MediumJune 19, 2026

NGINX RCE, Windows crypto-stealer, Salesforce breaches, INC ransomware surge

F5 patched critical NGINX RCE (CVE-2026-42530). Microsoft disclosed active Windows clipboard-stealing malware spreading via USB worms since Feb 2026. INC ransomware claims 830+ victims; Salesforce data stolen through Klue OAuth breach by Icarus group.

Vuln ExploitRansomwareTechnologyFinance
MediumJune 18, 2026

Microsoft Defender zero-day, FortiBleed exposes 73k devices, GitHub worm spreads

Microsoft Defender privilege-escalation zero-day CVE-2026-50656 (patch pending). FortiBleed leaks credentials for 73,932 Fortinet devices; attackers actively harvesting access across 200 countries. GitHub supply-chain worm exploiting dismissed design flaws compromises hundreds of packages.

Zero-DayCredential TheftTechnology
HighJune 17, 2026

Fortinet actively exploited; Rokarolla targets 217 banking apps; Google Vertex AI flaw

Fortinet FortiSandbox faces active in-the-wild exploitation of three CVEs. Android banking trojan Rokarolla targets 217 financial apps with 137 remote commands. Google Vertex AI SDK bucket-squatting flaw enables unauthorized model hijacking.

Vuln ExploitMobile MalwareFinanceTechnology
HighJune 16, 2026

China espionage dwell 1 year, Microsoft 200 patches, Cisco SD-WAN actively exploited

China-linked UNC6508 maintained undetected access to North American medical, military, and academic research networks for over a year via compromised REDCap servers. Microsoft issued record 200 patches with evidence of active exploitation. Cisco SD-WAN vManage CVE-2026-20262 exploited in the wild.

APTVuln ExploitDefenseTechnology
MediumJune 15, 2026

Critical: Splunk RCE, Arch Linux supply-chain hijack, phishing-as-a-service dismantled

FBI dismantles Outsider Enterprise phishing network; Arch Linux AUR compromised with 400+ malicious packages deploying credential stealer and rootkit; Splunk Enterprise CVSS-9.8 RCE patched.

Supply ChainVuln ExploitTechnologyFinance
MediumJune 14, 2026

Splunk RCE, Arch Linux supply-chain hijack, Velvet Ant decade-long backdoor

Splunk Enterprise CVE-2026-20253 (CVSS 9.8) enables unauthenticated RCE; 400+ Arch Linux AUR packages hijacked with infostealer/rootkit; China-linked Velvet Ant maintained decade-long PAM/OpenSSH backdoor.

Vuln ExploitAPTTechnologyGovernment
MediumJune 13, 2026

Arch Linux supply-chain worm, Velvet Ant backdoor, Gemini phishing-as-a-service

Over 400 Arch Linux AUR packages compromised with credential stealer and eBPF rootkit; China-linked Velvet Ant backdoored Linux authentication for decade; Google sues Chinese phishing-as-a-service using Gemini AI.

Supply ChainMalwareTechnology
HighJune 12, 2026

Critical: Oracle PeopleSoft Zero-Day, Windows BitLocker Bypass, Gentlemen Ransomware

Oracle PeopleSoft CVE-2026-35273 actively exploited by ShinyHunters targeting universities; Windows BitLocker bypassed via XML files; The Gentlemen ransomware claims 478 victims with worm-like spreading capability.

Zero-DayRansomwareEducationTechnology
HighJune 11, 2026

Langflow RCE exploited, JDY botnet expands U.S. military targeting, npm security hardened

CVE-2026-5027 in Langflow actively exploited for unauthenticated RCE; JDY botnet expands to 1,500 devices targeting U.S. military networks. CISA mandates 3-day patching for critical flaws.

Vuln ExploitAPTTechnologyDefense
HighJune 10, 2026

Microsoft 200-patch record, Veeam RCE critical, GitHub supply-chain worm ongoing

Microsoft released record 200 Patch Tuesday fixes including critical flaws; Veeam Backup & Replication RCE (CVE-2026-44963, CVSS 9.4) requires immediate patching; 73 GitHub repos remain compromised as Miasma supply-chain attack investigation continues.

