SecNoteMorning brief
Latest sync Aug 28, 10:22 PM
1 down

Reading Queue

Help
TodayActionsStack WatchFeedIntelligence
More
VendorMalwareRed TeamAIGlobal RiskUSWorld
HelpMethodologySourcesPrivacy

Queue triage

All feed: 20 matches for "initial access"

Top item: CISA Adds Six Known Exploited Vulnerabilities to Catalog

Action filterAll items
Showing18Saved0Sources down1

Feed counts show matched items; visible rows may be lower when repeated EPSS/CVE-only items are grouped for readability.

Reading Queue

Showing 18 of 20 visible rows.

Current state
More filters
criticalVulnerabilityKnown exploitedActive exploit

CVE-2015-3246 — Red Hat Libuser Race Condition +5 more (CISA KEV)

CISA Advisories | Aug 26, 2026

CISA has added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2015-3246 Red Hat Libuser Race Condition Vulnerability CVE-2015-5287 Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerabili...

Evidence and analyst toolsscore 124
Sourcerss | ok | CISA Advisories
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 26, 2026, 12:00 PM UTC
Score inputsbase score 124, priority score 134, critical severity, 6 CVEs, CISA Advisories feed item, Mentions CVE-2015-3246, CVE-2015-5287, Watchlist: CISA, KEV, Microsoft, Known exploited, Active exploit, RCE
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#CISA#KEV#Microsoft#Citrix#Linux
Sigma searchNuclei searchSentinel search
criticalVulnerabilityActive exploitRansomware

PTC Windchill & FlexPLM RCE

FortiGuard Threat Signal | Jul 28, 2026

What is the Attack? A critical unauthenticated remote code execution (RCE) vulnerability affecting PTC Windchill PDMlink and PTC FlexPLM is being actively exploited by Cl0p ransomware affiliates. The attackers are targeting vulnerable Internet-facing Product Lifecycle Manageme...

Evidence and analyst toolsscore 114
Sourcerss | ok | FortiGuard Threat Signal
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Jul 28, 2026, 11:57 PM UTC
Score inputsbase score 114, priority score 79, critical severity, 1 CVE, FortiGuard Threat Signal feed item, Mentions CVE-2026-12569, Watchlist: ransomware, Active exploit, Ransomware, RCE
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#ransomware#CVE-2026-12569#FortiGuard Threat Signal
Sigma searchNuclei searchSentinel search
criticalVulnerabilityActive exploitRansomware

WordPress Core Unauthenticated RCE (WP2Shell)

FortiGuard Threat Signal | Jul 30, 2026

What is the Attack? FortiGuard Labs is observing increasing exploitation activity targeting WP2Shell, a critical unauthenticated remote code execution (RCE) attack chain affecting WordPress Core. Unlike most WordPress attacks that rely on vulnerable plugins or themes, WP2Shell...

Evidence and analyst toolsscore 106
Sourcerss | ok | FortiGuard Threat Signal
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Jul 30, 2026, 4:33 AM UTC
Score inputsbase score 106, priority score 71, critical severity, FortiGuard Threat Signal feed item, Watchlist: ransomware, Active exploit, Ransomware, RCE
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#ransomware#FortiGuard Threat Signal
Sigma searchNuclei searchSentinel search
criticalVulnerabilityActive exploitRCE

Joomla SP Page Builder RCE

FortiGuard Outbreak Alerts | Jul 17, 2026

FortiGuard Labs continues to observe active exploitation of CVE-2026-48908, a critical unauthenticated remote code execution vulnerability affecting the JoomShaper SP Page Builder extension for Joomla. At the time of release, FortiGuard telemetry recorded 1,210 blocked exploit...

Evidence and analyst toolsscore 100
Sourcerss | ok | FortiGuard Outbreak Alerts
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Jul 17, 2026, 7:00 AM UTC
Score inputsbase score 100, priority score 65, critical severity, 1 CVE, FortiGuard Outbreak Alerts feed item, Mentions CVE-2026-48908, Active exploit, RCE
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#CVE-2026-48908#FortiGuard Outbreak Alerts
Sigma searchNuclei searchSentinel search
criticalVulnerabilityActive exploitRCE

Ubiquiti UniFi OS RCE

FortiGuard Threat Signal | Jul 9, 2026

What is the Vulnerability? Multiple critical vulnerabilities affecting Ubiquiti UniFi OS can be chained together to achieve unauthenticated remote code execution (RCE) with root privileges. The vulnerabilities include CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910, which t...

