Coverage Demonstrator
Pick the services you offer. See the vulnerabilities, threats and incidents from the last 90 days that each one addresses, grouped by how it helps — prevent, detect, respond, recover.
Rollup window ending 2026-09-12 · 2899 stories · Last updated: 12 September 2026 13:16 UTC
What the last 90 days already address
355 distinct news items in the last 90 days are addressed by at least one service an MSP sells, spread across 20 services. A story counts once per service and may count under several, so the column sums far past 355 — the headline is a distinct count, not a total.
Show the per-service breakdown (20 services)
| Service | 90d | 30d | Distinctive for | Addresses it by | |||
|---|---|---|---|---|---|---|---|
| Vulnerability Management | 290 | 140 | 9 | Prevent | Detect | ||
| Managed XDR | 259 | 139 | 2 | Prevent | Detect | Respond | |
| Firewall | 194 | 117 | 135 | Prevent | Detect | ||
| SASE/SSE | 187 | 113 | 48 | Prevent | Detect | ||
| WAF | 172 | 107 | 30 | Prevent | Detect | ||
| End-user elevation | 151 | 92 | 146 | Prevent | |||
| AI-enabled attack detection | 30 | 12 | 18 | Detect | |||
| DLP | 28 | 11 | — | Prevent | |||
| Compliance | 26 | 15 | — | Prevent | |||
| Third-party | 22 | 10 | — | Prevent | |||
| MFA | 13 | 3 | — | Prevent | |||
| SSO | 13 | 1 | — | Prevent | |||
| Gateway | 8 | 1 | — | Prevent | |||
| IEP (M365 email protection) | 8 | 1 | — | Prevent | |||
| Phishing simulation | 8 | 1 | — | Prevent | |||
| Training | 8 | 1 | — | Prevent | |||
| AI/ML system security | 7 | 2 | — | Prevent | |||
| Risk Management | 5 | 2 | — | Prevent | |||
| Help Desk validation | 2 | 1 | — | Prevent | |||
| M365 backup | 2 | 0 | — | Recover | |||
No story in this window ties to Entra ID backup, Google Backup, Shadow AI discovery and control specifically. The page says so below and links nothing — an honest empty, not a gap.
Client view: only confirmed and corroborated reports are shown — never an unverified leak-site claim.
Seller view: the full set, with each item's confidence labelled. Capabilities with news but no coverage are your attach map (below).
My service offerings
Check the services you provide to see the threats each one addresses. Saved on this device only; no account.
End-user elevation 151
Active threats this quarter that End-user elevation addresses:
Prevent
- NewsCISA Adds Three Known Exploited Vulnerabilities to Catalogconfirmed
- NewsPalo Alto Networks security advisory (AV26-905)confirmed
- NewsAVEVA Pipeline Integrity Monitorconfirmed
- NewsAVEVA Pipeline Integrity Monitorconfirmed
- NewsOrthanc DICOM Serverconfirmed
- NewsCISA Adds Two Known Exploited Vulnerabilities to Catalogconfirmed
- NewsST Engineering iDirect iQ-Series Terminals (Update A)confirmed
- NewsCISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadlinecorroborated
- NewsFortinet security advisory (AV26-023) - Update 1confirmed
- NewsGoogle security advisory (AV26-904)confirmed
- NewsConnectWise security advisory (AV26-903)confirmed
- NewsCheck Point security advisory (AV26-902)confirmed
- News2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Serverconfirmed
- NewsCISA Adds Four Known Exploited Vulnerabilities to Catalogconfirmed
- NewsMicrosoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploitedcorroborated
- NewsIvanti security advisory (AV26-897)confirmed
- NewsMikrotik security advisory (AV26-887)confirmed
- NewsAdobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shellcorroborated
- NewsInductive Automation Ignitionconfirmed
- NewsTycon Systems TPDIN-Monitor-WEB3confirmed
- NewsInductive Automation Ignitionconfirmed
- NewsTycon Systems TPDIN-Monitor-WEB3confirmed
- NewsPyramid Solutions NetStaX EtherNet/IP Stackconfirmed
- NewsPyramid Solutions NetStaX EtherNet/IP Stackconfirmed
- NewsProgress Software security advisory (AV26-875)confirmed
- NewsNearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)confirmed
- NewsSonicWall security advisory (AV26-872)confirmed
- NewsSonicWall Warns of Two SMA1000 Zero-Days Exploited in Attackscorroborated
- NewsJFrog security advisory (AV26-867)confirmed
- NewsRockwell Automation RSLinx Classicconfirmed
- NewsPaperCut releases second emergency patch for exploited flawscorroborated
- NewsAll-Line Equipment Company Fuel-Bossconfirmed
- NewsAll-Line Equipment Company Fuel-Bossconfirmed
- NewsCISA Adds Three Known Exploited Vulnerabilities to Catalogconfirmed
- NewsMitsubishi Electric Multiple FA Products (Update D)confirmed
- NewsMitsubishi Electric CNC Series (Update A)confirmed
- NewsEbyte NA111-Mconfirmed
- NewsXiiaozet LK100Wconfirmed
- NewsMitsubishi Electric CNC Series (Update A)confirmed
- NewsXiiaozet LK100Wconfirmed
- NewsEbyte NA111-Mconfirmed
- NewsCISA orders feds to patch Citrix NetScaler RCE flaw by Saturdayconfirmed
- NewsNext.js security advisory (AV26-851)confirmed
- NewsCritical Gitea vulnerability now exploited in the wild (CVE-2026-60004)corroborated
- NewsRently Smart Homeconfirmed
- NewsPayRange APIconfirmed
- NewsZoneminderconfirmed
- NewsRently Smart Homeconfirmed
- NewsPayRange APIconfirmed
- NewsZoneminderconfirmed
- NewsBendix EC80 Brake ECUconfirmed
- NewsFURUNO FA-50 Class B AIS Transponderconfirmed
- NewsFURUNO FA-50 Class B AIS Transponderconfirmed
- NewsBendix EC80 Brake ECUconfirmed
- NewsKEV: CVE-2026-60004 — Gitea Gitea (Gitea Code Injection Vulnerability)confirmed
- NewsCISA Adds One Known Exploited Vulnerability to Catalogconfirmed
- NewsCISA orders urgent patching of actively exploited Zimbra flawcorroborated
- NewsTrueConf security advisory (AV26-835)confirmed
- NewsJFrog Artifactory Flaws Enable Software Supply Chain Attackscorroborated
- NewsJohnson Controls Simplex Incident Managerconfirmed
- NewsCitrix security advisory (AV26-833)confirmed
- NewsCritical RCE flaw in Windows IKE Extension now actively exploitedcorroborated
- NewsPatch bundle: Oracle Oracle Critical Security Patch Update Advisory - August 2026 — 1040 CVEs, 151 criticalcorroborated
- NewsMattermost security advisory (AV26-828)confirmed
- NewsCISA Malcolmconfirmed
- NewsCritical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projectscorroborated
- NewsApple security advisory (AV26-823)confirmed
- NewsCitrix security advisory (AV26-645) – Update 2confirmed
- NewsMicrosoft Edge security advisory (AV26-822)confirmed
- NewsCISA Adds One Known Exploited Vulnerability to Catalogconfirmed
- NewsAL26-018 - Vulnerability affecting Cisco ASA and Secure Firewall Threat Defense Software Remote Access SSL VPN - CVE-2026-20349confirmed
- NewsFlow Neuroscience FL-100confirmed
- NewsHaiwell IoT Cloud HMI Gatewayconfirmed
- NewsSiemens Solid Edgeconfirmed
- NewsANDRITZ HIPASE-250 and 250 SCALAconfirmed
- NewsSiemens Siveillance Videoconfirmed
- NewsSiemens License Server (SLS)confirmed
- NewsSiemens Desigo DXR and PXC Controllersconfirmed
- NewsHitachi Energy APM Edge Productconfirmed
- NewsSiemens LOGO! Soft Comfortconfirmed
- NewsSiemens Parasolidconfirmed
- NewsSiemens Simcenter Femapconfirmed
- NewsSiemens License Server (SLS)confirmed
- NewsSiemens Desigo DXR and PXC Controllersconfirmed
- NewsSiemens LOGO! Soft Comfortconfirmed
- NewsANDRITZ HIPASE-250 and 250 SCALAconfirmed
- NewsSiemens Siveillance Videoconfirmed
- NewsHitachi Energy APM Edge Productconfirmed
- NewsSiemens Solid Edgeconfirmed
- NewsSiemens Siveillance Videoconfirmed
- NewsSiemens Siveillance Videoconfirmed
- NewsHaiwell IoT Cloud HMI Gatewayconfirmed
- NewsHackers exploit critical Adobe Commerce flaw to hijack customer accountsconfirmed
- NewsCisco security advisory (AV26-807)confirmed
- NewsBulletin de sécurité Red Hat (AV26-803)confirmed
- NewsMira Hormone Monitor, Mira Android Appconfirmed
- NewsKEV: CVE-2026-72898 — Metabase Metabase (Metabase SQL Injection Vulnerability)confirmed
- NewsWebPros security advisory (AV26-790)confirmed
- NewsGoogle security advisory (AV26-787)confirmed
- News200 accounts compromised in Swiss government’s Microsoft SharePoint breachcorroborated
- NewsABB Ability Zenonconfirmed
- NewsMedixant RadiAnt DICOMconfirmed
- NewsPatch bundle: August 2026 Early Security Updates — 19 CVEs, 0 exploitedcorroborated
- NewsPaperclip AI Flaws Let Unauthenticated Attackers Run Commandscorroborated
- NewsNew OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitchcorroborated
- NewsCritical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markupcorroborated
- News128 Seconds to disruption: Microsoft Defender stops ransomware at QNETvendor research
- NewsCISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromisesvendor research
- NewsKEV: CVE-2026-18577 — N-able N-central (N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability)confirmed
- NewsRails security advisory (AV26-767)confirmed
- NewsSolarWinds security advisory (AV26-766)confirmed
- NewsWhat the Hugging Face breach reveals about defense in the age of agentic AIcorroborated
- NewsVMware security advisory (AV26-763)confirmed
- News[Control Systems] Phoenix Contact security advisory (AV26-762)confirmed
- NewsSpring security advisory (AV26-759)confirmed
- NewsCisco security advisory (AV26-757)confirmed
- NewsJohnson Controls OpenBlue Employeeconfirmed
- NewsNASA Core Flight System (cFS) Health & Safety (HS) Applicationconfirmed
- NewsWatchfire Controller Softwareconfirmed
- NewsSchneider Electric IGSSconfirmed
- Newso6 Automation open62541confirmed
- NewsSchneider Electric IGSSconfirmed
- NewsJohnson Controls OpenBlue Employeeconfirmed
- NewsKEV: CVE-2026-20316 — Cisco Secure Firewall Management Center (FMC) (Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability)confirmed
- Newsigloohome Smart Lock Mobile Applicationconfirmed
- NewsSiemens Mendix Runtimeconfirmed
- NewsSiemens SIMATIC S7-PLCSIM Advancedconfirmed
- NewsSiemens Desigo CCconfirmed
- NewsMikroTik RouterOS and Cloud Hosted Routerconfirmed
- NewsCritical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging Incorroborated
- NewsErlang security advisory (AV26-750)confirmed
- NewsKEV: CVE-2026-16812 — Arista VeloCloud Orchestrator (Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability)confirmed
- NewsKEV: CVE-2025-68686 — Fortinet FortiOS (Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability)confirmed
- NewsCalifornia AG breach notice: Zacks Investment Research, Inc.confirmed
- NewsProgress security advisory (AV26-746)confirmed
- News[Control Systems] Moxa security advisory (AV26-742)confirmed
- News[UPDATE] [mittel] Bitdefender Internet und Total Security: Schwachstelle ermöglicht Privilegieneskalationconfirmed
- NewsClop ransomware targets Windchill, FlexPLM in data theft attackscorroborated
- NewsJohnson Controls XAAP Androidconfirmed
- NewsPanduit IntraVUEconfirmed
- NewsMZ Automation libIEC61850confirmed
- NewsWeintek cMT3092Xconfirmed
- NewsUbuntu snap-confine Vulnerability Enables Local Root Accesscorroborated
- NewsTenable security advisory (AV26-724)confirmed
- NewsRockwell Automation Studio 5000 Logix Designerconfirmed
- NewsSiemens IAM Clientconfirmed
- NewsCritical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Executioncorroborated
- NewsKEV: CVE-2026-0770 — Langflow Langflow (Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability)confirmed
- NewsInc Ransomware Exploits SonicWall SMA Zero-Dayscorroborated
- NewsProgress Restores ShareFile Storage Zones Access After Security Warningconfirmed
- NewsCISA Adds Two Known Exploited Vulnerabilities to Catalogconfirmed
Worked cases
Incidents from the harvested record that this service addresses. These do not depend on this week’s news; the badged items above do.
- Turn the remote-access appliance into a credential collector, then patch the authentication server to accept a chosen value
- An exploit that applies on viewing, defeating every control built around user action
- Tell the device to mail you its own configuration, using the management protocol's write function
- Compromise the carrier, and inherit everyone whose traffic crosses it
- Encrypt only the virtual estate, exfiltrate through the victim's own cloud tooling, and delete the encryptor afterwards
- Exploited inside the mandated patching window, then exploited again on a second instance during the response
- Select victims by exposure alone, finish the same day, and change name to stay unattributed
- Extort the victim a second time, from inside your own operation
- Chain four flaws in an end-of-life security appliance
- The account of someone who left, and the backup that kept their desk
- Register your own device as the second factor, and the lock is now yours
- The identities that cannot have a second factor
- A state-linked group that sells the access instead of using it
- Learn the help desk's reset procedure, then call back and use it
- Take dozens of build servers, then wait
- Phish from inside the marketing platform the recipient already trusts
- The tool that certifies the appliance is clean can be told to say so
- He says he is from IT, and if you will not let him in remotely he drives over
Help Desk validation 2
Active threats this quarter that Help Desk validation addresses:
Prevent
- NewsSpring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teamsvendor research
- NewsCorporate Data Stolen in Levi Strauss Cyberattackcorroborated
Worked cases
Incidents from the harvested record that this service addresses. These do not depend on this week’s news; the badged items above do.
- Turn the remote-access appliance into a credential collector, then patch the authentication server to accept a chosen value
- An exploit that applies on viewing, defeating every control built around user action
- Encrypt only the virtual estate, exfiltrate through the victim's own cloud tooling, and delete the encryptor afterwards
- Exploited inside the mandated patching window, then exploited again on a second instance during the response
- The account of someone who left, and the backup that kept their desk
- Register your own device as the second factor, and the lock is now yours
- The identities that cannot have a second factor
- Learn the help desk's reset procedure, then call back and use it
- The tool that certifies the appliance is clean can be told to say so
- He says he is from IT, and if you will not let him in remotely he drives over
MFA 13
Active threats this quarter that MFA addresses:
Prevent
- NewsSpring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teamsvendor research
- NewsCritical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836)claimed
- NewsJohnson Controls Simplex Incident Managerconfirmed
- NewsCorporate Data Stolen in Levi Strauss Cyberattackcorroborated
- NewsHijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malwarecorroborated
- NewsIn the Hugging Face breach, OpenAI’s hacker was noisy and fast — but not unstoppablecorroborated
- NewsMikroTik RouterOS and Cloud Hosted Routerconfirmed
- NewsHacked Public Wi-Fi Gateways Used to Harvest Corporate Credentialscorroborated
- NewsHugging Face CEO calls for ‘radical transparency’ after ‘unprecedented’ OpenAI hackcorroborated
- NewsRussian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codescorroborated
- NewsNew Dolphin X Stealer Employs AI Profiling to Prioritize Targetscorroborated
- NewsOpenAI scored an own goal with HuggingFace attack, showing how open Chinese models are winningcorroborated
- NewsMultiple Jscrambler Packages Impacted by Supply Chain Attackcorroborated
Worked cases
Incidents from the harvested record that this service addresses. These do not depend on this week’s news; the badged items above do.
- Turn the remote-access appliance into a credential collector, then patch the authentication server to accept a chosen value
- An exploit that applies on viewing, defeating every control built around user action
- Compromise the carrier, and inherit everyone whose traffic crosses it
- Encrypt only the virtual estate, exfiltrate through the victim's own cloud tooling, and delete the encryptor afterwards
- Exploited inside the mandated patching window, then exploited again on a second instance during the response
- Select victims by exposure alone, finish the same day, and change name to stay unattributed
- Extort the victim a second time, from inside your own operation
- The account of someone who left, and the backup that kept their desk
- Register your own device as the second factor, and the lock is now yours
- The identities that cannot have a second factor
- A state-linked group that sells the access instead of using it
- Ransom hospitals to pay for the nuclear-programme espionage
- Learn the help desk's reset procedure, then call back and use it
- The pipeline stopped because the company stopped it
- Phish from inside the marketing platform the recipient already trusts
- The tool that certifies the appliance is clean can be told to say so
- He says he is from IT, and if you will not let him in remotely he drives over
- Phish the credential, then change where the money is sent
- The QR code exists to get the victim off the managed device
SSO 13
Active threats this quarter that SSO addresses:
Prevent
- NewsJohnson Controls Simplex Incident Managerconfirmed
- NewsHijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malwarecorroborated
- News6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026corroborated
- NewsOkta buys AI security startup Permiso; source says for about $200Mcorroborated
- NewsIn the Hugging Face breach, OpenAI’s hacker was noisy and fast — but not unstoppablecorroborated
- NewsMikroTik RouterOS and Cloud Hosted Routerconfirmed
- News[UPDATE] [hoch] Shibboleth Service Provider: Schwachstelle ermöglicht SQL Injectionconfirmed
- NewsHacked Public Wi-Fi Gateways Used to Harvest Corporate Credentialscorroborated
- NewsHugging Face CEO calls for ‘radical transparency’ after ‘unprecedented’ OpenAI hackcorroborated
- NewsRussian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codescorroborated
- NewsNew Dolphin X Stealer Employs AI Profiling to Prioritize Targetscorroborated
- NewsOpenAI scored an own goal with HuggingFace attack, showing how open Chinese models are winningcorroborated
- NewsMultiple Jscrambler Packages Impacted by Supply Chain Attackcorroborated
Worked cases
Incidents from the harvested record that this service addresses. These do not depend on this week’s news; the badged items above do.
