FIRST EPSS: 20 high-likelihood CVEs clustered
FIRST EPSS | Aug 28, 2026
Grouped EPSS signal so repeated CVE-only entries do not dominate the stack. Top entries include CVE-2024-3400, CVE-2024-23897, CVE-2024-21893, CVE-2024-21887.
Queue triage
Top item: FIRST EPSS: 20 high-likelihood CVEs clustered
Feed counts show matched items; visible rows may be lower when repeated EPSS/CVE-only items are grouped for readability.
Showing 18 of 201 visible rows. 220 matched items before grouping.
FIRST EPSS | Aug 28, 2026
Grouped EPSS signal so repeated CVE-only entries do not dominate the stack. Top entries include CVE-2024-3400, CVE-2024-23897, CVE-2024-21893, CVE-2024-21887.
CISA Advisories | Aug 26, 2026
CISA has added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2015-3246 Red Hat Libuser Race Condition Vulnerability CVE-2015-5287 Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerabili...
CISA Advisories | Aug 27, 2026
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2023-49105 ownCloud Improper Authentication Vulnerability CVE-2026-53362 Linux Kernel Unspecified Vulnerability CVE-2026-66384 JFrog Art...
SecurityWeek | Aug 28, 2026
CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents. The post OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems appeared first on SecurityWeek.
The Hacker News | Aug 28, 2026
VulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (ZBT), each of which gives an unauthenticated remote attacker the ability to run commands as root on affected devices. The implants, named SPEAK...
SecurityWeek | Aug 28, 2026
Noteworthy stories that might have slipped under the radar: Manchester Airports Group cyberattack, Carhartt breach data was partly fake, U.S. Bank responds to ransomware gang’s claims. The post In Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctions appeared...
The Hacker News | Aug 27, 2026
OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, adding that it found evidence of misaligned behavior as early as late May. The incident, the company said, took place during cyber...
BleepingComputer | Aug 28, 2026
PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to bypass the initial fixes. [...]
SecurityWeek | Aug 28, 2026
A CVE identifier has not yet been assigned, but PaperCut is urging NG/MF users to install patches and implement mitigations. The post PaperCut Releases Emergency Patch for Exploited Zero-Day appeared first on SecurityWeek.
The Hacker News | Aug 28, 2026
PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. The company has released an emergency patch for v25 and v26 to address the issue. It ...
CISA Advisories | Aug 25, 2026
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-60004 Gitea Code Injection Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses si...
The Record | Aug 28, 2026
PaperCut released an emergency advisory on Thursday evening saying vulnerabilities in their print management software, PaperCut NG and MF, are under active exploitation.
Microsoft MSRC Updates | Aug 28, 2026
Improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Microsoft MSRC Updates | Aug 28, 2026
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Microsoft MSRC Updates | Aug 28, 2026
Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
Microsoft MSRC Updates | Aug 28, 2026
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
The Hacker News | Aug 28, 2026
Security researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU, including a Bluetooth Low Energy (BLE) path that can reach root on the robot's Locomotion PC. The flaws are tracked as CVE-2026-76639 and CV...
NVD Recent CVEs | Aug 25, 2026
NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
BleepingComputer
rss | 15 items
The Hacker News
rss | 18 items
SecurityWeek
rss | 10 items
Dark Reading
rss | 18 items
KrebsOnSecurity
rss | 10 items
OpenAI News
rss | 8 items
TechCrunch AI
rss | 10 items
VentureBeat AI
rss | 7 items
The Verge AI
rss | 8 items
Google AI
rss | 10 items
MIT News AI
rss | 8 items
MIT Technology Review
rss | 6 items
The Register AI/ML
rss | 8 items
Google Project Zero
rss | 7 items
CISA Advisories
rss | 18 items
CISA ICS Advisories
rss | 8 items
Microsoft Security
rss | 8 items
Microsoft MSRC Updates
rss | 10 items
Cisco Security Advisories
rss | 8 items
Palo Alto Security Advisories
rss | 8 items
FortiGuard Outbreak Alerts
rss | 8 items
FortiGuard Threat Signal
rss | 8 items
Chrome Releases
rss | 8 items
Mozilla Security
rss | 8 items
Unit 42
rss | 8 items
Cisco Talos
rss | 8 items
ESET WeLiveSecurity
rss | 8 items
Malwarebytes Labs
rss | 8 items
SentinelOne
rss | 6 items
SANS Internet Storm Center
rss | 8 items
CrowdStrike
rss | 7 items
CyberScoop
rss | 8 items
The Record
rss | 5 items
DataBreaches.net
rss | 6 items
BBC World
rss | 6 items
BBC Business
rss | 6 items
NPR World
rss | 3 items
NPR Politics
rss | 0 items | Source responded but no relevant items matched.
Al Jazeera
rss | 8 items
The Guardian World
rss | 6 items
The Guardian US Politics
rss | 5 items
The Guardian Business
rss | 6 items
NYTimes World
rss | 6 items
NYTimes Politics
rss | 2 items
Defense.gov News
rss | 0 items | Source responded but no relevant items matched.
Federal Reserve Press
rss | 0 items | Source responded but no relevant items matched.
GovInfo Federal Register
rss | 0 items | Source responded but no relevant items matched.
GovInfo Congressional Bills
rss | 6 items
NPR News
rss | 8 items
NPR National
rss | 8 items
NPR Politics
rss | 6 items
NYTimes U.S.
rss | 6 items
NYTimes Politics
rss | 6 items
The Guardian U.S.
rss | 6 items
BBC U.S. & Canada
rss | 6 items
BBC World
rss | 8 items
BBC Business
rss | 6 items
NPR World
rss | 8 items
Al Jazeera
rss | 8 items
The Guardian World
rss | 6 items
The Guardian Business
rss | 6 items
NYTimes World
rss | 6 items
NYTimes Business
rss | 6 items
CISA KEV
structured | 22 items
GitHub Advisories
api | 24 items
NVD Recent CVEs
api | 18 items
FIRST EPSS
api | 20 items
Hacker News
api | 6 items
GDELT
api | 0 items | fetch failed
1 source currently timed out or rejected the request. Refresh reruns every source, including failed pulls.