mitre-t1078
1045 articles with this tag
CRITICAL
HIGH
CRITICAL
CRITICAL
CRITICAL
HIGH
MEDIUM
MEDIUM
HIGH
HIGH
MEDIUM
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
CRITICAL
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
HIGH
MEDIUM
HIGH
CRITICAL
CRITICAL
CRITICAL
MEDIUM
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
MEDIUM
HIGH
MEDIUM
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
MEDIUM
More JFrog Artifactory bugs under attack, and all 3 have patches
Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion
PaperCut Flaws Exploited in AI-Powered Attacks
đľď¸ââď¸ SonicWall SMA1000 (CVE-2026-15409): SSRF to Erlang RCE chained into automated DCSync from the appliance
Organizations Warned of Cisco Secure FMC Exploitation
An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation
Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams
Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon
Anatomy of a Silent Domain Takeover
Two Alleged âTeamPCPâ Hackers Arrested in Australia
OpenAI's Artifactory opened covert data-stealing channel alongside Hugging Face attack
Another Artifactory CVE under attack by AI agents or humans
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Shai-Hulud hackers: two men charged over TeamPCPâs global supply chain crime spree that hit OpenAI, and thousands more
Passkey-themed social engineering leads to identity and cloud compromise
TerminalFix campaign deploys a reverse tunnel through multistage intrusion
Passkey-themed social engineering leads to identity and cloud compromise
OpenAI's Artifactory opened covert data-stealing channel alongside Hugging Face attack
Russian national extradited to US for alleged involvement in bank-account takeover scheme
NCSC-2026-0349 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Exchange server
ClickFix Campaigns Abuse Legitimate Services for Persistent Access
đ¨ Redis Cryptomining Botnet Compromised 3,562 Servers, Exposed by the Operator's Own Files
CISA tells operators to harden Siemens S7 PLCs. Hereâs how to do it without disrupting production
CVE-2026-69380 Microsoft Exchange Server Elevation of Privilege Vulnerability
Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours
Inside Knight Office, a New M365 AiTM Phishing Kit
RMM Tools for MSPs: Features, Risks & How to Stay Secure
Extortion crews have their eyes on high-value AI data, Google warns
BigBear 2.0 phishing campaign hijacks Microsoft 365 sessions after MFA
BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials
NCSC-2026-0345 [1.00] [M/H] Kwetsbaarheden verholpen in MikroTik RouterOS
Hacking AI customer service agents (Bug Bounty Village DEF CON 34)
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
Modified ScreenConnect Clients Used in Worm-Like Campaign
Back-to-back N-able bugs send admins on a patching spree
Counterfeit installers to system compromise: Tracking a deceptive software download campaign
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
Coder platform targeted by attackers delivering malicious Terraform modules
DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors
BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory
Human attacker uses AI agents to breach enterprise network in under 10 hours
AI 'Machine Speed' Cuts 2-Week Attack Down to 10 Hours
Outsider Phishing Kit Survives Takedown With 700 New Pages
Shai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means
Breeze Comet threat actor targets Brazilian financial sector with sophisticated attacks
Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
Anatomy of a Silent Domain Takeover
Exploit Published for Fresh Cleo Harmony Vulnerability
Exploited JFrog Artifactory bug puts software supply chain on alert
Microsoft identifies âTerminalFixâ campaign spreading Python reverse tunnel
An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation
Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon
Silver Fox uses adware to distribute ValleyRAT backdoor
Another Artifactory CVE under attack by AI agents or humans
Critical Langflow Flaw Exploited as Attacks on AI Platform Rise
Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure
USN-8708-1: sudo-rs vulnerability
Infostealer malware compromises Claude accounts, bypassing 2FA
Attackers Steal METR API Key and Burn $600,000 in AI Credits
Hackers Start Exploiting Critical Langflow Vulnerability
Hackers Just Poisoned the Rust Supply Chain | Threat Wire
Fake Cloudflare CAPTCHA tricks victims into opening a tunnel for attackers
China-linked hackers turn Cisco routers into covert attack infrastructure
Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity
McKesson discloses data breach after ShinyHunters claims theft of 284 million records
McKesson copes with fallout from data theft extortion attack
China-linked campaign targets high-value networks, critical infrastructure
McKesson confirms cyber incident after ShinyHunters claims patient-data theft
USN-8702-1: util-linux vulnerabilities
ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams
China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
Trusted Chrome, Edge extensions weaponized in supply chain campaign
TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
TerminalFix campaign deploys a reverse tunnel through multistage intrusion
Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network
Aurora ransomware actors leverage AI tool for exploitation campaigns
The AI agent swarm that attacked Hugging Face is a warning for the future
Authorities arrest 2 alleged members of prolific hacking group TeamPCP
Shai-Hulud hackers: two men charged over TeamPCPâs global supply chain crime spree that hit OpenAI, and thousands more
Australian cops cuff alleged TeamPCP masterminds
Siemens S7 Series PLCs and other Internet-exposed PLC Attack
CISA red team finds critical infrastructure vulnerabilities
WindRelay Combines NFC Relay Malware and Remote Access for Mobile Fraud
Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks
OpenAI Agents Coordinated via Makeshift Message Board Ahead of Hugging Face Hack
Two Alleged âTeamPCPâ Hackers Arrested in Australia
FBI takes down China-linked hacking network behind attacks on NASA, DOJ and U.S. Senate
Nimbus Manticore expands infrastructure and malware arsenal
Dark Caracal Adds New Malware to Cyber Espionage Arsenal
Officials disrupt Chinese espionage operation that hit multiple federal agencies
FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler
[NEU] [hoch] JFrog Artifactory: Mehrere Schwachstellen
U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches
Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows
You don't want this Sleepwalker backdoor on your Windows machine
Extended Rapid Response: Zimperium Identifies RecruitTrap Recruit Scams are Targeting Enterprise Credentials on Mobile
AWS Security makes an inscrutable choice