s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

Threats

153534 threats catalogued · filter, sort and triage below.

All Threats · 153534 TOTAL
Reset
ID Title Severity Category RefsRemediations Published Source updated APEX Update Time
OTX-6a722ddf8b8c2da176f0ee51 Infrastructure of Interest: Medium Confidence C2 - 2026-08 high ioi 1 10
OTX-6a722ddc939f04c5b7fe2d41 Infrastructure of Interest: Medium Confidence Phishing - 2026-08 high ioi 1 10
OTX-6a722dd93367ad9680ad63fe Infrastructure of Interest: High Confidence General - 2026-08 high ioi 1 10
OTX-6a722dd62b660bc553e0e610 Infrastructure of Interest: High Confidence Stealer - 2026-08 high ioi 1 10
OTX-6a722dd4a132dc9e71bc11b2 Infrastructure of Interest: High Confidence C2 - 2026-08 high ioi 1 9
CVE-2026-12000 Page and Post Restriction <= 1.4.1 - Unauthenticated Missing Authorization to Sensitive Information Exposure via REST API high wordpress-vulnerability 3 1
TF-1868466 Vidar: URL that is used for botnet Command&control (C&C) https://bib.sinism188.top/ high Vidar 2 8
TF-1868465 Vidar: Domain that is used for botnet Command&control (C&C) bib.sinism188.top high Vidar 2 8
URLhaus-PL-6d87df0326b71dca17d83744d5d26d7c417885c3fc3d3d134ab2062da009de0f URLhaus payload: (html) 6d87df0326b71dca… medium malware 2 10
TF-1868464 Mozi: URL that delivers a malware payload http://125.41.245.63:39395/Mozi.m high Mozi 3 10
TF-1868463 Mozi: URL that delivers a malware payload http://103.186.77.64:51823/Mozi.m high Mozi 3 10
TF-1868462 Mozi: URL that delivers a malware payload http://103.148.128.154:35695/Mozi.m high Mozi 3 10
TF-1868461 Mozi: URL that delivers a malware payload http://61.174.163.220:39657/Mozi.m high Mozi 3 10
TF-1868460 Mozi: URL that delivers a malware payload http://139.135.42.179:41902/Mozi.m high Mozi 3 10
CVE-2026-6627 WPFormify <= 1.1.1 - Missing Authorization high wordpress-vulnerability 3 1
MB-0e5159f1b507b56a59adc39564646aa07f83f1fced3dad6872e3752d777ea885 SalatStealer: Rexil.exe high SalatStealer 1 10
MB-e64b70bbc632b834064b4b268405323e0a83c5d63102b49c903792cb79c5a1fa SalatStealer: Rexil.exe high SalatStealer 1 10
TF-1868459 Vidar: URL that is used for botnet Command&control (C&C) https://bib.y8slot.net/ high Vidar 2 10
TF-1868458 Vidar: Domain that is used for botnet Command&control (C&C) bib.y8slot.net high Vidar 2 10
MB-1e306e8345ada5cab196a9045f9f63a33d7914408875e77655ffd57ddd4ac673 SalatStealer: Zapret.exe high SalatStealer 1 10
URLhaus-PL-a76823df078b029905426affc21b1a0f6dd17327330e9339da6b03beb9069d82 URLhaus payload: (zip) a76823df078b0299… medium malware 2 10
CVE-2026-13229 Zammad 7.0.1 - Improper authorization in ticket article attachment cloning high cve 0 0
MB-a4aa0f9613695363fdebef9cee46d959bc98a97e5e7fed466157b3afb01c79a5 SalatStealer: Zapret.exe high SalatStealer 1 10
CVE-2026-6972 SKT Skill Bar <= 2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting medium wordpress-vulnerability 3 1
TF-1868457 Cobalt Strike: ip:port combination that is used for botnet Command&control (C&C) 116.212.123.164:443 high Cobalt Strike 2 7
TF-1868456 VShell: ip:port combination that is used for botnet Command&control (C&C) 35.240.152.221:8080 high VShell 2 8
CVE-2026-7693 Backup Migration <= 2.1.5.1 - Authenticated (Administrator+) OS Command Injection via 'file' Parameter high wordpress-vulnerability 3 1
CVE-2026-5116 Contact Form 7 – Dynamic Text Extension <= 5.0.5 - Authenticated (Editor+) Stored Cross-Site Scripting medium wordpress-vulnerability 3 1
CVE-2026-7726 Layouts for WPBakery <= 1.1.3 - Missing Authorization to Unauthenticated Template Cache Manipulation via 'handle_sync' AJAX Action medium wordpress-vulnerability 3 1
TF-1868455 ClearFake: Domain name that delivers a malware payload nzjnxe.paquetitoexpressny.com high ClearFake 2 10
CVE-2026-70474 Flowise: Cross-Workspace OAuth2 Credential Metadata Leak high cve 0 0
TF-1868454 ClearFake: Domain name that delivers a malware payload paquetitoexpressny.com high ClearFake 2 10
TF-1868453 VBREVSHELL: ip:port combination that is used for botnet Command&control (C&C) 61.54.27.211:8082 medium VBREVSHELL 3 6
CVE-2026-47764 pdm: Path traversal in wheel installation via overridden write_to_fs high cve 0 0
CVE-2026-70473 Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history high cve 0 0
CVE-2026-7444 Search Analytics for WP <= 1.4.16 - Cross-Site Request Forgery high wordpress-vulnerability 3 1
MB-9dfbe92313bc0d309a0fb07cb6461d6c17f18b9b66842b101593373c1bf9fff7 Unknown: b.7z high Unknown 1 10
MB-8442930244e6302279d1a2861608df3c8590aa142ef6ec6fce0bd57d1594b1de Unknown: file high Unknown 1 9
CVE-2026-7441 Simple Yearly Archive <= 2.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting medium wordpress-vulnerability 3 1
MB-34ba0747cd912e37af2273f6b2bbfb579a9b806713f344925a39f6da2c0847bb RemusStealer: QuickFetch.exe high RemusStealer 1 10
MB-5892541e8901d5ea993dc7fe55726e90556e84e92f8cb10dbb10cf6d1e3d4705 Unknown: composer.dat high Unknown 1 10
CVE-2026-5651 Askeet <= 3.0 - Authenticated (Administrator+) SQL Injection via 'sql_query' Parameter medium wordpress-vulnerability 3 1
TF-1868452 ClearFake: Domain name that delivers a malware payload wifcimg.planksbiergarten.site high ClearFake 2 10
TF-1868451 ClearFake: Domain name that delivers a malware payload planksbiergarten.site high ClearFake 2 10
TF-1868450 Remus: ip:port combination that is used for botnet Command&control (C&C) 209.145.55.206:8839 high Remus 2 8
CVE-2026-70472 Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store high cve 0 0
CVE-2026-69702 SnailJob 1.7.0 Denial of Service via FuryUtil.deserialize OOM high cve 0 0
CVE-2026-70471 Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure high cve 0 0
CVE-2026-5108 Super Progressive Web Apps <= 2.2.43 - Authenticated (Administrator+) Stored Cross-Site Scripting via Offline Message Setting medium wordpress-vulnerability 3 1
CVE-2026-18830 Insufficient input validation in Amazon Bedrock AgentCore harness InvokeHarness API high cve 0 0
Showing 301–350 of 153534 threats (page 7 of 3071).