Report a CVE or Cyber Incident
DSADASD
In the Cyber Threat Monitor you will find continuously updated, daily information on threat actors, vulnerabilities & exploits, and recent incidents. In addition, the Cyber Threat Monitor provides a current risk assessment by country for a total of 12 sectors. The risk ratings are composed of factors from current cyber security & threat intelligence.
The Cyber Threat Monitor is available in the dashboard and on the website in the desktop version.
Real-time analysis for week 33/2026
The Cyber Threat Indicator reflects the weekly updated risk value for each country, broken down by sector.
The risk models are continuously calculated based on current cyber threat indicators.
For more information on the individual categories on the left, simply click on the category name.
| Date | CVE ID | Severity | Info | Report |
| Aug 14, 2026 | CVE-2026-72811 |
|
SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backlink.g...
|
|
| Aug 14, 2026 | CVE-2026-72810 |
|
SiYuan versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket broadcast sessions that allows ano...
|
|
| Aug 14, 2026 | CVE-2026-19822 |
|
A vulnerability was identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. This issue affects the function lstAdd of the f...
|
|
| Aug 14, 2026 | CVE-2025-71405 |
|
chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware function that uses the Ho...
|
|
| Aug 14, 2026 | MAL-2026-14019 |
Malicious code in fr-ito-web-react (npm)
|
||
| Aug 14, 2026 | GHSA-xqxv-q9jf-7cwc CVE-2026-12949 |
|
The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authenticity in versions up to and including 3.34.1. This is due to the wpm_register() function validating the registration cookie only against the GET reg parameter while accepting the POST mergewith and POST wpm_id parameters without verifying that the mergewith user ID references a temporary or incomplete registrant that is bound to the current registration transaction. This makes it possible for unauthenticated attackers to take over any existing WordPress account — including administrator accounts — by supplying an arbitrary user's numeric ID as the mergewith value, which causes wp_update_user() to overwrite the target account's username (additionally written via a direct $wpdb UPDATE), password, email address, first name, and last name with attacker-controlled values, while WordPress password and email change notification emails are explicitly suppressed. When wpm_id references a non-existent membership level, no role key is added to the update payload, causing wp_update_user() to preserve the target user's existing role — including administrator — making full privilege escalation a direct consequence of the takeover.
|
|
| Aug 14, 2026 | blt3115727cfa4d6923_en-us |
WindRelay and SpyNote Drive NFC Fraud
|
||
| Aug 14, 2026 | blt71cfff5729639c2d_en-us |
GhostDesk via Fake Softwares
|
||
| Aug 14, 2026 | blt7f934daa28b73b01_en-us |
PATCHCORD Malware Cluster Targets Telecom and Critical Infrastructure
|
||
| Aug 14, 2026 | CVE-2026-19821 |
|
A vulnerability was determined in Tenda AC12 15.03.06.23_multi_TD01. This vulnerability affects the function formSetRebootTim...
|
|
| Aug 14, 2026 | CVE-2026-19815 |
|
A flaw has been found in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected by this vulnerability is the function setParentalRul...
|
|
| Aug 14, 2026 | CVE-2026-19814 |
|
A vulnerability was detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setMacQos of the file /cgi-bi...
|
|
| Aug 14, 2026 | CVE-2026-19813 |
|
A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setMacFilterRu...
|
|
| Aug 14, 2026 | CVE-2026-19812 |
|
A weakness has been identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function UploadCustomModule of the ...
|
|
| Aug 14, 2026 | CVE-2026-19794 |
|
The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.56 due...
|
|
| Aug 14, 2026 | CVE-2026-19811 |
|
A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setIpQosRu...
|
|
| Aug 14, 2026 | CVE-2026-12949 |
|
The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authenticity in versions up to and including 3.34.1. This is due to the wpm_register() function validating the registration cookie only against the GET reg parameter while accepting the POST mergewith and POST wpm_id parameters without verifying that the mergewith user ID references a temporary or incomplete registrant that is bound to the current registration transaction. This makes it possible for unauthenticated attackers to take over any existing WordPress account — including administrator accounts — by supplying an arbitrary user's numeric ID as the mergewith value, which causes wp_update_user() to overwrite the target account's username (additionally written via a direct $wpdb UPDATE), password, email address, first name, and last name with attacker-controlled values, while WordPress password and email change notification emails are explicitly suppressed. When wpm_id references a non-existent membership level, no role key is added to the update payload, causing wp_update_user() to preserve the target user's existing role — including administrator — making full privilege escalation a direct consequence of the takeover.
|
|
| Aug 14, 2026 | CVE-2026-19617 |
|
A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with ...
|
|
| Aug 14, 2026 | CVE-2026-18039 |
|
The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields from ove...
|
|
| Aug 14, 2026 | CVE-2026-16810 |
|
The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is vulner...
