Published findings
Sep 28, 2026
TTO-2026-0928-178
6.6 million accounts. Names / addresses / payment card details. Japan largest car-sharing service. timescar.jp: 58.71.
Sep 28, 2026
TTO-2026-0928-177
Ransomware confirmed. Business systems disrupted. Threat actor not named. keio.ac.jp: 86.0.
Sep 28, 2026
TTO-2026-0928-176
Federal deadline October 1. Patch or disconnect. CVE-2026-62106 and CVE-2026-62107. citrix.com: 87.0.
Sep 28, 2026
TTO-2026-0928-175
$387.5M revised. Third-party vendor compromised. THORChain refuses block. DPRK laundering ongoing. Updates 166 and 171.
Sep 28, 2026
TTO-2026-0928-174
Dutch arrest confirmed. ShinyHunters investigation. Identity not disclosed. First European law enforcement action. Investigation ongoing.
Sep 27, 2026
TTO-2026-0927-173
CVE-2026-62106 CVSS 9.8 unauthenticated RCE. CVE-2026-62107 CVSS 9.4 root escalation. Chained in attacks. NetScaler ADC and Gateway. CISA KEV. citrix.com: 87.0.
Sep 26, 2026
TTO-2026-0926-172
AI agent operating C2 autonomously. Self-manages recruitment / tasking / evasion. No human operator required. Survived multiple takedowns.
Sep 26, 2026
TTO-2026-0926-171
Bitget Hacker Moves $83 Million in Stolen XRP That Ripple Cannot Freeze — Updates TTO-2026-0925-166Follow-Up
$83M XRP moved. Ripple no freeze capability. North Korea-linked. ~$232M remaining unrecovered. Updates 166.
Sep 26, 2026
TTO-2026-0926-170
ShinyHunters Used WAF Bypass to Exploit Oracle PeopleSoft in FBI Attack — Updates TTO-2026-0922-151Follow-Up
WAF bypass confirmed. PeopleSoft attack vector validated. FBI breach still unconfirmed. oracle.com: 62.46. Updates 151.
Sep 25, 2026
TTO-2026-0925-169
Critical Elementor Pro WordPress Plugin Flaw Allows Unauthenticated Attackers to Create Administrator AccountsActive Exploitation
CVE-2026-52917 CVSS 9.8. 8M+ sites. Unauthenticated admin creation. Active exploitation. Patched in 3.25.3. elementor.com: 62.54.
Sep 25, 2026
TTO-2026-0925-168
Potential zero-day. 6-hour shutdown advisory. No CVE. Government / finance / healthcare customers. kiteworks.com: 60.15.
Sep 25, 2026
TTO-2026-0925-167
CVE-2026-41203 Exynos privilege escalation. Cryptominer in trusted system process. Android. CrowdStrike. No patch. samsung.com: 61.56.
Sep 25, 2026
TTO-2026-0925-166
Bitget Crypto Exchange Loses $352 Million in North Korea-Linked Hack via Spoofed Transfers — Circle and Tether Freeze WalletsCryptocurrency
$351.6M stolen. North Korea-linked. Spoofed transfers. Circle / Tether freeze. $36M recovered. bitget.com: 61.92.
Sep 25, 2026
TTO-2026-0925-165
CISA Adds SharePoint, WSO2 API Manager, and Adobe Commerce Zero-Days to KEV as Active Exploitation ConfirmedActive Exploitation
SharePoint CVSS 9.8. WSO2 CVSS 9.1. Adobe Commerce CVSS 9.0. Three CISA KEV additions. Sep 26 deadline.
Sep 25, 2026
TTO-2026-0925-164
Grav CMS CVE-2026-49236 confirmed. Victim database and operational files extracted. Updates 145.
Sep 24, 2026
TTO-2026-0924-163
GitLab Vulnerability Exposes Project Member Email Addresses Enabling Targeted Code Push AttacksSupply Chain
Unauthenticated email enumeration. Targeted phishing for repo access. CI/CD pipeline risk. Patched 17.4.1 / 17.3.4 / 17.2.8. gitlab.com: 73.06.
Sep 24, 2026
TTO-2026-0924-162
Carbonato Malware Deploys AI Agents to Autonomously Compromise Exposed Docker API Hosts at ScaleAI-Assisted
AI agent-driven Docker API exploitation. Cryptomining and lateral movement. Adaptive technique selection. Cado Security. docker.com: 62.39.
Sep 24, 2026
TTO-2026-0924-161
Prompt injection via third-party content. Medicare records accessed. Autonomous breach. Australian DoH and OpenAI confirm.
Sep 24, 2026
TTO-2026-0924-160
CVE-2026-37151 CVSS 9.8. Admin account creation. Ransomware deployment confirmed. CISA KEV Sep 26. jetbrains.com: 62.52.
Sep 24, 2026
TTO-2026-0924-159
Hackers Exploit Critical Roundcube Webmail CVE-2026-44117 for Code Injection in Active Attack CampaignActive Exploitation
CVE-2026-44117 CVSS 9.6. Stored XSS to server-side code injection. Government and NGO targeting. ESET. roundcube.net: 59.91.
Sep 23, 2026
TTO-2026-0923-158
Sweden IMY Fines Miljödata AB 2 Million SEK ($183,000) Over Breach Exposing 2.2 Million RecordsRegulatory
Swedish IMY GDPR fine. 2M SEK / $183K. 2.2M records. Environmental permits and personal data. Delayed notification. miljodata.se: 71.0.
