TF-1868507 |
Unknown malware: Domain name that delivers a malware payload borrilkapi4422.icu |
high |
Unknown malware |
2 |
10 |
|
|
|
MB-677127548a230525e1a073d19dc64939dcbd942e4dea123bd76c30154fc7df2b |
Unknown: composer.dat |
high |
Unknown |
1 |
9 |
|
|
|
CVE-2026-70482 |
Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client |
high |
cve |
0 |
0 |
|
|
|
MB-329cb3582506bc7b7da039b4f75ea2a2ccdb45f8b8ad6817fd52fbe2e975b0e8 |
OverlordRAT: pg.exe |
high |
OverlordRAT |
1 |
10 |
|
|
|
TF-1868506 |
Aisuru: ip:port combination that is used for botnet Command&control (C&C) 137.184.70.190:9034 |
high |
Aisuru |
2 |
6 |
|
|
|
CVE-2026-16793 |
Remote Command Injection via OS Profile Password in Lenovo XClarity Orchestrator |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-16792 |
Global TLS Certificate Validation Bypass in Lenovo XClarity Orchestrator |
high |
cve |
0 |
0 |
|
|
|
MB-9bb943340f1b6bf6cff15334ab9b0ab32740455f50f76a779f1735445cb521ae |
Unknown: quis.exe |
high |
Unknown |
1 |
10 |
|
|
|
MB-67d1aeae3da2eea072c9f6bec6693a26c797ca372a2c6f2e58b804d9a063f7f8 |
Unknown: ?????.exe |
high |
Unknown |
1 |
9 |
|
|
|
TF-1868505 |
Eye Pyramid: ip:port combination that is used for botnet Command&control (C&C) 93.82.26.41:8000 |
high |
Eye Pyramid |
2 |
7 |
|
|
|
TF-1868504 |
PureRAT: ip:port combination that is used for botnet Command&control (C&C) 80.96.109.107:443 |
high |
PureRAT |
2 |
8 |
|
|
|
TF-1868503 |
Havoc: ip:port combination that is used for botnet Command&control (C&C) 43.134.169.103:8080 |
high |
Havoc |
2 |
10 |
|
|
|
TF-1868502 |
Evilginx: ip:port combination that is used for botnet Command&control (C&C) 35.202.238.13:8443 |
high |
Evilginx |
2 |
7 |
|
|
|
TF-1868501 |
Tsundere: ip:port combination that is used for botnet Command&control (C&C) 31.76.96.193:80 |
high |
Tsundere |
2 |
8 |
|
|
|
TF-1868500 |
Unknown malware: ip:port combination that is used for botnet Command&control (C&C) 3.122.223.106:80 |
high |
Unknown malware |
2 |
9 |
|
|
|
TF-1868499 |
PureRAT: ip:port combination that is used for botnet Command&control (C&C) 207.189.25.132:443 |
high |
PureRAT |
2 |
8 |
|
|
|
TF-1868498 |
AsyncRAT: ip:port combination that is used for botnet Command&control (C&C) 203.98.68.17:30200 |
high |
AsyncRAT |
2 |
8 |
|
|
|
TF-1868497 |
PureRAT: ip:port combination that is used for botnet Command&control (C&C) 195.177.94.71:56001 |
high |
PureRAT |
2 |
8 |
|
|
|
TF-1868496 |
PureRAT: ip:port combination that is used for botnet Command&control (C&C) 176.97.114.8:56002 |
high |
PureRAT |
2 |
7 |
|
|
|
TF-1868495 |
PureRAT: ip:port combination that is used for botnet Command&control (C&C) 176.97.114.8:56001 |
high |
PureRAT |
2 |
8 |
|
|
|
TF-1868494 |
Unknown malware: ip:port combination that is used for botnet Command&control (C&C) 172.182.216.158:443 |
high |
Unknown malware |
2 |
7 |
|
|
|
TF-1868493 |
PureRAT: ip:port combination that is used for botnet Command&control (C&C) 161.97.154.193:56002 |
high |
PureRAT |
2 |
8 |
|
|
|
TF-1868492 |
PureRAT: ip:port combination that is used for botnet Command&control (C&C) 161.97.154.193:56001 |
high |
PureRAT |
2 |
7 |
|
|
|
TF-1868491 |
PureRAT: ip:port combination that is used for botnet Command&control (C&C) 153.75.88.67:6666 |
high |