Vuln ExploitSupply ChainTechnologyGovernment
HighJune 9, 2026

Critical Check Point VPN and Linux kernel flaws under active exploitation; NSO spyware defies court order

Check Point VPN zero-day (CVSS 9.3) actively exploited since early May; Linux kernel use-after-free now has public exploit; NSO Group continues WhatsApp phishing despite federal court injunction.

Zero-DayVuln ExploitTechnologyFinance
MediumJune 8, 2026

Miasma worm hits Microsoft GitHub, SolarWinds Serv-U actively exploited, WordPress Everest Forms RCE

Miasma worm compromises 73 Microsoft GitHub repositories; SolarWinds Serv-U DoS flaw confirmed actively exploited; WordPress Everest Forms Pro critical RCE under active attack; Meta AI bot abused to reset Instagram accounts.

Supply ChainVuln ExploitTechnologyGovernment
MediumJune 7, 2026

Miasma worm hits Microsoft GitHub; SolarWinds actively exploited; Chrome 429 patches

Microsoft GitHub hit by Miasma self-replicating worm across 73 repositories; SolarWinds Serv-U actively exploited for DoS; Chrome 149 patches record 429 vulnerabilities.

Supply ChainVuln ExploitTechnologyGovernment
MediumJune 6, 2026

Critical Exploits: npm Supply Chain, WordPress Plugin, SolarWinds, IIS Attacks

IronWorm and Miasma worms actively distributed via 50+ poisoned npm packages; WordPress Everest Forms Pro (CVE-2026-3300) exploited for RCE on 4,000 sites; SolarWinds Serv-U flaw weaponized for DoS; 900+ US fuel tank gauges exposed and under attack.

Supply ChainVuln ExploitTechnologyEnergy
MediumJune 5, 2026

Cisco Unified CM RCE, Claude GitHub Action Hijack, AI Agent Exploits

Cisco patches critical Unified CM RCE with public PoC; Claude Code GitHub Action flaw enables repository hijack via GitHub issues; AI agents exploited in defense networks; Hola Browser compromised with cryptominer.

Vuln ExploitSupply ChainTechnologyGovernment
LowJune 4, 2026

Google Gemini prompt injection, Microsoft 365 token theft, Redis RCE patched

Google Gemini voice assistant hijackable via poisoned notifications; Microsoft 365 Android apps leak tokens; Redis RCE (CVE-2026-23479) patched; critical fuel tank systems under active attack.

Mobile MalwareCredential TheftTechnologyEnergy
HighJune 3, 2026

Android, WinRAR, WordPress Kirki: Three critical zero-days under active exploitation

Google Android zero-day (CVE-2025-48595) actively exploited; Gamaredon APT weaponizing WinRAR; WordPress Kirki plugin hijacking admin accounts. CISA adds Oracle WebLogic to KEV catalog.

Zero-DayVuln ExploitTechnologyGovernment
MediumJune 2, 2026

Red Hat npm, WordPress, Instagram under active attack; critical Windows vulnerability patching urgent

Red Hat npm packages compromised with Miasma credential-stealing worm; WordPress RCE via CVE-2026-8732; Instagram accounts hijacked via Meta AI bot exploit. Patch WP Maps Pro immediately, rotate developer credentials, enable MFA.

Supply ChainVuln ExploitTechnologyGovernment
HighJune 1, 2026

PAN-OS GlobalProtect actively exploited; Russian infrastructure dismantled; Linux kernel flaw

Palo Alto PAN-OS GlobalProtect authentication bypass (CVE-2026-0257) actively exploited; Dutch authorities arrest two hosting operators supporting Russian cyberattacks; Linux kernel CIFSwitch flaw allows privilege escalation.

Vuln ExploitAPTGovernmentTechnology
HighMay 31, 2026

Active exploits: Palo Alto GlobalProtect, CISA credential leak, Linux kernel RCE

Palo Alto PAN-OS GlobalProtect flaw (CVE-2026-0257) under active exploitation; CISA contractor exposed AWS GovCloud keys on GitHub; Linux kernel CIFSwitch privilege escalation disclosed.

Vuln ExploitCredential TheftTechnologyGovernment
HighMay 30, 2026

ChatGPT malware abuse, Marimo CVE-2026-39987 LLM exploitation, Russian infrastructure arrests

ChatGPT share links abused for malware delivery; Marimo CVE-2026-39987 exploited with LLM agents for post-compromise activity; Dutch authorities seize 800 Russian-linked servers and arrest hosting executives.

