Signals
Every approved advisory from 40+ monitored sources. Sorted by date, newest first. Click any card to read the full advisory.
For active exploits requiring immediate action, see Alerts →
Citrix NetScaler ADC and Gateway Memory Buffer Vulnerability (CVE-2026-8452)
CISA has added CVE-2026-8452 to the Known Exploited Vulnerabilities catalog, flagging a memory buffe…
Microsoft Entra ID Deserialization Vulnerability (CVE-2026-69836)
CISA has added CVE-2026-69836, a deserialization of untrusted data vulnerability in Microsoft Entra…
N-able N-central Authentication Bypass (CVE-2026-18556)
CISA has added an authentication bypass vulnerability in N-able N-central to its Known Exploited Vul…
Check Point SmartConsole Auth Bypass (CVE-2026-16232) — Full Admin Takeover, CISA KEV
CISA has added CVE-2026-16232 to the Known Exploited Vulnerabilities catalog, confirming that Check…
Fortinet FortiSandbox Unauthenticated RCE (CVE-2026-25089) — CISA KEV, Patch by July 19
CISA has added CVE-2026-25089, an unauthenticated OS command injection flaw in Fortinet FortiSandbox…
Oracle E-Business Suite Payments Takeover (CVE-2026-46817) — CISA KEV, Patch by July 18
CISA has added CVE-2026-46817 to the Known Exploited Vulnerabilities catalog, confirming active expl…
SonicWall SMA1000 SSRF (CVE-2026-15409) — Actively Exploited, CISA KEV
CISA has added CVE-2026-15409, a server-side request forgery flaw in SonicWall SMA1000 appliances, t…
SharePoint Server Missing Authentication (CVE-2026-56164) — CISA KEV, Patch by July 17
CISA has added CVE-2026-56164, a missing authentication vulnerability in Microsoft SharePoint Server…
Microsoft Defender RoguePlanet Elevation of Privilege (CVE-2026-50656) | MSSP Advisory
Microsoft issued an out-of-band patch on Wednesday for CVE-2026-50656, a Windows Defender elevation-…
Microsoft Malware Protection Engine local privilege escalation fix (CVE-2026-50656) | MSSP Advisory
Microsoft patched CVE-2026-50656, a local privilege escalation flaw in the Microsoft Malware Protect…
Adobe ColdFusion Path Traversal RCE (CVE-2026-48282) | MSSP Advisory
CISA has added CVE-2026-48282, an Adobe ColdFusion path traversal vulnerability allowing arbitrary c…
Citrix NetScaler Memory Overread Exploit Active (CVE-2026-8451) | MSSP Advisory
Citrix has patched CVE-2026-8451, a memory overread vulnerability in NetScaler ADC and NetScaler Gat…
Microsoft SharePoint Server Deserialization RCE (CVE-2026-45659) | MSSP Advisory
CISA has added CVE-2026-45659, a Microsoft SharePoint Server deserialization vulnerability, to the K…
Cisco Unified Communications Manager SSRF Arbitrary File Write (CVE-2026-20230) | MSSP Advisory
CISA has added CVE-2026-20230 to the Known Exploited Vulnerabilities catalog, confirming active expl…
PTC Windchill FlexPLM Unauthenticated RCE (CVE-2026-12569) | MSSP Advisory
CISA has added CVE-2026-12569 to the Known Exploited Vulnerabilities catalog, flagging an unauthenti…
Splunk Enterprise PostgreSQL Sidecar Pre-Auth RCE (CVE-2026-20253) | MSSP Advisory
CVE-2026-20253 is a pre-authentication remote code execution vulnerability in Splunk Enterprise affe…
Ivanti Sentry OS Command Injection RCE (CVE-2026-10520) | MSSP Advisory
CISA has issued a binding directive requiring federal agencies to patch CVE-2026-10520 in Ivanti Sen…
Check Point Remote Access VPN IKEv1 Authentication Bypass (CVE-2026-50751) | MSSP Advisory
Check Point released hotfixes on June 8, 2026 for CVE-2026-50751, a CVSS 9.3 authentication bypass i…
Ivanti Sentry OS Command Injection RCE (CVE-2026-10520) | MSSP Advisory
CISA has added CVE-2026-10520, an OS command injection flaw in Ivanti Sentry, to the Known Exploited…
Chrome V8 Out-of-Bounds Memory Access RCE (CVE-2026-11645) | MSSP Advisory
Google has patched CVE-2026-11645, an out-of-bounds memory access flaw in the V8 JavaScript engine a…
Ubiquiti UniFi OS Server Unauthenticated RCE (CVE-2026-34908) | MSSP Advisory
Three chained vulnerabilities in Ubiquiti UniFi OS Server versions 5.0.6 and earlier allow an unauth…
Check Point Security Gateway Authentication Bypass RCE (CVE-2026-50751) | MSSP Advisory
CISA has added CVE-2026-50751 to the Known Exploited Vulnerabilities catalog, confirming that attack…
Cisco Catalyst SD-WAN Manager Privilege Escalation RCE (CVE-2026-20245) | MSSP Advisory
Cisco disclosed an unpatched zero-day in Catalyst SD-WAN Manager tracked as CVE-2026-20245 that allo…
Mirasvit Full Page Cache Warmer RCE Active Exploitation (CVE-2026-45247) | MSSP Advisory
CISA added CVE-2026-45247 to its Known Exploited Vulnerabilities catalog on June 3, a CVSS 9.8 flaw…
Microsoft 365 Android Apps Token Theft Debug Flag | MSSP Advisory
A debug flag left set to true in production builds of six Microsoft 365 Android apps disabled the to…
Windows Search URI Handler NTLMv2 Hash Leak (CVE-2026-33829) | MSSP Advisory
