← All Intelligence

Vulnerability Exploit Threat Intelligence

47 briefings0 vulnerability reports

Vulnerability exploitation is the technical mechanism behind most cyberattacks, turning software flaws into unauthorized access. defend.network tracks vulnerabilities with confirmed exploitation in the wild, proof-of-concept code releases, and CISA Known Exploited Vulnerabilities catalog additions, focusing on those that affect widely deployed enterprise software.

47
briefings
1
critical
27
high
50%
of all briefings

Threat Briefings

2026-06-21

BlueNoroff npm supply chain attack; WordPress Gravity SMTP exploited on 100k sites

North Korean-linked BlueNoroff compromised 140+ npm packages via Mastra AI. Gravity SMTP WordPress plugin (100k sites) actively exploited for API key theft. AutoJack attack chain targets Windows AI browsing agents.

2026-06-20

Apple A12/A13 unpatchable exploit; Gentlemen RaaS doubles EDR killers; Fortinet FortiBleed escalates

Apple A12/A13 SecureROM exploited with unpatchable code execution; Gentlemen RaaS expands EDR-evasion toolkit targeting 400 processes; Fortinet FortiBleed now hits 86,644 devices. Klue OAuth breach spreads Salesforce credential theft to cybersecurity vendors.

2026-06-19

NGINX RCE, Windows crypto-stealer, Salesforce breaches, INC ransomware surge

F5 patched critical NGINX RCE (CVE-2026-42530). Microsoft disclosed active Windows clipboard-stealing malware spreading via USB worms since Feb 2026. INC ransomware claims 830+ victims; Salesforce data stolen through Klue OAuth breach by Icarus group.

2026-06-17

Fortinet actively exploited; Rokarolla targets 217 banking apps; Google Vertex AI flaw

Fortinet FortiSandbox faces active in-the-wild exploitation of three CVEs. Android banking trojan Rokarolla targets 217 financial apps with 137 remote commands. Google Vertex AI SDK bucket-squatting flaw enables unauthorized model hijacking.

2026-06-16

China espionage dwell 1 year, Microsoft 200 patches, Cisco SD-WAN actively exploited

China-linked UNC6508 maintained undetected access to North American medical, military, and academic research networks for over a year via compromised REDCap servers. Microsoft issued record 200 patches with evidence of active exploitation. Cisco SD-WAN vManage CVE-2026-20262 exploited in the wild.

2026-06-15

Critical: Splunk RCE, Arch Linux supply-chain hijack, phishing-as-a-service dismantled

FBI dismantles Outsider Enterprise phishing network; Arch Linux AUR compromised with 400+ malicious packages deploying credential stealer and rootkit; Splunk Enterprise CVSS-9.8 RCE patched.

2026-06-14

Splunk RCE, Arch Linux supply-chain hijack, Velvet Ant decade-long backdoor

Splunk Enterprise CVE-2026-20253 (CVSS 9.8) enables unauthenticated RCE; 400+ Arch Linux AUR packages hijacked with infostealer/rootkit; China-linked Velvet Ant maintained decade-long PAM/OpenSSH backdoor.

2026-06-11

Langflow RCE exploited, JDY botnet expands U.S. military targeting, npm security hardened

CVE-2026-5027 in Langflow actively exploited for unauthenticated RCE; JDY botnet expands to 1,500 devices targeting U.S. military networks. CISA mandates 3-day patching for critical flaws.

2026-06-10

Microsoft 200-patch record, Veeam RCE critical, GitHub supply-chain worm ongoing

Microsoft released record 200 Patch Tuesday fixes including critical flaws; Veeam Backup & Replication RCE (CVE-2026-44963, CVSS 9.4) requires immediate patching; 73 GitHub repos remain compromised as Miasma supply-chain attack investigation continues.