PhishingZero-DayTechnologyFinance
HighMay 29, 2026

FortiClient EMS, GitHub secrets, CISA breach: critical exploitation ongoing

FortiClient EMS actively exploited to deploy credential stealer; CISA contractor leaked AWS GovCloud keys on GitHub; BTMOB Android RAT spreading via phishing with builder interface.

Vuln ExploitCredential TheftGovernmentTechnology
HighMay 28, 2026

FortiClient EMS, Gogs RCE actively exploited; CISA GitHub leak exposes AWS keys

FortiClient EMS and Gogs RCE vulnerabilities actively exploited in the wild. CISA contractor exposed AWS GovCloud credentials on GitHub. FIFA World Cup fraud campaigns register 4,300+ malicious domains.

Vuln ExploitCredential TheftGovernmentTechnology
LowMay 27, 2026

Critical RCEs and credential leaks: Microsoft SharePoint, CISA AWS exposure, MuddyWater espionage

Microsoft patched SharePoint RCE (CVE-2026-45659); CISA contractor exposed AWS GovCloud keys on GitHub; MuddyWater targeted nine organizations across four continents using DLL side-loading.

Zero-DayVuln ExploitTechnologyGovernment
MediumMay 26, 2026

Ghost CMS, Microsoft 365 phishing, and supply-chain malware in active exploitation

Ghost CMS SQL injection actively exploited across 700+ sites; Microsoft 365 phishing service Kali365 bypasses MFA; multi-ecosystem supply-chain attacks deliver credential stealers.

Vuln ExploitSupply ChainTechnologyFinance
HighMay 25, 2026

GitHub npm supply chain attacks, LiteSpeed RCE, CISA credentials exposed

Supply-chain attacks hit npm and Composer ecosystems; LiteSpeed cPanel CVE-2026-48172 actively exploited; CISA contractor exposed AWS GovCloud credentials on GitHub.

Supply ChainVuln ExploitTechnologyGovernment
HighMay 24, 2026

GitHub, npm, and Drupal under attack: supply-chain threats and active CVE exploitation

Multiple supply-chain attacks targeting Laravel-Lang and Packagist packages, active exploitation of Drupal CVE-2026-9082, and critical CISA AWS credential leak on GitHub.

Supply ChainVuln ExploitTechnologyEducation
HighMay 23, 2026

GitHub supply-chain attack, Drupal RCE, AWS GovCloud credential leak

GitHub campaign injects malware into 5,561 repos; Drupal SQL injection actively exploited; CISA contractor exposes AWS GovCloud credentials.

Supply ChainVuln ExploitTechnologyGovernment
CriticalMay 22, 2026

Critical RCEs: Microsoft Defender, Linux kernel, Cisco Workload; Showboat targets telcos

Microsoft Defender vulnerabilities actively exploited; 9-year-old Linux kernel flaw enables root execution; Cisco Workload max-severity RCE patched; Showboat malware targets telcos across Middle East and Central Asia.

Zero-DayVuln ExploitTelecomGovernment
MediumMay 21, 2026

GitHub breach, SonicWall VPN MFA bypass, Drupal critical flaw demand patching

GitHub suffered breach of 3,800+ internal repos via TeamPCP. Microsoft disrupted malware-signing operation. SonicWall VPN and Drupal require urgent patching.

Data BreachAPTTechnologyFinance
LowMay 20, 2026

Microsoft, Drupal, Linux critical patches; OAuth phishing bypasses MFA on 340+ orgs

Microsoft disrupted Fox Tempest malware-signing service; Drupal critical patches May 20; OAuth phishing bypasses MFA on 340+ Microsoft 365 organizations. CVE-2026-31635 Linux PoC public.

Vuln ExploitPhishingTechnologyGovernment
MediumMay 19, 2026

Microsoft Exchange zero-day in active use; npm worm clones spread after source leak

Microsoft Exchange zero-day under active exploitation with no patch available. Shai-Hulud worm source code leaked, spawning clones targeting npm developers. INTERPOL Operation Ramz arrested 201 cybercriminals across MENA region.

Zero-DaySupply ChainTechnologyEducation
HighMay 18, 2026

Zero-days exploited: NGINX, MS Exchange, Cisco SD-WAN; TanStack hit

Critical zero-days in NGINX, Microsoft Exchange, and Cisco SD-WAN actively exploited in the wild. TanStack supply chain attack compromises OpenAI and AI companies. Immediate patching required.

