Home Cyber Threat Intelligence Mobile Version
Alert Details

Cisco  New

Cisco has published 4 new bulletins, 1 rated Critical and 3 rated Medium. The Critical bulletin identifies static SSH Credentials for root in Unified Communications Manager. CVSSv3 score of 10.

More...

Mitsubishi Electric  New

A DoS vulnerability exists in MELSEC iQ-F series that allows a remote attacker to lockout a legitimate user for a certain period of time by repeatedly attempting to login with an incorrect password. CVSSv3 score of 5.3

More...

Mitsubishi Electric  New

Arbitrary code execution vulnerabilities in 7-Zip allows a remote attacker to execute arbitrary malicious code by getting 7-Zip, which is included in MELSOFT Update Manager, to decompress a specially crafted compressed file. Highest CVSSv3 score of 8.1

More...

Endress+Hauser  New

Several vulnerabilities in the Endress+Hauser MEAC300-FNADE4 were discovered that can be accessed via Ethernet. Highest CVSSv3 score of 8.6

More...

Mozilla  New

Mozilla has published a bulletin rated High for Thunderbird.

More...

Dell  New

Dell has published a Critical bulletin for Integrated System for Microsoft Azure Stack Hub.

More...

Microsoft  Exploit

Microsoft has updated Edge with the latest chromium vulnerabilities. Exploits are in the wild.

More...

Festo  

FESTO Hardware Controller and Hardware Servo Press Kit contain several vulnerabilities that could allow a remote attacker to execute unauthorized system commands with root privileges. Highest CVSSv3 score of 9.8

More...

Festo  

FESTO and FESTO Didactic CIROS Studio / Education, Automation Suite, FluidDraw, FluidSIM, and MES-PC contain a vulnerability that allows a remote attacker to gain full control of the host system, including remote code execution. CVSSv3 score of 9.8

More...

Voltronic Power  

Voltronic Power Viewpower and PowerShield NetGuard contain vulnerabilities that allows a remote attacker to make configuration changes, resulting in shutting down UPS connected devices or execution of arbitrary code. CVSSv3 score of 9.8

More...

Contec  

Contec has identified several vulnerabilities in its CHS Web HMI/SCADA software that allows a remote attacker to steal and tamper with data, execute malicious programs that could result in destruction of the system, and deactivate of certain function. Highest CVSSv3 score of 6.1

More...

ModSecurity  

In ModSecurity, if the variable SecParseXmlIntoArgs is set to On or OnlyArgs, and the request type is application/xml, and at least one XML tag is empty then a segmentation fault occurs. CVSSv3 score of 6.5

More...

IBM  

IBM has published Critical bulletins for Business Automation Workflow, Cloud Pak for Data, and PowerVC.

More...

Linux  

Updates for Red Hat and AlmaLinux.

More...

Alert State
Cisco MitsubishiElec Endress+Hau
Patch Patch Patch
Mozilla Dell  
 
Patch Patch  
Click for vulnerability details
Alert State
Microsoft Festo Voltronic
+24hr +24hr +24hr
Contec ModSecurity IBM
+24hr +24hr +24hr
Click for vulnerability details
Virus News

Troj/ZipMal-CB   More...

Troj/RTFDrp-FN   More...

Troj/Phish-DEQ   More...

Troj/Phish-AMN   More...

Troj/PDFUri-FLA   More...

Troj/EncDoc-DY   More...

Troj/EncDoc-DV   More...

JS/Dwnldr-WHY   More...

Mal/MSIL-BM   More...

VBS/Drop-YJ   More...

Computer Network Defence Alert Level
Iran:Israel
Computer Network Defence Alert Level
Overall
Security News

Massive Android Fraud Operations Uncovered: IconAds, Kaleidoscope, SMS Malware, NFC Scams

More...

Over 40 Malicious Firefox Extensions Target Cryptocurrency Wallets, Stealing User Assets

More...

The Hidden Weaknesses in AI SOC Tools that No One Talks About

More...

Chinese Hackers Exploit Ivanti CSA Zero-Days in Attacks on French Government, Telecoms

More...

Critical Cisco Vulnerability in Unified CM Grants Root Access via Static Credentials

More...

North Korean Hackers Target Web3 with Nim Malware and Use ClickFix in BabyShark Campaign

More...

That Network Traffic Looks Legit, But it Could be Hiding a Serious Threat

More...

Hackers Using PDFs to Impersonate Microsoft, DocuSign, and More in Callback Phishing Campaigns

More...

U.S. Sanctions Russian Bulletproof Hosting Provider for Supporting Cybercriminals Behind Ransomware

More...

Vercel's v0 AI Tool Weaponized by Cybercriminals to Rapidly Create Fake Login Pages at Scale

More...

Critical Vulnerability in Anthropic's MCP Exposes Developer Machines to Remote Exploits

More...

