mitre-t1003
65 articles with this tag
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
MEDIUM
MEDIUM
HIGH
CRITICAL
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
HIGH
MEDIUM
MEDIUM
HIGH
CRITICAL
HIGH
MEDIUM
MEDIUM
HIGH
HIGH
MEDIUM
CRITICAL
CRITICAL
MEDIUM
MEDIUM
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
MEDIUM
CRITICAL
MEDIUM
HIGH
MEDIUM
CRITICAL
HIGH
CRITICAL
CRITICAL
HIGH
CRITICAL
CRITICAL
CRITICAL
HIGH
Laravel Lang Supply Chain Advisory
First Shai-Hulud Worm Clones Emerge
[local] Windows Snipping Tool - NTLMv2 Hash Hijack
Malicious node-ipc versions published to npm in suspected maintainer account compromise
TanStack Supply Chain Attack Hits Two OpenAI Employee Devices, Forces macOS Updates
OpenAI Hit by TanStack Supply Chain Attack
OpenAI caught in TanStack npm supply chain chaos after employee devices compromised
Dirty Frag gets a sequel as Fragnesia hands Linux attackers root-level access
New Fragnesia Linux Kernel LPE Grants Root Access via Page Cache Corruption
New Fragnesia Linux flaw lets attackers gain root privileges
State of ransomware in 2026
Checkmarx tackles another TeamPCP intrusion as Jenkins plugin sabotaged
'Dirty Frag' Linux zero-day exposes most distributions to LPE
Dirty Frag (CVE-2026-43284, CVE-2026-43500): Frequently asked questions about this Linux kernel privilege escalation vulnerability chain
[local] Linux nf_tables 6.19.3 - Local Privilege Escalation
New Windows flaw stems from incomplete fix for APT28-exploited bugs
ShinyHunters Claims Sale of Anthropic Claude Mythos AI Model Data and Internal Documents
Bitwarden NPM Package Hit in Supply Chain Attack
Namastex npm packages compromised in ‘CanisterWorm’ supply chain attack
The LiteLLM attack was a warning shot for Agentic AI supply chains
New npm supply-chain attack self-spreads to steal auth tokens
Critical Marimo pre-auth RCE flaw now under active exploitation
Russian hacking group targets home and small office routers to spy on users
Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns
Blast Radius of TeamPCP Attacks Expands Amid Hacker Infighting
How a Poisoned Security Scanner Became the Key to Backdooring LiteLLM
Attackers exploit critical Langflow RCE within hours as CISA sounds alarm
How a Poisoned Security Scanner Became the Key to Backdooring LiteLLM
Experts warn of a ‘loud and aggressive’ extortion wave following Trivy hack
Offensive Cases about Credential Guard & Detection Strategies
Undetected Discord Malware
Refund scam impersonates Avast to harvest credit card details
Russian group uses AI to exploit weakly-protected Fortinet firewalls, says Amazon
Russian Cyber Threat Actor Uses GenAI to Compromise Fortinet Firewalls
Arkanix Stealer pops up as short-lived AI info-stealer experiment
Ex-Google engineers charged with orchestrating high-tech secrets extraction
Facebook ads spread fake Windows 11 downloads that steal passwords and crypto wallets
“ZeroDayRAT” Emergence Signals Advanced Mobile Spyware Threats
New 'Massiv' Android banking malware poses as an IPTV app
Critical Grandstream VoIP Bug Highlights SMB Security Blind Spot
Grandstream GXP1600 VoIP Phones Exposed to Unauthenticated Remote Code Execution
Infostealer Targets OpenClaw to Loot Victim’s Digital Life
Infostealer Steals OpenClaw AI Agent Configuration Files and Gateway Tokens
Infostealer malware found stealing OpenClaw secrets for first time
New ZeroDayRAT Mobile Spyware Enables Real-Time Surveillance and Data Theft
VoidLink: The Cloud-Native Malware Framework
Android, iOS device compromise threatened by new ZeroDayRAT spyware
ZeroDayRAT spyware grants attackers total access to mobile devices
“ZeroDayRAT” Spyware Targets Android and iOS, Enables Remote Control, Camera and Microphone Access, and OTP Interception - Thailand Computer Emergency Response Team (ThaiCERT)
Multiple Researchers Confirm Active Exploitation of SolarWinds Web Help Desk Instances - RH-ISAC
North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms
North Korean hackers use new macOS malware in crypto-theft attacks
SolarWinds Web Help Desk Exploitation - February 2026
AVEVA PI to CONNECT Agent
ZeroDayRAT malware grants full access to Android, iOS devices
VoidLink Malware Exhibits Multi-Cloud Capabilities and AI Code
SolarWinds Web Help Desk Exploited for RCE in Multi-Stage Attacks on Exposed Servers
CVE-2026-2103 - Infor Syteline ERP - Keys Included: No Assembly Required
Recent SolarWinds Flaws Potentially Exploited as Zero-Days
Russian hackers exploited a critical Office bug within days of disclosure
New GlassWorm attack targets macOS via compromised OpenVSX extensions
149 Million Usernames and Passwords Exposed by Unsecured Database
CVE-2025-59102: The web server of the Access Manager offers a functionality to download a backup of the local databa...
CVE-2025-59098: The Access Manager is offering a trace functionality to debug errors and issues with the device. The...
CVE-2025-59093: Exos 9300 instances are using a randomly generated database password to connect to the configured MS...