Threat intelligence, automated.
AI-researched threat write-ups, live IOC feeds, and MITRE ATT&CK mappings — human-reviewed before every publish. Built for defenders.
CVE-2026-102490: Zammad GmbH Zammad Improper Privilege Management Vulnerability
CVE-2026-102490 describes a critical improper privilege management vulnerability in Zammad, an open-source helpdesk system. This flaw allows a local ‘zammad’ user to escalate privileges to root, posing a significant risk to system integrity. All Zammad versions, including the latest alpha, are affected.
Read full report →CVE-2026-102489: Zammad Session Fixation Leading to RCE
CVE-2026-102489 details a critical session fixation vulnerability in Zammad versions 6.3.0 through 6.5.4 that can be leveraged to achieve remote code execution (RCE) as the `zammad` user. While also present in versions 7.0.0 to 7.1.3, environmental conditions prevent its exploitation in that range. This vulnerability poses a significant risk to unpatched Zammad deployments.
CVE-2026-104286: Fortinet FortiMail Unauthenticated Path Traversal Leading to Arbitrary File Write
A critical path traversal vulnerability (CVE-2026-104286) in Fortinet FortiMail allows unauthenticated attackers to write arbitrary files to the underlying system via crafted HTTP/HTTPS requests. This flaw, with a CVSSv3.1 score of 9.8, affects multiple FortiMail versions and poses a significant risk of remote code execution or system compromise. Immediate patching is recommended.
CVE-2026-73570: Unauthenticated Command Injection in Zimbra
CVE-2026-73570 is a critical unauthenticated command injection vulnerability affecting Zimbra mail servers. Successful exploitation allows remote attackers to execute arbitrary commands, potentially leading to full system compromise of internet-facing mail infrastructure.
CVE-2026-76504: Cisco Catalyst SD-WAN Manager Authentication Bypass
A critical authentication bypass vulnerability (CVE-2026-76504) in Cisco Catalyst SD-WAN Manager allows unauthenticated remote attackers to gain admin privileges. The flaw stems from improper URI encoding handling, enabling attackers to bypass API authentication rules via crafted HTTP requests.
OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI
OpenAI has identified and disrupted a coordinated ‘distillation campaign’ aimed at illicitly extracting protected reasoning from its AI models. The activity, traced back to early July, has been attributed to individuals associated with the Chinese AI company Moonshot AI. This incident highlights a novel form of intellectual property theft targeting advanced AI capabilities.
AI Coding Agents Expose Internal Company Data on GitHub
AI coding agents, when prompted to share screenshots of code changes, have inadvertently uploaded over 13,000 sensitive internal company images to public GitHub repositories. This exposure includes customer billing records and unreleased product features from more than 300 organizations, highlighting a significant data leakage risk in development workflows utilizing AI tools.
Phishing Abuses RMM Tools for Persistent Access
Microsoft has observed phishing campaigns leveraging legitimate Remote Monitoring and Management (RMM) tools, specifically MSP360 RMM and ScreenConnect. Attackers use this method to establish redundant and persistent remote access channels on compromised systems. This tactic allows threat actors to maintain control for follow-on activities, bypassing traditional security controls.
Apple Emergency Patch for iOS 26, macOS 26, macOS 15 (CVE-2026-86950)
Apple has released emergency patches for iOS 26, macOS 26, and macOS 15 to address a critical vulnerability, CVE-2026-86950, which is actively being exploited in the wild. Users of affected older operating system branches are urged to update immediately. iOS and macOS 27 are not impacted by this specific security flaw.
Transparently AI-authored
Every report on this site is researched and drafted by an AI agent, then reviewed and approved by a human analyst before publication. The Agent Logbook shows every step — sources consulted, enrichment calls, tokens used, and approval status — in real time.