{"metadata":{"generatedAt":"2026-08-21T03:01:29.634Z","reportDate":"2026-08-21","totalItems":3339,"sourceBreakdown":{"cisa-kev":8,"nvd":3068,"cisa-advisories":7,"vendor-blogs":87,"malware-bazaar":9,"abuse-ipdb":20,"threatfox":2,"otx":33,"general-news":112},"categoryBreakdown":{"vulnerability":3073,"advisory":91,"malware":9,"ip-reputation":20,"threat-intel":35,"news":111},"fetchErrors":[]},"highlights":[{"id":"nvd-CVE-2026-15706","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-15706 — Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry…","description":"Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc. Baylan Smart Meter Management Application (BMS) allows Authentication Bypass.\n\nThis issue affects Baylan Smart Meter Management Application (BMS): before v1.1.10.142.","indicators":{"cves":["CVE-2026-15706"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T14:17:09.617Z","fetchedAt":"2026-08-21T03:01:29.087Z","references":[{"url":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0881","label":"iletisim@usom.gov.tr","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-64960","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-64960 — ATutor Gameme module allows users to upload files of any type and extension without restriction. Due…","description":"ATutor Gameme module allows users to upload files of any type and extension without restriction. Due to improper handling of file uploads, files are stored in a web-accessible location before their content is validated. An authenticated attacker who knows a valid course_id can upload a server-execut…","indicators":{"cves":["CVE-2026-64960"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T14:17:44.400Z","fetchedAt":"2026-08-21T03:01:29.087Z","references":[{"url":"https://atutor.github.io/","label":"cvd@cert.pl","domainType":"other"},{"url":"https://cert.pl/en/posts/2026/08/CVE-2026-64960","label":"cvd@cert.pl","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-64966","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-64966 — ATutor is vulnerable to a Path Traversal vulnerability in ZIP extraction functionality. An attacker…","description":"ATutor is vulnerable to a Path Traversal vulnerability in ZIP extraction functionality. An attacker with instructor privileges can upload and extract a specially crafted ZIP archive, causing files to be written outside the intended extraction directory. This allows an attacker to place a server-exec…","indicators":{"cves":["CVE-2026-64966"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T14:17:45.270Z","fetchedAt":"2026-08-21T03:01:29.087Z","references":[{"url":"https://atutor.github.io/","label":"cvd@cert.pl","domainType":"other"},{"url":"https://cert.pl/en/posts/2026/08/CVE-2026-64960","label":"cvd@cert.pl","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-16926","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-16926 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary f…","description":"IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary files due to improper neutralization of special elements in input.","indicators":{"cves":["CVE-2026-16926"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T15:17:28.963Z","fetchedAt":"2026-08-21T03:01:29.087Z","references":[{"url":"https://www.ibm.com/support/pages/node/7283858","label":"psirt@us.ibm.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-15679","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-15679 — Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution…","description":"Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face PyTorch Image Models. User interaction is required to exploit this vulner…","indicators":{"cves":["CVE-2026-15679"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:21.050Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-523/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-15686","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-15686 — Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability. Th…","description":"Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adminer. Authentication is required to exploit this vulnerability.\n\nThe specific flaw exists within the…","indicators":{"cves":["CVE-2026-15686"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:21.180Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/vrana/adminer/security/advisories/GHSA-3582-q6xq-5vf7#event-826206","label":"zdi-disclosures@trendmicro.com","domainType":"primary"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-478/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18264","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-18264 — NoMachine getstat Command Injection Remote Code Execution Vulnerability. This vulnerability allows r…","description":"NoMachine getstat Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NoMachine. Authentication is required to exploit this vulnerability.\n\nThe specific flaw exists within the web service, which list…","indicators":{"cves":["CVE-2026-18264"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:22.890Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://kb.nomachine.com/TR06X11869","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-483/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18265","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-18265 — OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulnerability al…","description":"OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OSNEXUS QuantaStor. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the conf…","indicators":{"cves":["CVE-2026-18265"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:23.017Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-480/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18274","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-18274 — Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution Vulnerability. This…","description":"Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Authentication is required to exploit this vulnerability.\n\nThe specific flaw…","indicators":{"cves":["CVE-2026-18274"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:24.003Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-479/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18279","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-18279 — Sony XAV-9500ES RTSP SETUP Buffer Overflow Remote Code Execution Vulnerability. This vulnerability a…","description":"Sony XAV-9500ES RTSP SETUP Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists…","indicators":{"cves":["CVE-2026-18279"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:24.280Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://www.sony.com/electronics/support/mobile-cd-players-digital-media-players-xav-series/xav-9500es/software/00274922","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-472/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null}],"items":[{"id":"nvd-CVE-2026-15706","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-15706 — Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry…","description":"Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc. Baylan Smart Meter Management Application (BMS) allows Authentication Bypass.\n\nThis issue affects Baylan Smart Meter Management Application (BMS): before v1.1.10.142.","indicators":{"cves":["CVE-2026-15706"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T14:17:09.617Z","fetchedAt":"2026-08-21T03:01:29.087Z","references":[{"url":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0881","label":"iletisim@usom.gov.tr","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-64960","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-64960 — ATutor Gameme module allows users to upload files of any type and extension without restriction. Due…","description":"ATutor Gameme module allows users to upload files of any type and extension without restriction. Due to improper handling of file uploads, files are stored in a web-accessible location before their content is validated. An authenticated attacker who knows a valid course_id can upload a server-execut…","indicators":{"cves":["CVE-2026-64960"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T14:17:44.400Z","fetchedAt":"2026-08-21T03:01:29.087Z","references":[{"url":"https://atutor.github.io/","label":"cvd@cert.pl","domainType":"other"},{"url":"https://cert.pl/en/posts/2026/08/CVE-2026-64960","label":"cvd@cert.pl","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-64966","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-64966 — ATutor is vulnerable to a Path Traversal vulnerability in ZIP extraction functionality. An attacker…","description":"ATutor is vulnerable to a Path Traversal vulnerability in ZIP extraction functionality. An attacker with instructor privileges can upload and extract a specially crafted ZIP archive, causing files to be written outside the intended extraction directory. This allows an attacker to place a server-exec…","indicators":{"cves":["CVE-2026-64966"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T14:17:45.270Z","fetchedAt":"2026-08-21T03:01:29.087Z","references":[{"url":"https://atutor.github.io/","label":"cvd@cert.pl","domainType":"other"},{"url":"https://cert.pl/en/posts/2026/08/CVE-2026-64960","label":"cvd@cert.pl","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-16926","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-16926 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary f…","description":"IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary files due to improper neutralization of special elements in input.","indicators":{"cves":["CVE-2026-16926"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T15:17:28.963Z","fetchedAt":"2026-08-21T03:01:29.087Z","references":[{"url":"https://www.ibm.com/support/pages/node/7283858","label":"psirt@us.ibm.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-15679","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-15679 — Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution…","description":"Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face PyTorch Image Models. User interaction is required to exploit this vulner…","indicators":{"cves":["CVE-2026-15679"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:21.050Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-523/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-15686","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-15686 — Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability. Th…","description":"Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adminer. Authentication is required to exploit this vulnerability.\n\nThe specific flaw exists within the…","indicators":{"cves":["CVE-2026-15686"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:21.180Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/vrana/adminer/security/advisories/GHSA-3582-q6xq-5vf7#event-826206","label":"zdi-disclosures@trendmicro.com","domainType":"primary"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-478/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18264","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-18264 — NoMachine getstat Command Injection Remote Code Execution Vulnerability. This vulnerability allows r…","description":"NoMachine getstat Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NoMachine. Authentication is required to exploit this vulnerability.\n\nThe specific flaw exists within the web service, which list…","indicators":{"cves":["CVE-2026-18264"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:22.890Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://kb.nomachine.com/TR06X11869","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-483/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18265","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-18265 — OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulnerability al…","description":"OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OSNEXUS QuantaStor. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the conf…","indicators":{"cves":["CVE-2026-18265"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:23.017Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-480/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18274","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-18274 — Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution Vulnerability. This…","description":"Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Authentication is required to exploit this vulnerability.\n\nThe specific flaw…","indicators":{"cves":["CVE-2026-18274"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:24.003Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-479/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18279","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-18279 — Sony XAV-9500ES RTSP SETUP Buffer Overflow Remote Code Execution Vulnerability. This vulnerability a…","description":"Sony XAV-9500ES RTSP SETUP Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists…","indicators":{"cves":["CVE-2026-18279"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:24.280Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://www.sony.com/electronics/support/mobile-cd-players-digital-media-players-xav-series/xav-9500es/software/00274922","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-472/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18281","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-18281 — Sony XAV-9500ES l2_reassemble_sdu Heap-based Buffer Overflow Remote Code Execution Vulnerability. Th…","description":"Sony XAV-9500ES l2_reassemble_sdu Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-9500ES devices. An attacker must first obtain the ability to pair a malicious Bluetoo…","indicators":{"cves":["CVE-2026-18281"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:24.523Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://www.sony.com/electronics/support/mobile-cd-players-digital-media-players-xav-series/xav-9500es/software/00274922","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-474/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18282","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-18282 — Sony XAV-9500ES AVRCP_Br_Response_Parser Heap-based Buffer Overflow Remote Code Execution Vulnerabil…","description":"Sony XAV-9500ES AVRCP_Br_Response_Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-9500ES devices. An attacker must first obtain the ability to pair a malicious…","indicators":{"cves":["CVE-2026-18282"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:24.643Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://www.sony.com/electronics/support/mobile-cd-players-digital-media-players-xav-series/xav-9500es/software/00274922","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-475/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18285","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-18285 — Aeon load_rehab_pile_dataset Deserialization of Untrusted Data Remote Code Execution Vulnerability.…","description":"Aeon load_rehab_pile_dataset Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Aeon. User interaction is required to exploit this vulnerability in that the target must visit a malic…","indicators":{"cves":["CVE-2026-18285"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:25.007Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/aeon-toolkit/aeon/commit/751918052c0cce266b4f7cd4b084408526efc015","label":"zdi-disclosures@trendmicro.com","domainType":"primary"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-468/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18286","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-18286 — Aeon load_human_activity_segmentation_datasets Code Injection Remote Code Execution Vulnerability. T…","description":"Aeon load_human_activity_segmentation_datasets Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of aeon. User interaction is required to exploit this vulnerability in that the target must visit a malici…","indicators":{"cves":["CVE-2026-18286"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:25.140Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/aeon-toolkit/aeon/commit/751918052c0cce266b4f7cd4b084408526efc015","label":"zdi-disclosures@trendmicro.com","domainType":"primary"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-469/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18287","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-18287 — Aeon load_time_series_segmentation_benchmark Code Injection Remote Code Execution Vulnerability. Thi…","description":"Aeon load_time_series_segmentation_benchmark Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of aeon. User interaction is required to exploit this vulnerability in that the target must visit a maliciou…","indicators":{"cves":["CVE-2026-18287"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:25.263Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/aeon-toolkit/aeon/commit/751918052c0cce266b4f7cd4b084408526efc015","label":"zdi-disclosures@trendmicro.com","domainType":"primary"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-470/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18288","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-18288 — OriginLab OriginPro OPJU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This…","description":"OriginLab OriginPro OPJU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that the target must vis…","indicators":{"cves":["CVE-2026-18288"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:25.397Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://docs.originlab.com/cve/CVE-2026-18288","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-547/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18289","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-18289 — OriginLab OriginPro OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This v…","description":"OriginLab OriginPro OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that the target must visi…","indicators":{"cves":["CVE-2026-18289"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:25.523Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://docs.originlab.com/cve/CVE-2026-18289","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-548/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18290","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-18290 — OriginLab OriginPro OGG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This v…","description":"OriginLab OriginPro OGG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that the target must visi…","indicators":{"cves":["CVE-2026-18290"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:25.647Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://docs.originlab.com/cve/CVE-2026-18290","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-549/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18291","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-18291 — OriginLab OriginPro OGW File Parsing Memory Corruption Remote Code Execution Vulnerability. This vul…","description":"OriginLab OriginPro OGW File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that the target must visit…","indicators":{"cves":["CVE-2026-18291"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:25.767Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://docs.originlab.com/cve/CVE-2026-18291","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-550/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18292","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-18292 — OriginLab OriginPro OGG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vul…","description":"OriginLab OriginPro OGG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro . User interaction is required to exploit this vulnerability in that the target must visit…","indicators":{"cves":["CVE-2026-18292"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:25.890Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://docs.originlab.com/cve/CVE-2026-18292","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-551/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18293","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-18293 — OriginLab Origin Viewer OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. Th…","description":"OriginLab Origin Viewer OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target m…","indicators":{"cves":["CVE-2026-18293"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:26.010Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://docs.originlab.com/cve/CVE-2026-18293","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-552/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18294","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-18294 — OriginLab Origin Viewer OGW File Parsing Memory Corruption Remote Code Execution Vulnerability. This…","description":"OriginLab Origin Viewer OGW File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target mus…","indicators":{"cves":["CVE-2026-18294"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:26.130Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://docs.originlab.com/cve/CVE-2026-18294","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-553/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18295","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-18295 — GStreamer MRF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerabili…","description":"GStreamer MRF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page o…","indicators":{"cves":["CVE-2026-18295"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:26.260Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://gstreamer.freedesktop.org/security/sa-2026-0050.html","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-463/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18296","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-18296 — GStreamer MRF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vuln…","description":"GStreamer MRF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious…","indicators":{"cves":["CVE-2026-18296"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:26.390Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://gstreamer.freedesktop.org/security/sa-2026-0050.html","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-464/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18297","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-18297 — GStreamer OGG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vul…","description":"GStreamer OGG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a maliciou…","indicators":{"cves":["CVE-2026-18297"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:26.507Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://gstreamer.freedesktop.org/security/sa-2026-0053.html","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-465/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18298","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-18298 — GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vuln…","description":"GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious…","indicators":{"cves":["CVE-2026-18298"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:26.643Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://gstreamer.freedesktop.org/security/sa-2026-0052.html","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-466/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18299","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-18299 — GStreamer rtpsbcdepay Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows…","description":"GStreamer rtpsbcdepay Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the…","indicators":{"cves":["CVE-2026-18299"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:26.767Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://gstreamer.freedesktop.org/security/sa-2026-0051.html","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-467/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18300","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-18300 — GIMP HDR File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allow…","description":"GIMP HDR File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a mali…","indicators":{"cves":["CVE-2026-18300"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:26.890Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://gitlab.gnome.org/GNOME/gegl/-/commit/d3d262008299341c5b032b354021632ceadb2799","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-453/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18301","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-18301 — GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allow…","description":"GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a mali…","indicators":{"cves":["CVE-2026-18301"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:27.017Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/2772","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-454/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18302","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-18302 — GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabi…","description":"GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or o…","indicators":{"cves":["CVE-2026-18302","CVE-2026-18307"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:27.143Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://gitlab.gnome.org/GNOME/gimp/-/commit/77e1a11636fae53c922fe92273b8f4e33c7a9176","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-455/","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://gitlab.gnome.org/GNOME/gimp/-/commit/bace3e7fd54104fe6b70c1703e9b982a4770811d","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-460/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18303","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-18303 — GIMP TIF File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerab…","description":"GIMP TIF File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or…","indicators":{"cves":["CVE-2026-18303"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:27.277Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://gitlab.gnome.org/GNOME/gimp/-/commit/5633b362026c6e5b2beb559a10cd76fa32a47592","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-456/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18304","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-18304 — GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allow…","description":"GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a mali…","indicators":{"cves":["CVE-2026-18304","CVE-2026-18305","CVE-2026-18308"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:27.403Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://gitlab.gnome.org/GNOME/gimp/-/commit/ad32d22c347674fa1bb5b60935c376b673d946e7","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-457/","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://gitlab.gnome.org/GNOME/gimp/-/commit/0a45a2b51b877829ef523131b50c0eb2a933b8a1","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-458/","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://gitlab.gnome.org/GNOME/gimp/-/commit/d84f8e58f56681a0b4c66129c568cb796725ab9d","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-461/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18306","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-18306 — GIMP SGI File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allow…","description":"GIMP SGI File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a mali…","indicators":{"cves":["CVE-2026-18306"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:27.633Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://gitlab.gnome.org/GNOME/gimp/-/commit/76531da9732f38566e5fd8f8f80c837158511ae5","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-459/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18309","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-18309 — GIMP APNG File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allo…","description":"GIMP APNG File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a mal…","indicators":{"cves":["CVE-2026-18309"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:27.987Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://gitlab.gnome.org/GNOME/gimp/-/commit/c760c8309d18bdf5259f1e04ced0779462c7c636","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-462/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-55642","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-55642 — dbx is a cross-platform database client for databases. Prior to 0.5.51, dbx-web auth_middleware in c…","description":"dbx is a cross-platform database client for databases. Prior to 0.5.51, dbx-web auth_middleware in crates/dbx-web/src/auth.rs passes every protected request to the handler chain when password_hash is None. A fresh deployment reaches that state when DBX_PASSWORD is unset and no stored password exists…","indicators":{"cves":["CVE-2026-55642"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:18:27.873Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/t8y2/dbx/commit/fb919efe0a62869631f49242d1f4fe8d41718c2a","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/t8y2/dbx/issues/2887","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/t8y2/dbx/releases/tag/v0.5.51","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/t8y2/dbx/security/advisories/GHSA-rqp4-8fxh-22vh","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/t8y2/dbx/security/advisories/GHSA-rqp4-8fxh-22vh","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-71428","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-71428 — The unstructured library provides open-source components for ingesting and pre-processing images and…","description":"The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. From 0.4.7 until 0.24.0, the url argument of partition, partition_html, and partition_md is fetched without host validation in unstructur…","indicators":{"cves":["CVE-2026-71428"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:19:40.773Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/Unstructured-IO/unstructured/commit/445c95735c4045057f51f399bc04c657751923bd","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/Unstructured-IO/unstructured/pull/4388","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/Unstructured-IO/unstructured/releases/tag/0.24.0","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/Unstructured-IO/unstructured/security/advisories/GHSA-4mvj-m6j5-pmf7","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-77022","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-77022 — A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the functi…","description":"A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component SSID Configuration. The manipulation of the argument ssid results in stack-based buffer overflow. The atta…","indicators":{"cves":["CVE-2026-77022"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:19:49.413Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/AdminSafe/CVE/issues/5","label":"cna@vuldb.com","domainType":"primary"},{"url":"https://vuldb.com/cve/CVE-2026-77022","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/submit/880599","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/vuln/393637","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/vuln/393637/cti","label":"cna@vuldb.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-2334","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-2334 — An issue was discovered in vsDesk v14.0101. An authenticated attacker with administrative privileges…","description":"An issue was discovered in vsDesk v14.0101. An authenticated attacker with administrative privileges can bypass client-side file validation in the \"Import via CSV\" component due to a lack of server-side validation. This allows the upload of an arbitrary file, which can lead to Remote Code Execution…","indicators":{"cves":["CVE-2026-2334"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T18:16:26.047Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/klsecservices/Advisories/blob/master/KLSA-00415-Missing-Server-Side-File-Extension-Validation-in-vsDesk.md","label":"vulnerability@kaspersky.com","domainType":"primary"},{"url":"https://vsdesk.ru/news/vyshla-novaya-versiya-140422","label":"vulnerability@kaspersky.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-53424","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-53424 — Authentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authent…","description":"Authentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it.\n\nSamly.Helper.decode_idp_auth_resp/3 in lib/samly/helper.ex calls esaml_sp:validate_assertion/2, whose default duplicate detector…","indicators":{"cves":["CVE-2026-53424"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["ransomware"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T18:16:27.680Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://cna.erlef.org/cves/CVE-2026-53424.html","label":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","domainType":"other"},{"url":"https://osv.dev/vulnerability/EEF-CVE-2026-53424","label":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-73256","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-73256 — Mongoose is an embedded web server and network library. Prior to 7.22, a remote unauthenticated atta…","description":"Mongoose is an embedded web server and network library. Prior to 7.22, a remote unauthenticated attacker can exploit an HTTP/1.0 reverse-proxy deployment by sending a request with Transfer-Encoding: chunked and conflicting framing. The http_cb() function in src/http.c tests hm.proto.len with an impo…","indicators":{"cves":["CVE-2026-73256"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T18:16:46.523Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://github.com/cesanta/mongoose/commit/a9df523f76f43a38bd53b4232b9cfd4c16869e71","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cesanta/mongoose/pull/3611","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cesanta/mongoose/releases/tag/7.22","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cesanta/mongoose/security/advisories/GHSA-mgp5-rjrv-h5j3","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-73257","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-73257 — Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthentica…","description":"Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthenticated attacker can send an HTTP request containing both Content-Length and Transfer-Encoding: chunked. The cl_count and te_count checks in the mg_http_parse() and http_cb() paths in src/http.c accept bo…","indicators":{"cves":["CVE-2026-73257"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T18:16:46.973Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://github.com/cesanta/mongoose/commit/a9df523f76f43a38bd53b4232b9cfd4c16869e71","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cesanta/mongoose/pull/3611","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cesanta/mongoose/releases/tag/7.22","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cesanta/mongoose/security/advisories/GHSA-5wfq-r6mr-wqp6","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cesanta/mongoose/security/advisories/GHSA-5wfq-r6mr-wqp6","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-66785","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-66785 — A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect ne…","description":"A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect network traffic from other connected clusters (peer clusters) by publishing a specially crafted network endpoint. The system fails to properly validate the network subnets provided by the malicious clus…","indicators":{"cves":["CVE-2026-66785"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T19:16:58.463Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-66785","label":"secalert@redhat.com","domainType":"other"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2507530","label":"secalert@redhat.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-66788","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-66788 — A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vu…","description":"A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where the destination namespace for resource injection is derived from an attacker-controlled label or annotation on the broker object. This allows the attacker to inject unauthorized Endp…","indicators":{"cves":["CVE-2026-66788"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T19:16:58.823Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-66788","label":"secalert@redhat.com","domainType":"other"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2507533","label":"secalert@redhat.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-77148","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-77148 — A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the fi…","description":"A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the file /cgi-bin/mbox-config?method=SET&section=ptest_channel of the component Web Management. The manipulation results in stack-based buffer overflow. The attack can be launched remotely. The exploit has…","indicators":{"cves":["CVE-2026-77148"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T19:17:04.710Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://github.com/AdminSafe/CVE/issues/7","label":"cna@vuldb.com","domainType":"primary"},{"url":"https://vuldb.com/cve/CVE-2026-77148","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/submit/880910","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/vuln/393733","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/vuln/393733/cti","label":"cna@vuldb.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-67567","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-67567 — A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a ten…","description":"A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), to bypass existing security controls. The system's HelmRelease controller processes Helm chart templates using its own elevated S…","indicators":{"cves":["CVE-2026-67567"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T21:17:07.403Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-67567","label":"secalert@redhat.com","domainType":"other"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2514224","label":"secalert@redhat.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-69242","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-69242 — libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, a crafted…","description":"libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, a crafted many-band TIFF processed through VipsForeignLoadTiff can evade scanline validation in libvips/iofuncs/image.c and cause an integer overflow in vips_image_sanity. The resulting buffer-region calculati…","indicators":{"cves":["CVE-2026-69242"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T21:17:07.697Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://github.com/libvips/libvips/commit/c72f50927413cd2451837d9813f954bc5d88f548","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libvips/libvips/pull/5012","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libvips/libvips/releases/tag/v8.18.3","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libvips/libvips/security/advisories/GHSA-9rwc-f68v-4482","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-71485","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-71485 — Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies…","description":"Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies the client-controlled protocol.ConnectRequest.headers map through OnClientConnecting in internal/client/handler.go, ConnectEvent.Headers, and SetEmulatedHeadersToContext. The requestHeaders path in in…","indicators":{"cves":["CVE-2026-71485"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T21:17:08.707Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://github.com/centrifugal/centrifugo/commit/84d38cea1dd2efa24375a148817a974c8727f4b0","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/centrifugal/centrifugo/pull/1182","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/centrifugal/centrifugo/releases/tag/v6.9.0","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/centrifugal/centrifugo/security/advisories/GHSA-9468-v6mj-fppw","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-62834","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-62834 — Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attack…","description":"Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.","indicators":{"cves":["CVE-2026-62834"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:43.070Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62834","label":"secure@microsoft.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-63509","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-63509 — Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over…","description":"Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.","indicators":{"cves":["CVE-2026-63509"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:46.963Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63509","label":"secure@microsoft.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-65770","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-65770 — Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed…","description":"Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.","indicators":{"cves":["CVE-2026-65770"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:52.010Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65770","label":"secure@microsoft.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-65801","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-65801 — Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to e…","description":"Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.","indicators":{"cves":["CVE-2026-65801"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:54.897Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65801","label":"secure@microsoft.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-65816","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-65816 — Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevat…","description":"Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.","indicators":{"cves":["CVE-2026-65816"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:55.597Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65816","label":"secure@microsoft.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-66309","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-66309 — Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges ov…","description":"Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.","indicators":{"cves":["CVE-2026-66309"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:55.790Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66309","label":"secure@microsoft.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-68782","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-68782 — Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Da…","description":"Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.","indicators":{"cves":["CVE-2026-68782","CVE-2026-68789"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:57.020Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68782","label":"secure@microsoft.com","domainType":"primary"},{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68789","label":"secure@microsoft.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-69400","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-69400 — Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps a…","description":"Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.","indicators":{"cves":["CVE-2026-69400"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:59.783Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69400","label":"secure@microsoft.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-69555","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-69555 — Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a ne…","description":"Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.","indicators":{"cves":["CVE-2026-69555"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:18:00.477Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69555","label":"secure@microsoft.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-69836","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-69836 — Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute c…","description":"Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.","indicators":{"cves":["CVE-2026-69836"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:18:00.740Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69836","label":"secure@microsoft.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-69851","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-69851 — Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevat…","description":"Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.","indicators":{"cves":["CVE-2026-69851"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:18:00.877Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69851","label":"secure@microsoft.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-72843","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-72843 — The customer update route in EverShop is declared with \"access\": \"public\" in packages/evershop/src/m…","description":"The customer update route in EverShop is declared with \"access\": \"public\" in packages/evershop/src/modules/customer/api/updateCustomer/route.json, which causes the admin authentication middleware to call next() without checking the caller, and no customer-session middleware guards the route; the onl…","indicators":{"cves":["CVE-2026-72843"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:18:05.253Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://github.com/evershopcommerce/evershop","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/evershopcommerce/evershop/blob/v2.1.2/packages/evershop/src/modules/customer/api/updateCustomer/route.json","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/evershopcommerce/evershop/blob/v2.1.2/packages/evershop/src/modules/customer/api/updateCustomer/updateCustomer.js","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/evershopcommerce/evershop/issues/952","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/evershopcommerce/evershop/releases/tag/v2.2.1","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://www.vulncheck.com/advisories/evershop-missing-authorization-on-patch-api-customers-id-allows-unauthenticated-account-takeover","label":"disclosure@vulncheck.