CVE-2026-12569 — PTC Windchill and FlexPLM: Improper Input Validation | CVSS 9.3 CRITICAL

CRITICAL

CVSS 9.3 CRITICAL  ·  EPSS 0%  ·  PTC Windchill and FlexPLM

Read more

Detection Playbook: Rundll32 (T1218.011)

T1218.011 · 2026-06-25 Rundll32 Stealth Windows MITRE ATT&CK → Technique Rundll32 (T1218.011) Tactic Stealth Platforms Windows Overview Rundll32.exe is a legitimate Windows utility designed to load and execute functions exported from DLL files. Attackers abuse it to execute malicious payloads — including DLLs, Control Panel items (.cpl), JavaScript, and remote scripts — while hiding behind … Read more

Threat Intelligence Report — June 24, 2026 | 5 New KEVs · 168 Victims

Report Date: 2026-06-24

New KEVs: 5  ▲ +5 vs last weekRansomware Victims: 168  ▼ -19 vs last week

5 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. Ubiquiti products show the strongest concentration of risk signals this week. Ransomware activity is moderate with 168 new victims posted to leak sites over the last 7 days, with Lockbit5 posting the most victims.

Read more

Detection Playbook: Pass the Hash (T1550.002)

T1550.002 · 2026-06-24 Pass the Hash Lateral Movement Windows MITRE ATT&CK → Technique Pass the Hash (T1550.002) Tactic Lateral Movement Platforms Windows Overview Pass the Hash (PtH) is a credential-based lateral movement technique where an attacker uses a captured NTLM password hash — rather than the plaintext password — to authenticate to remote systems. Because … Read more

Threat Intelligence Report — June 23, 2026 | 5 New KEVs · 165 Victims

Report Date: 2026-06-23

New KEVs: 5  — unchanged vs last weekRansomware Victims: 165  ▼ -39 vs last week

5 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. Ubiquiti products show the strongest concentration of risk signals this week. Ransomware activity is moderate with 165 new victims posted to leak sites over the last 7 days, with Lockbit5 posting the most victims.

Read more

CVE-2026-34908 — Ubiquiti UniFi OS | CVSS 10.0 CRITICAL

CRITICAL

CVSS 10.0 CRITICAL  ·  EPSS 1%  ·  Ubiquiti UniFi OS

Read more

CVE-2026-34909 — Ubiquiti UniFi OS: Path Traversal | CVSS 10.0 CRITICAL

CRITICAL

CVSS 10.0 CRITICAL  ·  EPSS 1%  ·  Ubiquiti UniFi OS

Read more

CVE-2026-34910 — Ubiquiti UniFi OS: Improper Input Validation | CVSS 10.0 CRITICAL

CRITICAL

CVSS 10.0 CRITICAL  ·  EPSS 34%  ·  Ubiquiti UniFi OS

Read more

CVE-2025-67038 — Lantronix EDS5000: Code Injection | CVSS 9.8 CRITICAL

CRITICAL

CVSS 9.8 CRITICAL  ·  EPSS 0%  ·  Lantronix EDS5000

Read more

Detection Playbook: Kerberoasting (T1558.003)

T1558.003 · 2026-06-23 Kerberoasting Credential Access Windows MITRE ATT&CK → Technique Kerberoasting (T1558.003) Tactic Credential Access Platforms Windows Overview Kerberoasting is a credential theft technique in which an attacker with any valid domain account requests Kerberos Ticket-Granting Service (TGS) tickets for accounts that have Service Principal Names (SPNs) registered. Because portions of these tickets are … Read more