Vallanx

Vallanx Cyber Threat Monitor
Your central hub for security-relevant information

In the Cyber Threat Monitor you will find continuously updated, daily information on threat actors, vulnerabilities & exploits, and recent incidents. In addition, the Cyber Threat Monitor provides a current risk assessment by country for a total of 12 sectors. The risk ratings are composed of factors from current cyber security & threat intelligence.

The Cyber Threat Monitor is available in the dashboard and on the website in the desktop version.

Current cyber risk level per country for

Real-time analysis for week 32/2026

The Cyber Threat Indicator reflects the weekly updated risk value for each country, broken down by sector.

The risk models are continuously calculated based on current cyber threat indicators.

For more information on the individual categories on the left, simply click on the category name.

Common Vulnerabilities & Exploits

990 new vulnerabilities in the last 24 hours

Date CVE ID Severity Info Report
Aug 6, 2026 CVE-2026-71327
Kubernetes
GitHub
CURL
TCP
HashiCorp
Linux
Traefik: Gateway API route identity collision allows cross-namespace backend hijacking
Open details
Aug 6, 2026 CVE-2026-54764
GitHub
CURL
Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false
Open details
Aug 6, 2026 CVE-2026-71325
Kubernetes
TCP
BIND
GitHub
Pods
Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef
Open details
Aug 6, 2026 CVE-2026-54765
Kubernetes
GitHub
Xiaomi
Versa
Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port
Open details
Aug 6, 2026 CVE-2026-67309
Kubernetes
Ingress
Nginx
GitHub
NeXT
Linux
Node.js
JavaScript
CURL
Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass
Open details
Aug 6, 2026 CVE-2026-65600
GitHub
Flask
Django
ASP.NET
Docker
CURL
JavaScript
Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware
Open details
Aug 6, 2026 CVE-2026-54763
GitHub
PHP
Nginx
Java
Scheme
Ingress
CURL
Docker
Node.js
Apache
HTML
Anthropic
Claude
Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in...
Open details
Aug 6, 2026 GHSA-pwwh-3685-58r7 CVE-2026-61466
Apache
OAuth2
In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist. This could lead to a client self-assigning privileged scopes at registration time. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
Open details
Aug 6, 2026 CVE-2026-65520 GHSA-75cj-86wv-m74j
SQL
OAuth
Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.
Open details
Aug 6, 2026 CVE-2026-65571 GHSA-98qj-xx3j-73qx
PHP
Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.
Open details
Aug 6, 2026 GHSA-vwq7-f8p8-h8fh CVE-2026-65576
PHP
Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.
Open details
Aug 6, 2026 blt33433fe9bdc7e443_en-us
NPM
JavaScript
GitHub
AWS
Kubernetes
HashiCorp Vault
CURL
Popular NPM Packages Hijacked with New Shai-Hulud Malware
Open details
Aug 6, 2026 CVE-2026-68750
HTML
Inefficient Algorithmic Complexity vulnerability in the traversal engine in rrrene html_sanitize_ex allows an unauthenticated...
Open details
Aug 6, 2026 CVE-2026-68749
HTML
Inefficient Regular Expression Complexity vulnerability in the CSS scrubber in rrrene html_sanitize_ex allows an unauthentica...
Open details
Aug 6, 2026 CVE-2026-68747
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in the CSS s...
Open details
Aug 6, 2026 CVE-2026-66843
HTML
JavaScript
Origin
Inclusion of Functionality from Untrusted Control Sphere vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allow...
Open details
Aug 6, 2026 CVE-2026-66829
Redirection
HTML
JavaScript
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a r...
Open details
Aug 6, 2026 CVE-2026-66370
Redirection
HTML
Scheme
Origin
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows an ...
Open details
Aug 6, 2026 CVE-2026-5423
Neo4j
JWT
@neo4j/graphql library versions prior to 7.5.6 fail to verify the authenticity of a client-supplied, pre-decoded JWT object p...
Open details
Aug 6, 2026 CVE-2026-53985
Docker
Ground Station prior to 0.6.0 contains an unauthenticated denial-of-service vulnerability in the Socket.IO server's service_c...
Open details

