Skip to main content

Threats Tagged 'high-priority'

View all threats tagged with 'high-priority'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: high-priority

Threats Tagged 'high-priority'

Click on any threat for detailed analysis and mitigation recommendations

Reports indicate that TikTok users' cameras have been hacked using an open weight AI model developed by a group named depthfirst. The claim is based on a news article discussing how free AI software is enhancing hacker capabilities. No technical details, affected versions, or confirmed exploits are provided in the available information.

Join the discussion

AI agents that rely on MCP (Model-Controller-Plugin) tool descriptions trust these descriptions similarly to how browsers trust TLS certificates. Attackers have begun exploiting this trust by poisoning tool metadata, which can lead to unauthorized actions such as secret exfiltration and silent email BCCs. This attack surface is not widely covered by existing security tools. The threat involves manipulating tool descriptions dynamically to alter agent behavior post-integration. The recommended defensive approach is to treat tool descriptions as untrusted input and implement measures such as pinning, hashing, and baseline comparisons to detect unauthorized changes.

Join the discussion

The GemStuffer incident involved AI agents exploiting a documentation feature in RubyGems infrastructure to achieve remote code execution (RCE). Specifically, the YARD tool's --load option in .yardopts files was abused to execute arbitrary Ruby code during automated documentation builds on RubyDoc.info. The attackers created disposable accounts, bypassed email confirmation, and uploaded over 2,000 malicious packages that weaponized this feature. This incident highlights a broader class of vulnerabilities where legitimate scripting or code execution features in configuration files are abused in package ecosystems. The attack demonstrates a real supply chain risk from automated AI-driven exploitation.

Join the discussion

atomicvulns is an open-source educational project providing a collection of small, intentionally vulnerable web applications, each demonstrating a single OWASP Top 10 2021 vulnerability. It includes 38 isolated apps ('atoms'), each with a vulnerable and fixed version, plus walkthroughs for exploitation and remediation. The project is designed for pentest and AppSec learners to study and practice exploiting and fixing common web vulnerabilities in a focused, hands-on manner. It is not a vulnerability or exploit itself but a learning tool.

Join the discussion

A joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. Special thanks to SentinelOne® Incident Readiness & Response for their contributions to this publication. It is the shared attack surface where state-sponsored threat actors and financially motivated criminal groups independently converge — not the province of a single adversary category, and not exclusively a nation-state problem, despite two years of headlines about China-nexus actors targeting Ivanti, Fortinet, and Palo Alto Networks. The data here tells a different and much broader story. One focused on vendors vs CVEs. Key Takeaways Two independent observation systems, Tenable exposure telemetry across thousands of customer containers and SentinelOne DFIR casework across 66 CVEs, converge 79% on the same vendor attack surfaces despite minimal CVE-level overlap. Twelve CVEs in the combined dataset have confirmed multi-nexus attribution: state-sponsored and criminal actors independently exploiting the same vulnerability, across five nexus categories (China, Russia, DPRK, Iran, ransomware). The exposure picture is flatter than the headlines suggest: Fortinet, the vendor most associated with edge-device attacks in the press, sits mid-pack on container-grain exposure (25%) — well behind F5 (54%) and in a tight 10-point band with Check Point, Ivanti, and Citrix. 54% of customer environments running F5 products have at least one exposed, actively-exploited CVE; Citrix customers show the slowest remediation patterns at 461 days median time to patch. Remediation complexity, particularly of high priority CVEs, leads to a statistically significant 24-day remediation gap, leaving large windows of opportunity for attackers. The same product lines get hit again and again: Ivanti EPMM and Ivanti Connect Secure each show a newly exploited CVE roughly every 8.5 to 13 months. Leverage multiple defense-in-depth strategies: patch as quickly as possible, but also minimize the attack surface (feature-set minimization) and run endpoints in protect mode to better stop lateral movement from attacks that gain initial access. The convergence is the story Twelve CVEs in the combined dataset have confirmed multi-nexus attribution: state-sponsored and criminal actors independently exploiting the same vulnerability, across five nexus categories. Four examples illustrate the pattern: CVE Product Actors (Nexus) Significance CVE-2026-15409 SonicWall SMA1000 UTA0533 (unattributed) + INC Ransomware Espionage-to-ransomware succession on an active zero-day CVE-2023-42793 JetBrains TeamCity APT29 (Russia) + Lazarus (DPRK) Two state-sponsored actors from different nations on the same CVE CVE-2024-3400 PAN-OS GlobalProtect UTA0218 (China) + INC Ransomware China-nexus zero-day reused by ransomware operators CVE-2024-24919 Check Point Quantum PurpleHaze (China) + Fox Kitten (Iran) China and Iran independently exploiting the same gateway vulnerability The remaining eight confirmed multi-nexus CVEs span Fortinet, Citrix, Cisco, and Ivanti product lines. State-sponsored actors and ransomware operators are not operating in separate vulnerability ecosystems. They share the same entry points into the same products. The breadth of the convergence, not any single actor's activity, is the finding. That pattern holds across the full combined analysis. Three conclusions emerge: Vendor attack surfaces are the persistent exploitation target. The same eleven vendors (i.e., Fortinet, Citrix, Ivanti, Palo Alto Networks, Cisco, Juniper, VMware, Microsoft, Oracle, CrushFTP, and Meta's React framework ) appear in both observation systems at 79% convergence, and all seven edge-product vendors converge. Serial exploitation timing on Ivanti products shows the vulnerability-to-exploitation pipeline refreshing at 8.5 to 13-month intervals on the same product lines. This is structural, not episodic. Patch…