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-77645","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-77645 — A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC Flex…","description":"A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.","indicators":{"cves":["CVE-2026-77645"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:18:06.510Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://www.ptc.com/en/support/article/CS474826","label":"0b655efc-079c-4cb9-9e8d-164871239f4e","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-77647","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-77647 — SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited i…","description":"SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identification of <?php blocks, and var_export's mishandling of certain cases such as presence of a '<' character.","indicators":{"cves":["CVE-2026-77647"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T23:16:28.647Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-4-20.html","label":"cve@mitre.org","domainType":"other"},{"url":"https://lists.debian.org/debian-security-announce/2026/msg00359.html","label":"cve@mitre.org","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-77649","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-77649 — The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project…","description":"The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.","indicators":{"cves":["CVE-2026-77649"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["botnet"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-21T01:17:01.837Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref","label":"cve@mitre.org","domainType":"other"},{"url":"https://github.com/rustsec/advisory-db/issues/3161","label":"cve@mitre.org","domainType":"primary"},{"url":"https://rustsec.org/advisories/RUSTSEC-2026-0266.html","label":"cve@mitre.org","domainType":"other"},{"url":"https://safedep.io/arrayref-proc-macro1-rust-build-time-malware/","label":"cve@mitre.org","domainType":"other"},{"url":"https://www.stepsecurity.io/blog/arrayref-rust-crate-supply-chain-attack","label":"cve@mitre.org","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-77650","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-77650 — The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a pr…","description":"The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.","indicators":{"cves":["CVE-2026-77650"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["botnet"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-21T01:17:01.993Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref","label":"cve@mitre.org","domainType":"other"},{"url":"https://github.com/rustsec/advisory-db/issues/3161","label":"cve@mitre.org","domainType":"primary"},{"url":"https://rustsec.org/advisories/RUSTSEC-2026-0262.html","label":"cve@mitre.org","domainType":"other"},{"url":"https://safedep.io/arrayref-proc-macro1-rust-build-time-malware/","label":"cve@mitre.org","domainType":"other"},{"url":"https://www.stepsecurity.io/blog/arrayref-rust-crate-supply-chain-attack","label":"cve@mitre.org","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-77651","source":"nvd","category":"vulnerability","severity":"critical","title":"CVE-2026-77651 — The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project…","description":"The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.","indicators":{"cves":["CVE-2026-77651"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["botnet"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-21T01:17:02.140Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref","label":"cve@mitre.org","domainType":"other"},{"url":"https://github.com/rustsec/advisory-db/issues/3161","label":"cve@mitre.org","domainType":"primary"},{"url":"https://rustsec.org/advisories/RUSTSEC-2026-0260.html","label":"cve@mitre.org","domainType":"other"},{"url":"https://safedep.io/arrayref-proc-macro1-rust-build-time-malware/","label":"cve@mitre.org","domainType":"other"},{"url":"https://www.stepsecurity.io/blog/arrayref-rust-crate-supply-chain-attack","label":"cve@mitre.org","domainType":"other"}],"feedLabel":null},{"id":"abuseip-213.209.159.241","source":"abuse-ipdb","category":"ip-reputation","severity":"critical","title":"Malicious IP: 213.209.159.241","description":"Country: DE | ISP: unknown | Abuse score: 100%","indicators":{"cves":[],"ips":["213.209.159.241"],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":100,"publishedAt":"2026-08-21T02:17:02.000Z","fetchedAt":"2026-08-21T03:00:00.167Z","references":[{"url":"https://www.abuseipdb.com/check/213.209.159.241","label":"AbuseIPDB","domainType":"primary"}],"feedLabel":null},{"id":"abuseip-64.62.197.138","source":"abuse-ipdb","category":"ip-reputation","severity":"critical","title":"Malicious IP: 64.62.197.138","description":"Country: US | ISP: unknown | Abuse score: 100%","indicators":{"cves":[],"ips":["64.62.197.138"],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":100,"publishedAt":"2026-08-21T02:17:02.000Z","fetchedAt":"2026-08-21T03:00:00.167Z","references":[{"url":"https://www.abuseipdb.com/check/64.62.197.138","label":"AbuseIPDB","domainType":"primary"}],"feedLabel":null},{"id":"abuseip-119.92.70.82","source":"abuse-ipdb","category":"ip-reputation","severity":"critical","title":"Malicious IP: 119.92.70.82","description":"Country: PH | ISP: unknown | Abuse score: 100%","indicators":{"cves":[],"ips":["119.92.70.82"],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":100,"publishedAt":"2026-08-21T02:17:02.000Z","fetchedAt":"2026-08-21T03:00:00.167Z","references":[{"url":"https://www.abuseipdb.com/check/119.92.70.82","label":"AbuseIPDB","domainType":"primary"}],"feedLabel":null},{"id":"abuseip-195.26.18.111","source":"abuse-ipdb","category":"ip-reputation","severity":"critical","title":"Malicious IP: 195.26.18.111","description":"Country: UA | ISP: unknown | Abuse score: 100%","indicators":{"cves":[],"ips":["195.26.18.111"],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":100,"publishedAt":"2026-08-21T02:17:02.000Z","fetchedAt":"2026-08-21T03:00:00.167Z","references":[{"url":"https://www.abuseipdb.com/check/195.26.18.111","label":"AbuseIPDB","domainType":"primary"}],"feedLabel":null},{"id":"abuseip-181.115.171.216","source":"abuse-ipdb","category":"ip-reputation","severity":"critical","title":"Malicious IP: 181.115.171.216","description":"Country: BO | ISP: unknown | Abuse score: 100%","indicators":{"cves":[],"ips":["181.115.171.216"],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":100,"publishedAt":"2026-08-21T02:17:01.000Z","fetchedAt":"2026-08-21T03:00:00.167Z","references":[{"url":"https://www.abuseipdb.com/check/181.115.171.216","label":"AbuseIPDB","domainType":"primary"}],"feedLabel":null},{"id":"abuseip-118.196.68.35","source":"abuse-ipdb","category":"ip-reputation","severity":"critical","title":"Malicious IP: 118.196.68.35","description":"Country: CN | ISP: unknown | Abuse score: 100%","indicators":{"cves":[],"ips":["118.196.68.35"],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":100,"publishedAt":"2026-08-21T02:17:01.000Z","fetchedAt":"2026-08-21T03:00:00.167Z","references":[{"url":"https://www.abuseipdb.com/check/118.196.68.35","label":"AbuseIPDB","domainType":"primary"}],"feedLabel":null},{"id":"abuseip-79.124.59.178","source":"abuse-ipdb","category":"ip-reputation","severity":"critical","title":"Malicious IP: 79.124.59.178","description":"Country: BG | ISP: unknown | Abuse score: 100%","indicators":{"cves":[],"ips":["79.124.59.178"],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":100,"publishedAt":"2026-08-21T02:17:01.000Z","fetchedAt":"2026-08-21T03:00:00.167Z","references":[{"url":"https://www.abuseipdb.com/check/79.124.59.178","label":"AbuseIPDB","domainType":"primary"}],"feedLabel":null},{"id":"abuseip-79.124.56.142","source":"abuse-ipdb","category":"ip-reputation","severity":"critical","title":"Malicious IP: 79.124.56.142","description":"Country: BG | ISP: unknown | Abuse score: 100%","indicators":{"cves":[],"ips":["79.124.56.142"],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":100,"publishedAt":"2026-08-21T02:17:01.000Z","fetchedAt":"2026-08-21T03:00:00.167Z","references":[{"url":"https://www.abuseipdb.com/check/79.124.56.142","label":"AbuseIPDB","domainType":"primary"}],"feedLabel":null},{"id":"abuseip-68.225.61.18","source":"abuse-ipdb","category":"ip-reputation","severity":"critical","title":"Malicious IP: 68.225.61.18","description":"Country: US | ISP: unknown | Abuse score: 100%","indicators":{"cves":[],"ips":["68.225.61.18"],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":100,"publishedAt":"2026-08-21T02:17:01.000Z","fetchedAt":"2026-08-21T03:00:00.167Z","references":[{"url":"https://www.abuseipdb.com/check/68.225.61.18","label":"AbuseIPDB","domainType":"primary"}],"feedLabel":null},{"id":"abuseip-193.47.62.69","source":"abuse-ipdb","category":"ip-reputation","severity":"critical","title":"Malicious IP: 193.47.62.69","description":"Country: NL | ISP: unknown | Abuse score: 100%","indicators":{"cves":[],"ips":["193.47.62.69"],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":100,"publishedAt":"2026-08-21T02:17:01.000Z","fetchedAt":"2026-08-21T03:00:00.167Z","references":[{"url":"https://www.abuseipdb.com/check/193.47.62.69","label":"AbuseIPDB","domainType":"primary"}],"feedLabel":null},{"id":"abuseip-163.7.9.55","source":"abuse-ipdb","category":"ip-reputation","severity":"critical","title":"Malicious IP: 163.7.9.55","description":"Country: ID | ISP: unknown | Abuse score: 100%","indicators":{"cves":[],"ips":["163.7.9.55"],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":100,"publishedAt":"2026-08-21T02:17:01.000Z","fetchedAt":"2026-08-21T03:00:00.167Z","references":[{"url":"https://www.abuseipdb.com/check/163.7.9.55","label":"AbuseIPDB","domainType":"primary"}],"feedLabel":null},{"id":"abuseip-68.221.130.146","source":"abuse-ipdb","category":"ip-reputation","severity":"critical","title":"Malicious IP: 68.221.130.146","description":"Country: ES | ISP: unknown | Abuse score: 100%","indicators":{"cves":[],"ips":["68.221.130.146"],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":100,"publishedAt":"2026-08-21T02:17:01.000Z","fetchedAt":"2026-08-21T03:00:00.167Z","references":[{"url":"https://www.abuseipdb.com/check/68.221.130.146","label":"AbuseIPDB","domainType":"primary"}],"feedLabel":null},{"id":"abuseip-61.184.128.210","source":"abuse-ipdb","category":"ip-reputation","severity":"critical","title":"Malicious IP: 61.184.128.210","description":"Country: CN | ISP: unknown | Abuse score: 100%","indicators":{"cves":[],"ips":["61.184.128.210"],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":100,"publishedAt":"2026-08-21T02:17:01.000Z","fetchedAt":"2026-08-21T03:00:00.167Z","references":[{"url":"https://www.abuseipdb.com/check/61.184.128.210","label":"AbuseIPDB","domainType":"primary"}],"feedLabel":null},{"id":"abuseip-70.183.230.195","source":"abuse-ipdb","category":"ip-reputation","severity":"critical","title":"Malicious IP: 70.183.230.195","description":"Country: US | ISP: unknown | Abuse score: 100%","indicators":{"cves":[],"ips":["70.183.230.195"],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":100,"publishedAt":"2026-08-21T02:17:00.000Z","fetchedAt":"2026-08-21T03:00:00.167Z","references":[{"url":"https://www.abuseipdb.com/check/70.183.230.195","label":"AbuseIPDB","domainType":"primary"}],"feedLabel":null},{"id":"abuseip-47.254.134.254","source":"abuse-ipdb","category":"ip-reputation","severity":"critical","title":"Malicious IP: 47.254.134.254","description":"Country: DE | ISP: unknown | Abuse score: 100%","indicators":{"cves":[],"ips":["47.254.134.254"],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":100,"publishedAt":"2026-08-21T02:17:00.000Z","fetchedAt":"2026-08-21T03:00:00.167Z","references":[{"url":"https://www.abuseipdb.com/check/47.254.134.254","label":"AbuseIPDB","domainType":"primary"}],"feedLabel":null},{"id":"abuseip-4.206.92.183","source":"abuse-ipdb","category":"ip-reputation","severity":"critical","title":"Malicious IP: 4.206.92.183","description":"Country: CA | ISP: unknown | Abuse score: 100%","indicators":{"cves":[],"ips":["4.206.92.183"],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":100,"publishedAt":"2026-08-21T02:17:00.000Z","fetchedAt":"2026-08-21T03:00:00.167Z","references":[{"url":"https://www.abuseipdb.com/check/4.206.92.183","label":"AbuseIPDB","domainType":"primary"}],"feedLabel":null},{"id":"abuseip-45.148.10.240","source":"abuse-ipdb","category":"ip-reputation","severity":"critical","title":"Malicious IP: 45.148.10.240","description":"Country: NL | ISP: unknown | Abuse score: 100%","indicators":{"cves":[],"ips":["45.148.10.240"],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":100,"publishedAt":"2026-08-21T02:17:00.000Z","fetchedAt":"2026-08-21T03:00:00.167Z","references":[{"url":"https://www.abuseipdb.com/check/45.148.10.240","label":"AbuseIPDB","domainType":"primary"}],"feedLabel":null},{"id":"abuseip-194.88.98.114","source":"abuse-ipdb","category":"ip-reputation","severity":"critical","title":"Malicious IP: 194.88.98.114","description":"Country: DE | ISP: unknown | Abuse score: 100%","indicators":{"cves":[],"ips":["194.88.98.114"],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":100,"publishedAt":"2026-08-21T02:17:00.000Z","fetchedAt":"2026-08-21T03:00:00.167Z","references":[{"url":"https://www.abuseipdb.com/check/194.88.98.114","label":"AbuseIPDB","domainType":"primary"}],"feedLabel":null},{"id":"abuseip-181.116.43.25","source":"abuse-ipdb","category":"ip-reputation","severity":"critical","title":"Malicious IP: 181.116.43.25","description":"Country: AR | ISP: unknown | Abuse score: 100%","indicators":{"cves":[],"ips":["181.116.43.25"],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":100,"publishedAt":"2026-08-21T02:17:00.000Z","fetchedAt":"2026-08-21T03:00:00.167Z","references":[{"url":"https://www.abuseipdb.com/check/181.116.43.25","label":"AbuseIPDB","domainType":"primary"}],"feedLabel":null},{"id":"abuseip-45.249.246.17","source":"abuse-ipdb","category":"ip-reputation","severity":"critical","title":"Malicious IP: 45.249.246.17","description":"Country: HK | ISP: unknown | Abuse score: 100%","indicators":{"cves":[],"ips":["45.249.246.17"],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":100,"publishedAt":"2026-08-21T02:17:00.000Z","fetchedAt":"2026-08-21T03:00:00.167Z","references":[{"url":"https://www.abuseipdb.com/check/45.249.246.17","label":"AbuseIPDB","domainType":"primary"}],"feedLabel":null},{"id":"threatfox-1883554","source":"threatfox","category":"threat-intel","severity":"critical","title":"payload_delivery: undefined","description":"https://honeylabs.net/lookup/153.117.40.47","indicators":{"cves":[],"ips":[""],"domains":[""],"urls":[""],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["ClearFake","mac-0xdcf2","macOS","Cloudflare","gif","PHP","webshell","WordPress","workers.dev","wp-admin","21August2026","Commandline","mac-0x68dc","CobaltStrike","Vshell","8560","asyncrat","c2","censys","compromised","etherhide","ClickFix","etherhiding","AISURU","elf","IoT","Mozi","Remus","mac-0x76c7","drb-ra","mac-0x0f14","20August2026","ErrTraffic","Viper","Havoc","dcrat","PureHVNC","PureRAT","RAT","HypeAgent","Mythic","Supershell","1xxbot","ArechClient","SectopRAT","CinaRAT","Quasar RAT","QuasarRAT","Yggdrasil","sliver","ResolverRAT","ConnectWise","ScreenConnect","903ac24fcd9670b9ef2e674243d550d8","Loader","stealer","Vidar","RemusStealer","fake-plugin","nochain","SmartApeSG","win-0xa770","Windows","ValleyRAT","Kongtuke","AgentTesla","XWorm","Dropper","SocGholish","Pink","Adaptix","RevStealer","DomainShadowing","NEWTEST","Stealc","test_2","STRRAT","DanBot","CONTABO","CTFLoaderService","FakeAdobe","iso","LNK","pre-ransomware","velociraptor","cs-watermark-987654321","RemcosRAT","remcos","OffLoader","Socks5Systemz","Mirai","Vjw0rm","RedGuard","shodan","orcus","NetSupport","StarKillerC2","UNAM","AdaptixC2","PowerSploit","locust","GoPhish","phishing","cs-watermark-100000","Amos","nakedpages","Lud","36903","MetaSploit","fake-copilot","RedLineStealer","19August2026","njrat","Covenant","NeedleStealer","sliverfox","Gafgyt","rmm","117ee8f56cb68a9f6a440e1b4329f856","SparkRAT","ExtRat","XTRAT","Xtreme RAT","Agentemis","Beacon","Cobalt Strike","cobeacon","clipboard","ACRStealer","Mac","Breut","darkcomet","Fynloski","klovbot","Lumma","NanoCore","SnappyClient","Diamotrix","URLscan","EvilGinx","EvilGoPhish","CHAOS","x4tte","PureLogsStealer","LxBaseRAT","ProRat","Panda","EpsteinClient","NetSupportManager","NetSupportRAT","592a9e009f92c0e8eaea74a337b4f67c","capture-drop","honeypot","ssh-dropper","HTA","mexico","WhatsApp","sepolia","tofsee","web-inject","Spynote","HookBot","Byakugan","nc","gs-netcat","gsocket","moobot","nimplant","quasar","sectop","shadowpad","cs-watermark-1234567890","valleyrat_s2","8395ea90eca49b3f66c2a339ab377348","974b6b4ed30ddaa4b6f4ec27976e52d8","IRAHook","40999","45090","gated","poshc2","BianLian","PG","hook","Deimos","Magecart","userr","4-72","card-theft","COLOMBIA","otp-relay","phishing-kit","telegram-exfil","tg.pe","BlakcSeeStealer","726a8431d5d2ee941d0e6046b5948889","17August2026","Loki","DinDoor","16August2026","NetSupportManager RAT","Nancrat","NanoCore RAT","Remvio","Socmer","Bladabindi","Lime-Worm","Venom RAT","Farfli","Gh0st RAT","Ghost RAT","PCRat","Polygon","6c0969259a3975582cd8a48f4c8913d7","UnamPanel","v1","8075","329556","214961","kimwolf","5fdb6df778631818165110294c620890","a6416186c7730e38c492792c820881c3","majinahanashi","Ransomware","whack.sh","013c5d2d6312702c9bd8d7499170ed6b","aa462c8dcc4d1e29e6e35cbe1cd9ac85","build3","newbuild","0f81469cc7638ba7c82eaddbd6b3c20a","cs-watermark-666666666","Cloudflare Inc.","15August2026","mac-0xfb64","mac-0xe447","be6f50208246a51977f7066c1ea613a0","e9bf104a963da535b0fb5aaebe6f06e1","51c45d4bde39c5d7874e05e8c68314ca","14August2026","cc382e7a75ab8441eee2f40142be37ed","AnimateClipper","LegionLoader","SheetRAT","MintsLoader","build1","L1","WilsonC2","panel","PhantomStrikeC2","EvilgnixC2","Tr4nsHack","ZygiskC2","AuraStealer","domain","DPRK","kimsuky","MoonPeak","Stella","golang","zimbra","zimbra-exfil","ZMBX","workes.dev","14618","a77f04bc08864469eb801630c24264ba","AsynRAT","malware","d8b0m","ransomware","apt","botnet","infostealer"],"malwareFamily":"ClearFake","confidence":100,"publishedAt":"2026-08-21T01:59:50Z","fetchedAt":"2026-08-21T03:00:01.482Z","references":[{"url":"https://honeylabs.net/lookup/153.117.40.47","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/125.44.18.27","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/7e788bd6e7940f7c57dbfd94da87a48b4f36fad48c04a8bb1ba82971317f9023/","label":"ThreatFox","domainType":"primary"},{"url":"https://clickfix.carsonww.com/domains/apartments-review261634860.sbs","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/e313c09240d94d6f8aed6e6f4c802f1dce4e204cb7020e72d5344a8cd93b3b26/","label":"ThreatFox","domainType":"primary"},{"url":"https://clickfix.carsonww.com/domains/ksr-racingparts.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/www.accademiadeiromani.it","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/825fe5ad51d9ecb3f33cf9b1ff7d92ddc47192a3b4dba4cc67150b33f8863832/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/74a1e4dead91d597b2474e157272794d0c43c877d79565b3ce306331f0bfe8b0/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/178fd830163f46b127955422415f10d5f5a337212940ecfbb16f715b8ab2a711/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/75b78d8c29a3dbe369c38cff68dcd8a509f88fbdc5af1aac2d3684a3f2c3207e/","label":"ThreatFox","domainType":"primary"},{"url":"https://honeylabs.net/lookup/202.70.139.165","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/160.30.142.218","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/202.47.57.186","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/110.38.0.239","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/112.123.98.99","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/psicopress.com","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/0ec8cd5306167f1c4a1480d0fc5f09099834435ec6ea308c48eabaa8eb2cd019/","label":"ThreatFox","domainType":"primary"},{"url":"https://clickfix.carsonww.com/domains/zaeroks.website","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/einfach-einfach.digital","label":"ThreatFox","domainType":"other"},{"url":"https://infosec.exchange/@monitorsg/117128471193325362","label":"ThreatFox","domainType":"other"},{"url":"https://www.microsoft.com/en-us/security/blog/2026/05/06/clickfix-campaign-uses-fake-macos-utilities-lures-deliver-infostealers/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/b781b07429a51a7a9b786160ad9ac0bc037b7ee062d1f88b9aff2e42b292270b/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/d478ce0f1dfabc910bf785490d577bc6c85cc47c6a35ccb9e5ca220f56914016/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/73d3fc27bb8991f739e2d52007e5a466e24682e0595fc7b12c5e0fec6457827e/","label":"ThreatFox","domainType":"primary"},{"url":"https://infosec.exchange/@monitorsg/117128226111472251","label":"ThreatFox","domainType":"other"},{"url":"https://infosec.exchange/@monitorsg/117128234563756631","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/fibre-industries.de","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/serve2lead.com","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/91.92.47.97","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/dcf42e88c3688f575a490e5b51a7ecce9a930630e230523679736dd6b8ae4ce3/","label":"ThreatFox","domainType":"primary"},{"url":"https://clickfix.carsonww.com/domains/freedomfamiliesfoundation.org","label":"ThreatFox","domainType":"other"},{"url":"https://app.any.run/tasks/0ca35420-52dc-4fd4-b3e2-055e1e43dee0","label":"ThreatFox","domainType":"other"},{"url":"https://www.virustotal.com/gui/domain/ntc-redirect.akamai-live.workers.dev/relations","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/2f4b0265ae7f7d1672082a13211346c81ae1ae2f1ee6451851d4fa8a56d6469d/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/c5103eaa70a4a80176440a0e0dc75136a0e7bcfd9a68d7c8440a4d0edea72011/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/545df941a12726eececab025c21f30ca6b96f4dca86883b5e834d2084f40ff9e/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/ca2f6a6a991da93820340a30003176dcea7bd568175991fc5dfdb644a0d65bdc/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/a909567fd036f81727e0bda7da6d9993d8eeed60207cce185d8862b40f5a2220/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/f6117413027a3ddba78e3dcc7e975a626bf0e8f9ffe1dc5dd2387237b40f378f/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/f6faf9fc35489cec62820f6f3cc353e0af986d67314bdbd5a5abf4fa4c067a3a/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/9024eaf8b8c84042848edd66ad69c09afff1cceaaee314b2c550c07c85b1a8e5/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/8a802c9ee489aac5864b648bd3db2d1ec2db952001776582158df04d83b2d361/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/539d07048204358515864a5a896f1b92cc1b2cd40ec8d596380ba870eaf73324/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/6e482ca3bf3fcc53e4e91c43c50b1720a48090f3149fe7ff760c447a37c1ef04/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/03d9b9675a98583ec96b59fec63059641e320cbc8774de2dfa736ab06cd008b1/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/cd2cbf3277a263102361c9ee187e542c15ee02bc257dc17cd207f355f1d0f959/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/d2d5abf113cb0723ba13b3e4c2c007de844f19673bdae5639b53cd01bb6859ec/","label":"ThreatFox","domainType":"primary"},{"url":"https://honeylabs.net/lookup/190.196.253.119","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/223.123.44.122","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/103.176.16.59","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/116.140.6.114","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/103.225.191.202","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/153.117.40.170","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/110.186.229.108","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/115.57.182.131","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/183.63.8.194","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/f626335064988d1687d5bc75faee7a1ff782c84efb62ae539ca2b7a0809df3fd/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/b9eabf9c1e7eda061eb824e4d6eee8dcebfa10e85a45bbfd623c87169c2f7a8e/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/f636ff2834f3f113d068225ba9fa1465aa6211c183ef9b10a043382bce6bff3b/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/af4ee79582992e348a8739579da478d50daccbaa6ec97420311916a2ac0fc503/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/3922a4af520229c368788879ca8312fba656bb9b1285d91a8f62429e979ba6cf/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/e747deb0d49a53cda8ebc02a97c5eeb875d6b5b07e1be8dfac5545adb78760f6/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/616b0525deac1fecbfa3f4a3d08f09748a027c9a850521c5df13fa193970890b/","label":"ThreatFox","domainType":"primary"},{"url":"https://www.shodan.io/host/129.226.174.180#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/185.130.45.240#80","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/102.220.160.204#10134","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/181.167.80.196#5603","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/78.186.49.17#1337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/193.233.130.223#80","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/94.249.230.177#80","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/152.32.133.192#7001","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/1.14.104.208#4321","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/50.6.44.138#4321","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/84.71.50.253#8443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/34.134.90.188#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/35.254.102.75#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/45.198.55.168#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/141.125.158.53#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/130.61.239.223#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/172.236.7.224#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/91.134.62.41#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/192.144.187.97#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/14.103.50.128#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/139.84.164.248#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/94.154.32.18#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/66.154.127.217#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/185.245.182.240#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/104.236.230.184#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/91.229.23.96#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/47.89.175.103#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/202.181.177.148#31337","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/c126a83d1def8e6458bdb92216892a0500984a979346676124c12a4b2dd4b41d/","label":"ThreatFox","domainType":"primary"},{"url":"https://www.shodan.io/host/64.176.175.194#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/103.253.75.155#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/51.77.46.205#7777","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/111.229.112.115#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/4.204.25.104#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/35.254.58.72#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/146.19.185.37#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/120.26.238.236#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/195.246.231.131#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/201.189.58.129#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/172.234.231.31#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/151.115.144.4#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/200.155.77.90#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/156.224.18.21#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/152.32.132.82#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/46.8.236.158#8090","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/47.84.50.235#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/52.56.222.66#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/8.219.220.240#7443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/104.199.132.123#10443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/52.147.196.140#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/137.59.110.53#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/156.224.18.21#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/82.29.71.121#8443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/81.69.15.52#51003","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/817067c431557ad88cd4fb18dc28a988a7a714f66b6b0f219cf9b03b5b665390/","label":"ThreatFox","domainType":"primary"},{"url":"https://clickfix.carsonww.com/domains/zaerkos.rest","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/proclean-ci.com","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/f94db5a93b19e1800be99cb0be2fb21794d3c89ccb588b53739a62c587bc20e6/","label":"ThreatFox","domainType":"primary"},{"url":"https://x.com/masaomi346/status/2089288204101066803","label":"ThreatFox","domainType":"other"},{"url":"https://x.com/skocherhan/status/2090166619435683931","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/sci-lumiere.ci","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/082370aaf679a20e722fec6c88ab73803063e34683b0106e11b0d1999508cec4/","label":"ThreatFox","domainType":"primary"},{"url":"https://clickfix.carsonww.com/domains/richplusglobal.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/meraapnabharat.ca","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/vidyalekha.co.in","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/vefasigorta.net","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/bathandyou.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/www.faceit-verification.help","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/noise.lat","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/hyperliquid-solana.xyz","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/taliy.sbs","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/tradegenius.sbs","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/sixpences.xyz","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/vvagyu.xyz","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/grvt.lat","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/cro-ent.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/essexfertilitystore.co.uk","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/cssfounder.us","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/shopforet.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/agendaurbanaribeira.gal","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/d684fb1e82d42041802c676440d58e964b19ae74e8e7669e84d15da1a1e9c7ee/","label":"ThreatFox","domainType":"primary"},{"url":"https://clickfix.carsonww.com/domains/palaciomaravilla.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/www.silviozamora.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/tarahenovin.ir","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/ovarquitectura.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/smdrsdptk.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/sevtapcapan.com.tr","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/www.uniticstudio.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/almomega.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/www.mciturkiye.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/www.masartech.io","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/jamesrichard.net","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/fixthatappliance.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/veryanjones.co.uk","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/drdolati.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/glenchua.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/mclropadetrabajo.cl","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/lovenet.org","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/avsafiyeyilmaz.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/izmirdellservisi.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/mjforwarding.pl","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/mgihub.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/monomit.com","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/60f3280493c50acf8ccc3b128177e714a7dd58dc5f89871ad6683ab1539b382c/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/4f92f1b658856b2662100c26dcd5f81525a74482b4fdebb16923ec27234f0a7e/","label":"ThreatFox","domainType":"primary"},{"url":"https://clickfix.carsonww.com/domains/mujerilumina.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/namaste.cat","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/saatavukatlikburosu.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/rotariosjurica.org","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/ofi-med.pl","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/onlinetarabar.ir","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/openmedia.ro","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/obesidadydiabetes.info","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/pasoapasofam.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/necckaduna.gov.ng","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/necckaduna.com.ng","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/thesomersetlocal.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/stomatolog-rybnik.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/smartheartboardgame.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/tmtweld.pl","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/sibilphone.ir","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/theset.co.za","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/spiritofadventureacademy.com","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/65af8ffdecfc2394c2a27c6d53880ad5b89de8fd201a69d33a34e31e320a3a5d/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/440cb05dbc1425d4e40e70c260ac1aed00152c2d348ecb7c87aa7a8198cd9eae/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/50774a5f75176f9698fc536e82a6106c04ccd1db4f1d788574fdb288952c6d7b/","label":"ThreatFox","domainType":"primary"},{"url":"https://clickfix.carsonww.com/domains/valokse.lol","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/c4227301dd23eb6ebd80bf1f5e48455413ba78cf1a33be2296a857618d5588dd/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/2dae1df14d0cc6ea8e670e0b327101d0fe5c475dc06a376e99a6df426bddf418/","label":"ThreatFox","domainType":"primary"},{"url":"https://x.com/solostalking/status/2089616109213569336","label":"ThreatFox","domainType":"other"},{"url":"https://x.com/tdatwja/status/2089986369544405063","label":"ThreatFox","domainType":"other"},{"url":"https://x.com/tdatwja/status/2089996616359174472","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/5d5f894ef71d10255620990abd68ba7ef14b7da956f6317375e9adbe04f2e5a5/","label":"ThreatFox","domainType":"primary"},{"url":"https://clickfix.carsonww.com/domains/varzeshsb.ir","label":"ThreatFox","domainType":"other"},{"url":"https://x.com/skocherhan/status/2090111458142994915","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/dugrangranitos.com.br","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/39a180aeadc544e9423433352159ebc88407455a24eb9f0c266b1e78e134ac8f/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/490ab4a48bebf291311d3c71046e2b3d44d846401f5258b8e1f96355c7e7c3fd/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/1da3b9d89c8932b5597e752fe1468ebe236d21328a2453769624f69becf05656/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/2d91a4c89713cfa5e9435141be213b568d9094b5e8d0f50f392140b019ddbd43/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/b3e1379e763c84c598fbf49006b46b6df57499efbaf6d018fdc5b236c756cdd8/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/edaff13bad2401227db98e70ecef36c910a4ad7079796b03da6a7977e3b7713c/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/8e11c717fa2e8c37b5f1ed695d8c8e1898d4e1f40a976e79ece0a8f4260fa9b4/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/1d1764ee1c71dd5da7339e1ac13b84fc6d041782ba66cd310bf268184fb43951/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/94ac07fc63269ca404c5f47a8298d92a227e8da5917e6fd3f96a1f06f90572b7/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/2d1ad9929558eff7927026b4b9286c03b75640431955d37d22b77b920198ed22/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/edb7f446f91211fcb38d3d38b69dc3e503a554a7b1399700af6aa4635266af15/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/684716407fac9db2bf2540db8c7c74928b98dbfbebeae2181d7bd0aa73656a31/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/ab81e32fd9260645a5a4e6534a69d4a8c8db5e5c873a2a8f5aae600902bd4a8c/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/d9630814908b32ab2454226015db48cc39f32f6a6fc0829367b5fe7f6db5161b/","label":"ThreatFox","domainType":"primary"},{"url":"https://infosec.exchange/@monitorsg/117122578470569567","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/207410d97d1af036297be90cf72c1a7bbd209a891beddfec222f19a081c346fa/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/6e15ca7dd35f30060885ed042912b306388abe7085bfdf3d3716df95a1f9459c/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/d3840bcd452fbd7df0083393d79e5848192231195a7242a018c0b8a991e3d3f8/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/cce3ddac2dbcaf1a4f4db50b48fcc4e65341096b51c7bc6c13e7bd98c867e1f2/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/71e5bb794cf80e7bfeae891138b6acaf5d391f75dd665d5ea7c6e024df8e2f9d/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/cd77dd458f512935cc8912da7964570f1efe44bb497968204877890b397bbfac/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/7ff4fe3f3d7784da58e257cc7ea7e4f7ce63255817e4b79be123144d3027cd62/","label":"ThreatFox","domainType":"primary"},{"url":"https://honeylabs.net/lookup/45.120.161.86","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/kalekos.world","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/1d62a76d0311297527849b772fcb42eb964d10bbb0eeced50d7b83a94a9e7ef7/","label":"ThreatFox","domainType":"primary"},{"url":"https://urlscan.io/result/01a0196e-970b-7389-a7a8-fecf720b7752","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/4bba11f8ae554be3cabbd44c1e67dde6a85c7f192e645c7aea7e35617ea38def/","label":"ThreatFox","domainType":"primary"},{"url":"https://urlscan.io/result/01a0196c-0490-779b-bb63-ec40c2fb4817","label":"ThreatFox","domainType":"other"},{"url":"https://urlscan.io/result/01a01969-5ab9-746e-9db5-2a93416478af","label":"ThreatFox","domainType":"other"},{"url":"https://urlscan.io/result/01a01969-56a4-7177-848c-25f5881151bf","label":"ThreatFox","domainType":"other"},{"url":"https://urlscan.io/result/01a01969-5336-708a-b813-7d1eaeea4a14","label":"ThreatFox","domainType":"other"},{"url":"https://urlscan.io/result/01a01968-e30d-745f-b07e-8609e729e5de","label":"ThreatFox","domainType":"other"},{"url":"https://urlscan.io/result/01a01968-cb76-7209-b7c6-c9dfc1e5f24b","label":"ThreatFox","domainType":"other"},{"url":"https://urlscan.io/result/01a01968-b996-744c-ab29-54c66343f2fb","label":"ThreatFox","domainType":"other"},{"url":"https://urlscan.io/result/01a01968-bb2a-772f-97fc-c5ece7061207","label":"ThreatFox","domainType":"other"},{"url":"https://urlscan.io/result/01a01968-bcee-718a-9e4c-b53c75894e11","label":"ThreatFox","domainType":"other"},{"url":"https://urlscan.io/result/01a01968-b695-766b-92ad-e95c23b1341a","label":"ThreatFox","domainType":"other"},{"url":"https://urlscan.io/result/01a01968-b321-708f-a23a-b80f2192d2da","label":"ThreatFox","domainType":"other"},{"url":"https://urlscan.io/result/01a01968-ade4-7031-a496-ccadf997859c","label":"ThreatFox","domainType":"other"},{"url":"https://urlscan.io/result/01a01968-abaa-7101-881d-980e5f6191e5","label":"ThreatFox","domainType":"other"},{"url":"https://urlscan.io/result/01a01968-a836-7291-82ef-16b53b2b4923","label":"ThreatFox","domainType":"other"},{"url":"https://urlscan.io/result/01a01968-a213-7670-be69-b2c06baab084","label":"ThreatFox","domainType":"other"},{"url":"https://urlscan.io/result/01a01968-a4e1-738a-8d47-b0b5b27574b5","label":"ThreatFox","domainType":"other"},{"url":"https://urlscan.io/result/01a01968-9e1a-7660-a50f-578e7113fb65","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/3e5ee46a8876358fbf020a710c1107f8d04812a22cbc47e39241594b7b1cd159/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/9768b7e31324805672cfcba91cf4d6da91494e9899db58f22da9dda6c91931d6/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/92b4af0bd6c1e058c9cce2fe34272ce6e15d5039aa57ac489022127aaafbdc3d/","label":"ThreatFox","domainType":"primary"},{"url":"https://clickfix.carsonww.com/domains/kakabrands.com","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/b7c60bc7570406370984e95e12934ecb7e935558d473e9444cee85951d202c67/","label":"ThreatFox","domainType":"primary"},{"url":"https://clickfix.carsonww.com/domains/casaandaimemarica.com.br","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/one1ppp.com.pk","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/speed.hirebiz.pro","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/autosolutionsconnect.com","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/64494586d79711a0c12ad714f5f895a5d14200247cc02f0434f2bcd8b3b8002f/","label":"ThreatFox","domainType":"primary"},{"url":"https://clickfix.carsonww.com/domains/topqualityroofingsolutionsltd.co.uk","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/120.48.63.129#8090","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/38.247.165.127#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/118.122.8.157#7634","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/112.45.129.157#7634","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/44.195.73.113#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/3.129.203.73#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/192.169.176.54#449","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/13.51.79.99#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/45.76.0.96#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/45.197.12.73#8888","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/38.190.245.20#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/138.16.160.172#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/5.189.145.93#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/212.50.234.154#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/185.207.154.238#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/185.208.175.18#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/45.39.60.110#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/2.58.197.179#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/192.169.176.54#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/62.3.32.232#1337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/103.79.118.60#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/45.136.13.14#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/81.17.101.18#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/34.69.181.211#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/172.234.208.153#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/20.82.45.152#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/157.245.42.93#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/57.129.100.77#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/138.2.168.165#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/34.57.211.177#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/34.60.126.85#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/34.80.62.77#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/195.66.24.49#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/136.110.112.87#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/34.138.65.248#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/85.210.172.79#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/34.16.89.64#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/194.156.67.69#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/42.117.13.122#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/154.12.24.149#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/54.250.85.43#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/23.149.36.116#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/43.203.36.6#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/38.60.216.38#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/106.13.186.173#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/134.209.219.114#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/167.233.157.154#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/43.156.210.9#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/195.245.229.109#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/62.171.176.111#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/8.130.81.118#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/167.71.105.40#4545","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/63.88.138.76#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/40.81.184.48#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/15.224.148.171#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/62.234.144.140#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/137.131.157.110#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/80.225.78.233#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/14.103.129.205#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/3.148.207.89#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/50.78.48.241#9443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/159.75.110.224#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/119.45.198.250#55555","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/118.24.42.214#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/172.232.97.189#4444","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/47.251.29.219#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/47.254.68.68#50050","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/8910f0cb2eb97c3b1ced8b512bb34884a958ba7d81829841b2e60eb487157662/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/1863c944ff0f5f06cafe0f98d6a6f54084ac266936c0dbc16a9d13ab03dda421/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/837278104e5d4ed94c286bd8ea3845377fd03c2f1fa4b7b43555b9fca3455115/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/79990567c7458e6c7274f0d61011f9ce4718c47f76dec51a604182f182e3aac7/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/d0e5808cea92aa335ba889cb401a51506a13e79f5fe18c21a1e765c8f5c897a3/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/3b1d59c71cf19f0be3f66f4ad7d89e3593bbcd1c461b835f663bce969d07dc53/","label":"ThreatFox","domainType":"primary"},{"url":"https://infosec.exchange/@RecklessPush38671/117118098460752628","label":"ThreatFox","domainType":"other"},{"url":"https://x.com/skocherhan/status/2089830470884143452","label":"ThreatFox","domainType":"other"},{"url":"https://x.com/skocherhan/status/2089834462951408044","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/12c2152d740d079902e326329ab53a9ac76bae36858475b5e0af1c217c4d46c3/","label":"ThreatFox","domainType":"primary"},{"url":"https://honeylabs.net/lookup/223.123.43.192","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/103.190.23.91","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/153.117.13.31","label":"ThreatFox","domainType":"other"},{"url":"https://twitter.com/NullBlue67","label":"ThreatFox","domainType":"other"},{"url":"https://infosec.exchange/@monitorsg/117117856549686474","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/8437f141b392c50cb27717fef260b9bc0509178eb7919afe96b637b30cdca5d8/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/3dd9f794833b29db94173ee707a300162e388cf75357e494e328954b5d61c650/","label":"ThreatFox","domainType":"primary"},{"url":"https://infosec.exchange/@monitorsg/117118086922735381","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/ce97b609df1b5fe98cea4d8763bbd569d98ca7494a59ab0590cc9176e1907eb2/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/093db91d8a9c42faf74d6531eacab95e1175952a8defd0a86113ab92403e4f22/","label":"ThreatFox","domainType":"primary"},{"url":"https://clickfix.carsonww.com/domains/valeroks.click","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/0ecbba5d1aa1cfb32e96df6d6d7854929353733668ad1134256ec0451dc1a1da/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/2ecf04b3f001039184d841dd067d6e47bf192047ffe6b92c72a9d57bda6c6afe/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/1d65b76219f184a4fc87d597b0ae50e2ef6f98a79558448b0f0868f761c5479f/","label":"ThreatFox","domainType":"primary"},{"url":"https://clickfix.carsonww.com/domains/zillow-app.sbs","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/s3hsyuj2k.sbs","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/a2229d944a164ef74389757ff84f6ec5572db1be83d53399638c4efa6503a436/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/7219dc43efbd5d57c3b8af838ef26b2426483259c1c7b36a6e4e1d3c574496e0/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/cc900a5a94804cc09fa2009055e3ef4aca1e3b18b32358e8d9884da4d374712b/","label":"ThreatFox","domainType":"primary"},{"url":"https://clickfix.carsonww.com/domains/moat55.io","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/winrupees.com.pk","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/lankataxicabs.