mitre-ta0002
324 articles with this tag
MEDIUM
MEDIUM
MEDIUM
HIGH
HIGH
CRITICAL
MEDIUM
HIGH
CRITICAL
CRITICAL
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
CRITICAL
MEDIUM
CRITICAL
HIGH
HIGH
CRITICAL
HIGH
CRITICAL
CRITICAL
HIGH
CRITICAL
MEDIUM
HIGH
CRITICAL
MEDIUM
HIGH
CRITICAL
HIGH
HIGH
CRITICAL
HIGH
CRITICAL
HIGH
CRITICAL
CRITICAL
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
MEDIUM
HIGH
CRITICAL
CRITICAL
HIGH
CRITICAL
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
MEDIUM
HIGH
CRITICAL
CRITICAL
HIGH
CRITICAL
HIGH
MEDIUM
HIGH
CRITICAL
CRITICAL
HIGH
CRITICAL
MEDIUM
HIGH
HIGH
MEDIUM
CRITICAL
CRITICAL
HIGH
HIGH
MEDIUM
CRITICAL
CRITICAL
HIGH
HIGH
India’s STPI serves TerminalFix-style attack via fake Cloudflare check
Android malware creates a hidden copy of your banking app
[NEU] [mittel] OpenClaw: Mehrere Schwachstellen
[NEU] [hoch] IBM MQ Appliance (Axios Node.js): Mehrere Schwachstellen
AI agents exploited PaperCut flaws to breach 395 organizations
PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks
[NEU] [hoch] Joplin: Mehrere Schwachstellen
Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows
Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks
F5 BIG-IP malware hides web shells in memory to evade detection
Linux Detection Engineering - Fileless Execution
Gigabud Uses Android App Cloning to Evade Fraud Detection
ClickFix Moves into the Browser to Steal Cryptocurrency
[NEU] [hoch] Dell OpenManage Server Administrator: Mehrere Schwachstellen
Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
Critical N-able N-central Vulnerability and Active Exploitation
Daisy-Chaining Trust: Investigating Faronics Deploy Abuse
Adobe Commerce max-severity bug comes under active attack
ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2
Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts
[NEU] [hoch] OpenCTI: Mehrere Schwachstellen
Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Hackers Found a Way Into Humanoid Robots | Threat Wire
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
Russian Man Extradited Over Malware Campaign Targeting Freelancers
Mobile Banking Fraud 2026: Malware Is Actively Targeting Mobile Banking Apps in the US and Canada
Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands
Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another
Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials
Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests
Mobile Fraud in 2026: Malware is Actively Targeting Mobile Banking Apps in Asia-Pacific & Japan
Off the Hook: Discovering and Observing Active Exploitation of Sangoma Switchvox CVE-2026-9586
'TerminalFix' Campaign Weaponizes PowerShell for Enterprise Attacks
⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More
[NEU] [hoch] Langflow OSS: Mehrere Schwachstellen
Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs
How Clop accessed the enterprise blueprint with no credentials
'HTTP Terminator' Hunts for Novel Desync Attacks
[NEU] [hoch] IBM Concert: Mehrere Schwachstellen
GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address
Tortoiseshell Expands Malware Toolset With New Backdoor, SSH Tunnel
You could've applied all 1,449 Oracle patches and still been hit by this attack
Mobile Banking Fraud 2026: Malware is Actively Targeting Mobile Banking Apps in Europe, Middle East & Africa
E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands
Foul Language: WordlistLoader Disguises Malware as Ordinary Text
WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords
Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor
Tracking PavinLoader across ClickFix and fake download campaigns
[NEU] [hoch] Notepad++: Mehrere Schwachstellen
UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit
Attackers use FTP banners to hide new E4del and PINHOLE RATs
[NEU] [hoch] TP-Link Omada Gateway: Mehrere Schwachstellen
[NEU] [hoch] n8n: Mehrere Schwachstellen
[NEU] [hoch] Splunk SOAR: Mehrere Schwachstellen
Def Con Attendees Targeted by Persistent Phishing Campaign
Grandoreiro Resurfaces in Mexico With New DLL Sideloading Campaign
CRLF-Powered Desync Attacks: Beheading HTTP Streams
StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data
[NEU] [hoch] Dell PowerScale OneFS: Mehrere Schwachstellen
🎥 Operation CameraSwarm: over 14,000 Dahua cameras compromised across Ukraine and Russia
Inside an Oracle Database SQL Injection Attack | Huntress
Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS
WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud
[NEU] [hoch] PostgreSQL: Mehrere Schwachstellen
Attackers target zero-day vulnerability in geospatial data platform GeoServer
It took $58 to break Microsoft’s SCCM, but a patch made it harder
New Android malware lets criminals use your bank card in real time
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide
[NEU] [mittel] OPNsense: Mehrere Schwachstellen
Lazarus hackers pair fake job offers with Windows zero-day exploit
Abuse of alternative runtime environments Deno-tes defender headaches
Fake CCleaner downloads turn Chrome into a credential-stealing surveillance tool
[NEU] [hoch] Fleet: Mehrere Schwachstellen
[NEU] [hoch] ILIAS: Mehrere Schwachstellen
NCSC-2026-0281 [1.00] [M/H] Kwetsbaarheden verholpen in Arista VeloCloud Orchestrator On-Prem
WordPress 'XSS2Shell' flaw allows admin takeover and remote code execution
The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications
Inside a Russian-speaking operator's toolkit for compromising Ukrainian IP cameras
North Korean spies are running local LLMs to cause AI mischief
Coruna, DarkSword iOS Exploits Proliferate Globally
TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore
Go-Based macOS Malware Steals Crypto and Secrets
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
Enterprise passkey security under threat from malware
[NEU] [hoch] n8n: Mehrere Schwachstellen
[NEU] [hoch] rclone: Mehrere Schwachstellen
Report: Passkey security issues could allow account takeover
Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports
Paperclip AI Flaws Let Unauthenticated Attackers Run Commands
Open-source software’s archenemy TeamPCP goes back further than anyone thought
Fake Bank of America Phishing Scam Installs Remote Access Malware
How Did Aqua Catch a Cryptomining Attack Hiding in Memory?
[NEU] [hoch] Zammad: Mehrere Schwachstellen
DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT
China-Linked Threat Actors Weaponize New Vulnerabilities in Under a Day
Midnight Blizzard Targets Travelers via Captive Portals