Malware 2026-09-12
Malware & phishing activity digest — 2026-09-12
343 new malicious URLs and indicators were observed from public threat-intelligence feeds (abuse.ch URLHaus).
Automated daily updates on newly exploited vulnerabilities, ransomware activity and malware indicators — from public sources.
Malware 2026-09-12
343 new malicious URLs and indicators were observed from public threat-intelligence feeds (abuse.ch URLHaus).
Ransomware 2026-09-12
12 organizations were newly listed on ransomware leak sites, with the most active groups being nightspire, Panzer, safepay. Figures are aggregated from public l
Vulnerability 2026-09-11
CVE-2026-85706 (GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability) affecting GitLab was added to CISA's Known Exploited Vulnerabiliti
Vulnerability 2026-09-11
CVE-2026-42018 (JFrog Artifactory Improper Authentication Vulnerability) affecting JFrog was added to CISA's Known Exploited Vulnerabilities catalog, indicating
Vulnerability 2026-09-11
CVE-2026-42016 (JFrog Artifactory Incorrect Authorization Vulnerability) affecting JFrog was added to CISA's Known Exploited Vulnerabilities catalog, indicating
Vulnerability 2026-09-11
CVE-2026-84869 (ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability) affecting ConnectWise was added to CISA's Known
Malware 2026-09-11
435 new malicious URLs and indicators were observed from public threat-intelligence feeds (abuse.ch URLHaus).
Ransomware 2026-09-11
24 organizations were newly listed on ransomware leak sites, with the most active groups being akira, Wallstreet, play. Figures are aggregated from public leak-
Vulnerability 2026-09-10
CVE-2026-67277 (MikroTik RouterOS Missing Authentication for Critical Function Vulnerability) affecting MikroTik was added to CISA's Known Exploited Vulnerabili
Vulnerability 2026-09-10
CVE-2026-86060 (MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability) affecting MikroTik was added to CISA's Known Exploi
Malware 2026-09-10
500 new malicious URLs and indicators were observed from public threat-intelligence feeds (abuse.ch URLHaus).
Ransomware 2026-09-10
26 organizations were newly listed on ransomware leak sites, with the most active groups being AuditTeam, Storm, emperador. Figures are aggregated from public l
Vulnerability 2026-09-09
CVE-2026-20079 (Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability) affecting Cisco was added to CISA's Kno
Vulnerability 2026-09-09
CVE-2026-87491 (Google Chromium V8 Out of Bounds Write Vulnerability) affecting Google was added to CISA's Known Exploited Vulnerabilities catalog, indicating a
Vulnerability 2026-09-09
CVE-2025-25249 (Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability) affecting Fortinet was added to CISA's Known Exploited Vulnerabilities cata
Vulnerability 2026-09-09
CVE-2026-19490 (Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability) affecting Citrix was added to CISA's Known Exploited Vu
Malware 2026-09-09
373 new malicious URLs and indicators were observed from public threat-intelligence feeds (abuse.ch URLHaus).
Ransomware 2026-09-09
29 organizations were newly listed on ransomware leak sites, with the most active groups being safepay, AuditTeam, akira. Figures are aggregated from public lea
Vulnerability 2026-09-08
CVE-2026-85880 (Microsoft Windows Heap-Based Buffer Overflow Vulnerability) affecting Microsoft was added to CISA's Known Exploited Vulnerabilities catalog, ind
Vulnerability 2026-09-08
CVE-2026-86218 (N-able N-central Static Code Injection Vulnerability) affecting N-able was added to CISA's Known Exploited Vulnerabilities catalog, indicating a
Vulnerability 2026-09-08
CVE-2026-81963 (Microsoft Windows Link Following Vulnerability) affecting Microsoft was added to CISA's Known Exploited Vulnerabilities catalog, indicating acti
Vulnerability 2026-09-08
CVE-2026-75650 (Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability) affecting Adobe was added to CIS
Malware 2026-09-08
500 new malicious URLs and indicators were observed from public threat-intelligence feeds (abuse.ch URLHaus).
Ransomware 2026-09-08
48 organizations were newly listed on ransomware leak sites, with the most active groups being thegentlemen, direwolf, metaencryptor. Figures are aggregated fro
Malware 2026-09-07
324 new malicious URLs and indicators were observed from public threat-intelligence feeds (abuse.ch URLHaus).
Ransomware 2026-09-07
10 organizations were newly listed on ransomware leak sites, with the most active groups being dragonforce, Panzer, direwolf. Figures are aggregated from public
Malware 2026-09-06
274 new malicious URLs and indicators were observed from public threat-intelligence feeds (abuse.ch URLHaus).
Ransomware 2026-09-06
21 organizations were newly listed on ransomware leak sites, with the most active groups being qilin, thegentlemen, pear. Figures are aggregated from public lea
Malware 2026-09-05
392 new malicious URLs and indicators were observed from public threat-intelligence feeds (abuse.ch URLHaus).
