Daily Threat Briefing
An automated daily threat intelligence briefing for SOC, incident response, and vulnerability management teams.
Generated every morning around 06:30 (Europe/Berlin) from 20 sources — CISA KEV, EUVD, BSI CERT-Bund, CERT-EU, vendor research blogs, and security news — and summarized by AI.
Recent briefings
-
WordPress Core · ServiceNow AI Platform · SailPoint IdentityIQ
Active exploitation of the WordPress "wp2shell" RCE chain (CVE-2026-63030 / CVE-2026-60137) is now confirmed with public PoCs circulating — this remains the highest-priority patching action for…
-
NGINX / NGINX Plus · SonicWall SMA 1000 · WordPress Core
The dominant new development today is the confirmed active exploitation of SonicWall SMA 1000 zero-days by threat actor UTA0533, predating public disclosure since June 22. NGINX has patched a…
-
VMware Avi Load Balancer · WordPress Core · @fastify/http-proxy
The most urgent new developments today are a cluster of six VMware Avi Load Balancer vulnerabilities — including unauthenticated authentication bypass (CVSS 9.8, EPSS 0.67) and two RCE flaws (EPSS…
-
WordPress Core · Windows Local Privilege Escalation Zero-Day · Multiple Critical Vulnerabilities
A critical unauthenticated RCE in WordPress Core (CVE-2026-63030, dubbed "wp2shell") was disclosed yesterday, affecting all 6.9.x and 7.0.x installations; patches are available and forced…
-
Fortinet FortiSandbox · Microsoft SharePoint · Zoom Workplace for Windows
Three new CISA KEV entries demand immediate attention: two unauthenticated OS command injection flaws in Fortinet FortiSandbox (CVE-2026-25089, CVE-2026-39808) and a Microsoft SharePoint…
-
SonicWall SMA1000 · Mozilla Firefox · Critical Account Takeover Vulnerability
Two critical SonicWall SMA1000 zero-days (CVE-2026-15409 / CVE-2026-15410) — already KEV-listed — have been detailed by Rapid7 with full technical analysis, confirmed IOCs, and a published Python PoC…
-
Microsoft SharePoint Server · Microsoft Active Directory Federation Services · SonicWall SMA1000 Appliances
July 2026 Patch Tuesday delivered a record-breaking 622 Microsoft CVEs, including two actively exploited zero-days: CVE-2026-56164 (SharePoint EoP, KEV) and CVE-2026-56155 (AD FS EoP, KEV). A…
-
SAP NetWeaver Application Server ABAP · ServiceNow AI Platform · SAP Approuter
Today's most significant new developments are a critical memory corruption flaw in SAP NetWeaver AS ABAP (CVE-2026-44747, CVSS 9.9) and an HTTP request smuggling vulnerability in SAP Approuter…
-
Flowise · Microsoft Edge · Balbooa Forms / iCagenda
Today's most significant new developments are a Metasploit exploit module now available for CVE-2026-41264 (Flowise CSV Agent unauthenticated RCE), materially elevating exploitation risk for that…
-
Daily Threat Briefing — 2026-07-12
Today's most significant new developments are a compromised jscrambler npm package (version 8.14.0) that executes a Rust-based infostealer on install across all platforms, a critical stored XSS in…
-
Daily Threat Briefing — 2026-07-11
The most critical new developments today are two actively exploited file upload vulnerabilities in Balbooa Forms and iCagenda (both added to CISA KEV with a 2026-07-13 remediation deadline), a…
-
Daily Threat Briefing — 2026-07-10
Today's most notable new developments are the GigaWiper destructive Windows backdoor (combining disk wiping, fake ransomware, and spyware), the GodDamn ransomware family using a kernel driver to…
-
Daily Threat Briefing — 2026-07-09
Today's most urgent items are two newly disclosed critical vulnerabilities: CVE-2026-54782 in CoreWCF (CVSS 10.0, SAML token validation bypass enabling authentication bypass) and CVE-2026-43499…
-
Daily Threat Briefing — 2026-07-08
Four new CISA KEV entries dominate today's briefing: Adobe ColdFusion path traversal (CVE-2026-48282), two Joomla-ecosystem file upload flaws enabling unauthenticated RCE, and a Langflow…
-
Daily Threat Briefing — 2026-07-07
Active exploitation of Adobe ColdFusion CVE-2026-48316 (CVSS 10.0) has been confirmed, making it the most urgent item today. Three critical pre-authentication vulnerabilities in BeyondTrust Remote…
-
Daily Threat Briefing — 2026-07-06
Intelligence volume is low today. No new CISA KEV entries, BSI advisories, or CERT-EU publications were recorded in the last 24 hours. The most notable new items are a critical unauthenticated input…
-
Daily Threat Briefing — 2026-07-05
Today's intelligence volume is low, with no new CISA KEV additions, no new BSI or CERT-EU advisories, and no new threat campaign reports from major vendors. The most notable new items are a cluster…
-
Daily Threat Briefing — 2026-07-04
Today's most significant new developments are a batch of critical Gitea vulnerabilities including an unauthenticated IP spoofing flaw (CVE-2026-20896, CVSS 9.8) and SSRF bypass (CVE-2026-22874, CVSS…
-
Daily Threat Briefing — 2026-07-03
No new CISA KEV additions in the last 24 hours. BSI published a significant batch of new advisories covering Kibana, OPNsense, Ubiquiti UniFi, Coolify, MediaWiki, and IBM DataPower Gateway. Cisco has…
-
Daily Threat Briefing — 2026-07-02
CISA added CVE-2026-45659 (Microsoft SharePoint Server deserialization RCE) to the KEV catalog with a three-day remediation deadline of 2026-07-04 — immediate patching is required. Google Chrome…