CVE-2026-73749: HPE ArubaOS-CX RCE
CVE-2026-73749: HPE ArubaOS-CX RCE HPE patched CVE-2026-73749, a critical unauthenticated Remote Code Execution (RCE) vulnerability in HPE Aruba Networking AOS-CX, also known as ArubaOS-CX. The flaw a...
CVE-2026-20212: Cisco Nexus 9000 RCE Flaw
CVE-2026-20212: Cisco Nexus 9000 RCE Flaw Cisco has disclosed a critical vulnerability, CVE-2026-20212, in the Silicon One integration used by certain Nexus 9000 switches. The flaw allows an unauthent...
Elementor Pro RCE Flaw Under Active Attack
Elementor Pro RCE Flaw Under Active Attack A critical vulnerability in Elementor Pro, a widely used WordPress page builder plugin, allowed unauthenticated attackers to upload files through the plugin’...
PEEP: A Browser RAT Posing as a Chrome Extension
PEEP: A Browser RAT Posing as a Chrome Extension The Threat Research Unit (STRU) at SOCRadar’s Extended Threat Intelligence (XTI) platform identified and analyzed PEEP, a Chromium-based emerging post-...
FalconFlank: CrowdStrike Falcon 0-Day PoC
FalconFlank: CrowdStrike Falcon 0-Day PoC FalconFlank is an alleged privilege escalation zero-day vulnerability in CrowdStrike Falcon Sensor for Windows, published with working Proof-of-Concept (PoC) ...
JFrog Artifactory CVE-2026-82329 Exploited
JFrog Artifactory CVE-2026-82329 Exploited A critical authentication bypass vulnerability in JFrog Artifactory, tracked as CVE-2026-82329, is under active exploitation, posing an immediate threat to s...
SonicWall CVE-2026-83548 Leads to CISA Alert
SonicWall CVE-2026-83548 Leads to CISA Alert SonicWall disclosed two actively exploited vulnerabilities in SMA1000 Series appliances: CVE-2026-83548, a pre-authentication server-side request forgery f...
FBI Investigates Nexus Claim of 153M+ Driver’s License Records
FBI Investigates Nexus Claim of 153M+ Driver’s License Records A Dark Web service called Nexus has claimed to offer access to more than 153 million driver’s license records from the United States and ...
Langflow and Rails Exploitation Raises Credential Risks
Langflow and Rails Exploitation Raises Credential Risks Attackers are exploiting two separate critical vulnerabilities affecting Langflow and Ruby on Rails. CVE-2026-0768 allows unauthenticated attack...
PaperCut RCE Chain: CVE-2026-82078 Exploited
PaperCut RCE Chain: CVE-2026-82078 Exploited PaperCut disclosed two vulnerabilities in PaperCut NG and PaperCut MF that can be chained into a pre-authentication Remote Code Execution (RCE) path agains...
ServiceNow Patches Multiple CVSS 10.0 Flaws
ServiceNow Patches Multiple CVSS 10.0 Flaws ServiceNow disclosed four vulnerabilities affecting its AI Platform and related Now Platform components on August 27, 2026. Three received vendor-assigned C...
Finnish Kennel Club, Shell Access, UK Iframe, Salt Mobile, and Brazil ...
Finnish Kennel Club, Shell Access, UK Iframe, Salt Mobile, and Brazil SERPRO Claims SOCRadar Dark Web Team identified several new underground posts, including an alleged Finnish Kennel Club and Showli...
Anthropic Links Claude Session Theft to Infostealer Malware
Anthropic Links Claude Session Theft to Infostealer Malware An affected Claude user has shared a warning from Anthropic stating that infostealer malware can steal active Claude login sessions from inf...
OpenAI Urges Cyber Defense Against AI Threats
OpenAI Urges Cyber Defense Against AI Threats OpenAI is calling for a global surge in cyber defense as AI-enabled attacks become more widespread and sophisticated. The call to action raises a practica...
TeamPCP Arrests: Two Charged in Australia Over the Supply Chain Campai...
TeamPCP Arrests: Two Charged in Australia Over the Supply Chain Campaign That Hit 1,000+ Organizations On 26 August 2026, the Australian Federal Police charged two West Australian men over their alleg...
Qilin Claims ATF Breach as Agency Confirms "Major Incident"
Qilin Claims ATF Breach as Agency Confirms “Major Incident” The Qilin Ransomware group listed the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) on its Dark Web leak site on August 26, 2026...
Critical Avada WordPress Flaw (CVE-2026-18431) Enables RCE
Critical Avada WordPress Flaw (CVE-2026-18431) Enables RCE A critical vulnerability chain tracked as CVE-2026-18431 affects the Avada WordPress theme and its required Fusion Builder plugin, now brande...
The GTA VI Leak by CyberLeek Explained
The GTA VI Leak by CyberLeek Explained GTA VI has been slipping out from behind Rockstar’s usually airtight walls in daily doses. An anonymous figure calling itself CyberLeek has been releasing gamepl...
WhatsApp Says One Billion Users Are Now Protected by Passkeys
WhatsApp Says One Billion Users Are Now Protected by Passkeys The milestone signals that phishing-resistant authentication has moved into the consumer mainstream, while new controls target registratio...
Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain
Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain The SOCRadar Threat Research Unit (STRU) has conducted an “inside-out” analysis of AnonyMousKIT, an AI-powered Phishing-as-a-Service (PhaaS) ecosys...