Huntress researcher Andrew Schwartz disclosed an unpatched vulnerability in the Windows search: URI…
Visual Studio Code GitHub Token Theft Zero-Day | MSSP Advisory
A publicly disclosed zero-day in Visual Studio Code allows an attacker to steal GitHub OAuth tokens…
Gamaredon WinRAR Vulnerability Data Theft Campaign (CVE-2025-8088) | MSSP Advisory
Russian FSB-linked group Gamaredon is actively exploiting CVE-2025-8088, a vulnerability in WinRAR,…
Google Android Framework Integer Overflow LPE Exploited (CVE-2025-48595) | MSSP Advisory
Google's June 2026 Android security update patches 124 vulnerabilities across Android 14, 15, 16, an…
Windows Netlogon Stack Buffer Overflow RCE (CVE-2026-41089) | MSSP Advisory
A critical Windows Netlogon vulnerability (CVE-2026-41089) is now actively exploited in the wild acc…
WP Maps Pro Privilege Escalation Admin Account Creation (CVE-2026-8732) | MSSP Advisory
WP Maps Pro WordPress plugin versions 6.1.0 and below contain a critical privilege escalation flaw (…
Palo Alto Networks PAN-OS Authentication Bypass VPN (CVE-2026-0257) | MSSP Advisory
CISA flagged CVE-2026-0257, an authentication bypass flaw in Palo Alto Networks PAN-OS that lets att…
ChatGPT Web Summaries Phishing Surface Vulnerability | MSSP Advisory
ChatGPT's web summarization feature automatically renders malicious Markdown links and images from t…
Fortinet FortiClient EMS Authentication Bypass RCE (CVE-2026-35616) | MSSP Advisory
Attackers are exploiting CVE-2026-35616, an authentication bypass flaw in FortiClient Enterprise Man…
GPU Mining Malware SEO Poisoning Campaign | MSSP Advisory
Threat actors are distributing GPU mining malware through SEO poisoning that manipulates search resu…
Starlette BadHost Header Injection Data Exposure (CVE-2026-48710) | MSSP Advisory
CVE-2026-48710 affects Starlette, a lightweight ASGI framework used in Python web applications inclu…
Daemon Tools Lite Embedded Malicious Code Vulnerability (CVE-2026-8398) | MSSP Advisory
CISA flagged CVE-2026-8398 affecting Daemon Tools Lite for embedded malicious code with high impact…
TanStack Malicious npm Package Supply Chain Compromise (CVE-2026-45321) | MSSP Advisory
CISA flagged CVE-2026-45321 affecting TanStack, where attackers published malicious versions contain…
Nx Console Embedded Malicious Code Supply Chain (CVE-2026-48027) | MSSP Advisory
CISA flagged CVE-2026-48027 in Nx Console, a developer tool extension that shipped with embedded mal…
Uruguay Government Data Breach Cybercriminal Campaign | MSSP Advisory
Cybercriminals leaked 5.8 million records of Uruguayan citizens after targeting government agencies…
Starlette Host Header Authentication Bypass (CVE-2026-48710) | MSSP Advisory
CVE-2026-48710 affects the Starlette Python framework that powers FastAPI applications, allowing att…
Gitea Private Container Images Unauthenticated Access | MSSP Advisory
A vulnerability in Gitea allows unauthenticated attackers to pull private container images from self…
LiteSpeed cPanel Plugin Remote Code Execution | MSSP Advisory
CISA issued an emergency directive giving federal agencies four days to patch a critical vulnerabili…
Glassworm Botnet Targets Developer Workstations Supply Chain | MSSP Advisory
CrowdStrike disrupted the Glassworm botnet that specifically targeted software developers and develo…
ShinyHunters Charter Communications Data Breach Extortion | MSSP Advisory
ShinyHunters breached Charter Communications and claims to have stolen 40 million customer records,…
Microsoft SharePoint Out-of-Band Unauthorized Access | MSSP Advisory
Microsoft released an emergency out-of-band patch for SharePoint, addressing an unspecified vulnerab…
Megalodon Malware Infects GitHub Repositories Supply Chain | MSSP Advisory
A campaign called Megalodon injected malicious code into over 5,500 GitHub repositories in six hours…
LiteSpeed cPanel Plugin Privilege Escalation to Root (CVE-2026-48172) | MSSP Advisory
CISA has added CVE-2026-48172 to the Known Exploited Vulnerabilities catalog, targeting LiteSpeed cP…
Ghost CMS Unauthenticated Admin API Key Theft | MSSP Advisory
CVE-2026-26980 targets Ghost CMS versions 3.24.0 through 6.19.0, allowing unauthenticated attackers…
Lazarus Group RemotePE Malware Financial Targeting | MSSP Advisory
North Korea's Lazarus Group deployed new RemotePE malware targeting financial institutions through a…
Japanese LMS Zero-Day Cobalt Strike Deployment (CVE-2026-5426) | MSSP Advisory
CVE-2026-5426 exposes a zero-day vulnerability in a Japanese Learning Management System where hard-c…
Universal Robots PolyScope OS Remote Command Execution | MSSP Advisory
Universal Robots PolyScope OS contains a critical vulnerability CVE-2026-8153 with a CVSS score of 9…
ABB B&R Automation Runtime DoS Vulnerability SDM | MSSP Advisory
ABB B&R Automation Runtime versions below 6.3 and Q4.93 contain a denial of service vulnerability in…
