CYBERSECURITY INTEL FREE'Dself-hosted CTI

LATEST // SURFACE WEB

Aggregated cybersecurity reporting, advisories and research. 406 matching records.
AUTO-POLL // 2026-08-16 07:10 UTC
SURFACE WEB DARK / DEEP WEB
RESET
2026-07-16 12:00 UTC
Vendor Research
TIER 2

CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities

Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-08-16 02:02 UTC

Four Microsoft SharePoint Server vulnerabilities are under active exploitation, prompting CISA to issue a hardening alert. An additional high-severity flaw recently patched adds pressure for organizations running on-premises deployments.Key TakeawaysCISA confirmed active exploitation of three on-premises SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164), used to gain unauthorized access, establish remote code execution, steal IIS machine keys and deploy malware for persistence.Two additional SharePoint Server vulnerabilities disclosed on July 14, 2026, CVE-202…

Cloud SecurityMalwareMicrosoftRansomwareThreat ActorsVulnerabilities CVE-2026-32201CVE-2026-45659CVE-2026-55040CVE-2026-56164CVE-2026-58644
P95
2026-07-16 10:00 UTC
Vendor Research
TIER 2

The Hunter's Paradox: Is it time to embrace automated threat hunting?

Cisco Talos Intelligence Blog · David J. Bianco · indexed 2026-08-16 02:02 UTC

Humans can no longer keep up with the volume and velocity of security data on their own, but AI can't be fully trusted. David discusses the merits of both and muses on what the future might look like.

P0
2026-07-15 23:00 UTC
Vendor Research
TIER 2

The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15)

Palo Alto Networks Unit 42 · Unit 42 · indexed 2026-08-16 02:02 UTC

Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. The post The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15) appeared first on Unit 42.

Malware
P15
2026-07-15 16:01 UTC
Vendor Research
TIER 1

Cisco Advance Notification for Publication of July 15, 2026, Security Advisories

Cisco Security Advisories · indexed 2026-08-16 02:02 UTC

On July 15, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE ID Security Impact Rating CVSS Base Score Cisco RoomOS Security Hardening Release: July 2026 CVE-2026-20150CVE-2026-20153CVE-2026-20156CVE-2026-20157CVE-2026-20158CVE-2026-20187 High 8.8 Cisco Identity Services Engine Path Traversal Vulnerability CVE-2026-20146 Medium 5.5 To fully remediate the vulnerabilities that were disclosed on July 15, 2026, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the advisories. F…

DFIRVulnerabilities CVE-2026-20146
P5
2026-07-15 16:00 UTC
Vendor Research
TIER 1

Cisco RoomOS Security Hardening Release: July 2026

Cisco Security Advisories · indexed 2026-08-16 02:02 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and to streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class — Common Weakness Enumeration (CWE) — and assigned a single Common…

Vulnerabilities CVE-2026-20150CVE-2026-20153CVE-2026-20156CVE-2026-20157CVE-2026-20158CVE-2026-20187
P30
2026-07-15 16:00 UTC
Vendor Research
TIER 1

Cisco Identity Services Engine Path Traversal Vulnerability

Cisco Security Advisories · indexed 2026-08-16 02:02 UTC

A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files …

Vulnerabilities CVE-2026-20146
P5
2026-07-15 14:00 UTC
Vendor Research
TIER 2

The Risk of Exposed Cloud Functions and How to Harden

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-16 02:02 UTC

Written by: Corné de Jong Introduction Mandiant security assessments frequently identify publicly exposed serverless applications that lack authentication, often as a result of specific business requirements. Serverless deployments typically run custom-developed code that incorporates third-party packages, making them targets for a wide range of application-level attacks, including: Local and Remote File Inclusion (LFI/RFI) Command Injection Successful exploitation of these vulnerabilities can grant an attacker full control over the underlying container instance. Such access can serve as a fo…

AI SecurityAppleCloud SecurityInitial AccessMalwareThreat ActorsVulnerabilities
P15
2026-07-15 13:14 UTC
Vendor Research
TIER 2

