Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
7 / 7 results
criticalbug_reportVulnerabilityVeeam ONE authentication bypass requires immediate patching
Veeam ONE backup management platform - specific affected versions not disclosed in available information. Authentication mechanism vulnerable to bypass allowing unauthorized access.
highperson_alertThreat ActorSandworm deploys trojanized WireGuard VPN via fake IT job offers
Sandworm (also tracked as APT44, UAC-0145 sub-cluster) is a Russian-linked advanced persistent threat group notorious for targeting critical infrastructure and government entities, particularly in Ukraine and other countries.
criticalbug_reportVulnerabilityN-able N-central exploited; attackers persist via Cloudflare tunnels
N-able N-central RMM product, all versions prior to 2026.3.1.7. CVE-2026-18577 (CVSS 8.2) is an incomplete fix for CVE-2026-18556 (CVSS 8.2), both enabling authentication bypass and account takeover. On-premise deployments are affected.
criticalbug_reportVulnerabilityN-able N-central auth bypass exploited; incomplete patch requires upgrade
N-able N-central builds prior to 2026.3.1.7. All versions before the August 2 emergency hotfix are vulnerable. Affects MSPs and IT teams using N-central for remote monitoring and management of customer endpoints.
criticalbug_reportVulnerabilityBeyondTrust Remote Support/PRA critical auth bypass (CVE-2026-40138)
BeyondTrust Remote Support and Privileged Remote Access (PRA) products. Specific affected versions not provided in available data. CVE-2026-40138 is a pre-authentication vulnerability with CVSS 9.2.
highperson_alertThreat ActorIran-linked MOIS group deploys Cavern C2 framework against Israel
An Iranian threat actor affiliated with Iran's Ministry of Intelligence and Security (MOIS), tracked by Check Point Research. The group operates in support of Iranian state intelligence objectives, focusing on espionage operations against adversary n…
highbug_reportVulnerabilitySimpleHelp OIDC flaw allows unauthenticated account creation
SimpleHelp remote management software servers with OpenID Connect (OIDC) authentication enabled. Specific affected versions not disclosed. All SimpleHelp deployments using OIDC for technician authentication are potentially vulnerable.