Ransomware 2026-09-05
24 organizations were newly listed on ransomware leak sites, with the most active groups being qilin, lockbit5, Vexy Ransomware. Figures are aggregated from pub
Vulnerability 2026-09-04
CVE-2026-85046 (Google Chromium V8 Type Confusion Vulnerability) affecting Google was added to CISA's Known Exploited Vulnerabilities catalog, indicating active
Malware 2026-09-04
319 new malicious URLs and indicators were observed from public threat-intelligence feeds (abuse.ch URLHaus).
Ransomware 2026-09-04
28 organizations were newly listed on ransomware leak sites, with the most active groups being settra, Storm, SilentRansomGroup. Figures are aggregated from pub
Malware 2026-09-03
498 new malicious URLs and indicators were observed from public threat-intelligence feeds (abuse.ch URLHaus).
Ransomware 2026-09-03
27 organizations were newly listed on ransomware leak sites, with the most active groups being incransom, akira, SilentRansomGroup. Figures are aggregated from
Vulnerability 2026-09-02
CVE-2026-83549 (SonicWall SMA1000 Appliances OS Command Injection Vulnerability) affecting SonicWall was added to CISA's Known Exploited Vulnerabilities catalog
Vulnerability 2026-09-02
CVE-2026-83548 (SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability) affecting SonicWall was added to CISA's Known Exploited Vulnerabilities
Vulnerability 2026-09-02
CVE-2026-9586 (Sangoma Switchvox SQL Injection Vulnerability) affecting Sangoma was added to CISA's Known Exploited Vulnerabilities catalog, indicating active e
Vulnerability 2026-09-02
CVE-2026-82329 (JFrog Artifactory Improper Authentication Vulnerability) affecting JFrog was added to CISA's Known Exploited Vulnerabilities catalog, indicating
Vulnerability 2026-09-02
CVE-2026-49869 (Kestra OSS OS Command Injection Vulnerability) affecting Kestra was added to CISA's Known Exploited Vulnerabilities catalog, indicating active e
Vulnerability 2026-09-02
CVE-2026-48710 (Kludex Starlette HTTP Request/Response Smuggling Vulnerability) affecting Kludex was added to CISA's Known Exploited Vulnerabilities catalog, in
Vulnerability 2026-09-02
CVE-2026-59822 (BerriAI LiteLLM Improper Authentication Vulnerability) affecting BerriAI was added to CISA's Known Exploited Vulnerabilities catalog, indicating
Malware 2026-09-02
439 new malicious URLs and indicators were observed from public threat-intelligence feeds (abuse.ch URLHaus).
Ransomware 2026-09-02
38 organizations were newly listed on ransomware leak sites, with the most active groups being krybit, thegentlemen, akira. Figures are aggregated from public l
Malware 2026-09-01
428 new malicious URLs and indicators were observed from public threat-intelligence feeds (abuse.ch URLHaus).
Ransomware 2026-09-01
52 organizations were newly listed on ransomware leak sites, with the most active groups being settra, BrainCipher, lockbit5. Figures are aggregated from public
Vulnerability 2026-08-31
CVE-2026-81578 (PaperCut NG/MF Missing Authentication for Critical Function Vulnerability) affecting PaperCut was added to CISA's Known Exploited Vulnerabilitie
Vulnerability 2026-08-31
CVE-2026-82078 (PaperCut NG/MF Unsafe Reflection Vulnerability) affecting PaperCut was added to CISA's Known Exploited Vulnerabilities catalog, indicating activ
Malware 2026-08-31
374 new malicious URLs and indicators were observed from public threat-intelligence feeds (abuse.ch URLHaus).
Ransomware 2026-08-31
45 organizations were newly listed on ransomware leak sites, with the most active groups being ZaWoo, thegentlemen, qilin. Figures are aggregated from public le
Malware 2026-08-30
359 new malicious URLs and indicators were observed from public threat-intelligence feeds (abuse.ch URLHaus).
Ransomware 2026-08-30
23 organizations were newly listed on ransomware leak sites, with the most active groups being qilin, iah6477, incransom. Figures are aggregated from public lea
Malware 2026-08-29
422 new malicious URLs and indicators were observed from public threat-intelligence feeds (abuse.ch URLHaus).
Ransomware 2026-08-29
30 organizations were newly listed on ransomware leak sites, with the most active groups being qilin, global, akira. Figures are aggregated from public leak-sit
Malware 2026-08-28
450 new malicious URLs and indicators were observed from public threat-intelligence feeds (abuse.ch URLHaus).
Ransomware 2026-08-28
40 organizations were newly listed on ransomware leak sites, with the most active groups being qilin, Storm, medusalocker. Figures are aggregated from public le
Vulnerability 2026-08-27
CVE-2026-66384 (JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability) affecting JFrog was added to CISA's Known Exploited
Vulnerability 2026-08-27
CVE-2026-53362 (Linux Kernel Unspecified Vulnerability) affecting Linux was added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitat
Vulnerability 2026-08-27
CVE-2023-49105 (ownCloud Improper Authentication Vulnerability) affecting ownCloud was added to CISA's Known Exploited Vulnerabilities catalog, indicating activ
Malware 2026-08-27
452 new malicious URLs and indicators were observed from public threat-intelligence feeds (abuse.ch URLHaus).
Run a free security report for any domain.
Get your free report