Report a CVE or Cyber Incident
DSADASD
In the Cyber Threat Monitor you will find continuously updated, daily information on threat actors, vulnerabilities & exploits, and recent incidents. In addition, the Cyber Threat Monitor provides a current risk assessment by country for a total of 12 sectors. The risk ratings are composed of factors from current cyber security & threat intelligence.
The Cyber Threat Monitor is available in the dashboard and on the website in the desktop version.
Real-time analysis for week 38/2026
The Cyber Threat Indicator reflects the weekly updated risk value for each country, broken down by sector.
The risk models are continuously calculated based on current cyber threat indicators.
For more information on the individual categories on the left, simply click on the category name.
| Date | CVE ID | Severity | Info | Report |
| Sep 14, 2026 | CVE-2026-46696 |
October CMS: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder Calls
|
||
| Sep 14, 2026 | CVE-2026-49400 |
October CMS: PHP Object Injection via Backend Widget Session Storage
|
||
| Sep 14, 2026 | GHSA-2xmm-m4wv-3fjh |
October CMS: Incomplete Scheme Validation in Image Resizer
|
||
| Sep 14, 2026 | RUSTSEC-2026-0285 |
TLS 1.3 handshake messages incorrectly accepted across encryption level boundaries
|
||
| Sep 14, 2026 | MAL-2026-16144 |
Malicious code in app-rrhh (npm)
|
||
| Sep 14, 2026 | MAL-2026-16146 |
Malicious code in @aiwfm/communitywfm.scripts.api (npm)
|
||
| Sep 14, 2026 | MAL-2026-16147 |
Malicious code in n8n-nodes-sysdiag (npm)
|
||
| Sep 14, 2026 | MAL-2026-16153 |
Malicious code in web-main (npm)
|
||
| Sep 14, 2026 | MAL-2026-16152 |
Malicious code in strapi-plugin-os-info-meeb322k (npm)
|
||
| Sep 14, 2026 | MAL-2026-16145 |
Malicious code in concierge-sdk (npm)
|
||
| Sep 14, 2026 | MAL-2026-16149 |
Malicious code in os-info-meeb322k (npm)
|
||
| Sep 14, 2026 | MAL-2026-16148 |
Malicious code in noblox-asset.js (npm)
|
||
| Sep 14, 2026 | MAL-2026-16150 |
Malicious code in postgreesqlhelper (npm)
|
||
| Sep 14, 2026 | MAL-2026-16151 |
Malicious code in sql-limit-enforcer (npm)
|
||
| Sep 14, 2026 | CVE-2026-46696 |
|
October CMS: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder Calls
|
|
| Sep 14, 2026 | CVE-2026-49400 |
|
October CMS: PHP Object Injection via Backend Widget Session Storage
|
|
| Sep 14, 2026 | GHSA-2xmm-m4wv-3fjh |
|
October CMS: Incomplete Scheme Validation in Image Resizer
|
|
| Sep 14, 2026 | CVE-2026-59178 |
|
ESPHome Device Builder: Renamed auth env vars silently disable dashboard authentication on upgrade
|
|
| Sep 14, 2026 | CVE-2026-90957 |
|
Affected versions of MISP serve uploaded SVG images inline without a restrictive browser sandbox.
The commit explains that ...
|
|
| Sep 14, 2026 | CVE-2026-90961 |
|
The LdapAuth and LinOTPAuth authentication plugins in MISP contain an authentication bypass vulnerability. Both LdapAuthentic...
|
| Date | Affected services | Details | Report |
| Sep 3, 2026 | Springfield Public Schools (US) | Cyber incident forces closure of 64 Springfield, Massachusetts, schools | |
| Sep 3, 2026 | Nephrology Associates, Arkansas (US) | Ransomware gang releases 550 pages of insurance data on the internet. | |
| Sep 3, 2026 | Nephrology Associates, Kansas (US) | The ransomware group will monetize stolen data. | |
| Sep 3, 2026 | Patērētāju tiesību aizsardzības centrs (PTAC) (LV) | Contact information of 731 people stolen. | |
| Sep 3, 2026 | Νομικό Συμβούλιο του Κράτους (GR) | Hackers demand cryptocurrency for the release of stolen database files. | |
| Sep 2, 2026 | Liga Nacional contra el Cáncer (CO) | Cyberattack Affects National Cancer League Services - La Red 106.1 FM | |
| Sep 2, 2026 | Ministère de la Transition écologique (FR) | Several government websites related to the Ministry for Ecological Transition are inaccessible | |
| Sep 2, 2026 | Hangte (TW) | Cyberattack on the Haught power plant | |
| Sep 2, 2026 | Not specified | GOLD SHERWOOD Operators Leverage Credential Abuse and EDR Killers in The Gentlemen Ransomware Attacks | |
| Sep 2, 2026 | Not specified | BraZetsu - a Python-based malware | |
| Sep 2, 2026 | Not specified | RevStealer malware impersonates legitimate software | |
| Sep 2, 2026 | Not specified | What did IPS audit signatures monitor and detect for you last month? August 2026 | |