Evidence and analyst toolsscore 100
Sourcerss | ok | FortiGuard Threat Signal
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Jul 9, 2026, 1:20 AM UTC
Score inputsbase score 100, priority score 65, critical severity, 3 CVEs, FortiGuard Threat Signal feed item, Mentions CVE-2026-34908, CVE-2026-34909, Active exploit, RCE, Identity
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#CVE-2026-34908#CVE-2026-34909#CVE-2026-34910#FortiGuard Threat Signal
Sigma searchNuclei searchSentinel search
criticalVulnerabilityActive exploitPatch

PaperCut releases second emergency patch for exploited flaws

BleepingComputer | Aug 28, 2026

PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to bypass the initial fixes. [...]

Evidence and analyst toolsscore 95
Sourcerss | ok | BleepingComputer
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 28, 2026, 7:08 PM UTC
Score inputsbase score 95, priority score 113, critical severity, BleepingComputer feed item, Active exploit, Patch
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#BleepingComputer
Sigma searchNuclei searchSentinel search
criticalVulnerabilityPublic PoCRCE

Ivanti Sentry Pre-Authentication RCE

FortiGuard Threat Signal | Jul 4, 2026

What is the Vulnerability? FortiGuard Labs continues to observe exploitation attempts targeting CVE-2026-10520 following the public release of technical details and proof-of-concept (PoC) exploit code. CVE-2026-10520 is a critical vulnerability affecting Ivanti Sentry that all...

Evidence and analyst toolsscore 82
Sourcerss | ok | FortiGuard Threat Signal
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Jul 4, 2026, 12:53 AM UTC
Score inputsbase score 82, priority score 17, critical severity, 1 CVE, FortiGuard Threat Signal feed item, Mentions CVE-2026-10520, Watchlist: Ivanti, Public PoC, RCE, Identity
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#Ivanti#CVE-2026-10520#FortiGuard Threat Signal
Sigma searchNuclei searchSentinel search
criticalVulnerabilityRCE

ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories

The Hacker News | Aug 27, 2026

A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine. The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in public infrastructure, malicious tools wait...

Evidence and analyst toolsscore 81
Sourcerss | ok | The Hacker News
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 27, 2026, 3:12 PM UTC
Score inputsbase score 81, priority score 91, critical severity, The Hacker News feed item, Watchlist: Windows, SharePoint, AI, RCE
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#Windows#SharePoint#AI#The Hacker News
Sigma searchNuclei searchSentinel search
highVulnerabilityPublic PoC

Learn How to Build Security Operations Ready for AI-Powered Attacks

The Hacker News | Aug 27, 2026

Security teams have spent years trying to detect threats faster. AI is changing the harder part: how much time defenders have left to act. Advanced AI models can now help attackers discover vulnerabilities, generate exploit code, and move through weaknesses faster than traditi...

Evidence and analyst toolsscore 70
Sourcerss | ok | The Hacker News
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 27, 2026, 11:56 AM UTC
Score inputsbase score 70, priority score 80, high severity, The Hacker News feed item, AI relevance match, Watchlist: AI, Public PoC
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#AI#The Hacker News
highVulnerabilityIAIdentity

Palo Alto Networks PAN-OS GlobalProtect Auth Bypass

FortiGuard Outbreak Alerts | Jul 21, 2026

Attackers are actively exploiting a PAN-OS GlobalProtect authentication bypass vulnerability to gain unauthorized VPN access to exposed Palo Alto Networks firewalls. An attacker who successfully exploits CVE-2026-0257 can: - Establish unauthorized VPN sessions through affected...

Evidence and analyst toolsscore 70
Sourcerss | ok | FortiGuard Outbreak Alerts
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Jul 21, 2026, 7:00 AM UTC
Score inputsbase score 70, priority score 35, high severity, 1 CVE, FortiGuard Outbreak Alerts feed item, Mentions CVE-2026-0257, Watchlist: Palo Alto, VPN, IA, Identity
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#Palo Alto#VPN#CVE-2026-0257#FortiGuard Outbreak Alerts
Sigma searchNuclei searchSentinel search
highCyber newsIAIdentity

The Good, the Bad and the Ugly in Cybersecurity – Week 35

SentinelOne | Aug 28, 2026

Authorities disrupt global cybercrime rings, attackers abuse DocuSign in NovaCookies phishing, and Spark RAT targets Cambodia with vulnerable drivers.