Current cyber attacks in the last 14 days

107 documented cases in the past two weeks

Date Affected services Details Report
Aug 7, 2026 Not specified Vanta Stealer
Open report
Aug 7, 2026 Not specified Greatness PhaaS Campaigns Continue
Open report
Aug 7, 2026 Not specified Fake CAPTCHA Prompts Leverage ClickFix Tactics to Infect macOS Systems
Open report
Aug 6, 2026 Not specified Popular NPM Packages Hijacked with New Shai-Hulud Malware
Open report
Aug 6, 2026 Frey Wille (AT) Cyberattack on jewelry retailer Frey Wille
Open report
Aug 6, 2026 Washburn County (US) Washburn County is experiencing a cyber attack
Open report
Aug 5, 2026 Jochu Technology Co., Ltd. (TW) Todays Information
Open report
Aug 5, 2026 Meta (US) Autonomous AI agent breaks out and hacks third-party systems.
Open report
Aug 5, 2026 HostDZire (IN) Critical Service Incident – Ransomware Attack on VMware Infrastructure (Updated at 4:00 AM IST | 10:43 PM UTC)
Open report
Aug 5, 2026 Municipalité de Sithonie Access Blocked
Open report
Aug 5, 2026 Administration cantonale des Grisons (CH) Cyberattack on a server of the Canton of Grisons
Open report
Aug 5, 2026 Caravan.kz (KZ) Caravan.kz was subjected to a cyberattack: the editorial office publishes an official statement
Open report
Aug 5, 2026 Zeus Wallet Unknown Threat Actors Breached Cryptocurrency Wallet Zeus Wallet In United States On 5 August 2026
Open report
Aug 5, 2026 Universidad Autónoma de San Luis Potosí (UASLP) (MX) August 7, 2026 | San Luis Potosí, SLP
Open report
Aug 5, 2026 Not specified Abuse of ScreenConnect RMM and Cloudflare Tunnels in SMOKE#SCREEN Campaign
Open report
Aug 4, 2026 The AME Group (US) Vincennes Community School Corporation Shuts Down Servers Due to Concerns Over Technology Provider Ransomware Attack
Open report
Aug 4, 2026 Brown Health Medical Group-MA (US) Attack exposes sensitive data.
Open report
Aug 4, 2026 North Carolina Ports (US) Cyberattack disrupts operations at NC Ports in Wilmington, Morehead City and Charlotte
Open report
Aug 4, 2026 Not specified What did SEP Web Extension do for you last month? August 2026
Open report
Aug 4, 2026 Not specified Hump Hump Locker Ransomware
Open report

Current ransomware attacks

82 registered incidents in the last 48 hours

Date Affected org. Details Report
Aug 7, 2026 Hitech Distribuzione Informatica S.r.l. (HTDI) (IT) Hitech Distribuzione Informatica S.r.l. (HTDI) became a victim of a ransomware attack by Spacebears on the Aug 7, 2026.
Open report
Aug 7, 2026 Hartfiel Automation (DE) Hartfiel Automation became a victim of a ransomware attack by Thegentlemen on the Aug 7, 2026.
Open report
Aug 7, 2026 Astro Electroplating (US) Astro Electroplating became a victim of a ransomware attack by Qilin on the Aug 7, 2026.
Open report
Aug 7, 2026 Filtronic (GB) Filtronic became a victim of a ransomware attack by Qilin on the Aug 7, 2026.
Open report
Aug 7, 2026 EISNER ZT GMBH (AT) EISNER ZT GMBH became a victim of a ransomware attack by Qilin on the Aug 7, 2026.
Open report
Aug 7, 2026 John C Saunders CPA (US) John C Saunders, CPA became a victim of a ransomware attack by Qilin on the Aug 7, 2026.
Open report
Aug 7, 2026 Nikan Awasisak Agency (CA) Nikan Awasisak Agency became a victim of a ransomware attack by Qilin on the Aug 7, 2026.
Open report
Aug 7, 2026 Depona (SE) Depona became a victim of a ransomware attack by Qilin on the Aug 7, 2026.
Open report
Aug 7, 2026 CONTINENTAL.AERO (US) CONTINENTAL.AERO became a victim of a ransomware attack by Clop on the Aug 7, 2026.
Open report
Aug 7, 2026 MINDRAY.COM (CN) MINDRAY.COM became a victim of a ransomware attack by Clop on the Aug 7, 2026.
Open report
Aug 7, 2026 ATMS (IN) ATMS became a victim of a ransomware attack by Incransom on the Aug 7, 2026.
Open report
Aug 7, 2026 Venture Logistics Venture Logistics became a victim of a ransomware attack by Helix on the Aug 7, 2026.
Open report
Aug 7, 2026 Uber (US) Uber became a victim of a ransomware attack by Helix on the Aug 7, 2026.
Open report
Aug 7, 2026 Highwoods Properties (US) Highwoods Properties became a victim of a ransomware attack by Helix on the Aug 7, 2026.
Open report
Aug 7, 2026 Morguard (US) Morguard became a victim of a ransomware attack by Helix on the Aug 7, 2026.
Open report
Aug 7, 2026 Westland Insurance (CA) Westland Insurance became a victim of a ransomware attack by Helix on the Aug 7, 2026.
Open report
Aug 7, 2026 reflet2000.fr (FR) reflet2000.fr became a victim of a ransomware attack by Krybit on the Aug 7, 2026.
Open report
Aug 7, 2026 www.actini.com (FR) www.actini.com became a victim of a ransomware attack by Krybit on the Aug 7, 2026.
Open report
Aug 7, 2026 www.ernat-bureau-etudes.fr (FR) www.ernat-bureau-etudes.fr became a victim of a ransomware attack by Krybit on the Aug 7, 2026.
Open report
Aug 7, 2026 www.serengetiestates.co.za (ZA) www.serengetiestates.co.za became a victim of a ransomware attack by Krybit on the Aug 7, 2026.
Open report