| Sep 2, 2026 | Not specified | What did IPS do to protect Servers last month? August 2026 | |
| Sep 2, 2026 | Not specified | What did IPS do for you last month? August 2026 | |
| Sep 2, 2026 | Rand Water (ZA) | Unknown Threat Actors Disrupted Payment Software And Geographic Information System Of Rand Water In South Africa On 2 September 2026 | |
| Sep 2, 2026 | Luminis Health (US) | Luminis Health seeks legal counsel amid a cybersecurity investigation | |
| Sep 2, 2026 | Tottori Prefecture (JP) | Unknown Threat Actors Launched Ransomware Attack on Environmental Radiation Monitoring System of Tottori Prefecture In Japan on 2 September 2026 | |
| Sep 2, 2026 | SPZOZ Warszawa-Ursynów (PL) | Attack on a clinic network in Warsaw. Possible data leak | |
| Sep 2, 2026 | SNEXI (FR) | Data leak at SNEXI: information about owners,... | |
| Sep 1, 2026 | Not specified | Adware Sideloading Chain Deploys ValleyRAT Payload |
| Date | Affected org. | Details | Report |
| Sep 14, 2026 | geekybunch.com (US) | geekybunch.com became a victim of a ransomware attack by Unsafe on the Sep 14, 2026. | |
| Sep 14, 2026 | Foremost Mfg (US) | Foremost Mfg became a victim of a ransomware attack by Qilin on the Sep 14, 2026. | |
| Sep 14, 2026 | Winston Contracting LLC (US) | Winston Contracting, LLC became a victim of a ransomware attack by Qilin on the Sep 14, 2026. | |
| Sep 14, 2026 | RoadEx America (US) | RoadEx America became a victim of a ransomware attack by Qilin on the Sep 14, 2026. | |
| Sep 14, 2026 | Minmer Global | Minmer Global became a victim of a ransomware attack by Qilin on the Sep 14, 2026. | |
| Sep 14, 2026 | Dublin City Schools GA (US) | Dublin City Schools GA became a victim of a ransomware attack by Eclipse on the Sep 14, 2026. | |
| Sep 14, 2026 | Rosello et Fils (FR) | Rosello et Fils became a victim of a ransomware attack by Eclipse on the Sep 14, 2026. | |
| Sep 14, 2026 | tpi.tw (TW) | tpi.tw became a victim of a ransomware attack by Lockbit5 on the Sep 14, 2026. | |
| Sep 14, 2026 | comune.robeccosulnaviglio.mi.it (IT) | comune.robeccosulnaviglio.mi.it became a victim of a ransomware attack by Lockbit5 on the Sep 14, 2026. | |
| Sep 14, 2026 | httoy.fi (FI) | httoy.fi became a victim of a ransomware attack by Lockbit5 on the Sep 14, 2026. | |
| Sep 14, 2026 | Massey Stotser Nichols (US) | Massey, Stotser & Nichols became a victim of a ransomware attack by Insomnia on the Sep 14, 2026. | |
| Sep 14, 2026 | glasfloss.com (US) | glasfloss.com became a victim of a ransomware attack by Chaos on the Sep 14, 2026. | |
| Sep 14, 2026 | steelhausinc.com (US) | steelhausinc.com became a victim of a ransomware attack by Chaos on the Sep 14, 2026. | |
| Sep 14, 2026 | Vitar Group (AR) | Vitar Group became a victim of a ransomware attack by Qilin on the Sep 14, 2026. | |
| Sep 14, 2026 | Mestechkin Law Group P.C. (US) | Mestechkin Law Group P.C. became a victim of a ransomware attack by Booba Project on the Sep 14, 2026. | |
| Sep 14, 2026 | Atlas Ocean Voyages (US) | Atlas Ocean Voyages became a victim of a ransomware attack by Booba Project on the Sep 14, 2026. | |
| Sep 13, 2026 | Gilco Scaffolding (GB) | Gilco Scaffolding became a victim of a ransomware attack by Qilin on the Sep 13, 2026. | |
| Sep 13, 2026 | Navitrans | Navitrans became a victim of a ransomware attack by Emperador on the Sep 13, 2026. | |
| Sep 13, 2026 | www.kashkha.com | www.kashkha.com became a victim of a ransomware attack by Krybit on the Sep 13, 2026. | |
| Sep 13, 2026 | CARIDRO VAL DE LOIRE (FR) | CARIDRO VAL DE LOIRE became a victim of a ransomware attack by Qilin on the Sep 13, 2026. |
|
|
Vallanx operates an AI-powered reporting & detection system for capturing cyber security incidents. Additional information on cyber attacks comes from a wide variety of sources. These include analyses from our own security and monitoring systems, which we operate for companies and organizations around the world. Furthermore, information from news portals, press agencies, publications from government agencies and authorities, etc. is incorporated. In addition, closed and OSINT sources are used for evaluation and verification, as well as direct reports from companies.
|
Which use case do you want to implement? Talk to us. We are happy to answer your initial questions about Cyber Security & Compliance for your company! |