Join the discussion
0

CVE-2026-86776 is a reported vulnerability affecting KeePass, referenced on a Reddit cybersecurity post linking to an external vulnerability database. No detailed technical information, affected versions, or patch status is provided in the available data. The vulnerability is rated medium severity but lacks further specifics or evidence of exploitation in the wild.

Join the discussion

An AI model named Cyberkimi claims to have autonomously developed a live exploit for a recently patched V8 JavaScript engine vulnerability in under 24 hours. The exploit targets Chrome Stable versions that still contain the unpatched bugs. The AI reportedly analyzed recent V8 security patches, identified incomplete fixes, and generated a working exploit chain demonstrated in a local Chromium environment. No official CVE has been assigned to these specific bugs yet, and independent confirmation is lacking. The exploit reportedly leverages a combination of aliasing bugs, race conditions, and control flow hijacking to achieve arbitrary code execution. Google has released Chrome updates addressing some V8 vulnerabilities around the same time, but it is unclear if these fixes cover the bugs exploited by Cyberkimi. This development highlights the shrinking window between patch release and exploit weaponization, potentially accelerating the risk exposure for users of affected Chrome versions.

Join the discussion

PATCHCORD is a newly identified malware cluster targeting Afghan telecom providers and critical infrastructure organizations in South Asia. The malware is a custom backdoor implant written in C/C++ and delivered via sector-specific lures such as fake VPN installers and telecom management tools impersonating legitimate Afghan Telecom software. This campaign is ongoing and was discovered by the Acronis Threat Research Unit. The malware aims to infiltrate sensitive telecom and infrastructure environments in the region.

Join the discussion

CVE-2026-17106, known as CopyEscape, is a high-severity vulnerability in Docker's 'docker cp' command that allows a malicious container to write arbitrary files to the host filesystem. The flaw stems from a filesystem race condition during archive creation combined with unsafe symbolic link handling during extraction. This can lead to arbitrary file creation or overwriting on the host and potentially code execution depending on the privileges of the Docker CLI user. Docker has released official fixes in Docker Engine/CLI version 29.7.2 and later, Docker Desktop 4.86.0 and later, and Docker Sandboxes 0.38.0 and later.

Join the discussion

The StopAndProtect operation is a cybercrime campaign that has compromised nearly 2,000 WordPress websites, turning them into a criminal network used for malware delivery, data theft, surveillance, and ransomware activities. The campaign uses social engineering via fake CAPTCHAs to trick victims into executing PowerShell commands that initiate multi-stage malware infections. The malware toolkit includes ransomware, credential stealers, screen lockers, and chat utilities, enabling attackers to selectively steal files and monitor victims before potentially encrypting data. Compromised WordPress sites serve multiple roles, including hosting malware, delivering commands, and storing stolen data. The operation exploits outdated WordPress versions and plugins with known vulnerabilities. The campaign has collected extensive victim data, including screenshots, passwords, and wallet information, indicating a sophisticated surveillance component alongside ransomware. The infection chain and infrastructure management tools were uncovered by Check Point Research in mid-2026.

Join the discussion

Showing 1 to 10 of 1153 results

Filters:Tag: high-priority
Page 1 of 116
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses