Report a CVE or Cyber Incident
DSADASD
In the Cyber Threat Monitor you will find continuously updated, daily information on threat actors, vulnerabilities & exploits, and recent incidents. In addition, the Cyber Threat Monitor provides a current risk assessment by country for a total of 12 sectors. The risk ratings are composed of factors from current cyber security & threat intelligence.
The Cyber Threat Monitor is available in the dashboard and on the website in the desktop version.
Real-time analysis for week 38/2026
The Cyber Threat Indicator reflects the weekly updated risk value for each country, broken down by sector.
The risk models are continuously calculated based on current cyber threat indicators.
For more information on the individual categories on the left, simply click on the category name.
| Date | CVE ID | Severity | Info | Report |
| Sep 14, 2026 | CVE-2026-46696 |
October CMS: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder Calls
|
||
| Sep 14, 2026 | CVE-2026-49400 |
October CMS: PHP Object Injection via Backend Widget Session Storage
|
||
| Sep 14, 2026 | GHSA-2xmm-m4wv-3fjh |
October CMS: Incomplete Scheme Validation in Image Resizer
|
||
| Sep 14, 2026 | RUSTSEC-2026-0285 |
TLS 1.3 handshake messages incorrectly accepted across encryption level boundaries
|
||
| Sep 14, 2026 | MAL-2026-16144 |
Malicious code in app-rrhh (npm)
|
||
| Sep 14, 2026 | MAL-2026-16146 |
Malicious code in @aiwfm/communitywfm.scripts.api (npm)
|
||
| Sep 14, 2026 | MAL-2026-16147 |
Malicious code in n8n-nodes-sysdiag (npm)
|
||
| Sep 14, 2026 | MAL-2026-16153 |
Malicious code in web-main (npm)
|
||
| Sep 14, 2026 | MAL-2026-16152 |
Malicious code in strapi-plugin-os-info-meeb322k (npm)
|
||
| Sep 14, 2026 | MAL-2026-16145 |
Malicious code in concierge-sdk (npm)
|
||
| Sep 14, 2026 | MAL-2026-16149 |
Malicious code in os-info-meeb322k (npm)
|
||
| Sep 14, 2026 | MAL-2026-16148 |
Malicious code in noblox-asset.js (npm)
|
||
| Sep 14, 2026 | MAL-2026-16150 |
Malicious code in postgreesqlhelper (npm)
|
||
| Sep 14, 2026 | MAL-2026-16151 |
Malicious code in sql-limit-enforcer (npm)
|
||
| Sep 14, 2026 | CVE-2026-46696 |
|
October CMS: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder Calls
|
|
| Sep 14, 2026 | CVE-2026-49400 |
|
October CMS: PHP Object Injection via Backend Widget Session Storage
|
|
| Sep 14, 2026 | GHSA-2xmm-m4wv-3fjh |
|
October CMS: Incomplete Scheme Validation in Image Resizer
|
|
| Sep 14, 2026 | CVE-2026-59178 |
|
ESPHome Device Builder: Renamed auth env vars silently disable dashboard authentication on upgrade
|
|
| Sep 14, 2026 | CVE-2026-90957 |
|
Affected versions of MISP serve uploaded SVG images inline without a restrictive browser sandbox.
The commit explains that ...
|
|
| Sep 14, 2026 | CVE-2026-90961 |
|
The LdapAuth and LinOTPAuth authentication plugins in MISP contain an authentication bypass vulnerability. Both LdapAuthentic...
