CYBERSECURITY INTEL FREE'Dself-hosted CTI

LATEST // SURFACE WEB

Aggregated cybersecurity reporting, advisories and research. 406 matching records.
AUTO-POLL // 2026-08-16 06:20 UTC
SURFACE WEB DARK / DEEP WEB
RESET
2026-07-30 01:00 UTC
Security Journalism
TIER 3

SE Asian Cybercriminal Syndicates Become a Global Power

Dark Reading · Robert Lemos · indexed 2026-08-16 02:02 UTC

The organized crime groups have moved from goods to services and continue to traffic people from at least 80 countries, costing nations in the region at least $88 billion in 2025 alone.

P0
2026-07-29 21:00 UTC
Vendor Research
TIER 2

Amazon identifies North Korean hacker group behind open-source supply chain attacks

AWS Security Blog · CJ Moses · indexed 2026-08-16 02:02 UTC

Amazon is sharing new findings about how a threat actor linked to the Democratic People’s Republic of Korea (DPRK) is targeting open source software libraries, the shared building blocks that companies around the world use to develop applications. Amazon Threat Intelligence has linked several recent compromises of popular Node Package Manager (NPM) libraries to the […]

Threat ActorsThreat Intelligence
P0
2026-07-29 16:16 UTC
Vendor Research
TIER 2

CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity

Rapid7 · Rapid7 · indexed 2026-08-16 02:02 UTC

OverviewOn July 27, 2026, JetBrains published a security advisory for CVE-2026-63077, a critical unauthenticated vulnerability affecting all versions of TeamCity On-Premises. The issue is classified as deserialization of untrusted data and has a CVSS score of 9.8. An unauthenticated remote attacker with HTTP(S) access to a TeamCity server can exploit the agent polling protocol to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process.In the blog post that JetBrains shared in tandem with CVE publication, they stated that …

Vulnerabilities CVE-2026-63077
P50
2026-07-29 16:00 UTC
Vendor Research
TIER 2

​​Better security starts with better questions

Microsoft Security Blog · Aarti Borkar · indexed 2026-08-16 02:02 UTC

Learn how better questions, trusted AI, and human judgment help security leaders make confident decisions and build resilient systems. The post ​​Better security starts with better questions appeared first on Microsoft Security Blog.

Microsoft
P0
2026-07-29 14:53 UTC
Vendor Research
TIER 2

Secure your npm and pip package updates in Amazon Linux

AWS Security Blog · Norbert Manthey · indexed 2026-08-16 02:02 UTC

If you use and install packages from npm or PyPI, the first hours after a package is published are the riskiest because scanners can’t analyze packages before publication. Recent supply chain events affecting NodeJS and Python packages have been detected and removed within hours. However, while those packages were available to the general public, it’s […]

Linux
P0
2026-07-29 13:00 UTC
Vendor Research
TIER 2

How AI is Rewriting the Zero-Day Playbook for Preemptive Security

Rapid7 · Joel Alcon · indexed 2026-08-16 02:02 UTC

The scenario is all too familiar for any cybersecurity professional: It’s late in the day, and a critical zero-day vulnerability is disclosed. When this happens, CISOs from every industry immediately turn to their Security Operations Centers (SOC) with the single most important, and often most difficult, question: "Are we exposed?”Answering questions like these when zero-days drop tends to trigger a frantic, high-stress fire drill. Analysts scramble to cross-reference outdated Configuration Management Databases (CMDBs), query disparate endpoint detection tools, and ping IT administrators. The…

DFIRVulnerabilities
P45
2026-07-29 06:40 UTC
Vendor Research
TIER 1

Link Library - Reflected Cross-Site Scripting

Tenable Research Advisories · Joshua Martinelle · indexed 2026-08-16 02:02 UTC

Link Library - Reflected Cross-Site Scripting The WordPress Plugin Link Library version below 7.9.4 is affected by an unauthenticated Reflected XSS.The 'thumbs_rating_add_vote' AJAX handler reads the 'likelabel' parameter without any sanitization and echoes it back into an HTML response. Joshua Martinelle Wed, 07/29/2026 - 02:40

P0
2026-07-29 03:19 UTC
Vendor Research
TIER 2

Coordinated "cyberattack" on U.S. water utilities: What you need to know

Tenable Blog · Research Special Operations · indexed 2026-08-16 02:02 UTC

A coordinated cyber attack disrupted water and wastewater systems in at least 12 U.S. states, including more than 30 Minnesota communities. Here is what defenders need to know about the attack so far. This FAQ also details recent cyberactivity targeting internet-exposed PLCs, and how to protect exposed infrastructure.Change logUpdate August 10: Added Columbus Water Works as a second confirmed Georgia victim. Added a table summarizing publicly confirmed affected entities to date.This is an active situation. Tenable's Research Special Operations team is monitoring developments and will update t…

DFIRICS / OTLaw EnforcementMalwareMicrosoftThreat IntelligenceVulnerabilities CVE-2021-22681
P45
2026-07-28 18:55 UTC
Vendor Research
TIER 2