Zero-DayVuln ExploitTechnologyGovernment
HighMay 17, 2026

Critical RCEs exploited: Cisco SD-WAN, Exchange, Funnel Builder

Critical vulnerabilities in Cisco SD-WAN (CVSS 10.0), Microsoft Exchange, and Funnel Builder WordPress plugin under active exploitation. Supply chain attacks compromise npm packages. Immediate patching required.

Zero-DayVuln ExploitTechnologyGovernment
HighMay 16, 2026

MS Exchange zero-day exploited; npm hits OpenAI; Turla evolves Kazuar

Critical Microsoft Exchange zero-day exploited in wild; npm supply chain attacks compromise OpenAI; Turla APT evolves Kazuar into P2P botnet; WordPress plugins actively harvesting payment cards.

Zero-DaySupply ChainTechnologyGovernment
HighMay 15, 2026

Cisco SD-WAN zero-day exploited; TanStack supply-chain hits OpenAI

Critical Cisco SD-WAN zero-day exploited in the wild; supply chain attacks compromise TanStack and node-ipc; state APTs target government; education platform disrupted by extortion.

Zero-DayVuln ExploitTechnologyGovernment
MediumMay 14, 2026

BitLocker zero-day PoCs public; Exchange APT; Foxconn breached

Critical BitLocker zero-days with public PoCs, Microsoft Exchange APT exploitation, Canvas ransomware attack on education sector, and Foxconn manufacturing compromise create immediate operational risks across multiple industries.

Zero-DayVuln ExploitTechnologyEnergy
MediumMay 13, 2026

npm/PyPI supply-chain; Canvas ransomware; Microsoft 137 patches

Critical supply-chain attacks via compromised npm/PyPI packages, Canvas ransomware disrupting education nationwide, and massive vulnerability patches (Microsoft 137, Adobe 52, Exim critical) require immediate response.

Supply ChainRansomwareTechnologyEducation
HighMay 12, 2026

Checkmarx Jenkins compromise; AI-generated zero-day 2FA bypass

Critical supply chain compromise of Checkmarx Jenkins plugin, first AI-generated zero-day 2FA bypass exploit, and active Canvas education platform extortion campaign require immediate response.

Supply ChainZero-DayTechnologyEducation
LowMay 11, 2026

Canvas ransomware hits universities; Ollama zero-day on 300k servers

Canvas ransomware disrupts universities nationwide; Ollama zero-day affects 300k+ servers; TCLBANKER targets financial platforms; critical infrastructure breached; supply-chain compromises detected.

RansomwareZero-DayEducationTechnology
LowMay 10, 2026

Canvas extortion attack; JDownloader, Hugging Face & Trellix hit

Canvas learning platform compromised in extortion attack affecting hundreds of schools; supply-chain attacks hit JDownloader, Hugging Face, and Trellix; banking trojan TCLBANKER targets 59 financial platforms; critical ICS/OT breaches at water treatment plants.

RansomwareSupply ChainEducationFinance
MediumMay 9, 2026

TCLBANKER trojan; Canvas breach hits education; Ivanti zero-day

Critical threats including TCLBANKER banking trojan, Canvas platform breach disrupting nationwide education, and active Ivanti zero-day exploitation require immediate response across financial, education, and government sectors.

MalwareRansomwareFinanceEducation
HighMay 8, 2026

Palo Alto & Ivanti EPMM RCE exploited; PCPJack worm hits cloud

Critical vulnerabilities in Palo Alto Networks and Ivanti EPMM under active exploitation. PCPJack credential stealer worm targeting cloud infrastructure. Russian state actors harvesting Office tokens via router compromise.

Zero-DayVuln ExploitTechnologyFinance
HighMay 7, 2026

vm2, Palo Alto, DAEMON Tools exploited; Iran APT false-flag operations

Critical vulnerabilities in vm2, Palo Alto firewalls, and DAEMON Tools combined with Russian military intelligence token harvesting and Iranian APT false-flag campaigns demand immediate patching and investigation.