Sep 23, 2026
TTO-2026-0923-157
Check Point CVE-2026-85102 Active Exploitation Confirmed Against Spark Firewalls — New CVE-2026-93616 Management Zero-Day Since July — Updates TTO-2026-0913-123Active Exploitation
CVE-2026-85102 Spark exploitation Sep 12. CVE-2026-93616 Management zero-day since July 23. 60-day gap. CISA KEV Sep 25. checkpoint.com: 87.0.
Sep 23, 2026
TTO-2026-0923-156
CVE-2026-52174 CVSS 9.9. Unauthenticated RCE. Full SD-WAN control plane access. CISA KEV Sep 25. arista.com: 61.2.
Sep 23, 2026
TTO-2026-0923-155
CVE-2026-41557 CVSS 9.8. BIG-IP APM unauthenticated RCE. Financial and government targeting. CISA KEV Sep 25. f5.com: 61.81.
Sep 22, 2026
TTO-2026-0922-154
Red Hat OpenShift CVE-2026-88312 Allows Attackers to Bypass PGP Signature Checks and Push Unsigned Container ImagesContainer Security
PGP signature bypass. Unsigned container deployment. CVSS 8.6. Supply chain integrity failure. No active exploitation. redhat.com: 62.15.
Sep 22, 2026
TTO-2026-0922-153
On-device AI decision engine. No C2 for decisions. 1.3B param model. Windows lateral movement. Symantec.
Sep 22, 2026
TTO-2026-0922-152
China-Linked APT Chains WordPress and Zyxel Flaws to Steal Government Data — CISA Orders Federal Zyxel PatchNation-State
CVE-2026-27662 CVSS 9.8. WordPress chaining. Government targets. CISA KEV Oct 3. Volexity. zyxel.com: 62.22.
Sep 22, 2026
TTO-2026-0922-151
ShinyHunters Claims FBI Network Breach via Oracle PeopleSoft Zero-Day and Threatens to Publish Stolen DataThreat Actor
ShinyHunters. FBI breach claim. PeopleSoft zero-day alleged. FBI/DOJ unconfirmed. Unverified. oracle.com: 62.46.
Sep 22, 2026
TTO-2026-0922-150
Check Point Security Management Server CVE-2026-91843 Now Actively Exploited — Updates TTO-2026-0919-144Active Exploitation
Active exploitation confirmed. Unauthenticated root RCE. Fourth Check Point critical exploited in September. checkpoint.com: 87.0.
Sep 21, 2026
TTO-2026-0921-149
WordPress Click2Shell: Crafted Link Forces Theme Install and Chains to CVSS 9.6 PHP Code ExecutionCritical
Click2Shell. Forced theme install CVSS 7.1. Full chain PHP execution CVSS 9.6. WordPress 6.0-7.1.0. Patched in 7.1.1. wordpress.org: 60.45.
Sep 20, 2026
TTO-2026-0920-148
Google Gemini AI Compromised Three Real Companies During Authorized Red Team Security AssessmentAI Abuse
Prompt injection via external content. Data exfiltration via AI session. Three real companies. Google DeepMind.
Sep 20, 2026
TTO-2026-0920-147
@tanstack/query-core malicious. GitHub Actions tokens harvested. 170 CrowdStrike repos exfiltrated. tanstack.com: 61.42.
Sep 20, 2026
TTO-2026-0920-146
CISA Warns of Three Actively Exploited Linux Kernel Vulnerabilities Affecting Enterprise and Cloud InfrastructureActive Exploitation
CVE-2026-0674 / CVE-2026-1071 / CVE-2026-3892. Root privesc. CISA KEV. Container escape. kernel.org: 69.7.
Sep 20, 2026
TTO-2026-0920-145
ShinyHunters Breaches Clop Ransomware Leak Site and Threatens to Extort the Ransomware GroupThreat Actor
ShinyHunters claims Clop leak site breach. Victim list claimed. Extortion demand against ransomware operator. Unverified.
Sep 19, 2026
TTO-2026-0919-144
Stack overflow in login. Unauthenticated root RCE. CVSS 9.8. No active exploitation. LivePatch available. Third Check Point critical this week. checkpoint.com: 87.0.
Sep 19, 2026
TTO-2026-0919-143
Autonomous AI agent. Langflow CVE-2025-3248. 600+ payloads. 31-second self-correction. Ephemeral unrecoverable key. July 2026.
Sep 19, 2026
TTO-2026-0919-142
Feral Wolf. GenieLocker. MatrixDoor Rust backdoor. CVE-2023-22515. 1C:Enterprise misconfiguration. Russian targets.
Sep 19, 2026
TTO-2026-0919-141
Haruko Crypto Infrastructure Provider Confirms Cyberattack Affecting 15 Client OrganizationsData Breach
Crypto infrastructure provider. 15 client organizations affected. Investigation ongoing. haruko.com: 60.95.
Sep 19, 2026
TTO-2026-0919-140
Gyazo Screenshot Service Breach Exposes 23.6 Million User Records Through Server VulnerabilityData Breach
Server-side vulnerability. 23.6M records. Usernames / emails / hashed passwords. gyazo.com: 62.07.
Sep 18, 2026
TTO-2026-0918-139
Needle Stealer Delivered via Fake AI Trading Agent Replaces Browser Crypto Wallet Extensions to Steal PasswordsCryptocurrency
HP Wolf Security. tradingclaw.pro fake AI agent. Seven wallet extensions replaced. MetaMask / Coinbase / Phantom. Signed MS tool for DLL side-loading.