PureRAT |
2 |
8 |
|
|
|
TF-1868490 |
PureRAT: ip:port combination that is used for botnet Command&control (C&C) 105.108.17.137:443 |
high |
PureRAT |
2 |
8 |
|
|
|
TF-1868489 |
DanaBot: ip:port combination that is used for botnet Command&control (C&C) 100.31.3.235:8082 |
high |
DanaBot |
2 |
7 |
|
|
|
MB-c3a148eb2be5d3ff907f77561644fe0ecde7f39179ed4eb72850d1d6316078ce |
Mirai: killbotx.arm4 |
high |
Mirai |
1 |
10 |
|
|
|
CVE-2026-70479 |
Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader |
high |
cve |
0 |
0 |
|
|
|
MB-89b741ebf2f10c8108571c044a2d822d58c64ff1a19c0af0dfdd3cb8d638ae94 |
Mirai: mipsel |
high |
Mirai |
1 |
10 |
|
|
|
MB-e08c0890b11d91b7ee58de25cc190e1fdf760d76b6d0821aa2d1f442b43e719a |
LummaStealer: setup.exe |
high |
LummaStealer |
1 |
10 |
|
|
|
CVE-2026-18657 |
Executable Resolution from Untrusted Project Directory in Kiro CLI on Windows |
high |
cve |
0 |
0 |
|
|
|
MB-4b788dc59db568205a6180f30bae301d6107896ee3e80c1edca4017c9bee5bed |
Stealc: SacramentoZum.exe |
high |
Stealc |
1 |
10 |
|
|
|
CVE-2026-70553 |
MaxSite CMS Unauthenticated RCE via Install Endpoint |
critical |
cve |
0 |
0 |
|
|
|
MB-3876764f99c301f22eec5d0dee52e4266e447f7079977b113826dcb7a8286fdf |
Mirai: mipsel |
high |
Mirai |
1 |
10 |
|
|
|
CVE-2026-70478 |
Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected service |
critical |
cve |
0 |
0 |
|
|
|
MB-c7bd4d80516ea71241d4d554f8441bcf523a6d91a59e9e8ddf8b35918b852dc6 |
Unknown: Setup.exe |
high |
Unknown |
1 |
9 |
|
|
|
MB-8ca2c6237e72f889bfebceea0e6bd6ff9e45971634e2e42f81ae10210190b35c |
Unknown: Installer_v2031_x64.exe |
high |
Unknown |
1 |
10 |
|
|
|
CVE-2026-18656 |
Executable Resolution from Untrusted Project Directory in Kiro IDE on Windows |
high |
cve |
0 |
0 |
|
|
|
MB-258c66d02c5b6c3abea28fbae7b30d67a35880c5b69f674ac1c37797846ab9d3 |
Unknown: Installer.iso |
high |
Unknown |
1 |
10 |
|
|
|
MB-61a9fe0873194f2c65636392b66863ee9263325edefe1f0cae2c7ef2cd746c24 |
Unknown: Loader.exe |
high |
Unknown |
1 |
10 |
|
|
|
CVE-2026-4431 |
Easy Post Submission <= 2.3.0 - Missing Authorization |
critical |
wordpress-vulnerability |
3 |
9 |
|
|
|
MB-83dc123d31c5be60e541eaee0b9808bf895988fe9654a56c9d4f16caba9a44c0 |
OverlordRAT: FLStudio2025_v64_Win.exe |
high |
OverlordRAT |
1 |
10 |
|
|
|
TF-1868488 |
ClearFake: Domain name that delivers a malware payload kozjbl.partyboxlovely.com |
high |
ClearFake |
2 |
10 |
|
|
|
CVE-2026-11977 |
WP Post Author <= 3.9.1 - Authenticated (Author+) SQL Injection |
medium |
wordpress-vulnerability |
3 |
9 |
|
|
|
MB-b04dd6daaf2f6606559de3f0b45574e804110f67c69c71326967443d8584daf4 |
Unknown: tbk |
high |
Unknown |
1 |
9 |
|
|
|
TF-1868487 |
ClearFake: Domain name that delivers a malware payload partyboxlovely.com |
high |
ClearFake |
2 |
10 |
|
|
|
CVE-2026-70477 |
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability |
critical |
cve |
0 |
0 |
|
|
|
CVE-2026-70552 |
MaxSite CMS 109.5 Unauthenticated AJAX Dispatcher Bypass via ajax.php |
critical |
cve |
0 |
0 |
|
|
|
MB-7bafabbac594b20daa9b9a0106261d6ac6fe4c289eb1ee6d5c63a0523a1ad558 |
Mirai: killbotx.mips |
high |
Mirai |
1 |
10 |
|
|
|
MB-45880839303fe491b2676a37faaa1fe6192917b3e64de1d46858563f16518e2f |
BlakcSeeStealer: vsdbg.dll |
high |
BlakcSeeStealer |
1 |
10 |
|
|
|