AWS KMS or AWS CloudHSM: Choose the right key management solution

AWS Security Blog · Derek Tumulak · indexed 2026-08-16 02:02 UTC

Choosing the right cryptographic key management service on Amazon Web Services (AWS) starts with understanding the difference between AWS Key Management Service (AWS KMS) and AWS CloudHSM. Both provide key storage backed by a hardware security module (HSM) but serve very different needs. AWS KMS is a fully managed service that integrates with all AWS […]

Cloud Security
P0
2026-07-28 18:32 UTC
Vendor Research
TIER 2

Rapid7 Analysis: Check Point SmartConsole Authentication Bypass (CVE-2026-16232)

Rapid7 · Stephen Fewer · indexed 2026-08-16 02:02 UTC

OverviewOn July 22, 2026, Check Point published a security advisory for CVE-2026-16232, an authentication bypass in the SmartConsole login process affecting Security Management Server and Multi-Domain Security Management Server (MDS). By leveraging CVE-2026-16232, an unauthenticated attacker can obtain an application login token, use this token to log in through SmartConsole with full administrator privileges, and modify the security policy or security configuration. Exploitation requires network access to the Management Server and for a Trusted Clients configuration that does not restrict GU…

MicrosoftVulnerabilities CVE-2026-16232
P60
2026-07-28 13:00 UTC
Vendor Research
TIER 2

Rapid7 Cyber GRC is now available: Turn security action into compliance proof

Rapid7 · Michael Chroney · indexed 2026-08-16 02:02 UTC

Compliance has become one of the biggest operational drains on modern security teams. CISOs are being asked to manage a growing sprawl of frameworks, prove control effectiveness more often, respond to more customer assurance requests, track risk across a growing web of third parties, and give executives and the board a clearer answer on whether cyber risk is actually going down.Most of that pressure does not come from the frameworks themselves. It comes from the way compliance is still handled in many organizations, with security work happening in one set of tools and governance, risk, and co…

P0
2026-07-28 13:00 UTC
Vendor Research
TIER 2

The Next Evolution of MDR: Preemptive Defense and Agentic Investigation

Rapid7 · Mikayla Wyman · indexed 2026-08-16 02:02 UTC

For years, security operations followed a familiar sequence: detect suspicious activity, investigate what happened, and respond before it caused significant harm. That model developed in a threat landscape where defenders had considerably more time to establish the facts and decide what to do next. In 2019, the average data breach took 206 days to identify and another 73 days to contain, creating a total breach lifecycle of 279 days.As the time between initial access and attacker movement continues to contract, security teams are being asked to operate within a much narrower window. AI is acc…

AI SecurityCredential ExposureCybercrimeData BreachesDFIRInitial AccessMicrosoftThreat IntelligenceVulnerabilities
P0
2026-07-24 14:00 UTC
Vendor Research
TIER 2

Updated Cyber Threat Actor Naming System

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-16 02:02 UTC

Update (July 30): A table listing the new names of select prominent threat actors was appended to this post. Introduction Today, Google Threat Intelligence Group (GTIG) will begin rolling out a unified naming schema for tracking threat actors. This new naming taxonomy represents an effort to standardize tracking across platforms and public reporting. Why are we Adopting a Different Naming System? Historically, Mandiant and Google’s Threat Analysis Group (TAG) maintained distinct tracking systems, relying on parallel naming schemas that grew independently over time. The creation of GTIG has ne…

AppleAPT / Nation-StateDFIRMicrosoftThreat ActorsThreat Intelligence
P0
2026-07-23 18:00 UTC
Vendor Research
TIER 2

Don’t swing at everything

Cisco Talos Intelligence Blog · Thorsten Rosendahl · indexed 2026-08-16 02:02 UTC

Thorsten explores Q2 2026 stats, the artificial buffer zone of 2026, and why smart, prioritized patching is more critical than ever.

P0
2026-07-23 14:10 UTC
Vendor Research
TIER 2

Russian Global Webmail Espionage

Palo Alto Networks Unit 42 · Unit 42 · indexed 2026-08-16 02:02 UTC

Unit 42 details a Russian cyberespionage campaign targeting Zimbra webmail servers using JavaScript injection to steal credentials. The post Russian Global Webmail Espionage appeared first on Unit 42.

APT / Nation-State
P0
2026-07-23 10:00 UTC
Vendor Research
TIER 2

Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel

Cisco Talos Intelligence Blog · Jordyn Dunk · indexed 2026-08-16 02:02 UTC

The Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker's IP from victims via WebRTC over TURN.

MalwareRansomware
P15
2026-07-23 10:00 UTC
Vendor Research
TIER 2

Preview: Cisco Talos at Black Hat USA 2026

Cisco Talos Intelligence Blog · Mitch Neff · indexed 2026-08-16 02:02 UTC

Here’s some of the ways Talos is showing up at Black Hat, alongside our friends at Cisco and Splunk.

