mitre-t1059
1849 articles with this tag
CRITICAL
HIGH
HIGH
HIGH
MEDIUM
MEDIUM
MEDIUM
CRITICAL
HIGH
HIGH
CRITICAL
HIGH
HIGH
CRITICAL
CRITICAL
CRITICAL
HIGH
CRITICAL
MEDIUM
MEDIUM
CRITICAL
CRITICAL
MEDIUM
HIGH
HIGH
CRITICAL
HIGH
MEDIUM
HIGH
HIGH
MEDIUM
HIGH
CRITICAL
MEDIUM
HIGH
HIGH
CRITICAL
CRITICAL
HIGH
MEDIUM
HIGH
CRITICAL
HIGH
CRITICAL
CRITICAL
HIGH
CRITICAL
CRITICAL
CRITICAL
MEDIUM
MEDIUM
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
MEDIUM
HIGH
CRITICAL
HIGH
MEDIUM
HIGH
MEDIUM
HIGH
CRITICAL
HIGH
HIGH
CRITICAL
HIGH
MEDIUM
HIGH
HIGH
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
HIGH
MEDIUM
HIGH
CRITICAL
HIGH
CRITICAL
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
More JFrog Artifactory bugs under attack, and all 3 have patches
Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
Claude Used to Automate Exploitation and Data Theft Across Multiple Victims
Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection
India’s STPI serves TerminalFix-style attack via fake Cloudflare check
Android malware creates a hidden copy of your banking app
[NEU] [mittel] OpenClaw: Mehrere Schwachstellen
[NEU] [hoch] GitLab: Mehrere Schwachstellen
[NEU] [hoch] IBM MQ Appliance (Axios Node.js): Mehrere Schwachstellen
AI agents exploited PaperCut flaws to breach 395 organizations
Read the Bits, Not the Integer: msPKI-Certificate-Name-Flag and the ESC4⤍ESC1 Chain
Attackers use passkey-themed scams to hijack Microsoft 365 accounts
Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion
PaperCut Flaws Exploited in AI-Powered Attacks
Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors
Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
Indonesia Hit by Android Banking App-Cloning Campaign
Hundreds of AI agents helped PaperCut attacker hit 395+ orgs, and some went off script
Protecting organizations from AI-assisted executive impersonation and invoice fraud
Detect and disrupt AI-themed attacks with Microsoft Defender
PaperCut MF/NG flaws attacked with hundreds of AI agents
PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks
MantaxOtax Android Malware Combines Ransomware With Spyware
[NEU] [hoch] Joplin: Mehrere Schwachstellen
Stealth rootkit targeting F5 BIG-IP could expose enterprise identity gateways
An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation
Angry Birds: Toy Ghouls’ new toys
Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set
The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT
Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon
The Models That Found 10,000 Zero-Days Broke Into Three Companies Using Weak Passwords
Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits
OpenAI's Artifactory opened covert data-stealing channel alongside Hugging Face attack
Extortion crews have their eyes on high-value AI data, Google warns
Attack hides malware in PNGs and drops custom reverse tunnel on victims' machines
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows
TerminalFix campaign deploys a reverse tunnel through multistage intrusion
Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America
Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks
Gigabud banking trojan uses app cloning to evade fraud detection
Orkes Conductor Evaluator Remote Code Execution
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
F5 BIG-IP malware hides web shells in memory to evade detection
MikroTik patches flaws currently being exploited to take over routers
Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows
Active exploitation of Cisco Secure Firewall Management Center vulnerabilities
Linux Detection Engineering - Fileless Execution
From 88 lines to 1: Detecting DLL hijacking with Elastic Defend
The Models That Found 10,000 Zero-Days Broke Into Three Companies Using Weak Passwords
Researchers Build WeChat Zero-Click Worm Hijacking Phones via Calls
ASCII smuggling crosses over from AI prompt injection to phishing evasion
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
Gigabud Uses Android App Cloning to Evade Fraud Detection
ClickFix Moves into the Browser to Steal Cryptocurrency
Mantax Otax: Indonesian Mobile Ransomware with Spyware Integration
NCSC-2026-0356 [1.00] [M/H] Kwetsbaarheden verholpen in diverse SAP-producten
[NEU] [hoch] Dell OpenManage Server Administrator: Mehrere Schwachstellen
Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
[NEU] [hoch] Adobe ColdFusion: Mehrere Schwachstellen
OpenAI's Artifactory opened covert data-stealing channel alongside Hugging Face attack
Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution
Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours
VU#943094: ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerability
The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT
Critical N-able N-central Vulnerability and Active Exploitation
Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity
Daisy-Chaining Trust: Investigating Faronics Deploy Abuse
[NEU] [hoch] IBM App Connect Enterprise: Mehrere Schwachstellen
[NEU] [mittel] MISP: Mehrere Schwachstellen
Extortion crews have their eyes on high-value AI data, Google warns
Adobe Commerce max-severity bug comes under active attack
ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2
Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
LG TV flaws could let attackers listen in, even in standby mode
Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts
North Korean Hackers Deploy New Linux Espionage Toolkit
[NEU] [hoch] OpenCTI: Mehrere Schwachstellen
Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Modified ScreenConnect Clients Used in Worm-Like Campaign
Counterfeit installers to system compromise: Tracking a deceptive software download campaign
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
PostGREShell vulnerability allows server takeover
Coder platform targeted by attackers delivering malicious Terraform modules
New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
Hackers Found a Way Into Humanoid Robots | Threat Wire
[NEU] [hoch] Dell Secure Connect Gateway: Mehrere Schwachstellen
DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors
12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover
ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories
ASCII smuggling crosses over from AI prompt injection to phishing evasion
BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory
Human attacker uses AI agents to breach enterprise network in under 10 hours
NCSC-2026-0340 [1.00] [M/H] Kwetsbaarheden verholpen in Aruba Networks ArubaOS-CX
NCSC-2026-0339 [1.00] [M/H] Kwetsbaarheden verholpen in HPE Networking Fabric Composer