2026-06-09

Critical Check Point VPN and Linux kernel flaws under active exploitation; NSO spyware defies court order

Check Point VPN zero-day (CVSS 9.3) actively exploited since early May; Linux kernel use-after-free now has public exploit; NSO Group continues WhatsApp phishing despite federal court injunction.

2026-06-08

Miasma worm hits Microsoft GitHub, SolarWinds Serv-U actively exploited, WordPress Everest Forms RCE

Miasma worm compromises 73 Microsoft GitHub repositories; SolarWinds Serv-U DoS flaw confirmed actively exploited; WordPress Everest Forms Pro critical RCE under active attack; Meta AI bot abused to reset Instagram accounts.

2026-06-07

Miasma worm hits Microsoft GitHub; SolarWinds actively exploited; Chrome 429 patches

Microsoft GitHub hit by Miasma self-replicating worm across 73 repositories; SolarWinds Serv-U actively exploited for DoS; Chrome 149 patches record 429 vulnerabilities.

2026-06-06

Critical Exploits: npm Supply Chain, WordPress Plugin, SolarWinds, IIS Attacks

IronWorm and Miasma worms actively distributed via 50+ poisoned npm packages; WordPress Everest Forms Pro (CVE-2026-3300) exploited for RCE on 4,000 sites; SolarWinds Serv-U flaw weaponized for DoS; 900+ US fuel tank gauges exposed and under attack.

2026-06-05

Cisco Unified CM RCE, Claude GitHub Action Hijack, AI Agent Exploits

Cisco patches critical Unified CM RCE with public PoC; Claude Code GitHub Action flaw enables repository hijack via GitHub issues; AI agents exploited in defense networks; Hola Browser compromised with cryptominer.

2026-06-03

Android, WinRAR, WordPress Kirki: Three critical zero-days under active exploitation

Google Android zero-day (CVE-2025-48595) actively exploited; Gamaredon APT weaponizing WinRAR; WordPress Kirki plugin hijacking admin accounts. CISA adds Oracle WebLogic to KEV catalog.

2026-06-02

Red Hat npm, WordPress, Instagram under active attack; critical Windows vulnerability patching urgent

Red Hat npm packages compromised with Miasma credential-stealing worm; WordPress RCE via CVE-2026-8732; Instagram accounts hijacked via Meta AI bot exploit. Patch WP Maps Pro immediately, rotate developer credentials, enable MFA.

2026-06-01

PAN-OS GlobalProtect actively exploited; Russian infrastructure dismantled; Linux kernel flaw

Palo Alto PAN-OS GlobalProtect authentication bypass (CVE-2026-0257) actively exploited; Dutch authorities arrest two hosting operators supporting Russian cyberattacks; Linux kernel CIFSwitch flaw allows privilege escalation.

2026-05-31

Active exploits: Palo Alto GlobalProtect, CISA credential leak, Linux kernel RCE

Palo Alto PAN-OS GlobalProtect flaw (CVE-2026-0257) under active exploitation; CISA contractor exposed AWS GovCloud keys on GitHub; Linux kernel CIFSwitch privilege escalation disclosed.

2026-05-29

FortiClient EMS, GitHub secrets, CISA breach: critical exploitation ongoing

FortiClient EMS actively exploited to deploy credential stealer; CISA contractor leaked AWS GovCloud keys on GitHub; BTMOB Android RAT spreading via phishing with builder interface.

2026-05-28

FortiClient EMS, Gogs RCE actively exploited; CISA GitHub leak exposes AWS keys

FortiClient EMS and Gogs RCE vulnerabilities actively exploited in the wild. CISA contractor exposed AWS GovCloud credentials on GitHub. FIFA World Cup fraud campaigns register 4,300+ malicious domains.

2026-05-27

Critical RCEs and credential leaks: Microsoft SharePoint, CISA AWS exposure, MuddyWater espionage

Microsoft patched SharePoint RCE (CVE-2026-45659); CISA contractor exposed AWS GovCloud keys on GitHub; MuddyWater targeted nine organizations across four continents using DLL side-loading.

