MB-769182c8505feeb18a5810e9fb5709727704739cd6b02068da8352f66ea1c3b3 |
Mirai: killbotx.mips |
high |
Mirai |
1 |
10 |
|
|
|
TF-1868486 |
RevStealer: Domain that is used for botnet Command&control (C&C) health.sigmacoast.one |
high |
RevStealer |
2 |
10 |
|
|
|
CVE-2026-70476 |
Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation |
high |
cve |
0 |
0 |
|
|
|
TF-1868485 |
Mirai: ip:port combination that is used for botnet Command&control (C&C) 155.103.69.225:25565 |
high |
Mirai |
2 |
8 |
|
|
|
TF-1868484 |
Mirai: ip:port combination that is used for botnet Command&control (C&C) 155.103.69.225:8080 |
high |
Mirai |
2 |
10 |
|
|
|
TF-1868483 |
Mirai: ip:port combination that is used for botnet Command&control (C&C) 155.103.69.225:123 |
high |
Mirai |
2 |
10 |
|
|
|
TF-1868482 |
Mirai: ip:port combination that is used for botnet Command&control (C&C) 155.103.69.225:80 |
high |
Mirai |
2 |
8 |
|
|
|
TF-1868481 |
Mirai: ip:port combination that is used for botnet Command&control (C&C) 178.83.206.213:8080 |
high |
Mirai |
2 |
9 |
|
|
|
TF-1868480 |
ClearFake: Domain name that delivers a malware payload keofokd.pureplatinumdancers.com |
high |
ClearFake |
2 |
10 |
|
|
|
TF-1868479 |
ClearFake: Domain name that delivers a malware payload pureplatinumdancers.com |
high |
ClearFake |
2 |
10 |
|
|
|
CVE-2026-70475 |
Flowise: Missing Authorization on Execution Update Endpoint |
high |
cve |
0 |
0 |
|
|
|
TF-1868478 |
Mirai: Domain that is used for botnet Command&control (C&C) poop.garden |
high |
Mirai |
2 |
10 |
|
|
|
TF-1868477 |
Mirai: ip:port combination that delivery a malware payload 176.65.148.145:2 |
high |
Mirai |
2 |
10 |
|
|
|
TF-1868476 |
Cobalt Strike: ip:port combination that is used for botnet Command&control (C&C) 116.212.123.164:8080 |
high |
Cobalt Strike |
2 |
7 |
|
|
|
TF-1868475 |
Cobalt Strike: ip:port combination that is used for botnet Command&control (C&C) 116.212.123.164:80 |
high |
Cobalt Strike |
2 |
7 |
|
|
|
TF-1868474 |
VShell: ip:port combination that is used for botnet Command&control (C&C) 107.161.86.90:5985 |
high |
VShell |
2 |
8 |
|
|
|
TF-1868473 |
VShell: ip:port combination that is used for botnet Command&control (C&C) 39.107.248.48:8083 |
high |
VShell |
2 |
8 |
|
|
|
TF-1868472 |
Unknown malware: ip:port combination that is used for botnet Command&control (C&C) 114.132.46.254:5173 |
high |
Unknown malware |
2 |
8 |
|
|
|
CVE-2026-49435 |
Keysight IxChariot-related products stack-based buffer overflow |
critical |
cve |
0 |
0 |
|
|
|
CVE-2026-69704 |
Atals-Livre SQL Injection via Unsanitized GET Parameter in supp() |
high |
cve |
0 |
0 |
|
|
|
TF-1868471 |
ClearFake: Domain name that delivers a malware payload cdyyhe.parma-delikatessen.com |
high |
ClearFake |
2 |
10 |
|
|
|
TF-1868470 |
ClearFake: Domain name that delivers a malware payload parma-delikatessen.com |
high |
ClearFake |
2 |
10 |
|
|
|
CVE-2026-11969 |
WP TripAdvisor Review Slider <= 14.3 - Authenticated (Administrator+) SQL Injection |
medium |
wordpress-vulnerability |
3 |
1 |
|
|
|
CVE-2026-11920 |
JoomSport <= 5.7.9 - Authenticated (Administrator+) SQL Injection via 'order' Parameter |
medium |
wordpress-vulnerability |
3 |
1 |
|
|
|
CVE-2026-47781 |
pdm: Project-Controlled `.pdm-plugins` Content Executes Before CLI Parsing |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-7520 |
MailChimp Forms by MailMunch <= 3.2.7 - Missing Authorization to Authenticated (Subscriber+) MailMunch Integration Takeover via 'sign_in' AJAX Action |
high |
wordpress-vulnerability |
3 |
1 |
|
|
|
CVE-2026-69703 |