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/zs777game.net","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/86d57ebab870af93c1501db0a6c3404636174d0d5b5bffa493f956d77631c321/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/58711b6e9e099eebfb66358560d52878e75ed91d901fb95906d059a36500cdf3/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/2a45e6c914ff7da1d39558fc1ffb65d2a9e4422d37352957b17f1cabfdf7130c/","label":"ThreatFox","domainType":"primary"},{"url":"https://clickfix.carsonww.com/domains/bytesolving.info","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/3pattipkr.com.pk","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/777szgame.pk","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/dk999app.com.pk","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/galonz.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/clubpkgame.vip","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/www.detoxiones.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/gbazzar.in","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/caltexpoint.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/bit2solutions.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/8jjbetgame.net","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/imworthdefending.org","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/pakaviator.net.pk","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/pakaviatoor.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/pak365game.pk","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/www.makttravels.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/k666game.pk","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/leannepearson.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/laverie-saint-marc.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/laprensadecojedes.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/kitkateventz.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/www.jahmadartstudio.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/techfixlogic.info","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/unifm1027.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/s92bet.net","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/spinwinpkgame.net","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/rr3game.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/royalpkr.pk","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/purekhaddo.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/pkcasino.org","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/winbdd.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/thetechinstruct.info","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/www.waouhmonde.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/vizanstudios.com","label":"ThreatFox","domainType":"other"},{"url":"https://urlscan.io/result/01a01540-1603-7265-8f1a-6a1bacb9caa3","label":"ThreatFox","domainType":"other"},{"url":"https://urlscan.io/result/01a01540-0f06-741a-bffe-2ee85e355ad7","label":"ThreatFox","domainType":"other"},{"url":"https://urlscan.io/result/01a01540-129d-75eb-aef5-738f5db07371","label":"ThreatFox","domainType":"other"},{"url":"https://urlscan.io/result/01a01540-0d9d-77c1-b166-e653130406e3","label":"ThreatFox","domainType":"other"},{"url":"https://urlscan.io/result/01a01540-0a5f-779f-9c61-c0722357003b","label":"ThreatFox","domainType":"other"},{"url":"https://urlscan.io/result/01a0153c-39d1-76fe-bb7a-9cad63fb8d64","label":"ThreatFox","domainType":"other"},{"url":"https://urlscan.io/result/01a0153b-dd26-70c9-810f-0a92da97847e","label":"ThreatFox","domainType":"other"},{"url":"https://urlscan.io/result/01a0153b-d9b1-735e-af74-6f9364a5f512","label":"ThreatFox","domainType":"other"},{"url":"https://urlscan.io/result/01a0153b-d761-76ae-94c6-1321e33fa9cc","label":"ThreatFox","domainType":"other"},{"url":"https://urlscan.io/result/01a0153b-1ef3-77a8-a6f7-a5699de3113d","label":"ThreatFox","domainType":"other"},{"url":"https://urlscan.io/result/01a01538-eca2-731f-b144-aa3495f014cb","label":"ThreatFox","domainType":"other"},{"url":"https://urlscan.io/result/01a01538-e5e2-71b4-b36f-40282c0d5876","label":"ThreatFox","domainType":"other"},{"url":"https://infosec.exchange/@monitorsg/117116679039975377","label":"ThreatFox","domainType":"other"},{"url":"https://infosec.exchange/@monitorsg/117116685559499326","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/c36f519a225ba04a6d463bd7f09428f695f0281fd5d8da0f6117a022b6b145aa/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/89e906327d8e85067e16f3eb077a4a891fd01773460363b235918035314703ea/","label":"ThreatFox","domainType":"primary"},{"url":"https://honeylabs.net/lookup/111.92.157.210","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/94.26.106.206#80","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/213.139.77.194#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/37.187.222.170#80","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/216.128.179.190#7443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/217.77.6.50#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/162.35.165.76#1337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/46.19.143.117#1337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/15.204.248.160#1337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/45.227.254.77#5000","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/5.188.87.210#5000","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/98.142.252.140#5000","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/91.238.181.7#5000","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/103.117.123.125#4433","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/64.90.10.227#8080","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/129.226.174.180#80","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/96.44.160.44#80","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/120.48.63.129#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/103.117.123.125#80","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/110.40.147.249#7777","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/23.106.131.15#8443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/122.114.12.82#12340","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/122.114.166.126#12340","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/89.23.110.250#4321","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/130.49.149.13#8010","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/186.244.227.52#9443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/186.244.227.27#9443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/104.244.89.232#4321","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/212.47.241.124#55555","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/159.203.165.107#4321","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/216.118.235.68#4321","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/186.244.227.104#9443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/52.128.231.154#4321","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/149.202.227.107#4321","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/216.126.236.168#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/34.145.5.205#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/64.227.176.189#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/141.125.111.183#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/141.98.154.146#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/172.233.168.65#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/20.223.13.151#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/173.212.213.138#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/220.158.194.222#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/172.232.176.54#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/164.52.199.72#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/62.244.225.145#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/203.185.67.223#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/77.237.239.166#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/35.200.224.221#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/35.194.54.154#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/136.66.108.120#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/45.79.246.83#8089","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/3.39.168.106#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/180.104.118.242#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/47.82.213.176#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/35.79.67.124#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/74.225.205.31#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/156.225.27.190#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/3.13.145.57#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/20.14.208.6#8443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/151.253.161.154#8443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/50.75.178.90#8080","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/18.223.6.45#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/84.68.26.77#8443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/91.231.11.17#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/92.27.20.99#8081","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/147.124.221.15#9443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/40.121.46.121#8444","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/171.33.196.226#8443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/94.72.98.60#8443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/82.64.37.175#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/135.236.152.188#8080","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/71.184.151.34#8443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/146.20.137.210#8443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/202.29.172.25#8080","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/51.52.39.37#8080","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/24.106.83.199#8443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/203.158.140.81#8443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/3.147.90.9#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/130.94.94.118#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/173.230.130.248#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/68.178.205.17#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/207.180.58.107#4443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/108.143.227.46#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/74.0.32.96#4443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/65.49.231.115#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/159.89.232.174#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/64.227.87.165#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/185.223.207.38#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/5.9.89.201#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/192.129.226.132#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/45.32.60.15#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/89.106.78.234#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/199.245.176.16#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/64.188.28.250#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/156.224.28.224#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/162.14.101.126#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/79.133.42.25#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/121.78.127.232#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/37.27.180.218#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/199.188.100.215#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/143.198.125.30#4443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/207.57.135.209#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/77.90.19.202#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/37.60.246.25#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/212.60.151.85#8443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/172.105.103.223#8443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/38.147.164.81#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/129.146.218.27#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/66.179.136.167#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/129.226.195.254#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/103.121.95.90#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/173.212.223.178#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/35.240.178.188#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/104.244.89.43#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/43.139.87.203#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/195.242.119.57#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/34.175.95.87#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/150.40.117.140#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/130.94.34.246#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/207.180.205.54#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/66.154.103.109#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/103.185.249.13#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/162.19.175.48#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/146.56.214.130#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/91.208.162.174#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/116.202.158.114#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/78.17.93.74#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/185.141.60.111#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/213.145.86.42#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/137.74.73.61#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/66.63.162.235#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/158.247.221.23#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/45.79.203.94#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/103.70.77.226#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/43.131.50.177#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/45.76.48.124#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/37.114.41.131#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/150.158.122.8#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/149.62.46.25#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/92.119.164.140#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/137.116.136.69#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/204.194.54.61#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/45.74.31.54#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/161.97.168.140#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/88.218.77.102#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/101.42.96.140#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/204.152.220.114#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/173.212.223.214#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/157.245.14.84#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/137.184.54.93#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/15.204.248.160#8443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/103.121.92.150#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/51.38.146.21#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/153.75.233.171#31337","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/178.33.157.230#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/85.215.56.158#8080","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/194.226.142.191#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/146.103.123.143#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/101.43.65.12#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/178.128.9.240#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/113.30.189.38#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/37.60.242.138#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/159.198.79.76#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/193.126.118.126#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/83.229.123.190#8080","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/31.70.83.235#8080","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/64.176.226.47#5555","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/51.77.47.134#7777","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/45.136.14.160#8080","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/194.68.44.212#2053","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/140.82.6.30#30001","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/172.105.40.31#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/204.168.238.206#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/138.36.238.226#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/161.97.184.153#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/185.202.238.199#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/95.0.200.36#8443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/79.76.52.42#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/20.71.123.165#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/136.119.232.128#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/157.230.7.157#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/151.145.54.26#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/157.230.109.184#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/35.195.56.119#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/51.38.142.130#7777","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/152.136.211.93#9999","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/43.218.88.179#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/118.25.137.16#8443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/64.227.136.20#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/107.174.39.59#8080","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/169.58.168.231#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/202.74.214.34#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/168.144.115.205#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/91.134.242.255#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/134.199.218.113#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/5.161.193.120#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/170.187.201.7#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/92.5.2.56#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/45.142.203.37#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/87.106.81.173#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/185.242.235.244#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/172.233.151.92#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/77.90.33.167#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/209.126.83.138#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/167.71.255.108#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/147.224.248.37#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/52.186.171.177#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/193.123.231.237#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/4.155.132.91#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/111.229.188.75#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/140.82.6.30#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/217.154.124.66#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/185.242.233.142#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/115.190.132.197#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/161.35.119.150#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/20.124.80.216#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/104.236.76.166#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/195.90.216.5#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/158.180.46.177#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/211.24.92.216#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/91.98.112.78#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/107.21.100.205#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/159.203.57.121#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/194.163.144.171#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/209.160.251.122#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/2.207.238.100#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/195.133.74.137#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/89.116.24.9#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/2.27.45.193#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/147.182.255.108#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/51.138.224.23#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/84.88.36.28#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/205.235.2.2#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/104.244.95.43#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/66.179.211.39#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/118.163.7.218#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/168.144.0.210#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/103.69.128.98#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/141.144.201.168#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/64.23.176.200#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/109.206.246.27#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/115.190.189.185#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/146.190.128.134#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/20.33.33.75#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/23.254.224.208#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/82.67.111.175#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/141.227.149.206#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/67.207.90.244#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/149.28.248.110#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/23.20.128.134#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/104.236.9.157#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/91.99.213.210#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/199.68.217.119#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/65.7.123.204#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/83.228.217.239#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/87.106.213.148#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/82.156.64.247#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/129.213.164.210#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/87.106.229.16#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/74.208.54.197#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/94.100.26.221#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/8.220.240.233#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/79.76.32.207#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/173.249.53.208#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/212.227.54.66#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/193.181.210.170#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/103.173.66.52#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/188.166.251.223#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/79.143.89.122#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/91.92.42.203#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/84.247.161.75#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/106.12.26.24#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/134.209.75.116#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/160.153.178.199#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/185.95.14.77#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/103.155.107.70#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/136.109.25.184#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/198.13.32.232#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/157.180.28.222#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/185.240.242.166#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/47.237.71.87#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/81.169.224.207#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/15.235.59.186#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/164.90.159.31#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/121.137.95.101#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/111.231.98.72#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/159.203.162.54#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/51.142.139.32#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/212.224.107.83#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/47.176.153.62#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/199.247.20.75#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/161.35.102.148#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/178.105.228.199#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/37.60.225.162#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/88.99.165.179#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/175.41.148.114#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/195.26.240.215#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/162.35.187.190#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/152.42.144.85#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/40.84.43.13#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/54.249.139.244#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/129.226.221.147#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/74.222.12.20#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/110.42.6.177#8443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/62.234.37.129#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/112.199.110.130#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/147.182.238.163#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/91.98.155.109#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/64.176.19.24#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/51.105.193.225#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/173.212.213.160#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/140.143.182.14#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/182.93.80.19#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/146.190.122.225#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/178.128.225.209#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/161.97.98.207#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/190.20.116.63#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/43.136.134.87#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/203.145.168.114#7887","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/91.107.198.222#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/138.197.40.76#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/89.167.116.198#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/140.82.6.30#30002","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/82.165.107.125#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/104.168.95.59#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/108.61.167.138#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/217.61.240.139#9205","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/206.189.187.187#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/149.210.237.27#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/64.23.221.249#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/57.129.100.65#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/67.207.80.64#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/86.54.29.105#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/103.236.60.111#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/85.111.86.99#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/137.184.205.40#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/84.247.165.18#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/103.179.44.58#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/114.132.49.100#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/81.95.108.92#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/81.68.238.141#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/129.121.84.227#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/101.34.243.103#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/35.214.74.71#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/77.38.125.37#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/147.182.183.223#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/178.156.174.122#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/204.168.253.216#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/67.207.93.220#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/167.114.114.51#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/145.132.81.61#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/23.254.233.159#8443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/88.99.165.179#8443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/216.238.121.111#8443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/51.89.191.93#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/61.28.131.37#8443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/210.16.65.37#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/134.209.9.147#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/1.14.193.53#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/35.77.200.163#80","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/38.179.64.13#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/211.24.89.101#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/4.188.67.185#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/217.160.244.124#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/209.97.157.78#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/207.246.95.182#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/192.210.135.124#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/95.0.200.36#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/34.128.95.189#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/107.172.90.224#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/51.79.146.29#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/138.199.144.32#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/51.83.76.215#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/185.198.74.29#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/164.132.40.255#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/103.27.133.120#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/183.237.211.34#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/154.9.232.209#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/120.48.51.184#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/36.212.223.87#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/195.228.150.125#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/51.15.238.70#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/200.58.109.89#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/185.84.47.181#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/51.15.139.207#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/201.161.34.130#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/77.95.252.240#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/145.241.98.7#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/159.89.44.68#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/162.43.55.101#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/43.166.246.26#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/51.81.254.201#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/60.251.233.186#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/162.19.224.70#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/146.59.83.148#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/4.152.69.149#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/37.187.226.148#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/62.235.177.215#8443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/162.243.39.41#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/65.49.232.115#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/143.198.25.46#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/169.58.3.208#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/172.188.59.225#8443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/152.32.189.145#9999","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/93.177.77.142#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/4.150.69.97#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/212.132.126.146#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/13.140.159.174#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/35.208.127.233#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/18.163.48.70#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/195.114.216.54#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/152.42.200.251#3333","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/94.23.121.241#7433","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/88.119.174.86#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/129.28.122.92#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/193.112.191.222#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/192.144.171.134#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/182.92.117.223#55000","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/198.199.72.177#7771","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/39.106.80.126#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/167.160.189.206#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/108.165.147.244#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/24.144.93.255#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/175.178.99.75#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/178.16.52.177#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/46.235.168.57#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/107.172.103.254#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/213.111.157.231#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/139.59.255.98#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/114.67.98.107#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/80.32.135.143#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/203.12.31.100#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/147.182.194.198#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/43.242.97.95#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/43.252.213.228#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/82.157.183.28#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/47.251.21.59#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/47.86.9.253#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/38.55.145.158#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/175.24.134.99#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/68.64.182.169#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/49.51.230.17#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/42.193.22.177#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/213.199.55.80#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/141.255.162.234#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/117.72.125.206#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/1.14.104.208#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/118.24.187.152#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/206.238.42.153#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/14.29.160.181#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/158.94.208.177#443","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/152.32.132.177#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/169.58.121.189#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/172.232.97.189#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/158.94.208.177#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/31.179.166.59#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/110.4.40.65#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/43.139.87.203#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/91.92.42.118#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/47.82.234.12#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/43.155.169.245#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/88.147.120.235#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/169.239.128.43#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/101.33.225.32#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/47.96.254.114#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/106.75.249.202#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/192.210.226.113#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/119.45.160.160#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/117.50.184.221#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/183.60.226.2#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/47.251.165.63#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/157.230.253.244#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/124.220.34.180#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/178.157.59.195#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/84.252.8.28#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/14.225.212.124#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/83.68.95.150#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/124.222.145.172#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/156.239.252.191#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/169.58.82.229#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/47.251.177.187#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/47.88.78.167#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/62.91.88.154#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/111.229.248.198#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/114.67.204.86#50050","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/9.205.158.119#80","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/98.80.179.181#80","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/47.82.234.12#8848","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/169.58.82.229#5556","label":"ThreatFox","domainType":"other"},{"url":"https://www.shodan.io/host/169.58.82.229#8055","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/7a42d5d51e97d4701f6b309508902faa5aea833bda338172d5c95f6fbb7f9a92/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/77ffb26f8837c388039a3ed7267003a46a7f1ca6c3c1ba9ceb46fce5702ebdae/","label":"ThreatFox","domainType":"primary"},{"url":"https://clickfix.carsonww.com/domains/chillifarmsukabumi.com","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/1692679c9f4e665f2570c0f7c9479288ae146755047b119388b07e74a20923fe/","label":"ThreatFox","domainType":"primary"},{"url":"https://honeylabs.net/lookup/202.9.122.47","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/36.255.33.118","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/891292d66392d8da0e92cf38abcb108a69e33fb1714f7920448301b1aa5094d5/","label":"ThreatFox","domainType":"primary"},{"url":"https://clickfix.carsonww.com/domains/sdsentura.com","label":"ThreatFox","domainType":"other"},{"url":"https://infosec.exchange/@monitorsg/117111648765961305","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/103.225.191.191","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/101.53.228.61","label":"ThreatFox","domainType":"other"},{"url":"https://infosec.exchange/@monitorsg/117112666763880038","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/111.92.157.255","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/175.107.3.113","label":"ThreatFox","domainType":"other"},{"url":"https://greedybear.honeynet.org","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/018937753ffa1fdc88796297948d82cff81b0b0beb1dae0335417b178eb581f2/","label":"ThreatFox","domainType":"primary"},{"url":"https://clickfix.carsonww.com/domains/bolerkas.shop","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/bolerkas.sbs","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/games.ccsam.ca","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/guiapergamino.com","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/797bcd9813c2c4f11e3abde7b4806e0d81531eaeb68dfa98d3482b7c9174a61d/","label":"ThreatFox","domainType":"primary"},{"url":"https://clickfix.carsonww.com/domains/klaragolez.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/exosia.ir","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/campfire-hospitality.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/www.bodycarer.xyz","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/formulaconsultoria.com.br","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/marjanalkhair.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/laboralmente.es","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/www.fabienne-mercier.fr","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/jzlightshow.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/harapouya.ir","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/realworldgrappling.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/koontyme.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/pptrans.sk","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/mpdumont.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/bventuretech.com.my","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/www.brefconcept.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/www.artemretouching.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/cyeller.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/ervindaneshazma.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/elitegorka.ru","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/archevive.fr","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/hbbuilding.vn","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/estudiogurugu.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/www.theatrecharbon.fr","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/www.sandomenicoets.it","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/www.statusplan.