CVE-2026-48939 — iCagenda iCagenda: Unrestricted File Upload | CVSS 10.0 CRITICAL

CRITICAL

CVSS 10.0 CRITICAL  ·  EPSS 1%  ·  iCagenda iCagenda

Read more

CVE-2026-56291 — Balbooa Forms: Unrestricted File Upload | CVSS 10.0 CRITICAL

CRITICAL

CVSS 10.0 CRITICAL  ·  EPSS 0%  ·  Balbooa Forms

Read more

Detection Playbook: Service Stop (T1489)

T1489 · 2026-07-10 Service Stop Impact ESXi IaaS Linux macOS MITRE ATT&CK → Technique Service Stop (T1489) Tactic Impact Platforms ESXi, IaaS, Linux, macOS, Windows Overview Service Stop (T1489) is a technique where adversaries deliberately halt or disable running services on a target system to prevent legitimate users from accessing them or to enable follow-on … Read more

Threat Intelligence Report — July 9, 2026 | 4 New KEVs · 127 Victims

Report Date: 2026-07-09

New KEVs: 4  ▲ +2 vs last weekRansomware Victims: 127  ▼ -75 vs last week

4 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. Joomlack products show the strongest concentration of risk signals this week. Ransomware activity is moderate with 127 new victims posted to leak sites over the last 7 days, with Qilin posting the most victims.

Read more

Detection Playbook: Inhibit System Recovery (T1490)

T1490 · 2026-07-09 Inhibit System Recovery Impact Containers ESXi IaaS Linux MITRE ATT&CK → Technique Inhibit System Recovery (T1490) Tactic Impact Platforms Containers, ESXi, IaaS, Linux, macOS, Network Devices, Windows Overview Inhibit System Recovery (T1490) describes adversary actions taken to delete, disable, or corrupt the built-in recovery mechanisms of an operating system or platform — … Read more

Threat Intelligence Report — July 8, 2026 | 4 New KEVs · 133 Victims

Report Date: 2026-07-08

New KEVs: 4  — unchanged vs last weekRansomware Victims: 133  ▼ -12 vs last week

4 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. Adobe products show the strongest concentration of risk signals this week. Ransomware activity is moderate with 133 new victims posted to leak sites over the last 7 days, with Thegentlemen posting the most victims.

Read more

Detection Playbook: Data Encrypted for Impact (T1486)

T1486 · 2026-07-08 Data Encrypted for Impact Impact ESXi IaaS Linux macOS MITRE ATT&CK → Technique Data Encrypted for Impact (T1486) Tactic Impact Platforms ESXi, IaaS, Linux, macOS, Windows Overview Data Encrypted for Impact (T1486) describes adversary activity where files, drives, or entire systems are encrypted to deny the victim access to their own data. … Read more

Threat Intelligence Report — July 7, 2026 | 5 New KEVs · 209 Victims

Report Date: 2026-07-07

New KEVs: 5  ▲ +2 vs last weekRansomware Victims: 209  ▲ +78 vs last week

5 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. Joomshaper products show the strongest concentration of risk signals this week. Ransomware activity is moderate with 209 new victims posted to leak sites over the last 7 days, with Thegentlemen posting the most victims.

Read more

CVE-2026-48282 — Adobe ColdFusion: Path Traversal | CVSS 10.0 CRITICAL

CRITICAL

CVSS 10.0 CRITICAL  ·  EPSS 1%  ·  Adobe ColdFusion

Read more

CVE-2026-56290 — Joomlack Page Builder: Unrestricted File Upload | CVSS 10.0 CRITICAL

CRITICAL

CVSS 10.0 CRITICAL  ·  EPSS 0%  ·  Joomlack Page Builder

Read more