critical
89
high
11
medium
0
low
0
New CRITICAL Threat: SonicWall Network Security Manager (NSM) Zip Slip
A Zip Slip vulnerability in the SonicWall NSM On-Prem file upload and archive processing functionality allows attackers to overwrite arbitrary files on the system, potentially leading to remote code execution.
New CRITICAL Threat: Apache Log4j Error Log Remote Code Execution
An actively exploited vulnerability involving the Apache Log4j logging library that allows attackers to execute arbitrary code remotely by injecting malicious strings into log messages.
New CRITICAL Threat: CVE-2026-26221 (Hyland OnBase Workflow Timer Service)
An unauthenticated .NET Remoting exposure in the Hyland OnBase Workflow Timer Service allows remote attackers to send crafted requests, potentially leading to full system compromise, data theft, or malware installation.
New CRITICAL Threat: SolarWinds SUNBURST Backdoor
A sophisticated backdoor malware actively exploited to gain unauthorized access and maintain persistence within enterprise networks.
New CRITICAL Threat: CVE-2026-26221 (Hyland OnBase Workflow Timer Service)
An unauthenticated .NET Remoting exposure in the OnBase Workflow Timer Service that allows remote attackers to achieve full system compromise.
New CRITICAL Threat: Apache Log4j Error Log Remote Code Execution
An active, high-volume exploit targeting the Apache Log4j logging library, allowing attackers to execute arbitrary code remotely on affected systems.
New CRITICAL Threat: SonicWall NSM Zip Slip Vulnerability (CVE-2026-81939)
A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows attackers to overwrite arbitrary files on the system.
New CRITICAL Threat: Apache Log4j Error Log Remote Code Execution
An actively exploited vulnerability involving the Apache Log4j logging library that allows attackers to execute arbitrary code remotely by injecting malicious strings into log messages.
New CRITICAL Threat: CVE-2026-26221
An unauthenticated .NET Remoting exposure in the Hyland OnBase Workflow Timer Service allows remote attackers to send crafted requests, potentially leading to full system compromise or malware installation.
New HIGH Threat: Apache HTTP Server Path Traversal
A path traversal vulnerability in the cgi-bin directory of Apache HTTP Server that allows attackers to access files outside the intended web root.
New CRITICAL Threat: Apache Log4j Remote Code Execution
An active, high-volume exploit targeting the Log4j logging library, allowing attackers to execute arbitrary code remotely on vulnerable servers.
New CRITICAL Threat: CVE-2026-26221
An unauthenticated .NET Remoting exposure in the Hyland OnBase Workflow Timer Service allows remote attackers to send crafted requests, potentially leading to full system compromise or malware installation.
New CRITICAL Threat: SolarWinds SUNBURST Backdoor
A sophisticated supply-chain attack involving a malicious backdoor embedded in software updates, providing attackers with persistent, unauthorized access to compromised networks.
New CRITICAL Threat: Apache Log4j Remote Code Execution
An active, high-volume exploit targeting the Log4j logging library, allowing attackers to execute arbitrary code on vulnerable servers by injecting malicious strings into log messages.
New CRITICAL Threat: CVE-2026-26221
An unauthenticated .NET Remoting exposure in the Hyland OnBase Workflow Timer Service allows remote attackers to send crafted requests, potentially leading to full system compromise, data theft, or malware installation.
New HIGH Threat: Microsoft 365 Business Email Compromise (BEC) Phishing
Sophisticated phishing campaigns targeting Microsoft 365 credentials using adversary-in-the-middle (AiTM) techniques to bypass multi-factor authentication.
New CRITICAL Threat: LockBit 3.0 Ransomware Campaigns
Ongoing active campaigns utilizing LockBit 3.0, which employs double-extortion tactics and sophisticated evasion techniques to compromise enterprise networks.
New CRITICAL Threat: Ivanti Connect Secure Vulnerability (CVE-2024-21887)
A command injection vulnerability in the web component of Ivanti Connect Secure, Policy Secure, and ZTA gateways that allows unauthenticated attackers to execute arbitrary commands.