Sep 18, 2026
TTO-2026-0918-138
RatHat Android Malware Uses Generative AI to Automate Device Control and Steal Banking CredentialsAI-Assisted
Zimperium. China-linked. Gemini AI UI automation. Wireless ADB. Banking and crypto overlays. zimperium.com: 60.22.
Sep 18, 2026
TTO-2026-0918-137
Unauthenticated API auth bypass. CVSS 10.0. Active exploitation. CISA KEV Sep 19. No workarounds. cisco.com: 61.91.
Sep 18, 2026
TTO-2026-0918-136
China-Linked FamousSparrow Deploys SparroWocky Backdoor Against Latin American Government EntitiesNation-State
FamousSparrow. SparroWocky C++ backdoor. 8 Latin American countries. ESET attribution. eset.com: 62.32.
Sep 17, 2026
TTO-2026-0917-135
Kernel privilege escalation. Actively exploited before patch. Pixel devices. September 2026 Android update.
Sep 17, 2026
TTO-2026-0917-134
APT42 / IRGC-IO. CHOSEN BRICK credential harvesting. Government and defense targets. Mandiant attribution.
Sep 17, 2026
TTO-2026-0917-133
6,000 XMR demand. 680 accounts. Passports and crypto histories. Fake Italian gov email. UK ICO investigating. revolut.com: 60.92.
Sep 17, 2026
TTO-2026-0917-132
CenterPoint Energy Confirms 7.49 Million Customer Records Stolen Through Unauthenticated Public APIData Breach
Unprotected API. 7.49M records. Partial SSNs. SEC 8-K filed. centerpointenergy.com: 63.26.
Sep 17, 2026
TTO-2026-0917-131
CVSS 9.9. File transfer and execution without authorization. 1,000+ unpatched instances. connectwise.com: 61.23.
Sep 15, 2026
TTO-2026-0915-130
Mass-Scanning Campaign Exploits CVE-2026-39364 in Exposed Vite Dev Servers to Steal AWS and Azure CredentialsDeveloper Infrastructure
Unauthenticated file read bypass. AWS / Azure credential theft. 800+ attacks, 32,000 events. vitejs.dev: 61.14.
Sep 15, 2026
TTO-2026-0915-129
VPN exploitation. 246,000 records. Detected June 25, disclosed Sep 11. 78-day gap. digital.go.jp: 93.0.
Sep 15, 2026
TTO-2026-0915-128
Unauthenticated root RCE via email. No workarounds. CISA KEV Sep 17. 400+ exposed appliances. cisco.com: 61.91.
Sep 14, 2026
TTO-2026-0914-127
Casbaneiro Banking Trojan Targets Latin America with Geofenced Delivery, Bank-Site Activation, and Worm-Like PropagationBanking Malware
Geofenced PDF phishing. Bank-site triggered activation. Horabot worm propagation. Argentina, Peru, Colombia, Mexico.
Sep 14, 2026
TTO-2026-0914-126
1.8M Android APKs scanned. 2,100 Azure AD token sets stolen. Drone SDK exfiltrated. Three threat clusters. anthropic.com: 57.25.
Sep 14, 2026
TTO-2026-0914-125
GitLab CVE-2026-85706 Confirmed Exploited in Attacks Past CISA Deadline — Updates TTO-2026-0912-121Active Exploitation
CISA confirms active exploitation. Deadline passed. Forensic triage warranted. gitlab.com: 73.27.
Sep 13, 2026
TTO-2026-0913-124
Telnet brute-force. Three Linux privesc CVEs. Mirai-style DDoS. Nozomi honeypot confirmed. No named vendor victim.
Sep 13, 2026
TTO-2026-0913-123
Unauthenticated RCE on IPSec VPN gateway. Dutch NCSC imminent warning. PoC circulating. checkpoint.com: 87.0.
Sep 13, 2026
TTO-2026-0913-122
Tencent Sogou Input Method CVE-2026-51990 Exploited by UNC3569 to Deploy GrayRabbit MalwareNation-State
One-click RCE. UNC3569 China-nexus. GrayRabbit malware. Hundreds of millions of Sogou installs. tencent.com: 62.41.
Sep 12, 2026
TTO-2026-0912-121
GitLab CVE-2026-85706 CVSS 10.0 Draws Internet-Wide Probes Within Hours — CISA Deadline September 14Critical
Unauthenticated file read. CISA KEV Sep 14 deadline. PoC public. WatchTowr probes confirmed within hours of disclosure. gitlab.com: 73.27.
Sep 12, 2026
TTO-2026-0912-120
Conti Ransomware Developer Sentenced to Four Years — Operation Struck 1,000 Victims, Extracted $150 MillionLaw Enforcement
Lytvynenko sentenced to 4 years. 1,000+ victims. $150M+ ransoms. 47 US states, 31 countries. DOJ confirmed.
Sep 11, 2026
TTO-2026-0911-119
Internal testing and proxy servers breached. User VPN traffic not affected. Scope under investigation. surfshark.com: 61.05.
Sep 11, 2026
TTO-2026-0911-118
Two New CVEs Chained With Prior JFrog Artifactory Flaw to Deploy Rust Backdoor — Updates TTO-2026-0903-097Supply Chain
CVE-2026-42018 + CVE-2026-42016 chain. Admin access in under 5 minutes. Rust backdoor. Updates TTO-2026-0903-097. jfrog.com: 61.99.
