Auto-updating • Public sources • Link-out only

Security Intel

Designed for engineers through CISOs: what is being exploited and what deserves attention. Always validate in your environment.

Feed status
CISA KEVOK
Wiz ResearchOK
AquaOK
Palo Alto Unit 42OK
SnykOK
Updated Jul 27, 2026 (auto-refresh ~15 min)
Showing 30 of 50
Palo Alto Unit 42Jul 23, 2026
Open ↗
Russian Global Webmail Espionage
Unit 42 details a Russian cyberespionage campaign targeting Zimbra webmail servers using JavaScript injection to steal credentials. The post Russian Global Webmail Espionage appeared first on Unit 42.
Wiz ResearchJul 22, 2026
Open ↗
Opening the Black Box: Agentless Threat Detection for Virtual Appliances
Mapping appliances event logs to real-world campaigns: A step-by-step researcher’s guide to continuous agentless monitoring.
CISA KEVJul 22, 2026High
Open ↗
CVE-2026-16232 — Check Point SmartConsole
Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
CISA KEVJul 22, 2026High
Open ↗
CVE-2026-50522 — Microsoft SharePoint
Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.
Wiz ResearchJul 21, 2026
Open ↗
Agentless Threat Detection: Illuminating Cloud Blind Spots
How Agentless Workload Detection exposes hidden threats in virtual appliances and modern cloud networks.
Wiz ResearchJul 21, 2026
Open ↗
300 WINtegrations Strong: An Open Security Ecosystem Built for the Speed of AI
As AI accelerates how organizations build and how attackers operate, a deeply connected security ecosystem is how defenders keep up.
CISA KEVJul 21, 2026High
Open ↗
CVE-2026-60137 — WordPress Core
WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.
CISA KEVJul 21, 2026High
Open ↗
CVE-2026-63030 — WordPress Core
WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.
CISA KEVJul 21, 2026High
Open ↗
CVE-2026-0770 — Langflow Langflow
Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.
CISA KEVJul 21, 2026High
Open ↗
CVE-2021-27137 — DD-WRT DD-WRT
DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.
Wiz ResearchJul 20, 2026
Open ↗
Exploitation in the Wild of wp2shell
Wiz Research has identified exploitation of "wp2shell", a critical pre-auth RCE vulnerability chain impacting WordPress Core (CVE-2026-63030 & CVE-2026-60137). Attackers are deploying persistent webshells on vulnerable servers. Organizations should prioritize patching or applying WAF mitigations.
Palo Alto Unit 42Jul 17, 2026
Open ↗
Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy
A technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and persistent root access. The post Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy appeared first on Unit 42.
Palo Alto Unit 42Jul 16, 2026
Open ↗
AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report
Explore Unit 42's perspectives on AI's impact on cybersecurity, including key updates since the 2026 Incident Response Report. The post AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report appeared first on Unit 42.
CISA KEVJul 16, 2026High
Open ↗
CVE-2026-58644 — Microsoft SharePoint
Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
CISA KEVJul 16, 2026High
Open ↗
CVE-2026-25089 — Fortinet FortiSandbox
Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.
CISA KEVJul 16, 2026High
Open ↗
CVE-2026-39808 — Fortinet FortiSandbox
Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.
Palo Alto Unit 42Jul 15, 2026
Open ↗
The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15)
Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. The post The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15) appeared first on Unit 42.
Wiz ResearchJul 15, 2026
Open ↗
The Red Agent POV: The One Boolean That Broke a B2B Platform’s Credit System
Part 3: How the Red Agent bypassed a credit and paywall system by changing a single client-side value from false to true.
Palo Alto Unit 42Jul 15, 2026
Open ↗
TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development
TuxBot v3 Evolution, an IoT botnet framework built with LLMs. Read our analysis of its cross-compiled binaries, C2 architecture and bugs. The post TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development appeared first on Unit 42.
CISA KEVJul 15, 2026High
Open ↗
CVE-2026-46817 — Oracle E-Business Suite
Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments.
CISA KEVJul 15, 2026High
Open ↗
CVE-2023-4346 — KNX Association KNX Protocol Connection Authorization Option 1
KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devices without additional security options enabled and set a BCU key to lock the device.
Wiz ResearchJul 14, 2026
Open ↗
M-Red-Team: AsyncAPI Supply Chain Compromise via GitHub Actions
Detect and mitigate malicious @asyncapi npm packages linked to the latest npm supply chain attack.
CISA KEVJul 14, 2026High
Open ↗
CVE-2026-56155 — Microsoft Active Directory Federation Services
Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.
CISA KEVJul 14, 2026High
Open ↗
CVE-2026-56164 — Microsoft SharePoint Server
Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.
CISA KEVJul 14, 2026High
Open ↗
CVE-2026-15409 — SonicWall SMA1000 Appliances
SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.
CISA KEVJul 14, 2026High
Open ↗
CVE-2026-15410 — SonicWall SMA1000 Appliances
SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
Wiz ResearchJul 13, 2026
Open ↗
Why IaC Coverage Belongs on Your Security Dashboard
Rethinking IaC coverage as a funnel that shows how much of your infrastructure is governed, traceable, and ready for remediation at speed
CISA KEVJul 13, 2026High
Open ↗
CVE-2008-4128 — Cisco IOS
Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI.
Palo Alto Unit 42Jul 10, 2026
Open ↗
No Manners Here: The Ruthless Rise of The Gentlemen Ransomware
Unit 42 explores The Gentlemen ransomware operations, revealing the affiliate model driving its rapid growth. Learn more here. The post No Manners Here: The Ruthless Rise of The Gentlemen Ransomware appeared first on Unit 42.
CISA KEVJul 10, 2026High
Open ↗
CVE-2026-56291 — Balbooa Forms
Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE.
Notes
  • • This page aggregates public feeds and links out; it does not scan your environment.
  • • Treat items as signals: verify applicability, exposure, and exploitability before action.
  • • For exec-ready prioritization, pair this with the Reality Assessment.