Evidence and analyst toolsscore 67
Sourcerss | ok | SentinelOne
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 28, 2026, 4:01 PM UTC
Score inputsbase score 67, priority score 85, high severity, SentinelOne feed item, Watchlist: phishing, IA, Identity
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#phishing#SentinelOne
Sigma searchNuclei searchSentinel search
highCyber newsIAIdentity

JavaScript obfuscation: From party trick to phishing kit

Cisco Talos | Aug 27, 2026

Learn the basics of what obfuscation is, why a researcher would try to reverse it, and several ways to approach the problem.

Evidence and analyst toolsscore 62
Sourcerss | ok | Cisco Talos
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 27, 2026, 10:00 AM UTC
Score inputsbase score 62, priority score 72, high severity, Cisco Talos feed item, Watchlist: phishing, IA, Identity
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#phishing#Cisco Talos
Sigma searchNuclei searchSentinel search
highCyber newsIAIdentity

A polymorphic phishing page (that occasionally breaks itself), (Thu, Aug 27th)

SANS Internet Storm Center | Aug 27, 2026

As I've mentioned before in some of my diaries, from time to time, I like to go over phishing messages that get caught in my various spam traps or sent to us here at the Internet Storm Center.

Evidence and analyst toolsscore 62
Sourcerss | ok | SANS Internet Storm Center
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 27, 2026, 9:57 AM UTC
Score inputsbase score 62, priority score 72, high severity, SANS Internet Storm Center feed item, Watchlist: phishing, IA, Identity
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#phishing#SANS Internet Storm Center
Sigma searchNuclei searchSentinel search
highCyber newsIAIdentity

'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month

Dark Reading | Aug 26, 2026

The adversary-in-the-middle (AitM) phishing service lowers the barrier to entry for actors to create attacks and steal more than just user credentials.

Evidence and analyst toolsscore 58
Sourcerss | ok | Dark Reading
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 26, 2026, 11:33 AM UTC
Score inputsbase score 58, priority score 68, high severity, Dark Reading feed item, Watchlist: phishing, Microsoft, IA, Identity
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#phishing#Microsoft#Dark Reading
Sigma searchNuclei searchSentinel search
highCyber newsIAIdentity

UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities

Cisco Talos | Aug 20, 2026

The newly identified SPECTRE implant represents an evolution in commodity intrusion tooling, integrating cross-platform C2 operations, process injection, credential theft, anti-analysis protections, and kernel-level endpoint detection and response (EDR) bypass functionality.

Evidence and analyst toolsscore 56
Sourcerss | ok | Cisco Talos
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 20, 2026, 10:00 AM UTC
Score inputsbase score 56, priority score 43, high severity, Cisco Talos feed item, Watchlist: Linux, IA, Identity
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#Linux#Cisco Talos
Sigma searchNuclei searchSentinel search
highCyber newsIAIdentity

Identity Abuse Through Trusted Communication Channels

Unit 42 | Aug 20, 2026

Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Discover key defense strategies. The post Identity Abuse Through Trusted Communication Channels appeared first on Unit 42.

Evidence and analyst toolsscore 56
Sourcerss | ok | Unit 42
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 20, 2026, 10:00 AM UTC
Score inputsbase score 56, priority score 43, high severity, Unit 42 feed item, Watchlist: identity, phishing, IA, Identity
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#identity#phishing#Unit 42
Sigma searchNuclei searchSentinel search
highCyber newsIAIdentity

How QR-code phishing can slip past corporate security measures

ESET WeLiveSecurity | Aug 17, 2026

Quishing has become a popular alternative to traditional phishing. Here’s how businesses can close the gap.

Evidence and analyst toolsscore 56
Sourcerss | ok | ESET WeLiveSecurity
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 17, 2026, 9:00 AM UTC
Score inputsbase score 56, priority score 39, high severity, ESET WeLiveSecurity feed item, Watchlist: phishing, IA, Identity
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#phishing#ESET WeLiveSecurity
Sigma searchNuclei searchSentinel search
highCyber news

Kimwolf v7: An Evolution of the Kimwolf Botnet

Unit 42 | Aug 11, 2026

Discover how Kimwolf v7 targets Android IoT devices with HTTP/2 DDoS fingerprinting, Ethereum ENS C2 resolution and Tor backup routing. The post Kimwolf v7: An Evolution of the Kimwolf Botnet appeared first on Unit 42.