New CRITICAL Threat: SonicWall NSM Zip Slip Vulnerability (CVE-2026-81939)
A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) file upload and archive processing functionality that allows for arbitrary file writes.
New CRITICAL Threat: CVE-2026-26221 (Hyland OnBase)
An unauthenticated .NET Remoting exposure in the OnBase Workflow Timer Service that allows remote attackers to achieve full system compromise.
New CRITICAL Threat: Apache Log4j Remote Code Execution
An active, high-volume exploit targeting the Log4j logging library, allowing attackers to execute arbitrary code remotely on affected systems.
New CRITICAL Threat: SonicWall NSM OS Command Injection (CVE-2026-78327)
An OS Command Injection vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows remote code execution.
New CRITICAL Threat: CVE-2026-53662
A reflected cross-site scripting (XSS) vulnerability in the immich photo and video management solution allows attackers to compromise authenticated user accounts via malicious links.
New CRITICAL Threat: CVE-2026-26221
An unauthenticated .NET Remoting exposure in the Hyland OnBase Workflow Timer Service allows remote attackers to send crafted requests, potentially leading to full system compromise.
Unpatched Log4j Vulnerability
Critical Log4Shell vulnerability detected in application servers
Unpatched Log4j Vulnerability
Critical Log4Shell vulnerability detected in application servers
New CRITICAL Threat: Apache.Log4j.Error.Log.Remote.Code.Execution
An active, high-volume exploit targeting the Log4j logging library, allowing attackers to execute arbitrary code on vulnerable servers.
New CRITICAL Threat: CVE-2026-81939
A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows for arbitrary file writes.
New CRITICAL Threat: CVE-2026-26221
An unauthenticated .NET Remoting exposure in the Hyland OnBase Workflow Timer Service allows remote attackers to send crafted requests, potentially leading to full system compromise or malware installation.
New CRITICAL Threat: SolarWinds.SUNBURST.Backdoor
A sophisticated backdoor malware that persists in network environments, allowing attackers to maintain unauthorized access and execute commands on compromised systems.
New CRITICAL Threat: Apache.Log4j.Error.Log.Remote.Code.Execution
An active, high-volume exploit targeting the Log4j logging library, allowing remote code execution on vulnerable servers by injecting malicious strings into log messages.
New CRITICAL Threat: CVE-2026-26221
An unauthenticated .NET Remoting exposure in the Hyland OnBase Workflow Timer Service allows remote attackers to send crafted requests, potentially leading to full system compromise or malware installation.
Outdated OpenSSL Version Detected
Systems running OpenSSL versions vulnerable to CVE-2023-XXXX
New CRITICAL Threat: SolarWinds SUNBURST Backdoor
A sophisticated supply-chain malware that provides unauthorized remote access and control over compromised systems, often used for persistent espionage.
New CRITICAL Threat: Apache Log4j Remote Code Execution
An ongoing, highly prevalent exploit targeting the Apache Log4j logging library, allowing attackers to execute arbitrary code remotely on vulnerable servers.
New CRITICAL Threat: CVE-2026-26221
An unauthenticated .NET Remoting exposure in the Hyland OnBase Workflow Timer Service allows remote attackers to send crafted requests, potentially leading to full system compromise or malware installation.
New CRITICAL Threat: SolarWinds SUNBURST Backdoor
A sophisticated supply-chain malware that provides persistent, unauthorized access to compromised networks, often used for long-term espionage.
New CRITICAL Threat: Hyland OnBase Workflow Timer Service Vulnerability (CVE-2026-26221)
An unauthenticated .NET Remoting exposure in the OnBase Workflow Timer Service that allows remote attackers to achieve full system compromise.
New CRITICAL Threat: Apache Log4j Remote Code Execution
An active, high-volume exploit targeting the Log4j logging library, allowing attackers to execute arbitrary code remotely on affected servers.
Outdated OpenSSL Version Detected
Systems running OpenSSL versions vulnerable to CVE-2023-XXXX
New CRITICAL Threat: SonicWall NSM OS Command Injection (CVE-2026-78327)
An OS Command Injection vulnerability in the SonicWall Network Security Manager (NSM) allows unauthenticated attackers to execute arbitrary commands on the underlying operating system.