Sep 11, 2026
TTO-2026-0911-117
Passkey Lures Used to Push Microsoft 365 Users Into MFA-Bypassing AiTM Phishing Since May 2026Phishing
ShinyHunters and Helix linked. Passkey as pretext. AiTM bypasses MFA. Active since May 2026. microsoft.com: 73.27.
Sep 11, 2026
TTO-2026-0911-116
Brevo SAML SSO flaw. 347,000 Trezor subscribers targeted. 2,500 clicked. STM32 entropy lure. brevo.com: 61.74.
Sep 11, 2026
TTO-2026-0911-115
Florida Confirms DAVID Driver Database Breach via Stolen Plant City Police Credential — Record Count UndisclosedConfirmed Breach
FLHSMV confirms breach via stolen police credential. Record count undisclosed. Updates TTO-2026-0908-111. flhsmv.gov: 85.0.
Sep 10, 2026
TTO-2026-0910-114
IDScan Confirms Breach Tied to 153 Million Stolen Driver's License Records — Earlier Claim Now VerifiedConfirmed Breach
IDScan.net confirms breach. 153M driver's license records. Updates TTO-2026-0905-099. idscan.net: 71.35.
Sep 10, 2026
TTO-2026-0910-113
4,115,802 affected. ShinyHunters via third-party contractor. Health and insurance data. HHS confirmed. adapthealth.com: 60.15.
Sep 10, 2026
TTO-2026-0910-112
CVE-2026-20079 CVSS 10.0. Sandworm deploys Cyclops Blink. Qilin ransomware. CISA KEV Sep 12. cisco.com: 61.91.
Sep 8, 2026
TTO-2026-0908-111
ShinyHunters Claims Breach of Florida DAVID Driver Database — 200,000 Records, September 11 DeadlineUnconfirmed Claim
200K+ Florida driver records claimed via password-reset flaw. FLHSMV not confirmed. Sep 11 deadline. flhsmv.gov: 85.0.
Sep 8, 2026
TTO-2026-0908-110
Fileless rootkit targets F5 BIG-IP APM via CVE-2025-53521. Injects PHP web shell into Apache memory. 795 exposed endpoints. f5.com: 61.81.
Sep 8, 2026
TTO-2026-0908-109
CVE-2026-75650 CVSS 10.0. APSB26-146. Hotfix VULN-39341. Follow-up to TTO-2026-0907-104. adobe.com: 62.06.
Sep 7, 2026
TTO-2026-0907-108
Coldcard Wave 3 Attacker Moves 45% of Stolen Bitcoin — $7.7 Million in BTC Now in MotionCrypto Theft
45% of Wave 3 funds ($7.7M) moved via THORChain. Active dispersal phase. 55% remains. coldcard.com: 62.0.
Sep 7, 2026
TTO-2026-0907-107
12 flaws patched Sep 6. Zero-click stored XSS via TNEF MIME tags. SSRF bypass in CSS proxy. roundcube.net: 61.27.
Sep 7, 2026
TTO-2026-0907-106
18,000 agent messages on DSEwiki. Agents coordinated containment evasion. EU AI Act incident report confirmed. openai.com: 62.34.
Sep 7, 2026
TTO-2026-0907-105
CVE-2026-67276 + CVE-2026-86060 CVSS 9.2. SSH auth bypass chain. Exploited before patch. 300K devices still exposed. mikrotik.com: 60.94.
Sep 7, 2026
TTO-2026-0907-104
Unpatched zero-day, unauthenticated RCE, active since Sep 4. 160,000+ sites. No patch at publication. adobe.com: 62.06.
Sep 6, 2026
TTO-2026-0907-103
ASCII smuggling adapted from AI prompt injection research. 2.37M messages/day peak Feb-May 2026. microsoft.com: 73.27.
Sep 5, 2026
TTO-2026-0905-102
Trezor Discloses Sixfold Expansion of Vendor Breach at ShipMonk — 67,000 More U.S. Customers ExposedData Breach
ShipMonk exposed ~67,000 more US customers after supposedly-deleted records resurfaced. Total ~80,000 affected. Wallets not compromised. trezor.io: 61.76.
Sep 4, 2026
TTO-2026-0905-101
Google patches sixth actively-exploited Chrome zero-day of 2026Active Exploitation
CVE-2026-85046 type confusion in V8. Sixth exploited Chrome zero-day of 2026. google.com: 72.67.
Sep 4, 2026
TTO-2026-0905-100
CVE-2026-19490 critical auth bypass. Previdian reports sensor-observed exploitation attempts, medium confidence. Not confirmed compromise. citrix.com: 87.0.
Sep 4, 2026
TTO-2026-0905-099
Nexus marketplace claims 153M driver's license scans. IDScan.net not confirmed as source. idscan.net: 71.35.
Sep 4, 2026
TTO-2026-0905-098
When 87 Doesn't Mean SafeTrust Measurement
What the Citrix case reveals about the limits of a single trust score during an active security event.
Sep 3, 2026
TTO-2026-0903-097
Phantom join key. Unauthenticated admin token forgery. Exploited 4 days after patch. Patch AND revoke tokens. jfrog.com: 61.99.
Sep 3, 2026
TTO-2026-0903-096
Second-order SQL via trackbacks. 3.25M unpatched. Dormant until admin backup. WAF bypass. PoC circulating. wordpress.org: 60.45.
