Report a CVE or Cyber Incident
DSADASD
In the Cyber Threat Monitor you will find continuously updated, daily information on threat actors, vulnerabilities & exploits, and recent incidents. In addition, the Cyber Threat Monitor provides a current risk assessment by country for a total of 12 sectors. The risk ratings are composed of factors from current cyber security & threat intelligence.
The Cyber Threat Monitor is available in the dashboard and on the website in the desktop version.
Real-time analysis for week 38/2026
The Cyber Threat Indicator reflects the weekly updated risk value for each country, broken down by sector.
The risk models are continuously calculated based on current cyber threat indicators.
For more information on the individual categories on the left, simply click on the category name.
| Date | CVE ID | Severity | Info | Report |
| Sep 14, 2026 | CVE-2026-46696 |
October CMS: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder Calls
|
||
| Sep 14, 2026 | CVE-2026-49400 |
October CMS: PHP Object Injection via Backend Widget Session Storage
|
||
| Sep 14, 2026 | GHSA-2xmm-m4wv-3fjh |
October CMS: Incomplete Scheme Validation in Image Resizer
|
||
| Sep 14, 2026 | RUSTSEC-2026-0285 |
TLS 1.3 handshake messages incorrectly accepted across encryption level boundaries
|
||
| Sep 14, 2026 | MAL-2026-16144 |
Malicious code in app-rrhh (npm)
|
||
| Sep 14, 2026 | MAL-2026-16146 |
Malicious code in @aiwfm/communitywfm.scripts.api (npm)
|
||
| Sep 14, 2026 | MAL-2026-16147 |
Malicious code in n8n-nodes-sysdiag (npm)
|
||
| Sep 14, 2026 | MAL-2026-16153 |
Malicious code in web-main (npm)
|
||
| Sep 14, 2026 | MAL-2026-16152 |
Malicious code in strapi-plugin-os-info-meeb322k (npm)
|
||
| Sep 14, 2026 | MAL-2026-16145 |
Malicious code in concierge-sdk (npm)
|
||
| Sep 14, 2026 | MAL-2026-16149 |
Malicious code in os-info-meeb322k (npm)
|
||
| Sep 14, 2026 | MAL-2026-16148 |
Malicious code in noblox-asset.js (npm)
|
||
| Sep 14, 2026 | MAL-2026-16150 |
Malicious code in postgreesqlhelper (npm)
|
||
| Sep 14, 2026 | MAL-2026-16151 |
Malicious code in sql-limit-enforcer (npm)
|
||
| Sep 14, 2026 | CVE-2026-46696 |
|
October CMS: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder Calls
|
|
| Sep 14, 2026 | CVE-2026-49400 |
|
October CMS: PHP Object Injection via Backend Widget Session Storage
|
|
| Sep 14, 2026 | GHSA-2xmm-m4wv-3fjh |
|
October CMS: Incomplete Scheme Validation in Image Resizer
|
|
| Sep 14, 2026 | CVE-2026-59178 |
|
ESPHome Device Builder: Renamed auth env vars silently disable dashboard authentication on upgrade
|
|
| Sep 14, 2026 | CVE-2026-90957 |
|
Affected versions of MISP serve uploaded SVG images inline without a restrictive browser sandbox.
The commit explains that ...
|
|
| Sep 14, 2026 | CVE-2026-90961 |
|
The LdapAuth and LinOTPAuth authentication plugins in MISP contain an authentication bypass vulnerability. Both LdapAuthentic...
|
| Date | Affected services | Details | Report |
| Nov 18, 2026 | Paylogix (US) | Employee benefits platform Paylogix says hackers stole financial and health information. | |
| Sep 11, 2026 | Not specified | Espionage Groups Deploy BlueMoon Exploit Chain | |
| Sep 11, 2026 | DR.WU Skincare Co., Ltd. (TW) | Securities Options | |
| Sep 11, 2026 | Not specified | SloppyRAT malware | |
| Sep 11, 2026 | Machelen (BE) | Cyberattack targets services of the municipality of Machelen: “Apparently no personal data stolen” | VRT NEWS News | |
| Sep 11, 2026 | Duopharma Biotech Bhd (DPHARMA) (MY) | United Pharmaceuticals hit by a cyberattack; personal information may have been leaked | |
| Sep 11, 2026 | Kreishandwerkerschaft Borken (DE) | District craft association attacked by hackers | |
| Sep 10, 2026 | Not specified | Mantax Otax Android Malware | |
| Sep 10, 2026 | Not specified | GoldFactory threat group abuses Android Work Profiles with Vwork clone tool | |
| Sep 10, 2026 | Not specified | CL-CRI-1171 cybercrime operation | |
| Sep 10, 2026 | Not specified | Telegram-beaconing VBS downloader deploys ScreenConnect RMM | |
| Sep 10, 2026 | Mississippi Institutions of Higher Learning (IHL) (US) | Mississippi public university system reports financial aid disruption | |
| Sep 9, 2026 | Not specified | MacSync Stealer deployment via ClickFix campaigns | |
| Sep 9, 2026 | Le Tampon (FR) | www.linfo.re | |
| Sep 9, 2026 | Stadtverwaltung von Le Tampon (FR) | Cyberattack significantly affects several municipal services. | |
| Sep 9, 2026 | Surfshark (NL) | Configuration error exploited: hackers access internal data. | |
| Sep 9, 2026 | Veradigm (US) | A ransomware group steals millions of patients’ data through third-party providers. | |
| Sep 9, 2026 | Port of Tanjung Pelepas (MY) | Cyber attack disrupts operations at Malaysia’s Port of Tanjung Pelepas | |
| Sep 8, 2026 | Not specified | Amatera stealer and ZigCryptoStealer among the payloads delivered in recent ClearFake WebDAV infection chain | |
| Sep 8, 2026 | Not specified | Ted backdoor and CurlRAT activities in South Korea |
| Date | Affected org. | Details | Report |
|
|
Vallanx operates an AI-powered reporting & detection system for capturing cyber security incidents. Additional information on cyber attacks comes from a wide variety of sources. These include analyses from our own security and monitoring systems, which we operate for companies and organizations around the world. Furthermore, information from news portals, press agencies, publications from government agencies and authorities, etc. is incorporated. In addition, closed and OSINT sources are used for evaluation and verification, as well as direct reports from companies.
|
Which use case do you want to implement? Talk to us. We are happy to answer your initial questions about Cyber Security & Compliance for your company! |