Report a CVE or Cyber Incident
DSADASD
In the Cyber Threat Monitor you will find continuously updated, daily information on threat actors, vulnerabilities & exploits, and recent incidents. In addition, the Cyber Threat Monitor provides a current risk assessment by country for a total of 12 sectors. The risk ratings are composed of factors from current cyber security & threat intelligence.
The Cyber Threat Monitor is available in the dashboard and on the website in the desktop version.
Real-time analysis for week 32/2026
The Cyber Threat Indicator reflects the weekly updated risk value for each country, broken down by sector.
The risk models are continuously calculated based on current cyber threat indicators.
For more information on the individual categories on the left, simply click on the category name.
| Date | CVE ID | Severity | Info | Report |
| Aug 6, 2026 | CVE-2026-71327 |
|
Traefik: Gateway API route identity collision allows cross-namespace backend hijacking
|
|
| Aug 6, 2026 | CVE-2026-54764 |
|
Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false
|
|
| Aug 6, 2026 | CVE-2026-71325 |
Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef
|
||
| Aug 6, 2026 | CVE-2026-54765 |
Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port
|
||
| Aug 6, 2026 | CVE-2026-67309 |
Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass
|
||
| Aug 6, 2026 | CVE-2026-65600 |
|
Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware
|
|
| Aug 6, 2026 | CVE-2026-54763 |
Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in...
|
||
| Aug 6, 2026 | GHSA-pwwh-3685-58r7 CVE-2026-61466 |
|
In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist. This could lead to a client self-assigning privileged scopes at registration time. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
|
|
| Aug 6, 2026 | CVE-2026-65520 GHSA-75cj-86wv-m74j |
|
Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.
|
|
| Aug 6, 2026 | CVE-2026-65571 GHSA-98qj-xx3j-73qx |
|
Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.
|
|
| Aug 6, 2026 | GHSA-vwq7-f8p8-h8fh CVE-2026-65576 |
|
Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.
|
|
| Aug 6, 2026 | blt33433fe9bdc7e443_en-us |
Popular NPM Packages Hijacked with New Shai-Hulud Malware
|
||
| Aug 6, 2026 | CVE-2026-68750 |
|
Inefficient Algorithmic Complexity vulnerability in the traversal engine in rrrene html_sanitize_ex allows an unauthenticated...
|
|
| Aug 6, 2026 | CVE-2026-68749 |
|
Inefficient Regular Expression Complexity vulnerability in the CSS scrubber in rrrene html_sanitize_ex allows an unauthentica...
|
|
| Aug 6, 2026 | CVE-2026-68747 |
|
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in the CSS s...
|
|
| Aug 6, 2026 | CVE-2026-66843 |
|
Inclusion of Functionality from Untrusted Control Sphere vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allow...
|
|
| Aug 6, 2026 | CVE-2026-66829 |
|
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a r...
|
|
| Aug 6, 2026 | CVE-2026-66370 |
|
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows an ...
|
|
| Aug 6, 2026 | CVE-2026-5423 |
|
@neo4j/graphql library versions prior to 7.5.6 fail to verify the authenticity of a client-supplied, pre-decoded JWT object p...
|
|
| Aug 6, 2026 | CVE-2026-53985 |
|
Ground Station prior to 0.6.0 contains an unauthenticated denial-of-service vulnerability in the Socket.IO server's service_c...
|
| Date | Affected services | Details | Report |
| Aug 7, 2026 | Not specified | Vanta Stealer | |
| Aug 7, 2026 | Not specified | Greatness PhaaS Campaigns Continue | |
| Aug 7, 2026 | Not specified | Fake CAPTCHA Prompts Leverage ClickFix Tactics to Infect macOS Systems | |
| Aug 6, 2026 | Not specified | Popular NPM Packages Hijacked with New Shai-Hulud Malware | |
| Aug 6, 2026 | Frey Wille (AT) | Cyberattack on jewelry retailer Frey Wille | |
| Aug 6, 2026 | Washburn County (US) | Washburn County is experiencing a cyber attack | |
| Aug 5, 2026 | Jochu Technology Co., Ltd. (TW) | Todays Information | |
| Aug 5, 2026 | Meta (US) | Autonomous AI agent breaks out and hacks third-party systems. | |
| Aug 5, 2026 | HostDZire (IN) | Critical Service Incident – Ransomware Attack on VMware Infrastructure (Updated at 4:00 AM IST | 10:43 PM UTC) | |
| Aug 5, 2026 | Municipalité de Sithonie | Access Blocked | |
| Aug 5, 2026 | Administration cantonale des Grisons (CH) | Cyberattack on a server of the Canton of Grisons | |