2026-05-26

Ghost CMS, Microsoft 365 phishing, and supply-chain malware in active exploitation

Ghost CMS SQL injection actively exploited across 700+ sites; Microsoft 365 phishing service Kali365 bypasses MFA; multi-ecosystem supply-chain attacks deliver credential stealers.

2026-05-25

GitHub npm supply chain attacks, LiteSpeed RCE, CISA credentials exposed

Supply-chain attacks hit npm and Composer ecosystems; LiteSpeed cPanel CVE-2026-48172 actively exploited; CISA contractor exposed AWS GovCloud credentials on GitHub.

2026-05-24

GitHub, npm, and Drupal under attack: supply-chain threats and active CVE exploitation

Multiple supply-chain attacks targeting Laravel-Lang and Packagist packages, active exploitation of Drupal CVE-2026-9082, and critical CISA AWS credential leak on GitHub.

2026-05-23

GitHub supply-chain attack, Drupal RCE, AWS GovCloud credential leak

GitHub campaign injects malware into 5,561 repos; Drupal SQL injection actively exploited; CISA contractor exposes AWS GovCloud credentials.

2026-05-22

Critical RCEs: Microsoft Defender, Linux kernel, Cisco Workload; Showboat targets telcos

Microsoft Defender vulnerabilities actively exploited; 9-year-old Linux kernel flaw enables root execution; Cisco Workload max-severity RCE patched; Showboat malware targets telcos across Middle East and Central Asia.

2026-05-20

Microsoft, Drupal, Linux critical patches; OAuth phishing bypasses MFA on 340+ orgs

Microsoft disrupted Fox Tempest malware-signing service; Drupal critical patches May 20; OAuth phishing bypasses MFA on 340+ Microsoft 365 organizations. CVE-2026-31635 Linux PoC public.

2026-05-18

Zero-days exploited: NGINX, MS Exchange, Cisco SD-WAN; TanStack hit

Critical zero-days in NGINX, Microsoft Exchange, and Cisco SD-WAN actively exploited in the wild. TanStack supply chain attack compromises OpenAI and AI companies. Immediate patching required.

2026-05-17

Critical RCEs exploited: Cisco SD-WAN, Exchange, Funnel Builder

Critical vulnerabilities in Cisco SD-WAN (CVSS 10.0), Microsoft Exchange, and Funnel Builder WordPress plugin under active exploitation. Supply chain attacks compromise npm packages. Immediate patching required.

2026-05-15

Cisco SD-WAN zero-day exploited; TanStack supply-chain hits OpenAI

Critical Cisco SD-WAN zero-day exploited in the wild; supply chain attacks compromise TanStack and node-ipc; state APTs target government; education platform disrupted by extortion.

2026-05-14

BitLocker zero-day PoCs public; Exchange APT; Foxconn breached

Critical BitLocker zero-days with public PoCs, Microsoft Exchange APT exploitation, Canvas ransomware attack on education sector, and Foxconn manufacturing compromise create immediate operational risks across multiple industries.

2026-05-08

Palo Alto & Ivanti EPMM RCE exploited; PCPJack worm hits cloud

Critical vulnerabilities in Palo Alto Networks and Ivanti EPMM under active exploitation. PCPJack credential stealer worm targeting cloud infrastructure. Russian state actors harvesting Office tokens via router compromise.

2026-05-07

vm2, Palo Alto, DAEMON Tools exploited; Iran APT false-flag operations

Critical vulnerabilities in vm2, Palo Alto firewalls, and DAEMON Tools combined with Russian military intelligence token harvesting and Iranian APT false-flag campaigns demand immediate patching and investigation.

2026-05-06

Apache HTTP/2 & MetInfo exploited; DAEMON Tools supply-chain hit

Critical vulnerabilities in Apache HTTP/2 and MetInfo CMS, supply-chain compromise of DAEMON Tools, and persistent OAuth backdoors require immediate response.