- Turn the remote-access appliance into a credential collector, then patch the authentication server to accept a chosen value
- An exploit that applies on viewing, defeating every control built around user action
- Compromise the carrier, and inherit everyone whose traffic crosses it
- Encrypt only the virtual estate, exfiltrate through the victim's own cloud tooling, and delete the encryptor afterwards
- Exploited inside the mandated patching window, then exploited again on a second instance during the response
- Extort the victim a second time, from inside your own operation
- The account of someone who left, and the backup that kept their desk
- Register your own device as the second factor, and the lock is now yours
- The identities that cannot have a second factor
- A state-linked group that sells the access instead of using it
- Learn the help desk's reset procedure, then call back and use it
- The tool that certifies the appliance is clean can be told to say so
- He says he is from IT, and if you will not let him in remotely he drives over
- Phish the credential, then change where the money is sent
- The QR code exists to get the victim off the managed device
AI/ML system security 7
Active threats this quarter that AI/ML system security addresses:
Prevent
- NewsAbliteration.ai is making a business out of removing AI guardrailscorroborated
- NewsOpenAI subpoenaed by Alabama attorney general over Hugging Face hackcorroborated
- NewsPaperclip AI Flaws Let Unauthenticated Attackers Run Commandscorroborated
- NewsPrompt Injection Remains Biggest LLM Risk, Despite Limited Incidentscorroborated
- NewsHugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Codecorroborated
- NewsWhat the Hugging Face breach reveals about defense in the age of agentic AIcorroborated
- NewsOpenAI agent swarm attack on Hugging Face: new NYT reporting adds detail (24 Aug)corroborated
Vulnerability Management 290
Active threats this quarter that Vulnerability Management addresses:
Prevent
- NewsGitLab security advisory (AV26-917)confirmed
- NewsCISA Adds Three Known Exploited Vulnerabilities to Catalogconfirmed
- NewsPalo Alto Networks security advisory (AV26-905)confirmed
- NewsAVEVA Pipeline Integrity Monitorconfirmed
- NewsNextGen Healthcare Mirth Connectconfirmed
- NewsAVEVA Pipeline Integrity Monitorconfirmed
- NewsOrthanc DICOM Serverconfirmed
- NewsCISA Adds Two Known Exploited Vulnerabilities to Catalogconfirmed
- NewsST Engineering iDirect iQ-Series Terminals (Update A)confirmed
- NewsCISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadlinecorroborated
- NewsSecurity Alert (A26-09-19): Multiple Vulnerabilities in Palo Alto Productsconfirmed
- NewsSecurity Alert (A26-09-20): Vulnerability in Fortinet FortiSandboxconfirmed
- NewsPalo Alto Products Multiple Vulnerabilitiesconfirmed
- NewsUPDATE Intel Chipset Firmware: CVSS (Max): 6.8confirmed
- Newsqt5-qtbase: CVSS (Max): 7.5confirmed
- NewsLinux Kernel (Live Patch 25 for SUSE Linux Enterprise Micro 6.0): CVSS (Max): 8.6confirmed
- NewsPalo Alto PAN-OS: CVSS (Max): 9.2confirmed
- NewsCisco security advisory (AV26-197) – Update 3confirmed
- NewsFortinet security advisory (AV26-023) - Update 1confirmed
- NewsGoogle security advisory (AV26-904)confirmed
- NewsConnectWise security advisory (AV26-903)confirmed
- NewsCheck Point security advisory (AV26-902)confirmed
- News2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Serverconfirmed
- NewsCISA Adds Four Known Exploited Vulnerabilities to Catalogconfirmed
- NewsCSA Singapore alert: 9 September 2026 Active Exploitation of Vulnerability in N-Able N-Central Attackers are exploiting a critical vulnerability in N-Able N-Central remote management and monitoring tool to execute code remotely without authentication. Patch immediately. Alertsconfirmed
- NewsCSA Singapore alert: 9 September 2026 Critical Vulnerabilities in SAP Products Attackers can exploit multiple vulnerabilities in SAP Products to execute arbitrary commands, obtain sensitive credentials, replace or delete tenant data and perform unauthorised actions. Patch immediately. Alertsconfirmed
- NewsAndroid Multiple Vulnerabilitiesconfirmed
- NewsMicrosoft Apps: CVSS (Max): 8.6confirmed
- NewsHSQLDB: CVSS (Max): 5.0confirmed
- Newsfirefox: CVSS (Max): 7.5confirmed
- NewsF5 BIG-IP DNS: CVSS (Max): 7.5confirmed
- NewsMicrosoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploitedcorroborated
- NewsIvanti security advisory (AV26-897)confirmed
- NewsMikrotik security advisory (AV26-887)confirmed
- NewsAdobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shellcorroborated
- Newsfirefox: CVSS (Max): 7.5confirmed
- NewsAdobe Commerce Zero-Day Exploited to Backdoor Online Storescorroborated
- NewsN-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218)corroborated
- NewsVMware Products: CVSS (Max): 9.3confirmed
- NewsALERT HPE Networking AOS-CX: CVSS (Max): 9.8confirmed
- NewsMicrosoft Edge Multiple Vulnerabilitiesconfirmed
- NewsInductive Automation Ignitionconfirmed
- NewsTycon Systems TPDIN-Monitor-WEB3confirmed
- NewsIXON VPN Clientconfirmed
- NewsOPCFoundation OPC UA LocalDiscoveryServer (LDS)confirmed
- NewsInductive Automation Ignitionconfirmed
- NewsOPCFoundation OPC UA LocalDiscoveryServer (LDS)confirmed
- NewsTycon Systems TPDIN-Monitor-WEB3confirmed
- NewsIXON VPN Clientconfirmed
- NewsPyramid Solutions NetStaX EtherNet/IP Stackconfirmed
- NewsRockwell Automation 1756-ENBT Moduleconfirmed
- NewsPyramid Solutions NetStaX EtherNet/IP Stackconfirmed
- NewsRockwell Automation 1756-ENBT Moduleconfirmed
- NewsProgress Software security advisory (AV26-875)confirmed
- NewsMalicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pagescorroborated
- NewsNearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)confirmed
- NewsSonicWall security advisory (AV26-872)confirmed
- NewsSonicWall Warns of Two SMA1000 Zero-Days Exploited in Attackscorroborated
- NewsJFrog security advisory (AV26-867)confirmed
- NewsRockwell Automation RSLinx Classicconfirmed
- NewsCISA Adds Two Known Exploited Vulnerabilities to Catalogconfirmed
- NewsPaperCut releases second emergency patch for exploited flawscorroborated
- NewsWebPros security advisory (AV26-854)confirmed
- NewsAll-Line Equipment Company Fuel-Bossconfirmed
- NewsAll-Line Equipment Company Fuel-Bossconfirmed
- NewsRockwell Automation OTTO Fleet Managerconfirmed
- NewsCISA Adds Three Known Exploited Vulnerabilities to Catalogconfirmed
- NewsMitsubishi Electric Multiple FA Products (Update D)confirmed
- NewsApplied Systems Engineering ASE2000 V2 Communications Test Setconfirmed
- NewsMitsubishi Electric CNC Series (Update A)confirmed
- NewsEbyte NA111-Mconfirmed
- NewsXiiaozet LK100Wconfirmed
- NewsApplied Systems Engineering ASE2000 V2 Communications Test Setconfirmed
- NewsMitsubishi Electric CNC Series (Update A)confirmed
- NewsXiiaozet LK100Wconfirmed
- NewsEbyte NA111-Mconfirmed
- NewsCISA orders feds to patch Citrix NetScaler RCE flaw by Saturdayconfirmed
- NewsNext.js security advisory (AV26-851)confirmed
- NewsJustice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical Infrastructureconfirmed
- NewsCritical Gitea vulnerability now exploited in the wild (CVE-2026-60004)corroborated
- NewsRently Smart Homeconfirmed
- NewsPayRange APIconfirmed
- NewsZoneminderconfirmed
- NewsRently Smart Homeconfirmed
- NewsPayRange APIconfirmed
- NewsZoneminderconfirmed
- NewsBendix EC80 Brake ECUconfirmed
- NewsFURUNO FA-50 Class B AIS Transponderconfirmed
- NewsEbyte NE2-D11confirmed
- NewsEbyte NE2-D11confirmed
- NewsSiemens SIMATIC IoT2050 Advancedconfirmed
- NewsFURUNO FA-50 Class B AIS Transponderconfirmed
- NewsBendix EC80 Brake ECUconfirmed
- NewsSiemens SIMATIC IoT2050 Advancedconfirmed
- NewsSecurity Alert (A26-08-38): Vulnerability in F5 BIG-IP DNSconfirmed
- NewsKEV: CVE-2026-60004 — Gitea Gitea (Gitea Code Injection Vulnerability)confirmed
- NewsCISA Adds One Known Exploited Vulnerability to Catalogconfirmed
- NewsCISA orders urgent patching of actively exploited Zimbra flawcorroborated
- NewsCritical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836)claimed
- NewsTrueConf security advisory (AV26-835)confirmed
- NewsJFrog Artifactory Flaws Enable Software Supply Chain Attackscorroborated
- NewsJohnson Controls Simplex Incident Managerconfirmed
- NewsCitrix security advisory (AV26-833)confirmed
- NewsMLflow security advisory (AV26-832)confirmed
- NewsCISA Adds One Known Exploited Vulnerability to Catalogconfirmed
- NewsCritical RCE flaw in Windows IKE Extension now actively exploitedcorroborated
- NewsHIGH ALERT: Active exploitation of remote monitoring and management platform within Australiaconfirmed
- NewsHIGH ALERT: Active exploitation of remote monitoring and management platform within Australiaconfirmed
- NewsPatch bundle: Oracle Oracle Critical Security Patch Update Advisory - August 2026 — 1040 CVEs, 151 criticalcorroborated
- NewsMattermost security advisory (AV26-828)confirmed
- NewsCISA Malcolmconfirmed
- NewsCritical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projectscorroborated
- NewsApple security advisory (AV26-823)confirmed
- NewsCitrix security advisory (AV26-645) – Update 2confirmed
- NewsMicrosoft Edge security advisory (AV26-822)confirmed
- NewsCISA Adds One Known Exploited Vulnerability to Catalogconfirmed
- NewsAL26-018 - Vulnerability affecting Cisco ASA and Secure Firewall Threat Defense Software Remote Access SSL VPN - CVE-2026-20349confirmed
- NewsAVEVA Enterprise SCADAconfirmed
- NewsAVEVA Enterprise SCADAconfirmed
- NewsFlow Neuroscience FL-100confirmed
- NewsHaiwell IoT Cloud HMI Gatewayconfirmed
- NewsSiemens Solid Edgeconfirmed
- NewsANDRITZ HIPASE-250 and 250 SCALAconfirmed
- NewsSiemens Siveillance Videoconfirmed
- NewsSiemens License Server (SLS)confirmed
- NewsSiemens Desigo DXR and PXC Controllersconfirmed
- NewsHitachi Energy APM Edge Productconfirmed
- NewsSiemens LOGO! Soft Comfortconfirmed
- NewsSiemens Parasolidconfirmed
- NewsSiemens Simcenter Femapconfirmed
- NewsSiemens License Server (SLS)confirmed
- NewsSiemens Desigo DXR and PXC Controllersconfirmed
- NewsSiemens LOGO! Soft Comfortconfirmed
- NewsANDRITZ HIPASE-250 and 250 SCALAconfirmed
- NewsSiemens Siveillance Videoconfirmed
- NewsHitachi Energy APM Edge Productconfirmed
- NewsSiemens Solid Edgeconfirmed
- NewsSiemens Siveillance Videoconfirmed
- NewsSiemens Siveillance Videoconfirmed
- NewsHaiwell IoT Cloud HMI Gatewayconfirmed
- NewsHackers exploit critical Adobe Commerce flaw to hijack customer accountsconfirmed
- NewsCisco security advisory (AV26-807)confirmed
- NewsBulletin de sécurité Red Hat (AV26-803)confirmed
- NewsMicrosoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-dayscorroborated
- NewsGrafana security advisory (AV26-796)confirmed
- NewsPulsetto Vagus Nerve Stimulatorconfirmed
- NewsMira Hormone Monitor, Mira Android Appconfirmed
- NewsGunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networkscorroborated
- NewsKEV: CVE-2026-72898 — Metabase Metabase (Metabase SQL Injection Vulnerability)confirmed
- NewsChina-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flawcorroborated
- NewsWordPress security advisory (AV26-792)confirmed
- NewsWebPros security advisory (AV26-790)confirmed
- NewsGoogle security advisory (AV26-787)confirmed
- News200 accounts compromised in Swiss government’s Microsoft SharePoint breachcorroborated
- NewsCyberattack on North Carolina Ports ‘contained’ as Coast Guard, state officials investigatecorroborated
- NewsPhotos: Black Hat USA 2026corroborated
- NewsABB Ability Zenonconfirmed
- NewsJohnson Controls Inc. TL280confirmed
- NewsMedixant RadiAnt DICOMconfirmed
- NewsJohnson Controls Inc. TL280confirmed
- NewsPatch bundle: August 2026 Early Security Updates — 19 CVEs, 0 exploitedcorroborated
- NewsPaperclip AI Flaws Let Unauthenticated Attackers Run Commandscorroborated
- NewsCISA Adds One Known Exploited Vulnerability to Catalogconfirmed
- NewsNew OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitchcorroborated
- NewsCritical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markupcorroborated
- News128 Seconds to disruption: Microsoft Defender stops ransomware at QNETvendor research
- NewsCheckpoint security advisory (AV26-774)confirmed
- NewsThermo Fisher Applied Biosystems Genetic Analyzersconfirmed
- NewsNew cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Rootconfirmed
- NewsCISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromisesvendor research
- News[UPDATE] [hoch] MariaDB: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriffconfirmed
- News[UPDATE] [mittel] libssh: Mehrere Schwachstellen ermöglichen Manipulation von Dateien und DoSconfirmed
- News[UPDATE] [hoch] poppler: Schwachstelle ermöglicht Codeausführungconfirmed
- News[UPDATE] [hoch] PowerDNS: Mehrere Schwachstellenconfirmed
- News[UPDATE] [niedrig] Checkmk: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen und Manipulation von Dateienconfirmed
- News[UPDATE] [hoch] FreeRDP: Schwachstelle ermöglicht Codeausführungconfirmed
- News[UPDATE] [niedrig] Contao: Schwachstelle ermöglicht Offenlegung von Informationenconfirmed
- News[UPDATE] [hoch] Node.js: Mehrere Schwachstellenconfirmed
- NewsN-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incompletecorroborated
- NewsHugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Codecorroborated
- NewsKEV: CVE-2026-18577 — N-able N-central (N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability)confirmed
- NewsGoogle security advisory (AV26-768)confirmed
- NewsRails security advisory (AV26-767)confirmed
- NewsSolarWinds security advisory (AV26-766)confirmed
- News[UPDATE] [hoch] PackageKit: Schwachstelle ermöglicht Privilegieneskalationconfirmed
- News[UPDATE] [mittel] GIMP: Schwachstelle ermöglicht Codeausführungconfirmed
- News[NEU] [hoch] Rancher: Mehrere Schwachstellenconfirmed
- NewsWhat the Hugging Face breach reveals about defense in the age of agentic AIcorroborated
- News[NEU] [mittel] WP Royal Royal Elementor Addons: Schwachstelle ermöglicht Offenlegung von Informationenconfirmed
- News[NEU] [hoch] PHP: Mehrere Schwachstellenconfirmed
- News[UPDATE] [mittel] Apache Tomcat: Mehrere Schwachstellenconfirmed
- News[UPDATE] [mittel] ImageMagick: Schwachstelle ermöglicht Denial of Serviceconfirmed
- News[UPDATE] [mittel] IBM Langflow Desktop OSS: Schwachstelle ermöglicht Offenlegung von Informationenconfirmed
- NewsPHP Group security advisory (AV26-764)confirmed
- NewsVMware security advisory (AV26-763)confirmed
- News[Control Systems] Phoenix Contact security advisory (AV26-762)confirmed
- NewsWebPros security advisory (AV26-761)confirmed
- NewsSpring security advisory (AV26-759)confirmed
- NewsGitLab security advisory (AV26-758)confirmed
- NewsCisco security advisory (AV26-757)confirmed
- NewsJohnson Controls OpenBlue Employeeconfirmed
- NewsNASA Core Flight System (cFS) Health & Safety (HS) Applicationconfirmed
- NewsMikroTik RouterOSconfirmed
- NewsMitsubishi Electric CC-Link IE TSN Communication Protocolconfirmed
- NewsWatchfire Controller Softwareconfirmed
- NewsSchneider Electric IGSSconfirmed
- NewsToptech Systems RCU II+ and Multiload II+confirmed
- Newso6 Automation open62541confirmed
- NewsMikroTik RouterOSconfirmed
- NewsRockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Moduleconfirmed
- NewsSchneider Electric IGSSconfirmed
- NewsJohnson Controls OpenBlue Employeeconfirmed
- NewsCISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCsconfirmed
- News[UPDATE] [mittel] vim: Schwachstelle ermöglicht Denial of Serviceconfirmed
- News[NEU] [hoch] IBM App Connect Enterprise: Mehrere Schwachstellenconfirmed
- News[NEU] [hoch] Google Chrome: Mehrere Schwachstellenconfirmed
- News[NEU] [mittel] Red Hat OpenStack (Neutron): Schwachstelle ermöglicht Manipulation von Daten und Umgehen von Sicherheitsvorkehrungenconfirmed
- News[UPDATE] [niedrig] libxml2: Schwachstelle ermöglicht Denial of Serviceconfirmed
- News[UPDATE] [mittel] Netty: Mehrere Schwachstellenconfirmed
- NewsCritical VM Escape Vulnerability Patched in VMware ESXicorroborated
- NewsKEV: CVE-2026-20316 — Cisco Secure Firewall Management Center (FMC) (Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability)confirmed
- Newsigloohome Smart Lock Mobile Applicationconfirmed
- NewsSiemens Mendix Runtimeconfirmed
- NewsSiemens SIMATIC S7-PLCSIM Advancedconfirmed
- NewsSiemens Desigo CCconfirmed
- NewsABB KNX Update Toolconfirmed
- News[UPDATE] [hoch] Oracle Solaris Drittanbieterkomponenten: Mehrere Schwachstellenconfirmed
- News[UPDATE] [mittel] OpenBSD: Schwachstelle ermöglicht nicht spezifizierten Angriffconfirmed
- News[UPDATE] [hoch] cPanel cPanel/WHM: Mehrere Schwachstellenconfirmed
- NewsCritical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging Incorroborated
- NewsErlang security advisory (AV26-750)confirmed
- NewsRedis security advisory (AV26-748)confirmed
- News[UPDATE] [hoch] Shibboleth Service Provider: Schwachstelle ermöglicht SQL Injectionconfirmed
- News[UPDATE] [mittel] CPython: Schwachstelle ermöglicht Manipulation von Datenconfirmed
- News[UPDATE] [mittel] Octopus Deploy: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungenconfirmed
- News[UPDATE] [hoch] Google Cloud Platform: Schwachstelle ermöglicht Cross-Site Scriptingconfirmed
- News[UPDATE] [hoch] ffmpeg: Schwachstelle ermöglicht Codeausführung und Denial of Serviceconfirmed
- NewsKEV: CVE-2026-16812 — Arista VeloCloud Orchestrator (Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability)confirmed
- NewsKEV: CVE-2025-68686 — Fortinet FortiOS (Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability)confirmed
- NewsLeak-site claim: ExfilSquad lists Frontier Airlinescorroborated
- NewsCalifornia AG breach notice: Zacks Investment Research, Inc.confirmed
- NewsProgress security advisory (AV26-746)confirmed
- NewsHPE security advisory (AV26-745)confirmed
- NewsMongoDB security advisory (AV26-744)confirmed
- NewsEricsson security advisory (AV26-743)confirmed
- News[Control Systems] Moxa security advisory (AV26-742)confirmed
- NewsGoogle Chrome security advisory (AV26-741)confirmed
- NewsMicrosoft Edge security advisory (AV26-740)confirmed
- News[UPDATE] [niedrig] BusyBox: Mehrere Schwachstellenconfirmed
- News[UPDATE] [mittel] wget: Mehrere Schwachstellen ermöglichen Denial of Serviceconfirmed
- News[UPDATE] [hoch] rsyslog: Schwachstelle ermöglicht Denial of Service und potenziell Codeausführungconfirmed
- NewsClop ransomware targets Windchill, FlexPLM in data theft attackscorroborated
- NewsRussian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codescorroborated
- NewsJetBrains security advisory (AV26-739)confirmed
- NewsJohnson Controls XAAP Androidconfirmed
- NewsPanduit IntraVUEconfirmed
- NewsMZ Automation libIEC61850confirmed
- NewsWeintek cMT3092Xconfirmed
- NewsRussian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suiteconfirmed
- News[UPDATE] [mittel] Podman: Schwachstelle ermöglicht Offenlegung von Informationenconfirmed
- News[UPDATE] [mittel] systemd: Mehrere Schwachstellenconfirmed
- News[UPDATE] [mittel] GStreamer: Mehrere Schwachstellenconfirmed
- News[UPDATE] [mittel] Veeam Backup & Replication: Schwachstelle ermöglicht Privilegieneskalationconfirmed
- NewsUS Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devicescorroborated
- NewsGitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tiercorroborated
- Newsn8n security advisory (AV26-733)confirmed
- NewsISC BIND security advisory (AV26-732)confirmed
- NewsAtlassian security advisory (AV26-731)confirmed
- NewsOracle security advisory – July 2026 quarterly rollup (AV26-729)confirmed
- NewsUbuntu snap-confine Vulnerability Enables Local Root Accesscorroborated
- News[UPDATE] [mittel] Linux Kernel (Bluetooth): Mehrere Schwachstellen ermöglichen Denial of Serviceconfirmed
- News[UPDATE] [mittel] libvirt: Schwachstelle ermöglicht Denial of Serviceconfirmed
- News[UPDATE] [hoch] Evince: Schwachstelle ermöglicht Codeausführungconfirmed
- News[UPDATE] [hoch] Apache Tomcat und Tomcat Native: Mehrere Schwachstellenconfirmed
- NewsHPE security advisory (AV26-727)confirmed
- NewsGoogle Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilitiescorroborated
- NewsTenable security advisory (AV26-724)confirmed
- NewsRockwell Automation Studio 5000 Logix Designerconfirmed
- NewsSiemens CADRAconfirmed
- NewsSiemens Opcenter Xconfirmed
- NewsSiemens IAM Clientconfirmed
- NewsSiemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFWconfirmed
- NewsCritical Palo Alto VPN bug now exploited by Qilin ransomware gangconfirmed
- NewsCritical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Executioncorroborated
- NewsKEV: CVE-2026-0770 — Langflow Langflow (Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability)confirmed
- NewsEstée Lauder discloses data breach via Oracle E-Business flawcorroborated
- NewsInc Ransomware Exploits SonicWall SMA Zero-Dayscorroborated
- NewsProgress Restores ShareFile Storage Zones Access After Security Warningconfirmed
- NewsCISA Adds Two Known Exploited Vulnerabilities to Catalogconfirmed
- NewsWhat to Know About China's DeepSeek AIcorroborated
Detect
- NewsCISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadlinecorroborated
- NewsCisco security advisory (AV26-197) – Update 3confirmed
- NewsCISA Adds Four Known Exploited Vulnerabilities to Catalogconfirmed
- NewsMicrosoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploitedcorroborated
- NewsIvanti security advisory (AV26-897)confirmed
- NewsMikrotik security advisory (AV26-887)confirmed
- NewsInductive Automation Ignitionconfirmed
- NewsInductive Automation Ignitionconfirmed
- NewsProgress Software security advisory (AV26-875)confirmed
- NewsRockwell Automation RSLinx Classicconfirmed
- NewsPaperCut releases second emergency patch for exploited flawscorroborated
- NewsXiiaozet LK100Wconfirmed
- NewsXiiaozet LK100Wconfirmed
- NewsCISA orders feds to patch Citrix NetScaler RCE flaw by Saturdayconfirmed
- NewsCritical Gitea vulnerability now exploited in the wild (CVE-2026-60004)corroborated
- NewsCISA Adds One Known Exploited Vulnerability to Catalogconfirmed
- NewsCitrix security advisory (AV26-833)confirmed
- NewsCritical RCE flaw in Windows IKE Extension now actively exploitedcorroborated
- NewsHIGH ALERT: Active exploitation of remote monitoring and management platform within Australiaconfirmed
- NewsHIGH ALERT: Active exploitation of remote monitoring and management platform within Australiaconfirmed
- NewsPatch bundle: Oracle Oracle Critical Security Patch Update Advisory - August 2026 — 1040 CVEs, 151 criticalcorroborated
- NewsANDRITZ HIPASE-250 and 250 SCALAconfirmed
- NewsSiemens License Server (SLS)confirmed
- NewsSiemens License Server (SLS)confirmed
- NewsANDRITZ HIPASE-250 and 250 SCALAconfirmed
- NewsPulsetto Vagus Nerve Stimulatorconfirmed
- NewsGunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networkscorroborated
- NewsPatch bundle: August 2026 Early Security Updates — 19 CVEs, 0 exploitedcorroborated
- NewsPaperclip AI Flaws Let Unauthenticated Attackers Run Commandscorroborated
- News128 Seconds to disruption: Microsoft Defender stops ransomware at QNETvendor research
- NewsCheckpoint security advisory (AV26-774)confirmed
- NewsThermo Fisher Applied Biosystems Genetic Analyzersconfirmed
- NewsCISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromisesvendor research
- NewsN-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incompletecorroborated
- NewsKEV: CVE-2026-18577 — N-able N-central (N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability)confirmed
- NewsRails security advisory (AV26-767)confirmed
- NewsRockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Moduleconfirmed
- NewsSiemens SIMATIC S7-PLCSIM Advancedconfirmed
- NewsABB KNX Update Toolconfirmed
- NewsCritical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging Incorroborated
- NewsKEV: CVE-2025-68686 — Fortinet FortiOS (Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability)confirmed
- NewsProgress security advisory (AV26-746)confirmed
- NewsHPE security advisory (AV26-727)confirmed
- NewsSiemens Opcenter Xconfirmed
- NewsKEV: CVE-2026-0770 — Langflow Langflow (Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability)confirmed
- NewsProgress Restores ShareFile Storage Zones Access After Security Warningconfirmed
- NewsCISA Adds Two Known Exploited Vulnerabilities to Catalogconfirmed
Worked cases
Incidents from the harvested record that this service addresses. These do not depend on this week’s news; the badged items above do.