Information about Threat Actors, APT & Cyber Crime Groups

Current Database: 1.494 Groups at Aug 7, 2026


Fetching Profile ...

Where does the data come from?

Vallanx operates an AI-powered reporting & detection system for capturing cyber security incidents. Additional information on cyber attacks comes from a wide variety of sources. These include analyses from our own security and monitoring systems, which we operate for companies and organizations around the world. Furthermore, information from news portals, press agencies, publications from government agencies and authorities, etc. is incorporated. In addition, closed and OSINT sources are used for evaluation and verification, as well as direct reports from companies.

Sources of Cyber Threat Monitoring

Title Title
Al Jazeera https://www.aljazeera.com
Arab News https://www.arabnews.com/
ArsTechnica https://arstechnica.com/
Associated Press https://apnews.com/
Avast Threat Labs https://decoded.avast.io/
Basic Thinking https://www.basicthinking.de/
BBC https://www.bbc.com
Beobachter https://www.beobachter.ch/
Berliner Zeitung https://www.berliner-zeitung.de/
BlackBerry https://blogs.blackberry.com/
Bleeping Computer https://www.bleepingcomputer.com/
Blocks & Files https://blocksandfiles.com/?
Bloomberg https://bloomberg.com
Brisbane Times https://www.brisbanetimes.com.au
Brookings https://www.brookings.edu
Business Insider (DE) https://www.businessinsider.de
Business Insider (EN) https://www.businessinsider.com
Buzzfeed https://www.buzzfeednews.com
C4ISR https://www.c4isrnet.com/
Canberra Times https://www.canberratimes.com.au/
CBC Canada https://www.cbc.ca/
CBS News https://www.cbsnews.com
Channel News Asia https://www.channelnewsasia.com/
Chip.de https://www.chip.de
CISA ICS Alerts https://www.cisa.gov/
Cisco Talos Intelligence Group https://talosintelligence.com/
Cisco https://blogs.cisco.com/
CNBC https://www.cnbc.com
CNET https://www.cnet.com/
CNN https://www.cnn.com
Common Vulnerability Scoring System (CVSS) https://www.first.org/cvss/
Computer Bild https://www.computerbild.de/
Computer World https://www.computerworld.com/
ComputerWeekly.com https://www.computerweekly.com
Corriere della Serra https://www.corriere.it/esteri/
CriminalIP https://www.criminalip.io/
CVE Details https://www.cvedetails.com/
Cybereason https://www.cybereason.com/blog/rss.xml
CyberGeeks https://cybergeeks.tech/
CyberScoop https://www.cyberscoop.com/
CybersecAsia https://www.cybersecasia.net/news/feed/
Cybersecurity Insiders https://www.cybersecurity-insiders.com
Cynber Security News https://cybersecuritynews.com/?wd=ad
Cyble https://www.cyble.com/?/
Daily Record EU https://eu.dailyrecord.com
Dark Reading https://www.darkreading.com/
DataBreaches https://www.databreaches.net/feed/
Decode39 https://decode39.com/
Defense One https://www.defenseone.com/
Der Standard https://www.derstandard.at/
Der Tagesspiegel https://plana-beratung.de/profil/
Deutschlandfunk https://www.deutschlandfunk.de/
Die Welt https://www.welt.de/
DPA International https://dpa-international.com
Dragos https://www.dragos.com/
Economic Times India CIO https://cio.economictimes.indiatimes.com/
Economic Times India Telecom https://telecom.economictimes.indiatimes.com/
Economist https://www.economist.com
Eesti Päevaleht https://epl.delfi.ee/
EFF Deeplinks https://www.eff.org/
El Mundo https://www.elmundo.es/
El Pais https://elpais.com/
Euractiv https://www.euractiv.com/
