CYBER Threat Intelligence Reports
LATEST CTIs
VMware vCenter CVE-2026-59310 Actively Exploited for RCE and Persistent Access
Threat actors are actively exploiting CVE-2026-59310, a critical unauthenticated remote code execution vulnerability affecting VMware vCenter Server, with incident responders identifying compromises across dozens of…
Read more >

ShieldBreak: Microsoft Defender 0-Day Leads to SYSTEM Privileges
A security researcher has released ShieldBreak, a new proof-of-concept exploit targeting Microsoft Defender that can elevate a low-privileged Windows user to NT AUTHORITY\SYSTEM on fully…
Read more >

Microsoft SharePoint CVE-2026-55040 PoC Weaponized in Active Attacks
Attackers have begun using publicly available exploit code for CVE-2026-55040, a critical Microsoft SharePoint authentication bypass vulnerability that allows an unauthenticated remote attacker to impersonate…
Read more >

WordPress CVE-2026-64638 Pre-Auth XSS Can Be Chained to RCE (XSS2Shell)
WordPress has released security updates to address a high-severity vulnerability that allows unauthenticated attackers to execute JavaScript in the context of a WordPress website and,…
Read more >

ChainDrop npm Supply Chain Attack Compromises Hundreds of Packages and Steals Developer Credentials
A rapidly spreading software supply chain attack known as ChainDrop has compromised hundreds of packages in the npm ecosystem, including widely used caching libraries with…
Read more >

N-able N-central Authentication Bypass Exploitation (CVE-2026-18577)
A high-severity authentication bypass vulnerability in N-able N-central is being actively exploited to compromise remote monitoring and management servers and gain access to downstream customer…
Read more >