- Ransomware sold as a product, with security professionals recruited as the supply chain
- Turn the remote-access appliance into a credential collector, then patch the authentication server to accept a chosen value
- An exploit that applies on viewing, defeating every control built around user action
- Tell the device to mail you its own configuration, using the management protocol's write function
- Compromise the carrier, and inherit everyone whose traffic crosses it
- Encrypt only the virtual estate, exfiltrate through the victim's own cloud tooling, and delete the encryptor afterwards
- Exploited inside the mandated patching window, then exploited again on a second instance during the response
- Select victims by exposure alone, finish the same day, and change name to stay unattributed
- Extort the victim a second time, from inside your own operation
- Chain four flaws in an end-of-life security appliance
- The account of someone who left, and the backup that kept their desk
- A state-linked group that sells the access instead of using it
- Ransom hospitals to pay for the nuclear-programme espionage
- Take dozens of build servers, then wait
- The pipeline stopped because the company stopped it
- Phish from inside the marketing platform the recipient already trusts
- The tool that certifies the appliance is clean can be told to say so
- Phish the credential, then change where the money is sent
WAF 172
Active threats this quarter that WAF addresses:
Prevent
- NewsGitLab security advisory (AV26-917)confirmed
- NewsCISA Adds Three Known Exploited Vulnerabilities to Catalogconfirmed
- NewsPalo Alto Networks security advisory (AV26-905)confirmed
- NewsAVEVA Pipeline Integrity Monitorconfirmed
- NewsNextGen Healthcare Mirth Connectconfirmed
- NewsAVEVA Pipeline Integrity Monitorconfirmed
- NewsOrthanc DICOM Serverconfirmed
- NewsCISA Adds Two Known Exploited Vulnerabilities to Catalogconfirmed
- NewsST Engineering iDirect iQ-Series Terminals (Update A)confirmed
- NewsCISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadlinecorroborated
- NewsCisco security advisory (AV26-197) – Update 3confirmed
- NewsFortinet security advisory (AV26-023) - Update 1confirmed
- NewsGoogle security advisory (AV26-904)confirmed
- NewsConnectWise security advisory (AV26-903)confirmed
- NewsCheck Point security advisory (AV26-902)confirmed
- News2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Serverconfirmed
- NewsCISA Adds Four Known Exploited Vulnerabilities to Catalogconfirmed
- NewsCSA Singapore alert: 9 September 2026 Active Exploitation of Vulnerability in N-Able N-Central Attackers are exploiting a critical vulnerability in N-Able N-Central remote management and monitoring tool to execute code remotely without authentication. Patch immediately. Alertsconfirmed
- NewsMicrosoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploitedcorroborated
- NewsIvanti security advisory (AV26-897)confirmed
- NewsMikrotik security advisory (AV26-887)confirmed
- NewsAdobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shellcorroborated
- NewsAdobe Commerce Zero-Day Exploited to Backdoor Online Storescorroborated
- NewsN-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218)corroborated
- NewsTycon Systems TPDIN-Monitor-WEB3confirmed
- NewsIXON VPN Clientconfirmed
- NewsTycon Systems TPDIN-Monitor-WEB3confirmed
- NewsIXON VPN Clientconfirmed
- NewsPyramid Solutions NetStaX EtherNet/IP Stackconfirmed
- NewsRockwell Automation 1756-ENBT Moduleconfirmed
- NewsPyramid Solutions NetStaX EtherNet/IP Stackconfirmed
- NewsRockwell Automation 1756-ENBT Moduleconfirmed
- NewsProgress Software security advisory (AV26-875)confirmed
- NewsMalicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pagescorroborated
- NewsSonicWall security advisory (AV26-872)confirmed
- NewsSonicWall Warns of Two SMA1000 Zero-Days Exploited in Attackscorroborated
- NewsJFrog security advisory (AV26-867)confirmed
- NewsRockwell Automation RSLinx Classicconfirmed
- NewsCISA Adds Two Known Exploited Vulnerabilities to Catalogconfirmed
- NewsPaperCut releases second emergency patch for exploited flawscorroborated
- NewsWebPros security advisory (AV26-854)confirmed
- NewsAll-Line Equipment Company Fuel-Bossconfirmed
- NewsAll-Line Equipment Company Fuel-Bossconfirmed
- NewsCISA Adds Three Known Exploited Vulnerabilities to Catalogconfirmed
- NewsMitsubishi Electric Multiple FA Products (Update D)confirmed
- NewsApplied Systems Engineering ASE2000 V2 Communications Test Setconfirmed
- NewsMitsubishi Electric CNC Series (Update A)confirmed
- NewsEbyte NA111-Mconfirmed
- NewsXiiaozet LK100Wconfirmed
- NewsApplied Systems Engineering ASE2000 V2 Communications Test Setconfirmed
- NewsMitsubishi Electric CNC Series (Update A)confirmed
- NewsXiiaozet LK100Wconfirmed
- NewsEbyte NA111-Mconfirmed
- NewsCISA orders feds to patch Citrix NetScaler RCE flaw by Saturdayconfirmed
- NewsNext.js security advisory (AV26-851)confirmed
- NewsJustice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical Infrastructureconfirmed
- NewsCritical Gitea vulnerability now exploited in the wild (CVE-2026-60004)corroborated
- NewsPayRange APIconfirmed
- NewsZoneminderconfirmed
- NewsPayRange APIconfirmed
- NewsZoneminderconfirmed
- NewsBendix EC80 Brake ECUconfirmed
- NewsFURUNO FA-50 Class B AIS Transponderconfirmed
- NewsEbyte NE2-D11confirmed
- NewsEbyte NE2-D11confirmed
- NewsSiemens SIMATIC IoT2050 Advancedconfirmed
- NewsFURUNO FA-50 Class B AIS Transponderconfirmed
- NewsBendix EC80 Brake ECUconfirmed
- NewsSiemens SIMATIC IoT2050 Advancedconfirmed
- NewsKEV: CVE-2026-60004 — Gitea Gitea (Gitea Code Injection Vulnerability)confirmed
- NewsCISA Adds One Known Exploited Vulnerability to Catalogconfirmed
- NewsCISA orders urgent patching of actively exploited Zimbra flawcorroborated
- NewsCritical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836)claimed
- NewsTrueConf security advisory (AV26-835)confirmed
- NewsJFrog Artifactory Flaws Enable Software Supply Chain Attackscorroborated
- NewsCitrix security advisory (AV26-833)confirmed
- NewsMLflow security advisory (AV26-832)confirmed
- NewsCISA Adds One Known Exploited Vulnerability to Catalogconfirmed
- NewsCritical RCE flaw in Windows IKE Extension now actively exploitedcorroborated
- NewsHIGH ALERT: Active exploitation of remote monitoring and management platform within Australiaconfirmed
- NewsHIGH ALERT: Active exploitation of remote monitoring and management platform within Australiaconfirmed
- NewsPatch bundle: Oracle Oracle Critical Security Patch Update Advisory - August 2026 — 1040 CVEs, 151 criticalcorroborated
- NewsMattermost security advisory (AV26-828)confirmed
- NewsCISA Malcolmconfirmed
- NewsCritical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projectscorroborated
- NewsApple security advisory (AV26-823)confirmed
- NewsCitrix security advisory (AV26-645) – Update 2confirmed
- NewsMicrosoft Edge security advisory (AV26-822)confirmed
- NewsCISA Adds One Known Exploited Vulnerability to Catalogconfirmed
- NewsAVEVA Enterprise SCADAconfirmed
- NewsAVEVA Enterprise SCADAconfirmed
- NewsHaiwell IoT Cloud HMI Gatewayconfirmed
- NewsSiemens Solid Edgeconfirmed
- NewsANDRITZ HIPASE-250 and 250 SCALAconfirmed
- NewsSiemens Siveillance Videoconfirmed
- NewsSiemens License Server (SLS)confirmed
- NewsHitachi Energy APM Edge Productconfirmed
- NewsSiemens Parasolidconfirmed
- NewsSiemens Simcenter Femapconfirmed
- NewsSiemens License Server (SLS)confirmed
- NewsANDRITZ HIPASE-250 and 250 SCALAconfirmed
- NewsSiemens Siveillance Videoconfirmed
- NewsHitachi Energy APM Edge Productconfirmed
- NewsSiemens Solid Edgeconfirmed
- NewsSiemens Siveillance Videoconfirmed
- NewsSiemens Siveillance Videoconfirmed
- NewsHaiwell IoT Cloud HMI Gatewayconfirmed
- NewsHackers exploit critical Adobe Commerce flaw to hijack customer accountsconfirmed
- NewsCisco security advisory (AV26-807)confirmed
- NewsGrafana security advisory (AV26-796)confirmed
- NewsMira Hormone Monitor, Mira Android Appconfirmed
- NewsGunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networkscorroborated
- NewsKEV: CVE-2026-72898 — Metabase Metabase (Metabase SQL Injection Vulnerability)confirmed
- NewsChina-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flawcorroborated
- NewsWordPress security advisory (AV26-792)confirmed
- NewsWebPros security advisory (AV26-790)confirmed
- News200 accounts compromised in Swiss government’s Microsoft SharePoint breachcorroborated
- NewsCyberattack on North Carolina Ports ‘contained’ as Coast Guard, state officials investigatecorroborated
- NewsABB Ability Zenonconfirmed
- NewsMedixant RadiAnt DICOMconfirmed
- NewsPatch bundle: August 2026 Early Security Updates — 19 CVEs, 0 exploitedcorroborated
- NewsPaperclip AI Flaws Let Unauthenticated Attackers Run Commandscorroborated
- NewsCISA Adds One Known Exploited Vulnerability to Catalogconfirmed
- NewsNew OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitchcorroborated
- NewsCritical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markupcorroborated
- News128 Seconds to disruption: Microsoft Defender stops ransomware at QNETvendor research
- NewsCheckpoint security advisory (AV26-774)confirmed
- NewsNew cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Rootconfirmed
- NewsCISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromisesvendor research
- NewsN-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incompletecorroborated
- NewsKEV: CVE-2026-18577 — N-able N-central (N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability)confirmed
- NewsRails security advisory (AV26-767)confirmed
- NewsSolarWinds security advisory (AV26-766)confirmed
- NewsWhat the Hugging Face breach reveals about defense in the age of agentic AIcorroborated
- NewsVMware security advisory (AV26-763)confirmed
- News[Control Systems] Phoenix Contact security advisory (AV26-762)confirmed
- NewsWebPros security advisory (AV26-761)confirmed
- NewsSpring security advisory (AV26-759)confirmed
- NewsJohnson Controls OpenBlue Employeeconfirmed
- NewsSchneider Electric IGSSconfirmed
- NewsToptech Systems RCU II+ and Multiload II+confirmed
- Newso6 Automation open62541confirmed
- NewsSchneider Electric IGSSconfirmed
- NewsJohnson Controls OpenBlue Employeeconfirmed
- NewsCISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCsconfirmed
- NewsCritical VM Escape Vulnerability Patched in VMware ESXicorroborated
- NewsKEV: CVE-2026-20316 — Cisco Secure Firewall Management Center (FMC) (Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability)confirmed
- NewsSiemens SIMATIC S7-PLCSIM Advancedconfirmed
- NewsSiemens Desigo CCconfirmed
- NewsCritical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging Incorroborated
- NewsKEV: CVE-2026-16812 — Arista VeloCloud Orchestrator (Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability)confirmed
- NewsKEV: CVE-2025-68686 — Fortinet FortiOS (Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability)confirmed
- NewsCalifornia AG breach notice: Zacks Investment Research, Inc.confirmed
- NewsProgress security advisory (AV26-746)confirmed
- NewsClop ransomware targets Windchill, FlexPLM in data theft attackscorroborated
- NewsRussian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codescorroborated
- NewsJohnson Controls XAAP Androidconfirmed
- NewsMZ Automation libIEC61850confirmed
- NewsRussian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suiteconfirmed
- NewsUS Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devicescorroborated
- NewsUbuntu snap-confine Vulnerability Enables Local Root Accesscorroborated
- NewsHPE security advisory (AV26-727)confirmed
- NewsTenable security advisory (AV26-724)confirmed
- NewsRockwell Automation Studio 5000 Logix Designerconfirmed
- NewsSiemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFWconfirmed
- NewsCritical Palo Alto VPN bug now exploited by Qilin ransomware gangconfirmed
- NewsCritical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Executioncorroborated
- NewsKEV: CVE-2026-0770 — Langflow Langflow (Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability)confirmed
- NewsInc Ransomware Exploits SonicWall SMA Zero-Dayscorroborated
- NewsProgress Restores ShareFile Storage Zones Access After Security Warningconfirmed
- NewsCISA Adds Two Known Exploited Vulnerabilities to Catalogconfirmed
- NewsWhat to Know About China's DeepSeek AIcorroborated
Detect
- NewsAVEVA Pipeline Integrity Monitorconfirmed
- NewsAVEVA Pipeline Integrity Monitorconfirmed
- NewsFortinet security advisory (AV26-023) - Update 1confirmed
- NewsCSA Singapore alert: 9 September 2026 Active Exploitation of Vulnerability in N-Able N-Central Attackers are exploiting a critical vulnerability in N-Able N-Central remote management and monitoring tool to execute code remotely without authentication. Patch immediately. Alertsconfirmed
- NewsN-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218)corroborated
- NewsIXON VPN Clientconfirmed
- NewsIXON VPN Clientconfirmed
- NewsRockwell Automation 1756-ENBT Moduleconfirmed
- NewsRockwell Automation 1756-ENBT Moduleconfirmed
- NewsEbyte NA111-Mconfirmed
- NewsEbyte NA111-Mconfirmed
- NewsANDRITZ HIPASE-250 and 250 SCALAconfirmed
- NewsANDRITZ HIPASE-250 and 250 SCALAconfirmed
- NewsWordPress security advisory (AV26-792)confirmed
- NewsKEV: CVE-2026-18577 — N-able N-central (N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability)confirmed
- NewsSpring security advisory (AV26-759)confirmed
- NewsJohnson Controls OpenBlue Employeeconfirmed
- NewsJohnson Controls OpenBlue Employeeconfirmed
- NewsCritical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging Incorroborated
- NewsKEV: CVE-2025-68686 — Fortinet FortiOS (Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability)confirmed
- NewsCalifornia AG breach notice: Zacks Investment Research, Inc.confirmed
- NewsProgress security advisory (AV26-746)confirmed
- NewsJohnson Controls XAAP Androidconfirmed
- NewsRussian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suiteconfirmed
- NewsSiemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFWconfirmed
- NewsCritical Palo Alto VPN bug now exploited by Qilin ransomware gangconfirmed
- NewsCISA Adds Two Known Exploited Vulnerabilities to Catalogconfirmed
Worked cases
Incidents from the harvested record that this service addresses. These do not depend on this week’s news; the badged items above do.
- Ransomware sold as a product, with security professionals recruited as the supply chain
- Turn the remote-access appliance into a credential collector, then patch the authentication server to accept a chosen value
- Tell the device to mail you its own configuration, using the management protocol's write function
- Compromise the carrier, and inherit everyone whose traffic crosses it
- Make the victim run the payload as proof they are human
- Encrypt only the virtual estate, exfiltrate through the victim's own cloud tooling, and delete the encryptor afterwards
- Exploited inside the mandated patching window, then exploited again on a second instance during the response
- Chain four flaws in an end-of-life security appliance
- Ransom hospitals to pay for the nuclear-programme espionage
- The pipeline stopped because the company stopped it
- The tool that certifies the appliance is clean can be told to say so
- The QR code exists to get the victim off the managed device
Gateway 8
Active threats this quarter that Gateway addresses:
Prevent
- NewsSpring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teamsvendor research
- NewsHijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malwarecorroborated
- News6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026corroborated
- NewsHacked Public Wi-Fi Gateways Used to Harvest Corporate Credentialscorroborated
- NewsUK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisationsconfirmed
- NewsRussian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suiteconfirmed
- NewsFake FBI agents target people who already got scammedcorroborated
- NewsResearchers Uncover North Korean 'ClickFake' Campaign Targeting Web3 Proscorroborated
Worked cases
Incidents from the harvested record that this service addresses. These do not depend on this week’s news; the badged items above do.