Euro News https://www.euronews.com/
Euro topics https://www.eurotopics.net/
Exploit Database https://www.exploit-db.com/
F5 Labs Threats https://www.f5.com/
Financial Times https://www.ft.com
Forbes https://www.forbes.com
Fortiguard https://www.fortiguard.com/
Fortune https://fortune.com/
Fox Business https://www.foxbusiness.com
Fox News https://www.foxnews.com
FoxIT https://blog.fox-it.com/
Frankfurter Allgemeine Zeitung https://www.faz.net/
Gazeta Wyborcza https://wyborcza.pl/
Gdata https://www.gdata.de/
GitHub https://github.com/
Golem https://www.golem.de/
Google Threat Analysis Group https://blog.google/threat-analysis-group/rss/
GovInfo Security https://www.govinfosecurity.com
Group-IB https://blog.group-ib.com/
Haaretz News https://www.haaretz.com/
Hacker News https://news.ycombinator.com/
Hackread https://www.hackread.com/
Handelsblatt Online https://www.handelsblatt.com/
Heise https://www.heise.de/
Help Net Security https://www.helpnetsecurity.com
Huffington Post https://www.huffingtonpost.com
Human Rights Watch https://www.hrw.org/publications
IBM X-Force Exchange https://exchange.xforce.ibmcloud.com/
Indian Express https://indianexpress.com/about/cyber-security/
Infosecurity Magazine https://www.infosecurity-magazine.com
Insight Crime https://insightcrime.org/news/
International Business Times https://www.ibtimes.com
Internet World Business https://www.internetworld.de/
Intrusion Truth https://intrusiontruth.wordpress.com/
IronNet https://www.ironnet.com/blog/tag/threat-research
Japan Times https://www.japantimes.co.jp
Jerusalem Post https://www.jpost.com/
Just Security https://www.justsecurity.org
Jylands Posten https://jyllands-posten.dk/
Kaspersky Threat Intelligence Portal https://opentip.kaspersky.com/
Kleine Zeitung https://www.kleinezeitung.at/
Krebs on Security https://krebsonsecurity.com
Kurier.at https://www.kurier.at
La Repubblica https://www.repubblica.it/
La Stampa https://www.lastampa.it/
LA Times https://www.latimes.com
La Vanguardia https://www.lavanguardia.com/
Lawfare Blog https://www.lawfareblog.com/
Le Figaro https://www.lefigaro.fr/
Le Monde https://www.lemonde.fr
Les Echos https://www.lesechos.fr
LookingGlass https://lookingglasscyber.com/
Malwarebytes Labs https://blog.malwarebytes.com/feed/
Mandiant Resources Blog https://www.mandiant.com/
Microsoft On the Issues https://blogs.microsoft.com/on-the-issues/
Microsoft Security https://www.microsoft.com/
MIT Technology Review https://www.technologyreview.com/
MITRE CVE https://cve.mitre.org/
n-tv https://www.n-tv.de/
Naked Security https://www.nakedsecurity.sophos.com
National Vulnerability Database (NVD) https://nvd.nist.gov/
NBC News https://www.nbcnews.com
NDR - Netzwelt https://www.ndr.de/nachrichten/netzwelt/index.html
Netzpolitik https://netzpolitik.org/
Netzwelt https://www.netzwelt.de/
Neue Zürcher Zeitung https://www.nzz.ch/
New York Times https://www.nytimes.com/
News.com https://www.news.com.au/
NPR https://www.npr.org
Open Source Vulnerability Database (OSVDB) https://www.osvdb.org/
Palo Alto Unit42 https://unit42.paloaltonetworks.com/
Politico EU https://www.politico.eu/
Politico https://www.politico.com
Politiken https://politiken.dk/
Postimees https://news.postimees.ee/
ProofPoint https://www.proofpoint.com/
QuoIntelligence https://quointelligence.eu/
Ransomware Live https://www.ransomware.live/
Rapid7 Vulnerability & Exploit Database https://www.rapid7.com/db/
