Daily Threat Briefing
An automated daily threat intelligence briefing for SOC, incident response, and vulnerability management teams.
Generated every morning around 06:30 (Europe/Berlin) from 20 sources — CISA KEV, EUVD, BSI CERT-Bund, CERT-EU, vendor research blogs, and security news — and summarized by AI.
Briefings
WordPress Core · ServiceNow AI Platform · SailPoint IdentityIQ
Active exploitation of the WordPress "wp2shell" RCE chain (CVE-2026-63030 / CVE-2026-60137) is now confirmed with public PoCs circulating — this remains the highest-priority patching action for…
NGINX / NGINX Plus · SonicWall SMA 1000 · WordPress Core
The dominant new development today is the confirmed active exploitation of SonicWall SMA 1000 zero-days by threat actor UTA0533, predating public disclosure since June 22. NGINX has patched a…
VMware Avi Load Balancer · WordPress Core · @fastify/http-proxy
The most urgent new developments today are a cluster of six VMware Avi Load Balancer vulnerabilities — including unauthenticated authentication bypass (CVSS 9.8, EPSS 0.67) and two RCE flaws (EPSS…
WordPress Core · Windows Local Privilege Escalation Zero-Day · Multiple Critical Vulnerabilities
A critical unauthenticated RCE in WordPress Core (CVE-2026-63030, dubbed "wp2shell") was disclosed yesterday, affecting all 6.9.x and 7.0.x installations; patches are available and forced…
Fortinet FortiSandbox · Microsoft SharePoint · Zoom Workplace for Windows
Three new CISA KEV entries demand immediate attention: two unauthenticated OS command injection flaws in Fortinet FortiSandbox (CVE-2026-25089, CVE-2026-39808) and a Microsoft SharePoint…
SonicWall SMA1000 · Mozilla Firefox · Critical Account Takeover Vulnerability
Two critical SonicWall SMA1000 zero-days (CVE-2026-15409 / CVE-2026-15410) — already KEV-listed — have been detailed by Rapid7 with full technical analysis, confirmed IOCs, and a published Python PoC…
Microsoft SharePoint Server · Microsoft Active Directory Federation Services · SonicWall SMA1000 Appliances
July 2026 Patch Tuesday delivered a record-breaking 622 Microsoft CVEs, including two actively exploited zero-days: CVE-2026-56164 (SharePoint EoP, KEV) and CVE-2026-56155 (AD FS EoP, KEV). A…
SAP NetWeaver Application Server ABAP · ServiceNow AI Platform · SAP Approuter
Today's most significant new developments are a critical memory corruption flaw in SAP NetWeaver AS ABAP (CVE-2026-44747, CVSS 9.9) and an HTTP request smuggling vulnerability in SAP Approuter…
Flowise · Microsoft Edge · Balbooa Forms / iCagenda
Today's most significant new developments are a Metasploit exploit module now available for CVE-2026-41264 (Flowise CSV Agent unauthenticated RCE), materially elevating exploitation risk for that…
Zimbra Collaboration Suite · Microsoft Edge · RSFiles extension for Joomla
Today's most significant new developments are a compromised jscrambler npm package (version 8.14.0) that executes a Rust-based infostealer on install across all platforms, a critical stored XSS in…
Balbooa Forms for Joomla · iCagenda for Joomla · Flowise
The most critical new developments today are two actively exploited file upload vulnerabilities in Balbooa Forms and iCagenda (both added to CISA KEV with a 2026-07-13 remediation deadline), a…
Microsoft Defender / Malware Protection Engine · Junos OS on MX Series · Metabase open-source and Enterprise —
Today's most notable new developments are the GigaWiper destructive Windows backdoor (combining disk wiping, fake ransomware, and spyware), the GodDamn ransomware family using a kernel driver to…
CoreWCF · Linux kernel — virtually all mainstream distributions shipping the affected code since 2011 · UniFi Connect
Today's most urgent items are two newly disclosed critical vulnerabilities: CVE-2026-54782 in CoreWCF (CVSS 10.0, SAML token validation bypass enabling authentication bypass) and CVE-2026-43499…
Adobe ColdFusion · JoomShaper SP Page Builder · Langflow
Four new CISA KEV entries dominate today's briefing: Adobe ColdFusion path traversal (CVE-2026-48282), two Joomla-ecosystem file upload flaws enabling unauthenticated RCE, and a Langflow…
ColdFusion · Linux kernel KVM hypervisor · BeyondTrust Remote Support and Privileged Remote Access