TA829 and UNK_GreenSec Share Tactics and Infrastructure in Ongoing Malware Campaigns

More...

New Flaw in IDEs Like Visual Studio Code Lets Malicious Extensions Bypass Verified Status

More...

A New Maturity Model for Browser Security: Closing the Last-Mile Risk

More...

Chrome Zero-Day CVE-2025-6554 Under Active Attack — Google Issues Security Update

More...

U.S. Arrests Facilitator in North Korean IT Worker Scheme; Seizes 29 Domains and Raids 21 Laptop Farms

More...

Microsoft Removes Password Management from Authenticator App Starting August 2025

More...

U.S. Agencies Warn of Rising Iranian Cyber Attacks on Defense, OT Networks, and Critical Infrastructure

More...

Europol Dismantles $540 Million Cryptocurrency Fraud Network, Arrests Five Suspects

More...

Blind Eagle Uses Proton66 Hosting for Phishing, RAT Deployment on Colombian Banks

More...

Leveraging Credentials As Unique Identifiers: A Pragmatic Approach To NHI Inventories 

More...

⚡ Weekly Recap: Airline Hacks, Citrix 0-Day, Outlook Malware, Banking Trojans and more

More...

FBI Warns of Scattered Spider's Expanding Attacks on Airlines Using Social Engineering

More...

GIFTEDCROOK Malware Evolves: From Browser Stealer to Intelligence-Gathering Tool

More...

Facebook’s New AI Tool Asks to Upload Your Photos for Story Ideas, Sparking Privacy Concerns

More...

Over 1,000 SOHO Devices Hacked in China-linked LapDogs Cyber Espionage Campaign

More...

PUBLOAD and Pubshell Malware Used in Mustang Panda's Tibet-Specific Attack

More...

Business Case for Agentic AI SOC Analysts

More...

Chinese Group Silver Fox Uses Fake Websites to Deliver Sainbox RAT and Hidden Rootkit

More...

MOVEit Transfer Faces Increased Threats as Scanning Surges and CVE Flaws Are Targeted

More...

OneClik Red Team Campaign Targets Energy Sector Using Microsoft ClickOnce and Golang Backdoors

More...

Critical Open VSX Registry Flaw Exposes Millions of Developers to Supply Chain Attacks

More...

Critical RCE Flaws in Cisco ISE and ISE-PIC Allow Unauthenticated Attackers to Gain Root Access

More...

New FileFix Method Emerges as a Threat Following 517% Rise in ClickFix Attacks

More...

The Hidden Risks of SaaS: Why Built-In Protections Aren't Enough for Modern Data Resilience

More...

Iranian APT35 Hackers Targeting Israeli Tech Experts with AI-Powered Phishing Attacks

More...

Cyber Criminals Exploit Open-Source Tools to Compromise Financial Institutions Across Africa

More...

CISA Adds 3 Flaws to KEV Catalog, Impacting AMI MegaRAC, D-Link, Fortinet

More...

WhatsApp Adds AI-Powered Message Summaries for Faster Chat Previews

More...

nOAuth Vulnerability Still Affects 9% of Microsoft Entra SaaS Apps Two Years After Discovery

More...

Citrix Releases Emergency Patches for Actively Exploited CVE-2025-6543 in NetScaler ADC

More...

Citrix Bleed 2 Flaw Enables Token Theft; SAP GUI Flaws Risk Sensitive Data Exposure

More...

Pro-Iranian Hacktivist Group Leaks Personal Records from the 2024 Saudi Games

More...

Beware the Hidden Risk in Your Entra Environment

More...

SonicWall NetExtender Trojan and ConnectWise Exploits Used in Remote Access Attacks

More...

North Korea-linked Supply Chain Attack Targets Developers with 35 Malicious npm Packages

More...

Microsoft Extends Windows 10 Security Updates for One Year with New Enrollment Options

More...

New U.S. Visa Rule Requires Applicants to Set Social Media Account Privacy to Public

More...

Researchers Find Way to Shut Down Cryptominer Campaigns Using Bad Shares and XMRogue

More...

Hackers Target Over 70 Microsoft Exchange Servers to Steal Credentials via Keyloggers

More...

World Map
Team Cymru Malicious Activity Map
Latest Tool Versions
Burp Suite   30Jun25 2025.5.6
Kali-Linux  13Juin25 20265.2
Metasploit  03Jul25 6.4.73
Nessus  17Apr25 10.8.4
NetworkMiner  04Apr25 3.0
Nmap  16Jun25 7.97
Snort  29Jun25 3.9.1.0
Wireshark  04Jun25 4.4.7
Latest IDS Signatures
Cisco Sourcefire  03Jul25 07-02-001
Talos  03Jul25 2025-07-03
Proofpoint ET  02Jul25 10962
Santa Clara CA Ft Belvoir (VA) UTC/Zulu London Central Europe Kyiv Moscow Shanghai Sydney Wellington NZ