Evidence and analyst toolsscore 46
Sourcerss | ok | Unit 42
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 11, 2026, 10:00 AM UTC
Score inputsbase score 46, priority score -7, high severity, Unit 42 feed item
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#Unit 42
Sigma searchNuclei searchSentinel search
TrustSource health1 failed and 4 degraded sources in this run.

Source Health

69 sources
Coverage impact: failed: GDELT. degraded: NPR Politics, Defense.gov News, Federal Reserve Press, GovInfo Federal Register. Treat affected lanes as incomplete until refresh succeeds.

BleepingComputer

rss | 15 items

ok

The Hacker News

rss | 18 items

ok

SecurityWeek

rss | 10 items

ok

Dark Reading

rss | 18 items

ok

KrebsOnSecurity

rss | 10 items

ok

OpenAI News

rss | 8 items

ok

TechCrunch AI

rss | 10 items

ok

VentureBeat AI

rss | 7 items

ok

The Verge AI

rss | 8 items

ok

Google AI

rss | 10 items

ok

MIT News AI

rss | 8 items

ok

MIT Technology Review

rss | 6 items

ok

The Register AI/ML

rss | 8 items

ok

Google Project Zero

rss | 7 items

ok

CISA Advisories

rss | 18 items

ok

CISA ICS Advisories

rss | 8 items

ok

Microsoft Security

rss | 8 items

ok

Microsoft MSRC Updates

rss | 10 items

ok

Cisco Security Advisories

rss | 8 items

ok

Palo Alto Security Advisories

rss | 8 items

ok

FortiGuard Outbreak Alerts

rss | 8 items

ok

FortiGuard Threat Signal

rss | 8 items

ok

Chrome Releases

rss | 8 items

ok

Mozilla Security

rss | 8 items

ok

Unit 42

rss | 8 items

ok

Cisco Talos

rss | 8 items

ok

ESET WeLiveSecurity

rss | 8 items

ok

Malwarebytes Labs

rss | 8 items

ok

SentinelOne

rss | 6 items

ok

SANS Internet Storm Center

rss | 8 items

ok

CrowdStrike

rss | 7 items

ok

CyberScoop

rss | 8 items

ok

The Record

rss | 5 items

ok

DataBreaches.net

rss | 6 items

ok

BBC World

rss | 7 items

ok

BBC Business

rss | 6 items

ok

NPR World

rss | 3 items

ok

NPR Politics

rss | 0 items | Source responded but no relevant items matched.

degraded

Al Jazeera

rss | 8 items

ok

The Guardian World

rss | 6 items

ok

The Guardian US Politics

rss | 5 items

ok

The Guardian Business

rss | 6 items

ok

NYTimes World

rss | 6 items

ok

NYTimes Politics

rss | 3 items

ok

Defense.gov News

rss | 0 items | Source responded but no relevant items matched.

degraded

Federal Reserve Press

rss | 0 items | Source responded but no relevant items matched.

degraded

GovInfo Federal Register

rss | 0 items | Source responded but no relevant items matched.

degraded

GovInfo Congressional Bills

rss | 6 items

ok

NPR News

rss | 8 items

ok

NPR National

rss | 8 items

ok

NPR Politics

rss | 6 items

ok

NYTimes U.S.

rss | 6 items

ok

NYTimes Politics

rss | 6 items

ok

The Guardian U.S.

rss | 6 items

ok

BBC U.S. & Canada

rss | 6 items

ok

BBC World

rss | 8 items

ok

BBC Business

rss | 6 items

ok

NPR World

rss | 8 items

ok

Al Jazeera

rss | 8 items

ok

The Guardian World

rss | 6 items

ok

The Guardian Business

rss | 6 items

ok

NYTimes World

rss | 6 items

ok

NYTimes Business

rss | 6 items

ok

CISA KEV

structured | 22 items

ok

GitHub Advisories

api | 24 items

ok

NVD Recent CVEs

api | 18 items

ok

FIRST EPSS

api | 20 items

ok

Hacker News

api | 5 items

ok

GDELT

api | 0 items | fetch failed

failed

1 source currently timed out or rejected the request. Refresh reruns every source, including failed pulls.

ScopeWatchlist75 terms used to highlight recurring products, tactics, and security topics.

Watchlist

CISAKEVzero-dayransomwareregulationtarifftradeexport controlsupply chaininitial accessidentityphishingAI securityprompt injectionmodel poisoningagentic AIdeepfakeMicrosoftWindowsAzureEntraActive DirectoryOktaCiscoPalo AltoFortinetIvantiVMware