threat-intel UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations Chinese-speaking cybercrime group UAT-10147 is leveraging AI-powered tools to automate complex post-compromise operations targeting web servers globally. The group, active since early 2026, utilizes a combination of publicly disclosed vulnerabilities and AI-generated exploitation guidance, reconnaissance, and payload g… Cisco Talos · Aug 20, 2026 High CVE-2022-0995CVE-2021-3156CVE-2015-5287CHBRBOaiautomationpost-exploitation
threat-intel ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories This week's ThreatsDay highlights a diverse range of cyber threats, from global fraud operations and ransomware tool overlaps to sophisticated social engineering attacks and vulnerabilities in popular software. Key event… The Hacker News · Jul 9, 2026 High CVE-2026-9181CVE-2025-49760CVE-2025-59200CHTAESsocial engineeringphishingransomware
vulnerability Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges A new Microsoft Defender zero-day vulnerability, dubbed "RoguePlanet," has emerged, allowing attackers to gain SYSTEM privileges on fully patched Windows 10 and 11 systems via a race condition. The vulnerability was disc… BleepingComputer · Jun 9, 2026 High zero-dayrace conditionremote code execution
vulnerability Exploit released for new PinTheft Arch Linux root escalation flaw A publicly available exploit, dubbed ‘PinTheft’, has been released for a Linux kernel vulnerability allowing local attackers to gain root privileges on Arch Linux systems. The vulnerability, residing in the RDS module, w… BleepingComputer · May 20, 2026 High linuxprivilege escalationrds
threat-intel DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability A Proof-of-Concept (PoC) exploit, dubbed DirtyDecrypt, has been released for a Linux kernel vulnerability (CVE-2026-31635) allowing for local privilege escalation. The vulnerability, related to a missing copy-on-write (C… The Hacker News · May 19, 2026 High CVE-2026-31635CVE-2026-31431CVE-2026-43284linuxkernellpe
vulnerability Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years A critical Linux kernel vulnerability, dubbed 'Copy Fail' (CVE-2026-31431), has been discovered allowing unprivileged local attackers to escalate their access to root across numerous Linux distributions since 2017. The f… Palo Alto Unit 42 · May 5, 2026 Critical CVE-2026-31431CVE-2026-314331USlinuxkernellpe