Automated feed
Threat Wire
Aggregated every six hours from CISA KEV, NIST NVD, CISA advisories and trade reporting, then deduplicated and stored. Free to read, and it will stay that way — these are links to other people's public work. What a membership adds is the analyst layer on top of them.
- Entries
- 105
- Known exploited
- 25
- Last ingest
- 30 Aug, 18:53 UTC
- Sources
- 5/5
| Date | Source | Severity | Entry |
|---|---|---|---|
| BLEEP | PaperCut releases second emergency patch for exploited flawsPaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to bypass the initial fixes. [...] | ||
| THN | CVE-2026-74232 | China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root AccessVulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (ZBT), each of which gives an unauthenticated remote attacker the ability to run commands as root on affected devices. The implants, named SPEAKINGSTONE and DARKLANTERN by the company's zero-day research team, are tracked as CVE-2026-74232 and CVE-2026-74233. | |
| THN | PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF VersionsPaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. The company has released an emergency patch for v25 and v26 to address the issue. It said it's "aware of confirmed customer incidents and is treating this matter with the highest priority." An | ||
| THN | OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging FaceOpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, adding that it found evidence of misaligned behavior as early as late May. The incident, the company said, took place during cybersecurity evaluations of several OpenAI models, and that it was mainly fueled by what it described as a "highly capable | ||
| THN | CVE-2026-75604 | Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCECredit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traversal flaw affecting servers that use a Windows filesystem. The Windows path traversal, tracked as CVE-2026-75604& |