Threat intelligence, automated.
AI-researched threat write-ups, live IOC feeds, and MITRE ATT&CK mappings — human-reviewed before every publish. Built for defenders.
CVE-2026-88772: Citrix NetScaler RCE/DoS Vulnerability
CVE-2026-88772 is a critical memory buffer vulnerability in Citrix NetScaler ADC and Gateway appliances. Successful exploitation can lead to remote code execution (RCE) or denial of service (DoS). Organizations are urged to patch immediately to prevent compromise.
Read full report →CVE-2026-88771: Citrix NetScaler Improper Input Validation Vulnerability
Citrix NetScaler ADC and Gateway are affected by CVE-2026-88771, an improper input validation vulnerability. This flaw allows an unauthenticated attacker to achieve arbitrary command execution, posing a severe risk to affected organizations. Immediate patching is recommended to mitigate this critical vulnerability.
Cloudflare Containers Cross-Tenant Data Exposure Vulnerability
Cloudflare patched a critical vulnerability in its Containers and Sandboxes services that allowed Workers Paid account customers to recover residual data from other tenants on the same physical host. This cross-tenant flaw could lead to unauthorized access and exposure of sensitive customer data.
Microsoft Announces ISOC in Defender for Agentic Security
Microsoft has announced ISOC in Microsoft Defender, a new foundation designed for ‘agentic security.’ This initiative aims to integrate SIEM and threat protection solutions to enhance security operations.
Anthropic Launches Claude AI Marketplace: New Attack Surface Considerations
Anthropic has launched a new marketplace for Claude AI, featuring over 2,000 plugins and connectors. While enhancing functionality, this introduces new security considerations for organizations, primarily around third-party plugin trust, data handling, and potential supply chain risks.
CVE-2026-58704: Google Pixel Cellular Modem Privilege Escalation
A critical improper authorization vulnerability (CVE-2026-58704) in Google Pixel cellular modems allows for remote (proximal/adjacent) privilege escalation without user interaction or additional execution privileges. This flaw, rated 8.8 CVSSv3.1, stems from a logic error enabling attackers to bypass permission checks. CISA has added this CVE to its Known Exploited Vulnerabilities Catalog.
ShinyHunters Exploits Oracle PeopleSoft via WAF Bypass
The ShinyHunters extortion group is actively exploiting Oracle PeopleSoft servers by leveraging a URL-encoding technique to bypass existing Web Application Firewall (WAF) rules designed to mitigate CVE-2026-35273. This bypass allows the group to continue widespread exploitation of the underlying vulnerability, posing a significant risk to unpatched and inadequately protected PeopleSoft instances.
CVE-2026-60004: Gitea Code Injection Vulnerability Actively Exploited
Gitea versions before 1.27.1 are vulnerable to a critical code injection flaw (CVE-2026-60004) allowing authenticated attackers with repository write access to achieve remote code execution. This vulnerability, actively exploited in the wild, enables the planting of malicious Git hooks to execute shell commands as the Gitea service account. Organizations using affected Gitea instances should patch immediately.
CVE-2026-48710: Starlette HTTP Request/Response Smuggling Vulnerability
CVE-2026-48710 is an HTTP request/response smuggling vulnerability in Kludex Starlette versions prior to 1.0.1. Improper validation of the `Host` header allows attackers to manipulate `request.url`, leading to authentication bypass and potential chaining with other vulnerabilities. The vulnerability has a CVSS 3.1 score of 6.5 (Medium).
Transparently AI-authored
Every report on this site is researched and drafted by an AI agent, then reviewed and approved by a human analyst before publication. The Agent Logbook shows every step — sources consulted, enrichment calls, tokens used, and approval status — in real time.