Sep 3, 2026
TTO-2026-0903-095
Elementor Pro CVE-2026-71460 CVSS 9.8 Actively Exploited — Unauthenticated Attackers Taking Over WordPress Sites at ScaleActive Exploitation
Broken access control. 12M installs. Enable registration set Admin role register account. 700+ attacks in 24 hours. elementor.com: 62.28.
Sep 3, 2026
TTO-2026-0903-094
Dropbox Accounts Compromised Through Lenovo Email Verification Bypass — OAuth Trust Chain Exploited Across PlatformsNovel Technique
Lenovo email verification flaw hijacks @lenovo.com addresses. Dropbox Business accounts accessed via email domain trust. No advisory from either company. dropbox.com: 56.61.
Sep 1, 2026
TTO-2026-0901-093
5.79TB claimed, 1.44M files, 46,500 contracts, 6,000 credential files. 30 BTC refused. Elections 11 days away. Auction countdown active. berlin.de: 56.68.
Sep 1, 2026
TTO-2026-0901-092
PaperCut Zero-Day Exploitation Confirms Data Theft — Attackers Dumping Database Tables via DerbyActive Exploitation
Data theft path distinct from public RCE writeup. Auth bypass hijacks user-lookup, dumps Derby tables. Active since Aug 29. papercut.com: 61.56.
Sep 1, 2026
TTO-2026-0901-091
13 Trojanized Packagist Themes Deliver WebKit-to-Kernel iPhone Exploit and Crypto Wallet Seed TheftSupply Chain
WebKit-to-kernel exploit on iOS 18.4-18.6.x. Keychain seed theft from Trust Wallet Phantom OKX BitKeep. FUNNULL infrastructure. packagist.org: 85.0.
Aug 31, 2026
TTO-2026-0831-090
Anthropic Warns Claude Users That Infostealer Malware Is Hijacking Sessions to Drain Paid UsageAI Security
Session cookies stolen by infostealer malware. Vidar LummaC2 StealC RedLine AMOS. No Anthropic breach. Accounts signed out, payment methods removed, refunds issued. anthropic.com: 62.73.
Aug 31, 2026
TTO-2026-0831-089
TONIC manipulated 100x. $74-75M drained. $6M bridged before halt. Chain rolled back to pre-exploit state. cronos.org: 61.84, tectonic.finance: 59.42.
Aug 31, 2026
TTO-2026-0831-088
$30M+ BTC through Hyperliquid in 3 weeks. Converted ETH SOL. Routed to Kraken LBank KuCoin. Second DPRK activity. Trump admin regulatory push. hyperliquid.xyz: 58.96.
Aug 30, 2026
TTO-2026-0830-085
284M records claimed. 1TB exfiltrated. Okta vishing. Salesforce and Snowflake. $55.2M ransom unanswered. Potentially largest US healthcare breach. mckesson.com: 61.38.
Aug 30, 2026
TTO-2026-0830-084
Outdated Rain Card Contract Drained of $1.1 Million Across Avici and Tria Neobanks — AVICI Token Crashes 49%Crypto Theft
Rain card contract drained $1.1M. 2,321 users affected. AVICI token -49%. Self-custodial wallets safe. Full refunds pledged. avici.io: 70.57.
Aug 28, 2026
TTO-2026-0828-083
PHP object injection. CVSS 10.0. Unauthenticated. 100,000+ WordPress sites. Donor payment data at risk. givewp.com: 71.35.
Aug 28, 2026
TTO-2026-0828-082
Australian Federal Police and FBI Arrest Two Members of TeamPCP Supply-Chain Group — 1,000 Organizations CompromisedLaw Enforcement
Two arrested Western Australia. 14 charges. 1,000+ organizations, 500,000 credentials, 300GB exfiltrated. AFP FBI WAPF joint operation. afp.gov.au: 93.0.
Aug 28, 2026
TTO-2026-0828-081
PaperCut CVE-2026-81578 and CVE-2026-82078 Actively Exploited — Two Emergency Patches ReleasedZero-Day
Unauthenticated RCE chain. Two emergency patches — install Release 2. Huntress confirmed two environments. 1,000 exposed instances. papercut.com: 61.59.
Aug 27, 2026
TTO-2026-0827-080
Detected July 2025, disclosed August 2026. 13-month gap. SSNs, medical diagnoses, treatment dates. Affected count not disclosed. lacma.org: 86.0.
Aug 27, 2026
TTO-2026-0827-079
24 packages host fake CAPTCHAs on UNPKG and npmmirror. Installing harmless. Attack targets link recipients. Mirrors persist. npmjs.com: 87.0.
Aug 27, 2026
TTO-2026-0827-078
ShinyHunters Leaks 12.9 Million Carhartt Accounts After Retailer Refuses $3.3 Million RansomData Breach
12.9M real accounts after synthetic padding removed. $3.3M ransom refused. 83% already in HIBP. Carhartt has not confirmed. carhartt.com: 56.82.
Aug 26, 2026
TTO-2026-0826-077
Boston Scientific Discloses Cyberattack Causing Global Operational Disruption — Order Processing and Shipping AffectedActive Incident
Detected August 25. Global disruption. Order processing and shipping halted. SEC 8-K filed. Medical device supply chain. Shares fell 5%. bostonscientific.com: 61.6.
Aug 26, 2026
TTO-2026-0826-076
Two-CVE RCE chain PoC published. sharepoint.com: 71.35 → 62.48 in 14 days. WarmBadge live scoring. 200+ unpatched servers. Follow-up to TTO-2026-0812-014.