CVE-2026-15409, CVE-2026-15410: SonicWall SMA 1000 zero-day vulnerabilities exploited in the wild

Tenable Cyber Exposure Alerts · Scott Caveza · indexed 2026-08-16 02:02 UTC

SonicWall patched two recently exploited zero-day vulnerabilities in its SMA 1000 Series secure remote access appliances which may have been chained for unauthenticated remote code execution.Key takeawaysCVE-2026-15409 and CVE-2026-15410 are a pair of exploited vulnerabilities that may have been chained together to allow for code execution on SonicWall SMA1000 series appliances. Zero-day exploitation of these vulnerabilities has been observed and confirmed by SonicWall. Patches and indicators of compromise are available and urgent patching is recommended.BackgroundSonicWall's Secure Mobile Ac…

Cloud SecurityNetwork SecurityRansomwareSecurity ResearchThreat ActorsThreat IntelligenceVulnerabilities CVE-2026-15409CVE-2026-15410
P100
2026-07-15 10:00 UTC
Vendor Research
TIER 2

TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development

Palo Alto Networks Unit 42 · Chris Navarrete, Asher Davila and Doel Santos · indexed 2026-08-16 02:02 UTC

TuxBot v3 Evolution, an IoT botnet framework built with LLMs. Read our analysis of its cross-compiled binaries, C2 architecture and bugs. The post TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development appeared first on Unit 42.

AI SecurityMalware
P0
2026-07-14 19:22 UTC
Independent Research
TIER 2

Microsoft Patches a Record 570 Security Flaws

Krebs on Security · BrianKrebs · indexed 2026-08-16 02:02 UTC

Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.

AI SecurityCloud SecurityMicrosoftVulnerabilities
P0
2026-07-14 14:23 UTC
Vendor Research
TIER 2

Microsoft’s July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164)

Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-08-16 02:02 UTC

56Critical510Important3Moderate0LowMicrosoft addresses 569 CVEs in the largest Patch Tuesday release yet. This month’s release includes three zero-days, two of which were exploited in the wild.Microsoft patched 569 CVEs in its July 2026 Patch Tuesday release, with 56 rated critical, 510 rated as important, and 3 rated as moderate. This marks the largest Patch Tuesday release ever, crushing the previous record of 198 CVEs in June. Last week, Microsoft announced that its multi-model agentic scanning harness (MDASH) is being used to identify vulnerabilities faster and noted that “customers will …

AppleCloud SecurityLinuxMalwareMicrosoftMobile SecurityNetwork SecurityVulnerabilities CVE-2026-56155CVE-2026-56164
P65
2026-07-13 15:03 UTC
Independent Research
TIER 2

Lessons Learned from CISA’s Recent GitHub Leak

Krebs on Security · BrianKrebs · indexed 2026-08-16 02:02 UTC

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almost six months before being notified by KrebsOnSecurity. Experts say the gaps identified in the agency's initial response provide important lessons that all security teams should absorb.

Cloud SecurityData Breaches
P0
2026-07-09 14:00 UTC
Vendor Research
TIER 2

Why we cannot wait for better post-quantum signature algorithms

Cloudflare Security · Bas Westerbaan · indexed 2026-08-16 02:02 UTC

NIST is advancing nine new post-quantum signature algorithms as potential candidates for future standardization. We take a closer look at all of them, and argue that while they are in the works and show great potential, we should use ML-DSA for now — the best currently available.

P0
2026-07-08 12:31 UTC
Independent Research
TIER 2

Felons, Fraudsters Flog Offensive Cybersecurity Startup

Krebs on Security · BrianKrebs · indexed 2026-08-16 02:02 UTC

A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names.