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/zetaclinic.it","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/ruthene-coachin.fr","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/leadvisiontw.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/ultraanalogic.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/journal-lb.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/savanamining.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/www.locksmithmn247.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/www.maketechnology.sk","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/oraville.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/lejardindunous.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/ejaz-sa.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/globalswissalliance.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/fccakebread.com","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/e2b6dbb5b5c44863df8e9e79a6c0d0c4d8fe7bfca346335fbfcd4dc6ca5f9010/","label":"ThreatFox","domainType":"primary"},{"url":"https://clickfix.carsonww.com/domains/apejese.org.br","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/smildner.de","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/www.smartbusiness.com.ec","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/windsorparknordic.ca","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/jbconstructionnyc.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/www.depannage-serrurier-91.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/ecomimperium.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/leitebrasil.com.br","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/www.havenpresents.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/purnama-4d.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/natuurlijkheidi.nl","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/modernfuji-ksa.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/chumak.io","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/leadsforest.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/bodychekwellness.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/helpgrandparents.org","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/172.168.179.87","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/139.135.45.135","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/shereegardnercogan.com","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/41a0fee35a8894c4ea476ea17f212ea0b08ec55cfe2e8caab209dd6015fcb3dc/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/fd7c3d18e60405f94ab0ae1aeccd609b803da3850e9950bc5104a646756db943/","label":"ThreatFox","domainType":"primary"},{"url":"https://clickfix.carsonww.com/domains/www.phonglong.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/simple88.net","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/glaube.at","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/www.singaporecasinogames.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/www.carolinajane.net","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/zonreizen.nl","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/planetwearz.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/www.newyorkcasinohotels.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/ope.com.br","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/asquareengineering.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/www.shaikhsalman.net","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/www.moqolobeaute.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/www.sudanfacts.org","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/pixs.jp","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/adlerbach.de","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/www.optimeg.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/www.talcgrindingmill.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/gbs-guinee.com","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/124.29.247.93","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/153.117.37.83","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/110.38.210.180","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/b41017f98f93938550a6655981a500ca5a5a97ea9503e3de89948f8d3cab057b/","label":"ThreatFox","domainType":"primary"},{"url":"https://honeylabs.net/lookup/105.224.117.178","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/125.42.11.109","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/69e6463c87739f2d4d0b345ba5f8954070926b13a43176a50ca4a8d7b64e3676/","label":"ThreatFox","domainType":"primary"},{"url":"https://clickfix.carsonww.com/domains/amanahkita.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/svtelindia.in","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/d5a72f54e4cea54ef1bd5ec023e4c62420c8f6a18098495babd4616b65b11718/","label":"ThreatFox","domainType":"primary"},{"url":"https://clickfix.carsonww.com/domains/pateriyaconsulting.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/loepaord.xyz","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/hermanoscalatayud.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/ikbenymp.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/thewadi.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/www.stateofwellness.org","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/multyshades.com","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/af12a273133b646805713254ad2012c5708be375c9dd1a3b11b3c2dd5811bc8c/","label":"ThreatFox","domainType":"primary"},{"url":"https://clickfix.carsonww.com/domains/avtomoyka.kiev.ua","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/kodech.fr","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/alwhda.se","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/www.devloerenboerderij.nl","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/absoluteav.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/mathabane.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/www.collomb.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/bellablumaternity.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/moleroos.pro","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/sparkwords.com","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/malware.dovgertz.com","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/85cd6c3229f9ab547cc54f2cbdcf6ef2937987c0181e5ffa3c4205105df8e8fe/","label":"ThreatFox","domainType":"primary"},{"url":"https://clickfix.carsonww.com/domains/www.kentertiyatrosu.org","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/www.mkperinat.com","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/ff8235089a02e71d422a0c227f177f14052b58d1558324a6001ded65418bb498/","label":"ThreatFox","domainType":"primary"},{"url":"https://clickfix.carsonww.com/domains/samid.com.br","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/470a41a0a6c204ac849fd7d224d81983fec2f27e91376a5025a6002508801639/","label":"ThreatFox","domainType":"primary"},{"url":"https://honeylabs.net/lookup/153.117.15.132","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/101.53.225.41","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/59.96.138.214","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/103.194.92.132","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/27.215.177.136","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/202.47.57.122","label":"ThreatFox","domainType":"other"},{"url":"https://urlquery.net/report/6f2942db-f30a-4faa-8fea-728840beebed","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/139.135.40.141","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/153.117.8.152","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/103.68.31.233","label":"ThreatFox","domainType":"other"},{"url":"https://x.com/skocherhan/status/2088682699129024911","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/61.173.162.42","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/103.26.86.217","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/1db6b60a7989a6c1dbba63d5a78463f5a4d4fbff75af27c281e1a93a11bfe4ad/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/c9698c118c2ba58fb2c7944354687333bd4f0d58ce5b6710920cdfa682bc9944/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/89a76ee1536416b632ddbfa183e001a875aea23fd30757fc21c3e4605431d942/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/250f9079f4018c6c1fed92b09b91e75222790a5f59379c4b7cb3185a9014f246/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/b4e869d592baf4370f850cbe71c7ae653ac1078646ef6633a4e769f6752b4d2e/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/cb1e15a47e40e7e1886531b829f4061c60b73ba4937e9161b4fc1fef846dfddb/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/997acaae90f21aebb154b75c2b2c787fa49e8d3d0cdf5c5893d6f7ddbb3d67b6/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/4b00c7ebad267025b84e7b4d1c996eaefec34a065913d73ee0070b119217d1be/","label":"ThreatFox","domainType":"primary"},{"url":"https://clickfix.carsonww.com/domains/cuuwa.ca","label":"ThreatFox","domainType":"other"},{"url":"https://theravenfile.com/2026/08/14/majinahanashi-ransomware-another-japanese-locker/","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/153.117.13.202","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/39.34.166.87","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/218.0.112.226","label":"ThreatFox","domainType":"other"},{"url":"https://infosec.exchange/@monitorsg/117095511868487413","label":"ThreatFox","domainType":"other"},{"url":"https://infosec.exchange/@monitorsg/117095683249617990","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/223.123.71.152","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/111.127.232.94","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/223.123.42.233","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/14.1.107.87","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/105.186.143.37","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/223.123.44.116","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/e65d6b1b86a1cca7c2290f1930306c47dded097c547878d1bad9fbf94a58ecc8/","label":"ThreatFox","domainType":"primary"},{"url":"https://honeylabs.net/lookup/144.48.132.151","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/153.117.6.98","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/14.205.104.200","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/172.168.171.137","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/144.48.134.114","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/lagerraum-mieten-luzern.ch","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/32c92e3a2f50c0d2e64bfaf78c6221de95cc23d4ca22045c70c8e237c60cf29f/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/cfabae2edf939f81d3fea8a50ba20555639cebd70afb58e0b2c18f820b75a9d0/","label":"ThreatFox","domainType":"primary"},{"url":"https://clickfix.carsonww.com/domains/flexsportpools.com","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/32c046428fa2df75cd8b454cfa6831930261f8e6f7c15e1adda189d15ba96d11/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/769c5186f40c16fa4e4871bf488301c01e89e3e94f1244f979e1b12b7f244ded/","label":"ThreatFox","domainType":"primary"},{"url":"https://clickfix.carsonww.com/domains/blaze-x.com","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/460001cd92917d1c8d4e538d0ec367abf02e6533e357083a8382a1e41f7be5ce/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/57478a0f3dcf4df1c96dbb3cd9aa3b255814bd3a4185bf90ba768eb28b471797/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/4f8b3ce56a567f4d1f5a3e4ef0fedcdfad707bfc1b4234397da600f8e2e32316/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/514fa7786356f49ad0e1164fec6fcfb3c2759db9c069beac2f89baa804f7d5fe/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/ad1f1c29707bba2a41e9d964abb63ff0dc764ea98c3e2a1e38a39dd2c7bcfd6b/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/1d118a9482bb8f30bb53c18c8441d5aa8b21ee823206c630238edf0f99ec568e/","label":"ThreatFox","domainType":"primary"},{"url":"https://clickfix.carsonww.com/domains/vuaketdinh.com","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/9fca5fad86800ea321191a1744a455d0d376d85970e9ae5781506292276f1a4a/","label":"ThreatFox","domainType":"primary"},{"url":"https://clickfix.carsonww.com/domains/wvtransportes.com.br","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/tkst.ac.th","label":"ThreatFox","domainType":"other"},{"url":"https://clickfix.carsonww.com/domains/www.thefootix.net","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/f3d0793c72028ec204e86a6156ed537433bd6d4dd1a020f90d7caa89b2d38e83/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/498a5fedae9ec61339e1003a47f67834fb51a10866129b7228dcc16fa863e936/","label":"ThreatFox","domainType":"primary"},{"url":"https://clickfix.carsonww.com/domains/befaes.mom","label":"ThreatFox","domainType":"other"},{"url":"https://bazaar.abuse.ch/sample/23437ab4e1de0de7907be7b9ba43454d85be19e4ff5476ae9154e6fe1cab922b/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/d93f8957f5467e4ba5bf1f6ea0fa38c4e9d22f1b8eb94baf74212b1405adaa3c/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/61366dc491bce133ceaeb4f1e93250b85431f99e9b5411ebea36c3f25a9b7467/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/e61dd367859cf5e495a86ecaa7fa084ae84c1e38a049a68e03813e657651b192/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/5334ab4eafeb63eaeab2d69bdfedf38cb92ed5d88dfe96564171cdfa22e3da17/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/9d435f7547926c1259d52301f8d95a28b0e39c0275a47d3b0e42cc81ef72e252/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/1a2f081585e05540a72ceb36178f9549ff5bc3c6505fddb6565b887aa55f54a3/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/97846a49e8314d0d097da1590e04decb5e1570fdaf27157c91e211038dd5eeeb/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/71aa9766db343fa5de8e83e8d8eef912df3f7396116cd7ceef34631dd46ea2ad/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/92f8f069c032422eb6048ce1a648bd140dab9d3cfca5c855e2b56e1ac6f1cc7b/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/63963fc9dede449e5e40520f6c40e34888ef2cc0fa459772437ec6b69f44267e/","label":"ThreatFox","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/191dccb04b3a98cf557a8bd994c6b8df433782653a3fa445bfa86ad5e6a5928a/","label":"ThreatFox","domainType":"primary"},{"url":"https://urlquery.net/queue/8565a541-dff7-49ef-9d5b-6778be8ab6ae","label":"ThreatFox","domainType":"other"},{"url":"https://urlquery.net/report/b17f966b-a7e8-4ab2-b17b-df77d504294a","label":"ThreatFox","domainType":"other"},{"url":"https://urlquery.net/queue/e2cf8499-4168-451f-b4a6-6a9e52b0a0f7","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/202.63.202.222","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/175.107.221.53","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/72.255.32.20","label":"ThreatFox","domainType":"other"},{"url":"https://lazarus.day/iocs/107.172.249.140/","label":"ThreatFox","domainType":"other"},{"url":"https://otx.alienvault.com/pulse/6a7e3df9ee68883c34577fe1","label":"ThreatFox","domainType":"primary"},{"url":"https://www.virustotal.com/gui/file/3c602fcb3fc8cecffc99454fa64e9ff28182d13b280055e4dce30d31210cb2f2","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/105.184.49.165","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/36.70.68.244","label":"ThreatFox","domainType":"other"},{"url":"https://honeylabs.net/lookup/115.50.94.75","label":"ThreatFox","domainType":"other"}],"feedLabel":null},{"id":"news-critical-elementor-pro-bug-exposes-wordpress-sites-to-rce-attacks","source":"general-news","category":"news","severity":"critical","title":"Critical Elementor Pro bug exposes WordPress sites to RCE attacks","description":"A critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote code execution on the server. [...]","indicators":{"cves":[],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T14:39:48.000Z","fetchedAt":"2026-08-21T03:00:02.308Z","references":[{"url":"https://www.bleepingcomputer.com/news/security/critical-elementor-pro-bug-exposes-wordpress-sites-to-rce-attacks/","label":"BleepingComputer","domainType":"media"}],"feedLabel":null},{"id":"news-threatsday-gogs-10-0-rce-n8n-workflow-to-rce-10m-reward-glm-5-3-ai-exploit-and-m","source":"general-news","category":"news","severity":"critical","title":"ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More","description":"A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do.\n\nSigned drivers get turned against defenses. Legitimate apps help malware blend in. A weak header check opens a path to code execution. Elsewhere, exposed systems, old bugs, odd hiding tricks, and AI-…","indicators":{"cves":[],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:23:48.000Z","fetchedAt":"2026-08-21T03:00:02.309Z","references":[{"url":"https://thehackernews.com/2026/08/threatsday-gogs-100-rce-n8n-workflow-to.html","label":"The Hacker News","domainType":"media"}],"feedLabel":null},{"id":"nvd-CVE-2026-76633","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-76633 — WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that a…","description":"WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that allows any authenticated user to change their account password without providing existing credentials by exploiting the unconditional exclusion of the alterarSenha method from permission checks in cont…","indicators":{"cves":["CVE-2026-76633"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T14:17:59.680Z","fetchedAt":"2026-08-21T03:01:29.087Z","references":[{"url":"https://github.com/LabRedesCefetRJ/WeGIA/releases#release-3.9.2","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-gfcx-7973-hjmp","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://www.vulncheck.com/advisories/wegia-authorization-bypass-password-change-via-alterarsenha","label":"disclosure@vulncheck.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-76635","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-76635 — baserCMS before 5.3.0 contains a SQL injection vulnerability in BcDatabaseService.php that allows au…","description":"baserCMS before 5.3.0 contains a SQL injection vulnerability in BcDatabaseService.php that allows authenticated administrators to inject attacker-controlled table names and configuration values directly into SQL statements across sequence update, CSV export, and table management operations. Attacker…","indicators":{"cves":["CVE-2026-76635"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T14:17:59.973Z","fetchedAt":"2026-08-21T03:01:29.087Z","references":[{"url":"https://github.com/baserproject/basercms/releases/tag/5.3.0","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/baserproject/basercms/security/advisories/GHSA-cg65-f2m7-9fqj","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://www.vulncheck.com/advisories/basercms-sql-injection-and-code-injection-via-bcdatabaseservice-php","label":"disclosure@vulncheck.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-76833","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-76833 — @cgauge/yaml npm package contains an arbitrary code execution vulnerability that allows attackers to…","description":"@cgauge/yaml npm package contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary JavaScript by embedding a custom !js YAML tag whose construct callback unconditionally calls eval() on attacker-supplied string values during document parsing. Any application parsi…","indicators":{"cves":["CVE-2026-76833"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T14:18:00.137Z","fetchedAt":"2026-08-21T03:01:29.087Z","references":[{"url":"https://gist.github.com/arjunjaincs/35da3a80b4b16f324f194acec18489ba","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/cgauge/packages","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://www.vulncheck.com/advisories/cgauge-yaml-npm-package-arbitrary-code-execution-via-eval-yaml-tag","label":"disclosure@vulncheck.com","domainType":"other"},{"url":"https://gist.github.com/arjunjaincs/35da3a80b4b16f324f194acec18489ba","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-76990","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-76990 — A vulnerability has been found in code-projects Simple Inventory System 1.0. Affected by this issue…","description":"A vulnerability has been found in code-projects Simple Inventory System 1.0. Affected by this issue is some unknown functionality of the file /delete.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public an…","indicators":{"cves":["CVE-2026-76990"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T14:18:00.313Z","fetchedAt":"2026-08-21T03:01:29.087Z","references":[{"url":"https://code-projects.org/","label":"cna@vuldb.com","domainType":"other"},{"url":"https://raw.githubusercontent.com/anubhavv106/Security-Advisories/refs/heads/main/Simple-Inventory-System-delete.php-SQLi.md","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/cve/CVE-2026-76990","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/submit/880114","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/vuln/393615","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/vuln/393615/cti","label":"cna@vuldb.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-16925","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-16925 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to achieve privilege esca…","description":"IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to achieve privilege escalation due to improper authorization.","indicators":{"cves":["CVE-2026-16925"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T15:17:28.800Z","fetchedAt":"2026-08-21T03:01:29.087Z","references":[{"url":"https://www.ibm.com/support/pages/node/7283858","label":"psirt@us.ibm.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-16927","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-16927 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain root privileges d…","description":"IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain root privileges due to a time-of-check to time-of-use (TOCTOU) race condition.","indicators":{"cves":["CVE-2026-16927"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T15:17:29.130Z","fetchedAt":"2026-08-21T03:01:29.087Z","references":[{"url":"https://www.ibm.com/support/pages/node/7283858","label":"psirt@us.ibm.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-49825","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-49825 — lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attribute…","description":"lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_c…","indicators":{"cves":["CVE-2026-49825"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T15:17:30.707Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/fedora-python/lxml_html_clean/commit/322357ac61c6cf80fcbaba53b4e92e31f3ded9f2","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/fedora-python/lxml_html_clean/releases/tag/0.4.5","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/fedora-python/lxml_html_clean/security/advisories/GHSA-4jhm-jv67-739f","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/lxml/lxml/commit/5927a6d5e851845140975d99b65461e255caaab0","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/lxml/lxml/releases/tag/lxml-6.1.1","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-61897","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-61897 — An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges…","description":"An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It changes the effective UID/GID to the target user but leaves the real UID as 0 (root). A shell spawned by a helper script inherits ruid=0 and may reset its…","indicators":{"cves":["CVE-2026-61897"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T15:17:38.740Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://bugs.launchpad.net/ubuntu/+source/accountsservice/+bug/2157985","label":"security@ubuntu.com","domainType":"other"},{"url":"https://ubuntu.com/security/CVE-2026-61897","label":"security@ubuntu.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-61898","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-61898 — The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accounts…","description":"The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13.9-8ubuntu7 treat the user-controlled LANGUAGE entry in ~/.pam_environment as trusted input. The value is interpolated unescaped into a GNU sed replacement expression, allowing an…","indicators":{"cves":["CVE-2026-61898"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T15:17:38.913Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://bugs.launchpad.net/ubuntu/+source/accountsservice/+bug/2157985","label":"security@ubuntu.com","domainType":"other"},{"url":"https://ubuntu.com/security/CVE-2026-61898","label":"security@ubuntu.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-63490","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-63490 — Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.g…","description":"Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.github.jknack.handlebars.springmvc.SpringTemplateLoader resolves attacker-influenced Spring MVC view names through Spring ResourceLoader without the path-containment validation used by other URL-based…","indicators":{"cves":["CVE-2026-63490"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T15:18:04.577Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/jknack/handlebars.java/commit/61f43423a337b87db5fec1fe59f0725aaaa38df5","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/jknack/handlebars.java/releases/tag/v4.5.3","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/jknack/handlebars.java/security/advisories/GHSA-g29j-rwfv-h99w","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-76996","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-76996 — A security flaw has been discovered in SourceCodester Simple Online Food Ordering System 1.0. Impact…","description":"A security flaw has been discovered in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/admin/view_order.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been released to…","indicators":{"cves":["CVE-2026-76996"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T15:18:40.783Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/hubdk01/cve/issues/2","label":"cna@vuldb.com","domainType":"primary"},{"url":"https://vuldb.com/cve/CVE-2026-76996","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/submit/880388","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/vuln/393619","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/vuln/393619/cti","label":"cna@vuldb.com","domainType":"other"},{"url":"https://www.sourcecodester.com/","label":"cna@vuldb.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-19611","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-19611 — A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode…","description":"A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A remote attacker can more easily guess affected passwords by using an ASCII-only dictionary against accounts whose passwords were i…","indicators":{"cves":["CVE-2026-19611"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T16:17:18.293Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-19611","label":"secalert@redhat.com","domainType":"other"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2514568","label":"secalert@redhat.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-75140","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-75140 — jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnera…","description":"jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnerability in XmlTreeBuilder that allows remote attackers to exhaust JVM heap memory by supplying a deeply nested XML document with uniquely-namespaced elements. The builder copies the entire inherited na…","indicators":{"cves":["CVE-2026-75140"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T16:18:02.030Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/jhy/jsoup/commit/862ba2f1d48ee95609183dbcfc848c9fd7afc76a","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/jhy/jsoup/pull/2556","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://www.vulncheck.com/advisories/jsoup-uncontrolled-resource-consumption-in-xmltreebuilder","label":"disclosure@vulncheck.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-76998","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-76998 — A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0.…","description":"A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. The impacted element is an unknown function of the file /admin/ajax.php?action=delete_category. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remote…","indicators":{"cves":["CVE-2026-76998"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T16:18:31.243Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/normabowie11-max/cve/issues/1","label":"cna@vuldb.com","domainType":"primary"},{"url":"https://vuldb.com/cve/CVE-2026-76998","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/submit/880465","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/vuln/393621","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/vuln/393621/cti","label":"cna@vuldb.com","domainType":"other"},{"url":"https://www.sourcecodester.com/","label":"cna@vuldb.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-77004","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-77004 — A flaw has been found in Comfast CF-N1-S 2.6.0.1. This impacts the function sprintf of the file /cgi…","description":"A flaw has been found in Comfast CF-N1-S 2.6.0.1. This impacts the function sprintf of the file /cgi-bin/mbox-config?method=SET&section=ptest_sn. Executing a manipulation of the argument sn can lead to command injection. The attack can be launched remotely. The exploit has been published and may be…","indicators":{"cves":["CVE-2026-77004"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T16:18:31.580Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/lxiansheng488-bit/-/blob/main/%E5%8E%82%E5%95%86comefast%20%20CF-N1-S%20V2.pdf","label":"cna@vuldb.com","domainType":"primary"},{"url":"https://vuldb.com/cve/CVE-2026-77004","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/submit/880584","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/vuln/393623","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/vuln/393623/cti","label":"cna@vuldb.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-54449","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-54449 — LangBot is a global IM bot platform designed for LLMs. In version 4.10.7 and earlier, any authentica…","description":"LangBot is a global IM bot platform designed for LLMs. In version 4.10.7 and earlier, any authenticated user can add or change an STDIO MCP server configuration without an adequate authorization boundary. In src/langbot/pkg/provider/tools/loaders/mcp.py, StdioServerParameters accepts the configured…","indicators":{"cves":["CVE-2026-54449"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:18:17.910Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/langbot-app/LangBot/security/advisories/GHSA-3pvh-63gf-j9mw","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://www.ox.security/blog/mcp-supply-chain-advisory-rce-vulnerabilities-across-the-ai-ecosystem","label":"security-advisories@github.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-54616","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-54616 — NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 1.0.88.0 un…","description":"NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 1.0.88.0 until stable version 6.0.1698.0 and preview version 6.5.1742.0, the Lz4Decode function in NanaZip.Core/SevenZip/CPP/7zip/Archive/SquashfsHandler.cpp rejects only a zero return from LZ4_decompress_safe e…","indicators":{"cves":["CVE-2026-54616"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:18:18.090Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/M2Team/NanaZip/commit/733e8570d2ba96c3e52aab44f5fd886775d5952f","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/M2Team/NanaZip/commit/ce0322a1932e16a53e4a13e48bc61804c7826956","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/M2Team/NanaZip/releases/tag/6.0.1698.0","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/M2Team/NanaZip/releases/tag/6.5.1742.0","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/M2Team/NanaZip/security/advisories/GHSA-95x5-qvvm-hmfp","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/M2Team/NanaZip/security/advisories/GHSA-95x5-qvvm-hmfp","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-61704","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-61704 — Link Preview JS extracts web links information. Prior to 4.0.4, the resolveDNSHost mitigation in ind…","description":"Link Preview JS extracts web links information. Prior to 4.0.4, the resolveDNSHost mitigation in index.ts validates one resolved IP address but fetches the original hostname, allowing an attacker-controlled DNS server to return a public address during validation and a loopback or internal address du…","indicators":{"cves":["CVE-2026-61704"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:18:51.940Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/OP-Engineering/link-preview-js/commit/6ee25043dd60b097eb70b4ce049aac94b28239e3","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/OP-Engineering/link-preview-js/commit/f3a3dd84adbb9d32d06a933f44ff3eaa837f9a12","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/OP-Engineering/link-preview-js/pull/181","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/OP-Engineering/link-preview-js/releases/tag/4.0.4","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/OP-Engineering/link-preview-js/security/advisories/GHSA-cpjf-6666-r8fx","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-65842","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-65842 — Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.2, @platejs/docx-io fetches remote…","description":"Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.2, @platejs/docx-io fetches remote image URLs while converting attacker-controlled HTML through htmlToDocxBlob in a server-side or privileged environment. The converter can make requests to internal network resources and include the fe…","indicators":{"cves":["CVE-2026-65842"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:19:23.433Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/udecode/plate/commit/21aa59926f4bbd421027354823cca09c6700ed73","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/udecode/plate/pull/5053","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/udecode/plate/releases/tag/v53.3.2","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/udecode/plate/security/advisories/GHSA-4q39-2jhr-7qx8","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-69183","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-69183 — Monkeytype is a minimalistic and customizable typing test. In 26.26.0 and earlier, the backend rate-…","description":"Monkeytype is a minimalistic and customizable typing test. In 26.26.0 and earlier, the backend rate-limit key generator in backend/src/middlewares/rate-limit.ts uses client-controlled cf-connecting-ip and x-forwarded-for headers before the trust-proxy-derived req.ip value. An unauthenticated attacke…","indicators":{"cves":["CVE-2026-69183"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:19:34.387Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/monkeytypegame/monkeytype/security/advisories/GHSA-c878-p3jh-mmjf","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/monkeytypegame/monkeytype/security/advisories/GHSA-c878-p3jh-mmjf","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-77019","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-77019 — A vulnerability was determined in CodeAstro Apartment Visitor Management System 1.0. Affected is an…","description":"A vulnerability was determined in CodeAstro Apartment Visitor Management System 1.0. Affected is an unknown function of the file /apartment-visitor/forgotpw.php. Executing a manipulation of the argument secode can lead to sql injection. The attack may be launched remotely. The exploit has been publi…","indicators":{"cves":["CVE-2026-77019"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:19:49.063Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://codeastro.com/","label":"cna@vuldb.com","domainType":"other"},{"url":"https://github.com/Witiers/CVEs/issues/1","label":"cna@vuldb.com","domainType":"primary"},{"url":"https://vuldb.com/cve/CVE-2026-77019","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/submit/880593","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/vuln/393635","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/vuln/393635/cti","label":"cna@vuldb.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-77020","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-77020 — A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. Affected by thi…","description":"A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file password-recovery.php. The manipulation of the argument email leads to sql injection. Remote exploitation of the attack is possible. The exploit…","indicators":{"cves":["CVE-2026-77020"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:19:49.237Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://codeastro.com/","label":"cna@vuldb.com","domainType":"other"},{"url":"https://github.com/Witiers/CVEs/issues/2","label":"cna@vuldb.com","domainType":"primary"},{"url":"https://vuldb.com/cve/CVE-2026-77020","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/submit/880596","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/vuln/393636","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/vuln/393636/cti","label":"cna@vuldb.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-77176","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-77176 — A flaw was found in Kata Containers. In configurations utilizing genpolicy for Confidential Containe…","description":"A flaw was found in Kata Containers. In configurations utilizing genpolicy for Confidential Containers guest protection, a malicious host operator can exploit insufficient validation of CreateContainer mount and storage rules. This allows them to mount arbitrary container-rootfs paths over sensitive…","indicators":{"cves":["CVE-2026-77176"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:19:49.773Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-77176","label":"secalert@redhat.com","domainType":"other"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517502","label":"secalert@redhat.com","domainType":"other"},{"url":"https://github.com/kata-containers/kata-containers/security/advisories/GHSA-fmg6-v47x-52wr","label":"secalert@redhat.com","domainType":"primary"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/20/19","label":"af854a3a-2127-422b-91ae-364da2661108","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-54623","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-54623 — django CMS is an easy-to-use and developer-friendly enterprise content management system powered by…","description":"django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, the move_plugin endpoint in cms/admin/placeholderadmin.py accepts an attacker-controlled plugin_parent value without rejecting a plugin’s own identifier or a descendant identif…","indicators":{"cves":["CVE-2026-54623","CVE-2026-54622","CVE-2026-54624","CVE-2026-61663","CVE-2026-63003","CVE-2026-75526"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T18:16:28.013Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/django-cms/django-cms/commit/7642a98ab3170793c0b27b4125dd1f3d318b8a1c","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/django-cms/django-cms/pull/8645","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/django-cms/django-cms/releases/tag/5.0.8","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/django-cms/django-cms/security/advisories/GHSA-8jj7-4v57-frf5","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/django-cms/django-cms/security/advisories/GHSA-4xfr-4p46-gc6p","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/django-cms/django-cms/security/advisories/GHSA-vgxm-h9gx-h9w7","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/django-cms/django-cms/commit/9c82abfeb25471583e23906ea1ebef9202527b04","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/django-cms/django-cms/pull/8703","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/django-cms/django-cms/releases/tag/5.0.9","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/django-cms/django-cms/security/advisories/GHSA-8qj2-c6q4-f399","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/django-cms/django-cms/commit/3e1ccf7573eb1a74ebbbfaaa812c1f5cadf14e6c","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/django-cms/django-cms/pull/8713","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/django-cms/django-cms/security/advisories/GHSA-6x92-6vx4-5fwr","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/django-cms/django-cms/commit/b56a568844ff3702495945f73a31d0868285bf88","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/django-cms/django-cms/pull/8711","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/django-cms/django-cms/security/advisories/GHSA-hvq6-2r72-p2x7","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-63387","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-63387 — Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an off-by-o…","description":"Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an off-by-one stack buffer overflow in evdns.c when dnsname_to_labels formats a name-bearing DNS record at the end of the 64 KB stack buffer allocated by evdns_server_request_format_response. The final-label che…","indicators":{"cves":["CVE-2026-63387"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T18:16:36.723Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libevent/libevent/security/advisories/GHSA-58rx-7448-jw47","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-63388","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-63388 — Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a heap out-…","description":"Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a heap out-of-bounds write in bufferevent_sock.c when bufferevent_socket_set_conn_address_ copies a kernel-supplied AF_UNIX peer address into bufferevent_private.conn_address. Release builds compiled with NDEBUG…","indicators":{"cves":["CVE-2026-63388"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T18:16:36.893Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://github.com/libevent/libevent/commit/52057cb33d0c20c0a0453fbabe6c0c96854931b9","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libevent/libevent/commit/ef38f926e9cd1f082416c6fff13587bc1f431d72","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libevent/libevent/security/advisories/GHSA-cvq5-vrvr-j338","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-63495","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-63495 — Libevent is an event notification library. From 2.2.0-alpha-dev until 2.2.2-alpha, the libevent WebS…","description":"Libevent is an event notification library. From 2.2.0-alpha-dev until 2.2.2-alpha, the libevent WebSocket server in ws.c accumulates fragmented frames in evws->incomplete_frames without enforcing a total message-size limit. An unauthenticated remote client can repeatedly send fragmented WebSocket fr…","indicators":{"cves":["CVE-2026-63495"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T18:16:37.040Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://github.com/libevent/libevent/commit/291c4d1cd75695e898030ebd5c4ddf26c094077b","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libevent/libevent/security/advisories/GHSA-qx89-wf2v-vgmx","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libevent/libevent/security/advisories/GHSA-qx89-wf2v-vgmx","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-76641","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-76641 — Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger me…","description":"Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption by processing XML with external entity parsers created via XML_ExternalEntityParserCreate. A struct size mismatch between ELEMENT_TYPE members causes storeAtts to read the attIndex mem…","indicators":{"cves":["CVE-2026-76641"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T18:16:51.887Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://github.com/libexpat/libexpat/commit/98599f6dcc2b460410881fe420f5f55d6bec63bf","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/libexpat/libexpat/pull/1331","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://www.vulncheck.com/advisories/expat-out-of-bounds-read-via-dtdcopy","label":"disclosure@vulncheck.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-77031","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-77031 — A vulnerability has been found in Tenda CH22 1.0.0.1. The affected element is the function formcreat…","description":"A vulnerability has been found in Tenda CH22 1.0.0.1. The affected element is the function formcreateFileName of the file /goform/formcreateFileName. The manipulation of the argument fileNameMit leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the p…","indicators":{"cves":["CVE-2026-77031"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T18:16:53.140Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://candle-throne-f75.notion.site/Tenda-CH22-formcreateFileName-392df0aa118580c38c4ad15fb15cd30d","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/cve/CVE-2026-77031","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/submit/880667","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/vuln/393642","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/vuln/393642/cti","label":"cna@vuldb.com","domainType":"other"},{"url":"https://www.tenda.com.cn/","label":"cna@vuldb.