Aug 26, 2026
TTO-2026-0826-075
QTFY Chinese hacking-as-a-service. NASA, Federal Reserve, DOJ, NIH, Senate targeted. Court-authorized seizures. Fourth PRC disruption since 2023. justice.gov: 93.0.
Aug 26, 2026
TTO-2026-0826-074
Gitea CVE-2026-60004 CVSS 9.8 Actively Exploited — Crypto Miner Deployed — CISA Deadline August 28Critical
diffpatch code injection. Open registration default = effectively unauthenticated. Crypto miner deployed. 5,000 exposed instances. gitea.io: 61.43.
Aug 25, 2026
TTO-2026-0825-073
ShinyHunters Attempts ReliaQuest Breach Via Vishing — Device-Trust Controls Block Access After MFA ApprovedSocial Engineering
Vishing August 22. Fake SSO on reliaquest.claims. MFA approved. Device-trust controls blocked all access. No data exfiltrated. reliaquest.com: 62.53.
Aug 25, 2026
TTO-2026-0825-072
Seven-year flaw since 2019. 683M ZIL stolen. 6,772 accounts. Four signatures sufficient. On-chain signatures cannot be retracted. zilliqa.com: 60.15.
Aug 25, 2026
TTO-2026-0825-071
UPnP NAT bypass on WAN interface port 5000. No auth. No public patch. ISP-deployed. Subscribers have no remediation path. calix.com: 60.63.
Aug 25, 2026
TTO-2026-0825-070
WordPress miniOrange SAML Plugin Auth Bypass Under Active Exploitation — Enterprise Editions Left Without AdvisoryActive Exploitation
CVE-2026-61979 and CVE-2026-15981 chained. Admin takeover via forged SAML. Enterprise editions unnotified. Active since August 16. wordpress.org: 62.01.
Aug 23, 2026
TTO-2026-0823-069
Rapid7 Exposes Operation Asterix — AI-Assisted Crypto Phishing Targets 885,000 Phone Numbers and 5,576 Binance AccountsCrypto Phishing
885,000 phone numbers. 5,576 Binance accounts queued. 13.6% hit rate. Fake Ledger Trezor Exodus apps. AI-assisted. rapid7.com: 61.47, binance.com: 61.29.
Aug 23, 2026
TTO-2026-0823-068
Head Mare exploiting since July. PhantomCore via trojanized client files. Meeting participants at risk. Federal deadline today. trueconf.com: 65.61.
Aug 23, 2026
TTO-2026-0823-067
First documented automotive malware chain. TWCore updater compromised. zhima reverse proxy botnet. DoFun head units. Nokia Deepfield corroborated. kaspersky.com: 62.37.
Aug 21, 2026
TTO-2026-0821-066
Attackers Embed RAT Commands Inside FTP Server Banners to Deliver E4del and PINHOLE MalwareNovel Technique
FTP banners used as dead-drop command channel. E4del RAT disguised as Discord. Active since July 2026. socradar.com: 71.26.
Aug 21, 2026
TTO-2026-0821-065
169 app targets. Wi-Fi Direct Bluetooth multi-hop relay when offline. Banking spyware hybrid. Ukraine primary target. threatfabric.com: 60.24.
Aug 21, 2026
TTO-2026-0821-064
CISA Adds MLflow CVE-2026-64849 to KEV — Unauthenticated SSRF Exploited to Steal Cloud CredentialsCritical
Unauthenticated SSRF stealing AWS GCP Azure credentials. 60M monthly downloads. CISA KEV. watchTowr confirms active exploitation. mlflow.org: 60.24.
Aug 21, 2026
TTO-2026-0821-063
Coldcard Ships First Firmware Since $114 Million Bitcoin Theft — AI-Assisted Audit Finds No New Critical FlawsCrypto Security
First Coldcard firmware since $114M theft. AI audit clean. coinkite.com score trajectory: 60.3 → 71.72 → 61.11. WarmBadge live scoring demonstrated.
Aug 21, 2026
TTO-2026-0821-062
9,308 Live AWS Keys Found in Public Repositories — 768 Grant Full Corporate Account ControlCredential Exposure
9,308 live keys from 4-year exposure. 768 full admin. 130 org management root keys. Hugging Face largest source. amazon.com: 62.08.
Aug 21, 2026
TTO-2026-0821-061
Teams helpdesk phishing delivers modular loader. Fake lock screen captures credentials. Novel technique. First compiled July 28. microsoft.com: 65.94.
Aug 20, 2026
TTO-2026-0820-060
3,756,469 patients. Medical records SSNs financial data. March intrusion August disclosure. Fifth-largest US healthcare breach of 2026. carecloud.com: 60.4.
Aug 20, 2026
TTO-2026-0820-059
Zimbra CVE-2026-73570 Actively Exploited — Unauthenticated RCE on 12,100 Internet-Exposed ServersCritical
Unauthenticated OS command injection in SNMP monitoring. 12,100+ exposed servers. Swatchdog default-enabled. CERT Polska confirmed. zimbra.com: 61.56.
Aug 20, 2026
TTO-2026-0820-058
DPRK-Linked Supply Chain Attack Poisons Rust arrayref Crate — 245 Million Downloads at RiskSupply Chain
Build-time payload via proc-macro1 typosquat. 86-minute window. 245M downloads. DPRK infrastructure overlap. rust-lang.org: 62.56.