Trend Micro Apex One Path Traversal RCE (CVE-2026-34926) | MSSP Advisory
A zero-day path traversal vulnerability in Trend Micro Apex One (CVE-2026-34926) is being actively e…
Microsoft SharePoint Deserialization RCE | MSSP Advisory
Microsoft patched CVE-2026-45659, a remote code execution vulnerability in SharePoint with a CVSS sc…
7-Eleven Customer Data Breach ShinyHunters | MSSP Advisory
ShinyHunters extortion gang breached 7-Eleven systems in April, stealing personal information of ove…
KnowledgeDeliver LMS Hard-Coded Keys RCE | MSSP Advisory
A high-severity vulnerability in Digital Knowledge KnowledgeDeliver Learning Management System was e…
Dutch Authorities Seize Bulletproof Hosting Infrastructure | MSSP Advisory
Dutch authorities seized 800 servers and arrested two hosting company owners who provided infrastruc…
Kali365 Phishing Service Microsoft 365 Account Compromise | MSSP Advisory
The FBI has identified Kali365, a phishing-as-a-service platform that compromises Microsoft 365 acco…
Ghost CMS SQL Injection ClickFix Campaign | MSSP Advisory
Threat actors are exploiting CVE-2026-26980, a critical SQL injection vulnerability in Ghost CMS wit…
Lazarus RemotePE Memory-Only RAT Campaign | MSSP Advisory
The North Korea-linked Lazarus Group is deploying RemotePE, a memory-only RAT that operates entirely…
Kali365 Phishing Kit Hijacks Microsoft 365 OAuth Tokens | MSSP Advisory
The FBI has issued a warning about Kali365, a phishing-as-a-service platform that steals Microsoft 3…
TrapDoor Supply Chain Attack Credential Stealer | MSSP Advisory
A coordinated supply chain attack called TrapDoor compromised 34 malicious packages across npm, PyPI…
Laravel Lang Packages Hijacked Credential-Stealing Malware | MSSP Advisory
Attackers hijacked the Laravel Lang localization packages on Packagist by exploiting GitHub version…
Packagist Supply Chain Attack Eight Composer Packages | MSSP Advisory
Eight Composer packages on Packagist were compromised with malicious code that downloads and execute…
Drupal Core SQL Injection Active Exploitation | MSSP Advisory
CISA added CVE-2026-9082, a critical SQL injection vulnerability in Drupal Core, to its Known Exploi…
LiteSpeed cPanel Plugin Privilege Escalation RCE Root (CVE-2026-48172) | MSSP Advisory
CVE-2026-48172 in LiteSpeed User-End cPanel Plugin allows any cPanel user to execute arbitrary scrip…
Ubiquiti UniFi OS Critical Vulnerabilities Path Traversal RCE | MSSP Advisory
Ubiquiti patched three critical vulnerabilities in UniFi OS that allow attackers to make unauthorize…
Middle East C2 Infrastructure Campaign Identified | MSSP Advisory
Hunt.io identified over 1,350 command and control servers across 98 providers in 14 Middle Eastern c…
Cisco Secure Workload API Remote Code Execution | MSSP Advisory
Cisco patched a critical severity 10.0 CVSS flaw in Secure Workload APIs that allows remote code exe…
Drupal Core SQL Injection RCE Privilege Escalation (CVE-2026-9082) | MSSP Advisory
CISA added CVE-2026-9082 to the Known Exploited Vulnerabilities catalog, flagging a SQL injection fl…
Drupal SQL Injection RCE Active Exploitation | MSSP Advisory
Drupal released emergency patches for a highly critical SQL injection vulnerability in Drupal core t…
Trend Micro Apex One Unauthenticated RCE | MSSP Advisory
Trend Micro patched CVE-2024-36308, a critical zero-day vulnerability in Apex One that allows unauth…
Microsoft Defender Malware Engine Privilege Escalation LPE | MSSP Advisory
Microsoft patched two zero-day vulnerabilities in Microsoft Defender's malware protection engine tha…
Cisco Secure Workload API Authentication Bypass | MSSP Advisory
A critical vulnerability in Cisco Secure Workload allows attackers to obtain site admin privileges o…
ChromaDB Race Condition Remote Code Execution | MSSP Advisory
ChromaDB versions 1.0.0 through 1.5.8 contain a critical race condition vulnerability (CVE-2026-4582…
Trend Micro Apex One Directory Traversal RCE (CVE-2026-34926) | MSSP Advisory
CISA added CVE-2026-34926 to the Known Exploited Vulnerabilities catalog targeting Trend Micro Apex…
Langflow CORS Validation Authentication Token Theft (CVE-2025-34291) | MSSP Advisory
CISA flagged CVE-2025-34291 in Langflow, a visual AI workflow platform, where broken CORS validation…
SonicWall Gen6 SSL-VPN MFA Bypass | MSSP Advisory
Attackers are exploiting CVE-2024-12802 to bypass multi-factor authentication on SonicWall Gen6 SSL-…
Showboat Linux Malware SOCKS5 Proxy Backdoor | MSSP Advisory
Showboat is a modular Linux malware framework targeting telecommunications providers in the Middle E…
First VPN Service Seized Law Enforcement Takedown | MSSP Advisory
Law enforcement seized First VPN, a criminal-focused VPN service that provided anonymity for ransomw…
Cisco Secure Workload Authentication Bypass Site Admin | MSSP Advisory