Zero-DayVuln ExploitTechnologyGovernment
MediumMay 6, 2026

Apache HTTP/2 & MetInfo exploited; DAEMON Tools supply-chain hit

Critical vulnerabilities in Apache HTTP/2 and MetInfo CMS, supply-chain compromise of DAEMON Tools, and persistent OAuth backdoors require immediate response.

Vuln ExploitSupply ChainTechnologyGovernment
HighMay 5, 2026

cPanel & MOVEit exploited; RMM phishing hits 80+ organizations

Critical vulnerabilities in cPanel and MOVEit, widespread RMM-based phishing compromising 80+ organizations, and supply-chain malware in PyTorch Lightning demand immediate patching and credential rotation.

PhishingVuln ExploitTechnologyFinance
HighMay 4, 2026

Linux root vulnerability in KEV; cPanel mass-exploitation continues

Critical Linux root access vulnerability added to CISA KEV with active exploitation confirmed. Multiple critical threats including cPanel mass-exploitation, source code breaches, and state-sponsored APT campaigns.

Zero-DayVuln ExploitTechnologyGovernment
HighMay 3, 2026

cPanel RCE ransomware; 30K Facebook hacked; Trellix source leaked

Critical cPanel RCE exploited for ransomware; Russian military harvesting Office tokens; 30K Facebook accounts compromised; Trellix source code breached; automated Azure OAuth attacks.

Vuln ExploitRansomwareTechnologyGovernment
HighMay 2, 2026

cPanel auth bypass; state token harvesting; SaaS extortion attacks

Critical vulnerabilities, state-sponsored token harvesting, large-scale phishing operations, and coordinated SaaS extortion attacks demand immediate defensive action across government and technology sectors.

PhishingCredential TheftGovernmentTechnology
HighMay 1, 2026

PyTorch Lightning & SAP supply-chain; AI cuts attack time to 24h

Critical supply chain attacks compromise PyTorch Lightning and SAP packages; Russian state-sponsored actors steal Office tokens; AI-accelerated exploitation shrinks time-to-compromise to 24 hours.

Supply ChainZero-DayTechnologyGovernment
MediumApril 30, 2026

SAP npm compromise; cPanel auth bypass; DPRK AI-assisted malware

Critical supply-chain attacks on SAP npm packages and North Korean AI-assisted malware, combined with cPanel authentication bypass and state-sponsored credential harvesting, create immediate existential threats to enterprise infrastructure and critical systems.

Supply ChainCredential TheftTechnologyFinance
HighApril 29, 2026

GitHub, Hugging Face RCE; VECT 2.0 ransomware; BlueNoroff deepfakes

Critical RCE vulnerabilities in GitHub and Hugging Face, destructive VECT 2.0 ransomware, Russian token harvesting, and BlueNoroff deepfake attacks demand immediate defensive action.

Zero-DayVuln ExploitTechnologyFinance
MediumApril 28, 2026

Developer platform supply-chain attacks; Windows RPC zero-day

Critical supply chain attacks on developer platforms, Russian state-sponsored token theft via router exploits, and unpatched Windows RPC privilege escalation demand immediate defensive action.

Supply ChainMalwareTechnologyGovernment
MediumApril 27, 2026

FIRESTARTER federal Cisco persistence; Chinese APT GopherWhisper

Critical threats include FIRESTARTER backdoor persistence on federal Cisco devices, Russian military token theft via router exploitation, Chinese APT GopherWhisper attacks, and four actively exploited CISA KEV vulnerabilities with May 2026 federal patching deadline.

APTMalwareGovernmentDefense
MediumApril 26, 2026

FIRESTARTER on federal Cisco gear; 4 critical CVEs added to CISA KEV

FIRESTARTER backdoor persists on federal Cisco infrastructure despite patches; Russian state actors harvesting Office tokens via router exploits; four critical CVEs added to CISA KEV with May 2026 deadline; APT campaigns targeting U.S. defense sector; AI-powered phishing escalates to personalized 1-to-1 attacks.

APTMalwareGovernmentDefense
MediumApril 25, 2026

FIRESTARTER persists on federal Cisco; APT spear-phishes NASA

FIRESTARTER backdoor persists on federal Cisco infrastructure despite patches. Russian military intelligence harvesting Office tokens via router exploits. Chinese APT targeting NASA and defense sector with spear-phishing. AI-powered phishing and FakeWallet credential theft escalating.