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-53583","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-53583 — libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a…","description":"libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, verify_server_cert in src/libgit2/streams/openssl.c uses an inverted !!memcmp result in the GEN_IPADD b…","indicators":{"cves":["CVE-2026-53583","CVE-2026-53584","CVE-2026-53585","CVE-2026-53586","CVE-2026-53587"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T19:16:54.500Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://github.com/libgit2/libgit2/commit/647dcb432980b84ede4cb5a008bbd1ccb4ead03d","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libgit2/libgit2/commit/c2aa35409ee0e6515df64da49750f13a0a42c47f","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libgit2/libgit2/commit/ef086bc3e4eedf62be38a910381aae24d49871ff","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libgit2/libgit2/releases/tag/v1.8.6","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libgit2/libgit2/releases/tag/v1.9.5","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libgit2/libgit2/security/advisories/GHSA-h7gc-w2gg-p9xp","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libgit2/libgit2/commit/419637d3587396f5d139d6d88480eab3cd81e7a1","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libgit2/libgit2/commit/467c2d95ed663df722f83a5960edf568514b128c","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libgit2/libgit2/commit/ec7371da9f359cd8293e9108e7a0b1c1b61b67c4","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libgit2/libgit2/security/advisories/GHSA-cw77-j82w-mchm","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libgit2/libgit2/commit/0cdfdd5fa8f8514c82413025e1e0808866cf7c30","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libgit2/libgit2/commit/c1896f06df22cc0ca5658df3a8f6cd7ede4cd6ae","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libgit2/libgit2/commit/dec22ac01ad9620c96b7b9ac3ef636ea46d43bed","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libgit2/libgit2/security/advisories/GHSA-27m5-gxxh-x79j","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libgit2/libgit2/commit/07de6a7e438f95ac9a6efd3222a82117e871ed27","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libgit2/libgit2/commit/af2b29ad0a74d5bac9751376879ddaf848136d3b","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libgit2/libgit2/commit/c1507abc44647b3acd832a33a5b1c8c9f5ba8821","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libgit2/libgit2/security/advisories/GHSA-2889-x8f6-mc4x","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libgit2/libgit2/commit/2c0ce8c0132ac38ab0db28239462a671e2e5440e","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libgit2/libgit2/commit/affda60c10fcef16723451c0d7dc71b71dc20ad3","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libgit2/libgit2/commit/d7a9fb87f504434e9f45228678953c4fa56e7640","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libgit2/libgit2/security/advisories/GHSA-pm24-4jhq-3xvm","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-66787","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-66787 — A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes.…","description":"A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability stems from insufficient validation of advertised IP addresses within EndpointSlice objects. A compromised spoke cluster can exploit this by creating EndpointSlices with attacker-con…","indicators":{"cves":["CVE-2026-66787"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T19:16:58.637Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-66787","label":"secalert@redhat.com","domainType":"other"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2507532","label":"secalert@redhat.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-72852","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-72852 — hank-ai/darknet sizes a convolutional layer's weight and output heap buffers by multiplying configur…","description":"hank-ai/darknet sizes a convolutional layer's weight and output heap buffers by multiplying configuration fields taken from a .cfg file in unchecked 32-bit int arithmetic. In src-lib/convolutional_layer.cpp, l.nweights is computed as (c / groups) * n * size * size and l.outputs as l.out_h * l.out_w…","indicators":{"cves":["CVE-2026-72852"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T19:17:00.830Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://github.com/hank-ai/darknet","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/hank-ai/darknet/blob/v6.0/src-lib/convolutional_layer.cpp#L1457","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/hank-ai/darknet/blob/v6.0/src-lib/convolutional_layer.cpp#L764","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/hank-ai/darknet/blob/v6.0/src-lib/convolutional_layer.cpp#L811","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/hank-ai/darknet/issues/148","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://www.vulncheck.com/advisories/darknet-integer-overflow-in-convolutional-layer-buffer-sizing-leads-to-heap-buffer-overflow","label":"disclosure@vulncheck.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18420","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-18420 — Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards a…","description":"Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arbitrary code on the server via a crafted JSON payload to the metrics visualization API endpoint. This issue is a form of prototype pollution that enable…","indicators":{"cves":["CVE-2026-18420"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["rce"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T21:17:06.137Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://aws.amazon.com/security/security-bulletins/2026-085-aws/","label":"ff89ba41-3aa1-4d27-914a-91399e9639e5","domainType":"other"},{"url":"https://github.com/opensearch-project/OpenSearch-Dashboards/releases/tag/3.8.0","label":"ff89ba41-3aa1-4d27-914a-91399e9639e5","domainType":"primary"},{"url":"https://github.com/opensearch-project/OpenSearch-Dashboards/security/advisories/GHSA-xmqx-xq2p-8jq2","label":"ff89ba41-3aa1-4d27-914a-91399e9639e5","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-53804","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-53804 — OTRS Community Edition contains an authenticated OS command injection vulnerability in the PGP encry…","description":"OTRS Community Edition contains an authenticated OS command injection vulnerability in the PGP encryption module that allows administrators to execute arbitrary operating-system commands by supplying crafted values for the PGP binary path and command options. Administrator-supplied configuration val…","indicators":{"cves":["CVE-2026-53804"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T21:17:06.813Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://h00die-gr3y.github.io/research/cve-2026-53804/","label":"disclosure@vulncheck.com","domainType":"other"},{"url":"https://www.vulncheck.com/advisories/otrs-community-edition-os-command-injection-via-pgp-configuration","label":"disclosure@vulncheck.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-73040","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-73040 — Dockge validates a stack name only on the write path. In backend/stack.ts the allow-list check in va…","description":"Dockge validates a stack name only on the write path. In backend/stack.ts the allow-list check in validate(), which requires the name to match ^[a-z0-9_-]+$, is reached from save() alone, while the path getter returns path.join(this.server.stacksDir, this.name) and Stack.getStack builds path.join(se…","indicators":{"cves":["CVE-2026-73040"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T21:17:09.110Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://github.com/louislam/dockge","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/louislam/dockge/blob/1.5.0/backend/agent-socket-handlers/docker-socket-handler.ts#L43-L78","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/louislam/dockge/blob/1.5.0/backend/stack.ts#L155-L157","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/louislam/dockge/blob/1.5.0/backend/stack.ts#L218-L232","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/louislam/dockge/blob/1.5.0/backend/stack.ts#L377-L379","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/louislam/dockge/issues/994","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://www.vulncheck.com/advisories/dockge-path-traversal-via-unvalidated-stack-name-allows-arbitrary-compose-and-env-disclosure-and-arbitrary-directory-deletion","label":"disclosure@vulncheck.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-73137","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-73137 — A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Mana…","description":"A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). A tenant with HelmRelease create permissions can exploit this vulnerability by manipulating the `secretRef.Namespace` field. This allows the `GetSecret()` function in the HelmRelease c…","indicators":{"cves":["CVE-2026-73137"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T21:17:09.270Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-73137","label":"secalert@redhat.com","domainType":"other"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2514223","label":"secalert@redhat.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-77584","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-77584 — Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has a…","description":"Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has attached streams. A malicious client could send a RELAY_COMMAND_BEGIN before the CONFLUX_LINK on the same circuit, attaching an exit stream that would later end up orphan leaving a dangling circuit bac…","indicators":{"cves":["CVE-2026-77584"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T21:17:10.810Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://gitlab.torproject.org/tpo/core/tor/-/raw/tor-0.4.9.10/ChangeLog","label":"cve@mitre.org","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-77638","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-77638 — Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous…","description":"Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion service that the client was trying to reach.","indicators":{"cves":["CVE-2026-77638"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T21:17:11.097Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://gitlab.torproject.org/tpo/core/tor/-/raw/tor-0.4.9.11/ChangeLog","label":"cve@mitre.org","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-17003","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-17003 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to compromise the confid…","description":"IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to compromise the confidentiality and integrity of the system due to an out-of-bounds write.","indicators":{"cves":["CVE-2026-17003"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:10.983Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://www.ibm.com/support/pages/node/7283858","label":"psirt@us.ibm.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-17171","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-17171 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite arbitrary fi…","description":"IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite arbitrary files due to improper resolution of symbolic links.","indicators":{"cves":["CVE-2026-17171"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:15.247Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://www.ibm.com/support/pages/node/7283858","label":"psirt@us.ibm.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-19442","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-19442 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtua…","description":"IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtual SCSI (vSCSI) initiator driver. Successful exploitation may result in denial of service, privilege escalation, or full compromise of the client LPAR kernel.","indicators":{"cves":["CVE-2026-19442"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:18.110Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://www.ibm.com/support/pages/node/7283858","label":"psirt@us.ibm.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-19446","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-19446 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote unauthenticated attacker can send a cr…","description":"IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote unauthenticated attacker can send a crafted UDP packet to a reachable RPC service, resulting in complete system unavailability and requiring an LPAR restart.","indicators":{"cves":["CVE-2026-19446"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:18.273Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://www.ibm.com/support/pages/node/7283858","label":"psirt@us.ibm.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-19449","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-19449 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a vulnerability in cmdnim that may allow an unpriv…","description":"IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a vulnerability in cmdnim that may allow an unprivileged local user to executes the payload as root.","indicators":{"cves":["CVE-2026-19449"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:18.613Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://www.ibm.com/support/pages/node/7283858","label":"psirt@us.ibm.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-46355","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-46355 — BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton exposed /bigbluebu…","description":"BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton exposed /bigbluebutton/api/handleJoinExistingUser through bigbluebutton-web/grails-app/controllers/org/bigbluebutton/web/controllers/ApiController.groovy. A requester able to supply an existingUserID for an active part…","indicators":{"cves":["CVE-2026-46355"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:19.193Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://github.com/bigbluebutton/bigbluebutton/commit/972b04e474e195cbd708b5b3f0485fe528a1a85b","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/bigbluebutton/bigbluebutton/releases/tag/v3.0.23","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-38fw-2gq7-ccgr","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-46682","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-46682 — BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton allowed authentica…","description":"BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton allowed authenticated moderators to inject SQL through the meetingId and userId values used by refreshBreakoutRoomsVisibleForUsers in akka-bbb-apps/src/main/scala/org/bigbluebutton/core/db/BreakoutRoomUserDAO.scala. Th…","indicators":{"cves":["CVE-2026-46682"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:19.347Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://github.com/bigbluebutton/bigbluebutton/commit/3365e340e0c102de0f8ea007c05053b562b6fa2b","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/bigbluebutton/bigbluebutton/releases/tag/v3.0.23","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-gfv2-46v4-jvw5","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-49217","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-49217 — Mailu is a mail server as a set of Docker images. Prior to version 2024.06.52, a missing authorizati…","description":"Mailu is a mail server as a set of Docker images. Prior to version 2024.06.52, a missing authorization check in the Mailu admin REST API allows any unauthenticated attacker to remove any potential IP restriction or update the comment field from any existing user token provided the REST API is enable…","indicators":{"cves":["CVE-2026-49217"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:19.803Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://github.com/Mailu/Mailu/security/advisories/GHSA-2w8v-6xr5-g9gh","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-49436","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-49436 — LinkAce is a self-hosted archive to collect website links. Prior to version 2.5.7, the Bulk Link API…","description":"LinkAce is a self-hosted archive to collect website links. Prior to version 2.5.7, the Bulk Link API endpoint (`POST /api/v2/bulk/links`) accepts URLs without any format validation, allowing an authenticated user to store a `javascript:` URI. The stored URI is later rendered verbatim as an `href` in…","indicators":{"cves":["CVE-2026-49436"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:20.240Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://github.com/Kovah/LinkAce/commit/642ac520347205a8277668bcae269bdc21223eae","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/Kovah/LinkAce/security/advisories/GHSA-6r73-pchm-4m39","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-55013","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-55013 — Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to per…","description":"Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally.","indicators":{"cves":["CVE-2026-55013"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:21.933Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55013","label":"secure@microsoft.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-55765","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-55765 — CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments.…","description":"CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG embedded cleartext role passwords in `ALTER ROLE` and `CREATE ROLE` statements generated by SetUserPassword in pkg/management/postgres/utils/roles.go and appe…","indicators":{"cves":["CVE-2026-55765","CVE-2026-55769"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:22.487Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://github.com/cloudnative-pg/cloudnative-pg/commit/2f0342747e1f160425b9d51753c0069b0d6117d5","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cloudnative-pg/cloudnative-pg/commit/3cd5af5d388c26758acf13c19ea806b4bcebb3fe","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cloudnative-pg/cloudnative-pg/commit/9a13573dbe3d78721b7ea92141e6d2324a2c0ef0","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cloudnative-pg/cloudnative-pg/pull/10724","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cloudnative-pg/cloudnative-pg/releases/tag/v1.28.4","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cloudnative-pg/cloudnative-pg/releases/tag/v1.29.2","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cloudnative-pg/cloudnative-pg/releases/tag/v1.30.0","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cloudnative-pg/cloudnative-pg/security/advisories/GHSA-w3gf-xc94-wvmj","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cloudnative-pg/cloudnative-pg/commit/02b5c6289b7609dc87fcb1ae9c113160e3d43308","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cloudnative-pg/cloudnative-pg/commit/db38f4d80315c8f1b21bf511ef0f28871820c14d","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cloudnative-pg/cloudnative-pg/commit/e0e2d53adbd907a61f583b1431904b5969f3fd22","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cloudnative-pg/cloudnative-pg/pull/10774","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cloudnative-pg/cloudnative-pg/security/advisories/GHSA-x8c2-3p4r-v9r6","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-66800","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-66800 — Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose…","description":"Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network.","indicators":{"cves":["CVE-2026-66800"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:56.043Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66800","label":"secure@microsoft.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-69419","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-69419 — Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to exe…","description":"Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network.","indicators":{"cves":["CVE-2026-69419"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:59.980Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69419","label":"secure@microsoft.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-69519","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-69519 — Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose infor…","description":"Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network.","indicators":{"cves":["CVE-2026-69519"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:18:00.123Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69519","label":"secure@microsoft.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-69543","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-69543 — Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevat…","description":"Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network.","indicators":{"cves":["CVE-2026-69543"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:18:00.270Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69543","label":"secure@microsoft.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-69558","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-69558 — Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized…","description":"Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network.","indicators":{"cves":["CVE-2026-69558"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:18:00.610Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69558","label":"secure@microsoft.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-69855","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-69855 — Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to di…","description":"Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network.","indicators":{"cves":["CVE-2026-69855"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:18:01.003Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69855","label":"secure@microsoft.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-72818","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-72818 — The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and app…","description":"The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+(?:[.\\-][a-z0-9]+)* is unbounded. Input consisting of many alternating label separators can be partit…","indicators":{"cves":["CVE-2026-72818"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:18:05.087Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://github.com/nltk/nltk","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/nltk/nltk/blob/3.9.4/nltk/tokenize/casual.py","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/nltk/nltk/issues/3704","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/nltk/nltk/releases/tag/v3.10.1","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://www.vulncheck.com/advisories/nltk-tweettokenizer-url-pattern-backtracks-catastrophically-on-naked-domain-like-input","label":"disclosure@vulncheck.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-72848","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-72848 — SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documente…","description":"SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_domain control only to leaf url entries. The loop over url elements filters cross-domain locations, but the loop over nested sitemap elements passes the child loc straight to self.s…","indicators":{"cves":["CVE-2026-72848"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:18:05.553Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://github.com/langchain-ai/langchain-community","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/langchain-ai/langchain-community/blob/main/libs/community/langchain_community/document_loaders/sitemap.py","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/langchain-ai/langchain/issues/38814","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://www.vulncheck.com/advisories/langchain-community-sitemaploader-does-not-apply-restrict-to-same-domain-to-nested-sitemap-index-entries-allowing-server-side-request-forgery","label":"disclosure@vulncheck.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-72860","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-72860 — The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues se…","description":"The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues server-side HTTP requests to it, guarding the destination with assertPublicUrl from src/shared/utils/ssrfGuard.js. That guard compares hostname strings only: it resolves no DNS, does not revalidate afte…","indicators":{"cves":["CVE-2026-72860"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:18:05.787Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://github.com/decolua/9router","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/decolua/9router/blob/master/src/app/api/provider-nodes/validate/route.js","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/decolua/9router/blob/master/src/shared/utils/ssrfGuard.js","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/decolua/9router/issues/3293","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/decolua/9router/pull/3370","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://www.vulncheck.com/advisories/9router-server-side-request-forgery-via-api-provider-nodes-validate-because-the-ipv4-mapped-ipv6-denylist-check-is-unreachable","label":"disclosure@vulncheck.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-77642","source":"nvd","category":"vulnerability","severity":"high","title":"CVE-2026-77642 — tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signatur…","description":"tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or  detached signature with unexpected signature digest type. Impact  is minor for most Tor roles, but potentially major for directory   authorities. This is TROVE-2026-019.","indicators":{"cves":["CVE-2026-77642"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:18:06.070Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://gitlab.torproject.org/tpo/core/tor/-/raw/tor-0.4.9.9/ChangeLog","label":"cve@mitre.org","domainType":"other"}],"feedLabel":null},{"id":"vendor-cisa-nsa-fbi-warn-of-siemens-s7-plc-exploitation-using-ai-generated-scripts-to-d","source":"vendor-blogs","category":"advisory","severity":"high","title":"CISA, NSA, FBI warn of Siemens S7 PLC exploitation using AI-generated scripts to disrupt critical industrial processes","description":"U.S. agencies published on Wednesday a joint Cybersecurity Advisory warning of threat activity targeting Siemens S7 Series programmable...\nThe post CISA, NSA, FBI warn of Siemens S7 PLC exploitation using AI-generated scripts to disrupt critical industrial processes appeared first on Industrial Cybe…","indicators":{"cves":[],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["ics"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T15:14:25.000Z","fetchedAt":"2026-08-21T03:00:09.022Z","references":[{"url":"https://industrialcyber.co/industrial-cyber-attacks/cisa-nsa-fbi-warn-of-siemens-s7-plc-exploitation-using-ai-generated-scripts-to-disrupt-critical-industrial-processes/","label":"Industrial Cyber","domainType":"other"}],"feedLabel":null},{"id":"malbaz-b93f2842c5ede1d48659eebbba629082787a8ccd17edd2571f5ada14c1252341","source":"malware-bazaar","category":"malware","severity":"high","title":"b93f2842c5ede1d48659eebbba629082787a8ccd17edd2571f5ada14c1252341.elf","description":"File type: elf | Reporter: Tuxxin","indicators":{"cves":[],"ips":[],"domains":[],"urls":[],"hashes":{"md5":"1c4345de3e48f3e396b07942ddc52c6a","sha1":"0dc38524f8ddf9b50eb5672e622863dd3212dcf9","sha256":"b93f2842c5ede1d48659eebbba629082787a8ccd17edd2571f5ada14c1252341"}},"tags":["elf","exe","whack.sh"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-21T02:51:06Z","fetchedAt":"2026-08-21T03:00:01.057Z","references":[{"url":"https://bazaar.abuse.ch/sample/b93f2842c5ede1d48659eebbba629082787a8ccd17edd2571f5ada14c1252341/","label":"MalwareBazaar","domainType":"primary"}],"feedLabel":null},{"id":"malbaz-611fa15a339dabc3efdfdde36db072b7cddb2b70f37dd092abf0496f3fad74c7","source":"malware-bazaar","category":"malware","severity":"high","title":"611fa15a339dabc3efdfdde36db072b7cddb2b70f37dd092abf0496f3fad74c7.exe","description":"File type: exe | Reporter: Tuxxin","indicators":{"cves":[],"ips":[],"domains":[],"urls":[],"hashes":{"md5":"2a4721f8805f3e2b7e8b17d67e474bf8","sha1":"aea0f9f7c15593d1e504c588428fc8681a232953","sha256":"611fa15a339dabc3efdfdde36db072b7cddb2b70f37dd092abf0496f3fad74c7"}},"tags":["ConnectWise","exe","whack.sh"],"malwareFamily":"ConnectWise","confidence":null,"publishedAt":"2026-08-21T02:40:54Z","fetchedAt":"2026-08-21T03:00:01.057Z","references":[{"url":"https://bazaar.abuse.ch/sample/611fa15a339dabc3efdfdde36db072b7cddb2b70f37dd092abf0496f3fad74c7/","label":"MalwareBazaar","domainType":"primary"}],"feedLabel":null},{"id":"malbaz-3fb78a20a4cd693982fa7adbecb074cc50be6a86ff05434dbfafc1096ad5b5ea","source":"malware-bazaar","category":"malware","severity":"high","title":"wr.php","description":"File type: sh | Reporter: abuse_ch","indicators":{"cves":[],"ips":[],"domains":[],"urls":[],"hashes":{"md5":"9d90aadfd3b645334807fec9e766e031","sha1":"c8e4a97e12bb8e6eedaa746cb32a71982254641b","sha256":"3fb78a20a4cd693982fa7adbecb074cc50be6a86ff05434dbfafc1096ad5b5ea"}},"tags":["sh"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-21T02:38:35Z","fetchedAt":"2026-08-21T03:00:01.057Z","references":[{"url":"https://bazaar.abuse.ch/sample/3fb78a20a4cd693982fa7adbecb074cc50be6a86ff05434dbfafc1096ad5b5ea/","label":"MalwareBazaar","domainType":"primary"}],"feedLabel":null},{"id":"malbaz-b59075c2da6a7f8e093a6ddc8f48d77244c8fc7330e66f767d99bdbe9fcb8006","source":"malware-bazaar","category":"malware","severity":"high","title":"ok","description":"File type: sh | Reporter: abuse_ch","indicators":{"cves":[],"ips":[],"domains":[],"urls":[],"hashes":{"md5":"d48beea3c242577eeb2f9041afbeac72","sha1":"93803fb4c0e1231d2ba5992a01275816e24599f2","sha256":"b59075c2da6a7f8e093a6ddc8f48d77244c8fc7330e66f767d99bdbe9fcb8006"}},"tags":["sh"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-21T02:37:18Z","fetchedAt":"2026-08-21T03:00:01.057Z","references":[{"url":"https://bazaar.abuse.ch/sample/b59075c2da6a7f8e093a6ddc8f48d77244c8fc7330e66f767d99bdbe9fcb8006/","label":"MalwareBazaar","domainType":"primary"}],"feedLabel":null},{"id":"malbaz-12dd079eab15afe12736e803cdb8134e4bcb70bd8ee3a0969aa56695b4a54c08","source":"malware-bazaar","category":"malware","severity":"high","title":"flutter.mipsel","description":"File type: elf | Reporter: abuse_ch","indicators":{"cves":[],"ips":[],"domains":[],"urls":[],"hashes":{"md5":"c9e08297a9f9d908ba1eca3e474db414","sha1":"6a48bfffdc701d9b1e4452ed06732c4fd8cf41a9","sha256":"12dd079eab15afe12736e803cdb8134e4bcb70bd8ee3a0969aa56695b4a54c08"}},"tags":["elf","Mirai","upx-dec","upx","botnet"],"malwareFamily":"Mirai","confidence":null,"publishedAt":"2026-08-21T02:36:16Z","fetchedAt":"2026-08-21T03:00:01.057Z","references":[{"url":"https://bazaar.abuse.ch/sample/12dd079eab15afe12736e803cdb8134e4bcb70bd8ee3a0969aa56695b4a54c08/","label":"MalwareBazaar","domainType":"primary"},{"url":"https://bazaar.abuse.ch/sample/6dfddd85b419d20ae75a50f4ad4835fb2da7d4522c168351e778ecc48e448b8e/","label":"MalwareBazaar","domainType":"primary"}],"feedLabel":null},{"id":"malbaz-377339da9394e4590baa1a2aa8e433cf676718bb83a50a37fb9399eb6c8f62c7","source":"malware-bazaar","category":"malware","severity":"high","title":"377339da9394e4590baa1a2aa8e433cf676718bb83a50a37fb9399eb6c8f62c7.exe","description":"File type: exe | Reporter: Tuxxin","indicators":{"cves":[],"ips":[],"domains":[],"urls":[],"hashes":{"md5":"eb3815f639e96df5dfff4eac36552750","sha1":"ab1f689d79c8ebb9068de42785fe08c248b840d9","sha256":"377339da9394e4590baa1a2aa8e433cf676718bb83a50a37fb9399eb6c8f62c7"}},"tags":["exe","signed","whack.sh"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-21T02:30:59Z","fetchedAt":"2026-08-21T03:00:01.057Z","references":[{"url":"https://bazaar.abuse.ch/sample/377339da9394e4590baa1a2aa8e433cf676718bb83a50a37fb9399eb6c8f62c7/","label":"MalwareBazaar","domainType":"primary"}],"feedLabel":null},{"id":"malbaz-f4b330adc3e1cb5d4ba6f1c506d0e4d6821b83d9b033f6e0f21cfdb94c35d2c2","source":"malware-bazaar","category":"malware","severity":"high","title":"f4b330adc3e1cb5d4ba6f1c506d0e4d6821b83d9b033f6e0f21cfdb94c35d2c2.bin","description":"File type: exe | Reporter: anonymous","indicators":{"cves":[],"ips":[],"domains":[],"urls":[],"hashes":{"md5":"61118b7b4e83504d6a7d294b220d3cd1","sha1":"e2f31afcd12f239c600a99b053c5032583af4201","sha256":"f4b330adc3e1cb5d4ba6f1c506d0e4d6821b83d9b033f6e0f21cfdb94c35d2c2"}},"tags":["exe","signed","Vidar","botnet","infostealer"],"malwareFamily":"Vidar","confidence":null,"publishedAt":"2026-08-21T02:30:44Z","fetchedAt":"2026-08-21T03:00:01.057Z","references":[{"url":"https://bazaar.abuse.ch/sample/f4b330adc3e1cb5d4ba6f1c506d0e4d6821b83d9b033f6e0f21cfdb94c35d2c2/","label":"MalwareBazaar","domainType":"primary"}],"feedLabel":null},{"id":"malbaz-a38e5b31a04720674a8183bbc9901cda1523f0f555b993359cfaa57fdbfcfad9","source":"malware-bazaar","category":"malware","severity":"high","title":"wr.php","description":"File type: sh | Reporter: abuse_ch","indicators":{"cves":[],"ips":[],"domains":[],"urls":[],"hashes":{"md5":"fdf04b0361e5fcb9e86e5d66c3d1b079","sha1":"b10d57aae529d194d961010ae72fedadf3f5136a","sha256":"a38e5b31a04720674a8183bbc9901cda1523f0f555b993359cfaa57fdbfcfad9"}},"tags":["sh"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-21T02:25:21Z","fetchedAt":"2026-08-21T03:00:01.057Z","references":[{"url":"https://bazaar.abuse.ch/sample/a38e5b31a04720674a8183bbc9901cda1523f0f555b993359cfaa57fdbfcfad9/","label":"MalwareBazaar","domainType":"primary"}],"feedLabel":null},{"id":"malbaz-d59aa853fe50e2c441d088e790f1f6aa1e472389beb7668e86dc81dc256c4a59","source":"malware-bazaar","category":"malware","severity":"high","title":"k.php","description":"File type: sh | Reporter: abuse_ch","indicators":{"cves":[],"ips":[],"domains":[],"urls":[],"hashes":{"md5":"1c44f812710050f6702e1634806c7535","sha1":"b982660cef3cab0dfc07bf5dba658d19fa1bf813","sha256":"d59aa853fe50e2c441d088e790f1f6aa1e472389beb7668e86dc81dc256c4a59"}},"tags":["sh"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-21T02:20:42Z","fetchedAt":"2026-08-21T03:00:01.057Z","references":[{"url":"https://bazaar.abuse.ch/sample/d59aa853fe50e2c441d088e790f1f6aa1e472389beb7668e86dc81dc256c4a59/","label":"MalwareBazaar","domainType":"primary"}],"feedLabel":null},{"id":"otx-6a873495a873c0ec3c6d9880","source":"otx","category":"threat-intel","severity":"high","title":"Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia","description":"Kimsuky conducted spear phishing campaigns against South Korean and Japanese targets during the first half of 2026, distributing LNK malware through OneDrive share links. The malicious files established scheduled tasks that periodically fetched PowerShell scripts from command-and-control servers to…","indicators":{"cves":[],"ips":[],"domains":[],"urls":["http://103.249.117.183/receive.php","http://103.77.242.187/receive.php","http://160.187.147.119/any/app.vmd","http://160.187.147.119/any/attach.vmd","http://160.187.147.119/any/bimage.vmd","http://160.187.147.119/any/mnfst.vmd","http://160.187.147.119/any/sch.vmd","http://160.187.147.119/any/vpost.vmd"],"hashes":{"md5":"f6f7a94c11ea0ee01cbbe674cfac7851","sha1":"df6abbfd20e731689f3c7d2a55f45ac83fbbc40b","sha256":"b9ad79eaf7a4133f95f24c3b9d976c72f34264dc5c99030f0e57992cb5621f78"}},"tags":["spear phishing","chrome remote desktop","powershell","gmail exfiltration","onedrive","northeast asia","keylogger","lnk malware","anydesk","chrome extension","apt","phishing","botnet","infostealer"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:08:37.705Z","fetchedAt":"2026-08-21T03:00:01.555Z","references":[{"url":"https://otx.alienvault.com/pulse/6a873495a873c0ec3c6d9880","label":"OTX Pulse","domainType":"primary"}],"feedLabel":null},{"id":"otx-6a8734bac622f3c7b2d9a633","source":"otx","category":"threat-intel","severity":"high","title":"Distinct Clusters Target Individuals of Interest to Russia","description":"Three distinct suspected Russian cyber espionage threat clusters—UNC6293, UNC7005, and UNC5976—are abusing legitimate authentication flows to target individuals in academia, aerospace, defense, governments, and think tanks across Europe and the United States. These groups conduct sophisticated phish…","indicators":{"cves":[],"ips":[],"domains":["mioisiskwowiwjowuwjwolab.club","miov2iaiaoubqosiqoiajwowiwjso.online","chamber-ua.org","fewfwfwfwfwf.info","globsec.net","wa-connect.net","m365-owa.com","ms365-device.com","ms365-live.com","owa-ms365.com","my-invite.org","wa-connect.eu","wa-meeting.com","statistic-ms.live","finishoperations.com","finishoperations.org","foc-share.com","foc-share.org","foreignrelations.us","internal-share.com","share-foc.com","shopinvite.org","verify-drive.com","wa-device.com","wa-invite.com","drive.google.verify-drive.com","mail.kiis.co.uk"],"urls":[],"hashes":{"md5":"5484009071ea96c7b43e8fa052b8d88a","sha1":"1b97e0df9600335b0cd8db2eb4577d3dbf6e76db","sha256":"ca3be5885afb3eb3bb19341e2653212200c568f3f900e0b2f04de9ba209aed25"}},"tags":["russian cyber espionage","oauth phishing","vidar","device code phishing","headrush","app password phishing","unc6293","atomic","cherrypie","unc7005","enginelight","hospitality captive portal","unc5976","whatsapp device linking","authentication abuse","phishing","infostealer"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:09:14.994Z","fetchedAt":"2026-08-21T03:00:01.555Z","references":[{"url":"https://otx.alienvault.com/pulse/6a8734bac622f3c7b2d9a633","label":"OTX Pulse","domainType":"primary"}],"feedLabel":null},{"id":"news-rust-supply-chain-attack-puts-build-time-malware-in-crates-with-245-million-down","source":"general-news","category":"news","severity":"high","title":"Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads","description":"The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a remote payload during compilation.\n\nThe affected releases are ar…","indicators":{"cves":[],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["supply-chain"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T20:22:35.000Z","fetchedAt":"2026-08-21T03:00:02.309Z","references":[{"url":"https://thehackernews.com/2026/08/rust-supply-chain-attack-puts-build.html","label":"The Hacker News","domainType":"media"}],"feedLabel":null},{"id":"news-jfrog-artifactory-flaws-enable-software-supply-chain-attacks","source":"general-news","category":"news","severity":"high","title":"JFrog Artifactory Flaws Enable Software Supply Chain Attacks","description":"Two Artifactory flaws allowed attackers to poison package metadata across software repositories","indicators":{"cves":[],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["supply-chain"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T14:30:00.000Z","fetchedAt":"2026-08-21T03:00:02.309Z","references":[{"url":"https://www.infosecurity-magazine.com/news/jfrog-flaws-software-supply-chain/","label":"InfoSecurity Magazine","domainType":"media"}],"feedLabel":null},{"id":"nvd-CVE-2026-76634","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-76634 — WeGIA before 3.9.2 contains an insecure direct object reference vulnerability in the employee profil…","description":"WeGIA before 3.9.2 contains an insecure direct object reference vulnerability in the employee profile page that allows authenticated attackers to access arbitrary employee records by injecting an id_pessoa parameter through a request extraction function that overwrites the session-derived identifier…","indicators":{"cves":["CVE-2026-76634"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T14:17:59.837Z","fetchedAt":"2026-08-21T03:01:29.087Z","references":[{"url":"https://github.com/LabRedesCefetRJ/WeGIA/releases#release-3.9.2","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-jqh5-66qr-85qv","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://www.vulncheck.com/advisories/wegia-insecure-direct-object-reference-via-profile-funcionario-php","label":"disclosure@vulncheck.com","domainType":"other"},{"url":"https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-jqh5-66qr-85qv","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-44725","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-44725 — EMQX is a scalable and reliable MQTT broker for AI, IoT, IIoT, and connected vehicles. Prior to vers…","description":"EMQX is a scalable and reliable MQTT broker for AI, IoT, IIoT, and connected vehicles. Prior to versions 5.8.11, 5.9.3, 5.10.4, 6.0.3, 6.1.2, and 6.2.1, the plugin-install REST API and dashboard upload accepted stale grants created with emqx ctl plugins allow because there was no five-minute grant l…","indicators":{"cves":["CVE-2026-44725"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["transport"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T15:17:30.003Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/emqx/emqx/commit/2f926359fa847dd9928a8e94d3e342f5621806f4","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/emqx/emqx/commit/efa1ca1bef1517f1f87e1d562f8db8750b6d6ce3","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/emqx/emqx/pull/17200","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/emqx/emqx/pull/17201","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/emqx/emqx/releases/tag/6.0.3","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/emqx/emqx/releases/tag/6.1.2","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/emqx/emqx/releases/tag/6.2.1","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/emqx/emqx/releases/tag/e5.10.4","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/emqx/emqx/releases/tag/e5.8.11","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/emqx/emqx/security/advisories/GHSA-cp9x-5qwc-fj6r","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-55558","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-55558 — aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.2, SMTPProtocol.start_t…","description":"aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.2, SMTPProtocol.start_tls in src/aiosmtplib/protocol.py consumes the server's 220 response and starts the TLS handshake without clearing SMTPProtocol._buffer. An active network attacker can place attacker-chosen SMTP respon…","indicators":{"cves":["CVE-2026-55558"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T15:17:31.980Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/cole/aiosmtplib/commit/9fab7ba1361dbf7622ede1315a24be805cff09c9","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cole/aiosmtplib/releases/tag/v5.1.2","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cole/aiosmtplib/security/advisories/GHSA-vxj7-4xrp-5vr4","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-76991","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-76991 — A vulnerability was found in itsourcecode Hospital Management System 1.0. This affects an unknown pa…","description":"A vulnerability was found in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file /viewappointmentapproved.php. Performing a manipulation of the argument delid results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public a…","indicators":{"cves":["CVE-2026-76991"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T15:18:39.760Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/ltranquility/vuln_submit/issues/23","label":"cna@vuldb.com","domainType":"primary"},{"url":"https://itsourcecode.com/","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/cve/CVE-2026-76991","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/submit/880115","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/vuln/393616","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/vuln/393616/cti","label":"cna@vuldb.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-76993","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-76993 — A vulnerability was determined in GreyDGL PentestGPT up to 1.0.0. This vulnerability affects unknown…","description":"A vulnerability was determined in GreyDGL PentestGPT up to 1.0.0. This vulnerability affects unknown code of the component Web-Page Crawling. Executing a manipulation of the argument Traceback can lead to injection. The attack can be executed remotely. A high complexity level is associated with this…","indicators":{"cves":["CVE-2026-76993"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T15:18:40.013Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/GreyDGL/PentestGPT/","label":"cna@vuldb.com","domainType":"primary"},{"url":"https://github.com/GreyDGL/PentestGPT/issues/484","label":"cna@vuldb.com","domainType":"primary"},{"url":"https://github.com/ez-lbz/pentestgpt-vul-report","label":"cna@vuldb.com","domainType":"primary"},{"url":"https://vuldb.com/cve/CVE-2026-76993","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/submit/880116","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/vuln/393617","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/vuln/393617/cti","label":"cna@vuldb.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-76995","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-76995 — A vulnerability was identified in SourceCodester Simple Online Food Ordering System 1.0. This issue…","description":"A vulnerability was identified in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /admin/ajax.php?action=save_menu. The manipulation of the argument img leads to unrestricted upload. The attack is possible to be carried out remotely. The…","indicators":{"cves":["CVE-2026-76995"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T15:18:40.387Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/hubdk01/cve/issues/1","label":"cna@vuldb.com","domainType":"primary"},{"url":"https://vuldb.com/cve/CVE-2026-76995","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/submit/880371","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/vuln/393618","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/vuln/393618/cti","label":"cna@vuldb.com","domainType":"other"},{"url":"https://www.sourcecodester.com/","label":"cna@vuldb.