Cisco patched a maximum-severity authentication bypass flaw (CVE-2024-20441) in Secure Workload that…
Chinese Hackers Showboat Linux Malware Telco Campaign | MSSP Advisory
Chinese threat actors deployed new Linux malware called Showboat and Windows backdoor JFMBackdoor ag…
TeamTCP Nx Console Extension Supply Chain Attack | MSSP Advisory
GitHub and Grafana Labs suffered breaches after the TeamTCP threat group compromised the Nx Console…
Linux Kernel ptrace Memory Disclosure SSH Keys | MSSP Advisory
Qualys discovered a nine-year-old vulnerability in the Linux kernel's ptrace system call that allows…
Microsoft Defender Malware Protection Engine Privilege Escalation (CVE-2026-41091) | MSSP Advisory
Two Microsoft Defender vulnerabilities are being exploited in the wild, with CISA adding them to its…
Windows Defender Privilege Escalation Active Exploitation | MSSP Advisory
Microsoft disclosed two actively exploited vulnerabilities in Windows Defender, including CVE-2026-4…
Windows Defender Zero-Day Detection Bypass | MSSP Advisory
Microsoft patched two zero-day vulnerabilities in Windows Defender that attackers actively exploited…
Drupal Core SQL Injection PostgreSQL RCE | MSSP Advisory
Drupal released an emergency patch for CVE-2026-9082, a maximum severity SQL injection vulnerability…
WantToCry Ransomware SMB Brute Force Remote Encryption | MSSP Advisory
WantToCry ransomware exploits exposed SMB ports through brute force attacks to establish lateral net…
SonicWall Gen6 SSL-VPN MFA Bypass Incomplete Patching | MSSP Advisory
Threat actors are brute-forcing VPN credentials and bypassing multi-factor authentication on SonicWa…
Trump Mobile Customer Data Leak | MSSP Advisory
Trump Mobile T1 phone customers are experiencing data leaks exposing personal information including…
ChromaDB Unauthenticated Remote Code Execution | MSSP Advisory
ChromaDB, a vector database with nearly 14 million monthly PyPI downloads, contains a max-severity v…
Microsoft Defender Denial of Service Vulnerability (CVE-2026-45498) | MSSP Advisory
CISA added CVE-2026-45498 to the Known Exploited Vulnerabilities catalog, flagging an unspecified Mi…
Microsoft Defender Privilege Escalation LPE (CVE-2026-41091) | MSSP Advisory
CISA added CVE-2026-41091 to the Known Exploited Vulnerabilities catalog, flagging a privilege escal…
Adobe Acrobat Reader Heap Buffer Overflow RCE (CVE-2009-3459) | MSSP Advisory
CISA added a 15-year-old Adobe Acrobat vulnerability to the Known Exploited Vulnerabilities catalog,…
GitHub Internal Repositories Breached via Malicious Extension | MSSP Advisory
GitHub confirmed attackers exfiltrated code from approximately 3,800 internal repositories through a…
Premium Deception Android Malware Campaign Subscription Fraud | MSSP Advisory
The Premium Deception campaign distributed over 250 malicious Android apps through official app stor…
Drupal Core Critical Vulnerability High Exploitation Risk | MSSP Advisory
Drupal released emergency security patches today for a critical vulnerability affecting Drupal 10.2…
SHub Reaper macOS Infostealer Impersonation Attack Chain | MSSP Advisory
SHub Reaper is a new macOS infostealer variant that impersonates Apple, Google, and Microsoft in a s…
Microsoft Disrupts Malware Code-Signing Service Ransomware Groups | MSSP Advisory
Microsoft disrupted a malware code-signing service that provided digitally signed certificates to ra…
Windows Zero-Day Vulnerabilities YellowKey GreenPlasma MiniPlasma | MSSP Advisory
Security researcher Simone Margaritelli disclosed three new Windows zero-day vulnerabilities named Y…
CISA Exposed Credentials in Public GitHub Repository | MSSP Advisory
CISA exposed sensitive credentials and secrets in a GitHub repository labeled 'Private-CISA' that ha…
SHub Reaper Stealer macOS Backdoor Campaign | MSSP Advisory
SHub Reaper stealer targets macOS systems through fake WeChat and Miro installer packages that spoof…
Microsoft Self-Service Password Reset Azure Account Takeover | MSSP Advisory
A threat actor is exploiting Microsoft's legitimate Self-Service Password Reset feature to gain unau…
Reaper macOS Infostealer Multi-Stage Attack Chain | MSSP Advisory
A new macOS infostealer called Reaper impersonates Apple, Microsoft, and Google to trick users into…
Microsoft Exchange OWA XSS Zero-Day Active (CVE-2026-42897) | MSSP Advisory
CVE-2026-42897 is a cross-site scripting vulnerability in Microsoft Exchange that allows attackers t…
F5 NGINX Critical Vulnerability Active Exploitation | MSSP Advisory
F5 NGINX has a critical vulnerability under active exploitation that affects one-third of all websit…
NGINX Rift Critical RCE Exploitation Active | MSSP Advisory
Attackers are actively exploiting CVE-2026-42945, a critical NGINX vulnerability dubbed NGINX Rift t…
MiniPlasma Windows Privilege Escalation Zero-Day | MSSP Advisory