MalwareAPTGovernmentDefense
MediumApril 24, 2026

Bitwarden CLI & Checkmarx compromised; Russian Office 365 token theft

Critical supply-chain compromises affecting Bitwarden CLI and Checkmarx tools; Russian state actors harvesting Office 365 tokens; AI-powered attacks outpacing human response capabilities.

Supply ChainCredential TheftTechnologyGovernment
HighApril 23, 2026

Docker & npm supply-chain hits; Lotus Wiper on Venezuelan energy

Critical supply chain attacks via malicious Docker images and npm worms, state-sponsored credential theft campaigns targeting Microsoft Office, and destructive Lotus Wiper malware deployed against Venezuelan energy infrastructure require immediate response across all organizations.

Supply ChainMalwareTechnologyEnergy
HighApril 22, 2026

Russian APT token theft; Gentlemen ransomware claims 1,570 victims

Russian state-backed APT harvesting Microsoft tokens, 1,570+ Gentlemen ransomware victims, critical SD-WAN and RMM exploits, Windows Defender flaws—urgent patching required across infrastructure.

APTCredential TheftTechnologyGovernment
MediumApril 21, 2026

SGLang & Anthropic MCP RCE; APT campaigns hit OT/healthcare auth

Critical RCE vulnerabilities in AI infrastructure (SGLang, Anthropic MCP) combined with state-sponsored APT campaigns targeting authentication systems and OT/healthcare infrastructure demand immediate patching and access controls.

Zero-DayVuln ExploitTechnologyGovernment
MediumApril 20, 2026

Defender zero-day; protobuf.js RCE; APT28 hits Ukrainian government

Critical Microsoft Defender zero-days actively exploited, 68% of cloud breaches from unmanaged service accounts, Russian state actors harvesting Office tokens, protobuf.js RCE with public exploit, APT28 targeting Ukrainian government.

Zero-DayCredential TheftTechnologyGovernment
MediumApril 19, 2026

Microsoft Defender zero-days; 68% cloud breaches from ghost identities

Critical Microsoft Defender zero-days under active exploitation, 68% of cloud breaches from unmanaged service accounts, and Russian state-sponsored token harvesting campaigns demand immediate action.

Zero-DayCredential TheftTechnologyGovernment
HighApril 18, 2026

Microsoft Defender & ActiveMQ zero-days under exploitation

Critical zero-day exploits in Microsoft Defender and Apache ActiveMQ, Russian state-sponsored token harvesting, and sophisticated ransomware evasion techniques pose immediate threats requiring emergency patching and threat hunting.

Zero-DayVuln ExploitTechnologyFinance
HighApril 17, 2026

Apache ActiveMQ exploited; Defender zero-day; ZionSiphon hits water

Apache ActiveMQ actively exploited; Microsoft Defender zero-day disclosed; Russian state actors harvesting Office 365 tokens; ZionSiphon targets water infrastructure.

Zero-DayVuln ExploitTechnologyGovernment
MediumApril 16, 2026

nginx-ui auth bypass exploited; SharePoint zero-day in 169 patches

Critical nginx-ui authentication bypass actively exploited; Microsoft releases 169 patches including SharePoint zero-day; n8n webhooks weaponized for phishing; WordPress plugins and signed software compromised.

Vuln ExploitZero-DayTechnologyGovernment
MediumApril 15, 2026

Microsoft zero-days exploited; Mirax RAT hits 220K; PHP supply chain

Critical Microsoft zero-days under exploitation, Russian state hackers harvesting Office tokens via routers, and 220K users compromised by Mirax RAT. Supply-chain risks escalating across PHP and development ecosystems.

Zero-DayVuln ExploitTechnologyGovernment
MediumApril 14, 2026

Adobe zero-day exploited; APT37 attacks; AI-powered exploitation

Critical Adobe zero-day under active exploitation, Russian state-sponsored token harvesting, and APT37 social engineering campaigns compound with AI-powered vulnerability discovery threats.

Zero-DayAPTTechnologyGovernment
HighApril 13, 2026

Adobe Reader zero-day; CPUID STX RAT supply-chain; Iran hits 4,000 ICS

Critical Adobe Reader zero-day, CPUID supply-chain compromise distributing STX RAT, Russian APT harvesting Office tokens via router exploits, and Iranian actors targeting 4,000+ U.S. industrial control systems.

