Cyber Security Alerts & Threat Intelligence
Stay up to date with the latest security alerts and threat intelligence updates
Latest Alerts
China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies
Executive summary China-based artificial intelligence (AI) companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy. While “distillation” is recognized as a legitimate and useful technique in AI research, China-based AI companies are engaging in aggressive, malicious, and targeted distillation activities at an industrial scale that extract restricted proprietary functionalities and capabilities of U.S. frontier AI models. The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and Federal Bureau of Investigation (FBI) (hereafter referred to as the…
Vulnerability Summary for the Week of August 31, 2026
High Vulnerabilities PrimaryVendor — Product Description Published CVSS Score Source Info 1Hive–gardens-v2 Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. In 3e595f3 and prior, when a streaming proposal is funded, the cluster of streaming contracts moves real pool funds into the proposal’s StreamingEscrow to back the Superfluid constant flow agreement (the CFA deposit, plus a 0.5 percent margin). cancelProposal then zeroes the escrow’s GDA member units but never reclaims that parked balance, and the permissionless claim() forwards the escrow’s entire balance, including the pool funded…
Vulnerability Summary for the Week of August 24, 2026
High Vulnerabilities PrimaryVendor — Product Description Published CVSS Score Source Info 4MOSAn Security Technology–4MOSAn GCB Doctor 4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. Unauthenticated remote attackers can inject malicious commands through an unremoved ADOdb test page parameter, thereby executing arbitrary system commands on the server. 2026-08-24 9.8 CVE-2026-78211 4MOSAn Security Technology–4MOSAn Management Center 4MOSAn developed by 4MOSAn Security Technology Co., Ltd. has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit a Relative Path Traversal flaw to download arbitrary system files. 2026-08-24 7.5 CVE-2026-78212 A CPT–ACPT (Pro) – Custom Post Types Plugin…
A Tale of Two SOCs: Insights From Two Red Team Assessments
Advisory at a Glance Title A Tale of Two SOCs: Insights From Two Red Team Assessments Original Publication August 25, 2026 Executive Summary The Cybersecurity and Infrastructure Security Agency (CISA) conducted simultaneous red team assessments at two organizations and observed different defensive outcomes. In both environments, the red team achieved full domain compromise and accessed sensitive business systems (SBSs) and cloud resources. Organization A failed to detect or contain the activity, but Organization B rapidly identified initial compromise attempts, isolated affected systems, and forced the red team into an assume breach model. This advisory details the red team’s activity and…
Vulnerability Summary for the Week of August 17, 2026
High Vulnerabilities PrimaryVendor — Product Description Published CVSS Score Source Info 101gen–Automation Web Platform Notifications and OTP for WooCommerce, Advanced Country Code The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly accessible OTP request, rather than only delivering it to the user’s email address. This makes it possible for unauthenticated attackers to log in as any user on the site, including administrators,…
Defending Against an Active Threat to Siemens S7 Series PLCs
Executive summary Note: This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems. The Siemens-specific content in this advisory should be understood and applied as one subset of the wider threat landscape. Top Mitigations Inventory all Siemens S7 Series programmable logic controllers (PLCs) Apply critical security patches Ensure PLCs are not accessible from the Internet Strengthen access controls Monitor for unauthorized activity Harden PLC services, protocols, and ladder logic integrity Hunt for anomalies that may indicate…
Vulnerability Summary for the Week of August 10, 2026
High Vulnerabilities PrimaryVendor — Product Description Published CVSS Score Source Info 1meril–Blog Floating Button Unauthenticated Cross Site Scripting (XSS) in Blog Floating Button <= 1.4.20 versions. 2026-08-13 7.1 CVE-2026-28170 4xmen–pm2panel An OS command injection vulnerability in 4xmen/pm2panel (all versions) allows an authenticated remote attacker to execute arbitrary system commands on the host. The pm2panel.js handler at line 188 passes the unsanitized req.query.id parameter directly to exec(‘pm2 restart ‘ + id) without input validation or shell escaping, enabling command chaining via semicolons or other shell metacharacters. 2026-08-10 8.8 CVE-2026-72573 @fastify/busboy–@fastify/busboy @fastify/busboy is a multipart form-data parser. In versions 1.0.0 through 3.2.0,…
Vulnerability Summary for the Week of August 3, 2026
High Vulnerabilities PrimaryVendor — Product Description Published CVSS Score Source Info @fastify/aws-lambda–@fastify/aws-lambda @fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and request.awsLambda.context, values that applications are documented to use for authorization decisions such as reading API Gateway authorizer claims. In the default configuration, the getter that populates this decoration reads the client-controlled x-apigateway-event and x-apigateway-context HTTP headers before falling back to the trusted internal request token, and those reserved headers are not stripped from the incoming event. An unauthenticated attacker who can set a single HTTP header can therefore forge the entire Lambda proxy event, including the authorizer context,…
#StopRansomware: Gunra Ransomware
Advisory at a Glance Title #StopRansomware: Gunra Ransomware Original Publication August 10, 2026 Executive Summary Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site (DLS) if the ransom is not paid. This advisory provides technical details of the activity, as well as tailored detection and mitigation guidance to protect at-risk organizations from Gunra. Key Actions Prioritize patching known…
Vulnerability Summary for the Week of July 27, 2026
High Vulnerabilities PrimaryVendor — Product Description Published CVSS Score Source Info @fastify/rate-limit–@fastify/rate-limit @fastify/rate-limit before 11.2.0 keys rate-limit buckets by the verbatim client IP string returned from request.ip. Because a single IPv6 client can control a large address range (a /64 holds 2^64 distinct addresses) and the same address has multiple valid textual representations, an IPv6 capable client can defeat the rate-limit boundary by rotating addresses or by rewriting the same address in different forms. Applications that use @fastify/rate-limit to protect endpoints such as authentication, password reset, OTP delivery, or expensive API calls can be bypassed by IPv6 clients behind a…
CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs
CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector. CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible. Threat actors targeting exposed PLCs have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses. This activity has resulted in boil water notices and sustained manual operations. These threat actors are targeting water entities of all sizes. Even water organizations with mature cybersecurity processes should…
Vulnerability Summary for the Week of July 20, 2026
High Vulnerabilities PrimaryVendor — Product Description Published CVSS Score Source Info @fastify/static–@fastify/static @fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request pathnames before the file-resolution stage. This is a bypass of the earlier fix for CVE-2026-6414, which only covered encoded forward slashes. Because the underlying send library normalizes dot segments before applying its own path-traversal guard, an unauthenticated attacker can bypass any route-scoped middleware and read files inside the static root that live under the guarded URL prefix. The bypass does not allow access outside the configured static root by itself, it defeats route-guard…
Need Expert Cybersecurity Guidance?
Our US-based Security Operations Center is ready to help protect your organization.
