Auto-updating • Public sources • Link-out only
Security Intel
Designed for engineers through CISOs: what is being exploited and what deserves attention. Always validate in your environment.
Feed status
CISA KEVOK
Wiz ResearchOK
AquaOK
Palo Alto Unit 42OK
SnykOK
Updated Sep 02, 2026 (auto-refresh ~15 min)
Unified feed
Take Reality Assessment →Showing 30 of 50
Palo Alto Unit 42Sep 02, 2026
Open ↗An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation
Using autonomous AI agents, an attacker breached an enterprise network in a matter of hours. Understand how to address and defend against agentic attacks. The post An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation appeared first on Unit 42.
Wiz ResearchSep 01, 2026
Open ↗Introducing Continuous Vulnerability Assessment: Real-Time Defense for the AI Threat Era
Detect exposure to new vulnerabilities the moment they are published with Wiz CVA
Palo Alto Unit 42Aug 31, 2026
Open ↗Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams
Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers. The post Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams appeared first on Unit 42.
CISA KEVAug 31, 2026High
Open ↗CVE-2026-82078 — PaperCut NG/MF
PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. This vulnerability can be chained with CVE-2026-81578.
CISA KEVAug 31, 2026High
Open ↗CVE-2026-81578 — PaperCut NG/MF
PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078.
Palo Alto Unit 42Aug 28, 2026
Open ↗Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety
New research reveals that AI safety refusal lives in a thin neural layer, highlighting the critical need for external, multi-layered security. The post Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety appeared first on Unit 42.
Wiz ResearchAug 27, 2026
Open ↗Inside 90 days of attacks on AI infrastructure
Wiz honeypots uncover active campaigns targeting LiteLLM, MCP servers, and AI frameworks through RCE, blind prompt injection, and memory credential theft.
Wiz ResearchAug 27, 2026
Open ↗From Concept to Context Engine: How Wiz Built AI-Powered Data Discovery
Inside the multi-agent pipeline and feedback loops that turned a bucket scanner into a context engine.
Wiz ResearchAug 27, 2026
Open ↗Version Control DFIR: a Cheatsheet to GitHub, GitLab, Bitbucket, and Azure DevOps
A practitioner’s guide to log visibility, incident readiness, and threat hunting across the major version control services.
CISA KEVAug 27, 2026High
Open ↗CVE-2023-49105 — ownCloud ownCloud
ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured.
CISA KEVAug 27, 2026High
Open ↗CVE-2026-53362 — Linux Kernel
Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including but not limited to Suse, Red Hat, and other products using Linux.
CISA KEVAug 27, 2026High
Open ↗CVE-2026-66384 — JFrog Artifactory
JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.
Wiz ResearchAug 26, 2026
Open ↗Democratizing FinOps with Wiz: Driving Cost Attribution with the Wiz Service Catalog
How the Wiz Cloud Cost automates cost allocation to power developer-led cost optimization and connect cost to business value.
Wiz ResearchAug 26, 2026
Open ↗The State of Cloud Risk 2026: Most Security Findings Aren’t Real Attacker Opportunities
Wiz Research telemetry reveals why the majority of high-severity findings lack a path to compromise
SnykAug 26, 2026
Open ↗Why Your AI Application Is Exposed
AI applications can pass security scans yet remain exploitable through chained attacks across models, tools, data, and business workflows. Learn how DAST, AI pentesting, and red teaming work together to expose end-to-end risk.
CISA KEVAug 26, 2026High
Open ↗CVE-2021-23758 — Ajax.NET Professional Ajax.NET Professional
Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
CISA KEVAug 26, 2026High
Open ↗CVE-2015-3246 — Red Hat Libuser
Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation.
CISA KEVAug 26, 2026High
Open ↗CVE-2015-5287 — Red Hat Automatic Bug Reporting Tool
Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
CISA KEVAug 26, 2026High
Open ↗CVE-2022-0995 — Linux Kernel
Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system.
CISA KEVAug 26, 2026High
Open ↗CVE-2026-8452 — Citrix NetScaler ADC and NetScaler Gateway
Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service.
CISA KEVAug 26, 2026High
Open ↗CVE-2019-1068 — Microsoft SQL Server
Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.
Palo Alto Unit 42Aug 25, 2026
Open ↗The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution
Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution. The post The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution appeared first on Unit 42.
CISA KEVAug 25, 2026High
Open ↗CVE-2026-60004 — Gitea Gitea
Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.
CISA KEVAug 24, 2026High
Open ↗CVE-2026-21962 — Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in accessible data.
Palo Alto Unit 42Aug 21, 2026
Open ↗Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain
Attackers are targeting CI/CD pipelines and developer tools instead of application code, requiring total SDLC visibility and strict security controls The post Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain appeared first on Unit 42.
CISA KEVAug 21, 2026High
Open ↗CVE-2026-73570 — Synacor Zimbra Collaboration Suite (ZCS)
Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
Wiz ResearchAug 20, 2026
Open ↗Rust Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns
Malicious versions of the arrayref Rust crate (and others) executed a backdoor at compile time. The campaign's infrastructure overlaps with recent DPRK supply chain attacks, including Mastra and axios.
Palo Alto Unit 42Aug 20, 2026
Open ↗Identity Abuse Through Trusted Communication Channels
Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Discover key defense strategies. The post Identity Abuse Through Trusted Communication Channels appeared first on Unit 42.
CISA KEVAug 20, 2026High
Open ↗CVE-2026-72530 — TrueConf Server
TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
CISA KEVAug 20, 2026High
Open ↗CVE-2026-72529 — TrueConf Server
TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script.
Notes
- • This page aggregates public feeds and links out; it does not scan your environment.
- • Treat items as signals: verify applicability, exposure, and exploitability before action.
- • For exec-ready prioritization, pair this with the Reality Assessment.