- An exploit that applies on viewing, defeating every control built around user action
- Tell the device to mail you its own configuration, using the management protocol's write function
- Compromise the carrier, and inherit everyone whose traffic crosses it
- Make the victim run the payload as proof they are human
- Encrypt only the virtual estate, exfiltrate through the victim's own cloud tooling, and delete the encryptor afterwards
- Exploited inside the mandated patching window, then exploited again on a second instance during the response
- Extort the victim a second time, from inside your own operation
- Chain four flaws in an end-of-life security appliance
- Register your own device as the second factor, and the lock is now yours
- The identities that cannot have a second factor
- A state-linked group that sells the access instead of using it
- Ransom hospitals to pay for the nuclear-programme espionage
- Learn the help desk's reset procedure, then call back and use it
- The pipeline stopped because the company stopped it
- Phish from inside the marketing platform the recipient already trusts
- He says he is from IT, and if you will not let him in remotely he drives over
- Phish the credential, then change where the money is sent
- The QR code exists to get the victim off the managed device
IEP (M365 email protection) 8
Active threats this quarter that IEP (M365 email protection) addresses:
Prevent
- NewsSpring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teamsvendor research
- NewsHijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malwarecorroborated
- News6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026corroborated
- NewsHacked Public Wi-Fi Gateways Used to Harvest Corporate Credentialscorroborated
- NewsUK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisationsconfirmed
- NewsRussian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suiteconfirmed
- NewsFake FBI agents target people who already got scammedcorroborated
- NewsResearchers Uncover North Korean 'ClickFake' Campaign Targeting Web3 Proscorroborated
Worked cases
Incidents from the harvested record that this service addresses. These do not depend on this week’s news; the badged items above do.
- An exploit that applies on viewing, defeating every control built around user action
- Tell the device to mail you its own configuration, using the management protocol's write function
- Compromise the carrier, and inherit everyone whose traffic crosses it
- Make the victim run the payload as proof they are human
- Encrypt only the virtual estate, exfiltrate through the victim's own cloud tooling, and delete the encryptor afterwards
- Exploited inside the mandated patching window, then exploited again on a second instance during the response
- Extort the victim a second time, from inside your own operation
- Chain four flaws in an end-of-life security appliance
- Register your own device as the second factor, and the lock is now yours
- The identities that cannot have a second factor
- A state-linked group that sells the access instead of using it
- Ransom hospitals to pay for the nuclear-programme espionage
- Learn the help desk's reset procedure, then call back and use it
- The pipeline stopped because the company stopped it
- Phish from inside the marketing platform the recipient already trusts
- He says he is from IT, and if you will not let him in remotely he drives over
- Phish the credential, then change where the money is sent
- The QR code exists to get the victim off the managed device
Phishing simulation 8
Active threats this quarter that Phishing simulation addresses:
Prevent
- NewsSpring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teamsvendor research
- NewsHijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malwarecorroborated
- News6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026corroborated
- NewsHacked Public Wi-Fi Gateways Used to Harvest Corporate Credentialscorroborated
- NewsUK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisationsconfirmed
- NewsRussian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suiteconfirmed
- NewsFake FBI agents target people who already got scammedcorroborated
- NewsResearchers Uncover North Korean 'ClickFake' Campaign Targeting Web3 Proscorroborated
Worked cases
Incidents from the harvested record that this service addresses. These do not depend on this week’s news; the badged items above do.
- An exploit that applies on viewing, defeating every control built around user action
- Make the victim run the payload as proof they are human
- The account of someone who left, and the backup that kept their desk
- Learn the help desk's reset procedure, then call back and use it
- Extort by telling the victim's customers
- The pipeline stopped because the company stopped it
- Phish from inside the marketing platform the recipient already trusts
- He says he is from IT, and if you will not let him in remotely he drives over
- Phish the credential, then change where the money is sent
- The QR code exists to get the victim off the managed device
Training 8
Active threats this quarter that Training addresses:
Prevent
- NewsSpring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teamsvendor research
- NewsHijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malwarecorroborated
- News6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026corroborated
- NewsHacked Public Wi-Fi Gateways Used to Harvest Corporate Credentialscorroborated
- NewsUK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisationsconfirmed
- NewsRussian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suiteconfirmed
- NewsFake FBI agents target people who already got scammedcorroborated
- NewsResearchers Uncover North Korean 'ClickFake' Campaign Targeting Web3 Proscorroborated
Worked cases
Incidents from the harvested record that this service addresses. These do not depend on this week’s news; the badged items above do.
- An exploit that applies on viewing, defeating every control built around user action
- Make the victim run the payload as proof they are human
- The account of someone who left, and the backup that kept their desk
- Learn the help desk's reset procedure, then call back and use it
- Extort by telling the victim's customers
- The pipeline stopped because the company stopped it
- Phish from inside the marketing platform the recipient already trusts
- He says he is from IT, and if you will not let him in remotely he drives over
- Phish the credential, then change where the money is sent
- The QR code exists to get the victim off the managed device
DLP 28
Active threats this quarter that DLP addresses:
Prevent
- News8-K Item 8.01: CONDUENT Inc discloses a cybersecurity incident (not filed as material)confirmed
- News8-K Item 8.01: Rigetti Computing, Inc. (RGTI, RGTIW) discloses a cybersecurity incident (not filed as material)confirmed
- News8-K Item 8.01: D-Wave Quantum Inc. discloses a cybersecurity incident (not filed as material)confirmed
- News8-K Item 1.05: BOSTON SCIENTIFIC CORP reports material cybersecurity incidentconfirmed
- News8-K Item 8.01: UNITED NATURAL FOODS INC discloses a cybersecurity incident (not filed as material)confirmed
- News8-K Item 8.01: Veradigm Inc. discloses a cybersecurity incident (not filed as material)confirmed
- News8-K Item 1.05: Park Dental Partners, Inc. reports material cybersecurity incidentconfirmed
- News8-K Item 1.05: Nutex Health Inc. reports material cybersecurity incidentconfirmed
- NewsCalifornia AG breach notice: Bennett Collegeconfirmed
- NewsNorth Korean remote workers are broadening their job hunt beyond ITcorroborated
- NewsTwo Alleged ‘TeamPCP’ Hackers Arrested in Australiacorroborated
- NewsGunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networkscorroborated
- NewsChina-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flawcorroborated
- NewsCorporate Data Stolen in Levi Strauss Cyberattackcorroborated
- NewsRansom Cartel ransomware creator sentenced to 16 years in prisoncorroborated
- News77 Open VSX extensions found harvesting developer infocorroborated
- NewsN-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incompletecorroborated
- NewsHijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malwarecorroborated
- News8-K Item 1.05: AMGEN INC reports material cybersecurity incidentconfirmed
- NewsIn the Hugging Face breach, OpenAI’s hacker was noisy and fast — but not unstoppablecorroborated
- News8-K Item 1.05: River Financial Corp reports material cybersecurity incidentconfirmed
- NewsLeak-site claim: shinyhunters lists Ernst & Youngcorroborated
- NewsHacked Public Wi-Fi Gateways Used to Harvest Corporate Credentialscorroborated
- NewsLeak-site claim: ExfilSquad lists Frontier Airlinescorroborated
- NewsClop ransomware targets Windchill, FlexPLM in data theft attackscorroborated
- NewsMultiple Jscrambler Packages Impacted by Supply Chain Attackcorroborated
- News8-K Item 1.05: Hewlett Packard Enterprise Co reports material cybersecurity incidentconfirmed
- News8-K Item 8.01: National Bank Holdings Corp discloses a cybersecurity incident (not filed as material)confirmed
Worked cases
Incidents from the harvested record that this service addresses. These do not depend on this week’s news; the badged items above do.
- Ransomware sold as a product, with security professionals recruited as the supply chain
- An exploit that applies on viewing, defeating every control built around user action
- Tell the device to mail you its own configuration, using the management protocol's write function
- Compromise the carrier, and inherit everyone whose traffic crosses it
- Encrypt only the virtual estate, exfiltrate through the victim's own cloud tooling, and delete the encryptor afterwards
- Select victims by exposure alone, finish the same day, and change name to stay unattributed
- Extort the victim a second time, from inside your own operation
- The account of someone who left, and the backup that kept their desk
- A state-linked group that sells the access instead of using it
- Ransom hospitals to pay for the nuclear-programme espionage
- Extort by telling the victim's customers
- He says he is from IT, and if you will not let him in remotely he drives over
- Phish the credential, then change where the money is sent
Entra ID backup
No story in this window ties to Entra ID backup specifically:
Identity backup restores directory objects after tampering or deletion. 50 extortion or ransomware claims this window, none naming an Entra ID or Azure AD estate.
Entra ID backup
Worked cases this service addresses:
- Ransomware sold as a product, with security professionals recruited as the supply chain
- Encrypt only the virtual estate, exfiltrate through the victim's own cloud tooling, and delete the encryptor afterwards
- Select victims by exposure alone, finish the same day, and change name to stay unattributed
- Extort the victim a second time, from inside your own operation
- The pipeline stopped because the company stopped it
Google Backup
No story in this window ties to Google Backup specifically:
Backup is the recovery arm when data is encrypted or purged. 50 extortion or ransomware claims this window, none naming a Google Workspace estate.
Google Backup
Worked cases this service addresses:
- Ransomware sold as a product, with security professionals recruited as the supply chain
- Encrypt only the virtual estate, exfiltrate through the victim's own cloud tooling, and delete the encryptor afterwards
- Select victims by exposure alone, finish the same day, and change name to stay unattributed
- Extort the victim a second time, from inside your own operation
- The pipeline stopped because the company stopped it
M365 backup 2
Active threats this quarter that M365 backup addresses:
Recover
- NewsLeak-site claim: Helix lists Uberclaimed
- NewsLeak-site claim: Helix lists Highwoods Propertiesclaimed
Worked cases
Incidents from the harvested record that this service addresses. These do not depend on this week’s news; the badged items above do.
- Ransomware sold as a product, with security professionals recruited as the supply chain
- Encrypt only the virtual estate, exfiltrate through the victim's own cloud tooling, and delete the encryptor afterwards
- Select victims by exposure alone, finish the same day, and change name to stay unattributed
- Extort the victim a second time, from inside your own operation
- The pipeline stopped because the company stopped it
Shadow AI discovery and control
No story in this window ties to Shadow AI discovery and control specifically:
Shadow AI discovery finds company data going into unsanctioned assistants. 13 AI-security items ran this window, but none described staff use of an outside tool, which is what this service addresses.
AI-enabled attack detection 30
Active threats this quarter that AI-enabled attack detection addresses:
Detect
- NewsAVEVA Pipeline Integrity Monitorconfirmed
- NewsAVEVA Pipeline Integrity Monitorconfirmed
- NewsUkrainian National Sentenced to Four Years in Prison for Wire Fraud Conspiracy in Connection with Conti Ransomwareconfirmed
- NewsRockwell Automation 1756-ENBT Moduleconfirmed
- NewsRockwell Automation 1756-ENBT Moduleconfirmed
- NewsEbyte NA111-Mconfirmed
- NewsEbyte NA111-Mconfirmed
- NewsJustice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical Infrastructureconfirmed
- NewsFederal docket: United States v. Thomson (3:26-cr-00426, District Court, N.D. California)confirmed
- News17 Iranians Charged with Conducting Massive Cyber Theft Campaign on Behalf of the Islamic Revolutionary Guard Corps and Other Iranian Entitiesconfirmed
- NewsANDRITZ HIPASE-250 and 250 SCALAconfirmed
- NewsANDRITZ HIPASE-250 and 250 SCALAconfirmed
- NewsWordPress security advisory (AV26-792)confirmed
- NewsRansom Cartel ransomware creator sentenced to 16 years in prisoncorroborated
- NewsCanadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millionsconfirmed
- News128 Seconds to disruption: Microsoft Defender stops ransomware at QNETvendor research
- NewsSpring security advisory (AV26-759)confirmed
- NewsJohnson Controls OpenBlue Employeeconfirmed
- NewsJohnson Controls OpenBlue Employeeconfirmed
- NewsCISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCsconfirmed
- NewsCritical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging Incorroborated
- NewsProgress security advisory (AV26-746)confirmed
- NewsJohnson Controls XAAP Androidconfirmed
- NewsUK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisationsconfirmed
- NewsRussian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suiteconfirmed
- NewsUS Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devicescorroborated
- NewsSiemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFWconfirmed
- NewsFake FBI agents target people who already got scammedcorroborated
- NewsCritical Palo Alto VPN bug now exploited by Qilin ransomware gangconfirmed
- NewsMore than 1,000 domains illegally streaming World Cup games seized, DOJ sayscorroborated
Worked cases
Incidents from the harvested record that this service addresses. These do not depend on this week’s news; the badged items above do.
- An exploit that applies on viewing, defeating every control built around user action
- Make the victim run the payload as proof they are human
- A state-linked group that sells the access instead of using it
Firewall 194
Active threats this quarter that Firewall addresses:
Prevent
- NewsGitLab security advisory (AV26-917)confirmed
- NewsCISA Adds Three Known Exploited Vulnerabilities to Catalogconfirmed
- NewsPalo Alto Networks security advisory (AV26-905)confirmed
- NewsAVEVA Pipeline Integrity Monitorconfirmed
- NewsNextGen Healthcare Mirth Connectconfirmed
- NewsAVEVA Pipeline Integrity Monitorconfirmed
- NewsOrthanc DICOM Serverconfirmed
- NewsCISA Adds Two Known Exploited Vulnerabilities to Catalogconfirmed
- NewsST Engineering iDirect iQ-Series Terminals (Update A)confirmed
- NewsCISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadlinecorroborated
- NewsSecurity Alert (A26-09-19): Multiple Vulnerabilities in Palo Alto Productsconfirmed
- NewsUPDATE ALERT Cisco Secure Firewall Management Center Software: CVSS (Max): 10.0confirmed
- NewsPalo Alto PAN-OS: CVSS (Max): 9.2confirmed
- NewsCisco security advisory (AV26-197) – Update 3confirmed
- NewsFortinet security advisory (AV26-023) - Update 1confirmed
- NewsGoogle security advisory (AV26-904)confirmed
- NewsConnectWise security advisory (AV26-903)confirmed
- NewsCheck Point security advisory (AV26-902)confirmed
- News2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Serverconfirmed
- NewsCISA Adds Four Known Exploited Vulnerabilities to Catalogconfirmed
- NewsMicrosoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploitedcorroborated
- NewsIvanti security advisory (AV26-897)confirmed
- NewsMikrotik security advisory (AV26-887)confirmed
- NewsAdobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shellcorroborated
- NewsInductive Automation Ignitionconfirmed
- NewsTycon Systems TPDIN-Monitor-WEB3confirmed
- NewsIXON VPN Clientconfirmed
- NewsInductive Automation Ignitionconfirmed
- NewsTycon Systems TPDIN-Monitor-WEB3confirmed
- NewsIXON VPN Clientconfirmed
- NewsPyramid Solutions NetStaX EtherNet/IP Stackconfirmed
- NewsRockwell Automation 1756-ENBT Moduleconfirmed
- NewsPyramid Solutions NetStaX EtherNet/IP Stackconfirmed
- NewsRockwell Automation 1756-ENBT Moduleconfirmed
- NewsProgress Software security advisory (AV26-875)confirmed
- NewsNearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)confirmed
- NewsSonicWall security advisory (AV26-872)confirmed
- NewsSonicWall Warns of Two SMA1000 Zero-Days Exploited in Attackscorroborated
- NewsJFrog security advisory (AV26-867)confirmed
- NewsRockwell Automation RSLinx Classicconfirmed
- NewsCISA Adds Two Known Exploited Vulnerabilities to Catalogconfirmed
- NewsPaperCut releases second emergency patch for exploited flawscorroborated
- NewsWebPros security advisory (AV26-854)confirmed
- NewsAll-Line Equipment Company Fuel-Bossconfirmed
- NewsAll-Line Equipment Company Fuel-Bossconfirmed
- NewsRockwell Automation OTTO Fleet Managerconfirmed
- NewsCISA Adds Three Known Exploited Vulnerabilities to Catalogconfirmed
- NewsMitsubishi Electric Multiple FA Products (Update D)confirmed
- NewsApplied Systems Engineering ASE2000 V2 Communications Test Setconfirmed
- NewsMitsubishi Electric CNC Series (Update A)confirmed
- NewsEbyte NA111-Mconfirmed
- NewsRockwell Automation OTTO Fleet Managerconfirmed
- NewsXiiaozet LK100Wconfirmed
- NewsApplied Systems Engineering ASE2000 V2 Communications Test Setconfirmed
- NewsMitsubishi Electric CNC Series (Update A)confirmed
- NewsXiiaozet LK100Wconfirmed
- NewsEbyte NA111-Mconfirmed
- NewsCISA orders feds to patch Citrix NetScaler RCE flaw by Saturdayconfirmed
- NewsNext.js security advisory (AV26-851)confirmed
- NewsCritical Gitea vulnerability now exploited in the wild (CVE-2026-60004)corroborated
- NewsRently Smart Homeconfirmed
- NewsPayRange APIconfirmed
- NewsZoneminderconfirmed
- NewsRently Smart Homeconfirmed
- NewsPayRange APIconfirmed
- NewsZoneminderconfirmed
- NewsBendix EC80 Brake ECUconfirmed
- NewsFURUNO FA-50 Class B AIS Transponderconfirmed
- NewsEbyte NE2-D11confirmed
- NewsEbyte NE2-D11confirmed
- NewsSiemens SIMATIC IoT2050 Advancedconfirmed
- NewsFURUNO FA-50 Class B AIS Transponderconfirmed
- NewsBendix EC80 Brake ECUconfirmed
- NewsSiemens SIMATIC IoT2050 Advancedconfirmed
- NewsKEV: CVE-2026-60004 — Gitea Gitea (Gitea Code Injection Vulnerability)confirmed
- NewsCISA Adds One Known Exploited Vulnerability to Catalogconfirmed
- NewsCISA orders urgent patching of actively exploited Zimbra flawcorroborated
- NewsCritical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836)claimed
- NewsTrueConf security advisory (AV26-835)confirmed
- NewsJFrog Artifactory Flaws Enable Software Supply Chain Attackscorroborated
- NewsCitrix security advisory (AV26-833)confirmed
- NewsMLflow security advisory (AV26-832)confirmed
- NewsCISA Adds One Known Exploited Vulnerability to Catalogconfirmed
- NewsCritical RCE flaw in Windows IKE Extension now actively exploitedcorroborated
- NewsHIGH ALERT: Active exploitation of remote monitoring and management platform within Australiaconfirmed
- NewsHIGH ALERT: Active exploitation of remote monitoring and management platform within Australiaconfirmed