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-63015","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-63015 — Uncontrolled Resource Consumption vulnerability in Apache InLong. Non-template responsible persons c…","description":"Uncontrolled Resource Consumption vulnerability in Apache InLong. Non-template responsible persons can view template information.\n\nThis issue affects Apache InLong: from 2.0.0 before 2.4.0.\n\n\n\nUsers are advised to upgrade to Apache InLong's  2.4.0 or cherry-pick [1] to solve it.\n\n[1] \n\n https://gith…","indicators":{"cves":["CVE-2026-63015"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T16:17:28.557Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://lists.apache.org/thread/b7bvsg59bo619rywwpd7tj66rkzz62k4","label":"security@apache.org","domainType":"other"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/20/9","label":"af854a3a-2127-422b-91ae-364da2661108","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-63016","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-63016 — Uncontrolled Resource Consumption vulnerability in Apache InLong. Users could affect operational con…","description":"Uncontrolled Resource Consumption vulnerability in Apache InLong. Users could affect operational configuration or allow upload of non-official packages.\n\nThis issue affects Apache InLong: from 2.0.0 before 2.4.0.\n\n\n\nUsers are advised to upgrade to Apache InLong's  2.4.0 or cherry-pick [1] to solve i…","indicators":{"cves":["CVE-2026-63016"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T16:17:29.097Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://lists.apache.org/thread/jmsn2slhqmmw7kt24zqcnw6tyjnrcykp","label":"security@apache.org","domainType":"other"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/20/10","label":"af854a3a-2127-422b-91ae-364da2661108","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-76997","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-76997 — A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. The affecte…","description":"A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. The affected element is an unknown function of the file /admin/ajax.php?action=save_category. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploi…","indicators":{"cves":["CVE-2026-76997"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T16:18:31.070Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/hubdk01/cve/issues/3","label":"cna@vuldb.com","domainType":"primary"},{"url":"https://vuldb.com/cve/CVE-2026-76997","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/submit/880392","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/vuln/393620","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/vuln/393620/cti","label":"cna@vuldb.com","domainType":"other"},{"url":"https://www.sourcecodester.com/","label":"cna@vuldb.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-76999","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-76999 — A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analy…","description":"A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects the function add_grade of the file /index.php. Performing a manipulation of the argument student_id results in improper authorization. The attack can be initiated remotely.","indicators":{"cves":["CVE-2026-76999"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T16:18:31.410Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://vuldb.com/cve/CVE-2026-76999","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/submit/880522","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/vuln/393622","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/vuln/393622/cti","label":"cna@vuldb.com","domainType":"other"},{"url":"https://www.sourcecodester.com/","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/submit/880522","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-54770","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-54770 — WebOb provides objects for HTTP requests and responses. Prior to 1.8.11, Response._make_location_abs…","description":"WebOb provides objects for HTTP requests and responses. Prior to 1.8.11, Response._make_location_absolute() in src/webob/response.py checks a Location value for a URI scheme or leading double slash before urllib.parse.urljoin() strips leading C0 control characters and spaces. An attacker-controlled…","indicators":{"cves":["CVE-2026-54770"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["phishing"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:18:18.277Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/Pylons/webob/commit/ff89560643fb252751b4db8806a283b5377f1f07","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/Pylons/webob/security/advisories/GHSA-6hx8-3wjj-gr8g","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/Pylons/webob/tree/1.8.11","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-55586","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-55586 — SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, a crafted CHM file can supply…","description":"SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, a crafted CHM file can supply malformed LZX Huffman code lengths to make_decode_table in ext/CHMLib/lzx.c. In the long-code branch, the function writes new internal nodes through next_symbol before validating that the canonical H…","indicators":{"cves":["CVE-2026-55586"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:18:27.723Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/sumatrapdfreader/sumatrapdf/commit/13b3d4204dd12d93d426f2157b157b149edc29bf","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/sumatrapdfreader/sumatrapdf/security/advisories/GHSA-m423-rp8p-whj8","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-61625","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-61625 — VictoriaMetrics is a scalable solution for monitoring and managing time series data. Prior to 1.122.…","description":"VictoriaMetrics is a scalable solution for monitoring and managing time series data. Prior to 1.122.25, 1.136.12, and 1.146.0, vmrestore does not validate backup part path components before using lib/backup/actions/restore.go and lib/backup/fslocal/fslocal.go to write restored data below storageData…","indicators":{"cves":["CVE-2026-61625"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:18:51.783Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/VictoriaMetrics/VictoriaMetrics/commit/710c920d6083327042a309e449fae4383617d817","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/VictoriaMetrics/VictoriaMetrics/releases/tag/v1.122.25","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/VictoriaMetrics/VictoriaMetrics/releases/tag/v1.136.12","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/VictoriaMetrics/VictoriaMetrics/releases/tag/v1.146.0","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/VictoriaMetrics/VictoriaMetrics/security/advisories/GHSA-8q3c-rjr9-xxrp","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-77025","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-77025 — A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unkno…","description":"A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file /viewappointmentpending.php. This manipulation of the argument delid causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to…","indicators":{"cves":["CVE-2026-77025"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:19:49.583Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/ltranquility/vuln_submit/issues/24","label":"cna@vuldb.com","domainType":"primary"},{"url":"https://itsourcecode.com/","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/cve/CVE-2026-77025","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/submit/880600","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/vuln/393638","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/vuln/393638/cti","label":"cna@vuldb.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-54625","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-54625 — django CMS is a content management system powered by Django. Prior to 5.0.8 and in 5.1.0a1, the djan…","description":"django CMS is a content management system powered by Django. Prior to 5.0.8 and in 5.1.0a1, the django CMS page cache in cms/cache/page.py ignores request headers declared by plugins through get_vary_cache_on(). The _page_cache_key function includes the cache prefix, site, language, path, and timezo…","indicators":{"cves":["CVE-2026-54625"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T18:16:28.170Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/django-cms/django-cms/commit/8758714b865ffa79c6bcd0e5c503958ea48885aa","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/django-cms/django-cms/commit/d5dc1efa18d157445491c4b12c2dd1efd56f439f","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/django-cms/django-cms/pull/8646","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/django-cms/django-cms/pull/8647","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/django-cms/django-cms/releases/tag/5.0.8","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/django-cms/django-cms/releases/tag/5.1.0","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/django-cms/django-cms/security/advisories/GHSA-fwjf-m4qw-9f2x","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-72844","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-72844 — The Lean 4 kernel does not verify that the structure named in a projection expression matches the ty…","description":"The Lean 4 kernel does not verify that the structure named in a projection expression matches the type of the value being projected, and environment::add_inductive in src/kernel/inductive.cpp did not type check the nested inductive applications that are replaced by auxiliary types, so their parametr…","indicators":{"cves":["CVE-2026-72844"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T18:16:45.290Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://github.com/endrazine/lean-cve-poc","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/leanprover/lean4","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/leanprover/lean4/commit/a39eab69e1eee9ad38f4efe507907b1026a77808","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/leanprover/lean4/issues/14576","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/leanprover/lean4/pull/14577","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/xrchz/CollatzLean","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://www.openwall.com/lists/oss-security/2026/08/02/1","label":"disclosure@vulncheck.com","domainType":"other"},{"url":"https://www.vulncheck.com/advisories/lean-4-kernel-type-checking-bypass-via-mismatched-structure-projections","label":"disclosure@vulncheck.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-72847","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-72847 — broot renders each file and directory name in its interactive tree view exactly as read from the fil…","description":"broot renders each file and directory name in its interactive tree view exactly as read from the filesystem. Names are converted with a plain to_string_lossy() call in src/tree_build/builder.rs and in TreeLine::unprune in src/tree/tree_line.rs, and no control-character filtering exists anywhere in t…","indicators":{"cves":["CVE-2026-72847"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T18:16:45.540Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://github.com/Canop/broot","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/Canop/broot/blob/v1.58.0/src/tree/tree_line.rs","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/Canop/broot/blob/v1.58.0/src/tree_build/builder.rs","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/Canop/broot/commit/0717a94b3c0efa19c7bbcfe0fb49a2374752a168","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/Canop/broot/commit/4ba40f7d47af78457c7656f15eba71d63d97fce5","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/Canop/broot/issues/1188","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://www.vulncheck.com/advisories/broot-terminal-escape-sequence-injection-via-unsanitized-file-and-directory-names-in-the-tree-view","label":"disclosure@vulncheck.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-73254","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-73254 — Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can create a…","description":"Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can create a file with an HTML payload in its name can trigger stored cross-site scripting when a user browses a directory served with MG_ENABLE_DIRLIST. The printdirentry() path called by listdir() in src/http.c…","indicators":{"cves":["CVE-2026-73254"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T18:16:46.113Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://github.com/cesanta/mongoose/commit/a9df523f76f43a38bd53b4232b9cfd4c16869e71","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cesanta/mongoose/pull/3611","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cesanta/mongoose/releases/tag/7.22","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cesanta/mongoose/security/advisories/GHSA-5g6j-m3pv-4f7g","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-73255","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-73255 — Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can control a…","description":"Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can control an SSI-enabled file can place directory traversal sequences in an #include file or #include virtual directive. The mg_ssi() function in src/ssi.c concatenates the directive argument into a filesystem p…","indicators":{"cves":["CVE-2026-73255"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T18:16:46.313Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://github.com/cesanta/mongoose/commit/a9df523f76f43a38bd53b4232b9cfd4c16869e71","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cesanta/mongoose/pull/3611","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cesanta/mongoose/releases/tag/7.22","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cesanta/mongoose/security/advisories/GHSA-h7m9-764r-7x4x","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-73258","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-73258 — Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can place a…","description":"Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can place a lone carriage return or line feed in multipart input processed by mg_http_next_multipart() in src/http.c. The loops comparing s[b] and s[b + 1], and s[h2] and s[h2 + 1], use an incorrect AND conditio…","indicators":{"cves":["CVE-2026-73258"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T18:16:47.323Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://github.com/cesanta/mongoose/commit/a9df523f76f43a38bd53b4232b9cfd4c16869e71","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cesanta/mongoose/pull/3611","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cesanta/mongoose/releases/tag/7.22","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cesanta/mongoose/security/advisories/GHSA-cc55-8v3r-59p8","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cesanta/mongoose/security/advisories/GHSA-cc55-8v3r-59p8","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-73259","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-73259 — Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can send a…","description":"Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can send a crafted percent-encoded request path to a deployment using MG_ENABLE_DIRLIST and persuade a user to visit it. The mg_http_serve_dir() and listdir() path in src/http.c places the decoded request URI in…","indicators":{"cves":["CVE-2026-73259"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T18:16:47.730Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://github.com/cesanta/mongoose/commit/a9df523f76f43a38bd53b4232b9cfd4c16869e71","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cesanta/mongoose/pull/3611","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cesanta/mongoose/releases/tag/7.22","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cesanta/mongoose/security/advisories/GHSA-9cwm-487w-h25w","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cesanta/mongoose/security/advisories/GHSA-9cwm-487w-h25w","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-77036","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-77036 — A vulnerability was found in elunez eladmin up to 2.7. The impacted element is the function EmailCon…","description":"A vulnerability was found in elunez eladmin up to 2.7. The impacted element is the function EmailController/AliPayController/GeneratorController/GenConfigController. The manipulation results in improper authorization. The attack can be launched remotely. The exploit has been made public and could be…","indicators":{"cves":["CVE-2026-77036"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T18:16:53.320Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://github.com/elunez/eladmin/","label":"cna@vuldb.com","domainType":"primary"},{"url":"https://github.com/elunez/eladmin/issues/903","label":"cna@vuldb.com","domainType":"primary"},{"url":"https://vuldb.com/cve/CVE-2026-77036","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/submit/880860","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/vuln/393643","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/vuln/393643/cti","label":"cna@vuldb.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-43678","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-43678 — An unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingb…","description":"An unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingbird) with a single 11-byte frame sent after a completed WebSocket handshake, dropping all active connections until the process restarts. This vulnerability is addressed in swift-nio version 2.101.0.","indicators":{"cves":["CVE-2026-43678"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T19:16:52.353Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://github.com/apple/swift-nio/security/advisories/GHSA-qcc5-f287-vgmq","label":"product-security@apple.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-64777","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-64777 — A malicious builder peer may be able to request an in-context file by name from the host and receive…","description":"A malicious builder peer may be able to request an in-context file by name from the host and receive the contents of whatever the name resolves to, even when it resolves outside the build context. This vulnerability is addressed in container version 1.2.0.","indicators":{"cves":["CVE-2026-64777"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T19:16:57.733Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://github.com/apple/container/security/advisories/GHSA-2v2q-4q35-h585","label":"product-security@apple.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-72854","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-72854 — msgpack_unpacker_expand_buffer in src/unpack.c, reached through the public msgpack_unpacker_reserve_…","description":"msgpack_unpacker_expand_buffer in src/unpack.c, reached through the public msgpack_unpacker_reserve_buffer API, computes its new buffer size using an unchecked size_t addition of the requested size and the amount already used. The doubling loop guards its own multiplication against overflow, but the…","indicators":{"cves":["CVE-2026-72854"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T19:17:01.040Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://github.com/msgpack/msgpack-c","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/msgpack/msgpack-c/blob/c-7.0.1/example/lib_buffer_unpack.c","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/msgpack/msgpack-c/blob/c-7.0.1/include/msgpack/unpack.h#L219-L223","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/msgpack/msgpack-c/blob/c-7.0.1/src/unpack.c#L429-L502","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/msgpack/msgpack-c/issues/1181","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://www.vulncheck.com/advisories/msgpack-c-integer-overflow-in-msgpack-unpacker-expand-buffer-causes-a-false-success-undersized-reservation","label":"disclosure@vulncheck.com","domainType":"other"},{"url":"https://github.com/msgpack/msgpack-c/issues/1181","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-75514","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-75514 — BunkerWeb is an open-source, next-generation Web Application Firewall. Prior to 1.6.13, the blacklis…","description":"BunkerWeb is an open-source, next-generation Web Application Firewall. Prior to 1.6.13, the blacklist, greylist, and antibot modules in src/common/core/blacklist/blacklist.lua, src/common/core/greylist/greylist.lua, and src/common/core/antibot/antibot.lua trust PTR suffix matches in IGNORE_RDNS, GRE…","indicators":{"cves":["CVE-2026-75514"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T19:17:03.637Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://github.com/bunkerity/bunkerweb/commit/1a97e5b3f977130a1b84507a9e1f703c8eec12eb","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/bunkerity/bunkerweb/pull/3710","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/bunkerity/bunkerweb/releases/tag/v1.6.13","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/bunkerity/bunkerweb/security/advisories/GHSA-q54j-5484-pvjm","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/bunkerity/bunkerweb/security/advisories/GHSA-q54j-5484-pvjm","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-72861","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-72861 — The github-issue-bot templates in appwrite/templates verify the GitHub webhook signature with an inv…","description":"The github-issue-bot templates in appwrite/templates verify the GitHub webhook signature with an inverted condition. verifyWebhook in node/github-issue-bot/src/github.js and in node-typescript/github-issue-bot/src/github.ts returns \"typeof signature !== 'string' || (await verify(...))\", so when the…","indicators":{"cves":["CVE-2026-72861"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T20:17:46.190Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://github.com/appwrite/templates","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/appwrite/templates/blob/1.1.2/node-typescript/github-issue-bot/src/github.ts","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/appwrite/templates/blob/1.1.2/node/github-issue-bot/src/github.js","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/appwrite/templates/blob/1.1.2/node/github-issue-bot/src/main.js","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/appwrite/templates/issues/350","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://www.vulncheck.com/advisories/appwrite-templates-github-issue-bot-skips-webhook-signature-verification-when-the-x-hub-signature-256-header-is-absent","label":"disclosure@vulncheck.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-75910","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-75910 — Incorrect privilege assignment in the ClickHouse connector deployment template in Amazon Athena Fede…","description":"Incorrect privilege assignment in the ClickHouse connector deployment template in Amazon Athena Federated Query prior to v2026.17.1 could allow an authenticated remote user to read arbitrary AWS Secrets Manager secrets in the deploying account by pointing the connector's connection string at an unre…","indicators":{"cves":["CVE-2026-75910"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T20:17:46.937Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://aws.amazon.com/security/security-bulletins/2026-084-aws/","label":"ff89ba41-3aa1-4d27-914a-91399e9639e5","domainType":"other"},{"url":"https://github.com/awslabs/aws-athena-query-federation/releases/tag/v2026.17.1","label":"ff89ba41-3aa1-4d27-914a-91399e9639e5","domainType":"primary"},{"url":"https://github.com/awslabs/aws-athena-query-federation/security/advisories/GHSA-vmjg-c6wv-wjm9","label":"ff89ba41-3aa1-4d27-914a-91399e9639e5","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-67445","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-67445 — Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit reads SMTP command…","description":"Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit reads SMTP commands through internal/smtpd/smtpd.go session.readLine() using bufio.Reader.ReadString before session.parseLine() parses the verb or the RFC 5321 512-octet command-line limit is enforced. An unauthenticat…","indicators":{"cves":["CVE-2026-67445"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T21:17:07.110Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://github.com/axllent/mailpit/commit/993bed95b3c74d95231af93bd0e0d4c3d5b4db4d","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/axllent/mailpit/releases/tag/v1.30.4","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/axllent/mailpit/security/advisories/GHSA-w878-pj84-3j5v","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-67446","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-67446 — Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit decodes attacker-s…","description":"Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit decodes attacker-supplied image attachments into a full raster before checking decoded dimensions, pixel count, or memory use in the GET /api/v1/message/{id}/part/{partID}/thumb endpoint. The Thumbnail handler in serve…","indicators":{"cves":["CVE-2026-67446"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T21:17:07.260Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://github.com/axllent/mailpit/commit/6bcb6337838b542d53c348e38c7977f569b6db35","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/axllent/mailpit/releases/tag/v1.30.4","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/axllent/mailpit/security/advisories/GHSA-75mr-qw9x-3r39","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-68921","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-68921 — DiceBear is an avatar library for designers and developers. Prior to 9.4.3, @dicebear/core interpola…","description":"DiceBear is an avatar library for designers and developers. Prior to 9.4.3, @dicebear/core interpolates the rotate option into an SVG transform attribute without XML escaping in addRotate in packages/@dicebear/core/src/utils/svg.ts, while @dicebear/initials similarly emits fontSize and fontWeight wi…","indicators":{"cves":["CVE-2026-68921"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T21:17:07.540Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://github.com/dicebear/dicebear/commit/922946d738c4e77ab6c412e27ede75941fec4b59","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/dicebear/dicebear/releases/tag/v9.4.3","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/dicebear/dicebear/security/advisories/GHSA-gcr2-9v8m-gq45","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-76018","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-76018 — Privilege elevation in Import in Google Chrome prior to 151.0.7922.173 allowed a remote attacker lev…","description":"Privilege elevation in Import in Google Chrome prior to 151.0.7922.173 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted file. (Chromium security severity: High)","indicators":{"cves":["CVE-2026-76018"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["phishing"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T21:17:09.920Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0404570826.html","label":"chrome-cve-admin@google.com","domainType":"other"},{"url":"https://issues.chromium.org/issues/513757918","label":"chrome-cve-admin@google.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-76019","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-76019 — Incorrect authorization in Workers in Google Chrome prior to 151.0.7922.173 allowed a remote attacke…","description":"Incorrect authorization in Workers in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)","indicators":{"cves":["CVE-2026-76019"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["phishing"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T21:17:10.040Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0404570826.html","label":"chrome-cve-admin@google.com","domainType":"other"},{"url":"https://issues.chromium.org/issues/539032888","label":"chrome-cve-admin@google.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-77506","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-77506 — Znuny before LTS 6.5.22 allows AgentTicketEmailResend template XSS.","description":"Znuny before LTS 6.5.22 allows AgentTicketEmailResend template XSS.","indicators":{"cves":["CVE-2026-77506"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T21:17:10.673Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://www.znuny.org/en/advisories/zsa-2026-12","label":"cve@mitre.org","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-77587","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-77587 — Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object whe…","description":"Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object when a recovery leg revives a conflux set whose last linked leg has already been closed. A malicious exit node could use this to crash a client. This is TROVE-2026-026.","indicators":{"cves":["CVE-2026-77587"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T21:17:10.957Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://gitlab.torproject.org/tpo/core/tor/-/raw/tor-0.4.9.11/ChangeLog","label":"cve@mitre.org","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-77639","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-77639 — Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many g…","description":"Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream detection threshold, to avoid the compression bomb check entirely. This is TROVE-2026-022.","indicators":{"cves":["CVE-2026-77639"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T21:17:11.233Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://gitlab.torproject.org/tpo/core/tor/-/raw/tor-0.4.9.9/ChangeLog","label":"cve@mitre.org","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-77641","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-77641 — tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails. Th…","description":"tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails. The return value of relay_send_command_from_edge() was   ignored, so a send failure (which calls circuit_mark_for_close()  and removes the leg via cfx_del_leg()) would go undetected, causing the caller…","indicators":{"cves":["CVE-2026-77641"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T21:17:11.517Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://gitlab.torproject.org/tpo/core/tor/-/raw/tor-0.4.9.9/ChangeLog","label":"cve@mitre.org","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-16951","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-16951 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local authenticated attacker to execute…","description":"IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local authenticated attacker to execute arbitrary code due to a heap-based buffer overflow.","indicators":{"cves":["CVE-2026-16951"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:08.977Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://www.ibm.com/support/pages/node/7283858","label":"psirt@us.ibm.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-16964","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-16964 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to intercept messages an…","description":"IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to intercept messages and forge replies due to the exposure of sensitive information.","indicators":{"cves":["CVE-2026-16964"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:09.470Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://www.ibm.com/support/pages/node/7283858","label":"psirt@us.ibm.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-16973","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-16973 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to disclose sensitive ker…","description":"IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to disclose sensitive kernel memory due to an out-of-bounds read.","indicators":{"cves":["CVE-2026-16973"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:09.810Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://www.ibm.com/support/pages/node/7283858","label":"psirt@us.ibm.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-17424","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-17424 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to bypass security restr…","description":"IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to bypass security restrictions due to improper limitation of a pathname to a restricted directory.","indicators":{"cves":["CVE-2026-17424"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:15.940Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://www.ibm.com/support/pages/node/7283858","label":"psirt@us.ibm.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-19448","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-19448 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory corruption vulnerability exists in the…","description":"IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory corruption vulnerability exists in the AIX IPsec ESP decapsulation handler. Successful exploitation may corrupt kernel stack state and cause a system crash, resulting in denial of service.","indicators":{"cves":["CVE-2026-19448"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:18.440Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://www.ibm.com/support/pages/node/7283858","label":"psirt@us.ibm.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-19783","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-19783 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause kernel memory co…","description":"IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause kernel memory corruption due to insufficient validation. A crafted filesystem image can trigger an out-of-bounds kernel-stack write during directory reads, causing a system crash or potentially enabling privilege esc…","indicators":{"cves":["CVE-2026-19783"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:18.773Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://www.ibm.com/support/pages/node/7283858","label":"psirt@us.ibm.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-49244","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-49244 — SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the public we…","description":"SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the public web-client partial ZIP download endpoint for a browsable share validates client-supplied files entries with a raw byte-prefix comparison rather than a directory-boundary-aware check. An unauthenticated…","indicators":{"cves":["CVE-2026-49244"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:19.947Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://github.com/drakkan/sftpgo/commit/52a56584c417e325aea35ab23849422a90ba512f","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/drakkan/sftpgo/releases/tag/v2.7.3","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/drakkan/sftpgo/security/advisories/GHSA-h64p-8h4r-6gfh","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-54389","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-54389 — Ghidra before 12.1.3 contains an uncontrolled resource consumption vulnerability in the PDB parser t…","description":"Ghidra before 12.1.3 contains an uncontrolled resource consumption vulnerability in the PDB parser that allows attackers to terminate the Ghidra process by supplying a crafted PDB file with an oversized parameters section. The AbstractPdb deserialization routine reads all remaining parameters into a…","indicators":{"cves":["CVE-2026-54389"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:21.117Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://github.com/NationalSecurityAgency/ghidra/releases/tag/Ghidra_12.1.3_build","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/NationalSecurityAgency/ghidra/security/advisories/GHSA-f75p-8cqj-9v3g","label":"disclosure@vulncheck.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-54509","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-54509 — TREK is a collaborative travel planner. From 3.0.0 until 3.1.0, the GET /api/journeys/:id/share-link…","description":"TREK is a collaborative travel planner. From 3.0.0 until 3.1.0, the GET /api/journeys/:id/share-link route in server/src/routes/journey.ts returns the result of getJourneyShareLink() from server/src/services/journeyShareService.ts without checking whether the authenticated requester can access the j…","indicators":{"cves":["CVE-2026-54509"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:21.553Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://github.com/liketrek/TREK/commit/ad893eb1cc75b6d56f402d73a6d41bd48ba7ae11","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/liketrek/TREK/pull/1185","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/liketrek/TREK/releases/tag/v3.1.0","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/liketrek/TREK/security/advisories/GHSA-mx6m-qxv8-w624","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-55015","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-55015 — Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny servic…","description":"Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally.","indicators":{"cves":["CVE-2026-55015"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:22.080Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55015","label":"secure@microsoft.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-55489","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-55489 — BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton presenters could s…","description":"BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton presenters could submit a presentationId through /api/graphql that identified a presentation belonging to another meeting. akka-bbb-apps/src/main/scala/org/bigbluebutton/core/apps/presentationpod/RemovePresentationPubM…","indicators":{"cves":["CVE-2026-55489"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:22.200Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://github.com/bigbluebutton/bigbluebutton/commit/c9e93f9af07b9661e286d101b83cbccb891c551f","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/bigbluebutton/bigbluebutton/releases/tag/v3.0.29","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-jxpq-r3h3-p75g","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-55491","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-55491 — BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton failed to escape m…","description":"BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton failed to escape meetingName in record-and-playback/screenshare/playback/index.html.erb when generating the screenshare playback format. A low-privileged user could store a crafted meeting name that embedded script con…","indicators":{"cves":["CVE-2026-55491"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["ransomware"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:22.347Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://github.com/bigbluebutton/bigbluebutton/commit/a53f2b92022388bfa4109d3136d1f3a932404b1b","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/bigbluebutton/bigbluebutton/releases/tag/v3.0.29","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-57p5-c888-74f9","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-62945","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-62945 — TREK is a collaborative travel planner. Prior to 3.1.3, TREK file upload, update, and link actions a…","description":"TREK is a collaborative travel planner. Prior to 3.1.3, TREK file upload, update, and link actions accept attacker-controlled reservation_id, place_id, and assignment_id values without using findForeignLinkTarget() to verify that the referenced object belongs to the file's trip. An authenticated use…","indicators":{"cves":["CVE-2026-62945"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:46.740Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://github.com/liketrek/TREK/commit/03cdb4d27689922460ba87085d04b426d4d40d26","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/liketrek/TREK/pull/1324","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/liketrek/TREK/releases/tag/v3.1.3","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/liketrek/TREK/security/advisories/GHSA-r4cp-666p-8f69","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-67447","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-67447 — Mailpit is an email testing tool and API for developers. From 1.30.0 until 1.30.5, Mailpit's interna…","description":"Mailpit is an email testing tool and API for developers. From 1.30.0 until 1.30.5, Mailpit's internal/smtpd/smtpd.go readData() function calls bufio.Reader.ReadBytes before applying the len(data)+len(line) size check to the completed SMTP DATA line against Server.MaxSize. An unauthenticated SMTP cli…","indicators":{"cves":["CVE-2026-67447"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:56.720Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://github.com/axllent/mailpit/commit/8720c6bd8281fc00d458081908f1dbef8e59a98c","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/axllent/mailpit/releases/tag/v1.30.5","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/axllent/mailpit/security/advisories/GHSA-r553-m4fv-5v97","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-67448","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-67448 — Mailpit is an email testing tool and API for developers. From 1.29.0 until 1.30.6, Mailpit's server/…","description":"Mailpit is an email testing tool and API for developers. From 1.29.0 until 1.30.6, Mailpit's server/server.go origin middleware checks the raw RequestURI for the /api/ prefix while Go's ServeMux routes using the percent-decoded URL path, and server/websockets/client.go configures websocket.Upgrader.…","indicators":{"cves":["CVE-2026-67448"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:56.870Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://github.com/axllent/mailpit/commit/fbe5e006c3f1682b819df58b4a932d7a84920be9","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/axllent/mailpit/releases/tag/v1.30.6","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/axllent/mailpit/security/advisories/GHSA-8r62-w5wh-fc5m","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-70105","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-70105 — Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose infor…","description":"Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.","indicators":{"cves":["CVE-2026-70105"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:18:01.723Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70105","label":"secure@microsoft.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-72846","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-72846 — Lightdash stores the webhook URL supplied with a scheduled delivery and later posts to it from sendW…","description":"Lightdash stores the webhook URL supplied with a scheduled delivery and later posts to it from sendWebhook in packages/backend/src/clients/GoogleChat/GoogleChatClient.ts and in packages/backend/src/clients/MicrosoftTeams/MicrosoftTeamsClient.ts. In affected versions both call fetch on the stored URL…","indicators":{"cves":["CVE-2026-72846"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:18:05.400Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://github.com/lightdash/lightdash","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/lightdash/lightdash/blob/1.146.3/packages/backend/src/clients/GoogleChat/GoogleChatClient.ts","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/lightdash/lightdash/blob/1.146.3/packages/backend/src/clients/MicrosoftTeams/MicrosoftTeamsClient.ts","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/lightdash/lightdash/issues/24389","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://github.com/lightdash/lightdash/releases/tag/1.146.4","label":"disclosure@vulncheck.com","domainType":"primary"},{"url":"https://www.vulncheck.com/advisories/lightdash-scheduled-delivery-webhook-urls-are-not-validated-allowing-server-side-request-forgery","label":"disclosure@vulncheck.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-77643","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-77643 — A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core…","description":"A cross-site scripting vulnerability in \nqueryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and before 1.4.32 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). NOTE: this issue exists because of a missed corner case of CVE-2018-0499.","indicators":{"cves":["CVE-2026-77643"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:18:06.207Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://bugs.debian.org/1144490","label":"cve@mitre.org","domainType":"other"},{"url":"https://lists.xapian.org/pipermail/xapian-devel/2026-August/003429.html","label":"cve@mitre.org","domainType":"other"},{"url":"https://trac.xapian.org/wiki/SecurityFixes/2018-07-02#a2026-08-13update","label":"cve@mitre.org","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-77391","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-77391 — A security flaw has been discovered in SourceCodester Dynamic Input Field Generator Using HTML, CSS,…","description":"A security flaw has been discovered in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This affects an unknown function. The manipulation results in cross-site request forgery. The attack can be launched remotely. The exploit has been released to the public and may be used…","indicators":{"cves":["CVE-2026-77391"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-21T02:16:27.883Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://gist.github.com/rionyxraiza/428d4481fe471704829ca06de7be9d8c","label":"cna@vuldb.com","domainType":"primary"},{"url":"https://vuldb.com/cve/CVE-2026-77391","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/submit/881030","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/vuln/393853","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/vuln/393853/cti","label":"cna@vuldb.com","domainType":"other"},{"url":"https://www.sourcecodester.com/","label":"cna@vuldb.