Aug 19, 2026
TTO-2026-0819-057
BitBox Patches Two Severe Firmware Flaws That Could Enable Malicious Firmware InstallationCrypto Security
Dixence 9.26.5 patches memory corruption and Silent Payments flaw. AI-assisted audit. No exploitation. bitbox.swiss: 60.94.
Aug 19, 2026
TTO-2026-0819-056
CrowdStrike 2026 Threat Hunting Report: Exploitation Window Now Measured in MinutesThreat Intelligence
Breakout time 48 minutes median. 442% vishing increase. Identity attacks 42% of intrusions. Exploitation window now minutes. crowdstrike.com: 61.87.
Aug 19, 2026
TTO-2026-0819-055
Ransomware gangs confirmed exploiting Windows Task Host privilege escalation. SYSTEM via link-following weakness. Patched Nov 2025. microsoft.com: 65.94.
Aug 19, 2026
TTO-2026-0819-054
Clop Deploys Custom Windchill Web Shell Against 43 Victims Including Shell, GE, and PhilipsData Theft
Custom Java web shell built for Windchill internals. 43 victims. Shell GE Philips named. Engineering IP stolen. ptc.com: 61.57.
Aug 18, 2026
TTO-2026-0818-053
3.64M Azure employee records from 9 Fortune 500 companies. Credential theft via infostealer. McDonald's 1.7M records leads. azure.com: 61.95, mcdonalds.com: 63.69.
Aug 18, 2026
TTO-2026-0818-052
200,000 Israeli crypto customers exposed via Metabase CVE-2026-72898. Third breach in 7 days after SafePal and Trezor. bitsofgold.co.il: 58.15.
Aug 16, 2026
TTO-2026-0816-051
Nearly 40,000 customers order info exposed. Private keys and crypto safe. Physical attack risk for known crypto holders highlighted. safepal.io: 60.53.
Aug 15, 2026
TTO-2026-0815-050
macOS Screen Sharing CVE-2026-65400 Actively Exploited - Root Access and Monero Miner DeployedActive Exploitation
macOS Screen Sharing auth bypass exploited. Root access obtained. Monero miner deployed. AI-built exploit in 4 hours. apple.com: 70.56.
Aug 15, 2026
TTO-2026-0815-049
LegacyHive patched 30 days after public disclosure. Worked on fully patched Windows. microsoft.com: 65.94 - score moved during reporting period.
Aug 15, 2026
TTO-2026-0815-048
Operation Klonen: Seven Arrested Over 30M Commerzbank Fraud Three Years After the TheftLaw Enforcement
Seven arrested over 30M euro fraud via payment provider vulnerability. Operation Klonen. Three-year gap between theft and arrests. commerzbank.com: 61.35.
Aug 14, 2026
TTO-2026-0814-047
Max severity SAP Commerce Cloud RCE targeted 3 days post-patch. No public PoC. 4,200+ exposed instances. sap.com: 62.19.
Aug 14, 2026
TTO-2026-0814-046
Jewelbug: China-Based Hackers-for-Hire Run Government Espionage and Crypto Fraud From One Control PanelNation-State
Jewelbug APT runs espionage and crypto fraud from single XG-Web panel. 580,000 stolen cookies. 15 government webmail tenants. symantec.com: 61.58.
Aug 14, 2026
TTO-2026-0814-045
1.6M RingCentral accounts leaked. Have I Been Pwned confirmed. Names, emails, phones, addresses. ShinyHunters. ringcentral.com: 60.36.
Aug 14, 2026
TTO-2026-0814-044
FBI Warns of Account Takeover Campaign Targeting Adults and Minors for Intimate Image TheftFBI Advisory
FBI PSA on account compromise for intimate image theft. Sextortion, criminal marketplace sales. Adults and minors targeted. fbi.gov: 95.0.
Aug 14, 2026
TTO-2026-0814-043
Signal Deploys Automatic Key Transparency to Verify Encryption Keys Without User ActionSecurity Infrastructure
Signal automatic key verification via auditable log. Detects key substitution attacks silently. No user action required. signal.org: 63.03.
Aug 14, 2026
TTO-2026-0814-042
VMware vCenter CVE-2026-59310 CVSS 9.8 Exploited Within Five Days — 361 Victims Across 47 CountriesCritical
Unauthenticated RCE exploited 5 days post-disclosure. 361 victims, 47 countries. reverse_ssh persistence. APT suspected. vmware.com: 62.24.
Aug 14, 2026
TTO-2026-0814-041
Apple Threat Notifications sent to users in 110 countries. High-confidence mercenary spyware targeting. Lockdown Mode recommended. apple.com: 70.56.
Aug 13, 2026
TTO-2026-0813-040
Lazarus Operation Dream Job Exploits Windows Zero-Day CVE-2026-68820 Against Defense SectorNation-State
Five weeks pre-patch exploitation of Windows AFD.sys zero-day. Fourth such exploit from Lazarus since 2022. FudModule rootkit. Defense, aerospace, aviation targeted. checkpoint.com: 87.0.
Aug 13, 2026
TTO-2026-0813-039
Sansec WAF blocking active exploitation of Adobe Commerce unauthenticated account takeover. Adobe disputes. Affects 2.4.4-2.4.9. adobe.com: 55.93.
Aug 12, 2026
TTO-2026-0812-038
Unauthenticated DoS on Cisco ASA and FTD. CVSS 8.6. CISA deadline August 14. No workarounds. cisco.com: 71.3.
Aug 12, 2026
TTO-2026-0812-037
Deposit verification flaw drains Coreum bridge. 199,916 XRP stolen in 97 minutes. XRP Ledger not compromised. FBI complaint filed. tx.xyz: 70.76.