- NewsPatch bundle: Oracle Oracle Critical Security Patch Update Advisory - August 2026 — 1040 CVEs, 151 criticalcorroborated
- NewsMattermost security advisory (AV26-828)confirmed
- NewsCISA Malcolmconfirmed
- NewsCritical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projectscorroborated
- NewsApple security advisory (AV26-823)confirmed
- NewsCitrix security advisory (AV26-645) – Update 2confirmed
- NewsMicrosoft Edge security advisory (AV26-822)confirmed
- NewsCISA Adds One Known Exploited Vulnerability to Catalogconfirmed
- NewsAL26-018 - Vulnerability affecting Cisco ASA and Secure Firewall Threat Defense Software Remote Access SSL VPN - CVE-2026-20349confirmed
- NewsAVEVA Enterprise SCADAconfirmed
- NewsAVEVA Enterprise SCADAconfirmed
- NewsHaiwell IoT Cloud HMI Gatewayconfirmed
- NewsSiemens Solid Edgeconfirmed
- NewsANDRITZ HIPASE-250 and 250 SCALAconfirmed
- NewsSiemens Siveillance Videoconfirmed
- NewsSiemens License Server (SLS)confirmed
- NewsSiemens Desigo DXR and PXC Controllersconfirmed
- NewsHitachi Energy APM Edge Productconfirmed
- NewsSiemens LOGO! Soft Comfortconfirmed
- NewsSiemens Parasolidconfirmed
- NewsSiemens Simcenter Femapconfirmed
- NewsSiemens License Server (SLS)confirmed
- NewsSiemens Desigo DXR and PXC Controllersconfirmed
- NewsSiemens LOGO! Soft Comfortconfirmed
- NewsANDRITZ HIPASE-250 and 250 SCALAconfirmed
- NewsSiemens Siveillance Videoconfirmed
- NewsHitachi Energy APM Edge Productconfirmed
- NewsSiemens Solid Edgeconfirmed
- NewsSiemens Siveillance Videoconfirmed
- NewsSiemens Siveillance Videoconfirmed
- NewsHaiwell IoT Cloud HMI Gatewayconfirmed
- NewsHackers exploit critical Adobe Commerce flaw to hijack customer accountsconfirmed
- NewsCisco security advisory (AV26-807)confirmed
- NewsGrafana security advisory (AV26-796)confirmed
- NewsPulsetto Vagus Nerve Stimulatorconfirmed
- NewsMira Hormone Monitor, Mira Android Appconfirmed
- NewsGunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networkscorroborated
- NewsKEV: CVE-2026-72898 — Metabase Metabase (Metabase SQL Injection Vulnerability)confirmed
- NewsWordPress security advisory (AV26-792)confirmed
- NewsWebPros security advisory (AV26-790)confirmed
- News200 accounts compromised in Swiss government’s Microsoft SharePoint breachcorroborated
- NewsABB Ability Zenonconfirmed
- NewsJohnson Controls Inc. TL280confirmed
- NewsMedixant RadiAnt DICOMconfirmed
- NewsJohnson Controls Inc. TL280confirmed
- NewsPatch bundle: August 2026 Early Security Updates — 19 CVEs, 0 exploitedcorroborated
- NewsPaperclip AI Flaws Let Unauthenticated Attackers Run Commandscorroborated
- NewsCISA Adds One Known Exploited Vulnerability to Catalogconfirmed
- NewsNew OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitchcorroborated
- NewsCritical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markupcorroborated
- News128 Seconds to disruption: Microsoft Defender stops ransomware at QNETvendor research
- NewsCheckpoint security advisory (AV26-774)confirmed
- NewsThermo Fisher Applied Biosystems Genetic Analyzersconfirmed
- NewsNew cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Rootconfirmed
- NewsCISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromisesvendor research
- NewsN-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incompletecorroborated
- NewsKEV: CVE-2026-18577 — N-able N-central (N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability)confirmed
- NewsRails security advisory (AV26-767)confirmed
- NewsSolarWinds security advisory (AV26-766)confirmed
- NewsWhat the Hugging Face breach reveals about defense in the age of agentic AIcorroborated
- NewsVMware security advisory (AV26-763)confirmed
- News[Control Systems] Phoenix Contact security advisory (AV26-762)confirmed
- NewsIn the Hugging Face breach, OpenAI’s hacker was noisy and fast — but not unstoppablecorroborated
- NewsWebPros security advisory (AV26-761)confirmed
- NewsSpring security advisory (AV26-759)confirmed
- NewsCisco security advisory (AV26-757)confirmed
- NewsJohnson Controls OpenBlue Employeeconfirmed
- NewsNASA Core Flight System (cFS) Health & Safety (HS) Applicationconfirmed
- NewsMikroTik RouterOSconfirmed
- NewsMitsubishi Electric CC-Link IE TSN Communication Protocolconfirmed
- NewsSchneider Electric IGSSconfirmed
- NewsToptech Systems RCU II+ and Multiload II+confirmed
- Newso6 Automation open62541confirmed
- NewsMikroTik RouterOSconfirmed
- NewsRockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Moduleconfirmed
- NewsSchneider Electric IGSSconfirmed
- NewsJohnson Controls OpenBlue Employeeconfirmed
- NewsThe Network Has Become the Control Plane for AI Securitycorroborated
- NewsCritical VM Escape Vulnerability Patched in VMware ESXicorroborated
- NewsKEV: CVE-2026-20316 — Cisco Secure Firewall Management Center (FMC) (Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability)confirmed
- NewsSiemens SIMATIC S7-PLCSIM Advancedconfirmed
- NewsSiemens Desigo CCconfirmed
- NewsABB KNX Update Toolconfirmed
- NewsMikroTik RouterOS and Cloud Hosted Routerconfirmed
- NewsSiemens Mendix Runtimeconfirmed
- NewsCritical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging Incorroborated
- NewsErlang security advisory (AV26-750)confirmed
- NewsKEV: CVE-2026-16812 — Arista VeloCloud Orchestrator (Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability)confirmed
- NewsKEV: CVE-2025-68686 — Fortinet FortiOS (Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability)confirmed
- NewsCalifornia AG breach notice: Zacks Investment Research, Inc.confirmed
- NewsProgress security advisory (AV26-746)confirmed
- NewsClop ransomware targets Windchill, FlexPLM in data theft attackscorroborated
- NewsJohnson Controls XAAP Androidconfirmed
- NewsPanduit IntraVUEconfirmed
- NewsMZ Automation libIEC61850confirmed
- NewsWeintek cMT3092Xconfirmed
- NewsRussian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suiteconfirmed
- NewsUbuntu snap-confine Vulnerability Enables Local Root Accesscorroborated
- NewsHPE security advisory (AV26-727)confirmed
- NewsTenable security advisory (AV26-724)confirmed
- NewsRockwell Automation Studio 5000 Logix Designerconfirmed
- NewsSiemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFWconfirmed
- NewsCritical Palo Alto VPN bug now exploited by Qilin ransomware gangconfirmed
- NewsCritical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Executioncorroborated
- NewsKEV: CVE-2026-0770 — Langflow Langflow (Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability)confirmed
- NewsInc Ransomware Exploits SonicWall SMA Zero-Dayscorroborated
- NewsProgress Restores ShareFile Storage Zones Access After Security Warningconfirmed
- NewsCISA Adds Two Known Exploited Vulnerabilities to Catalogconfirmed
Detect
- NewsSonicWall security advisory (AV26-872)confirmed
- NewsSonicWall Warns of Two SMA1000 Zero-Days Exploited in Attackscorroborated
- NewsCISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromisesvendor research
- NewsPanduit IntraVUEconfirmed
Worked cases
Incidents from the harvested record that this service addresses. These do not depend on this week’s news; the badged items above do.
- Ransomware sold as a product, with security professionals recruited as the supply chain
- Turn the remote-access appliance into a credential collector, then patch the authentication server to accept a chosen value
- An exploit that applies on viewing, defeating every control built around user action
- Tell the device to mail you its own configuration, using the management protocol's write function
- Compromise the carrier, and inherit everyone whose traffic crosses it
- Encrypt only the virtual estate, exfiltrate through the victim's own cloud tooling, and delete the encryptor afterwards
- Exploited inside the mandated patching window, then exploited again on a second instance during the response
- Extort the victim a second time, from inside your own operation
- Chain four flaws in an end-of-life security appliance
- The account of someone who left, and the backup that kept their desk
- Register your own device as the second factor, and the lock is now yours
- The identities that cannot have a second factor
- Build the target list before the vulnerability is public
- Ransom hospitals to pay for the nuclear-programme espionage
- The pipeline stopped because the company stopped it
- Phish from inside the marketing platform the recipient already trusts
- The tool that certifies the appliance is clean can be told to say so
- He says he is from IT, and if you will not let him in remotely he drives over
SASE/SSE 187
Active threats this quarter that SASE/SSE addresses:
Prevent
- NewsGitLab security advisory (AV26-917)confirmed
- NewsCISA Adds Three Known Exploited Vulnerabilities to Catalogconfirmed
- NewsPalo Alto Networks security advisory (AV26-905)confirmed
- NewsAVEVA Pipeline Integrity Monitorconfirmed
- NewsNextGen Healthcare Mirth Connectconfirmed
- NewsAVEVA Pipeline Integrity Monitorconfirmed
- NewsOrthanc DICOM Serverconfirmed
- NewsCISA Adds Two Known Exploited Vulnerabilities to Catalogconfirmed
- NewsST Engineering iDirect iQ-Series Terminals (Update A)confirmed
- NewsCISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadlinecorroborated
- NewsCisco security advisory (AV26-197) – Update 3confirmed
- NewsFortinet security advisory (AV26-023) - Update 1confirmed
- NewsGoogle security advisory (AV26-904)confirmed
- NewsConnectWise security advisory (AV26-903)confirmed
- NewsCheck Point security advisory (AV26-902)confirmed
- News2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Serverconfirmed
- NewsCISA Adds Four Known Exploited Vulnerabilities to Catalogconfirmed
- NewsCSA Singapore alert: 9 September 2026 Active Exploitation of Vulnerability in N-Able N-Central Attackers are exploiting a critical vulnerability in N-Able N-Central remote management and monitoring tool to execute code remotely without authentication. Patch immediately. Alertsconfirmed
- NewsMicrosoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploitedcorroborated
- NewsIvanti security advisory (AV26-897)confirmed
- NewsMikrotik security advisory (AV26-887)confirmed
- NewsAdobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shellcorroborated
- NewsN-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218)corroborated
- NewsTycon Systems TPDIN-Monitor-WEB3confirmed
- NewsIXON VPN Clientconfirmed
- NewsTycon Systems TPDIN-Monitor-WEB3confirmed
- NewsIXON VPN Clientconfirmed
- NewsPyramid Solutions NetStaX EtherNet/IP Stackconfirmed
- NewsRockwell Automation 1756-ENBT Moduleconfirmed
- NewsPyramid Solutions NetStaX EtherNet/IP Stackconfirmed
- NewsRockwell Automation 1756-ENBT Moduleconfirmed
- NewsProgress Software security advisory (AV26-875)confirmed
- NewsNearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)confirmed
- NewsSonicWall security advisory (AV26-872)confirmed
- NewsSonicWall Warns of Two SMA1000 Zero-Days Exploited in Attackscorroborated
- NewsJFrog security advisory (AV26-867)confirmed
- NewsRockwell Automation RSLinx Classicconfirmed
- NewsCISA Adds Two Known Exploited Vulnerabilities to Catalogconfirmed
- NewsPaperCut releases second emergency patch for exploited flawscorroborated
- NewsWebPros security advisory (AV26-854)confirmed
- NewsAll-Line Equipment Company Fuel-Bossconfirmed
- NewsAll-Line Equipment Company Fuel-Bossconfirmed
- NewsRockwell Automation OTTO Fleet Managerconfirmed
- NewsCISA Adds Three Known Exploited Vulnerabilities to Catalogconfirmed
- NewsMitsubishi Electric Multiple FA Products (Update D)confirmed
- NewsApplied Systems Engineering ASE2000 V2 Communications Test Setconfirmed
- NewsMitsubishi Electric CNC Series (Update A)confirmed
- NewsEbyte NA111-Mconfirmed
- NewsRockwell Automation OTTO Fleet Managerconfirmed
- NewsXiiaozet LK100Wconfirmed
- NewsApplied Systems Engineering ASE2000 V2 Communications Test Setconfirmed
- NewsMitsubishi Electric CNC Series (Update A)confirmed
- NewsXiiaozet LK100Wconfirmed
- NewsEbyte NA111-Mconfirmed
- NewsCISA orders feds to patch Citrix NetScaler RCE flaw by Saturdayconfirmed
- NewsNext.js security advisory (AV26-851)confirmed
- NewsCritical Gitea vulnerability now exploited in the wild (CVE-2026-60004)corroborated
- NewsRently Smart Homeconfirmed
- NewsPayRange APIconfirmed
- NewsZoneminderconfirmed
- NewsRently Smart Homeconfirmed
- NewsPayRange APIconfirmed
- NewsZoneminderconfirmed
- NewsBendix EC80 Brake ECUconfirmed
- NewsFURUNO FA-50 Class B AIS Transponderconfirmed
- NewsEbyte NE2-D11confirmed
- NewsEbyte NE2-D11confirmed
- NewsSiemens SIMATIC IoT2050 Advancedconfirmed
- NewsFURUNO FA-50 Class B AIS Transponderconfirmed
- NewsBendix EC80 Brake ECUconfirmed
- NewsSiemens SIMATIC IoT2050 Advancedconfirmed
- NewsKEV: CVE-2026-60004 — Gitea Gitea (Gitea Code Injection Vulnerability)confirmed
- NewsCISA Adds One Known Exploited Vulnerability to Catalogconfirmed
- NewsCISA orders urgent patching of actively exploited Zimbra flawcorroborated
- NewsCritical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836)claimed
- NewsTrueConf security advisory (AV26-835)confirmed
- NewsJFrog Artifactory Flaws Enable Software Supply Chain Attackscorroborated
- NewsCitrix security advisory (AV26-833)confirmed
- NewsMLflow security advisory (AV26-832)confirmed
- NewsCISA Adds One Known Exploited Vulnerability to Catalogconfirmed
- NewsCritical RCE flaw in Windows IKE Extension now actively exploitedcorroborated
- NewsHIGH ALERT: Active exploitation of remote monitoring and management platform within Australiaconfirmed
- NewsHIGH ALERT: Active exploitation of remote monitoring and management platform within Australiaconfirmed
- NewsPatch bundle: Oracle Oracle Critical Security Patch Update Advisory - August 2026 — 1040 CVEs, 151 criticalcorroborated
- NewsMattermost security advisory (AV26-828)confirmed
- NewsCISA Malcolmconfirmed
- NewsCritical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projectscorroborated
- NewsApple security advisory (AV26-823)confirmed
- NewsCitrix security advisory (AV26-645) – Update 2confirmed
- NewsMicrosoft Edge security advisory (AV26-822)confirmed
- NewsCISA Adds One Known Exploited Vulnerability to Catalogconfirmed
- NewsAVEVA Enterprise SCADAconfirmed
- NewsAVEVA Enterprise SCADAconfirmed
- NewsHaiwell IoT Cloud HMI Gatewayconfirmed
- NewsSiemens Solid Edgeconfirmed
- NewsANDRITZ HIPASE-250 and 250 SCALAconfirmed
- NewsSiemens Siveillance Videoconfirmed
- NewsSiemens License Server (SLS)confirmed
- NewsSiemens Desigo DXR and PXC Controllersconfirmed
- NewsHitachi Energy APM Edge Productconfirmed
- NewsSiemens LOGO! Soft Comfortconfirmed
- NewsSiemens Parasolidconfirmed
- NewsSiemens Simcenter Femapconfirmed
- NewsSiemens License Server (SLS)confirmed
- NewsSiemens Desigo DXR and PXC Controllersconfirmed
- NewsSiemens LOGO! Soft Comfortconfirmed
- NewsANDRITZ HIPASE-250 and 250 SCALAconfirmed
- NewsSiemens Siveillance Videoconfirmed
- NewsHitachi Energy APM Edge Productconfirmed
- NewsSiemens Solid Edgeconfirmed
- NewsSiemens Siveillance Videoconfirmed
- NewsSiemens Siveillance Videoconfirmed
- NewsHaiwell IoT Cloud HMI Gatewayconfirmed
- NewsHackers exploit critical Adobe Commerce flaw to hijack customer accountsconfirmed
- NewsGrafana security advisory (AV26-796)confirmed
- NewsPulsetto Vagus Nerve Stimulatorconfirmed
- NewsMira Hormone Monitor, Mira Android Appconfirmed
- NewsGunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networkscorroborated
- NewsKEV: CVE-2026-72898 — Metabase Metabase (Metabase SQL Injection Vulnerability)confirmed
- NewsWordPress security advisory (AV26-792)confirmed
- NewsWebPros security advisory (AV26-790)confirmed
- News200 accounts compromised in Swiss government’s Microsoft SharePoint breachcorroborated
- NewsABB Ability Zenonconfirmed
- NewsJohnson Controls Inc. TL280confirmed
- NewsMedixant RadiAnt DICOMconfirmed
- NewsJohnson Controls Inc. TL280confirmed
- NewsPatch bundle: August 2026 Early Security Updates — 19 CVEs, 0 exploitedcorroborated
- NewsPaperclip AI Flaws Let Unauthenticated Attackers Run Commandscorroborated
- NewsCISA Adds One Known Exploited Vulnerability to Catalogconfirmed
- NewsNew OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitchcorroborated
- NewsCritical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markupcorroborated
- News128 Seconds to disruption: Microsoft Defender stops ransomware at QNETvendor research
- NewsCheckpoint security advisory (AV26-774)confirmed
- NewsThermo Fisher Applied Biosystems Genetic Analyzersconfirmed
- NewsNew cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Rootconfirmed
- NewsCISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromisesvendor research
- NewsN-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incompletecorroborated
- NewsKEV: CVE-2026-18577 — N-able N-central (N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability)confirmed
- NewsRails security advisory (AV26-767)confirmed
- NewsSolarWinds security advisory (AV26-766)confirmed
- NewsWhat the Hugging Face breach reveals about defense in the age of agentic AIcorroborated
- NewsVMware security advisory (AV26-763)confirmed
- News[Control Systems] Phoenix Contact security advisory (AV26-762)confirmed
- NewsWebPros security advisory (AV26-761)confirmed
- NewsSpring security advisory (AV26-759)confirmed
- NewsCisco security advisory (AV26-757)confirmed
- NewsJohnson Controls OpenBlue Employeeconfirmed
- NewsNASA Core Flight System (cFS) Health & Safety (HS) Applicationconfirmed
- NewsMikroTik RouterOSconfirmed
- NewsMitsubishi Electric CC-Link IE TSN Communication Protocolconfirmed
- NewsSchneider Electric IGSSconfirmed
- NewsToptech Systems RCU II+ and Multiload II+confirmed
- Newso6 Automation open62541confirmed
- NewsMikroTik RouterOSconfirmed
- NewsRockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Moduleconfirmed
- NewsSchneider Electric IGSSconfirmed
- NewsJohnson Controls OpenBlue Employeeconfirmed
- NewsThe Network Has Become the Control Plane for AI Securitycorroborated
- NewsCritical VM Escape Vulnerability Patched in VMware ESXicorroborated
- NewsKEV: CVE-2026-20316 — Cisco Secure Firewall Management Center (FMC) (Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability)confirmed
- NewsSiemens SIMATIC S7-PLCSIM Advancedconfirmed
- NewsSiemens Desigo CCconfirmed
- NewsABB KNX Update Toolconfirmed
- NewsMikroTik RouterOS and Cloud Hosted Routerconfirmed
- NewsCritical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging Incorroborated
- NewsErlang security advisory (AV26-750)confirmed
- NewsKEV: CVE-2026-16812 — Arista VeloCloud Orchestrator (Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability)confirmed
- NewsKEV: CVE-2025-68686 — Fortinet FortiOS (Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability)confirmed
- NewsCalifornia AG breach notice: Zacks Investment Research, Inc.confirmed
- NewsProgress security advisory (AV26-746)confirmed
- NewsClop ransomware targets Windchill, FlexPLM in data theft attackscorroborated
- NewsJohnson Controls XAAP Androidconfirmed
- NewsPanduit IntraVUEconfirmed
- NewsMZ Automation libIEC61850confirmed
- NewsWeintek cMT3092Xconfirmed
- NewsRussian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suiteconfirmed
- NewsUbuntu snap-confine Vulnerability Enables Local Root Accesscorroborated
- NewsHPE security advisory (AV26-727)confirmed
- NewsTenable security advisory (AV26-724)confirmed
- NewsRockwell Automation Studio 5000 Logix Designerconfirmed
- NewsSiemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFWconfirmed
- NewsCritical Palo Alto VPN bug now exploited by Qilin ransomware gangconfirmed
- NewsCritical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Executioncorroborated
- NewsKEV: CVE-2026-0770 — Langflow Langflow (Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability)confirmed
- NewsInc Ransomware Exploits SonicWall SMA Zero-Dayscorroborated
- NewsProgress Restores ShareFile Storage Zones Access After Security Warningconfirmed
- NewsCISA Adds Two Known Exploited Vulnerabilities to Catalogconfirmed
Detect
- NewsCISA Adds Three Known Exploited Vulnerabilities to Catalogconfirmed
- NewsPalo Alto Networks security advisory (AV26-905)confirmed
- NewsAVEVA Pipeline Integrity Monitorconfirmed
- NewsAVEVA Pipeline Integrity Monitorconfirmed
- NewsCISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadlinecorroborated
- NewsCisco security advisory (AV26-197) – Update 3confirmed
- NewsFortinet security advisory (AV26-023) - Update 1confirmed
- NewsGoogle security advisory (AV26-904)confirmed
- NewsCheck Point security advisory (AV26-902)confirmed
- News2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Serverconfirmed
- NewsCISA Adds Four Known Exploited Vulnerabilities to Catalogconfirmed
- NewsCSA Singapore alert: 9 September 2026 Active Exploitation of Vulnerability in N-Able N-Central Attackers are exploiting a critical vulnerability in N-Able N-Central remote management and monitoring tool to execute code remotely without authentication. Patch immediately. Alertsconfirmed
- NewsMicrosoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploitedcorroborated
- NewsIvanti security advisory (AV26-897)confirmed
- NewsAdobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shellcorroborated
- NewsN-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218)corroborated
- NewsIXON VPN Clientconfirmed
- NewsIXON VPN Clientconfirmed
- NewsRockwell Automation 1756-ENBT Moduleconfirmed
- NewsRockwell Automation 1756-ENBT Moduleconfirmed
- NewsProgress Software security advisory (AV26-875)confirmed
- NewsNearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)confirmed
- NewsSonicWall security advisory (AV26-872)confirmed
- NewsSonicWall Warns of Two SMA1000 Zero-Days Exploited in Attackscorroborated
- NewsJFrog security advisory (AV26-867)confirmed
- NewsRockwell Automation RSLinx Classicconfirmed
- NewsPaperCut releases second emergency patch for exploited flawscorroborated
- NewsAll-Line Equipment Company Fuel-Bossconfirmed
- NewsAll-Line Equipment Company Fuel-Bossconfirmed
- NewsRockwell Automation OTTO Fleet Managerconfirmed
- NewsCISA Adds Three Known Exploited Vulnerabilities to Catalogconfirmed
- NewsMitsubishi Electric Multiple FA Products (Update D)confirmed
- NewsApplied Systems Engineering ASE2000 V2 Communications Test Setconfirmed
- NewsEbyte NA111-Mconfirmed
- NewsRockwell Automation OTTO Fleet Managerconfirmed
- NewsXiiaozet LK100Wconfirmed
- NewsApplied Systems Engineering ASE2000 V2 Communications Test Setconfirmed
- NewsXiiaozet LK100Wconfirmed
- NewsEbyte NA111-Mconfirmed
- NewsCISA orders feds to patch Citrix NetScaler RCE flaw by Saturdayconfirmed
- NewsCritical Gitea vulnerability now exploited in the wild (CVE-2026-60004)corroborated
- NewsRently Smart Homeconfirmed
- NewsRently Smart Homeconfirmed
- NewsCISA Adds One Known Exploited Vulnerability to Catalogconfirmed
- NewsJFrog Artifactory Flaws Enable Software Supply Chain Attackscorroborated
- NewsCitrix security advisory (AV26-833)confirmed
- NewsCritical RCE flaw in Windows IKE Extension now actively exploitedcorroborated
- NewsHIGH ALERT: Active exploitation of remote monitoring and management platform within Australiaconfirmed
- NewsHIGH ALERT: Active exploitation of remote monitoring and management platform within Australiaconfirmed
- NewsPatch bundle: Oracle Oracle Critical Security Patch Update Advisory - August 2026 — 1040 CVEs, 151 criticalcorroborated
- NewsCISA Malcolmconfirmed
- NewsApple security advisory (AV26-823)confirmed
- NewsCitrix security advisory (AV26-645) – Update 2confirmed
- NewsSiemens Solid Edgeconfirmed
- NewsANDRITZ HIPASE-250 and 250 SCALAconfirmed
- NewsSiemens Desigo DXR and PXC Controllersconfirmed
- NewsHitachi Energy APM Edge Productconfirmed
- NewsSiemens LOGO! Soft Comfortconfirmed
- NewsSiemens Parasolidconfirmed
- NewsSiemens Simcenter Femapconfirmed
- NewsSiemens Desigo DXR and PXC Controllersconfirmed
- NewsSiemens LOGO! Soft Comfortconfirmed
- NewsANDRITZ HIPASE-250 and 250 SCALAconfirmed
- NewsHitachi Energy APM Edge Productconfirmed
- NewsSiemens Solid Edgeconfirmed
- NewsPulsetto Vagus Nerve Stimulatorconfirmed
- NewsMira Hormone Monitor, Mira Android Appconfirmed
- NewsGunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networkscorroborated
- NewsWordPress security advisory (AV26-792)confirmed
- News200 accounts compromised in Swiss government’s Microsoft SharePoint breachcorroborated
- NewsJohnson Controls Inc. TL280confirmed
- NewsMedixant RadiAnt DICOMconfirmed
- NewsJohnson Controls Inc. TL280confirmed
- NewsPatch bundle: August 2026 Early Security Updates — 19 CVEs, 0 exploitedcorroborated
- NewsPaperclip AI Flaws Let Unauthenticated Attackers Run Commandscorroborated
- NewsNew OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitchcorroborated
- NewsCritical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markupcorroborated
- News128 Seconds to disruption: Microsoft Defender stops ransomware at QNETvendor research
- NewsCheckpoint security advisory (AV26-774)confirmed
- NewsThermo Fisher Applied Biosystems Genetic Analyzersconfirmed
- NewsCISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromisesvendor research
- NewsN-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incompletecorroborated
- NewsKEV: CVE-2026-18577 — N-able N-central (N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability)confirmed
- NewsSolarWinds security advisory (AV26-766)confirmed
- NewsWhat the Hugging Face breach reveals about defense in the age of agentic AIcorroborated
- NewsVMware security advisory (AV26-763)confirmed
- News[Control Systems] Phoenix Contact security advisory (AV26-762)confirmed
- NewsSpring security advisory (AV26-759)confirmed
- NewsJohnson Controls OpenBlue Employeeconfirmed
- NewsNASA Core Flight System (cFS) Health & Safety (HS) Applicationconfirmed
- NewsMikroTik RouterOSconfirmed
- NewsMitsubishi Electric CC-Link IE TSN Communication Protocolconfirmed
- NewsSchneider Electric IGSSconfirmed
- NewsMikroTik RouterOSconfirmed
- NewsRockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Moduleconfirmed
- NewsSchneider Electric IGSSconfirmed
- NewsJohnson Controls OpenBlue Employeeconfirmed
- NewsSiemens SIMATIC S7-PLCSIM Advancedconfirmed
- NewsSiemens Desigo CCconfirmed
- NewsABB KNX Update Toolconfirmed
- NewsMikroTik RouterOS and Cloud Hosted Routerconfirmed
- NewsCritical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging Incorroborated
- NewsErlang security advisory (AV26-750)confirmed
- NewsKEV: CVE-2025-68686 — Fortinet FortiOS (Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability)confirmed
- NewsCalifornia AG breach notice: Zacks Investment Research, Inc.confirmed
- NewsProgress security advisory (AV26-746)confirmed
- NewsClop ransomware targets Windchill, FlexPLM in data theft attackscorroborated
- NewsJohnson Controls XAAP Androidconfirmed
- NewsPanduit IntraVUEconfirmed
- NewsMZ Automation libIEC61850confirmed
- NewsWeintek cMT3092Xconfirmed
- NewsRussian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suiteconfirmed
- NewsHPE security advisory (AV26-727)confirmed
- NewsTenable security advisory (AV26-724)confirmed
- NewsSiemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFWconfirmed
- NewsCritical Palo Alto VPN bug now exploited by Qilin ransomware gangconfirmed
- NewsKEV: CVE-2026-0770 — Langflow Langflow (Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability)confirmed
- NewsProgress Restores ShareFile Storage Zones Access After Security Warningconfirmed
- NewsCISA Adds Two Known Exploited Vulnerabilities to Catalogconfirmed
Worked cases
Incidents from the harvested record that this service addresses. These do not depend on this week’s news; the badged items above do.
- Ransomware sold as a product, with security professionals recruited as the supply chain
- Turn the remote-access appliance into a credential collector, then patch the authentication server to accept a chosen value
- An exploit that applies on viewing, defeating every control built around user action
- Tell the device to mail you its own configuration, using the management protocol's write function
- Compromise the carrier, and inherit everyone whose traffic crosses it
- Make the victim run the payload as proof they are human
- Encrypt only the virtual estate, exfiltrate through the victim's own cloud tooling, and delete the encryptor afterwards
- Exploited inside the mandated patching window, then exploited again on a second instance during the response
- Select victims by exposure alone, finish the same day, and change name to stay unattributed
- Extort the victim a second time, from inside your own operation
- Chain four flaws in an end-of-life security appliance
- The account of someone who left, and the backup that kept their desk
- Register your own device as the second factor, and the lock is now yours
- The identities that cannot have a second factor
- A state-linked group that sells the access instead of using it
- Build the target list before the vulnerability is public
- Ransom hospitals to pay for the nuclear-programme espionage
- Learn the help desk's reset procedure, then call back and use it
- Extort by telling the victim's customers
- The pipeline stopped because the company stopped it
- Phish from inside the marketing platform the recipient already trusts
- The tool that certifies the appliance is clean can be told to say so
- He says he is from IT, and if you will not let him in remotely he drives over
- Phish the credential, then change where the money is sent
- The QR code exists to get the victim off the managed device
Managed XDR 259
Active threats this quarter that Managed XDR addresses:
Prevent
- NewsUkrainian National Sentenced to Four Years in Prison for Wire Fraud Conspiracy in Connection with Conti Ransomwareconfirmed
- News8-K Item 8.01: CONDUENT Inc discloses a cybersecurity incident (not filed as material)confirmed
- News8-K Item 8.01: Rigetti Computing, Inc. (RGTI, RGTIW) discloses a cybersecurity incident (not filed as material)confirmed
- News8-K Item 8.01: D-Wave Quantum Inc. discloses a cybersecurity incident (not filed as material)confirmed
- News8-K Item 1.05: BOSTON SCIENTIFIC CORP reports material cybersecurity incidentconfirmed
- News8-K Item 8.01: UNITED NATURAL FOODS INC discloses a cybersecurity incident (not filed as material)confirmed
- News8-K Item 8.01: Veradigm Inc. discloses a cybersecurity incident (not filed as material)confirmed
- NewsN-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218)corroborated
- News8-K Item 1.05: Park Dental Partners, Inc. reports material cybersecurity incidentconfirmed
- News8-K Item 1.05: Nutex Health Inc. reports material cybersecurity incidentconfirmed
- NewsMcKesson discloses breach after ShinyHunters claims patient data theftcorroborated
- NewsCalifornia AG breach notice: Bennett Collegeconfirmed
- NewsCybercrooks jet off with Manchester Airports Group customer datacorroborated
- NewsTwo Alleged ‘TeamPCP’ Hackers Arrested in Australiacorroborated
- NewsBoston Scientific says cyberattack disrupted operations globallycorroborated
- NewsJFrog Artifactory Flaws Enable Software Supply Chain Attackscorroborated
- NewsHIGH ALERT: Active exploitation of remote monitoring and management platform within Australiaconfirmed
- NewsFrench tax authority data breach affects 678,000 individualscorroborated
- NewsGunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networkscorroborated
- NewsChina-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flawcorroborated
- NewsLeak-site claim: Helix lists Uberclaimed
- NewsLeak-site claim: Helix lists Highwoods Propertiesclaimed
- NewsRansom Cartel ransomware creator sentenced to 16 years in prisoncorroborated
- NewsCanadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millionsconfirmed
- News77 Open VSX extensions found harvesting developer infocorroborated
- NewsN-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incompletecorroborated
- NewsHugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Codecorroborated
- News8-K Item 1.05: AMGEN INC reports material cybersecurity incidentconfirmed
- NewsOpen Source Software: Security Principles and Practicesconfirmed
- News8-K Item 1.05: River Financial Corp reports material cybersecurity incidentconfirmed
- NewsWhen AppSec Scanners Become a Supply Chain Attack Vectorcorroborated
- News2026 Minimum Elements for a Software Bill of Materials (SBOM)confirmed
- NewsLeak-site claim: shinyhunters lists Ernst & Youngcorroborated
- NewsCoca-Cola Confirms Data Breach After Fairlife Ransomware Attackcorroborated
- NewsLeak-site claim: ExfilSquad lists Frontier Airlinescorroborated
- NewsLeak-site claim: ExfilSquad lists Police National Legal Databasecorroborated
- NewsCalifornia AG breach notice: Zacks Investment Research, Inc.confirmed
- NewsClop ransomware targets Windchill, FlexPLM in data theft attackscorroborated
- NewsSwiss rail giant Stadler rejects $12.3M ransom demand after cyberattackcorroborated
- NewsAnubis ransomware claims Coca-Cola Fairlife attack, threatens data leakcorroborated
- NewsSiemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFWconfirmed
- NewsCritical Palo Alto VPN bug now exploited by Qilin ransomware gangconfirmed
- NewsEstée Lauder discloses data breach via Oracle E-Business flawcorroborated
- NewsHackers were inside South Korea's diplomat training system for 9 monthscorroborated
- NewsAn AI SOC Evaluation Guide for Security Leaderscorroborated
- NewsMultiple Jscrambler Packages Impacted by Supply Chain Attackcorroborated
- News8-K Item 1.05: Hewlett Packard Enterprise Co reports material cybersecurity incidentconfirmed
- News8-K Item 8.01: National Bank Holdings Corp discloses a cybersecurity incident (not filed as material)confirmed
Detect
- NewsGitLab security advisory (AV26-917)confirmed
- NewsCISA Adds Three Known Exploited Vulnerabilities to Catalogconfirmed
- NewsPalo Alto Networks security advisory (AV26-905)confirmed
- NewsAVEVA Pipeline Integrity Monitorconfirmed
- NewsNextGen Healthcare Mirth Connectconfirmed
- NewsAVEVA Pipeline Integrity Monitorconfirmed
- NewsOrthanc DICOM Serverconfirmed
- NewsCISA Adds Two Known Exploited Vulnerabilities to Catalogconfirmed
- NewsUkrainian National Sentenced to Four Years in Prison for Wire Fraud Conspiracy in Connection with Conti Ransomwareconfirmed
- NewsST Engineering iDirect iQ-Series Terminals (Update A)confirmed
- NewsCISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadlinecorroborated
- News8-K Item 8.01: CONDUENT Inc discloses a cybersecurity incident (not filed as material)confirmed
- NewsCisco security advisory (AV26-197) – Update 3confirmed
- NewsFortinet security advisory (AV26-023) - Update 1confirmed
- NewsGoogle security advisory (AV26-904)confirmed
- NewsConnectWise security advisory (AV26-903)confirmed
- NewsCheck Point security advisory (AV26-902)confirmed
- News2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Serverconfirmed
- NewsCISA Adds Four Known Exploited Vulnerabilities to Catalogconfirmed
- NewsCSA Singapore alert: 9 September 2026 Active Exploitation of Vulnerability in N-Able N-Central Attackers are exploiting a critical vulnerability in N-Able N-Central remote management and monitoring tool to execute code remotely without authentication. Patch immediately. Alertsconfirmed
- NewsMicrosoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploitedcorroborated
- NewsIvanti security advisory (AV26-897)confirmed
- NewsMikrotik security advisory (AV26-887)confirmed
- NewsAdobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shellcorroborated
- News8-K Item 8.01: Rigetti Computing, Inc. (RGTI, RGTIW) discloses a cybersecurity incident (not filed as material)confirmed
- News8-K Item 8.01: D-Wave Quantum Inc. discloses a cybersecurity incident (not filed as material)confirmed
- News8-K Item 1.05: BOSTON SCIENTIFIC CORP reports material cybersecurity incidentconfirmed
- News8-K Item 8.01: UNITED NATURAL FOODS INC discloses a cybersecurity incident (not filed as material)confirmed
- News8-K Item 8.01: Veradigm Inc. discloses a cybersecurity incident (not filed as material)confirmed
- NewsAdobe Commerce Zero-Day Exploited to Backdoor Online Storescorroborated
- NewsN-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218)corroborated
- NewsInductive Automation Ignitionconfirmed
- NewsTycon Systems TPDIN-Monitor-WEB3confirmed
- NewsIXON VPN Clientconfirmed
- NewsInductive Automation Ignitionconfirmed
- NewsTycon Systems TPDIN-Monitor-WEB3confirmed
- NewsIXON VPN Clientconfirmed
- NewsPyramid Solutions NetStaX EtherNet/IP Stackconfirmed
- NewsRockwell Automation 1756-ENBT Moduleconfirmed
- NewsPyramid Solutions NetStaX EtherNet/IP Stackconfirmed
- NewsRockwell Automation 1756-ENBT Moduleconfirmed
- NewsProgress Software security advisory (AV26-875)confirmed
- NewsMalicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pagescorroborated
- NewsNearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)confirmed
- NewsSonicWall security advisory (AV26-872)confirmed
- NewsSonicWall Warns of Two SMA1000 Zero-Days Exploited in Attackscorroborated
- NewsJFrog security advisory (AV26-867)confirmed
- NewsRockwell Automation RSLinx Classicconfirmed
- News8-K Item 1.05: Park Dental Partners, Inc. reports material cybersecurity incidentconfirmed
- NewsCISA Adds Two Known Exploited Vulnerabilities to Catalogconfirmed
- News8-K Item 1.05: Nutex Health Inc. reports material cybersecurity incidentconfirmed
- NewsMcKesson discloses breach after ShinyHunters claims patient data theftcorroborated
- NewsPaperCut releases second emergency patch for exploited flawscorroborated
- NewsCalifornia AG breach notice: Bennett Collegeconfirmed
- NewsNorth Korean remote workers are broadening their job hunt beyond ITcorroborated
- NewsWebPros security advisory (AV26-854)confirmed
- NewsCybercrooks jet off with Manchester Airports Group customer datacorroborated
- NewsTwo Alleged ‘TeamPCP’ Hackers Arrested in Australiacorroborated
- NewsAll-Line Equipment Company Fuel-Bossconfirmed
- NewsAll-Line Equipment Company Fuel-Bossconfirmed
- NewsRockwell Automation OTTO Fleet Managerconfirmed
- NewsCISA Adds Three Known Exploited Vulnerabilities to Catalogconfirmed
- NewsMitsubishi Electric Multiple FA Products (Update D)confirmed
- NewsApplied Systems Engineering ASE2000 V2 Communications Test Setconfirmed
- NewsMitsubishi Electric CNC Series (Update A)confirmed
- NewsEbyte NA111-Mconfirmed
- NewsRockwell Automation OTTO Fleet Managerconfirmed
- NewsXiiaozet LK100Wconfirmed
- NewsApplied Systems Engineering ASE2000 V2 Communications Test Setconfirmed
- NewsMitsubishi Electric CNC Series (Update A)confirmed
- NewsXiiaozet LK100Wconfirmed
- NewsEbyte NA111-Mconfirmed
- NewsCISA orders feds to patch Citrix NetScaler RCE flaw by Saturdayconfirmed
- NewsNext.js security advisory (AV26-851)confirmed
- NewsBoston Scientific says cyberattack disrupted operations globallycorroborated
- NewsJustice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical Infrastructureconfirmed
- NewsCritical Gitea vulnerability now exploited in the wild (CVE-2026-60004)corroborated
- NewsRently Smart Homeconfirmed
- NewsPayRange APIconfirmed
- NewsZoneminderconfirmed
- NewsRently Smart Homeconfirmed
- NewsPayRange APIconfirmed
- NewsZoneminderconfirmed
- NewsBendix EC80 Brake ECUconfirmed
- NewsFURUNO FA-50 Class B AIS Transponderconfirmed
- NewsEbyte NE2-D11confirmed
- NewsEbyte NE2-D11confirmed
- NewsSiemens SIMATIC IoT2050 Advancedconfirmed
- NewsFURUNO FA-50 Class B AIS Transponderconfirmed
- NewsBendix EC80 Brake ECUconfirmed
- NewsSiemens SIMATIC IoT2050 Advancedconfirmed
- NewsKEV: CVE-2026-60004 — Gitea Gitea (Gitea Code Injection Vulnerability)confirmed
- NewsFederal docket: United States v. Thomson (3:26-cr-00426, District Court, N.D. California)confirmed
- NewsCISA Adds One Known Exploited Vulnerability to Catalogconfirmed
- NewsCISA orders urgent patching of actively exploited Zimbra flawcorroborated
- NewsCritical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836)claimed
- NewsTrueConf security advisory (AV26-835)confirmed
- NewsJFrog Artifactory Flaws Enable Software Supply Chain Attackscorroborated
- NewsJohnson Controls Simplex Incident Managerconfirmed
- NewsCitrix security advisory (AV26-833)confirmed
- NewsMLflow security advisory (AV26-832)confirmed
- NewsCISA Adds One Known Exploited Vulnerability to Catalogconfirmed
- NewsCritical RCE flaw in Windows IKE Extension now actively exploitedcorroborated
- NewsHIGH ALERT: Active exploitation of remote monitoring and management platform within Australiaconfirmed
- NewsHIGH ALERT: Active exploitation of remote monitoring and management platform within Australiaconfirmed