A Windows privilege escalation zero-day called MiniPlasma allows attackers to gain SYSTEM privileges…
Windows Kernel MiniPlasma Privilege Escalation LPE | MSSP Advisory
Security researcher released working exploit code for MiniPlasma, a Windows privilege escalation zer…
Tycoon2FA Microsoft 365 Account Hijacking Device-Code Phishing | MSSP Advisory
The Tycoon2FA phishing kit now supports device code phishing attacks targeting Microsoft 365 account…
NGINX Heap Buffer Overflow RCE Exploited | MSSP Advisory
CVE-2026-42945 is a heap buffer overflow in NGINX's rewrite module affecting versions 0.6.27 through…
Grafana GitHub Token Compromise Codebase Download | MSSP Advisory
An unauthorized party compromised Grafana's GitHub environment using a stolen token, downloaded the…
Funnel Builder Plugin WooCommerce Checkout Skimming | MSSP Advisory
The Funnel Builder plugin for WordPress contains a critical security vulnerability being actively ex…
Microsoft Exchange Server OWA XSS Active Exploitation | MSSP Advisory
Microsoft disclosed a zero-day cross-site scripting vulnerability in Exchange Server with CVSS 8.1 t…
Cisco Catalyst SD-WAN Controller Authentication Bypass | MSSP Advisory
CISA added a maximum-severity authentication bypass vulnerability in Cisco Catalyst SD-WAN Controlle…
node-ipc npm package supply chain attack malware | MSSP Advisory
Attackers compromised the node-ipc npm package by registering an expired domain to hijack a maintain…
American Lending Center Ransomware Data Breach | MSSP Advisory
American Lending Center suffered a ransomware attack where threat actors compromised their internal…
WordPress Funnel Builder Payment Data Theft Vulnerability | MSSP Advisory
A vulnerability in the WordPress Funnel Builder plugin, installed on over 40,000 websites, allows un…
Microsoft Exchange Windows 11 Zero-Day Exploits Pwn2Own | MSSP Advisory
Pwn2Own Berlin 2026 competitors exploited 15 zero-day vulnerabilities across Windows 11, Microsoft E…
Microsoft Exchange Server Outlook Web Access XSS (CVE-2026-42897) | MSSP Advisory
CISA added CVE-2026-42897 to the Known Exploited Vulnerabilities catalog targeting Microsoft Exchang…
Cisco SD-WAN Controller Authentication Bypass Active Exploit (CVE-2026-20182) | MSSP Advisory
Cisco patched CVE-2026-20182, an authentication bypass vulnerability in Catalyst SD-WAN Controller a…
Cisco Catalyst SD-WAN Controller Authentication Bypass RCE | MSSP Advisory
Cisco disclosed a maximum severity authentication bypass vulnerability in Catalyst SD-WAN Controller…
Cisco Catalyst SD-WAN Controller Auth Bypass Admin Access (CVE-2026-20182) | MSSP Advisory
Cisco released patches for CVE-2026-20182, a maximum severity authentication bypass vulnerability in…
Cisco Catalyst SD-WAN Controller Authentication Bypass (CVE-2026-20182) | MSSP Advisory
CISA flagged CVE-2026-20182, an authentication bypass vulnerability in Cisco Catalyst SD-WAN control…
Tokee Messaging App MongoDB Data Exposure | MSSP Advisory
Security researchers found an unsecured MongoDB database belonging to Deucetek, developer of the Tok…
Microsoft BitLocker Recovery Mode Issue | MSSP Advisory
Microsoft acknowledged a BitLocker recovery issue on April 14 affecting Windows 10, Windows 11, and…
Exim Mail Server User-After-Free RCE | MSSP Advisory
A user-after-free vulnerability in Exim mail servers allows remote code execution during TLS shutdow…
FlowerStorm Phishing Gang KrakVM Obfuscation Campaign | MSSP Advisory
FlowerStorm phishing-as-a-service operation has adopted KrakVM, an open-source JavaScript virtual ma…
KongTuke Initial Access Brokers Microsoft Teams Social Engineering | MSSP Advisory
KongTuke initial access brokers now use Microsoft Teams to conduct social engineering attacks, gaini…
Windows BitLocker Bypass and CTFMON Privilege Escalation | MSSP Advisory
Two new Windows zero-day vulnerabilities allow BitLocker drive encryption bypass (YellowKey) and pri…
Community Bank Customer Data Exposure Unauthorized AI Software | MSSP Advisory
Community Bank disclosed that customer data was exposed through unauthorized AI software deployed in…
Škoda Auto Customer Data Breach | MSSP Advisory
Škoda Auto suffered a data breach through an unspecified vulnerability in their e-commerce portal so…
West Pharmaceutical Services Ransomware Attack | MSSP Advisory
West Pharmaceutical Services, a pharmaceutical packaging manufacturer, suffered a ransomware attack…
Windows Critical RCE Flaws Discovered by AI System | MSSP Advisory
Microsoft's new AI system MDASH discovered 16 Windows vulnerabilities including four critical remote…
Nitrogen Ransomware Foxconn Manufacturing Facilities Attack | MSSP Advisory
Foxconn confirmed a cyberattack by the Nitrogen ransomware gang that disrupted operations at multipl…
Microsoft DNS Server Unauthenticated RCE | MSSP Advisory