New CRITICAL Threat: SonicWall NSM Zip Slip Vulnerability (CVE-2026-81939)
A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows attackers to execute arbitrary code.
New CRITICAL Threat: CVE-2026-26221
An unauthenticated .NET Remoting exposure in the Hyland OnBase Workflow Timer Service allows remote attackers to send crafted requests, potentially leading to full system compromise or malware installation.
New CRITICAL Threat: Active Enterprise Software Exploitation
Threat actors are actively scanning for and weaponizing vulnerabilities in enterprise software, such as SAP NetWeaver and Microsoft SharePoint, often within days of disclosure.
New CRITICAL Threat: CVE-2026-53662
A reflected cross-site scripting (XSS) vulnerability in the Immich photo and video management solution allows attackers to compromise authenticated user accounts via a malicious link.
New CRITICAL Threat: CVE-2026-26221
An unauthenticated .NET Remoting exposure in the Hyland OnBase Workflow Timer Service allows remote attackers to send crafted requests, potentially leading to full system compromise or malware installation.
New HIGH Threat: Brevo Supply Chain Attack
A supply chain compromise involving Brevo has resulted in the injection of malicious code into approximately 100,000 websites, potentially leading to user data theft or redirection to malicious sites.
New CRITICAL Threat: SonicWall NSM Zip Slip Vulnerability (CVE-2026-81939)
A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows attackers to overwrite arbitrary files on the system.
New CRITICAL Threat: CVE-2026-26221
An unauthenticated .NET Remoting exposure in the Hyland OnBase Workflow Timer Service allows remote attackers to send crafted requests, potentially leading to full system compromise or malware installation.
New CRITICAL Threat: SonicWall NSM Zip Slip Vulnerability (CVE-2026-81939)
A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality that allows attackers to overwrite arbitrary files on the system.
New CRITICAL Threat: Apache.Log4j.Error.Log.Remote.Code.Execution
An ongoing, high-volume exploit attempt targeting the Log4j logging library, which allows attackers to execute arbitrary code on vulnerable servers by injecting malicious log strings.
New CRITICAL Threat: CVE-2026-26221
An unauthenticated .NET Remoting exposure in the Hyland OnBase Workflow Timer Service allows remote attackers to send crafted requests, potentially leading to full system compromise or malware installation.
New CRITICAL Threat: CVE-2026-26221
An unauthenticated .NET Remoting exposure in the Hyland OnBase Workflow Timer Service that can lead to full system compromise, data theft, or malware installation.
New CRITICAL Threat: CVE-2026-78327
An OS Command Injection vulnerability in the SonicWall Network Security Manager (NSM) On-Prem that allows an attacker to execute arbitrary commands on the underlying system.
New CRITICAL Threat: CVE-2026-81939
A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows for arbitrary file writes.
New CRITICAL Threat: Hyland OnBase .NET Remoting Exposure (CVE-2026-26221)
An unauthenticated .NET Remoting exposure in the OnBase Workflow Timer Service that allows remote attackers to send crafted requests, potentially leading to full system compromise.
New CRITICAL Threat: SolarWinds SUNBURST Backdoor
A sophisticated supply-chain attack involving a backdoor embedded in software updates, allowing attackers to maintain persistent access and exfiltrate sensitive data.
New CRITICAL Threat: Apache Log4j Error Log Remote Code Execution
A highly prevalent remote code execution vulnerability involving the Apache Log4j logging library, which continues to be one of the most actively exploited threats globally.
New CRITICAL Threat: CVE-2025-8821 Exploit Chain
An active exploit chain currently being utilized in the wild, identified as a zero-day threat targeting specific network sectors.
New CRITICAL Threat: CVE-2026-81939 (SonicWall NSM Zip Slip)
A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows for arbitrary file writes.
