AI Threat Intelligence

Threat intelligence, automated.

AI-researched threat write-ups, live IOC feeds, and MITRE ATT&CK mappings — human-reviewed before every publish. Built for defenders.

Threats tracked—
IOCs published—
MITRE techniques—
Last updated—
Latest Report
CRITICALvulnerability

Cloudflare Containers Cross-Tenant Data Exposure Vulnerability

Cloudflare patched a critical vulnerability in its Containers and Sandboxes services that allowed Workers Paid account customers to recover residual data from other tenants on the same physical host. This cross-tenant flaw could lead to unauthorized access and exposure of sensitive customer data.

Read full report →
Recent Threats
INFOthreat

Microsoft Announces ISOC in Defender for Agentic Security

Microsoft has announced ISOC in Microsoft Defender, a new foundation designed for ‘agentic security.’ This initiative aims to integrate SIEM and threat protection solutions to enhance security operations.

Read report →
LOWthreat

Anthropic Launches Claude AI Marketplace: New Attack Surface Considerations

Anthropic has launched a new marketplace for Claude AI, featuring over 2,000 plugins and connectors. While enhancing functionality, this introduces new security considerations for organizations, primarily around third-party plugin trust, data handling, and potential supply chain risks.

Read report →
HIGHvulnerability

CVE-2026-58704: Google Pixel Cellular Modem Privilege Escalation

A critical improper authorization vulnerability (CVE-2026-58704) in Google Pixel cellular modems allows for remote (proximal/adjacent) privilege escalation without user interaction or additional execution privileges. This flaw, rated 8.8 CVSSv3.1, stems from a logic error enabling attackers to bypass permission checks. CISA has added this CVE to its Known Exploited Vulnerabilities Catalog.

Read report →
HIGHvulnerability

ShinyHunters Exploits Oracle PeopleSoft via WAF Bypass

The ShinyHunters extortion group is actively exploiting Oracle PeopleSoft servers by leveraging a URL-encoding technique to bypass existing Web Application Firewall (WAF) rules designed to mitigate CVE-2026-35273. This bypass allows the group to continue widespread exploitation of the underlying vulnerability, posing a significant risk to unpatched and inadequately protected PeopleSoft instances.

Read report →
CRITICALvulnerability

CVE-2026-60004: Gitea Code Injection Vulnerability Actively Exploited

Gitea versions before 1.27.1 are vulnerable to a critical code injection flaw (CVE-2026-60004) allowing authenticated attackers with repository write access to achieve remote code execution. This vulnerability, actively exploited in the wild, enables the planting of malicious Git hooks to execute shell commands as the Gitea service account. Organizations using affected Gitea instances should patch immediately.

Read report →
MEDIUMvulnerability

CVE-2026-48710: Starlette HTTP Request/Response Smuggling Vulnerability

CVE-2026-48710 is an HTTP request/response smuggling vulnerability in Kludex Starlette versions prior to 1.0.1. Improper validation of the `Host` header allows attackers to manipulate `request.url`, leading to authentication bypass and potential chaining with other vulnerabilities. The vulnerability has a CVSS 3.1 score of 6.5 (Medium).

Read report →
MEDIUMvulnerability

WordPress Core SQL Injection (CVE-2026-60137) Chained for RCE

A SQL injection vulnerability in WordPress Core’s `WP_Query` `author__not_in` parameter (CVE-2026-60137) allows attackers to inject malicious SQL. This vulnerability can be chained with CVE-2026-63030 to achieve unauthenticated remote code execution on default WordPress installations, and is currently being actively exploited in the wild.

Read report →
CRITICALvulnerability

CVE-2026-50522: Critical SharePoint RCE via Deserialization of Untrusted Data

CVE-2026-50522 is a critical deserialization vulnerability in Microsoft SharePoint Server, allowing unauthorized remote code execution. Actively exploited, this flaw enables attackers to compromise SharePoint instances, potentially leading to machine key theft and broader network compromise. Immediate patching is required.

Read report →

Transparently AI-authored

Every report on this site is researched and drafted by an AI agent, then reviewed and approved by a human analyst before publication. The Agent Logbook shows every step — sources consulted, enrichment calls, tokens used, and approval status — in real time.