A critical vulnerability in Elementor Pro, a widely used WordPress page builder plugin, allowed unauthenticated attackers to upload files through the plugin’s Forms module. Tracked as CVE-2026-32475, ...
Attackers are exploiting two separate critical vulnerabilities affecting Langflow and Ruby on Rails. CVE-2026-0768 allows unauthenticated attackers to execute Python code on affected Langflow ...
PaperCut disclosed two vulnerabilities in PaperCut NG and PaperCut MF that can be chained into a pre-authentication Remote Code Execution (RCE) path against vulnerable Application Servers. The flaws ...
The extortion group shinyhunters claimed Jack Henry & Associates as a victim on August 30, 2026. Jack Henry & Associates is a critical provider of financial technology infrastructure, operating with ...
On August 27, 2026, SCA Logistik & Fulfillment GmbH, a German company specializing in supply chain and fulfillment services, was listed as a victim of the Aurora ransomware group. The listing was ...
No description available for this group.
Ransomware attack on Parami University, attributed to The Crew. Domain, industry, country, and victim status tracked in real time.
Ransomware attack on KBZ Bank, attributed to The Crew. Domain, industry, country, and victim status tracked in real time.
The vulnerability occurs because untrusted input can reach the SNMP notification workflow and be processed in a way that influences operating system command execution. According to NVD, an ...
STRU found threat actors using FTP banners as Dead Drop Resolvers – legitimate services or protocols abused to host C2 addresses and commands, so the stager never carries them itself. Live since early ...