| Aug 5, 2026 | Caravan.kz (KZ) | Caravan.kz was subjected to a cyberattack: the editorial office publishes an official statement | |
| Aug 5, 2026 | Zeus Wallet | Unknown Threat Actors Breached Cryptocurrency Wallet Zeus Wallet In United States On 5 August 2026 | |
| Aug 5, 2026 | Universidad Autónoma de San Luis Potosí (UASLP) (MX) | August 7, 2026 | San Luis Potosí, SLP | |
| Aug 5, 2026 | Not specified | Abuse of ScreenConnect RMM and Cloudflare Tunnels in SMOKE#SCREEN Campaign | |
| Aug 4, 2026 | The AME Group (US) | Vincennes Community School Corporation Shuts Down Servers Due to Concerns Over Technology Provider Ransomware Attack | |
| Aug 4, 2026 | Brown Health Medical Group-MA (US) | Attack exposes sensitive data. | |
| Aug 4, 2026 | North Carolina Ports (US) | Cyberattack disrupts operations at NC Ports in Wilmington, Morehead City and Charlotte | |
| Aug 4, 2026 | Not specified | What did SEP Web Extension do for you last month? August 2026 | |
| Aug 4, 2026 | Not specified | Hump Hump Locker Ransomware |
| Date | Affected org. | Details | Report |
| Aug 7, 2026 | Hitech Distribuzione Informatica S.r.l. (HTDI) (IT) | Hitech Distribuzione Informatica S.r.l. (HTDI) became a victim of a ransomware attack by Spacebears on the Aug 7, 2026. | |
| Aug 7, 2026 | Hartfiel Automation (DE) | Hartfiel Automation became a victim of a ransomware attack by Thegentlemen on the Aug 7, 2026. | |
| Aug 7, 2026 | Astro Electroplating (US) | Astro Electroplating became a victim of a ransomware attack by Qilin on the Aug 7, 2026. | |
| Aug 7, 2026 | Filtronic (GB) | Filtronic became a victim of a ransomware attack by Qilin on the Aug 7, 2026. | |
| Aug 7, 2026 | EISNER ZT GMBH (AT) | EISNER ZT GMBH became a victim of a ransomware attack by Qilin on the Aug 7, 2026. | |
| Aug 7, 2026 | John C Saunders CPA (US) | John C Saunders, CPA became a victim of a ransomware attack by Qilin on the Aug 7, 2026. | |
| Aug 7, 2026 | Nikan Awasisak Agency (CA) | Nikan Awasisak Agency became a victim of a ransomware attack by Qilin on the Aug 7, 2026. | |
| Aug 7, 2026 | Depona (SE) | Depona became a victim of a ransomware attack by Qilin on the Aug 7, 2026. | |
| Aug 7, 2026 | CONTINENTAL.AERO (US) | CONTINENTAL.AERO became a victim of a ransomware attack by Clop on the Aug 7, 2026. | |
| Aug 7, 2026 | MINDRAY.COM (CN) | MINDRAY.COM became a victim of a ransomware attack by Clop on the Aug 7, 2026. | |
| Aug 7, 2026 | ATMS (IN) | ATMS became a victim of a ransomware attack by Incransom on the Aug 7, 2026. | |
| Aug 7, 2026 | Venture Logistics | Venture Logistics became a victim of a ransomware attack by Helix on the Aug 7, 2026. | |
| Aug 7, 2026 | Uber (US) | Uber became a victim of a ransomware attack by Helix on the Aug 7, 2026. | |
| Aug 7, 2026 | Highwoods Properties (US) | Highwoods Properties became a victim of a ransomware attack by Helix on the Aug 7, 2026. | |
| Aug 7, 2026 | Morguard (US) | Morguard became a victim of a ransomware attack by Helix on the Aug 7, 2026. | |
| Aug 7, 2026 | Westland Insurance (CA) | Westland Insurance became a victim of a ransomware attack by Helix on the Aug 7, 2026. | |
| Aug 7, 2026 | reflet2000.fr (FR) | reflet2000.fr became a victim of a ransomware attack by Krybit on the Aug 7, 2026. | |
| Aug 7, 2026 | www.actini.com (FR) | www.actini.com became a victim of a ransomware attack by Krybit on the Aug 7, 2026. | |
| Aug 7, 2026 | www.ernat-bureau-etudes.fr (FR) | www.ernat-bureau-etudes.fr became a victim of a ransomware attack by Krybit on the Aug 7, 2026. | |
| Aug 7, 2026 | www.serengetiestates.co.za (ZA) | www.serengetiestates.co.za became a victim of a ransomware attack by Krybit on the Aug 7, 2026. |
|
|
Vallanx operates an AI-powered reporting & detection system for capturing cyber security incidents. Additional information on cyber attacks comes from a wide variety of sources. These include analyses from our own security and monitoring systems, which we operate for companies and organizations around the world. Furthermore, information from news portals, press agencies, publications from government agencies and authorities, etc. is incorporated. In addition, closed and OSINT sources are used for evaluation and verification, as well as direct reports from companies.
|
Which use case do you want to implement? Talk to us. We are happy to answer your initial questions about Cyber Security & Compliance for your company! |