Microsoft patched 138 vulnerabilities this month with 30 rated Critical, including remote code execu…
Microsoft Windows Networking Authentication RCE Flaws | MSSP Advisory
Microsoft's new AI-powered security system MDASH discovered 16 vulnerabilities in Windows networking…
Fake OpenAI Repository Hugging Face Infostealer Malware | MSSP Advisory
A fake OpenAI repository on Hugging Face distributed information-stealing malware disguised as a pri…
cPanel WHM Privilege Escalation Code Execution Vulnerabilities | MSSP Advisory
cPanel and Web Host Manager released patches for three vulnerabilities including CVE-2026-29201 with…
Linux Dirty Frag Zero-Day LPE | MSSP Advisory
A Linux zero-day vulnerability dubbed 'Dirty Frag' enables local privilege escalation to root across…
Microsoft Edge Plaintext Password Storage Memory Exposure | MSSP Advisory
Microsoft Edge converts all saved passwords to plaintext in memory immediately upon browser startup,…
TCLBANKER Banking Trojan Targets Financial Platforms | MSSP Advisory
TCLBANKER is a Brazilian banking trojan targeting 59 financial platforms including banks, fintech se…
BerriAI LiteLLM SQL Injection Database Exposure (CVE-2026-42208) | MSSP Advisory
CISA flags a SQL injection vulnerability in BerriAI LiteLLM that exposes proxy databases and managed…
Linux Kernel Dirty Frag Local Privilege Escalation | MSSP Advisory
Dirty Frag is a Linux local privilege escalation vulnerability in kernel networking components inclu…
RansomHouse Trellix Source Code Breach | MSSP Advisory
RansomHouse compromised Trellix source code repositories and leaked proof of the breach through samp…
Quasar Linux RAT Developer Credential Theft | MSSP Advisory
A new Linux RAT called Quasar Linux RAT (QLNX) specifically targets developer systems to steal crede…
Zara Customer Data Breach | MSSP Advisory
Hackers breached Zara's customer database and stole personal information from 197,000 customers incl…
xrdp Pre-Authentication Remote Code Execution | MSSP Advisory
CVE-2025-68670 is a pre-authentication remote code execution vulnerability in xrdp server, discovere…
Canvas Learning Management System Breach Ransom Demand | MSSP Advisory
A cybercrime group breached Canvas, the dominant education technology platform, and defaced login pa…
TCLBanker Trojan Self-Spreads WhatsApp Outlook Banking Theft | MSSP Advisory
TCLBanker trojan spreads through compromised MSI installers disguised as legitimate Logitech AI Prom…
Ivanti EPMM Improper Input Validation RCE (CVE-2026-6973) | MSSP Advisory
CISA added CVE-2026-6973 to the Known Exploited Vulnerabilities catalog, flagging an Ivanti EPMM fla…
Beagle Backdoor Distributed via Fake Claude Site | MSSP Advisory
A fake Claude AI website is distributing the Beagle backdoor through DonutLoader malware using DLL s…
Beagle Windows Malware Fake Claude Website | MSSP Advisory
Threat actors created a fake Claude AI website that distributes Beagle malware through a fraudulent…
Palo Alto Networks PAN-OS Authentication Bypass Zero-Day | MSSP Advisory
Palo Alto Networks confirmed that suspected state-sponsored attackers exploited CVE-2024-0012, a cri…
Vercel Platform Abused for Phishing Campaigns | MSSP Advisory
Attackers are exploiting Vercel's serverless hosting platform to launch phishing campaigns, taking a…
Palo Alto Networks PAN-OS Critical RCE Exploited | MSSP Advisory
Palo Alto Networks disclosed a critical vulnerability in PAN-OS with active exploitation, scoring CV…
Instructure Canvas LMS Data Breach | MSSP Advisory
The ShinyHunters group breached Instructure, the company behind Canvas LMS that serves educational i…
GoDaddy ManageWP Login Phishing Campaign | MSSP Advisory
Attackers are buying Google Ads that appear in search results for ManageWP login queries, redirectin…
Palo Alto Networks PAN-OS Captive Portal RCE (CVE-2026-0300) | MSSP Advisory
CISA flagged CVE-2026-0300, a root-level code execution vulnerability in Palo Alto PAN-OS captive po…
ClickFix macOS Infostealer Campaign Fake Utilities | MSSP Advisory
Threat actors are running a ClickFix campaign targeting macOS users with fake utility repair prompts…
MuddyWater Microsoft Teams Credential Theft Campaign | MSSP Advisory
MuddyWater, an Iranian state-sponsored group, executed a false flag ransomware attack using Microsof…
Weaver E-cology Critical Vulnerability Active Exploitation | MSSP Advisory
Attackers are actively exploiting a critical vulnerability in Weaver E-cology, a Chinese workflow an…
Ivanti Endpoint Manager Mobile Unauthenticated RCE (CVE-2026-1340) | MSSP Advisory
CISA added CVE-2026-1340 to the Known Exploited Vulnerabilities catalog targeting Ivanti Endpoint Ma…
Fortinet FortiClient EMS SQL Injection RCE (CVE-2026-21643) | MSSP Advisory
CISA flagged a SQL injection vulnerability in Fortinet FortiClient EMS that allows unauthenticated r…