Active exploitation of Adobe ColdFusion CVE-2026-48316 (CVSS 10.0) has been confirmed, making it the most urgent item today. Three critical pre-authentication vulnerabilities in BeyondTrust Remote…
cve-search · ail-framework v0
Intelligence volume is low today. No new CISA KEV entries, BSI advisories, or CERT-EU publications were recorded in the last 24 hours. The most notable new items are a critical unauthenticated input…
picklescan · n8n · Unity Parsec for Windows
Today's intelligence volume is low, with no new CISA KEV additions, no new BSI or CERT-EU advisories, and no new threat campaign reports from major vendors. The most notable new items are a cluster…
Gitea Open Source Git Server · Linux kernel · Microsoft Edge
Today's most significant new developments are a batch of critical Gitea vulnerabilities including an unauthenticated IP spoofing flaw (CVE-2026-20896, CVSS 9.8) and SSRF bypass (CVE-2026-22874, CVSS…
Cisco Unified Communications Manager · Kibana · OPNsense
No new CISA KEV additions in the last 24 hours. BSI published a significant batch of new advisories covering Kibana, OPNsense, Ubiquiti UniFi, Coolify, MediaWiki, and IBM DataPower Gateway. Cisco has…
Microsoft SharePoint Server · Google Chrome · SUSE Rancher
CISA added CVE-2026-45659 (Microsoft SharePoint Server deserialization RCE) to the KEV catalog with a three-day remediation deadline of 2026-07-04 — immediate patching is required. Google Chrome…
Progress Kemp LoadMaster · IBM Db2 · Adobe ColdFusion 2025
Active exploitation of CVE-2026-46817 (Oracle E-Business Suite) continues with confirmed breach victims. New today: CVE-2026-48558 (SimpleHelp) CISA KEV deadline falls tomorrow (2026-07-02) — any…
SimpleHelp · libssh2 · Oracle E-Business Suite
The most critical new development is active exploitation of CVE-2026-48558, a SimpleHelp authentication bypass now on the CISA KEV catalog, with confirmed deployment of a previously undocumented…
BerriAI LiteLLM Proxy · Dalfox Server
Today's most significant new developments are the addition of new Metasploit exploit modules for CVE-2026-42208 (LiteLLM pre-auth SQL injection, CISA KEV) and CVE-2026-45087 (Dalfox Server…
Invoice Generator plugin for WordPress · libssh2 · Gitea act_runner with Docker backend
Today's most notable new items are two libssh2 memory-safety vulnerabilities (CVE-2026-58050 and CVE-2026-58051) affecting all deployments through version 1.11.1, a critical privilege escalation in…
Linux kernel · Kestra OSS workflow orchestration platform · Budibase low-code platform
The most significant new developments today are: a public working exploit for the Linux kernel "pedit COW" privilege escalation (CVE-2026-46331) and a newly detailed DirtyClone variant…
PTC Windchill PLM platform and FlexPLM · All Go applications using golang.org/x/crypto
Two new CISA KEV entries demand immediate attention: CVE-2026-12569 (PTC Windchill/FlexPLM, unauthenticated RCE) and CVE-2026-20230 (Cisco Unified CM SSRF, file-write to root) — both with a patch…
Cisco Catalyst SD-WAN Manager · Cacti performance and fault management framework · Gogs self-hosted Git service
Mandiant has published technical details on active zero-day exploitation of CVE-2026-20245 in Cisco Catalyst SD-WAN Manager, enabling root-level privilege escalation at a service provider. A…
Cisco Unified Communications Manager · Ubiquiti UniFi OS · Lantronix EDS5000 serial-to-Ethernet device server
CISA added four actively exploited vulnerabilities to the KEV catalog on 2026-06-23, including three Ubiquiti UniFi OS flaws and a Lantronix EDS5000 code injection, all with a 2026-06-26 remediation…
IBM Langflow OSS · MISP · Multiple TP-Link models including Archer MR200 v7/v8
The most significant new developments today are a large-scale supply chain attack backdooring multiple ShapedPlugin WordPress Pro plugins, a new OXLOADER/CastleStealer malvertising campaign…
Craft CMS · Crawl4AI · libssh2 library
Today's most significant new developments are a critical remote code execution vulnerability in Craft CMS affecting versions 5.5.0 through 5.9.13, multiple critical flaws in the libssh2 library…