CybercrimeVulnerabilities
P25
2026-07-07 14:00 UTC
Vendor Research
TIER 2

The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-16 02:02 UTC

Written by: Shebin Mathew Introduction The "Golden SAML" technique, first described by CyberArk researchers in 2017, and further detailed by Mandiant researchers in 2021, remains one of the most effective methods for threat actors to forge identity assertions in the Microsoft ecosystem. By obtaining the private key of an ADFS token-signing certificate, an attacker can authenticate as any user to any SAML-federated application, bypassing multifactor authentication (MFA), conditional access, and all identity-based controls. However, during a recent red team engagement, Mandiant discovered that …

AppleCredential ExposureMicrosoftThreat ActorsThreat Intelligence
P0
2026-07-06 19:20 UTC
Vendor Research
TIER 1

Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities

Cisco Security Advisories · indexed 2026-08-16 02:02 UTC

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to achieve remote code execution or conduct information disclosure attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cis…

Vulnerabilities CVE-2026-20181CVE-2026-20190
P20
2026-07-06 12:00 UTC
Vendor Research
TIER 1

Cisco Catalyst Center Arbitrary File Read Vulnerability

Cisco Security Advisories · indexed 2026-08-16 02:02 UTC

A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to read arbitrary files from a restricted container of the affected device. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at…

Vulnerabilities CVE-2026-20191
P5
2026-07-02 20:52 UTC
Vendor Research
TIER 1

ClamAV Vulnerabilities Affecting Cisco Products: July 2026

Cisco Security Advisories · indexed 2026-08-16 02:02 UTC

Multiple vulnerabilities in ClamAV could allow a remote attacker to cause a denial of service (DoS) condition, interrupting scanning operations. For more information about these vulnerabilities, see the Details section of this advisory. For additional information on these vulnerabilities in ClamAV, see the ClamAV blog. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. Notes: The Security Impact Rating (SIR) for these vulnerabilities is High for Windows-based platforms only because those platforms run the ClamAV…

LinuxMicrosoftVulnerabilities CVE-2026-20213CVE-2026-20214CVE-2026-20215CVE-2026-20216CVE-2026-20217CVE-2026-20243CVE-2026-20244
P5
2026-07-02 19:27 UTC
Independent Research
TIER 2

FBI Seizes NetNut Proxy Platform, Popa Botnet

Krebs on Security · BrianKrebs · indexed 2026-08-16 02:02 UTC

The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes roughly two weeks after KrebsOnSecurity published findings from multiple security firms connecting NetNut to the Popa botnet, a collection of at least two million devices that have been compromised by malicious software with little or no consent from victims.

DFIRLaw EnforcementMalware
P0
2026-07-02 14:00 UTC
Vendor Research
TIER 2

Google’s Continued Disruption of Malicious Residential Proxy Networks

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-16 02:02 UTC

Background Today, in coordination with the FBI, Lumen, and others, Google took action against the NetNut residential proxy network, also known as Popa. This action builds on our disruption of the IPIDEA proxy network that took place in January 2026, and is a continuation of Google’s objective to dismantle malicious residential proxy networks. Actions Taken As a part of this disruption we took the following actions: Disabled Google accounts and associated Google services used by NetNut for malware command and control (C2), which directly violates Google’s Terms of Service and Acceptable Use Po…

APT / Nation-StateLaw EnforcementMalwareMicrosoftMobile SecurityNetwork SecurityThreat Intelligence
P0
2026-07-01 16:01 UTC
Vendor Research
TIER 1

Cisco Advance Notification for Publication of July 1, 2026, Security Advisories

Cisco Security Advisories · indexed 2026-08-16 02:02 UTC

On July 1, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE-ID Security Impact Rating CVSS Base Score Cisco Catalyst Center Arbitrary File Read Vulnerability CVE-2026-20191 High 7.5 ClamAV Vulnerabilities Affecting Cisco Products: July 2026 CVE-2026-20216CVE-2026-20213CVE-2026-20214CVE-2026-20215CVE-2026-20217CVE-2026-20243CVE-2026-20244 High 7.5 To fully remediate the vulnerabilities that were disclosed on July 1, 2026, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the…

DFIRVulnerabilities CVE-2026-20191
P5
2026-07-01 15:10 UTC
Vendor Research
TIER 1

Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability

Cisco Security Advisories · indexed 2026-08-16 02:02 UTC

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to write files to the underlying operating system that could be used later to elevat…

Vulnerabilities CVE-2026-20230
P5
2026-07-01 14:00 UTC
Government
TIER 1

Cyber Brief 26-07 - June 2026

CERT-EU Threat Intelligence · indexed 2026-08-16 02:02 UTC

Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.