Microsoft SharePoint Server Input Validation Spoofing (CVE-2026-32201) | MSSP Advisory
CISA added CVE-2026-32201 to the Known Exploited Vulnerabilities catalog, flagging a Microsoft Share…
Apache ActiveMQ Code Injection RCE (CVE-2026-34197) | MSSP Advisory
CISA added Apache ActiveMQ CVE-2026-34197 to the Known Exploited Vulnerabilities catalog, flagging a…
JetBrains TeamCity Path Traversal Auth Bypass (CVE-2024-27199) | MSSP Advisory
CISA flagged CVE-2024-27199, a path traversal vulnerability in JetBrains TeamCity that allows limite…
Quest KACE Systems Management Appliance Authentication Bypass (CVE-2025-32975) | MSSP Advisory
CISA added CVE-2025-32975 to the Known Exploited Vulnerabilities catalog, targeting Quest KACE Syste…
Cisco Catalyst SD-WAN Manager Password Storage Privilege Escalation (CVE-2026-20128) | MSSP Advisory
CISA added CVE-2026-20128 to the KEV catalog, exposing a password storage flaw in Cisco Catalyst SD-…
Synacor Zimbra Collaboration Suite XSS (CVE-2025-48700) | MSSP Advisory
CISA added a cross-site scripting vulnerability in Zimbra Collaboration Suite to their Known Exploit…
Kentico Xperience Path Traversal Arbitrary File Upload (CVE-2025-2749) | MSSP Advisory
CISA added CVE-2025-2749 to its Known Exploited Vulnerabilities catalog, flagging a path traversal f…
Cisco Catalyst SD-WAN Manager Sensitive Information Disclosure (CVE-2026-20133) | MSSP Advisory
CISA flagged CVE-2026-20133 affecting Cisco Catalyst SD-WAN Manager for exposing sensitive informati…
Cisco Catalyst SD-WAN Manager Privilege Escalation File Upload (CVE-2026-20122) | MSSP Advisory
CISA added CVE-2026-20122 to the Known Exploited Vulnerabilities catalog targeting Cisco Catalyst SD…
Microsoft Defender Privilege Escalation Access Control (CVE-2026-33825) | MSSP Advisory
CISA flagged CVE-2026-33825 as a Known Exploited Vulnerability affecting Microsoft Defender, allowin…
Marimo Pre-Authorization Remote Code Execution (CVE-2026-39987) | MSSP Advisory
CISA flagged CVE-2026-39987 in Marimo, a pre-authorization remote code execution flaw that gives att…
SimpleHelp Missing Authorization Privilege Escalation (CVE-2024-57726) | MSSP Advisory
CISA flagged CVE-2024-57726 in SimpleHelp remote access software, where low-privilege technicians ca…
SimpleHelp Path Traversal Remote Code Execution (CVE-2024-57728) | MSSP Advisory
CISA added CVE-2024-57728 to the Known Exploited Vulnerabilities catalog targeting SimpleHelp remote…
Samsung MagicINFO 9 Server Path Traversal File Write (CVE-2024-7399) | MSSP Advisory
CISA added CVE-2024-7399 to its Known Exploited Vulnerabilities catalog, targeting Samsung MagicINFO…
D-Link DIR-823X Command Injection RCE (CVE-2025-29635) | MSSP Advisory
CISA added CVE-2025-29635 to the Known Exploited Vulnerabilities catalog, flagging a command injecti…
Trellix Source Code Breach Supply Chain | MSSP Advisory
Trellix suffered a source code breach that potentially exposed detection logic and security controls…
Weaver E-cology Critical RCE Actively Exploited | MSSP Advisory
A critical vulnerability in Weaver E-cology enterprise workflow platform has a CVSS score of 9.8 and…
Progress MOVEit Automation Arbitrary Code Execution | MSSP Advisory
Progress Software disclosed CVE-2026-4670, a critical vulnerability affecting multiple versions of M…
Apache HTTP Server HTTP/2 Double Free DoS RCE | MSSP Advisory
Apache HTTP Server contains a critical double free vulnerability in HTTP/2 protocol handling (CVE-20…
UAT-8302 Targets Government Entities Across Regions | MSSP Advisory
China-linked APT group UAT-8302 actively targets government entities across South America and southe…
Ollama Windows Auto-Updater Persistent RCE | MSSP Advisory
Two vulnerabilities in Ollama's Windows auto-updater allow attackers to plant persistent executables…
Venomous#Helper RMM Phishing Campaign | MSSP Advisory
Attackers are impersonating the US Social Security Administration through fake emails to distribute…
Vimeo Data Breach Exposes 119000 Users | MSSP Advisory
ShinyHunters breached Vimeo in April and stole personal data from 119,000 users including names, ema…
MetInfo CMS Code Injection RCE Exploitation | MSSP Advisory
Threat actors are actively exploiting CVE-2026-29014, a critical code injection vulnerability in Met…
Phishing Campaign Fake Compliance Notices Credential Harvesting | MSSP Advisory
A phishing campaign targeted over 35,000 users across 13,000 organizations using fake workplace comp…
CloudZ RAT Abuses Microsoft Phone Link SMS Interception | MSSP Advisory
The CloudZ remote access trojan with its Pheno plugin exploits Microsoft Phone Link to intercept SMS…
CloudZ RAT Pheno Plugin SMS OTP Theft | MSSP Advisory
CloudZ RAT now includes a plugin called Pheno that hijacks Microsoft Phone Link connections to inter…
Weaver E-cology Unauthenticated RCE Debug API | MSSP Advisory
