Report a CVE or Cyber Incident
DSADASD
In the Cyber Threat Monitor you will find continuously updated, daily information on threat actors, vulnerabilities & exploits, and recent incidents. In addition, the Cyber Threat Monitor provides a current risk assessment by country for a total of 12 sectors. The risk ratings are composed of factors from current cyber security & threat intelligence.
The Cyber Threat Monitor is available in the dashboard and on the website in the desktop version.
Real-time analysis for week 38/2026
The Cyber Threat Indicator reflects the weekly updated risk value for each country, broken down by sector.
The risk models are continuously calculated based on current cyber threat indicators.
For more information on the individual categories on the left, simply click on the category name.
| Date | CVE ID | Severity | Info | Report |
| Sep 14, 2026 | CVE-2026-46696 |
October CMS: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder Calls
|
||
| Sep 14, 2026 | CVE-2026-49400 |
October CMS: PHP Object Injection via Backend Widget Session Storage
|
||
| Sep 14, 2026 | GHSA-2xmm-m4wv-3fjh |
October CMS: Incomplete Scheme Validation in Image Resizer
|
||
| Sep 14, 2026 | RUSTSEC-2026-0285 |
TLS 1.3 handshake messages incorrectly accepted across encryption level boundaries
|
||
| Sep 14, 2026 | MAL-2026-16144 |
Malicious code in app-rrhh (npm)
|
||
| Sep 14, 2026 | MAL-2026-16146 |
Malicious code in @aiwfm/communitywfm.scripts.api (npm)
|
||
| Sep 14, 2026 | MAL-2026-16147 |
Malicious code in n8n-nodes-sysdiag (npm)
|
||
| Sep 14, 2026 | MAL-2026-16153 |
Malicious code in web-main (npm)
|
||
| Sep 14, 2026 | MAL-2026-16152 |
Malicious code in strapi-plugin-os-info-meeb322k (npm)
|
||
| Sep 14, 2026 | MAL-2026-16145 |
Malicious code in concierge-sdk (npm)
|
||
| Sep 14, 2026 | MAL-2026-16149 |
Malicious code in os-info-meeb322k (npm)
|
||
| Sep 14, 2026 | MAL-2026-16148 |
Malicious code in noblox-asset.js (npm)
|
||
| Sep 14, 2026 | MAL-2026-16150 |
Malicious code in postgreesqlhelper (npm)
|
||
| Sep 14, 2026 | MAL-2026-16151 |
Malicious code in sql-limit-enforcer (npm)
|
||
| Sep 14, 2026 | CVE-2026-46696 |
|
October CMS: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder Calls
|
|
| Sep 14, 2026 | CVE-2026-49400 |
|
October CMS: PHP Object Injection via Backend Widget Session Storage
|
|
| Sep 14, 2026 | GHSA-2xmm-m4wv-3fjh |
|
October CMS: Incomplete Scheme Validation in Image Resizer
|
|
| Sep 14, 2026 | CVE-2026-59178 |
|
ESPHome Device Builder: Renamed auth env vars silently disable dashboard authentication on upgrade
|
|
| Sep 14, 2026 | CVE-2026-90957 |
|
Affected versions of MISP serve uploaded SVG images inline without a restrictive browser sandbox.
The commit explains that ...
|
|
| Sep 14, 2026 | CVE-2026-90961 |
|
The LdapAuth and LinOTPAuth authentication plugins in MISP contain an authentication bypass vulnerability. Both LdapAuthentic...