Zero-DaySupply ChainTechnologyGovernment
HighApril 12, 2026

Iran PLC attacks; Marimo RCE exploited in 10h; GlassWorm IDE infection

Critical threats span Iranian PLC targeting, Russian token harvesting, Marimo RCE exploitation within 10 hours, and GlassWorm IDE infections. Immediate patching and detection deployment required.

APTZero-DayEnergyManufacturing
HighApril 11, 2026

Marimo RCE exploited; Iran targets 4,000 US PLCs; Russian token theft

Critical exploitation of Marimo RCE, Iranian targeting of 4,000 US PLCs, and Russian token harvesting via routers demand immediate patching and access controls.

Supply ChainZero-DayTechnologyGovernment
MediumApril 10, 2026

Adobe Reader zero-day exploited; APT28 router credential theft

Critical zero-day in Adobe Reader, state-sponsored credential theft via routers, and major supply-chain compromises demand immediate action across all organizations.

Zero-DayAPTTechnologyFinance
MediumApril 9, 2026

APT28 PRISMEX on NATO; ActiveMQ 13-yr RCE; Russian router token theft

APT28 deploys PRISMEX malware targeting NATO allies; 13-year-old ActiveMQ RCE and Russian router-based token theft critical; new botnets and healthcare ransomware disruptions.

APTZero-DayGovernmentDefense
MediumApril 8, 2026

APT28 DNS hijack via routers; Iran hits PLCs; Docker RCE

Russian APT28 conducting large-scale DNS hijacking via compromised routers for token theft; Iranian hackers targeting U.S. critical infrastructure PLCs; critical Docker and Flowise vulnerabilities under active exploitation.

APTCredential TheftDefenseGovernment
HighApril 7, 2026

Iran & DPRK target Microsoft 365; GitHub C2 supply-chain attacks

State-sponsored APT campaigns targeting Microsoft 365 and supply chains escalate with GitHub C2 usage and zero-day exploits deployed within 24 hours of breach.

APTSupply ChainTechnologyGovernment
CriticalApril 6, 2026

FortiClient RCE exploited; DPRK & Chinese APTs hit EU institutions

State-sponsored DPRK and China-linked APT campaigns, critical FortiClient RCE exploit, and cascading supply chain attacks affecting European institutions and npm ecosystem.

APTZero-DayFinanceTechnology
MediumApril 5, 2026

TA416 PlugX on EU govts; UNC1069 Axios npm; device code phishing 37x

Nation-state campaigns targeting European governments and supply chain infrastructure. TA416 resumes targeting with PlugX. North Korean UNC1069 compromises Axios npm. Device code phishing surges 37x.

APTPhishingGovernmentDefense
MediumApril 4, 2026

TrueConf zero-day; TA416 hits EU govts; UNC1069 npm compromise

Critical zero-day in TrueConf, resurgent Chinese APT targeting European governments, North Korean npm supply chain compromise, and third-party vendor breaches require immediate response

Zero-DayAPTGovernmentTechnology
HighApril 3, 2026

Next.js, Cisco IMC, Progress ShareFile exploited; $280M DPRK theft

Critical vulnerabilities in Next.js, Cisco IMC, and Progress ShareFile actively exploited; $280M cryptocurrency theft attributed to North Korea; credential harvesting impacts 766 hosts

Vuln ExploitCredential TheftTechnologyFinance
HighApril 2, 2026

Chrome & TrueConf zero-days exploited; widespread malware campaigns

Critical zero-day vulnerabilities in Chrome and TrueConf under active exploitation, combined with widespread malware campaigns targeting mobile and enterprise infrastructure.

Zero-DayMalwareTechnologyGovernment
HighApril 1, 2026

TrueConf zero-day exploited; North Korea Axios npm compromise

Critical zero-day exploits in TrueConf and North Korean Axios compromise, plus wiper attacks and AI platform over-privilege vulnerabilities demand immediate response across cloud, government, and healthcare sectors.

Zero-DayAPTGovernmentTechnology
HighMarch 31, 2026

Citrix exploited; Axios npm RAT supply-chain; OpenAI data theft

Critical Citrix vulnerability actively exploited, Axios npm supply chain attack spreading RAT, OpenAI vulnerabilities enabling data theft, state-sponsored APT operations escalating against telecom and healthcare sectors

Vuln ExploitSupply ChainGovernmentFinance
CriticalMarch 30, 2026

FBI Director email breached; Citrix & F5 zero-days exploited

FBI Director's email breached by Iran-linked hackers; critical Citrix and F5 vulnerabilities under active exploitation; wiper attacks target Stryker; nation-state exploit kits leaked publicly.