ReadMe by Synack https://readme.security/
Reaqta https://reaqta.com/
Recorded Future Insikt Group https://www.recordedfuture.com/
Red Alert https://redalert.nshc.net/
Redaktionsnetzwerk Deutschland https://www.rnd.de/
Reuters https://www.reuters.com/
RFE/RL https://www.rferl.org/
RSF https://rsf.org/
Rzeczpospolita https://www.rp.pl/
SC Magazine UK https://www.scmagazineuk.com
Schneier on Security https://www.schneier.com/
Securelist by Kaspersky https://securelist.com/
Security Affairs https://securityaffairs.com/
Security Insider https://www.security-insider.de/
Security Middle East & Africa https://securitymea.com/
Security Middle East Magazine https://www.securitymiddleeastmag.com/
Security Week https://www.securityweek.com/
Security-Incidents.de https://www.security-incidents.de/sicherheitsvorfall-datenbank/
SecurityBrief Asia https://securitybrief.asia/
Securonix https://www.securonix.com/
Sentinel One Blog https://de.sentinelone.com/blog/
Sky News https://news.sky.com/
SocRadar https://socradar.io/blog/
Softpedia News https://news.softpedia.com/
South China Morning Post https://www.scmp.com
SPIEGEL Online https://www.spiegel.de/
Sydney Morning Herald https://www.smh.com.au
Symantec https://symantec-enterprise-blogs.security.com/
Süddeutsche Zeitung https://www.sueddeutsche.de/
t3n https://t3n.de/
Tagespiegel https://www.tagesspiegel.de/
Tarnkappe.info https://tarnkappe.info/
Tech Radar https://www.techradar.com/
TechCrunch https://techcrunch.com/
Technology Review https://www.technologyreview.com/
TechRepublic https://www.techrepublic.com/
The Atlantic https://www.theatlantic.com/
The Christian Science Monitor https://www.csmonitor.com/
The Cipher Brief https://www.thecipherbrief.com/
The Citizen Lab https://citizenlab.ca
The Daily Swig https://portswigger.net/
The Diplomat https://thediplomat.com/
The Guardian https://www.theguardian.com/
The Hacker News https://www.thehackernews.com
The Hill https://www.thehill.com
The Independent https://www.independent.co.uk
The Intercept https://theintercept.com
The Record https://therecord.media/
The Register https://www.theregister.com/security/cyber_crime/
The Start https://www.thestar.com.my/
The Telegraph https://www.telegraph.co.uk/
The Times UK https://www.thetimes.co.uk/
The Verge https://www.theverge.com
The Washington Post https://www.washingtonpost.com/
ThreatConnect https://threatconnect.com/
Threatpost https://threatpost.com/
Time https://time.com/
Trend Micro https://www.trendmicro.com/
Twitter https://twitter.com
USA Today Europe https://eu.usatoday.com/
USA Today https://www.usatoday.com/
Voice of America News https://www.voanews.com
Volexity https://www.volexity.com/blog/
Volkskrant https://www.volkskrant.nl
Vox https://www.vox.com
Vulners https://vulners.com/
Wall Street Journal https://www.wsj.com/
War on the Rocks https://warontherocks.com/
Washington Post https://www.washingtonpost.com
WeLiveSecurity https://www.welivesecurity.com/
Wired https://www.wired.com/
Wirtschaftswoche https://www.wiwo.de/
ZDnet https://www.zdnet.com/
ZeeNews India https://zeenews.india.com
ZEIT Online https://www.zeit.de/
DFIR Report https://thedfirreport.com/feed/
Imprint

nsakldnalksd mlasödalsdmklasmdlasm lakms ksadm klam klasm kldmaslkd m
Contact Vallanx

Which use case do you want to implement?

Talk to us. We are happy to answer your initial questions about Cyber Security & Compliance for your company!