2026-05-25 14:00 UTC
Vendor Research
TIER 2

Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-16 02:02 UTC

Written by: Takahiro Sugiyama, Peter Revelant, Mathew Potaczek Introduction In late 2025, Mandiant responded to a security incident involving a compromised web server running KnowledgeDeliver. KnowledgeDeliver is a Learning Management System (LMS) developed by Digital Knowledge commonly used in Japan. Mandiant identified a critical vulnerability that allowed unauthenticated Remote Code Execution (RCE). An unknown threat actor leveraged this access to inject malicious code into the LMS platform, with the goal of infecting users visiting the site. This vulnerability stems from the use of identi…

AppleDFIRMalwareMicrosoftThreat ActorsThreat IntelligenceVulnerabilities CVE-2026-5426
P55
2026-05-15 14:00 UTC
Vendor Research
TIER 2

Welcome to BlackFile: Inside a Vishing Extortion Operation

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-16 02:02 UTC

Written by: Austin Larsen, Tyler McLellan, Genevieve Stark, Dan Ebreo Introduction Google Threat Intelligence Group (GTIG) has continued to track an expansive extortion campaign by UNC6671, a threat actor operating under the "BlackFile" brand, that targets organizations via sophisticated voice phishing (vishing) and single sign-on (SSO) compromise. By leveraging adversary-in-the-middle (AiTM) techniques to bypass traditional perimeter defenses and multi-factor authentication (MFA), UNC6671 gains deep access to cloud environments. The group primarily targets Microsoft 365 and Okta infrastructu…

Data BreachesInitial AccessMicrosoftNetwork SecurityPhishingThreat ActorsThreat IntelligenceVulnerabilities
P0
2026-05-11 14:00 UTC
Vendor Research
TIER 2

GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-16 02:02 UTC

Executive Summary Since our February 2026 report on AI-related threat activity, Google Threat Intelligence Group (GTIG) has continued to track a maturing transition from nascent AI-enabled operations to the industrial-scale application of generative models within adversarial workflows. This report, based on insights derived from Mandiant incident response engagements, Gemini, and GTIG’s proactive research, highlights the dual nature of the current threat environment where AI serves as both a sophisticated engine for adversary operations and a high-value target for attacks. We explore the foll…

AI SecurityAppleAPT / Nation-StateCloud SecurityDFIRInitial AccessMalwareMicrosoftNetwork SecurityRansomwareSecurity ResearchThreat ActorsThreat IntelligenceVulnerabilities
P60
2026-04-23 14:00 UTC
Vendor Research
TIER 2

Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-16 02:02 UTC

Written by: JP Glab, Tufail Ahmed, Josh Kelley, Muhammad Umair Introduction Google Threat Intelligence Group (GTIG) identified a multistage intrusion campaign by a newly tracked threat group, UNC6692, that leveraged persistent social engineering, a custom modular malware suite, and deft pivoting inside the victim’s environment to achieve deep network penetration. As with many other intrusions in recent years, UNC6692 relied heavily on impersonating IT helpdesk employees, convincing their victim to accept a Microsoft Teams chat invitation from an account outside their organization. The UNC6692…

Cloud SecurityInitial AccessMalwareMicrosoftPhishingThreat ActorsThreat Intelligence
P0
2026-04-16 14:00 UTC
Vendor Research
TIER 2

Defending Your Enterprise When AI Models Can Find Vulnerabilities Faster Than Ever

Google Threat Intelligence / Mandiant · Francis deSouza · indexed 2026-08-16 02:02 UTC

Introduction Advances in AI model-powered exploitation have demonstrated that general-purpose AI models can excel at vulnerability discovery, even without being purpose-built for the task. Eventually, capabilities such as these will be integrated directly into the development cycle, and code will be more difficult to exploit than ever; however, this transition creates a critical window of risk. As we harden existing software with AI, threat actors will use it to discover and exploit novel vulnerabilities. Faced with this scenario, defenders have two critical tasks: hardening the software we u…

AI SecurityAPT / Nation-StateCloud SecurityDFIRMicrosoftRansomwareThreat Actor ChatterThreat ActorsUnderground IntelligenceVulnerabilities
P60
2026-04-09 19:25 UTC
Vendor Research
TIER 2

Protecting Cookies with Device Bound Session Credentials

Google Security Blog · Benjamin Ackerman · indexed 2026-08-16 02:02 UTC

Following our April 2024 announcement, Device Bound Session Credentials (DBSC) is now entering public availability for Windows users on Chrome 146, and expanding to macO…

Microsoft
P0
2026-03-25 07:51 UTC
Government
TIER 1

2026-004: Critical Vulnerability in SharePoint Exploited

CERT-EU Security Advisories · indexed 2026-08-16 02:02 UTC

On 17 March 2026, Microsoft updated one of its January 2026 security advisories related to a remote code execution vulnerability in Microsoft SharePoint. Specifically, Microsoft raised the CVSS score and changed the FAQ section to indicate that the vulnerability could be exploited by an unauthenticated attacker. This vulnerability was added in the CISA's Known Exploited Vulnerabilities (KEV) catalogue on 18 March 2026. Additionally, three further RCE flaws affecting Microsoft SharePoint were addressed in the March 2026 release. CERT-EU strongly recommends updating SharePoint servers as soon a…

Cloud SecurityMicrosoftVulnerabilities
P55
123