Auto-updating • Public sources • Link-out only
Security Intel
Designed for engineers through CISOs: what is being exploited and what deserves attention. Always validate in your environment.
Feed status
CISA KEVOK
Wiz ResearchOK
AquaOK
Palo Alto Unit 42OK
SnykOK
Updated May 29, 2026 (auto-refresh ~15 min)
Unified feed
Take Reality Assessment →Showing 30 of 50
Wiz ResearchMay 28, 2026
Open ↗State of Post Quantum Cryptography
Discussion of PQC relevant statistics that we see across our customers and other data sources.
Palo Alto Unit 42May 28, 2026
Open ↗2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface
The 2026 World Cup presents major cyber risks from ransomware groups, state-aligned actors, and other groups targeting critical infrastructure. Learn more here. The post 2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface appeared first on Unit 42.
Palo Alto Unit 42May 27, 2026
Open ↗Out of the Crypt: The Evolving Cyber Extortion Economy
Unit 42 explores trends in data theft and extortion, outlining key strategies for organizations as frontier AI models advance. The post Out of the Crypt: The Evolving Cyber Extortion Economy appeared first on Unit 42.
Wiz ResearchMay 27, 2026
Open ↗Evidence at the Moment of Attack. Answers at AI Speed.
Wiz Sensor Forensics is now generally available - automatically capturing forensic artifacts at the moment of detection and using AI to accelerate investigation for SOC and IR teams.
Wiz ResearchMay 27, 2026
Open ↗Commit to Compromise: A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure
Wiz CIRT and Wiz Research detail JINX-0164, a threat actor using LinkedIn social engineering, custom macOS malware, and CI/CD hijacking to target cryptocurrency organizations.
Wiz ResearchMay 27, 2026
Open ↗Defending at Machine-Speed: Building AI Threat Readiness with Wiz
How Wiz helps organizations adopt an AI Operating Model for AI Threat Readiness
SnykMay 27, 2026
Open ↗Continuous Offensive Security: The Line We've Been Walking
Snyk's Continuous Offensive Security unifies DAST, AI pentesting, and agent red teaming to find exploitable flaws — not just bugs — before attackers do. Here's why lineage matters.
CISA KEVMay 27, 2026High
Open ↗CVE-2026-48027 — Nx Nx Console
Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory.
CISA KEVMay 27, 2026High
Open ↗CVE-2026-45321 — TanStack TanStack
TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.
CISA KEVMay 27, 2026High
Open ↗CVE-2026-8398 — Daemon Daemon Tools Lite
Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability.
Wiz ResearchMay 26, 2026
Open ↗State of SDLC Security 2026: How Risk Scales in Modern Development
Insights from real-world environments into how code, developer tooling, automation, and AI are reshaping application security.
CISA KEVMay 26, 2026High
Open ↗CVE-2026-48172 — LiteSpeed cPanel Plugin
LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user account to execute arbitrary scripts with root privileges.
SnykMay 23, 2026
Open ↗Laravel Lang Supply Chain Advisory
Hundreds of historical Laravel Lang Packagist releases were republished with malicious code, putting Composer installs at risk of credential theft and secret exfiltration.
Palo Alto Unit 42May 22, 2026
Open ↗Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns
Unit 42 details Screening Serpens' use of AppDomainManager hijacking and new RAT variants to target tech and defense sectors in recent campaigns. The post Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns appeared first on Unit 42.
Palo Alto Unit 42May 22, 2026
Open ↗Paved With Intent: ROADtools and Nation-State Tactics in the Cloud
Open-source framework ROADtools is being misused by threat actors for cloud intrusions. Learn how to identify its malicious use. The post Paved With Intent: ROADtools and Nation-State Tactics in the Cloud appeared first on Unit 42.
CISA KEVMay 22, 2026High
Open ↗CVE-2026-9082 — Drupal Core
Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.
Wiz ResearchMay 21, 2026
Open ↗Claude Enterprise Meets the Security Graph: Wiz Integrates with Anthropic's Compliance API
Security and compliance teams can now monitor Claude activity directly in Wiz, extending the workflows they already rely on to AI
SnykMay 21, 2026
Open ↗Snyk announces Anthropic updates: Evo integrates with Claude Enterprise, and Snyk Desk comes to Claude Desktop
Snyk announces two new integrations with Anthropic that cover both sides of AI-assisted development. Evo by Snyk now integrates with Anthropic's Claude Enterprise, and the Snyk Security Desktop Extension is now available in Claude for macOS and Windows.
Palo Alto Unit 42May 21, 2026
Open ↗The npm Threat Landscape: Attack Surface and Mitigations (Updated May 21)
Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. The post The npm Threat Landscape: Attack Surface and Mitigations (Updated May 21) appeared first on Unit 42.
SnykMay 21, 2026
Open ↗Securing The AI Revolution: How Snyk And Our Partners Are Scaling For The Future
AI is accelerating code creation. Learn how Snyk is scaling its AI Security Platform and investing in new partner programs to help enterprises govern AI-generated code at scale.
CISA KEVMay 21, 2026High
Open ↗CVE-2025-34291 — Langflow Langflow
Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. This could allow the attacker to execute arbitrary code and achieve full system compromise via obtained tokens that permit access to authenticated endpoints.
CISA KEVMay 21, 2026High
Open ↗CVE-2026-34926 — Trend Micro Apex One
Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.
Palo Alto Unit 42May 20, 2026
Open ↗Tracking TamperedChef Clusters via Certificate and Code Reuse
Unit 42 analyzes TamperedChef malware clusters that use trojanized productivity apps and malvertising to deliver stealthy payloads to targets. The post Tracking TamperedChef Clusters via Certificate and Code Reuse appeared first on Unit 42.
CISA KEVMay 20, 2026High
Open ↗CVE-2008-4250 — Microsoft Windows
Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.
CISA KEVMay 20, 2026High
Open ↗CVE-2009-1537 — Microsoft DirectX
Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file.
CISA KEVMay 20, 2026High
Open ↗CVE-2009-3459 — Adobe Acrobat and Reader
Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption.
CISA KEVMay 20, 2026High
Open ↗CVE-2010-0249 — Microsoft Internet Explorer
Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
CISA KEVMay 20, 2026High
Open ↗CVE-2010-0806 — Microsoft Internet Explorer
Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
CISA KEVMay 20, 2026High
Open ↗CVE-2026-41091 — Microsoft Defender
Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally.
CISA KEVMay 20, 2026High
Open ↗CVE-2026-45498 — Microsoft Defender
Microsoft Defender contains an unspecified vulnerability that allows for denial of service.
Notes
- • This page aggregates public feeds and links out; it does not scan your environment.
- • Treat items as signals: verify applicability, exposure, and exploitability before action.
- • For exec-ready prioritization, pair this with the Reality Assessment.