Research
Public posts are TLP:CLEAR with defanged IOCs. Social posts link here for the full analysis. Subscribe via RSS.
-
Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
Public reporting (Segu-Info summarizing The Hacker News; heise title-level coverage) says CISA added four already-patched, high-severity bugs to the Known Exploited Vulnerabilities catalog because they are under active exploitation: Apple macOS Screen Sharing auth failure
-
CVE-2026-15446 | nosilver4u EWWW Image Optimizer Plugin bis 8.7.3 auf WordPress Unveilhooks
Public VulDB listings describe two WordPress plugin cross-site scripting issues: CVE-2026-15780 in Veronalabs WP Statistics through 14.16.8 (REST hit endpoint, `utm_campaign`) and CVE-2026-15446 in nosilver4u EWWW Image Optimizer through 8.7.3 (Unveilhooks Addon, `data-script`).
-
[MàJ] Vulnérabilité dans Citrix NetScaler ADC et NetScaler Gateway (23 octobre 2023)
Public advisories describe several Citrix NetScaler ADC / NetScaler Gateway problems that are not clearly the same event: a 2023 session-disclosure issue (CVE-2023-4966) with confirmed in-the-wild use (CERT-FR, citing Citrix, Mandiant, and CISA), and two 2026 advisory sets that
-
CVE-2026-76049 | SourceCodester Simple Online Food Ordering System 1.0
Public VulDB reporting describes three remotely reachable SQL injection flaws in SourceCodester Simple Online Food Ordering System 1.0, all in `/admin/ajax.php` (CVE-2026-76048 login username; CVE-2026-76049 `save_menu` ID; CVE-2026-76050 `delete_menu` ID).
-
Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner
Public reporting describes active abuse of CVE-2026-65400, an authentication-bypass issue in built-in macOS Screen Sharing, on hosts that expose the service to the internet.
-
Open Season: CZDS
Josh Rickard frames ICANN CZDS daily gTLD zone files as an early-lifecycle hunting source: they show that a name was delegated and which authoritative name servers (plus glue IPs) serve it, often before CT issuance, hosting, or a live lure.
-
SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code
Public reporting describes CVE-2026-58231, a maximum-severity (CVSS 10.0) unauthenticated remote code execution issue in SAP Commerce Cloud (formerly Hybris), specifically an improper-authorization weakness in the core Data Hub Adapter.
-
KindaRails2Shell: Rails Active Storage arbitrary file read
Critical unauthenticated arbitrary file read in Ruby on Rails Active Storage image processing when libvips is used (CVE-2026-66066). Public-source synthesis.
-
CVE-2026-19847 | TOTOLINK A800R 4.1.2cu.5137_B20200730 wps.so /cgi-bin/cstecgi.cgi
Public VulDB listings describe four critical buffer-overflow issues in TOTOLINK A800R firmware 4.1.2cu.5137_B20200730, all reached through `/cgi-bin/cstecgi.cgi` in different shared objects (`ipv6.so`, `lan.so`, `firewall.so`, `wps.so`).
-
August 2026 Patch Tuesday
Public August 2026 Microsoft Patch Tuesday reporting — one exploited zero-day and dozens of critical CVEs among a large patch set.
-
ZDI-26-577: Trend Micro VPN OpenSSL Configuration Uncontrolled Search Path Element Local
This memo synthesizes public Zero Day Initiative advisories dated 13 August 2026.
-
First look at Flare Academy Darkroom (CTIA)
Flare opened a free Darkroom lab for dark-web intelligence tradecraft. A practitioner first look at the CTIA track, still in progress.
-
Cisco ISE directory traversal and command injection
Public ZDI advisories (coordinated 2026-08-13) describe four Cisco Identity Services Engine (ISE) flaws: unauthenticated information disclosure via upgrade-file handling, two authenticated directory-traversal bugs, and authenticated command injection.
-
VMware vCenter Syslog Server RCE exploited in the wild
Unauthenticated RCE in vCenter Syslog Server (CVE-2026-59310), then reverse-SSH persistence. Public-source synthesis; not independent reverse engineering.
-
SharePoint JWT/S2S authentication bypass
CVE-2026-55040 is an unauthenticated JWT/S2S authentication bypass in on-premises Microsoft SharePoint.