Weaver E-cology enterprise automation platform contains a critical unauthenticated remote code execu…
Microsoft Defender DigiCert Certificate False Positive Detection | MSSP Advisory
Microsoft Defender flagged legitimate DigiCert root certificates as Trojan:Win32/Cerdigent.A!dha mal…
Weaver E-cology Critical RCE Actively Exploited | MSSP Advisory
Hackers have been actively exploiting CVE-2026-22679, a critical vulnerability in Weaver E-cology of…
cPanel Authentication Bypass Exploitation Active | MSSP Advisory
Multiple proof-of-concept exploits have emerged targeting a critical authentication bypass vulnerabi…
Progress MOVEit Automation Authentication Bypass | MSSP Advisory
Progress Software patched two security flaws in MOVEit Automation including a critical authenticatio…
Progress MOVEit Automation Auth Bypass RCE | MSSP Advisory
Progress Software patched a critical authentication bypass vulnerability (CVE-2026-4670) and privile…
Progress MOVEit Automation Authentication Bypass RCE | MSSP Advisory
Progress Software disclosed a critical authentication bypass vulnerability (CVE-2024-7954) in MOVEit…
cPanel Vulnerability Exploited Against Government MSP Networks | MSSP Advisory
An unknown threat actor exploited the recently disclosed cPanel vulnerability to target government e…
France Titres Government Data Breach | MSSP Advisory
A 15-year-old hacker breached France Titres, the French government agency that issues official docum…
Microsoft Windows Network Spoofing Protection Mechanism Failure (CVE-2026-32202) | MSSP Advisory
CVE-2026-32202 exposes a protection mechanism failure in Microsoft Windows Shell that enables unauth…
ConnectWise ScreenConnect Path Traversal RCE (CVE-2024-1708) | MSSP Advisory
ConnectWise ScreenConnect contains a critical path traversal vulnerability tracked as CVE-2024-1708…
cPanel Critical Flaw Sorry Ransomware Mass Exploitation | MSSP Advisory
A critical cPanel vulnerability CVE-2024-41940 is being mass-exploited to deploy Sorry ransomware ac…
SonicWall Firewall Vulnerabilities Exploited by Ransomware | MSSP Advisory
SonicWall released firmware updates addressing three CVEs that security experts warn ransomware acto…
The Com Threat Groups Target Critical Infrastructure Data Theft | MSSP Advisory
Two threat groups linked to The Com are targeting critical infrastructure through voice-phishing and…
Microsoft Remote Desktop Security Warning Display Bug | MSSP Advisory
Microsoft patched a bug where Remote Desktop security warnings displayed incorrectly when opening .r…
BlackCat Ransomware Insider Attack Campaign | MSSP Advisory
Two cybersecurity professionals received four-year prison sentences for deploying BlackCat ransomwar…
Linux Kernel Nine-Year-Old Zero-Day Flaw | MSSP Advisory
A nine-year-old zero-day vulnerability in the Linux kernel was discovered by Theori security researc…
Vercel OAuth Integration Breach Third-Party Compromise | MSSP Advisory
Vercel suffered a breach through a compromised third-party OAuth integration that provided attackers…
cPanel WHM Authentication Bypass Zero-Day | MSSP Advisory
CVE-2026-41940 is a critical authentication bypass vulnerability in cPanel and WHM that bypasses all…
GitHub Git Push Remote Code Execution | MSSP Advisory
A critical RCE vulnerability in GitHub allowed authenticated attackers to execute arbitrary code on…
Google Gemini CLI RCE in CI/CD Pipelines | MSSP Advisory
Google patched a CVSS 10 remote code execution vulnerability in Gemini CLI, specifically the '@googl…
Windows RPC Privilege Escalation PhantomRPC Technique | MSSP Advisory
Kaspersky researchers discovered PhantomRPC, a Windows RPC architecture vulnerability that allows at…
cPanel WHM Authentication Bypass Admin Access | MSSP Advisory
A critical authentication bypass vulnerability exists in cPanel & WHM (CVE-2026-41940) that allows a…
cPanel Authentication Bypass Zero-Day Exploited | MSSP Advisory
CVE-2026-41940 is a critical authentication bypass vulnerability in cPanel that attackers have been…
TrueConf Zero-Day Exploitation Southeast Asian Governments (CVE-2026-3502) | MSSP Advisory
Threat actors exploited a zero-day vulnerability CVE-2026-3502 in TrueConf video conferencing softwa…
Microsoft Defender Three Zero-Days Privilege Escalation | MSSP Advisory
Threat actors are actively exploiting three zero-day vulnerabilities in Microsoft Defender codenamed…
Citrix NetScaler Unauthenticated Remote Code Execution (CVE-2026-3055) | MSSP Advisory
Attackers are actively exploiting CVE-2026-3055, a critical vulnerability in Citrix NetScaler applia…
Citrix NetScaler Critical RCE Exploited (CVE-2026-3055) | MSSP Advisory
CVE-2026-3055 is a critical vulnerability in Citrix NetScaler appliances that attackers are actively…
Every advisory becomes a finished, branded client communication under your name.