Attackers are exploiting two separate critical vulnerabilities affecting Langflow and Ruby on Rails. CVE-2026-0768 allows unauthenticated attackers to execute Python code on affected Langflow ...
PaperCut disclosed two vulnerabilities in PaperCut NG and PaperCut MF that can be chained into a pre-authentication Remote Code Execution (RCE) path against vulnerable Application Servers. The flaws ...
The extortion group shinyhunters claimed Jack Henry & Associates as a victim on August 30, 2026. Jack Henry & Associates is a critical provider of financial technology infrastructure, operating with ...
Ransomware attack on Parami University, attributed to The Crew. Domain, industry, country, and victim status tracked in real time.
The vulnerability occurs because untrusted input can reach the SNMP notification workflow and be processed in a way that influences operating system command execution. According to NVD, an ...
STRU found threat actors using FTP banners as Dead Drop Resolvers – legitimate services or protocols abused to host C2 addresses and commands, so the stager never carries them itself. Live since early ...
Cisco published a new set of security advisories, addressing vulnerabilities across Catalyst SD-WAN, IOS XE, Cisco Integrated Management Controller (IMC), RoomOS, Terminal Services Agent, and related ...
Telegram briefly disappeared from the App Store worldwide on Monday night – no warning, no explanation, and no way for new users to download it. Why did it disappear? Is it back now, and how does this ...
The compromise removed official staff from the community server and turned a trusted communication channel into a potential vehicle for phishing and malicious links. Meccha Chameleon is a popular ...
Ransomware attack on Nexon, attributed to Global Secret Group. Domain, industry, country, and victim status tracked in real time.
Ransomware attack on Sunway Group, attributed to Qilin. Domain, industry, country, and victim status tracked in real time.
This article by SOCRadar Threat Research Unit (STRU) analyzes the latest ClickFake Interview campaign, a North Korean social engineering operation that targets cryptocurrency and Web3 professionals ...