Skip to content
Auto-CTI
Archive view — this data may be outdated.

CTI status

Joel Traber AG

As of:

Last pipeline run:

Status High

All threats

Sorted by KEV · Risk · EPSS
Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

NEW A2
100

CVE-2026-58275

An authentication vulnerability in Azure DNS allows unauthorized attackers to escalate network privileges, potentially compromising access to cloud-hosted services.

Critical CVSS 10.0 EPSS 0%
NEW Iran-linked APT (Cavern Manticore operators) B3
75

Cavern Manticore: Exposing Iran-Linked Modular C2 Framework

Cavern Manticore is a modular Iran-controlled C2 framework indicating infrastructure-targeting and distributed attack capabilities threatening Western targets in critical sectors.

Critical
NEW Laundry Bear (Void Blizzard, CL-STA-1114, TA488, UNK_PitStop) C3
75

Russian Attackers Exploit Zero-Click Vulnerability in Zimbra

Russian intelligence-linked APT group Laundry Bear has been exploiting a zero-day in Zimbra since July 2025 to target email systems in Western government institutions, escalating from basic phishing techniques to sophisticated attacks.

Critical
NEW UAC-0099 C3
75

Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks

UAC-0099 uses trojaned Notepad++ plugins as a social-engineering vector to deliver MATCHBOIL.V2 malware into Windows environments, with the camouflage pattern presenting significant detection risk for organizations relying on signature-based detection of popular development software.

Critical
A3
37

Ubiquiti UniFi OS: Multiple Vulnerabilities

A BSI alert on multiple Ubiquiti UniFi OS vulnerabilities indicates elevated risk to network-perimeter security in European manufacturing environments.

Critical
NEW B3
32

Begun, the Patch Wars have

The July 2026 patch cycle marks a turning point: 622 vulnerabilities (62 critical, 3 zero-days) demonstrate accelerated vulnerability discovery by AI frontier models; simultaneously, novel malware families (StarLand RAT, WLDR C2, ARToken MFA-bypass) are active in campaigns , combined pressure on Windows/Microsoft 365 environments.

Critical
A3
20

Microsoft Edge: Multiple Vulnerabilities

BSI warns of multiple unspecified Edge vulnerabilities with variable exploitability , without CVE numbers or patch status, the concrete threat level is unclear and requires Microsoft security advisories for prioritization.

High
NEW A3
20

7-Zip: Vulnerability Enables Code Execution

An unauthenticated, remotely exploitable heap buffer overflow in 7-Zip enables code execution during XZ file processing, but requires user interaction to trigger.

High
NEW C3
20

Adobe Chrome Extension Enabled Data Theft

A widely deployed browser extension with data access enabled unauthorized data access without disclosing active exploit details or CVE numbers.

High
A3
20

7-Zip: Multiple Vulnerabilities

Multiple vulnerabilities in 7-Zip enable arbitrary code execution through opening malformed archives; patching is critical given the application's widespread use.

High
NEW C3
17

Full Disclosure as Self-Defense: The Cursor Zero Day

The Cursor vulnerability illustrates a fundamental disclosure dilemma: responsible disclosure fails when vendors do not respond promptly, forcing security researchers toward full disclosure as a last resort.

High
What has changed since yesterday? →
ESC