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-77392","source":"nvd","category":"vulnerability","severity":"medium","title":"CVE-2026-77392 — A weakness has been identified in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and…","description":"A weakness has been identified in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This impacts the function saveUser of the file /public/submit.php. This manipulation of the argument Researcher causes sql injection. The attack may be initiated remotely. The exploit has bee…","indicators":{"cves":["CVE-2026-77392"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-21T02:16:28.063Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://gist.github.com/rionyxraiza/6b22a5e02da6b8581495761ff7393760","label":"cna@vuldb.com","domainType":"primary"},{"url":"https://vuldb.com/cve/CVE-2026-77392","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/submit/881045","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/vuln/393854","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/vuln/393854/cti","label":"cna@vuldb.com","domainType":"other"},{"url":"https://www.sourcecodester.com/","label":"cna@vuldb.com","domainType":"other"}],"feedLabel":null},{"id":"otx-6a8734846b4cc1afd4bde567","source":"otx","category":"threat-intel","severity":"medium","title":"BRIDGEHEAD: An npm typosquatting campaign that crosses from WSL into Windows to plant a crypto-wallet stealer","description":"In August 2026, an operator published forty typosquatted npm packages mimicking popular libraries like chalk, axios, commander, lodash, react, and typescript. Each package contained an install script that profiles the host and, when detecting Windows or WSL environments, downloads a 22MB Rust-based…","indicators":{"cves":[],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":"6888d4c54ef2b5bf23889f9637c2efe77e1d2af4724d315b73d646cf5547dc73"}},"tags":["rust","github-hosted-payload","browser-credentials","wsl","telegram","npm","cryptocurrency-stealer","typosquatting","in-memory-execution","supply-chain","botnet"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:08:20.505Z","fetchedAt":"2026-08-21T03:00:01.555Z","references":[{"url":"https://otx.alienvault.com/pulse/6a8734846b4cc1afd4bde567","label":"OTX Pulse","domainType":"primary"}],"feedLabel":null},{"id":"otx-6a8734bb1e57bed1c101e5e9","source":"otx","category":"threat-intel","severity":"medium","title":"How Peer2Profit and Astroproxy Turn Your Bandwidth Into Someone Else's Product","description":"Investigation into residential proxy networks reveals that bandwidth-sharing applications like PEER2PROFIT recruit users to share internet connections for payment, then monetize this bandwidth through commercial proxy service ASTROPROXY at up to 27 times the original cost. Over 72 hours, researchers…","indicators":{"cves":[],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":"c85c7436fdb71cf52db6ef134b336d66c7dbd3738a7866f8b9992434d1208a4b"}},"tags":["backconnect infrastructure","bandwidth-sharing","internal network exposure","privateloader","sdk analysis","proxy enumeration","peer2profit","residential proxies","astroproxy"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:09:15.451Z","fetchedAt":"2026-08-21T03:00:01.555Z","references":[{"url":"https://otx.alienvault.com/pulse/6a8734bb1e57bed1c101e5e9","label":"OTX Pulse","domainType":"primary"}],"feedLabel":null},{"id":"otx-6a873496e3b94c2a2c962d39","source":"otx","category":"threat-intel","severity":"medium","title":"N4D Mesh Controller: New infrastructure, a UPX-packed agent labeled \"go-titan,\" and how to hunt for it","description":"N4D Mesh Controller is an active Linux malware campaign exploiting exposed Model Context Protocol (MCP) servers and various internet-facing services for credential theft, lateral movement, and command and control. First documented in June 2026, recent analysis reveals evolved tactics including a new…","indicators":{"cves":["CVE-2023-48022","CVE-2026-26220","CVE-2026-27944","CVE-2026-33032","CVE-2026-39987"],"ips":[],"domains":["cdnorigin.net"],"urls":["http://209.99.186.235:8443/api/agent/full?arch=amd64"],"hashes":{"md5":"b8e66803519f9376f243cef0ef017867","sha1":"6e282e673293e5599e97c19cfa6e2d04ac3bd418","sha256":"e09ac5e8c23a768a2370cff29aca64be0d6e210e1176ee526bb7e47f537509ae"}},"tags":["n4d mesh controller","cve-2023-48022","cve-2026-26220","linux malware","go-titan","cve-2026-27944","ray dashboard","cve-2026-33032","n4d","cve-2026-39987","mcp exploitation","lateral movement","ai infrastructure targeting","cloudflare tunnels","credential theft","lightllm","botnet"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:08:38.281Z","fetchedAt":"2026-08-21T03:00:01.555Z","references":[{"url":"https://otx.alienvault.com/pulse/6a873496e3b94c2a2c962d39","label":"OTX Pulse","domainType":"primary"}],"feedLabel":null},{"id":"news-hackers-poison-arrayref-rust-crate-to-push-infostealer-malware","source":"general-news","category":"news","severity":"medium","title":"Hackers poison arrayref Rust crate to push infostealer malware","description":"Hackers compromised the maintainer account behind the widely used Rust crate arrayref to introduce malware that executed on developers' systems during compilation. [...]","indicators":{"cves":[],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["infostealer"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:53:52.000Z","fetchedAt":"2026-08-21T03:00:02.308Z","references":[{"url":"https://www.bleepingcomputer.com/news/security/hackers-poison-arrayref-rust-crate-to-push-infostealer-malware/","label":"BleepingComputer","domainType":"media"}],"feedLabel":null},{"id":"nvd-CVE-2026-64846","source":"nvd","category":"vulnerability","severity":"low","title":"CVE-2026-64846 — Nix is a package manager for Linux and other Unix systems. Prior to 2.35.0, a malicious derivation e…","description":"Nix is a package manager for Linux and other Unix systems. Prior to 2.35.0, a malicious derivation executed with the recursive-nix experimental feature can exploit a time-of-check/time-of-use race involving final symlink handling in the LocalStore restore path. The race can cause writeFile to follow…","indicators":{"cves":["CVE-2026-64846"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:19:16.813Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/NixOS/nix/commit/26679828f74ee6e82a4100904e6361f993ff5390","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/NixOS/nix/pull/15401","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/NixOS/nix/security/advisories/GHSA-6h4g-g5j9-fm5f","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-49996","source":"nvd","category":"vulnerability","severity":"low","title":"CVE-2026-49996 — SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle s…","description":"SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. Prior to version 1.3.1, a malicious SecureDrop Server could bypass securedrop-proxy's origin limitation by responding with cross-origin redirects. SecureDrop…","indicators":{"cves":["CVE-2026-49996"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T19:16:53.757Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://github.com/freedomofpress/securedrop-client/commit/3c9769b12fb115768d43617635fd2e00737ef2f7","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/freedomofpress/securedrop-client/security/advisories/GHSA-6qxc-pcfg-v6qv","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-77151","source":"nvd","category":"vulnerability","severity":"low","title":"CVE-2026-77151 — A security flaw has been discovered in lin-snow Ech0 up to 5.4.1. Affected by this issue is the func…","description":"A security flaw has been discovered in lin-snow Ech0 up to 5.4.1. Affected by this issue is the function MD5Encrypt of the file internal/util/crypto/crypto.go. Performing a manipulation results in risky cryptographic algorithm. Remote exploitation of the attack is possible. The complexity of an atta…","indicators":{"cves":["CVE-2026-77151"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T20:17:47.253Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://github.com/lin-snow/Ech0/","label":"cna@vuldb.com","domainType":"primary"},{"url":"https://github.com/lin-snow/Ech0/commit/9ce19a3b0d0765086a655f45d3a706ec1810404f","label":"cna@vuldb.com","domainType":"primary"},{"url":"https://github.com/lin-snow/Ech0/issues/314","label":"cna@vuldb.com","domainType":"primary"},{"url":"https://github.com/lin-snow/Ech0/pull/315","label":"cna@vuldb.com","domainType":"primary"},{"url":"https://github.com/lin-snow/Ech0/releases/tag/ech0-5.4.2","label":"cna@vuldb.com","domainType":"primary"},{"url":"https://vuldb.com/cve/CVE-2026-77151","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/submit/881015","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/vuln/393736","label":"cna@vuldb.com","domainType":"other"},{"url":"https://vuldb.com/vuln/393736/cti","label":"cna@vuldb.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-77640","source":"nvd","category":"vulnerability","severity":"low","title":"CVE-2026-77640 — tor before 0.4.9.9 was prone to an infinite loop when decompressing a truncated zlib/gzip stream wit…","description":"tor before 0.4.9.9 was prone to an infinite loop when decompressing a truncated zlib/gzip  stream with done=1. A truncated stream never reaches Z_STREAM_END,  causing zlib to return Z_BUF_ERROR with no input remaining, which  buf_add_compress() mistook for a full output buffer and retried forever. F…","indicators":{"cves":["CVE-2026-77640"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T21:17:11.373Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://gitlab.torproject.org/tpo/core/tor/-/raw/tor-0.4.9.9/ChangeLog","label":"cve@mitre.org","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-49245","source":"nvd","category":"vulnerability","severity":"low","title":"CVE-2026-49245 — SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the inline qu…","description":"SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the inline query parameter on browsable-share file downloads and authenticated user-file downloads suppresses Content-Disposition: attachment, allowing an attacker-controlled HTML file stored in a share or home di…","indicators":{"cves":["CVE-2026-49245"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":["phishing"],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:20.107Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://github.com/drakkan/sftpgo/commit/b5409a478138fca5f1d369ae5d47f753156cbd15","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/drakkan/sftpgo/releases/tag/v2.7.3","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/drakkan/sftpgo/security/advisories/GHSA-3vcg-pv95-pq54","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-77648","source":"nvd","category":"vulnerability","severity":"low","title":"CVE-2026-77648 — In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_f…","description":"In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that\nbypass import_filtering_opts, allowing an admin to fetch internal\nURLs from the Glance service network (aka SSRF), as long as https:// or http:// is used. This API has been available only to admins since Xena, and i…","indicators":{"cves":["CVE-2026-77648"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T23:16:28.797Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://wiki.openstack.org/wiki/OSSN/OSSN-0105","label":"cve@mitre.org","domainType":"other"},{"url":"https://www.openwall.com/lists/oss-security/2026/08/11/7","label":"cve@mitre.org","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-64961","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-64961 — ATutor is vulnerable to authentication bypass . Although a token validation check is present in the…","description":"ATutor is vulnerable to authentication bypass . Although a token validation check is present in the auto-login functionality, the values required for token validation remain uninitialized in certain code paths. An unauthenticated attacker who can determine a user's identifier and registration timest…","indicators":{"cves":["CVE-2026-64961"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T14:17:44.577Z","fetchedAt":"2026-08-21T03:01:29.087Z","references":[{"url":"https://atutor.github.io/","label":"cvd@cert.pl","domainType":"other"},{"url":"https://cert.pl/en/posts/2026/08/CVE-2026-64960","label":"cvd@cert.pl","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-64962","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-64962 — ATutor is vulnerable to Cross-Site Request Forgery (CSRF) in profile update functionality. An attack…","description":"ATutor is vulnerable to Cross-Site Request Forgery (CSRF) in profile update functionality. An attacker can craft a malicious website which, when visited by an authenticated victim, submits a forged request to the system. Due to the lack of proper CSRF token implementation, the forged request is proc…","indicators":{"cves":["CVE-2026-64962"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T14:17:44.713Z","fetchedAt":"2026-08-21T03:01:29.087Z","references":[{"url":"https://atutor.github.io/","label":"cvd@cert.pl","domainType":"other"},{"url":"https://cert.pl/en/posts/2026/08/CVE-2026-64960","label":"cvd@cert.pl","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-64963","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-64963 — A path traversal vulnerability in ATutor allows an authenticated user to access files from other cou…","description":"A path traversal vulnerability in ATutor allows an authenticated user to access files from other course directories when the AT_FORCE_GET_FILE configuration option is enabled. This can lead to unauthorized access to files and disclosure of information about the filesystem structure.\n\n\n\n\n\n\n\n\nProduct…","indicators":{"cves":["CVE-2026-64963"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T14:17:44.850Z","fetchedAt":"2026-08-21T03:01:29.087Z","references":[{"url":"https://atutor.github.io/","label":"cvd@cert.pl","domainType":"other"},{"url":"https://cert.pl/en/posts/2026/08/CVE-2026-64960","label":"cvd@cert.pl","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-64964","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-64964 — ATutor generates predictable email confirmation tokens due to the use of insufficiently random value…","description":"ATutor generates predictable email confirmation tokens due to the use of insufficiently random values in the account confirmation functionality. Due to the use of predictable values related to user registration, an attacker who knows or can predict these values can guess valid account activation tok…","indicators":{"cves":["CVE-2026-64964"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T14:17:44.990Z","fetchedAt":"2026-08-21T03:01:29.087Z","references":[{"url":"https://atutor.github.io/","label":"cvd@cert.pl","domainType":"other"},{"url":"https://cert.pl/en/posts/2026/08/CVE-2026-64960","label":"cvd@cert.pl","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-64965","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-64965 — ATutor is vulnerable to Missing Authorization Check on Test and Question Import endpoints. A low-pri…","description":"ATutor is vulnerable to Missing Authorization Check on Test and Question Import endpoints.  A low-privileged authenticated user (e.g. a student) enrolled in a course can bypass authorization checks by sending requests directly to the backend import endpoints, allowing the unauthorized import of test…","indicators":{"cves":["CVE-2026-64965"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T14:17:45.133Z","fetchedAt":"2026-08-21T03:01:29.087Z","references":[{"url":"https://atutor.github.io/","label":"cvd@cert.pl","domainType":"other"},{"url":"https://cert.pl/en/posts/2026/08/CVE-2026-64960","label":"cvd@cert.pl","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-64967","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-64967 — A path traversal vulnerability in ATutor's error log viewer allows an attacker with administrative p…","description":"A path traversal vulnerability in ATutor's error log viewer allows an attacker with administrative privileges to access arbitrary files outside the intended logs directory. This can lead to unauthorized access to sensitive files and other resources accessible to the web server process.\n\n\n\n\n\n\nProduct…","indicators":{"cves":["CVE-2026-64967"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T14:17:45.410Z","fetchedAt":"2026-08-21T03:01:29.087Z","references":[{"url":"https://atutor.github.io/","label":"cvd@cert.pl","domainType":"other"},{"url":"https://cert.pl/en/posts/2026/08/CVE-2026-64960","label":"cvd@cert.pl","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-64968","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-64968 — ATutor is vulnerable to Server-Side request forgery in import functionalities. An authenticated admi…","description":"ATutor is vulnerable to Server-Side request forgery in import functionalities. An authenticated administrator can make the server request arbitrary internal HTTP endpoints, cloud metadata services, or local files via file:// if the PHP\nenvironment permits URL wrappers.\n\n\nProduct is no longer activel…","indicators":{"cves":["CVE-2026-64968"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T14:17:45.543Z","fetchedAt":"2026-08-21T03:01:29.087Z","references":[{"url":"https://atutor.github.io/","label":"cvd@cert.pl","domainType":"other"},{"url":"https://cert.pl/en/posts/2026/08/CVE-2026-64960","label":"cvd@cert.pl","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-64969","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-64969 — ATutor is vulnerable to Insecure Direct Object Reference (IDOR) attack in profile picture related en…","description":"ATutor is vulnerable to Insecure Direct Object Reference (IDOR) attack in profile picture related endpoints. Any authenticated user, including a student, can supply another user's member_id in a POST request to the profile album endpoint and permanently delete that user's profile picture, including…","indicators":{"cves":["CVE-2026-64969"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T14:17:45.680Z","fetchedAt":"2026-08-21T03:01:29.087Z","references":[{"url":"https://atutor.github.io/","label":"cvd@cert.pl","domainType":"other"},{"url":"https://cert.pl/en/posts/2026/08/CVE-2026-64960","label":"cvd@cert.pl","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-64970","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-64970 — ATutor is vulnerable to Stored Cross Site Scripting in registration functionality. An attacker can r…","description":"ATutor is vulnerable to Stored Cross Site Scripting in registration functionality.  An attacker can register a new account and enter a JavaScript payload in the phone field during registration. When any authenticated user visits the attacker's public profile, the profile template echoes the phone va…","indicators":{"cves":["CVE-2026-64970"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T14:17:45.810Z","fetchedAt":"2026-08-21T03:01:29.087Z","references":[{"url":"https://atutor.github.io/","label":"cvd@cert.pl","domainType":"other"},{"url":"https://cert.pl/en/posts/2026/08/CVE-2026-64960","label":"cvd@cert.pl","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-64971","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-64971 — ATutor is vulnerable to Reflected XSS in restore functionality. An attacker can provide a specially…","description":"ATutor is vulnerable to Reflected XSS in restore functionality. An attacker can provide a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser.\nProduct is no longer actively supported and the vulnerabilities have not been fixed. Only version 2.2.…","indicators":{"cves":["CVE-2026-64971"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T14:17:45.943Z","fetchedAt":"2026-08-21T03:01:29.087Z","references":[{"url":"https://atutor.github.io/","label":"cvd@cert.pl","domainType":"other"},{"url":"https://cert.pl/en/posts/2026/08/CVE-2026-64960","label":"cvd@cert.pl","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-64972","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-64972 — ATutor is vulnerable to Reflected XSS via popup parameter in preview.php. An authenticated attacker…","description":"ATutor is vulnerable to Reflected XSS via popup parameter in preview.php. An authenticated attacker can inject a double quote into the popup parameter, break out of the attribute value, and append a new event handler such as onload. The related preview_top.php file sanitises these parameters, but th…","indicators":{"cves":["CVE-2026-64972"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T14:17:46.077Z","fetchedAt":"2026-08-21T03:01:29.087Z","references":[{"url":"https://atutor.github.io/","label":"cvd@cert.pl","domainType":"other"},{"url":"https://cert.pl/en/posts/2026/08/CVE-2026-64960","label":"cvd@cert.pl","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-70383","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-70383 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Esto…","description":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Estonian Information System Authority (RIA) DigiDoc4 client.\n\nThis issue affects DigiDoc4: from 4.0.0 before 4.11.0.","indicators":{"cves":["CVE-2026-70383"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T14:17:58.050Z","fetchedAt":"2026-08-21T03:01:29.087Z","references":[{"url":"https://github.com/open-eid/DigiDoc4-Client","label":"a6d3dc9e-0591-4a13-bce7-0f5b31ff6158","domainType":"primary"},{"url":"https://github.com/open-eid/DigiDoc4-Client/pull/1402","label":"a6d3dc9e-0591-4a13-bce7-0f5b31ff6158","domainType":"primary"},{"url":"https://github.com/open-eid/libdigidocpp/pull/736","label":"a6d3dc9e-0591-4a13-bce7-0f5b31ff6158","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-73220","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-73220 — CVAT is an open source interactive video and image annotation tool for computer vision. From 2.68.0…","description":"CVAT is an open source interactive video and image annotation tool for computer vision. From 2.68.0 until 2.70.0, the audio-task annotation guide renderer in cvat-ui/src/audio/components/annotation-page/audio-workspace/top-bar/audio-right-group.tsx passes attacker-controlled guide Markdown to MDEdit…","indicators":{"cves":["CVE-2026-73220"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T15:18:37.200Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/cvat-ai/cvat/commit/33aaa1987ea89a4d229bf4c19fcbe6b04ed55b42","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cvat-ai/cvat/pull/10893","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cvat-ai/cvat/releases/tag/v2.70.0","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cvat-ai/cvat/security/advisories/GHSA-chxx-45vm-qhc9","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-63040","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-63040 — Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource per…","description":"Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource performs no authorization check, any authenticated user can logically delete ALL stream sources.\n\nThis issue affects Apache InLong: from 2.0.0 before 2.4.0.\n\n\n\nUsers are advised to upgrade to Apache InLo…","indicators":{"cves":["CVE-2026-63040"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T16:17:29.993Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://lists.apache.org/thread/sbqrk88cjv3r9rnqfqgn31ox4711offy","label":"security@apache.org","domainType":"other"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/20/14","label":"af854a3a-2127-422b-91ae-364da2661108","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-63042","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-63042 — Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any user who can…","description":"Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any user who can authenticate to the manager can create, modify and delete Data Node definitions.\n\nThis issue affects Apache InLong: from 2.0.0 before 2.4.0.\n\n\n\nUsers are advised to upgrade to Apache InLong's  2.4.0…","indicators":{"cves":["CVE-2026-63042"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T16:17:30.163Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://lists.apache.org/thread/wxs4jfjkoo6rlyovhrx8bo74rfmzwbk7","label":"security@apache.org","domainType":"other"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/20/15","label":"af854a3a-2127-422b-91ae-364da2661108","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-63043","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-63043 — Relative Path Traversal vulnerability in Apache InLong. Arbitrary file read from the Agent host file…","description":"Relative Path Traversal vulnerability in Apache InLong. Arbitrary file read from the Agent host filesystem.\n\nThis issue affects Apache InLong: from 2.0.0 before 2.4.0.\n\n\n\nUsers are advised to upgrade to Apache InLong's  2.4.0 or cherry-pick [1] to solve it.\n\n[1]  https://github.com/apache/inlong/pul…","indicators":{"cves":["CVE-2026-63043"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T16:17:30.327Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://lists.apache.org/thread/0ohn861tzd9g7nsosd6oz3of6dvhvqnk","label":"security@apache.org","domainType":"other"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/20/16","label":"af854a3a-2127-422b-91ae-364da2661108","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-63044","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-63044 — Server-Side Request Forgery (SSRF) vulnerability in Apache InLong. Any authenticated user (no admin…","description":"Server-Side Request Forgery (SSRF) vulnerability in Apache InLong.  Any authenticated user (no admin role required) can cause the InLong Manager server to make outbound HTTP requests or TCP connections to\narbitrary internal hosts and ports.\n\nThis issue affects Apache InLong: from 2.0.0 before 2.4.0.…","indicators":{"cves":["CVE-2026-63044"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T16:17:30.483Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://lists.apache.org/thread/b3rtzssd8hdk0dyq4y6mpdx6jj5ro4g6","label":"security@apache.org","domainType":"other"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/20/17","label":"af854a3a-2127-422b-91ae-364da2661108","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-13121","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-13121 — Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulne…","description":"Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels RAS Client. An attacker must first obtain the ability to execute low-privileged code o…","indicators":{"cves":["CVE-2026-13121","CVE-2026-18262","CVE-2026-18263"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:20.787Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-554/","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-555/","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-556/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18267","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-18267 — Kenwood DNR1007XR Firmware Update Link Following Code Execution Vulnerability. This vulnerability al…","description":"Kenwood DNR1007XR Firmware Update Link Following Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DNR1007XR devices. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exi…","indicators":{"cves":["CVE-2026-18267"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:23.140Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://www.kenwood.com/cs/ce/mm/firmware/2020/2020f/eng.html","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-484/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18268","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-18268 — Kenwood DNR1007XR JKGenService Command Injection Local Privilege Escalation Vulnerability. This vuln…","description":"Kenwood DNR1007XR JKGenService Command Injection Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Kenwood DNR1007XR devices. An attacker must first obtain the ability to execute low-privileged code on the target s…","indicators":{"cves":["CVE-2026-18268"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:23.277Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://www.kenwood.com/cs/ce/mm/firmware/2020/2020f/eng.html","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-485/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18269","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-18269 — Kenwood DNR1007XR tchdr_bytestream_read Out-Of-Bounds Write Code Execution Vulnerability. This vulne…","description":"Kenwood DNR1007XR tchdr_bytestream_read Out-Of-Bounds Write Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DNR1007XR devices. Authentication is not required to exploit this vulnerability.\n\nThe specif…","indicators":{"cves":["CVE-2026-18269"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:23.393Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://www.kenwood.com/cs/ce/mm/firmware/2020/2020f/eng.html","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-486/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18270","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-18270 — Kenwood DNR1007XR udhcpd Incorrect Permission Assignment Local Privilege Escalation Vulnerability. T…","description":"Kenwood DNR1007XR udhcpd Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Kenwood DNR1007XR devices. An attacker must first obtain the ability to execute low-privileged code on the…","indicators":{"cves":["CVE-2026-18270"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:23.513Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://www.kenwood.com/cs/ce/mm/firmware/2020/2020f/eng.html","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-487/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18271","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-18271 — Kenwood DNR1007XR vCardParser Heap-based Buffer Overflow Code Execution Vulnerability. This vulnerab…","description":"Kenwood DNR1007XR vCardParser Heap-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DNR1007XR devices. Authentication is not required to exploit this vulnerability.\n\nThe specific…","indicators":{"cves":["CVE-2026-18271"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:23.640Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://www.kenwood.com/cs/ce/mm/firmware/2020/2020f/eng.html","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-488/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18272","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-18272 — Kenwood DNR1007XR startUpdateProcess Command Injection Vulnerability. This vulnerability allows phys…","description":"Kenwood DNR1007XR startUpdateProcess Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DNR1007XR devices. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists withi…","indicators":{"cves":["CVE-2026-18272"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:23.757Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://www.kenwood.com/cs/ce/mm/firmware/2020/2020f/eng.html","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-489/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18273","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-18273 — Kenwood DNR1007XR USB Incorrect Default Permissions Local Privilege Escalation Vulnerability. This v…","description":"Kenwood DNR1007XR USB Incorrect Default Permissions Local Privilege Escalation Vulnerability. This vulnerability allows physically present attackers to escalate privileges on affected installations of Kenwood DNR1007XR devices. An attacker must first obtain the ability to execute low-privileged code…","indicators":{"cves":["CVE-2026-18273"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:23.880Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://www.kenwood.com/cs/ce/mm/firmware/2020/2020f/eng.html","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-490/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18278","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-18278 — Sony XAV-9500ES prh_l2_decode_packet Out-Of-Bounds Read Information Disclosure Vulnerability. This v…","description":"Sony XAV-9500ES prh_l2_decode_packet Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sony XAV-9500ES devices. An attacker must first obtain the ability to pair a malicious Blu…","indicators":{"cves":["CVE-2026-18278"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:24.123Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://www.sony.com/electronics/support/mobile-cd-players-digital-media-players-xav-series/xav-9500es/software/00274922","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-471/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18280","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-18280 — Sony XAV-9500ES gpsd Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allo…","description":"Sony XAV-9500ES gpsd Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists…","indicators":{"cves":["CVE-2026-18280"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:24.403Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://www.sony.com/electronics/support/mobile-cd-players-digital-media-players-xav-series/xav-9500es/software/00274922","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-473/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18283","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-18283 — Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability. This vulnerability allows physica…","description":"Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability. This vulnerability allows physically present attackers to bypass authorization on affected installations on Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the u…","indicators":{"cves":["CVE-2026-18283"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:24.763Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://www.sony.com/electronics/support/mobile-cd-players-digital-media-players-xav-series/xav-9500es/software/00274922","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-476/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-18284","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-18284 — Sony XAV-9500ES Crash Dump Handler Command Injection Local Privilege Escalation Vulnerability. This…","description":"Sony XAV-9500ES Crash Dump Handler Command Injection Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Sony XAV-9500ES devices. An attacker must first obtain the ability to execute low-privileged code on the target…","indicators":{"cves":["CVE-2026-18284"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:24.883Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://www.sony.com/electronics/support/mobile-cd-players-digital-media-players-xav-series/xav-9500es/software/00274922","label":"zdi-disclosures@trendmicro.com","domainType":"other"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-477/","label":"zdi-disclosures@trendmicro.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-40345","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-40345 — deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects.…","description":"deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects. Prior to 8.0.0, the deepmerge, deepmergeCustom, deepmergeInto, and deepmergeIntoCustom APIs do not track visited objects or object pairs when recursively merging records. When two input values contain…","indicators":{"cves":["CVE-2026-40345"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:17:29.783Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/RebeccaStevens/deepmerge-ts/commit/398492757b3f22a0d7d89b09ce1ae9cd32806c9a","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/RebeccaStevens/deepmerge-ts/pull/707","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/RebeccaStevens/deepmerge-ts/releases/tag/v8.0.0","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/RebeccaStevens/deepmerge-ts/security/advisories/GHSA-ggr8-5vv4-36mx","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-54136","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-54136 — Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows an…","description":"Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to 1.715.0, a resource-scoped API token could read script contents outside its allowed path scope through GET /api/w/{workspace}/scripts/list_search. The route-level scope middleware vali…","indicators":{"cves":["CVE-2026-54136"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:18:17.737Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/windmill-labs/windmill/commit/7edf3f02122e20fde1e95e0252e7bda641075326","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/windmill-labs/windmill/pull/9426","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/windmill-labs/windmill/releases/tag/v1.715.0","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/windmill-labs/windmill/security/advisories/GHSA-2ppx-66jv-wpw5","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-55095","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-55095 — OpenProject is open-source, web-based project management software. In version 17.5.1 and earlier, an…","description":"OpenProject is open-source, web-based project management software. In version 17.5.1 and earlier, an authenticated non-admin project member can request the inplace-edit dialog for a raw custom_field_ project attribute. The dialog path resolves the project custom field by its raw identifier without e…","indicators":{"cves":["CVE-2026-55095"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:18:24.947Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/opf/openproject/releases/tag/v17.6.0","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/opf/openproject/security/advisories/GHSA-63fg-pgqj-3qf8","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-63481","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-63481 — Hurl is a command line tool that runs and tests HTTP requests defined in plain text files. In versio…","description":"Hurl is a command line tool that runs and tests HTTP requests defined in plain text files. In version 8.0.1 and earlier, the redirect handling in packages/hurl/src/http/client.rs strips Authorization and Cookie headers and basic-auth credentials when a redirect changes host, but it carries RequestSp…","indicators":{"cves":["CVE-2026-63481"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:19:15.037Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/Orange-OpenSource/hurl/commit/ed91c894c2cf11704422010554037e3ba70b446e","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/Orange-OpenSource/hurl/pull/5119","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/Orange-OpenSource/hurl/releases/tag/8.0.1","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/Orange-OpenSource/hurl/security/advisories/GHSA-7w2g-9mf9-324m","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-71492","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-71492 — Banks generates meaningful LLM prompts using a simple template language. Prior to version 2.4.5, Dir…","description":"Banks generates meaningful LLM prompts using a simple template language. Prior to version 2.4.5, DirectoryPromptRegistry.set() in src/banks/registries/directory.py interpolates attacker-controlled Prompt.name and Prompt.version values into a Path without canonicalization or containment validation. R…","indicators":{"cves":["CVE-2026-71492"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:19:40.930Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/masci/banks/commit/a215f6d779966945c56e0af5abed1ae5916fd9d3","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/masci/banks/pull/77","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/masci/banks/releases/tag/v2.4.5","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/masci/banks/security/advisories/GHSA-x8wg-4xgc-vr54","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/masci/banks/security/advisories/GHSA-x8wg-4xgc-vr54","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-53425","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-53425 — Insufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to…","description":"Insufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticated session using a SAML response the service provider never requested.\n\nSamly.SPHandler.validate_authresp/3 in lib/samly/sp_handler.ex validates a SAML response for the SP-init…","indicators":{"cves":["CVE-2026-53425"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T18:16:27.850Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://cna.erlef.org/cves/CVE-2026-53425.html","label":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","domainType":"other"},{"url":"https://osv.dev/vulnerability/EEF-CVE-2026-53425","label":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-63379","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-63379 — Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent processes chunk…","description":"Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent processes chunked HTTP trailers in http.c through evhttp_read_trailer and merges them into request headers. The fix introduces evhttp_parse_headers_impl_ and a temporary trailer header list. An unauthenticated remot…","indicators":{"cves":["CVE-2026-63379"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T18:16:35.200Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/libevent/libevent/commit/87e8e44fa774e9677b089b1a5114ee68aefa1636","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libevent/libevent/commit/b847071141b3827900d536594ec9045eb0a4c485","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libevent/libevent/security/advisories/GHSA-2gmv-p5m7-98p6","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-63380","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-63380 — Libevent is an event notification library. Prior to 2.2.2-alpha, libevent can dereference invalid li…","description":"Libevent is an event notification library. Prior to 2.2.2-alpha, libevent can dereference invalid list pointers in ws.c when evws_new_session enters its error path after evhttp_start_ws_ succeeds but bufferevent_enable_locking_ fails. evws_connection_free sees a non-null http_server and unconditiona…","indicators":{"cves":["CVE-2026-63380"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T18:16:35.357Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/libevent/libevent/commit/825c18bd99f556b59d61200523237f264d5cc734","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libevent/libevent/security/advisories/GHSA-3rpf-frgx-xq34","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-63381","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-63381 — Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after…","description":"Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after-free in buffer.c when evbuffer_add_buffer_reference processes an output buffer whose out_total_len is zero. evbuffer_free_all_chains frees the initial empty chain without resetting outbuf->first, out…","indicators":{"cves":["CVE-2026-63381"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T18:16:35.530Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/libevent/libevent/commit/5cb95ba2f804f8aff46f88d58391c71e1251cd1c","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libevent/libevent/commit/9db091b04f569be3a700fa9860ef02f90b830af9","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libevent/libevent/security/advisories/GHSA-c2pj-cg4r-88c8","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-63382","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-63382 — Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhttp pars…","description":"Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhttp parser in http.c inconsistently handles duplicate Transfer-Encoding headers, comma-separated Transfer-Encoding values, and bare line feeds in chunked framing. evhttp_find_header can select only the first…","indicators":{"cves":["CVE-2026-63382"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T18:16:35.700Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/libevent/libevent/commit/10abb34b8dc3e1184de315dd261ce4b77563cda6","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libevent/libevent/commit/5119ceb00557bf007f9065709e852686f3c0bb6e","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libevent/libevent/commit/83ba67373032334559b82409db035dd8c3cc1660","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libevent/libevent/commit/ac38703b2d312200c4f967f02936af0118d384a0","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libevent/libevent/security/advisories/GHSA-q39v-w2g7-gr8j","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libevent/libevent/security/advisories/GHSA-q39v-w2g7-gr8j","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-63383","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-63383 — Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent can read beyond…","description":"Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent can read beyond a contiguous evbuffer region in event_tagging.c when decode_tag_internal requests at most five bytes from evbuffer_pullup but iterates using the full logical buffer length. A fragmented evbuffer cont…","indicators":{"cves":["CVE-2026-63383"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T18:16:35.917Z","fetchedAt":"2026-08-21T03:01:29.088Z","references":[{"url":"https://github.com/libevent/libevent/commit/91ed8745eebabdd27592a83d350338a8c4626321","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libevent/libevent/commit/e1f9e21887c6b104e206a718385ba3ffc75180cb","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libevent/libevent/security/advisories/GHSA-fj29-64w6-73h6","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libevent/libevent/security/advisories/GHSA-fj29-64w6-73h6","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-63384","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-63384 — Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an incorrec…","description":"Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an incorrect integer conversion in event_tagging.c when evtag_unmarshal_header uses evtag_decode_int to decode an attacker-controlled uint32 payload length and returns it as a signed int. Values above INT_MAX be…","indicators":{"cves":["CVE-2026-63384"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T18:16:36.367Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://github.com/libevent/libevent/commit/109c16499282959d70f56ec3baf4c8b1e6646bda","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libevent/libevent/commit/5e3c6ebe342b34c5a9bcf48e9a32ad6708b9c416","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libevent/libevent/security/advisories/GHSA-45c6-qx49-89m8","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libevent/libevent/security/advisories/GHSA-45c6-qx49-89m8","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-63385","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-63385 — Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP pa…","description":"Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP parsing weaknesses in http.c. evhttp_decode_uri_internal decodes percent-encoded %00 bytes into literal NUL characters, which can cause downstream C string operations to truncate a path and bypass valid…","indicators":{"cves":["CVE-2026-63385"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T18:16:36.543Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://github.com/libevent/libevent/commit/758be0c0f69c1934ef9a84ab39e9f9e5fde2e6d0","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libevent/libevent/commit/9170dd35e64714613e8d13b290587cfc28e258e2","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libevent/libevent/security/advisories/GHSA-jcwh-pvf2-73p2","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-73251","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-73251 — Mongoose is an embedded web server and network library. Prior to 7.23, a network attacker can impers…","description":"Mongoose is an embedded web server and network library. Prior to 7.23, a network attacker can impersonate a TLS server to a Mongoose client configured with a multi-certificate CA bundle. In src/tls_builtin.c, the mg_tls_init() function stores the bundle in tls->ca_bundle_der while tls->ca_der.len re…","indicators":{"cves":["CVE-2026-73251"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T18:16:45.743Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://github.com/cesanta/mongoose/commit/2988bc9df3a5efc9539471cb7455975fa25df483","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cesanta/mongoose/releases/tag/7.23","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cesanta/mongoose/security/advisories/GHSA-qj6j-2692-v2r8","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cesanta/mongoose/security/advisories/GHSA-qj6j-2692-v2r8","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cesanta/mongoose/security/advisories/GHSA-qj6j-2692-v2r8","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cesanta/mongoose/security/advisories/GHSA-qj6j-2692-v2r8","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-73253","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-73253 — Mongoose is an embedded web server and network library. Prior to version 7.22, an on-path network at…","description":"Mongoose is an embedded web server and network library. Prior to version 7.22, an on-path network attacker with a wildcard certificate for a parent domain can impersonate deeper subdomains to a client using the built-in TLS stack. The mg_tls_verify_cert_san() and mg_tls_verify_cert_cn() functions in…","indicators":{"cves":["CVE-2026-73253"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T18:16:45.940Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://github.com/cesanta/mongoose/commit/a9df523f76f43a38bd53b4232b9cfd4c16869e71","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cesanta/mongoose/pull/3611","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cesanta/mongoose/releases/tag/7.22","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cesanta/mongoose/security/advisories/GHSA-jp6g-796f-39vp","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/cesanta/mongoose/security/advisories/GHSA-jp6g-796f-39vp","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-15743","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-15743 — Catalyst::Plugin::Static::Simple versions through 0.38 for Perl mark responses as publicly cacheable…","description":"Catalyst::Plugin::Static::Simple versions through 0.38 for Perl mark responses as publicly cacheable.