New CRITICAL Threat: CVE-2026-26221
An unauthenticated .NET Remoting exposure in the Hyland OnBase Workflow Timer Service allows remote attackers to send crafted requests, potentially leading to full system compromise.
New CRITICAL Threat: Apache Log4j Remote Code Execution
An ongoing, highly prevalent exploit targeting the Apache Log4j library, allowing attackers to execute arbitrary code remotely on vulnerable servers.
New CRITICAL Threat: SonicWall NSM Zip Slip and Command Injection
Multiple vulnerabilities in SonicWall Network Security Manager (NSM) On-Prem, including Zip Slip and OS Command Injection, allow unauthenticated or low-privileged users to execute arbitrary code or manipulate files.
New CRITICAL Threat: CVE-2026-26221
An unauthenticated .NET Remoting exposure in the Hyland OnBase Workflow Timer Service allows remote attackers to send crafted requests, potentially leading to full system compromise, data theft, or malware installation.
Unpatched Log4j Vulnerability
Critical Log4Shell vulnerability detected in application servers
New CRITICAL Threat: CVE-2025-8821 Exploit Chain
An active zero-day exploit chain currently being utilized in the wild, involving advanced techniques to bypass perimeter defenses and gain unauthorized access.
New CRITICAL Threat: CVE-2026-81939
A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows for arbitrary file writes.
New CRITICAL Threat: CVE-2026-26221
An unauthenticated .NET Remoting exposure in the Hyland OnBase Workflow Timer Service allows remote attackers to send crafted requests, potentially leading to full system compromise or malware installation.
New CRITICAL Threat: APT-42 DNS Tunneling Exfiltration
The threat actor APT-42 has been observed utilizing DNS tunneling techniques to exfiltrate data from compromised network nodes, bypassing traditional perimeter security.
New CRITICAL Threat: SonicWall NSM Zip Slip and Command Injection
Multiple vulnerabilities in SonicWall Network Security Manager (NSM) On-Prem, including a Zip Slip vulnerability and OS Command Injection, allow attackers to execute arbitrary code or manipulate file uploads.
New CRITICAL Threat: CVE-2026-26221
An unauthenticated .NET Remoting exposure in the Hyland OnBase Workflow Timer Service allows remote attackers to send crafted requests, potentially leading to full system compromise, data theft, or malware installation.
Unpatched Log4j Vulnerability
Critical Log4Shell vulnerability detected in application servers
Outdated OpenSSL Version Detected
Systems running OpenSSL versions vulnerable to CVE-2023-XXXX
New CRITICAL Threat: Apache Log4j Remote Code Execution
An ongoing, highly prevalent exploit targeting the Apache Log4j logging library, allowing attackers to achieve remote code execution by injecting malicious strings into log messages.
New CRITICAL Threat: SonicWall NSM Zip Slip Vulnerability (CVE-2026-81939)
A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows attackers to execute arbitrary code or overwrite system files.
New CRITICAL Threat: CVE-2026-26221
An unauthenticated .NET Remoting exposure in the Hyland OnBase Workflow Timer Service allows remote attackers to send crafted requests, potentially leading to full system compromise, data theft, or malware installation.
New HIGH Threat: Anubis Ransomware Attack on Quest Group
The Anubis ransomware group targeted the US-based Quest Group, resulting in the compromise of internal files and employee data.
New CRITICAL Threat: Emperador Ransomware Attack on Cassias MG Government
The Emperador ransomware group successfully breached the Cassias MG Government in Brazil, compromising sensitive data across the finance and healthcare sectors.
New CRITICAL Threat: CVE-2026-26221
An unauthenticated .NET Remoting exposure in the Hyland OnBase Workflow Timer Service allows remote attackers to send crafted requests, potentially leading to full system compromise or malware installation.
New HIGH Threat: Emperador Ransomware Attack
The Emperador ransomware group has actively targeted government entities, such as the Cassias MG Government in Brazil, compromising sensitive financial and healthcare data.
New CRITICAL Threat: SonicWall NSM Zip Slip Vulnerability (CVE-2026-81939)
A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows for arbitrary file writes.
