CYBER Threat Intelligence Reports
LATEST CTIs
Elementor Pro CVE-2026-32475 Enables Unauthenticated File Upload and RCE
A critical vulnerability in the widely deployed Elementor Pro plugin for WordPress can allow unauthenticated attackers to bypass file-type restrictions, upload executable PHP files to…
Read more >

Windows IKE CVE-2026-33824 Exploited for Pre-Auth Remote Code Execution
A critical remote code execution vulnerability in Microsoft Windows Internet Key Exchange (IKE) is now being actively exploited. Tracked as CVE-2026-33824, the vulnerability is a…
Read more >

VMware vCenter CVE-2026-59310 Actively Exploited for RCE and Persistent Access
Threat actors are actively exploiting CVE-2026-59310, a critical unauthenticated remote code execution vulnerability affecting VMware vCenter Server, with incident responders identifying compromises across dozens of…
Read more >

ShieldBreak: Microsoft Defender 0-Day Leads to SYSTEM Privileges
A security researcher has released ShieldBreak, a new proof-of-concept exploit targeting Microsoft Defender that can elevate a low-privileged Windows user to NT AUTHORITY\SYSTEM on fully…
Read more >

Microsoft SharePoint CVE-2026-55040 PoC Weaponized in Active Attacks
Attackers have begun using publicly available exploit code for CVE-2026-55040, a critical Microsoft SharePoint authentication bypass vulnerability that allows an unauthenticated remote attacker to impersonate…
Read more >

WordPress CVE-2026-64638 Pre-Auth XSS Can Be Chained to RCE (XSS2Shell)
WordPress has released security updates to address a high-severity vulnerability that allows unauthenticated attackers to execute JavaScript in the context of a WordPress website and,…
Read more >