- NewsPatch bundle: Oracle Oracle Critical Security Patch Update Advisory - August 2026 — 1040 CVEs, 151 criticalcorroborated
- NewsMattermost security advisory (AV26-828)confirmed
- NewsCISA Malcolmconfirmed
- News17 Iranians Charged with Conducting Massive Cyber Theft Campaign on Behalf of the Islamic Revolutionary Guard Corps and Other Iranian Entitiesconfirmed
- NewsCritical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projectscorroborated
- NewsApple security advisory (AV26-823)confirmed
- NewsCitrix security advisory (AV26-645) – Update 2confirmed
- NewsMicrosoft Edge security advisory (AV26-822)confirmed
- NewsCISA Adds One Known Exploited Vulnerability to Catalogconfirmed
- NewsFrench tax authority data breach affects 678,000 individualscorroborated
- NewsAL26-018 - Vulnerability affecting Cisco ASA and Secure Firewall Threat Defense Software Remote Access SSL VPN - CVE-2026-20349confirmed
- NewsAVEVA Enterprise SCADAconfirmed
- NewsAVEVA Enterprise SCADAconfirmed
- NewsFlow Neuroscience FL-100confirmed
- NewsHaiwell IoT Cloud HMI Gatewayconfirmed
- NewsSiemens Solid Edgeconfirmed
- NewsANDRITZ HIPASE-250 and 250 SCALAconfirmed
- NewsSiemens Siveillance Videoconfirmed
- NewsSiemens License Server (SLS)confirmed
- NewsSiemens Desigo DXR and PXC Controllersconfirmed
- NewsHitachi Energy APM Edge Productconfirmed
- NewsSiemens LOGO! Soft Comfortconfirmed
- NewsSiemens Parasolidconfirmed
- NewsSiemens Simcenter Femapconfirmed
- NewsSiemens License Server (SLS)confirmed
- NewsSiemens Desigo DXR and PXC Controllersconfirmed
- NewsSiemens LOGO! Soft Comfortconfirmed
- NewsANDRITZ HIPASE-250 and 250 SCALAconfirmed
- NewsSiemens Siveillance Videoconfirmed
- NewsHitachi Energy APM Edge Productconfirmed
- NewsSiemens Solid Edgeconfirmed
- NewsSiemens Siveillance Videoconfirmed
- NewsSiemens Siveillance Videoconfirmed
- NewsHaiwell IoT Cloud HMI Gatewayconfirmed
- NewsHackers exploit critical Adobe Commerce flaw to hijack customer accountsconfirmed
- NewsCisco security advisory (AV26-807)confirmed
- NewsBulletin de sécurité Red Hat (AV26-803)confirmed
- NewsGrafana security advisory (AV26-796)confirmed
- NewsPulsetto Vagus Nerve Stimulatorconfirmed
- NewsMira Hormone Monitor, Mira Android Appconfirmed
- NewsGunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networkscorroborated
- NewsKEV: CVE-2026-72898 — Metabase Metabase (Metabase SQL Injection Vulnerability)confirmed
- NewsChina-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flawcorroborated
- NewsWordPress security advisory (AV26-792)confirmed
- NewsWebPros security advisory (AV26-790)confirmed
- NewsGoogle security advisory (AV26-787)confirmed
- News200 accounts compromised in Swiss government’s Microsoft SharePoint breachcorroborated
- NewsLeak-site claim: Helix lists Uberclaimed
- NewsLeak-site claim: Helix lists Highwoods Propertiesclaimed
- NewsCyberattack on North Carolina Ports ‘contained’ as Coast Guard, state officials investigatecorroborated
- NewsABB Ability Zenonconfirmed
- NewsJohnson Controls Inc. TL280confirmed
- NewsMedixant RadiAnt DICOMconfirmed
- NewsJohnson Controls Inc. TL280confirmed
- NewsPatch bundle: August 2026 Early Security Updates — 19 CVEs, 0 exploitedcorroborated
- NewsRansom Cartel ransomware creator sentenced to 16 years in prisoncorroborated
- NewsPaperclip AI Flaws Let Unauthenticated Attackers Run Commandscorroborated
- NewsCISA Adds One Known Exploited Vulnerability to Catalogconfirmed
- NewsCanadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millionsconfirmed
- NewsNew OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitchcorroborated
- NewsCritical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markupcorroborated
- News77 Open VSX extensions found harvesting developer infocorroborated
- News128 Seconds to disruption: Microsoft Defender stops ransomware at QNETvendor research
- NewsCheckpoint security advisory (AV26-774)confirmed
- NewsThermo Fisher Applied Biosystems Genetic Analyzersconfirmed
- NewsNew cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Rootconfirmed
- NewsCISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromisesvendor research
- NewsN-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incompletecorroborated
- NewsHugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Codecorroborated
- NewsKEV: CVE-2026-18577 — N-able N-central (N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability)confirmed
- NewsHijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malwarecorroborated
- NewsRails security advisory (AV26-767)confirmed
- NewsSolarWinds security advisory (AV26-766)confirmed
- NewsWhat the Hugging Face breach reveals about defense in the age of agentic AIcorroborated
- News8-K Item 1.05: AMGEN INC reports material cybersecurity incidentconfirmed
- NewsVMware security advisory (AV26-763)confirmed
- News[Control Systems] Phoenix Contact security advisory (AV26-762)confirmed
- NewsIn the Hugging Face breach, OpenAI’s hacker was noisy and fast — but not unstoppablecorroborated
- NewsWebPros security advisory (AV26-761)confirmed
- NewsSpring security advisory (AV26-759)confirmed
- NewsCisco security advisory (AV26-757)confirmed
- NewsJohnson Controls OpenBlue Employeeconfirmed
- NewsNASA Core Flight System (cFS) Health & Safety (HS) Applicationconfirmed
- NewsMikroTik RouterOSconfirmed
- NewsMitsubishi Electric CC-Link IE TSN Communication Protocolconfirmed
- NewsWatchfire Controller Softwareconfirmed
- NewsSchneider Electric IGSSconfirmed
- NewsToptech Systems RCU II+ and Multiload II+confirmed
- Newso6 Automation open62541confirmed
- NewsMikroTik RouterOSconfirmed
- NewsRockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Moduleconfirmed
- NewsSchneider Electric IGSSconfirmed
- NewsJohnson Controls OpenBlue Employeeconfirmed
- NewsCISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCsconfirmed
- NewsOpen Source Software: Security Principles and Practicesconfirmed
- News8-K Item 1.05: River Financial Corp reports material cybersecurity incidentconfirmed
- NewsWhen AppSec Scanners Become a Supply Chain Attack Vectorcorroborated
- News2026 Minimum Elements for a Software Bill of Materials (SBOM)confirmed
- NewsCritical VM Escape Vulnerability Patched in VMware ESXicorroborated
- NewsKEV: CVE-2026-20316 — Cisco Secure Firewall Management Center (FMC) (Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability)confirmed
- Newsigloohome Smart Lock Mobile Applicationconfirmed
- NewsSiemens Mendix Runtimeconfirmed
- NewsSiemens SIMATIC S7-PLCSIM Advancedconfirmed
- NewsSiemens Desigo CCconfirmed
- NewsABB KNX Update Toolconfirmed
- NewsMikroTik RouterOS and Cloud Hosted Routerconfirmed
- NewsCritical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging Incorroborated
- NewsErlang security advisory (AV26-750)confirmed
- NewsLeak-site claim: shinyhunters lists Ernst & Youngcorroborated
- NewsCoca-Cola Confirms Data Breach After Fairlife Ransomware Attackcorroborated
- NewsHacked Public Wi-Fi Gateways Used to Harvest Corporate Credentialscorroborated
- NewsKEV: CVE-2026-16812 — Arista VeloCloud Orchestrator (Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability)confirmed
- NewsKEV: CVE-2025-68686 — Fortinet FortiOS (Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability)confirmed
- NewsHugging Face CEO calls for ‘radical transparency’ after ‘unprecedented’ OpenAI hackcorroborated
- NewsLeak-site claim: ExfilSquad lists Frontier Airlinescorroborated
- NewsLeak-site claim: ExfilSquad lists Police National Legal Databasecorroborated
- NewsCalifornia AG breach notice: Zacks Investment Research, Inc.confirmed
- NewsProgress security advisory (AV26-746)confirmed
- News[Control Systems] Moxa security advisory (AV26-742)confirmed
- NewsClop ransomware targets Windchill, FlexPLM in data theft attackscorroborated
- NewsRussian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codescorroborated
- NewsJohnson Controls XAAP Androidconfirmed
- NewsPanduit IntraVUEconfirmed
- NewsMZ Automation libIEC61850confirmed
- NewsWeintek cMT3092Xconfirmed
- NewsUK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisationsconfirmed
- NewsRussian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suiteconfirmed
- NewsNew Dolphin X Stealer Employs AI Profiling to Prioritize Targetscorroborated
- NewsUS Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devicescorroborated
- NewsOpenAI scored an own goal with HuggingFace attack, showing how open Chinese models are winningcorroborated
- NewsSwiss rail giant Stadler rejects $12.3M ransom demand after cyberattackcorroborated
- NewsUbuntu snap-confine Vulnerability Enables Local Root Accesscorroborated
- NewsAnubis ransomware claims Coca-Cola Fairlife attack, threatens data leakcorroborated
- NewsHPE security advisory (AV26-727)confirmed
- NewsTenable security advisory (AV26-724)confirmed
- NewsRockwell Automation Studio 5000 Logix Designerconfirmed
- NewsSiemens Opcenter Xconfirmed
- NewsSiemens IAM Clientconfirmed
- NewsSiemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFWconfirmed
- NewsFake FBI agents target people who already got scammedcorroborated
- NewsCritical Palo Alto VPN bug now exploited by Qilin ransomware gangconfirmed
- NewsCritical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Executioncorroborated
- NewsKEV: CVE-2026-0770 — Langflow Langflow (Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability)confirmed
- NewsEstée Lauder discloses data breach via Oracle E-Business flawcorroborated
- NewsMore than 1,000 domains illegally streaming World Cup games seized, DOJ sayscorroborated
- NewsHackers were inside South Korea's diplomat training system for 9 monthscorroborated
- NewsAn AI SOC Evaluation Guide for Security Leaderscorroborated
- NewsInc Ransomware Exploits SonicWall SMA Zero-Dayscorroborated
- NewsProgress Restores ShareFile Storage Zones Access After Security Warningconfirmed
- NewsMultiple Jscrambler Packages Impacted by Supply Chain Attackcorroborated
- NewsCISA Adds Two Known Exploited Vulnerabilities to Catalogconfirmed
- NewsWhat to Know About China's DeepSeek AIcorroborated
- News8-K Item 1.05: Hewlett Packard Enterprise Co reports material cybersecurity incidentconfirmed
- News8-K Item 8.01: National Bank Holdings Corp discloses a cybersecurity incident (not filed as material)confirmed
Respond
- NewsGitLab security advisory (AV26-917)confirmed
- NewsCISA Adds Three Known Exploited Vulnerabilities to Catalogconfirmed
- NewsPalo Alto Networks security advisory (AV26-905)confirmed
- NewsAVEVA Pipeline Integrity Monitorconfirmed
- NewsNextGen Healthcare Mirth Connectconfirmed
- NewsAVEVA Pipeline Integrity Monitorconfirmed
- NewsOrthanc DICOM Serverconfirmed
- NewsCISA Adds Two Known Exploited Vulnerabilities to Catalogconfirmed
- NewsUkrainian National Sentenced to Four Years in Prison for Wire Fraud Conspiracy in Connection with Conti Ransomwareconfirmed
- NewsST Engineering iDirect iQ-Series Terminals (Update A)confirmed
- NewsCISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadlinecorroborated
- News8-K Item 8.01: CONDUENT Inc discloses a cybersecurity incident (not filed as material)confirmed
- NewsCisco security advisory (AV26-197) – Update 3confirmed
- NewsFortinet security advisory (AV26-023) - Update 1confirmed
- NewsGoogle security advisory (AV26-904)confirmed
- NewsConnectWise security advisory (AV26-903)confirmed
- NewsCheck Point security advisory (AV26-902)confirmed
- News2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Serverconfirmed
- NewsCISA Adds Four Known Exploited Vulnerabilities to Catalogconfirmed
- NewsCSA Singapore alert: 9 September 2026 Active Exploitation of Vulnerability in N-Able N-Central Attackers are exploiting a critical vulnerability in N-Able N-Central remote management and monitoring tool to execute code remotely without authentication. Patch immediately. Alertsconfirmed
- NewsMicrosoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploitedcorroborated
- NewsIvanti security advisory (AV26-897)confirmed
- NewsMikrotik security advisory (AV26-887)confirmed
- NewsAdobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shellcorroborated
- News8-K Item 8.01: Rigetti Computing, Inc. (RGTI, RGTIW) discloses a cybersecurity incident (not filed as material)confirmed
- News8-K Item 8.01: D-Wave Quantum Inc. discloses a cybersecurity incident (not filed as material)confirmed
- News8-K Item 1.05: BOSTON SCIENTIFIC CORP reports material cybersecurity incidentconfirmed
- News8-K Item 8.01: UNITED NATURAL FOODS INC discloses a cybersecurity incident (not filed as material)confirmed
- News8-K Item 8.01: Veradigm Inc. discloses a cybersecurity incident (not filed as material)confirmed
- NewsN-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218)corroborated
- NewsInductive Automation Ignitionconfirmed
- NewsTycon Systems TPDIN-Monitor-WEB3confirmed
- NewsIXON VPN Clientconfirmed
- NewsInductive Automation Ignitionconfirmed
- NewsTycon Systems TPDIN-Monitor-WEB3confirmed
- NewsIXON VPN Clientconfirmed
- NewsPyramid Solutions NetStaX EtherNet/IP Stackconfirmed
- NewsRockwell Automation 1756-ENBT Moduleconfirmed
- NewsPyramid Solutions NetStaX EtherNet/IP Stackconfirmed
- NewsRockwell Automation 1756-ENBT Moduleconfirmed
- NewsProgress Software security advisory (AV26-875)confirmed
- NewsNearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)confirmed
- NewsSonicWall security advisory (AV26-872)confirmed
- NewsSonicWall Warns of Two SMA1000 Zero-Days Exploited in Attackscorroborated
- NewsJFrog security advisory (AV26-867)confirmed
- NewsRockwell Automation RSLinx Classicconfirmed
- News8-K Item 1.05: Park Dental Partners, Inc. reports material cybersecurity incidentconfirmed
- NewsCISA Adds Two Known Exploited Vulnerabilities to Catalogconfirmed
- News8-K Item 1.05: Nutex Health Inc. reports material cybersecurity incidentconfirmed
- NewsMcKesson discloses breach after ShinyHunters claims patient data theftcorroborated
- NewsPaperCut releases second emergency patch for exploited flawscorroborated
- NewsCalifornia AG breach notice: Bennett Collegeconfirmed
- NewsWebPros security advisory (AV26-854)confirmed
- NewsCybercrooks jet off with Manchester Airports Group customer datacorroborated
- NewsTwo Alleged ‘TeamPCP’ Hackers Arrested in Australiacorroborated
- NewsAll-Line Equipment Company Fuel-Bossconfirmed
- NewsAll-Line Equipment Company Fuel-Bossconfirmed
- NewsRockwell Automation OTTO Fleet Managerconfirmed
- NewsCISA Adds Three Known Exploited Vulnerabilities to Catalogconfirmed
- NewsMitsubishi Electric Multiple FA Products (Update D)confirmed
- NewsApplied Systems Engineering ASE2000 V2 Communications Test Setconfirmed
- NewsMitsubishi Electric CNC Series (Update A)confirmed
- NewsEbyte NA111-Mconfirmed
- NewsRockwell Automation OTTO Fleet Managerconfirmed
- NewsXiiaozet LK100Wconfirmed
- NewsApplied Systems Engineering ASE2000 V2 Communications Test Setconfirmed
- NewsMitsubishi Electric CNC Series (Update A)confirmed
- NewsXiiaozet LK100Wconfirmed
- NewsEbyte NA111-Mconfirmed
- NewsCISA orders feds to patch Citrix NetScaler RCE flaw by Saturdayconfirmed
- NewsNext.js security advisory (AV26-851)confirmed
- NewsBoston Scientific says cyberattack disrupted operations globallycorroborated
- NewsCritical Gitea vulnerability now exploited in the wild (CVE-2026-60004)corroborated
- NewsRently Smart Homeconfirmed
- NewsPayRange APIconfirmed
- NewsZoneminderconfirmed
- NewsRently Smart Homeconfirmed
- NewsPayRange APIconfirmed
- NewsZoneminderconfirmed
- NewsBendix EC80 Brake ECUconfirmed
- NewsFURUNO FA-50 Class B AIS Transponderconfirmed
- NewsEbyte NE2-D11confirmed
- NewsEbyte NE2-D11confirmed
- NewsSiemens SIMATIC IoT2050 Advancedconfirmed
- NewsFURUNO FA-50 Class B AIS Transponderconfirmed
- NewsBendix EC80 Brake ECUconfirmed
- NewsSiemens SIMATIC IoT2050 Advancedconfirmed
- NewsKEV: CVE-2026-60004 — Gitea Gitea (Gitea Code Injection Vulnerability)confirmed
- NewsCISA Adds One Known Exploited Vulnerability to Catalogconfirmed
- NewsCISA orders urgent patching of actively exploited Zimbra flawcorroborated
- NewsCritical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836)claimed
- NewsTrueConf security advisory (AV26-835)confirmed
- NewsJFrog Artifactory Flaws Enable Software Supply Chain Attackscorroborated
- NewsJohnson Controls Simplex Incident Managerconfirmed
- NewsCitrix security advisory (AV26-833)confirmed
- NewsMLflow security advisory (AV26-832)confirmed
- NewsCISA Adds One Known Exploited Vulnerability to Catalogconfirmed
- NewsCritical RCE flaw in Windows IKE Extension now actively exploitedcorroborated
- NewsHIGH ALERT: Active exploitation of remote monitoring and management platform within Australiaconfirmed
- NewsHIGH ALERT: Active exploitation of remote monitoring and management platform within Australiaconfirmed
- NewsPatch bundle: Oracle Oracle Critical Security Patch Update Advisory - August 2026 — 1040 CVEs, 151 criticalcorroborated
- NewsMattermost security advisory (AV26-828)confirmed
- NewsCISA Malcolmconfirmed
- NewsCritical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projectscorroborated
- NewsApple security advisory (AV26-823)confirmed
- NewsCitrix security advisory (AV26-645) – Update 2confirmed
- NewsMicrosoft Edge security advisory (AV26-822)confirmed
- NewsCISA Adds One Known Exploited Vulnerability to Catalogconfirmed
- NewsFrench tax authority data breach affects 678,000 individualscorroborated
- NewsAL26-018 - Vulnerability affecting Cisco ASA and Secure Firewall Threat Defense Software Remote Access SSL VPN - CVE-2026-20349confirmed
- NewsAVEVA Enterprise SCADAconfirmed
- NewsAVEVA Enterprise SCADAconfirmed
- NewsFlow Neuroscience FL-100confirmed
- NewsHaiwell IoT Cloud HMI Gatewayconfirmed
- NewsSiemens Solid Edgeconfirmed
- NewsANDRITZ HIPASE-250 and 250 SCALAconfirmed
- NewsSiemens Siveillance Videoconfirmed
- NewsSiemens License Server (SLS)confirmed
- NewsSiemens Desigo DXR and PXC Controllersconfirmed
- NewsHitachi Energy APM Edge Productconfirmed
- NewsSiemens LOGO! Soft Comfortconfirmed
- NewsSiemens Parasolidconfirmed
- NewsSiemens Simcenter Femapconfirmed
- NewsSiemens License Server (SLS)confirmed
- NewsSiemens Desigo DXR and PXC Controllersconfirmed
- NewsSiemens LOGO! Soft Comfortconfirmed
- NewsANDRITZ HIPASE-250 and 250 SCALAconfirmed
- NewsSiemens Siveillance Videoconfirmed
- NewsHitachi Energy APM Edge Productconfirmed
- NewsSiemens Solid Edgeconfirmed
- NewsSiemens Siveillance Videoconfirmed
- NewsSiemens Siveillance Videoconfirmed
- NewsHaiwell IoT Cloud HMI Gatewayconfirmed
- NewsHackers exploit critical Adobe Commerce flaw to hijack customer accountsconfirmed
- NewsCisco security advisory (AV26-807)confirmed
- NewsBulletin de sécurité Red Hat (AV26-803)confirmed
- NewsGrafana security advisory (AV26-796)confirmed
- NewsPulsetto Vagus Nerve Stimulatorconfirmed
- NewsMira Hormone Monitor, Mira Android Appconfirmed
- NewsGunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networkscorroborated
- NewsKEV: CVE-2026-72898 — Metabase Metabase (Metabase SQL Injection Vulnerability)confirmed
- NewsChina-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flawcorroborated
- NewsWordPress security advisory (AV26-792)confirmed
- NewsWebPros security advisory (AV26-790)confirmed
- NewsGoogle security advisory (AV26-787)confirmed
- News200 accounts compromised in Swiss government’s Microsoft SharePoint breachcorroborated
- NewsLeak-site claim: Helix lists Uberclaimed
- NewsLeak-site claim: Helix lists Highwoods Propertiesclaimed
- NewsABB Ability Zenonconfirmed
- NewsJohnson Controls Inc. TL280confirmed
- NewsMedixant RadiAnt DICOMconfirmed
- NewsJohnson Controls Inc. TL280confirmed
- NewsPatch bundle: August 2026 Early Security Updates — 19 CVEs, 0 exploitedcorroborated
- NewsRansom Cartel ransomware creator sentenced to 16 years in prisoncorroborated
- NewsPaperclip AI Flaws Let Unauthenticated Attackers Run Commandscorroborated
- NewsCISA Adds One Known Exploited Vulnerability to Catalogconfirmed
- NewsCanadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millionsconfirmed
- NewsNew OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitchcorroborated
- NewsCritical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markupcorroborated
- News77 Open VSX extensions found harvesting developer infocorroborated