New CRITICAL Threat: CVE-2026-26221
An unauthenticated .NET Remoting exposure in the Hyland OnBase Workflow Timer Service allows remote attackers to send crafted requests, potentially leading to full system compromise or malware installation.
New HIGH Threat: DNS Tunnel Exfiltration
An active attempt to exfiltrate data via DNS tunneling has been detected, where attackers use DNS queries to bypass traditional firewalls and exfiltrate sensitive information from internal nodes.
New CRITICAL Threat: SonicWall NSM Zip Slip Vulnerability (CVE-2026-81939)
A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows attackers to execute arbitrary code.
New CRITICAL Threat: CVE-2026-26221
An unauthenticated .NET Remoting exposure in the Hyland OnBase Workflow Timer Service allows remote attackers to send crafted requests, potentially leading to full system compromise or malware installation.
Outdated OpenSSL Version Detected
Systems running OpenSSL versions vulnerable to CVE-2023-XXXX
New CRITICAL Threat: DNS Tunnel Exfiltration
An active anomaly involving DNS tunnel exfiltration attempts, often associated with advanced persistent threat (APT) activity to bypass traditional firewalls and steal sensitive data.
New CRITICAL Threat: SonicWall NSM Zip Slip Vulnerability (CVE-2026-81939)
A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows for arbitrary file write operations.
New CRITICAL Threat: CVE-2026-26221
An unauthenticated .NET Remoting exposure in the Hyland OnBase Workflow Timer Service allows remote attackers to send crafted requests, potentially leading to full system compromise or malware installation.
New CRITICAL Threat: Apache Log4j Remote Code Execution
An ongoing, highly prevalent exploit targeting the Apache Log4j logging library, allowing attackers to execute arbitrary code remotely by injecting malicious strings into log messages.
New CRITICAL Threat: SonicWall NSM Zip Slip Vulnerability (CVE-2026-81939)
A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows attackers to overwrite arbitrary files on the system.
New CRITICAL Threat: CVE-2026-26221
An unauthenticated .NET Remoting exposure in the Hyland OnBase Workflow Timer Service allows remote attackers to send crafted requests, potentially leading to full system compromise, data theft, or malware installation.
New CRITICAL Threat: APT-42 DNS Tunnel Exfiltration
Active detection of APT-42 utilizing DNS tunneling techniques to exfiltrate data from compromised network nodes.
New CRITICAL Threat: TheGentlemen Ransomware Attack on ACA Pescara
The ransomware group TheGentlemen has targeted the Italian public housing agency ACA Pescara, resulting in the compromise of sensitive data.
New CRITICAL Threat: CVE-2026-42945 (NGINX Heap-based Buffer Overflow)
A critical 18-year-old vulnerability in the ngx_http_rewrite_module allows unauthenticated attackers to crash NGINX worker processes or achieve remote code execution on systems where ASLR is disabled.
New HIGH Threat: TheGentlemen Ransomware Attack
The ransomware group 'TheGentlemen' is actively targeting public sector organizations, such as the Italian housing agency ACA Pescara, to exfiltrate sensitive data and encrypt systems.
New CRITICAL Threat: APT-42 Intrusion Campaign
An active advanced persistent threat (APT) campaign originating from the Eastern Bloc, currently utilizing sophisticated intrusion techniques and DNS tunnel exfiltration.
New CRITICAL Threat: CVE-2026-42945 (NGINX Heap-based Buffer Overflow)
A critical heap-based buffer overflow in the ngx_http_rewrite_module of NGINX that allows unauthenticated attackers to crash worker processes or achieve remote code execution on systems where ASLR is disabled.
New CRITICAL Threat: CVE-2022-27228 (Bitrix Site Manager RCE)
A remote code execution vulnerability in the 'Polls, Votes' module of Bitrix Site Manager (versions prior to 21.0.100) that allows unauthenticated attackers to execute arbitrary code.
New CRITICAL Threat: APT-42 Intrusion Campaign
An active advanced persistent threat (APT) campaign originating from the Eastern Bloc, currently targeting network infrastructure and utilizing sophisticated intrusion techniques.