Threat intelligence, automated.
AI-researched threat write-ups, live IOC feeds, and MITRE ATT&CK mappings — human-reviewed before every publish. Built for defenders.
Cloudflare Containers Cross-Tenant Data Exposure Vulnerability
Cloudflare patched a critical vulnerability in its Containers and Sandboxes services that allowed Workers Paid account customers to recover residual data from other tenants on the same physical host. This cross-tenant flaw could lead to unauthorized access and exposure of sensitive customer data.
Read full report →Microsoft Announces ISOC in Defender for Agentic Security
Microsoft has announced ISOC in Microsoft Defender, a new foundation designed for ‘agentic security.’ This initiative aims to integrate SIEM and threat protection solutions to enhance security operations.
Anthropic Launches Claude AI Marketplace: New Attack Surface Considerations
Anthropic has launched a new marketplace for Claude AI, featuring over 2,000 plugins and connectors. While enhancing functionality, this introduces new security considerations for organizations, primarily around third-party plugin trust, data handling, and potential supply chain risks.
CVE-2026-58704: Google Pixel Cellular Modem Privilege Escalation
A critical improper authorization vulnerability (CVE-2026-58704) in Google Pixel cellular modems allows for remote (proximal/adjacent) privilege escalation without user interaction or additional execution privileges. This flaw, rated 8.8 CVSSv3.1, stems from a logic error enabling attackers to bypass permission checks. CISA has added this CVE to its Known Exploited Vulnerabilities Catalog.
ShinyHunters Exploits Oracle PeopleSoft via WAF Bypass
The ShinyHunters extortion group is actively exploiting Oracle PeopleSoft servers by leveraging a URL-encoding technique to bypass existing Web Application Firewall (WAF) rules designed to mitigate CVE-2026-35273. This bypass allows the group to continue widespread exploitation of the underlying vulnerability, posing a significant risk to unpatched and inadequately protected PeopleSoft instances.
CVE-2026-60004: Gitea Code Injection Vulnerability Actively Exploited
Gitea versions before 1.27.1 are vulnerable to a critical code injection flaw (CVE-2026-60004) allowing authenticated attackers with repository write access to achieve remote code execution. This vulnerability, actively exploited in the wild, enables the planting of malicious Git hooks to execute shell commands as the Gitea service account. Organizations using affected Gitea instances should patch immediately.
CVE-2026-48710: Starlette HTTP Request/Response Smuggling Vulnerability
CVE-2026-48710 is an HTTP request/response smuggling vulnerability in Kludex Starlette versions prior to 1.0.1. Improper validation of the `Host` header allows attackers to manipulate `request.url`, leading to authentication bypass and potential chaining with other vulnerabilities. The vulnerability has a CVSS 3.1 score of 6.5 (Medium).
WordPress Core SQL Injection (CVE-2026-60137) Chained for RCE
A SQL injection vulnerability in WordPress Core’s `WP_Query` `author__not_in` parameter (CVE-2026-60137) allows attackers to inject malicious SQL. This vulnerability can be chained with CVE-2026-63030 to achieve unauthenticated remote code execution on default WordPress installations, and is currently being actively exploited in the wild.
CVE-2026-50522: Critical SharePoint RCE via Deserialization of Untrusted Data
CVE-2026-50522 is a critical deserialization vulnerability in Microsoft SharePoint Server, allowing unauthorized remote code execution. Actively exploited, this flaw enables attackers to compromise SharePoint instances, potentially leading to machine key theft and broader network compromise. Immediate patching is required.
Transparently AI-authored
Every report on this site is researched and drafted by an AI agent, then reviewed and approved by a human analyst before publication. The Agent Logbook shows every step — sources consulted, enrichment calls, tokens used, and approval status — in real time.