|
| Date | Affected services | Details | Report |
| Nov 18, 2026 | Paylogix (US) | Employee benefits platform Paylogix says hackers stole financial and health information. | |
| Sep 11, 2026 | Not specified | Espionage Groups Deploy BlueMoon Exploit Chain | |
| Sep 11, 2026 | DR.WU Skincare Co., Ltd. (TW) | Securities Options | |
| Sep 11, 2026 | Not specified | SloppyRAT malware | |
| Sep 11, 2026 | Machelen (BE) | Cyberattack targets services of the municipality of Machelen: “Apparently no personal data stolen” | VRT NEWS News | |
| Sep 11, 2026 | Duopharma Biotech Bhd (DPHARMA) (MY) | United Pharmaceuticals hit by a cyberattack; personal information may have been leaked | |
| Sep 11, 2026 | Kreishandwerkerschaft Borken (DE) | District craft association attacked by hackers | |
| Sep 10, 2026 | Not specified | Mantax Otax Android Malware | |
| Sep 10, 2026 | Not specified | GoldFactory threat group abuses Android Work Profiles with Vwork clone tool | |
| Sep 10, 2026 | Not specified | CL-CRI-1171 cybercrime operation | |
| Sep 10, 2026 | Not specified | Telegram-beaconing VBS downloader deploys ScreenConnect RMM | |
| Sep 10, 2026 | Mississippi Institutions of Higher Learning (IHL) (US) | Mississippi public university system reports financial aid disruption | |
| Sep 9, 2026 | Not specified | MacSync Stealer deployment via ClickFix campaigns | |
| Sep 9, 2026 | Le Tampon (FR) | www.linfo.re | |
| Sep 9, 2026 | Stadtverwaltung von Le Tampon (FR) | Cyberattack significantly affects several municipal services. | |
| Sep 9, 2026 | Surfshark (NL) | Configuration error exploited: hackers access internal data. | |
| Sep 9, 2026 | Veradigm (US) | A ransomware group steals millions of patients’ data through third-party providers. | |
| Sep 9, 2026 | Port of Tanjung Pelepas (MY) | Cyber attack disrupts operations at Malaysia’s Port of Tanjung Pelepas | |
| Sep 8, 2026 | Not specified | Amatera stealer and ZigCryptoStealer among the payloads delivered in recent ClearFake WebDAV infection chain | |
| Sep 8, 2026 | Not specified | Ted backdoor and CurlRAT activities in South Korea |
| Date | Affected org. | Details | Report |
| Sep 14, 2026 | geekybunch.com (US) | geekybunch.com became a victim of a ransomware attack by Unsafe on the Sep 14, 2026. | |
| Sep 14, 2026 | Foremost Mfg (US) | Foremost Mfg became a victim of a ransomware attack by Qilin on the Sep 14, 2026. | |
| Sep 14, 2026 | Winston Contracting LLC (US) | Winston Contracting, LLC became a victim of a ransomware attack by Qilin on the Sep 14, 2026. | |
| Sep 14, 2026 | RoadEx America (US) | RoadEx America became a victim of a ransomware attack by Qilin on the Sep 14, 2026. | |
| Sep 14, 2026 | Minmer Global | Minmer Global became a victim of a ransomware attack by Qilin on the Sep 14, 2026. | |
| Sep 14, 2026 | Dublin City Schools GA (US) | Dublin City Schools GA became a victim of a ransomware attack by Eclipse on the Sep 14, 2026. | |
| Sep 14, 2026 | Rosello et Fils (FR) | Rosello et Fils became a victim of a ransomware attack by Eclipse on the Sep 14, 2026. | |
| Sep 14, 2026 | tpi.tw (TW) | tpi.tw became a victim of a ransomware attack by Lockbit5 on the Sep 14, 2026. | |
| Sep 14, 2026 | comune.robeccosulnaviglio.mi.it (IT) | comune.robeccosulnaviglio.mi.it became a victim of a ransomware attack by Lockbit5 on the Sep 14, 2026. | |
| Sep 14, 2026 | httoy.fi (FI) | httoy.fi became a victim of a ransomware attack by Lockbit5 on the Sep 14, 2026. | |
| Sep 14, 2026 | Massey Stotser Nichols (US) | Massey, Stotser & Nichols became a victim of a ransomware attack by Insomnia on the Sep 14, 2026. | |
| Sep 14, 2026 | glasfloss.com (US) | glasfloss.com became a victim of a ransomware attack by Chaos on the Sep 14, 2026. | |
| Sep 14, 2026 | steelhausinc.com (US) | steelhausinc.com became a victim of a ransomware attack by Chaos on the Sep 14, 2026. | |
| Sep 14, 2026 | Vitar Group (AR) | Vitar Group became a victim of a ransomware attack by Qilin on the Sep 14, 2026. | |
| Sep 14, 2026 | Mestechkin Law Group P.C. (US) | Mestechkin Law Group P.C. became a victim of a ransomware attack by Booba Project on the Sep 14, 2026. | |
| Sep 14, 2026 | Atlas Ocean Voyages (US) | Atlas Ocean Voyages became a victim of a ransomware attack by Booba Project on the Sep 14, 2026. | |
| Sep 14, 2026 | Neox (RU) | Ne***ox became a victim of a ransomware attack by AuditTeam on the Sep 14, 2026. | |
| Sep 14, 2026 | Alicotrans (BR) | Alicotrans became a victim of a ransomware attack by Qilin on the Sep 14, 2026. | |
| Sep 14, 2026 | Cerámicas Kantu | Cerámicas Kantu became a victim of a ransomware attack by Panzer on the Sep 14, 2026. | |
| Sep 13, 2026 | Gilco Scaffolding (GB) | Gilco Scaffolding became a victim of a ransomware attack by Qilin on the Sep 13, 2026. |
|
|
Vallanx operates an AI-powered reporting & detection system for capturing cyber security incidents. Additional information on cyber attacks comes from a wide variety of sources. These include analyses from our own security and monitoring systems, which we operate for companies and organizations around the world. Furthermore, information from news portals, press agencies, publications from government agencies and authorities, etc. is incorporated. In addition, closed and OSINT sources are used for evaluation and verification, as well as direct reports from companies.
|
Which use case do you want to implement? Talk to us. We are happy to answer your initial questions about Cyber Security & Compliance for your company! |