P0
2026-07-23 07:13 UTC
Government
TIER 1

2026-009: Critical Vulnerabilities in Microsoft SharePoint

CERT-EU Security Advisories · indexed 2026-08-16 02:02 UTC

[UPDATED] On 14 July 2026, Microsoft released security updates addressing critical remote code execution (RCE) vulnerabilities in Microsoft SharePoint Server. On 20 July 2026, WatchTowr identified a proof-of-concept exploit code and subsequently observed active exploitation of CVE-2026-50522, a vulnerability part of an ongoing series of actively exploited flaws affecting on-premise SharePoint Server instances, including CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644. CERT-EU strongly recommends updating affected servers immediately, rotating credentials for any assets that…

Cloud SecurityCredential ExposureMicrosoftVulnerabilities CVE-2026-32201CVE-2026-45659CVE-2026-50522CVE-2026-56164CVE-2026-58644
P45
2026-07-22 01:10 UTC
Independent Research
TIER 2

LG to Ban Residential Proxies from Smart TV Apps

Krebs on Security · BrianKrebs · indexed 2026-08-16 02:02 UTC

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG's webOS store allow unknown third-parties to route their Internet traffic through a user's TV.

P0
2026-07-21 21:07 UTC
Vendor Research
TIER 2

Oracle July 2026 Critical Patch Update Addresses 1235 CVEs

Tenable Blog · Research Special Operations · indexed 2026-08-16 02:02 UTC

Oracle addresses 1235 CVEs in its third quarterly update of 2026 with 1449 patches, including 261 critical updates.Key TakeawaysThe third Critical Patch Update (CPU) for 2026 contains fixes for 1235 unique CVEs in 1449 security updates, the largest CPU release.261 issues (18% of all patches) were assigned a critical severity ratingOracle E-Business Suite received the highest number of patches at 410, accounting for 28.3% of all patchesBackgroundOn July 21, Oracle released its Critical Patch Update (CPU) for July 2026, the third quarterly update of the year. This CPU contains fixes for 1235 un…

P5
2026-07-21 16:01 UTC
Vendor Research
TIER 1

Cisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager, and Catalyst SD-WAN Validator Authenticated Privilege Escalation Vulnerability

Cisco Security Advisories · indexed 2026-08-16 02:02 UTC

A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by uploading a crafted file to the affected system. A successful exploit could allow the attacker to perform command injection attacks on …

Vulnerabilities CVE-2026-20127CVE-2026-20182CVE-2026-20245
P15
2026-07-20 15:47 UTC
Vendor Research
TIER 1

Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities

Cisco Security Advisories · indexed 2026-08-16 02:02 UTC

Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) guest portals could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit these vulnerabilities by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the a…

Vulnerabilities CVE-2025-20204CVE-2025-20205
P5
2026-07-20 09:36 UTC
Vendor Research
TIER 2

wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core

Tenable Cyber Exposure Alerts · Satnam Narang · indexed 2026-08-16 02:02 UTC

An unauthenticated attacker can chain two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to achieve remote code execution against affected WordPress installations. Multiple security firms have confirmed active in-the-wild exploitation within days of public disclosure, and public proof-of-concept exploits are circulating.Key takeaways:Two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, can be chained together to achieve pre-authentication remote code execution against WordPress 6.9.x and 7.0.x installations. Multiple security firms have confirmed in-the-w…

Cloud SecurityDFIRMicrosoftNetwork SecurityRansomwareSecurity ResearchThreat ActorsThreat IntelligenceVulnerabilities CVE-2026-60137CVE-2026-601377CVE-2026-63030
P70
2026-07-17 10:00 UTC
Vendor Research
TIER 2

Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy

Palo Alto Networks Unit 42 · Emmanuel Zhou, Adam Robbie, Rick Wyble and Miguel Pereira · indexed 2026-08-16 02:02 UTC

A technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and persistent root access. The post Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy appeared first on Unit 42.

Network SecurityVulnerabilities
P35
2026-07-16 23:00 UTC
Vendor Research
TIER 2

AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report

Palo Alto Networks Unit 42 · Ria Bhatia · indexed 2026-08-16 02:02 UTC

Explore Unit 42's perspectives on AI's impact on cybersecurity, including key updates since the 2026 Incident Response Report. The post AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report appeared first on Unit 42.

DFIR
P0
2026-07-16 18:00 UTC
Vendor Research
TIER 2

Begun, the Patch Wars have

Cisco Talos Intelligence Blog · Joe Marshall · indexed 2026-08-16 02:02 UTC

Long foretold, the Great Patching has begun and it’s a doozy. Buckle in as Joe takes you through the story.

P0
2026-07-16 14:00 UTC
Vendor Research
TIER 2

Demystifying AI Exploits: A Blueprint for AI-Assisted Vulnerability Management

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-16 02:02 UTC

Written by: Jules Czarniak Introduction As highlighted in the Mandiant M-Trends 2026 report, the mean time-to-exploit (TTE) has dropped to -7 days, meaning vulnerabilities are often exploited a week before a patch even exists. To keep pace, many security teams are exploring how to integrate large language model (LLM) agents into their codebases, development environments and continuous integration and continuous delivery (CI/CD) pipelines for automated vulnerability discovery and remediation. However, deploying privileged artificial intelligence (AI) agents without mature integration processes…

AI SecurityAppleMicrosoftThreat ActorsThreat IntelligenceVulnerabilities
P10
7891011