AI Threat Intelligence

Threat intelligence, automated.

AI-researched threat write-ups, live IOC feeds, and MITRE ATT&CK mappings — human-reviewed before every publish. Built for defenders.

Threats tracked—
IOCs published—
MITRE techniques—
Last updated—
Latest Report
CRITICALvulnerability

CVE-2026-88772: Citrix NetScaler RCE/DoS Vulnerability

CVE-2026-88772 is a critical memory buffer vulnerability in Citrix NetScaler ADC and Gateway appliances. Successful exploitation can lead to remote code execution (RCE) or denial of service (DoS). Organizations are urged to patch immediately to prevent compromise.

Read full report →
Recent Threats
CRITICALvulnerability

CVE-2026-88771: Citrix NetScaler Improper Input Validation Vulnerability

Citrix NetScaler ADC and Gateway are affected by CVE-2026-88771, an improper input validation vulnerability. This flaw allows an unauthenticated attacker to achieve arbitrary command execution, posing a severe risk to affected organizations. Immediate patching is recommended to mitigate this critical vulnerability.

Read report →
CRITICALvulnerability

Cloudflare Containers Cross-Tenant Data Exposure Vulnerability

Cloudflare patched a critical vulnerability in its Containers and Sandboxes services that allowed Workers Paid account customers to recover residual data from other tenants on the same physical host. This cross-tenant flaw could lead to unauthorized access and exposure of sensitive customer data.

Read report →
INFOthreat

Microsoft Announces ISOC in Defender for Agentic Security

Microsoft has announced ISOC in Microsoft Defender, a new foundation designed for ‘agentic security.’ This initiative aims to integrate SIEM and threat protection solutions to enhance security operations.

Read report →
LOWthreat

Anthropic Launches Claude AI Marketplace: New Attack Surface Considerations

Anthropic has launched a new marketplace for Claude AI, featuring over 2,000 plugins and connectors. While enhancing functionality, this introduces new security considerations for organizations, primarily around third-party plugin trust, data handling, and potential supply chain risks.

Read report →
HIGHvulnerability

CVE-2026-58704: Google Pixel Cellular Modem Privilege Escalation

A critical improper authorization vulnerability (CVE-2026-58704) in Google Pixel cellular modems allows for remote (proximal/adjacent) privilege escalation without user interaction or additional execution privileges. This flaw, rated 8.8 CVSSv3.1, stems from a logic error enabling attackers to bypass permission checks. CISA has added this CVE to its Known Exploited Vulnerabilities Catalog.

Read report →
HIGHvulnerability

ShinyHunters Exploits Oracle PeopleSoft via WAF Bypass

The ShinyHunters extortion group is actively exploiting Oracle PeopleSoft servers by leveraging a URL-encoding technique to bypass existing Web Application Firewall (WAF) rules designed to mitigate CVE-2026-35273. This bypass allows the group to continue widespread exploitation of the underlying vulnerability, posing a significant risk to unpatched and inadequately protected PeopleSoft instances.

Read report →
CRITICALvulnerability

CVE-2026-60004: Gitea Code Injection Vulnerability Actively Exploited

Gitea versions before 1.27.1 are vulnerable to a critical code injection flaw (CVE-2026-60004) allowing authenticated attackers with repository write access to achieve remote code execution. This vulnerability, actively exploited in the wild, enables the planting of malicious Git hooks to execute shell commands as the Gitea service account. Organizations using affected Gitea instances should patch immediately.

Read report →
MEDIUMvulnerability

CVE-2026-48710: Starlette HTTP Request/Response Smuggling Vulnerability

CVE-2026-48710 is an HTTP request/response smuggling vulnerability in Kludex Starlette versions prior to 1.0.1. Improper validation of the `Host` header allows attackers to manipulate `request.url`, leading to authentication bypass and potential chaining with other vulnerabilities. The vulnerability has a CVSS 3.1 score of 6.5 (Medium).

Read report →

Transparently AI-authored

Every report on this site is researched and drafted by an AI agent, then reviewed and approved by a human analyst before publication. The Agent Logbook shows every step — sources consulted, enrichment calls, tokens used, and approval status — in real time.