|
| Date | Affected services | Details | Report |
| Aug 14, 2026 | Not specified | PATCHCORD Malware Cluster Targets Telecom and Critical Infrastructure | |
| Aug 14, 2026 | Not specified | GhostDesk via Fake Softwares | |
| Aug 14, 2026 | Not specified | WindRelay and SpyNote Drive NFC Fraud | |
| Aug 14, 2026 | Beacon (UK) | A compromised AWS key exposes data from organizations. | |
| Aug 14, 2026 | Shell (UK) | The CL0P group steals 89 GB of data through a software vulnerability. | |
| Aug 14, 2026 | Not specified | Project CAV3RN abuses trusted Google infrastructure for resilient espionage | |
| Aug 13, 2026 | Not specified | Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side | |
| Aug 13, 2026 | Not specified | Sandworm-Linked Group Uses Fake Job Interviews to Deploy Trojanized WireGuard Client | |
| Aug 13, 2026 | Trezor (WW) | Supply-chain attack on logistics partner exposes data of 14,000 customers. | |
| Aug 12, 2026 | Not specified | Aeternum Botnet | |
| Aug 12, 2026 | Not specified | Gunra Ransomware expands its operations | |
| Aug 12, 2026 | Not specified | A new variant of the Kimwolf botnet identified in the wild | |
| Aug 12, 2026 | Not specified | Chaos Malware Variant Targeting Linux Cloud Infrastructure | |
| Aug 12, 2026 | Berri AI (WW) | Terabytes of access data compromised through a supply-chain attack on LightLLM. | |
| Aug 12, 2026 | Threema (CH) | Messaging service repeatedly brought down again and again by DDoS attacks. | |
| Aug 11, 2026 | Not specified | DeadLock Ransomware Combines Resource-Aware Encryption with Resilient Extortion Protocols | |
| Aug 11, 2026 | Ágape Consultoria (BR) | The City Hall and Chamber of Vila Pavão are affected by a hacker attack that took down portals in Espírito Santo. | |
| Aug 11, 2026 | CH BIOTECH R&D CO., LTD. (TW) | Todays Information | |
| Aug 11, 2026 | Bloctel (FR) | Cybercriminals Stole 3 Million Phone Numbers From French Government Anti-Telemarketing List Bloctel On 11 August 2026 | |
| Aug 11, 2026 | Darlington County (US) | Darlington County, South Carolina, takes systems offline after cybersecurity incident |
| Date | Affected org. | Details | Report |
| Aug 14, 2026 | granjarinya.com (ES) | granjarinya.com became a victim of a ransomware attack by Safepay on the Aug 14, 2026. | |
| Aug 14, 2026 | Columbia University Information (Dental) (US) | Columbia University Information (Dental) became a victim of a ransomware attack by Global Secret Group on the Aug 14, 2026. | |
| Aug 14, 2026 | Connections (BE) | Connections became a victim of a ransomware attack by Qilin on the Aug 14, 2026. | |
| Aug 14, 2026 | Connell Enterprises LLC (US) | Connell Enterprises LLC became a victim of a ransomware attack by Interlock on the Aug 14, 2026. | |
| Aug 14, 2026 | Turner and Townsend (GB) | Turner and Townsend became a victim of a ransomware attack by Coinbasecartel on the Aug 14, 2026. | |
| Aug 14, 2026 | Serruya private equity (US) | Serruya private equity became a victim of a ransomware attack by Coinbasecartel on the Aug 14, 2026. | |
| Aug 14, 2026 | Sweet Water Holdings (US) | Sweet Water Holdings became a victim of a ransomware attack by Coinbasecartel on the Aug 14, 2026. | |
| Aug 14, 2026 | Keystops (US) | Keystops became a victim of a ransomware attack by Akira on the Aug 14, 2026. | |
| Aug 14, 2026 | Cozad Asset Management (US) | Cozad Asset Management became a victim of a ransomware attack by Akira on the Aug 14, 2026. | |
| Aug 14, 2026 | Aletex Group (ES) | Aletex Group became a victim of a ransomware attack by Qilin on the Aug 14, 2026. | |
| Aug 14, 2026 | Pierce Township (US) | Pierce Township became a victim of a ransomware attack by Rhysida on the Aug 14, 2026. | |
| Aug 14, 2026 | Radiant (SG) | Radiant became a victim of a ransomware attack by Qilin on the Aug 14, 2026. | |
| Aug 14, 2026 | ZEBRA.COM (US) | ZEBRA.COM became a victim of a ransomware attack by Clop on the Aug 14, 2026. | |
| Aug 14, 2026 | Lercher Werkzeugbau (AT) | Lercher Werkzeugbau became a victim of a ransomware attack by Qilin on the Aug 14, 2026. | |
| Aug 14, 2026 | 3f (DK) | 3f became a victim of a ransomware attack by Qilin on the Aug 14, 2026. | |
| Aug 14, 2026 | PenLink (US) | PenLink became a victim of a ransomware attack by Qilin on the Aug 14, 2026. | |
| Aug 14, 2026 | Urban Worldwide (NL) | Urban Worldwide became a victim of a ransomware attack by Qilin on the Aug 14, 2026. | |
| Aug 14, 2026 | tecnoabi.com (BR) | tecnoabi.com became a victim of a ransomware attack by M3rx on the Aug 14, 2026. | |
| Aug 14, 2026 | Cook Medical LLC (US) | Cook Medical LLC became a victim of a ransomware attack by Shinyhunters on the Aug 14, 2026. | |
| Aug 14, 2026 | Gravity Coffee (US) | Gravity Coffee became a victim of a ransomware attack by Thegentlemen on the Aug 14, 2026. |
|
|
Vallanx operates an AI-powered reporting & detection system for capturing cyber security incidents. Additional information on cyber attacks comes from a wide variety of sources. These include analyses from our own security and monitoring systems, which we operate for companies and organizations around the world. Furthermore, information from news portals, press agencies, publications from government agencies and authorities, etc. is incorporated. In addition, closed and OSINT sources are used for evaluation and verification, as well as direct reports from companies.
|
Which use case do you want to implement? Talk to us. We are happy to answer your initial questions about Cyber Security & Compliance for your company! |