Global Threat Level: CRITICAL

7 critical threats detected in the last 24 hours. Active threat actors: Midnight Blizzard, Conti, LockBit. Immediate review of affected systems recommended.

710
CVEs Tracked
197
Critical Threats
290
High Threats
19
Threat Actors

Latest Intelligence

MEDIUMVulnerability

CFTC fines UBS $8 million for AML failures

The Commodity Futures Trading Commission today announced an order filing and settling charges against UBS Financial Services Inc., a registered futures commission merchant, for failing to diligently supervise the configuration and operation of its anti-money laundering transaction monitoring systems for wire transfers denominated in foreign currencies (FX).

45m agoGlobalFinextra
MEDIUMVulnerabilityNEW

Mastercard closes acquisition of BVNK

Mastercard (NYSE: MA) today completed its acquisition of BVNK, expanding the company’s strategy to support greater choice in how people and businesses exchange value by enabling interoperability across fiat and digital currencies.

Finextra
CRITICALVulnerabilityNEW

China-Linked Threat Actors Weaponize New Vulnerabilities in Under a Day

Chinese actors exploited the critical React2Shell exploit inside a day, while 88% of exploited vulnerabilities in H1 2026 were compromised within 48 hours of disclosure

Infosecurity Magazine
MEDIUMMalware

Inside the Underground Business of BTMOB RAT

Flare researchers analyzed thousands of underground posts to examine how the BTMOB Android malware operation evolved into a fragmented ecosystem of resellers, source-code vendors, custom versions, and competing sales channels. [...]

BleepingComputer
MEDIUMApt

Midnight Blizzard Targets Travelers via Captive Portals

Russian actor Storm-2945 hijacked hotel captive portals to push fake updates and steal tokens

Infosecurity Magazine
MEDIUMVulnerability

Infinios goes live with Mastercard on stablecoin settlement

INFINIOS, the Bahrain‑based digital financial infrastructure company, today announced that it is officially live with Mastercard on stablecoin settlement, marking a major milestone in the evolution of regulated digital payments in the Middle East.

Finextra
CRITICALVulnerability

NVD CRITICAL: CVE-2026-69085 — SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree...

SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-supplied keyword parameter is concatenated directly into SQL statements with no escaping or parameter binding. The endpoint is reachable by a publish RoleReader token, or unauthenticated when publish mode is enabled with Publish.Auth.Enable set to false. Because the statement exec

CVE-2026-69085
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-69084 — SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, whic...

SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement verbatim to the main read-write siyuan.db handle with no single-statement, read-only, or admin restrictions. The endpoint is gated only by CheckAuth, making it reachable by the publish RoleReader token and by anonymous users when publish authentication is disabled. Because the u

CVE-2026-69084
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-69083 — SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullT...

SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and publish RoleReader tokens. Attackers can execute arbitrary SQL on the read-write asset-content database via unescaped method parameters and REGEXP clauses to read, modify, or delete cross-notebook data.

CVE-2026-69083
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-64827 — Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x...

Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.php where the redirectToLoginAdminIRequestHaveAccessToken() function derives the current page name from PHP_SELF and skips authentication when the value matches 'login_admin.php'. Attackers can append '/login_admin.php' to the path of any target PHP s

CVE-2026-64827
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-18601 — A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the fun...

A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the function ovpn-client.check_config of the file /cgi-bin/glc of the component ovpn-client.so Native Plugin. Performing a manipulation of the argument filename results in command injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about

CVE-2026-18601
NIST NVD
LOWVulnerability

⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks

This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows all gave away more than intended. Some of it was clever. Most of it was just access left lying around: old bugs, exposed gear, poisoned dependencies, weak defaults, and tooling that moved from

The Hacker News
MEDIUMVulnerability

Is There Really a Fix for CISO Fatigue?

Accountability without any real authority is driving CISO burnout, and organizations need to take notice.

Dark Reading

Live Activity

Threat Alerts

Real-time alerts for the threats that matter to you. Choose your severity levels and threat categories.