\n\nThe _serve_static method always sets the Cache-Control header to \"public\", with no means of overriding it.  This advises proxies that the content may be stored in a shared cache, and may be reused…","indicators":{"cves":["CVE-2026-15743"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T19:16:48.700Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://datatracker.ietf.org/doc/html/rfc9111","label":"9b29abf9-4ab0-4765-b253-1875cd9b441e","domainType":"other"},{"url":"https://github.com/perl-catalyst/Catalyst-Plugin-Static-Simple/pull/3","label":"9b29abf9-4ab0-4765-b253-1875cd9b441e","domainType":"primary"},{"url":"https://security.metacpan.org/patches/C/Catalyst-Plugin-Static-Simple/0.38/CVE-2026-15743-r1.patch","label":"9b29abf9-4ab0-4765-b253-1875cd9b441e","domainType":"other"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/20/18","label":"af854a3a-2127-422b-91ae-364da2661108","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-19586","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-19586 — A pre-authentication OS command injection vulnerability has been identified in Omada gateways config…","description":"A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection establishment. An unauthenticated remote attacker may provide specially crafted in…","indicators":{"cves":["CVE-2026-19586"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T19:16:51.103Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://www.omadanetworks.com/en/support/download/","label":"f23511db-6c3e-4e32-a477-6aa17d310630","domainType":"other"},{"url":"https://www.omadanetworks.com/us/support/download/","label":"f23511db-6c3e-4e32-a477-6aa17d310630","domainType":"other"},{"url":"https://www.tp-link.com/us/support/faq/5256/","label":"f23511db-6c3e-4e32-a477-6aa17d310630","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-19683","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-19683 — A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During com…","description":"A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a third-party DDNS service, authentication credentials are transmitted over an unencrypted channel. An attacker who can observe or manipulate traffic between an affected device and the…","indicators":{"cves":["CVE-2026-19683"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T19:16:51.303Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://www.omadanetworks.com/en/support/download/","label":"f23511db-6c3e-4e32-a477-6aa17d310630","domainType":"other"},{"url":"https://www.omadanetworks.com/us/support/download/","label":"f23511db-6c3e-4e32-a477-6aa17d310630","domainType":"other"},{"url":"https://www.tp-link.com/us/support/faq/5256/","label":"f23511db-6c3e-4e32-a477-6aa17d310630","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-50190","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-50190 — Shaarli is a personal bookmarking service. Versions prior to 0.16.3 are vulnerable to stored XSS in…","description":"Shaarli is a personal bookmarking service. Versions prior to 0.16.3 are vulnerable to stored XSS in `application/front/controller/visitor/BookmarkListController.php`. The `permalink` handler concatenates the raw `$bookmark->getTitle()` into the `pagetitle` template variable and the RainTPL template…","indicators":{"cves":["CVE-2026-50190"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T19:16:53.907Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://github.com/shaarli/Shaarli/security/advisories/GHSA-xm98-h5jj-64xv","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/shaarli/Shaarli/security/advisories/GHSA-xm98-h5jj-64xv","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-53569","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-53569 — Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted to…","description":"Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted toggle_like and mark_as_seen endpoints in frappe/desk/like.py and frappe/desk/doctype/note/note.py do not enforce read permission before modifying _liked_by metadata or a Note seen state. An authenticat…","indicators":{"cves":["CVE-2026-53569"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T19:16:54.350Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://github.com/frappe/frappe/commit/91155d12deba4426cf33196805da77bc78c5cde1","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/frappe/frappe/commit/aeb93abe6b217ea0ae27253ef105ad6d0803613e","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/frappe/frappe/pull/39760","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/frappe/frappe/security/advisories/GHSA-rx6h-4p83-m76x","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-62315","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-62315 — Frappe is a full-stack web application framework. In version 16.31.0 and earlier, frappe.client.set_…","description":"Frappe is a full-stack web application framework. In version 16.31.0 and earlier, frappe.client.set_value in frappe/client.py checks a dictionary supplied through the fieldname parameter against forbidden standard and child-table fields before parsing the dictionary into individual field names. An a…","indicators":{"cves":["CVE-2026-62315"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T19:16:56.980Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://github.com/frappe/frappe/commit/2a04fae9353c02f0a9ce9f40f92c1eba6765c77b","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/frappe/frappe/pull/38951","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/frappe/frappe/security/advisories/GHSA-2c6h-wv85-fxvj","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-63654","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-63654 — Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted fr…","description":"Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted frappe.model.workflow.bulk_workflow_approval endpoint in frappe/model/workflow.py accepts safe HTTP methods for state-changing workflow approvals because the endpoint is not restricted to POST. An attac…","indicators":{"cves":["CVE-2026-63654"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T19:16:57.570Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://github.com/frappe/frappe/commit/8465376ad9f81775c20892338f920c695b88fb1f","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/frappe/frappe/pull/41361","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/frappe/frappe/security/advisories/GHSA-cgwf-xgph-hxgm","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-66001","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-66001 — Frappe is a full-stack web application framework. Prior to 15.114.0 and 16.26.0, the approve and aut…","description":"Frappe is a full-stack web application framework. Prior to 15.114.0 and 16.26.0, the approve and authorize functions in frappe/integrations/oauth2.py allow the OAuth2 consent flow to proceed without restricting approve to POST, without a csrf_token in frappe/templates/includes/oauth_confirmation.htm…","indicators":{"cves":["CVE-2026-66001"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T19:16:58.020Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://github.com/frappe/frappe/commit/336c7d335db762b494acdfe43aea69d459fd51d7","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/frappe/frappe/commit/d7460769f999c68d3121b680119f8724ddd3eb9d","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/frappe/frappe/commit/eb9c1446cac13236c6d573b136786db2e46254fa","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/frappe/frappe/pull/40073","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/frappe/frappe/pull/40700","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/frappe/frappe/pull/40701","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/frappe/frappe/releases/tag/v15.114.0","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/frappe/frappe/releases/tag/v16.26.0","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/frappe/frappe/security/advisories/GHSA-2ph8-x773-8p2x","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-66002","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-66002 — Frappe is a full-stack web application framework. Prior to 15.115.0 and 16.27.0, the public request-…","description":"Frappe is a full-stack web application framework. Prior to 15.115.0 and 16.27.0, the public request-data web form and PersonalDataDownloadRequest class in frappe/website/doctype/personal_data_download_request/personal_data_download_request.py return distinguishable response shapes for registered and…","indicators":{"cves":["CVE-2026-66002"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T19:16:58.187Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://github.com/frappe/frappe/commit/30fe0b4118ff94c95c239dce4bc74ec4ca10a827","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/frappe/frappe/commit/47a396ec59f5362029feb349eb2b9d10a21afcf8","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/frappe/frappe/commit/4b32a4e0072e61ce0abcb0d09cfd1f14724fe896","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/frappe/frappe/pull/40787","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/frappe/frappe/pull/40814","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/frappe/frappe/pull/40815","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/frappe/frappe/releases/tag/v15.115.0","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/frappe/frappe/releases/tag/v16.27.0","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/frappe/frappe/security/advisories/GHSA-c2xv-c53h-qvr5","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-9033","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-9033 — An unauthenticated attacker with network access to the captive portal service of an affected device…","description":"An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, including forcing logout of specific users or clearing all active sessions. Affected users must re-authenticate to regain access. \n\n\n\nSuccessful exploitat…","indicators":{"cves":["CVE-2026-9033"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T19:17:04.950Z","fetchedAt":"2026-08-21T03:01:29.089Z","references":[{"url":"https://www.omadanetworks.com/en/support/download/","label":"f23511db-6c3e-4e32-a477-6aa17d310630","domainType":"other"},{"url":"https://www.omadanetworks.com/us/support/download/","label":"f23511db-6c3e-4e32-a477-6aa17d310630","domainType":"other"},{"url":"https://www.tp-link.com/us/support/faq/5256/","label":"f23511db-6c3e-4e32-a477-6aa17d310630","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-19755","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-19755 — NoSleep 1.5.1 exposes a privileged XPC Mach service and accepts raw dictionary messages containing a…","description":"NoSleep 1.5.1 exposes a privileged XPC Mach service and accepts raw dictionary messages containing attacker-controlled command and NSBundlePath values.This issue affects NoSleep: 1.5.1.","indicators":{"cves":["CVE-2026-19755"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T21:17:06.283Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://fluidattacks.com/advisories/iggy","label":"help@fluidattacks.com","domainType":"other"},{"url":"https://github.com/integralpro/nosleep/","label":"help@fluidattacks.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-43798","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-43798 — A single crafted SSH message gives an unauthenticated network attacker an out-of-bounds stack write…","description":"A single crafted SSH message gives an unauthenticated network attacker an out-of-bounds stack write of attacker-controlled length and content against any application built on swift-nio-ssh. This vulnerability is addressed in swift-nio-ssh version 0.14.1.","indicators":{"cves":["CVE-2026-43798"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T21:17:06.580Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://github.com/apple/swift-nio-ssh/security/advisories/GHSA-998x-vgvp-xwpc","label":"product-security@apple.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-52021","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-52021 — An issue in code100xDevs 100xdevs CMS v.1.0 (2026-04-30) allows a remote attacker to obtain sensitiv…","description":"An issue in code100xDevs 100xdevs CMS v.1.0 (2026-04-30) allows a remote attacker to obtain sensitive information via the src/middleware.ts, and src/app/api/mobile/search/route.ts components.","indicators":{"cves":["CVE-2026-52021"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T21:17:06.687Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://gist.github.com/itsmohitnarayan/e456399f083130962bab6c710f208437","label":"cve@mitre.org","domainType":"primary"},{"url":"https://github.com/code100x/cms","label":"cve@mitre.org","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-70651","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-70651 — libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips b…","description":"libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built without libtiff support but with ImageMagick support can overflow the combined frame height while loading a crafted multi-page TIFF through VipsForeignLoadMagick. The vulnerable calculations in l…","indicators":{"cves":["CVE-2026-70651","CVE-2026-70652"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T21:17:08.120Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://github.com/libvips/libvips/commit/05719ca3d5852acdeb6714de2e8e769c9a5d2c11","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libvips/libvips/pull/5040","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libvips/libvips/releases/tag/v8.18.3","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libvips/libvips/security/advisories/GHSA-7p29-wg2h-36q4","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libvips/libvips/commit/cff17794f0698a4f47c74bb31c9700b2c83252a8","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libvips/libvips/pull/5039","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libvips/libvips/security/advisories/GHSA-h27h-jf9v-m8rg","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-70653","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-70653 — libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, the old-s…","description":"libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, the old-style Radiance RLE decoder in libvips/foreign/radiance.c can process a repeat marker at the beginning of a scanline in scanline_read_old and read q[-1] before any prior pixel exists. A crafted Radiance…","indicators":{"cves":["CVE-2026-70653"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T21:17:08.427Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://github.com/libvips/libvips/commit/dc945573e15d598054e701c65b90a35b16b19304","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libvips/libvips/pull/5037","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libvips/libvips/releases/tag/v8.18.3","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libvips/libvips/security/advisories/GHSA-fh99-55jf-5hj3","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-70654","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-70654 — libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, applicati…","description":"libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, applications that define unusual custom libvips sources and use them to process untrusted uncompressed PPM images can trigger a max/min error in vips_source_read_to_memory in libvips/iofuncs/source.c. The func…","indicators":{"cves":["CVE-2026-70654"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T21:17:08.567Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://github.com/libvips/libvips/commit/80e021c6cdda0f80b756c2109d99839c94c03258","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libvips/libvips/pull/5038","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libvips/libvips/releases/tag/v8.18.3","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/libvips/libvips/security/advisories/GHSA-rjmm-3qch-m9rg","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-74836","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-74836 — Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows an unaut…","description":"Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows an unauthenticated remote attacker to pin an unbounded number of HTTP/2 stream processes indefinitely via connection-level flow control. When a stream's response body outruns the HTTP/2 connection-level send…","indicators":{"cves":["CVE-2026-74836"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T21:17:09.407Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://cna.erlef.org/cves/CVE-2026-74836.html","label":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","domainType":"other"},{"url":"https://github.com/mtrudel/bandit/commit/f6914aad14bb1365dd6f306aa592cfb0819bed3e","label":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","domainType":"primary"},{"url":"https://github.com/mtrudel/bandit/security/advisories/GHSA-xj8g-532w-jv94","label":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","domainType":"primary"},{"url":"https://osv.dev/vulnerability/EEF-CVE-2026-74836","label":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-75484","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-75484 — Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in mtrudel bandit allows…","description":"Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in mtrudel bandit allows an unauthenticated remote attacker to smuggle CR, LF, or NUL characters into application-visible request headers via HTTP/2. Bandit.HTTP2.Stream.read_headers/1 validates pseudo-header placement and un…","indicators":{"cves":["CVE-2026-75484"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T21:17:09.597Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://cna.erlef.org/cves/CVE-2026-75484.html","label":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","domainType":"other"},{"url":"https://github.com/mtrudel/bandit/commit/d38cf046c9a3cae4d0f88001c2ceb4143f86366b","label":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","domainType":"primary"},{"url":"https://github.com/mtrudel/bandit/security/advisories/GHSA-x3gh-xhj4-3vq8","label":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","domainType":"primary"},{"url":"https://osv.dev/vulnerability/EEF-CVE-2026-75484","label":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-76017","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-76017 — Use after free in Chromoting in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to e…","description":"Use after free in Chromoting in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Critical)","indicators":{"cves":["CVE-2026-76017"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T21:17:09.800Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0404570826.html","label":"chrome-cve-admin@google.com","domainType":"other"},{"url":"https://issues.chromium.org/issues/522819252","label":"chrome-cve-admin@google.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-76020","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-76020 — Race condition in V8 in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute a…","description":"Race condition in V8 in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","indicators":{"cves":["CVE-2026-76020"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T21:17:10.167Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0404570826.html","label":"chrome-cve-admin@google.com","domainType":"other"},{"url":"https://issues.chromium.org/issues/541837151","label":"chrome-cve-admin@google.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-76021","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-76021 — Use after free in DOM in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute…","description":"Use after free in DOM in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","indicators":{"cves":["CVE-2026-76021"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T21:17:10.280Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0404570826.html","label":"chrome-cve-admin@google.com","domainType":"other"},{"url":"https://issues.chromium.org/issues/541854084","label":"chrome-cve-admin@google.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-76022","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-76022 — Buffer overflow in Network in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to exe…","description":"Buffer overflow in Network in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","indicators":{"cves":["CVE-2026-76022"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T21:17:10.420Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0404570826.html","label":"chrome-cve-admin@google.com","domainType":"other"},{"url":"https://issues.chromium.org/issues/543798025","label":"chrome-cve-admin@google.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-76023","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-76023 — Improper resource control in Linux Toolkit Theming in Google Chrome prior to 151.0.7922.173 allowed…","description":"Improper resource control in Linux Toolkit Theming in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","indicators":{"cves":["CVE-2026-76023"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T21:17:10.553Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0404570826.html","label":"chrome-cve-admin@google.com","domainType":"other"},{"url":"https://issues.chromium.org/issues/545124048","label":"chrome-cve-admin@google.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2025-52182","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2025-52182 — The Library Corporation LS2 Admin v5.7 to v5.8.0 was discovered to contain an information disclosure…","description":"The Library Corporation LS2 Admin v5.7 to v5.8.0 was discovered to contain an information disclosure vulnerability.","indicators":{"cves":["CVE-2025-52182"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:05.863Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://gist.github.com/joachimjohannesen/a0781100d374b86450a81a54c959f59c","label":"cve@mitre.org","domainType":"primary"},{"url":"https://ocipubdemo.tlcdelivers.com/admin/locationConfiguration/export","label":"cve@mitre.org","domainType":"other"},{"url":"https://ocipubdemo.tlcdelivers.com/scripts/TlcIndigo/ls2admin/Control/ExportReportControl.js","label":"cve@mitre.org","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-50192","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-50192 — Kerberos Agent is an open source video (surveillance) management agent. Prior to version 3.6.26, the…","description":"Kerberos Agent is an open source video (surveillance) management agent. Prior to version 3.6.26, the Kerberos Hub upload path sends the agent's Hub credentials in the custom `X-Kerberos-Hub-PrivateKey` and `X-Kerberos-Hub-PublicKey` request headers to the operator-configured Hub URL (`config.HubURI`…","indicators":{"cves":["CVE-2026-50192"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:20.390Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://github.com/kerberos-io/agent/commit/51f1a52e170f21c1264c6de1dc781d5b5e2a5d09","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/kerberos-io/agent/security/advisories/GHSA-h5gx-45rj-2h5j","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-54505","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-54505 — TREK is a collaborative travel planner. Prior to 3.1.0, when the Journey add-on is enabled, TREK int…","description":"TREK is a collaborative travel planner. Prior to 3.1.0, when the Journey add-on is enabled, TREK interpolates the unescaped activeSuggestion.title value into journey.frontpage.suggestionText through client/src/i18n/TranslationContext.tsx and renders the result with dangerouslySetInnerHTML in client/…","indicators":{"cves":["CVE-2026-54505"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:21.263Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://github.com/liketrek/TREK/commit/ad893eb1cc75b6d56f402d73a6d41bd48ba7ae11","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/liketrek/TREK/pull/1185","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/liketrek/TREK/releases/tag/v3.1.0","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/liketrek/TREK/security/advisories/GHSA-g8rf-gqrw-4qf9","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-54508","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-54508 — TREK is a collaborative travel planner. Prior to 3.1.0, TREK validates only the initial URL before n…","description":"TREK is a collaborative travel planner. Prior to 3.1.0, TREK validates only the initial URL before native redirect following in importGoogleList() and importNaverList() in server/src/services/placeService.ts and resolveGoogleMapsUrl() in server/src/services/mapsService.ts. The affected sinks call ch…","indicators":{"cves":["CVE-2026-54508"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:21.410Z","fetchedAt":"2026-08-21T03:01:29.098Z","references":[{"url":"https://github.com/liketrek/TREK/commit/ad893eb1cc75b6d56f402d73a6d41bd48ba7ae11","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/liketrek/TREK/pull/1185","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/liketrek/TREK/releases/tag/v3.1.0","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/liketrek/TREK/security/advisories/GHSA-f5vh-p2h5-x735","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-55893","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-55893 — Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.…","description":"Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c SH floating-point decoders such as opFADD, opFMUL, and opFSUB call set_reg() and set_reg_n() using sh_info.op.op_count without checking the fixed-size operands[] array. Repeated crafted instructions…","indicators":{"cves":["CVE-2026-55893","CVE-2026-55894"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:22.787Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://github.com/capstone-engine/capstone/commit/09e76802380b9e94d9720c44458d9d5282219e7e","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/capstone-engine/capstone/commit/e17ee44a8307ea33375b4727ac4f987650bf7bed","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/capstone-engine/capstone/pull/2968","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/capstone-engine/capstone/pull/2969","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/capstone-engine/capstone/releases/tag/6.0.0-Alpha10","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/capstone-engine/capstone/security/advisories/GHSA-3hpv-wr3j-rxwh","label":"security-advisories@github.com","domainType":"primary"},{"url":"https://github.com/capstone-engine/capstone/security/advisories/GHSA-gf2c-xwcp-hvf4","label":"security-advisories@github.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-64773","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-64773 — An attacker that can reach a container's published TCP port may be able to force the host's forwardi…","description":"An attacker that can reach a container's published TCP port may be able to force the host's forwarding process to buffer an unbounded amount of that client's data in memory, for as long as the backend container connection takes to complete — with no cap on how much accumulates or how long the wait c…","indicators":{"cves":["CVE-2026-64773"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:17:48.603Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://github.com/apple/container/security/advisories/GHSA-wg28-286f-56v6","label":"product-security@apple.com","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-77644","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-77644 — A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliabili…","description":"A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliability (WRR) Enterprise Edition.","indicators":{"cves":["CVE-2026-77644"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:18:06.357Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://www.ptc.com/en/support/article/CS474818","label":"0b655efc-079c-4cb9-9e8d-164871239f4e","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-77646","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-77646 — A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PT…","description":"A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.","indicators":{"cves":["CVE-2026-77646"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T22:18:06.657Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://www.ptc.com/en/support/article/CS474826","label":"0b655efc-079c-4cb9-9e8d-164871239f4e","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-77113","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-77113 — Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allow…","description":"Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allows an attacker to create or overwrite arbitrary files with the privileges of the executing user via an attacker controlled key names in crash report files.","indicators":{"cves":["CVE-2026-77113"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T23:16:28.387Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://github.com/canonical/apport/pull/646","label":"security@ubuntu.com","domainType":"primary"},{"url":"https://launchpad.net/bugs/2161697","label":"security@ubuntu.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-16520","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-16520 — Improper input validation and Exposure of sensitive information through data queries vulnerability i…","description":"Improper input validation and Exposure of sensitive information through data queries vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, and Genians Genian ZTNA V6.0 allows SQL Injection and Authentication Bypass.\n\nThis issue affects Genian NAC V4.0: from 4.0.0 before 4.0.175(Revision…","indicators":{"cves":["CVE-2026-16520"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-21T00:16:31.623Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://docs.genians.com/release/ko/advisories/GN-SA-2026-003.html","label":"09832df1-09c1-45b4-8a85-16c601d30feb","domainType":"other"},{"url":"https://github.com/genians/security-research/security/advisories/GHSA-f6f5-wx2h-ccfw","label":"09832df1-09c1-45b4-8a85-16c601d30feb","domainType":"primary"}],"feedLabel":null},{"id":"nvd-CVE-2026-20679","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-20679 — The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Son…","description":"The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. Processing a maliciously crafted file may lead to unexpected app termination.","indicators":{"cves":["CVE-2026-20679"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-21T01:16:59.830Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://support.apple.com/en-us/126794","label":"product-security@apple.com","domainType":"other"},{"url":"https://support.apple.com/en-us/126795","label":"product-security@apple.com","domainType":"other"},{"url":"https://support.apple.com/en-us/126796","label":"product-security@apple.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-43679","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-43679 — This issue was addressed with improved permissions checking. This issue is fixed in watchOS 26.4. An…","description":"This issue was addressed with improved permissions checking. This issue is fixed in watchOS 26.4. An attacker with physical access to a locked Apple Watch may be able to view user contacts.","indicators":{"cves":["CVE-2026-43679"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-21T01:17:01.723Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://support.apple.com/en-us/126798","label":"product-security@apple.com","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-76155","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-76155 — Use of default credentials in Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a rem…","description":"Use of default credentials in Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to gain administrative access to the management platform by logging in with default administrator credentials.","indicators":{"cves":["CVE-2026-76155"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-21T02:16:25.840Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://zuso.ai/advisory","label":"ART@zuso.ai","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-76156","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-76156 — OS command injection in the api endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.…","description":"OS command injection in the api endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an authenticated administrator to execute arbitrary operating system commands as root.","indicators":{"cves":["CVE-2026-76156"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-21T02:16:27.090Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://zuso.ai/advisory","label":"ART@zuso.ai","domainType":"other"}],"feedLabel":null},{"id":"nvd-CVE-2026-76157","source":"nvd","category":"vulnerability","severity":"unknown","title":"CVE-2026-76157 — Missing authentication for a critical function in the upload API endpoint of Datiphy Data Management…","description":"Missing authentication for a critical function in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an unauthenticated remote attacker to upload arbitrary files to the server's configured upload directory.","indicators":{"cves":["CVE-2026-76157"],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-21T02:16:27.260Z","fetchedAt":"2026-08-21T03:01:29.099Z","references":[{"url":"https://zuso.ai/advisory","label":"ART@zuso.ai","domainType":"other"}],"feedLabel":null},{"id":"vendor-is-cyber-missing-the-marque","source":"vendor-blogs","category":"advisory","severity":"unknown","title":"Is Cyber missing the Marque?","description":"In this week's newsletter, new author Mick Baccio introduces himself and explores the operational and security implications of the new White House memorandum regarding private sector participation in government-authorized offensive cyber operations.","indicators":{"cves":[],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T18:00:18.000Z","fetchedAt":"2026-08-21T03:00:09.022Z","references":[{"url":"https://blog.talosintelligence.com/is-cyber-missing-the-marque/","label":"Cisco Talos","domainType":"other"}],"feedLabel":null},{"id":"news-ai-generated-exploit-scripts-target-siemens-s7-plcs-in-u-s-critical-infrastructu","source":"general-news","category":"news","severity":"unknown","title":"AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure","description":"The U.S. government on Wednesday warned of an \"active threat\" targeting critical infrastructure organizations in the country using artificial intelligence (AI)-generated exploit scripts.\n\nThe activity is targeting Siemens S7 SeriesProgrammable Logic Controllers (PLCs) to conduct reconnaissance and c…","indicators":{"cves":[],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T16:59:44.000Z","fetchedAt":"2026-08-21T03:00:02.309Z","references":[{"url":"https://thehackernews.com/2026/08/ai-generated-exploit-scripts-target.html","label":"The Hacker News","domainType":"media"}],"feedLabel":null},{"id":"news-new-cryptographic-context-injection-attack-could-let-web-pages-steal-grok-chat-d","source":"general-news","category":"news","severity":"unknown","title":"New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data","description":"Adversa AI has disclosed an attack technique that it says can cause xAI's Grok chatbot to send a user's name, approximate location, subscription tier, and the prompts from the ongoing conversation to an attacker-controlled server after the user asks it to summarize an ordinary web page.\n\nThe AI secu…","indicators":{"cves":[],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T14:36:27.000Z","fetchedAt":"2026-08-21T03:00:02.309Z","references":[{"url":"https://thehackernews.com/2026/08/new-cryptographic-context-injection.html","label":"The Hacker News","domainType":"media"}],"feedLabel":null},{"id":"news-new-custody-framework-constrains-ai-agents-inside-the-network","source":"general-news","category":"news","severity":"unknown","title":"New CUSTODY Framework Constrains AI Agents Inside the Network","description":"Enterprise cybersecurity expert Jake Williams joins the Dark Reading News Desk to explain why he decided to release his new agentic AI framework in the wake of the OpenAI attacks on Hugging Face.","indicators":{"cves":[],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T20:42:18.000Z","fetchedAt":"2026-08-21T03:00:02.309Z","references":[{"url":"https://www.darkreading.com/perimeter/new-custody-framework-constrains-ai-agents-inside-network","label":"Dark Reading","domainType":"media"}],"feedLabel":null},{"id":"news-n-able-bug-exposes-password-vault-master-keys","source":"general-news","category":"news","severity":"unknown","title":"N-able Bug Exposes Password Vault Master Keys","description":"The popular \"Passportal\" password manager, favored by MSPs and SMBs, remains risky even after its patch, thanks to its cloud-based design. Should these products stay away from the cloud entirely?","indicators":{"cves":[],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T17:39:24.000Z","fetchedAt":"2026-08-21T03:00:02.309Z","references":[{"url":"https://www.darkreading.com/vulnerabilities-threats/n-able-bug-password-vault-master-keys","label":"Dark Reading","domainType":"media"}],"feedLabel":null},{"id":"news-pakistan-s-transparent-tribe-refreshes-toolset-for-afghan-cyberattacks","source":"general-news","category":"news","severity":"unknown","title":"Pakistan's Transparent Tribe Refreshes Toolset for Afghan Cyberattacks","description":"A nation-state threat actor is picking on immature organizations run by the Taliban, but failing against more prepared government agencies in India.","indicators":{"cves":[],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T14:59:22.000Z","fetchedAt":"2026-08-21T03:00:02.309Z","references":[{"url":"https://www.darkreading.com/cyberattacks-data-breaches/pakistan-transparent-tribe-afghan-cyberattacks","label":"Dark Reading","domainType":"media"}],"feedLabel":null},{"id":"news-hackers-target-zimbra-servers-in-active-exploitation-campaign","source":"general-news","category":"news","severity":"unknown","title":"Hackers Target Zimbra Servers in Active Exploitation Campaign","description":"Exploitation of the Zimbra Collaboration vulnerability CVE-2026-73570 has been observed by Poland’s CERT Polska.\nThe post Hackers Target Zimbra Servers in Active Exploitation Campaign appeared first on SecurityWeek.","indicators":{"cves":[],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T14:50:49.000Z","fetchedAt":"2026-08-21T03:00:02.309Z","references":[{"url":"https://www.securityweek.com/hackers-target-zimbra-servers-in-active-exploitation-campaign/","label":"SecurityWeek","domainType":"media"}],"feedLabel":null},{"id":"news-china-s-silkparasite-espionage-operation-targeting-central-asia-with-ai-assisted","source":"general-news","category":"news","severity":"unknown","title":"China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware","description":"Suspected military-grade hackers based in China used artificial intelligence to develop malware in a campaign to penetrate Central Asian governments.","indicators":{"cves":[],"ips":[],"domains":[],"urls":[],"hashes":{"md5":null,"sha1":null,"sha256":null}},"tags":[],"malwareFamily":null,"confidence":null,"publishedAt":"2026-08-20T19:30:00.000Z","fetchedAt":"2026-08-21T03:00:02.309Z","references":[{"url":"https://therecord.media/china-cyber-espionage-central-asia","label":"The Record","domainType":"media"}],"feedLabel":null}],"llmPrompt":"You are a cybersecurity analyst. Summarize this daily threat intelligence report for 2026-08-21.\nTotal items collected: 3339 from sources: cisa-kev: 8, nvd: 3068, cisa-advisories: 7, vendor-blogs: 87, malware-bazaar: 9, abuse-ipdb: 20, threatfox: 2, otx: 33, general-news: 112.\n\nTop threats by severity:\n1. [CRITICAL] CVE-2026-15706 — Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry…\n2. [CRITICAL] CVE-2026-64960 — ATutor Gameme module allows users to upload files of any type and extension without restriction. Due…\n3. [CRITICAL] CVE-2026-64966 — ATutor is vulnerable to a Path Traversal vulnerability in ZIP extraction functionality. An attacker…\n4. [CRITICAL] CVE-2026-16926 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary f…\n5. [CRITICAL] CVE-2026-15679 — Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution…\n6. [CRITICAL] CVE-2026-15686 — Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability. Th…\n7. [CRITICAL] CVE-2026-18264 — NoMachine getstat Command Injection Remote Code Execution Vulnerability. This vulnerability allows r…\n8. [CRITICAL] CVE-2026-18265 — OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulnerability al…\n9. [CRITICAL] CVE-2026-18274 — Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution Vulnerability. This…\n10. [CRITICAL] CVE-2026-18279 — Sony XAV-9500ES RTSP SETUP Buffer Overflow Remote Code Execution Vulnerability. This vulnerability a…\n\nProvide: (1) Executive summary (2-3 sentences), (2) Key threats to watch,\n(3) Recommended actions for security teams, (4) Notable trends.\nBe concise and actionable. Focus on what matters most to defenders."}