- News128 Seconds to disruption: Microsoft Defender stops ransomware at QNETvendor research
- NewsCheckpoint security advisory (AV26-774)confirmed
- NewsThermo Fisher Applied Biosystems Genetic Analyzersconfirmed
- NewsNew cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Rootconfirmed
- NewsCISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromisesvendor research
- NewsN-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incompletecorroborated
- NewsHugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Codecorroborated
- NewsKEV: CVE-2026-18577 — N-able N-central (N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability)confirmed
- NewsRails security advisory (AV26-767)confirmed
- NewsSolarWinds security advisory (AV26-766)confirmed
- NewsWhat the Hugging Face breach reveals about defense in the age of agentic AIcorroborated
- News8-K Item 1.05: AMGEN INC reports material cybersecurity incidentconfirmed
- NewsVMware security advisory (AV26-763)confirmed
- News[Control Systems] Phoenix Contact security advisory (AV26-762)confirmed
- NewsWebPros security advisory (AV26-761)confirmed
- NewsSpring security advisory (AV26-759)confirmed
- NewsCisco security advisory (AV26-757)confirmed
- NewsJohnson Controls OpenBlue Employeeconfirmed
- NewsNASA Core Flight System (cFS) Health & Safety (HS) Applicationconfirmed
- NewsMikroTik RouterOSconfirmed
- NewsMitsubishi Electric CC-Link IE TSN Communication Protocolconfirmed
- NewsWatchfire Controller Softwareconfirmed
- NewsSchneider Electric IGSSconfirmed
- NewsToptech Systems RCU II+ and Multiload II+confirmed
- Newso6 Automation open62541confirmed
- NewsMikroTik RouterOSconfirmed
- NewsRockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Moduleconfirmed
- NewsSchneider Electric IGSSconfirmed
- NewsJohnson Controls OpenBlue Employeeconfirmed
- NewsOpen Source Software: Security Principles and Practicesconfirmed
- News8-K Item 1.05: River Financial Corp reports material cybersecurity incidentconfirmed
- NewsWhen AppSec Scanners Become a Supply Chain Attack Vectorcorroborated
- News2026 Minimum Elements for a Software Bill of Materials (SBOM)confirmed
- NewsCritical VM Escape Vulnerability Patched in VMware ESXicorroborated
- NewsKEV: CVE-2026-20316 — Cisco Secure Firewall Management Center (FMC) (Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability)confirmed
- Newsigloohome Smart Lock Mobile Applicationconfirmed
- NewsSiemens Mendix Runtimeconfirmed
- NewsSiemens SIMATIC S7-PLCSIM Advancedconfirmed
- NewsSiemens Desigo CCconfirmed
- NewsABB KNX Update Toolconfirmed
- NewsMikroTik RouterOS and Cloud Hosted Routerconfirmed
- NewsCritical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging Incorroborated
- NewsErlang security advisory (AV26-750)confirmed
- NewsLeak-site claim: shinyhunters lists Ernst & Youngcorroborated
- NewsCoca-Cola Confirms Data Breach After Fairlife Ransomware Attackcorroborated
- NewsKEV: CVE-2026-16812 — Arista VeloCloud Orchestrator (Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability)confirmed
- NewsKEV: CVE-2025-68686 — Fortinet FortiOS (Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability)confirmed
- NewsLeak-site claim: ExfilSquad lists Frontier Airlinescorroborated
- NewsLeak-site claim: ExfilSquad lists Police National Legal Databasecorroborated
- NewsCalifornia AG breach notice: Zacks Investment Research, Inc.confirmed
- NewsProgress security advisory (AV26-746)confirmed
- News[Control Systems] Moxa security advisory (AV26-742)confirmed
- NewsClop ransomware targets Windchill, FlexPLM in data theft attackscorroborated
- NewsJohnson Controls XAAP Androidconfirmed
- NewsPanduit IntraVUEconfirmed
- NewsMZ Automation libIEC61850confirmed
- NewsWeintek cMT3092Xconfirmed
- NewsRussian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suiteconfirmed
- NewsSwiss rail giant Stadler rejects $12.3M ransom demand after cyberattackcorroborated
- NewsUbuntu snap-confine Vulnerability Enables Local Root Accesscorroborated
- NewsAnubis ransomware claims Coca-Cola Fairlife attack, threatens data leakcorroborated
- NewsHPE security advisory (AV26-727)confirmed
- NewsTenable security advisory (AV26-724)confirmed
- NewsRockwell Automation Studio 5000 Logix Designerconfirmed
- NewsSiemens Opcenter Xconfirmed
- NewsSiemens IAM Clientconfirmed
- NewsSiemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFWconfirmed
- NewsCritical Palo Alto VPN bug now exploited by Qilin ransomware gangconfirmed
- NewsCritical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Executioncorroborated
- NewsKEV: CVE-2026-0770 — Langflow Langflow (Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability)confirmed
- NewsEstée Lauder discloses data breach via Oracle E-Business flawcorroborated
- NewsHackers were inside South Korea's diplomat training system for 9 monthscorroborated
- NewsAn AI SOC Evaluation Guide for Security Leaderscorroborated
- NewsInc Ransomware Exploits SonicWall SMA Zero-Dayscorroborated
- NewsProgress Restores ShareFile Storage Zones Access After Security Warningconfirmed
- NewsMultiple Jscrambler Packages Impacted by Supply Chain Attackcorroborated
- NewsCISA Adds Two Known Exploited Vulnerabilities to Catalogconfirmed
- News8-K Item 1.05: Hewlett Packard Enterprise Co reports material cybersecurity incidentconfirmed
- News8-K Item 8.01: National Bank Holdings Corp discloses a cybersecurity incident (not filed as material)confirmed
Worked cases
Incidents from the harvested record that this service addresses. These do not depend on this week’s news; the badged items above do.
- Ransomware sold as a product, with security professionals recruited as the supply chain
- Turn the remote-access appliance into a credential collector, then patch the authentication server to accept a chosen value
- An exploit that applies on viewing, defeating every control built around user action
- Tell the device to mail you its own configuration, using the management protocol's write function
- Compromise the carrier, and inherit everyone whose traffic crosses it
- Make the victim run the payload as proof they are human
- Encrypt only the virtual estate, exfiltrate through the victim's own cloud tooling, and delete the encryptor afterwards
- Exploited inside the mandated patching window, then exploited again on a second instance during the response
- Select victims by exposure alone, finish the same day, and change name to stay unattributed
- Extort the victim a second time, from inside your own operation
- Chain four flaws in an end-of-life security appliance
- The account of someone who left, and the backup that kept their desk
- Register your own device as the second factor, and the lock is now yours
- The identities that cannot have a second factor
- A state-linked group that sells the access instead of using it
- Build the target list before the vulnerability is public
- Ransom hospitals to pay for the nuclear-programme espionage
- Learn the help desk's reset procedure, then call back and use it
- Take dozens of build servers, then wait
- The pipeline stopped because the company stopped it
- Phish from inside the marketing platform the recipient already trusts
- The tool that certifies the appliance is clean can be told to say so
- He says he is from IT, and if you will not let him in remotely he drives over
- Phish the credential, then change where the money is sent
- The QR code exists to get the victim off the managed device
Cloud Detection & Response
Worked cases this service addresses:
- Ransomware sold as a product, with security professionals recruited as the supply chain
- Turn the remote-access appliance into a credential collector, then patch the authentication server to accept a chosen value
- An exploit that applies on viewing, defeating every control built around user action
- Tell the device to mail you its own configuration, using the management protocol's write function
- Compromise the carrier, and inherit everyone whose traffic crosses it
- Encrypt only the virtual estate, exfiltrate through the victim's own cloud tooling, and delete the encryptor afterwards
- Exploited inside the mandated patching window, then exploited again on a second instance during the response
- Select victims by exposure alone, finish the same day, and change name to stay unattributed
- Extort the victim a second time, from inside your own operation
- Chain four flaws in an end-of-life security appliance
- The account of someone who left, and the backup that kept their desk
- Register your own device as the second factor, and the lock is now yours
- The identities that cannot have a second factor
- Build the target list before the vulnerability is public
- Ransom hospitals to pay for the nuclear-programme espionage
- Learn the help desk's reset procedure, then call back and use it
- The pipeline stopped because the company stopped it
- The tool that certifies the appliance is clean can be told to say so
- He says he is from IT, and if you will not let him in remotely he drives over
Endpoint Detection & Response
Worked cases this service addresses:
- Ransomware sold as a product, with security professionals recruited as the supply chain
- Turn the remote-access appliance into a credential collector, then patch the authentication server to accept a chosen value
- An exploit that applies on viewing, defeating every control built around user action
- Tell the device to mail you its own configuration, using the management protocol's write function
- Compromise the carrier, and inherit everyone whose traffic crosses it
- Make the victim run the payload as proof they are human
- Encrypt only the virtual estate, exfiltrate through the victim's own cloud tooling, and delete the encryptor afterwards
- Exploited inside the mandated patching window, then exploited again on a second instance during the response
- Select victims by exposure alone, finish the same day, and change name to stay unattributed
- Extort the victim a second time, from inside your own operation
- Chain four flaws in an end-of-life security appliance
- The account of someone who left, and the backup that kept their desk
- Register your own device as the second factor, and the lock is now yours
- The identities that cannot have a second factor
- A state-linked group that sells the access instead of using it
- Ransom hospitals to pay for the nuclear-programme espionage
- Learn the help desk's reset procedure, then call back and use it
- Take dozens of build servers, then wait
- The pipeline stopped because the company stopped it
- Phish from inside the marketing platform the recipient already trusts
- The tool that certifies the appliance is clean can be told to say so
- He says he is from IT, and if you will not let him in remotely he drives over
- Phish the credential, then change where the money is sent
- The QR code exists to get the victim off the managed device
Identity Threat Detection & Response
Worked cases this service addresses:
- Turn the remote-access appliance into a credential collector, then patch the authentication server to accept a chosen value
- An exploit that applies on viewing, defeating every control built around user action
- Tell the device to mail you its own configuration, using the management protocol's write function
- Compromise the carrier, and inherit everyone whose traffic crosses it
- Encrypt only the virtual estate, exfiltrate through the victim's own cloud tooling, and delete the encryptor afterwards
- Exploited inside the mandated patching window, then exploited again on a second instance during the response
- Select victims by exposure alone, finish the same day, and change name to stay unattributed
- Extort the victim a second time, from inside your own operation
- Chain four flaws in an end-of-life security appliance
- The account of someone who left, and the backup that kept their desk
- Register your own device as the second factor, and the lock is now yours
- The identities that cannot have a second factor
- A state-linked group that sells the access instead of using it
- Ransom hospitals to pay for the nuclear-programme espionage
- Learn the help desk's reset procedure, then call back and use it
- The pipeline stopped because the company stopped it
- The tool that certifies the appliance is clean can be told to say so
- He says he is from IT, and if you will not let him in remotely he drives over
- Phish the credential, then change where the money is sent
- The QR code exists to get the victim off the managed device
Network Detection & Response
Worked cases this service addresses:
- Ransomware sold as a product, with security professionals recruited as the supply chain
- Turn the remote-access appliance into a credential collector, then patch the authentication server to accept a chosen value
- An exploit that applies on viewing, defeating every control built around user action
- Tell the device to mail you its own configuration, using the management protocol's write function
- Compromise the carrier, and inherit everyone whose traffic crosses it
- Encrypt only the virtual estate, exfiltrate through the victim's own cloud tooling, and delete the encryptor afterwards
- Exploited inside the mandated patching window, then exploited again on a second instance during the response
- Select victims by exposure alone, finish the same day, and change name to stay unattributed
- Extort the victim a second time, from inside your own operation
- Chain four flaws in an end-of-life security appliance
- The account of someone who left, and the backup that kept their desk
- The identities that cannot have a second factor
- A state-linked group that sells the access instead of using it
- Build the target list before the vulnerability is public
- Ransom hospitals to pay for the nuclear-programme espionage
- The pipeline stopped because the company stopped it
- Phish from inside the marketing platform the recipient already trusts
- The tool that certifies the appliance is clean can be told to say so
- He says he is from IT, and if you will not let him in remotely he drives over
Compliance 26
Active threats this quarter that Compliance addresses:
Prevent
- News8-K Item 8.01: CONDUENT Inc discloses a cybersecurity incident (not filed as material)confirmed
- News8-K Item 8.01: Rigetti Computing, Inc. (RGTI, RGTIW) discloses a cybersecurity incident (not filed as material)confirmed
- News8-K Item 8.01: D-Wave Quantum Inc. discloses a cybersecurity incident (not filed as material)confirmed
- News8-K Item 1.05: BOSTON SCIENTIFIC CORP reports material cybersecurity incidentconfirmed
- News8-K Item 8.01: UNITED NATURAL FOODS INC discloses a cybersecurity incident (not filed as material)confirmed
- News8-K Item 8.01: Veradigm Inc. discloses a cybersecurity incident (not filed as material)confirmed
- NewsHoneywell Aerospace Inc. Agrees to Pay Over $2M to Settle False Claims Act Allegations of Failing to Comply with Cybersecurity Requirements in a U.S. Department of Defense Contractconfirmed
- News8-K Item 1.05: Park Dental Partners, Inc. reports material cybersecurity incidentconfirmed
- News8-K Item 1.05: Nutex Health Inc. reports material cybersecurity incidentconfirmed
- NewsMcKesson discloses breach after ShinyHunters claims patient data theftcorroborated
- NewsCalifornia AG breach notice: Bennett Collegeconfirmed
- NewsCybercrooks jet off with Manchester Airports Group customer datacorroborated
- NewsBoston Scientific says cyberattack disrupted operations globallycorroborated
- NewsTikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuitcorroborated
- NewsFrench tax authority data breach affects 678,000 individualscorroborated
- News8-K Item 1.05: AMGEN INC reports material cybersecurity incidentconfirmed
- NewsIn the Hugging Face breach, OpenAI’s hacker was noisy and fast — but not unstoppablecorroborated
- NewsOpen Source Software: Security Principles and Practicesconfirmed
- News8-K Item 1.05: River Financial Corp reports material cybersecurity incidentconfirmed
- NewsSiemens Mendix Runtimeconfirmed
- NewsCoca-Cola Confirms Data Breach After Fairlife Ransomware Attackcorroborated
- NewsLeak-site claim: ExfilSquad lists Police National Legal Databasecorroborated
- NewsEstée Lauder discloses data breach via Oracle E-Business flawcorroborated
- NewsHackers were inside South Korea's diplomat training system for 9 monthscorroborated
- News8-K Item 1.05: Hewlett Packard Enterprise Co reports material cybersecurity incidentconfirmed
- News8-K Item 8.01: National Bank Holdings Corp discloses a cybersecurity incident (not filed as material)confirmed
Risk Management 5
Active threats this quarter that Risk Management addresses:
Prevent
- NewsHoneywell Aerospace Inc. Agrees to Pay Over $2M to Settle False Claims Act Allegations of Failing to Comply with Cybersecurity Requirements in a U.S. Department of Defense Contractconfirmed
- NewsTikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuitcorroborated
- NewsOpen Source Software: Security Principles and Practicesconfirmed
- NewsCI Fortify – Advice for isolating vital systemsconfirmed
- NewsPost-quantum cryptography (PQC) migration workshop reportconfirmed
Worked cases
Incidents from the harvested record that this service addresses. These do not depend on this week’s news; the badged items above do.
- An exploit that applies on viewing, defeating every control built around user action
- Tell the device to mail you its own configuration, using the management protocol's write function
- Compromise the carrier, and inherit everyone whose traffic crosses it
- Learn the help desk's reset procedure, then call back and use it
Third-party 22
Active threats this quarter that Third-party addresses:
Prevent
- NewsN-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218)corroborated
- NewsMcKesson discloses breach after ShinyHunters claims patient data theftcorroborated
- NewsNorth Korean remote workers are broadening their job hunt beyond ITcorroborated
- NewsCybercrooks jet off with Manchester Airports Group customer datacorroborated
- NewsTwo Alleged ‘TeamPCP’ Hackers Arrested in Australiacorroborated
- NewsBoston Scientific says cyberattack disrupted operations globallycorroborated
- NewsJFrog Artifactory Flaws Enable Software Supply Chain Attackscorroborated
- NewsHIGH ALERT: Active exploitation of remote monitoring and management platform within Australiaconfirmed
- News17 Iranians Charged with Conducting Massive Cyber Theft Campaign on Behalf of the Islamic Revolutionary Guard Corps and Other Iranian Entitiesconfirmed
- NewsFrench tax authority data breach affects 678,000 individualscorroborated
- News77 Open VSX extensions found harvesting developer infocorroborated
- NewsN-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incompletecorroborated
- NewsHugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Codecorroborated
- NewsOpen Source Software: Security Principles and Practicesconfirmed
- NewsWhen AppSec Scanners Become a Supply Chain Attack Vectorcorroborated
- News2026 Minimum Elements for a Software Bill of Materials (SBOM)confirmed
- NewsLeak-site claim: shinyhunters lists Ernst & Youngcorroborated
- NewsHugging Face CEO calls for ‘radical transparency’ after ‘unprecedented’ OpenAI hackcorroborated
- NewsSwiss rail giant Stadler rejects $12.3M ransom demand after cyberattackcorroborated
- NewsSiemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFWconfirmed
- NewsMultiple Jscrambler Packages Impacted by Supply Chain Attackcorroborated
- News8-K Item 1.05: Hewlett Packard Enterprise Co reports material cybersecurity incidentconfirmed
Worked cases
Incidents from the harvested record that this service addresses. These do not depend on this week’s news; the badged items above do.
- An exploit that applies on viewing, defeating every control built around user action
- Tell the device to mail you its own configuration, using the management protocol's write function
- Compromise the carrier, and inherit everyone whose traffic crosses it
- Exploited inside the mandated patching window, then exploited again on a second instance during the response
- Build the target list before the vulnerability is public
- Learn the help desk's reset procedure, then call back and use it
Check one or more of your service offerings above to see the vulnerabilities, threats and incidents each one addresses.