APTData BreachGovernmentHealthcare
CriticalMarch 29, 2026

Iran breaches FBI Director email; Citrix & F5 zero-days unpatched

Iran-linked actors breached FBI Director Kash Patel's email and launched wiper attacks on Stryker. Critical Citrix and F5 vulnerabilities under active exploitation with no patches available.

APTData BreachGovernmentHealthcare
MediumMarch 28, 2026

Telnyx PyPI compromise; iOS exploit active; APT hits telecom

Critical supply-chain compromise of Telnyx PyPI package, active iOS exploitation, state-sponsored wiper attacks on medical device firm, and advanced APT malware targeting telecom infrastructure demand immediate response.

Supply ChainMalwareTechnologyHealthcare
HighMarch 27, 2026

Chinese APT in telecom backbone; Langflow zero-day exploited

State-sponsored Chinese APT embedded in telecom backbone, critical Langflow AI vulnerability actively exploited, wiper malware targeting Iran systems, and zero-click AI assistant vulnerabilities require immediate response.

APTZero-DayTelecomGovernment
MediumMarch 26, 2026

AI autonomous espionage; device code phishing at 340+ orgs

AI-powered autonomous cyber espionage, device code phishing at 340+ organizations, and critical infrastructure vulnerabilities require immediate defensive action across all sectors.

APTPhishingDefenseGovernment
MediumMarch 25, 2026

LiteLLM supply-chain compromise; wiper hits medical device firm

Critical supply chain attacks on LiteLLM and development tools, wiper attacks on medical device manufacturer, and RCE vulnerabilities in manufacturing systems demand immediate response.

Supply ChainRansomwareTechnologyHealthcare
MediumMarch 24, 2026

Trivy & VS Code supply-chain breach; Iran wipers hit Kubernetes

Critical supply chain attacks on Trivy scanner and VS Code, destructive Iran-linked wipers targeting Kubernetes, and phishing-as-a-service platforms resurging with 29K IRS victims. Initial access now occurs in 22 seconds.

Supply ChainMalwareTechnologyHealthcare
MediumMarch 23, 2026

Russian phishing on Signal/WhatsApp; Oracle RCE exploited

Russian intelligence conducting mass Signal/WhatsApp phishing; critical Oracle RCE vulnerability; Trivy supply-chain attack spreads CanisterWorm across 47+ npm packages; VoidStealer bypasses Chrome encryption; Iran-backed wiper attacks on medical technology.

PhishingAPTGovernmentDefense
MediumMarch 22, 2026

Oracle RCE exploited; Iran wiper hits healthcare; Trivy worm spreads

Critical Oracle RCE, Russian state-sponsored phishing, Trivy supply-chain worm, and Iran-backed healthcare wiper attacks demand immediate emergency response and patching across enterprise infrastructure.

Vuln ExploitPhishingTechnologyFinance
HighMarch 21, 2026

Oracle Identity Manager, Langflow exploited; Trivy supply-chain worm

Critical vulnerabilities in Oracle Identity Manager and Langflow actively exploited; Trivy supply chain attack escalates with CanisterWorm across 47 npm packages; Russian intelligence phishing campaigns compromise thousands.

Vuln ExploitSupply ChainTechnologyFinance
MediumMarch 20, 2026

VMware ESXi ransomware exploit; BlackSuit healthcare breach

Critical VMware ESXi vulnerability actively exploited by ransomware operators. BlackSuit group claims major U.S. healthcare breach. CISA adds 3 new CVEs. Microsoft patches Windows kernel zero-day. New PhishRelay kit enables real-time MFA bypass.

RansomwareZero-DayHealthcareFinance
🤖 Threat briefings are generated using AI-powered analysis of multiple cybersecurity sources including CISA, vendor advisories, and industry news. Always verify critical intelligence through official channels.

Evaluating security tools for your stack? Browse 59 deep-evaluated tools & head-to-head comparisons →

Never Miss a Briefing

Get the Daily Threat Briefing delivered to your inbox every morning.