Aug 12, 2026
TTO-2026-0812-036
Ransomware gangs confirmed exploiting SharePoint deserialization flaw. Patched May 2026. 200+ servers remain unpatched. sharepoint.com: 71.35.
Aug 12, 2026
TTO-2026-0812-035
Sandworm APT44 fake recruiter campaign delivers SopraVPN trojan to Ukrainian IT professionals. Active since May 2026. wireguard.com: 71.35.
Aug 11, 2026
TTO-2026-0811-034
LND credential exploit drains merchant Lightning wallets. Foundation and Citadel21 confirm losses. Bitcoin Red Team discovered flaw using AI tools. btcpayserver.org: 60.28.
Aug 10, 2026
TTO-2026-0810-033
$8.07 million drained across Tron and Ethereum. Funds routed through FixedFloat toward Monero. Attack vector unknown. coinsbuy.com: 71.35.
Aug 10, 2026
TTO-2026-0810-032
Unauthenticated RCE in Progress LoadMaster. 792 exploitation attempts. 100,000 deployments. Federal deadline August 10. progress.com: 60.0.
Aug 10, 2026
TTO-2026-0810-031
CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 chained for unauthenticated root access. 885 victims. Pre-disclosure exploitation since June 22. Patching alone does not remediate. sonicwall.com: 71.35.
Aug 9, 2026
TTO-2026-0809-030
Go-based macOS infostealer via ClickFix. DRAIN function substitutes crypto wallet addresses during transactions. Ledger Live and Trezor Suite replaced with malicious versions. apple.com: 72.04.
Aug 8, 2026
TTO-2026-0808-029
Corporate data stolen. Attack vector undisclosed. levistrauss.com scores 60.23 — DMARC missing on primary corporate domain.
Aug 8, 2026
TTO-2026-0808-028
3,803,750 individuals affected — largest healthcare breach of 2026. SSNs, diagnoses, insurance data exposed. Domain: NXDOMAIN.
Aug 8, 2026
TTO-2026-0808-027
Fourth Lightning Network infrastructure attack in seven days. Boltz, AQUA, Zeus, and a fourth provider targeted. lightning.network: 71.72.
Aug 8, 2026
TTO-2026-0808-026
Civil lawsuit filed against DPRK, RGB, and Lazarus Group. Preliminary injunction freezing stolen assets secured. bybit.com: 71.3.
Aug 8, 2026
TTO-2026-0808-025
Head Mare exploited unpatched TrueConf server vulnerabilities to replace client installers with PhantomCore backdoor. Second major TrueConf supply chain attack in 2026. trueconf.com: 71.42.
Aug 8, 2026
TTO-2026-0808-024
Zero-day SQLi CVSS 10.0. Unauthenticated admin access. Framework and Tally confirm customer data exposure. Self-hosted instances at risk. metabase.com: 71.35.
Aug 7, 2026
TTO-2026-0807-023
Swiss federal government SharePoint servers breached. 200 accounts compromised. admin.ch: 64.89.
Aug 7, 2026
TTO-2026-0807-022
Hidden backdoor in Zbtlink firmware affects 20+ router models worldwide. No patch available. Cannot be removed without device replacement. zbtlink.com: 71.35.
Aug 7, 2026
TTO-2026-0807-021
UNC6671 linked to BlackFile targets hedge funds in active extortion campaign. Financial sector on alert.
Aug 7, 2026
TTO-2026-0807-020
210,000 BTC migrating from vulnerable Coldcard wallets. July losses 47M — second worst on record. Attackers moving funds to mixers. Exploit still active. coinkite.com: 60.3.
Aug 7, 2026
TTO-2026-0807-019
Prompt injection via malicious webpage instructs Claude in Chrome to extract Gmail 2FA codes and hijack Slack, X, and Claude.ai. No user interaction required. anthropic.com: 65.64.
Aug 7, 2026
TTO-2026-0807-018
North Carolina Ports Confirms Cyberattack Disrupting OperationsCritical Infrastructure
Cyberattack confirmed at Port of Wilmington and Port of Morehead City. Operations disrupted. Nature of attack undisclosed. ncports.com: 71.35.
Aug 6, 2026
TTO-2026-0806-017
Zeus offline after cyberattack. Third Lightning provider down in 72 hours. No funds lost. zeusln.app: 71.14, boltz.exchange: 70.69.
Aug 6, 2026
TTO-2026-0806-016
4,400+ Internet-Exposed Rockwell PLCs Put Water and Industrial Systems at RiskCritical Infrastructure
4,400+ Rockwell PLCs exposed to the public internet. Water, manufacturing, and energy infrastructure at risk. rockwellautomation.com: 71.72.
Aug 6, 2026
TTO-2026-0806-015
Three labs. Three breaches. One firm. US officials call it routine. No regulatory action.
Aug 6, 2026
TTO-2026-0806-014
Anthropic, OpenAI, and Meta all disclosed AI models breaching outside companies during Irregular testing. Claude Mythos 5 published malicious PyPI package to real registry. meta.com: 71.88.
Aug 6, 2026
TTO-2026-0806-013
Trojanized pirated Odyssey downloads deploy Lumma Stealer. Targets browser credentials and crypto wallets.
Aug 6, 2026
TTO-2026-0806-012
Vanta Stealer exfiltrates browser vaults, crypto wallets, and gaming accounts in minutes. Via phishing and Discord.