|
| Date | Affected services | Details | Report |
| Sep 1, 2026 | Not specified | KryBit Ransomware | |
| Sep 1, 2026 | Not specified | Fiasco Ransomware | |
| Sep 1, 2026 | Westfield Public Schools (US) | Network outage disrupts Westfield Public Schools in New Jersey as a ransomware group posts samples | |
| Sep 1, 2026 | Salus (IT) | Ransomware cripples hospital bookings, online test results, and phone service. | |
| Sep 1, 2026 | Wildberries | Unknown Threat Actor Conducted DDoS Attack on E-Commerce Company Wildberries in Russia in September 2026 | |
| Aug 31, 2026 | Universitat de Barcelona (UB) (ES) | The UB investigates the scope of a cyberattack detected “recently” in several of its systems | |
| Aug 31, 2026 | Microsoft (US) | An expired certificate causes worldwide outages of various services. | |
| Aug 31, 2026 | Préfecture de Cordoue (CO) | A cyberattack affected the Córdoba Departmental Revenue systems | |
| Aug 31, 2026 | Kommunix GmbH (DE) | Cyberattack on Wolfenbüttel: Citizen services offline on August 31 | |
| Aug 31, 2026 | Salus di Trieste (IT) | Crypto for the data: the medical information of Salus was seized in a hacker attack, and a ransom was demanded | |
| Aug 31, 2026 | Policlinico Salus (IT) | Alleged Russian-Albanian Criminals Carried Out Ransomware Attack Against Salus Polyclinic in Italy From 31 August to 3 September 2026 | |
| Aug 31, 2026 | Landkreis Wolfenbüttel (DE) | Supply chain attack paralyzes online appointment booking. | |
| Aug 31, 2026 | Universitat de Barcelona (ES) | Hack leads to access credential changes and service disruptions. |
| Date | Affected org. | Details | Report |
| Sep 14, 2026 | geekybunch.com (US) | geekybunch.com became a victim of a ransomware attack by Unsafe on the Sep 14, 2026. | |
| Sep 14, 2026 | Foremost Mfg (US) | Foremost Mfg became a victim of a ransomware attack by Qilin on the Sep 14, 2026. | |
| Sep 14, 2026 | Winston Contracting LLC (US) | Winston Contracting, LLC became a victim of a ransomware attack by Qilin on the Sep 14, 2026. | |
| Sep 14, 2026 | RoadEx America (US) | RoadEx America became a victim of a ransomware attack by Qilin on the Sep 14, 2026. | |
| Sep 14, 2026 | Minmer Global | Minmer Global became a victim of a ransomware attack by Qilin on the Sep 14, 2026. | |
| Sep 14, 2026 | Dublin City Schools GA (US) | Dublin City Schools GA became a victim of a ransomware attack by Eclipse on the Sep 14, 2026. | |
| Sep 14, 2026 | Rosello et Fils (FR) | Rosello et Fils became a victim of a ransomware attack by Eclipse on the Sep 14, 2026. | |
| Sep 14, 2026 | tpi.tw (TW) | tpi.tw became a victim of a ransomware attack by Lockbit5 on the Sep 14, 2026. | |
| Sep 14, 2026 | comune.robeccosulnaviglio.mi.it (IT) | comune.robeccosulnaviglio.mi.it became a victim of a ransomware attack by Lockbit5 on the Sep 14, 2026. | |
| Sep 14, 2026 | httoy.fi (FI) | httoy.fi became a victim of a ransomware attack by Lockbit5 on the Sep 14, 2026. | |
| Sep 14, 2026 | Massey Stotser Nichols (US) | Massey, Stotser & Nichols became a victim of a ransomware attack by Insomnia on the Sep 14, 2026. | |
| Sep 14, 2026 | glasfloss.com (US) | glasfloss.com became a victim of a ransomware attack by Chaos on the Sep 14, 2026. | |
| Sep 14, 2026 | steelhausinc.com (US) | steelhausinc.com became a victim of a ransomware attack by Chaos on the Sep 14, 2026. | |
| Sep 14, 2026 | Vitar Group (AR) | Vitar Group became a victim of a ransomware attack by Qilin on the Sep 14, 2026. | |
| Sep 14, 2026 | Mestechkin Law Group P.C. (US) | Mestechkin Law Group P.C. became a victim of a ransomware attack by Booba Project on the Sep 14, 2026. | |
| Sep 14, 2026 | Atlas Ocean Voyages (US) | Atlas Ocean Voyages became a victim of a ransomware attack by Booba Project on the Sep 14, 2026. | |
| Sep 14, 2026 | Neox (RU) | Ne***ox became a victim of a ransomware attack by AuditTeam on the Sep 14, 2026. | |
| Sep 14, 2026 | Alicotrans (BR) | Alicotrans became a victim of a ransomware attack by Qilin on the Sep 14, 2026. | |
| Sep 14, 2026 | Cerámicas Kantu | Cerámicas Kantu became a victim of a ransomware attack by Panzer on the Sep 14, 2026. | |
| Sep 13, 2026 | Gilco Scaffolding (GB) | Gilco Scaffolding became a victim of a ransomware attack by Qilin on the Sep 13, 2026. |
|
|
Vallanx operates an AI-powered reporting & detection system for capturing cyber security incidents. Additional information on cyber attacks comes from a wide variety of sources. These include analyses from our own security and monitoring systems, which we operate for companies and organizations around the world. Furthermore, information from news portals, press agencies, publications from government agencies and authorities, etc. is incorporated. In addition, closed and OSINT sources are used for evaluation and verification, as well as direct reports from companies.
|
Which use case do you want to implement? Talk to us. We are happy to answer your initial questions about Cyber Security & Compliance for your company! |