CYBER Threat Intelligence Reports
LATEST CTIs
Next.js Critical Vulnerabilities Enable Unauthenticated RCE
Vercel has released security updates for two critical vulnerabilities in Next.js that could allow unauthenticated attackers to achieve remote code execution on vulnerable applications. The…
Read more >

Keycloak CVE-2026-18963 Enables Unauthenticated Account Takeover
A critical vulnerability in Keycloak could allow an unauthenticated remote attacker to take control of arbitrary user accounts through the platform's password recovery functionality. Tracked…
Read more >

Elementor Pro CVE-2026-32475 Enables Unauthenticated File Upload and RCE
A critical vulnerability in the widely deployed Elementor Pro plugin for WordPress can allow unauthenticated attackers to bypass file-type restrictions, upload executable PHP files to…
Read more >

Windows IKE CVE-2026-33824 Exploited for Pre-Auth Remote Code Execution
A critical remote code execution vulnerability in Microsoft Windows Internet Key Exchange (IKE) is now being actively exploited. Tracked as CVE-2026-33824, the vulnerability is a…
Read more >

VMware vCenter CVE-2026-59310 Actively Exploited for RCE and Persistent Access
Threat actors are actively exploiting CVE-2026-59310, a critical unauthenticated remote code execution vulnerability affecting VMware vCenter Server, with incident responders identifying compromises across dozens of…
Read more >

ShieldBreak: Microsoft Defender 0-Day Leads to SYSTEM Privileges
A security researcher has released ShieldBreak, a new proof-of-concept exploit targeting Microsoft Defender that can elevate a low-privileged Windows user to NT AUTHORITY\SYSTEM on fully…
Read more >

