CYBER Threat Intelligence Reports
LATEST CTIs
WordPress CVE-2026-64638 Pre-Auth XSS Can Be Chained to RCE (XSS2Shell)
WordPress has released security updates to address a high-severity vulnerability that allows unauthenticated attackers to execute JavaScript in the context of a WordPress website and,…
Read more >

ChainDrop npm Supply Chain Attack Compromises Hundreds of Packages and Steals Developer Credentials
A rapidly spreading software supply chain attack known as ChainDrop has compromised hundreds of packages in the npm ecosystem, including widely used caching libraries with…
Read more >

N-able N-central Authentication Bypass Exploitation (CVE-2026-18577)
A high-severity authentication bypass vulnerability in N-able N-central is being actively exploited to compromise remote monitoring and management servers and gain access to downstream customer…
Read more >

Cisco FMC Zero-Day CVE-2026-20316 Actively Exploited to Access Sensitive Data
Cisco has disclosed an actively exploited vulnerability in Cisco Secure Firewall software that allows unauthenticated remote attackers to gain access to affected systems using static…
Read more >

Check Point SmartConsole Authentication Bypass (CVE-2026-16232)
Check Point has released an urgent security update addressing three vulnerabilities affecting its Security Management, Multi-Domain Management, Quantum Security Gateway, and Gaia operating system products.…
Read more >

WP2Shell WordPress Core RCE Exploited in the Wild (CVE-2026-63030 and CVE-2026-60137)
WordPress administrators should urgently patch two recently disclosed Core vulnerabilities collectively known as WP2Shell. When chained together, the flaws allow an unauthenticated attacker to execute…
Read more >