P0
2026-07-01 06:00 UTC
Vendor Research
TIER 2

Unmasking the crawls with Attribution Business Insights

Cloudflare Security · Jin-Hee Lee · indexed 2026-08-16 02:02 UTC

Cloudflare’s new Attribution Business Insights dashboard helps website owners understand crawler behavior, appetite, and potential value, fueling business-level conversations around crawl compensation.

P0
2026-06-29 14:00 UTC
Vendor Research
TIER 2

The Bear Necessities: A Look at the Drivers, Dynamics, and Applications of the Pro-Russia Influence Ecosystem

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-16 02:02 UTC

Written by: James Sadowski, Alden Wahlstrom Introduction Four years into Russia’s full-scale invasion of Ukraine, the pro-Russia influence ecosystem has evolved from a tool of war back into a global strategic asset. Since the mobilization of this ecosystem to support frontline objectives, we have witnessed the expedited development of new influence assets linked to multiple, expansive, covert information operations (IO) campaigns and a revitalization of pro-Russia hacktivism at an unprecedented scale. While this threat activity initially adapted to encompass Ukraine-related priorities, it is …

APT / Nation-StateMicrosoft
P0
2026-06-25 14:31 UTC
Vendor Research
TIER 1

Cisco Finesse Remote File Inclusion Vulnerability

Cisco Security Advisories · indexed 2026-08-16 02:02 UTC

A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to load arbitrary files from remote locations into an active user session on an affected device, possibly leading to browser-based attacks. This vulnerability is due to insufficient validation of user-supplied input for HTTP requests that are sent to an affected device. An attacker who has knowledge of the address of the affected device could exploit this vulnerability by persuading a user to click a crafted link that contains the affected device address. A successful exploit could allow the attacker to conduct b…

Vulnerabilities CVE-2026-20175
P5
2026-06-25 14:00 UTC
Vendor Research
TIER 2

STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-16 02:02 UTC

Written by: Jordan Jones Introduction Google Threat Intelligence Group (GTIG) has conducted an in-depth analysis of a .NET backdoor, tracked as STOCKSTAY, that has been continually developed and deployed by the Russia-linked threat actor Turla (aka SUMMIT, Secret Blizzard, VENOMOUS BEAR, UAC-0194) since at least December 2022. Turla has deployed STOCKSTAY against government and military organizations in Ukraine, as well as entities with an interest in Italian foreign policy. Used for ongoing cyber espionage, this backdoor shares significant code and functional overlaps with KAZUAR, a successf…

APT / Nation-StateMalwareMicrosoftThreat ActorsThreat Intelligence
P0
2026-06-24 11:00 UTC
Vendor Research
TIER 2

Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-16 02:02 UTC

Written by: Chester Sng, Pete Boonyakarn, Logeswaran Nadarajan, Lukasz Lamparski Introduction In early 2026, Mandiant identified a threat actor targeting SD-WAN infrastructure at a service provider. After gaining initial access, the threat actor exploited a zero-day vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN to escalate privileges from a compromised administrative account to root-level access. The vulnerability stems from the device’s file upload feature lacking the ability to properly filter malicious data. Throughout the intrusion, to maintain operational security and avoid det…

Initial AccessMicrosoftNetwork SecurityThreat ActorsVulnerabilities CVE-2026-20127CVE-2026-20182CVE-2026-20245
P40
2026-06-24 06:00 UTC
Vendor Research
TIER 2

Unlocking the Cloudflare app ecosystem with OAuth for all

Cloudflare Security · Sam Cabell · indexed 2026-08-16 02:02 UTC

Self-Managed OAuth is now available to all developers on Cloudflare. Here's how we executed a zero-downtime migration of our core OAuth engine to make it happen.

P0
89101112