Atlas-Livre Unauthenticated Access via Admin Controllers Missing Exit |
critical |
cve |
0 |
0 |
|
|
|
WORDFENCE-7bbead7c-47b9-473f-b335-6fae4b5998d6 |
Contact Form Extender for Divi Builder <= 1.0.6 - Unauthenticated Arbitrary File Deletion via Path Traversal |
high |
wordpress-vulnerability |
2 |
1 |
|
|
|
CVE-2026-6020 |
ShopLentor <= 3.3.7 - Authenticated (Administrator+) Arbitrary Function Execution via 'callback' Parameter via REST API |
high |
wordpress-vulnerability |
3 |
1 |
|
|
|
CVE-2026-11454 |
Groundhogg — CRM, Newsletters, and Marketing Automation <= 4.5.2 - Insecure Direct Object Reference |
medium |
wordpress-vulnerability |
3 |
1 |
|
|
|
URLhaus-PL-3749e4fbc23fb164d0284cd88a0e9a82fa59c133529ef7a703bb817658de3214 |
URLhaus payload: (html) 3749e4fbc23fb164… |
medium |
malware |
2 |
10 |
|
|
|
CVE-2026-7105 |
Xpro Addons <= 1.5.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Creation via get_menu_content_editor() Function |
medium |
wordpress-vulnerability |
3 |
1 |
|
|
|
TF-1868469 |
ClearFake: Domain name that delivers a malware payload sqqzefc.pmco-sa.com |
high |
ClearFake |
2 |
10 |
|
|
|
TF-1868468 |
ClearFake: Domain name that delivers a malware payload pmco-sa.com |
high |
ClearFake |
2 |
10 |
|
|
|
CVE-2026-15281 |
User Access Manager <= 2.3.12 - Authenticated (Subscriber+) SQL Injection |
medium |
wordpress-vulnerability |
3 |
1 |
|
|
|
CVE-2026-7456 |
Udimi Tools <= 3.2 - Missing Authorization to Authenticated (Subscriber+) Plugin Configuration Reset via 'disconnect' AJAX Action |
medium |
wordpress-vulnerability |
3 |
1 |
|
|
|
URLhaus-PL-3a93450387d976dda5bc7722d7db09be11e11b29abf9b176094502c24fe201ca |
URLhaus payload: (zip) 3a93450387d976dd… |
medium |
malware |
2 |
10 |
|
|
|
CVE-2026-18881 |
TableOn <= 1.0.5.1 - Unauthenticated Blind SQL Injection via 'comment_count' Filter Parameter |
high |
wordpress-vulnerability |
3 |
1 |
|
|
|
MB-bf94b7278ed33a993b98dc03afc34c60e2c5adb143a27300e7b8ad62c06b4b36 |
Unknown: dollar.exe |
high |
Unknown |
1 |
10 |
|
|
|
CVE-2026-5581 |
Multi Uploader for Gravity Forms <= 1.1.8 - Missing Authorization to Unauthenticated Arbitrary Media Deletion |
critical |
wordpress-vulnerability |
3 |
1 |
|
|
|
MB-a26e60693dadcc06a106fb2cb339f2b438d1c0e1a3e630cbf73a4cc00954b364 |
Unknown: dollar.exe |
high |
Unknown |
1 |
10 |
|
|
|
TF-1868467 |
ClearFake: Domain name that delivers a malware payload xn6yof5y.josephmichaelnh.com |
high |
ClearFake |
2 |
10 |
|
|
|
CVE-2026-6079 |
Material Dashboard <= 1.4.10 - Missing Authorization to Unauthenticated Task Enumeration, Execution, and Deletion |
high |
wordpress-vulnerability |
3 |
1 |
|
|
|
CVE-2026-17532 |
Seraphinite Accelerator <= 2.29.18 - Reflected Cross-Site Scripting |
medium |
wordpress-vulnerability |
3 |
1 |
|
|
|
CVE-2026-17505 |
TranslatePress <= 3.2.5 - Reflected Cross-Site Scripting |
medium |
wordpress-vulnerability |
3 |
1 |
|
|
|
MB-c2b078ab7d96bcdb061c34eb88e0d581ff2b8914ac26ab236e63775ebe7949d1 |
Unknown: 8e8fd0cc41163bccb6013ac5967bd4613cb2ee6e0829f1a9340eca1d299c91d7 |
high |
Unknown |
1 |
10 |
|
|
|
MB-1ae69db09035542cafb9ae06eb1e85858743973541e894dfb3a5158ac848d1e0 |
Unknown: CrossDNS_Setup.exe |
high |
Unknown |
1 |
10 |
|
|
|
CVE-2026-6147 |
LightSync Pro <= 2.1.6 - Authenticated (Author+) Arbitrary File Upload |
high |
wordpress-vulnerability |
3 |
1 |
|
|
|
OTX-6a722de5c337abfb11fea137 |
Infrastructure of Interest: Medium Confidence General - 2026-08 |
high |
ioi |
1 |
10 |
|
|
|
OTX-6a722de1e519791d40ff581c |
Infrastructure of Interest: Medium Confidence Stealer - 2026-08 |
high |
ioi |
1 |
10 |
|
|
|