2026-05-05

cPanel & MOVEit exploited; RMM phishing hits 80+ organizations

Critical vulnerabilities in cPanel and MOVEit, widespread RMM-based phishing compromising 80+ organizations, and supply-chain malware in PyTorch Lightning demand immediate patching and credential rotation.

2026-05-04

Linux root vulnerability in KEV; cPanel mass-exploitation continues

Critical Linux root access vulnerability added to CISA KEV with active exploitation confirmed. Multiple critical threats including cPanel mass-exploitation, source code breaches, and state-sponsored APT campaigns.

2026-05-03

cPanel RCE ransomware; 30K Facebook hacked; Trellix source leaked

Critical cPanel RCE exploited for ransomware; Russian military harvesting Office tokens; 30K Facebook accounts compromised; Trellix source code breached; automated Azure OAuth attacks.

2026-04-29

GitHub, Hugging Face RCE; VECT 2.0 ransomware; BlueNoroff deepfakes

Critical RCE vulnerabilities in GitHub and Hugging Face, destructive VECT 2.0 ransomware, Russian token harvesting, and BlueNoroff deepfake attacks demand immediate defensive action.

2026-04-21

SGLang & Anthropic MCP RCE; APT campaigns hit OT/healthcare auth

Critical RCE vulnerabilities in AI infrastructure (SGLang, Anthropic MCP) combined with state-sponsored APT campaigns targeting authentication systems and OT/healthcare infrastructure demand immediate patching and access controls.

2026-04-18

Microsoft Defender & ActiveMQ zero-days under exploitation

Critical zero-day exploits in Microsoft Defender and Apache ActiveMQ, Russian state-sponsored token harvesting, and sophisticated ransomware evasion techniques pose immediate threats requiring emergency patching and threat hunting.

2026-04-17

Apache ActiveMQ exploited; Defender zero-day; ZionSiphon hits water

Apache ActiveMQ actively exploited; Microsoft Defender zero-day disclosed; Russian state actors harvesting Office 365 tokens; ZionSiphon targets water infrastructure.

2026-04-16

nginx-ui auth bypass exploited; SharePoint zero-day in 169 patches

Critical nginx-ui authentication bypass actively exploited; Microsoft releases 169 patches including SharePoint zero-day; n8n webhooks weaponized for phishing; WordPress plugins and signed software compromised.

2026-04-15

Microsoft zero-days exploited; Mirax RAT hits 220K; PHP supply chain

Critical Microsoft zero-days under exploitation, Russian state hackers harvesting Office tokens via routers, and 220K users compromised by Mirax RAT. Supply-chain risks escalating across PHP and development ecosystems.

2026-04-03

Next.js, Cisco IMC, Progress ShareFile exploited; $280M DPRK theft

Critical vulnerabilities in Next.js, Cisco IMC, and Progress ShareFile actively exploited; $280M cryptocurrency theft attributed to North Korea; credential harvesting impacts 766 hosts

2026-03-31

Citrix exploited; Axios npm RAT supply-chain; OpenAI data theft

Critical Citrix vulnerability actively exploited, Axios npm supply chain attack spreading RAT, OpenAI vulnerabilities enabling data theft, state-sponsored APT operations escalating against telecom and healthcare sectors

2026-03-22

Oracle RCE exploited; Iran wiper hits healthcare; Trivy worm spreads

Critical Oracle RCE, Russian state-sponsored phishing, Trivy supply-chain worm, and Iran-backed healthcare wiper attacks demand immediate emergency response and patching across enterprise infrastructure.

2026-03-21

Oracle Identity Manager, Langflow exploited; Trivy supply-chain worm

Critical vulnerabilities in Oracle Identity Manager and Langflow actively exploited; Trivy supply chain attack escalates with CanisterWorm across 47 npm packages; Russian intelligence phishing campaigns compromise thousands.

Get the Daily Briefing in Your Inbox

Subscribe free and never miss a threat briefing.