ervik.as
Free · Live · No Signup Required

Real-Time Cyber
Threat Intelligence

The same live CVE, zero-day, and ransomware data enterprise platforms charge for — free, with no account and no paywall. Updated continuously, not on a delay.

CVEs, zero-days, ransomware campaigns, threat actors, OT/ICS advisories, and global attack activity from a single platform.

Subscribe via RSS — get every update the moment it's published
Global Cyber Threat Intelligence
Live intelligence from
0+
CVEs
0+
Threat Actors
0
Active Zero Days
0+
Ransomware Victims
Updated every 15 minutes · running totals tracked since this dashboard went live

What Matters Today

Actively exploited
CVE-2026-76461

Cisco Secure Email Gateway SQL Injection Vulnerability

Cisco Secure Email Gateway

Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Full analysis
Actively exploited
CVE-2026-42016

JFrog Artifactory Incorrect Authorization Vulnerability

JFrog Artifactory

Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Full analysis
Actively exploited
CVE-2026-42018

JFrog Artifactory Improper Authentication Vulnerability

JFrog Artifactory

Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Full analysis
[The Hacker News]Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution[Dark Reading]'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink[Krebs on Security]Microsoft Plugs Nearly 1,000 Security Holes[The Hacker News]China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE[Dark Reading]Maximum Severity GitLab Flaw Puts Supply Chains at Risk[Krebs on Security]FBI Probes Service Selling 153M+ Drivers Licenses[The Hacker News]New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing[Dark Reading]Anthropic CEO: Time to Shift From Improving to Controlling AI[Krebs on Security]Two Alleged ‘TeamPCP’ Hackers Arrested in Australia[The Hacker News]3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials[Dark Reading]Threat Actor Generates 1M Personalized Fraud Emails in 3 Days[Krebs on Security]Who’s Tracking You? Use This New Service to Find Out[The Hacker News]Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports[Dark Reading]CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate[Krebs on Security]Microsoft Plugs Nearly 400 Security Holes[The Hacker News]Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries[Dark Reading]SpiderSilk Hunts External Threats With AI-Based Scanner[Krebs on Security]Canadian Man Pleads Guilty in Snowflake Extortions[The Hacker News]WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution[Dark Reading]Why AI Is So Good at Scamming Humans[Krebs on Security]Read This Before You Buy That TV Streaming Stick[The Hacker News]⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits[Dark Reading]AI Governance Can't Wait[Krebs on Security]LG to Ban Residential Proxies from Smart TV Apps[The Hacker News]Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution[Dark Reading]'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink[Krebs on Security]Microsoft Plugs Nearly 1,000 Security Holes[The Hacker News]China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE[Dark Reading]Maximum Severity GitLab Flaw Puts Supply Chains at Risk[Krebs on Security]FBI Probes Service Selling 153M+ Drivers Licenses[The Hacker News]New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing[Dark Reading]Anthropic CEO: Time to Shift From Improving to Controlling AI[Krebs on Security]Two Alleged ‘TeamPCP’ Hackers Arrested in Australia[The Hacker News]3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials[Dark Reading]Threat Actor Generates 1M Personalized Fraud Emails in 3 Days[Krebs on Security]Who’s Tracking You? Use This New Service to Find Out[The Hacker News]Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports[Dark Reading]CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate[Krebs on Security]Microsoft Plugs Nearly 400 Security Holes[The Hacker News]Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries[Dark Reading]SpiderSilk Hunts External Threats With AI-Based Scanner[Krebs on Security]Canadian Man Pleads Guilty in Snowflake Extortions[The Hacker News]WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution[Dark Reading]Why AI Is So Good at Scamming Humans[Krebs on Security]Read This Before You Buy That TV Streaming Stick[The Hacker News]⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits[Dark Reading]AI Governance Can't Wait[Krebs on Security]LG to Ban Residential Proxies from Smart TV Apps

Global Threat Map

Live attack telemetry from the SANS ISC DShield sensor network.

Open full map

Latest CVEs

Newly disclosed vulnerabilities ranked by exploitability.

Full database
CVE-2026-91088medium · 4.8

A vulnerability has been found in GPAC up to f1219cde. This issue affects the function gf_url_concatenate_ex of the file utils/url.c of the …

A vulnerability has been found in GPAC up to f1219cde. This issue affects the function gf_url_concatenate_ex of the file utils/url.c of the component URL Handler. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. Upgrading to version abi-16.23 is capable of addressing this issue. The identifier of the patch is afca1f1181668d85941d51ed1adf647807d5d975. It is advisable to upgrade the affected component.

· · 9/15/2026
CVE-2026-91087high · 7.3

A flaw has been found in GPAC up to f1219cde. This vulnerability affects the function gf_mo_get_od_id of the file compositor/media_object.c …

A flaw has been found in GPAC up to f1219cde. This vulnerability affects the function gf_mo_get_od_id of the file compositor/media_object.c of the component Compositor. Executing a manipulation can lead to use after free. The attack may be performed from remote. The exploit has been published and may be used. Upgrading to version abi-16.24 is able to resolve this issue. This patch is called e34f4ba349d55cd1849f0bcf4cf46552732e2db7. Upgrading the affected component is advised.

· · 9/15/2026
CVE-2026-91086medium · 6.3

A security vulnerability has been detected in GPAC up to f1219cde. Affected by this issue is the function mpgviddmx_process of the file filt…

A security vulnerability has been detected in GPAC up to f1219cde. Affected by this issue is the function mpgviddmx_process of the file filters/reframe_mpgvid.c of the component MPEG Video Reframer. Such manipulation leads to heap-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. Upgrading to version abi-16.23 can resolve this issue. The name of the patch is afca1f1181668d85941d51ed1adf647807d5d975. Upgrading the affected component is recommended.

· · 9/15/2026
CVE-2026-91005medium · 6.3

A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. This affects the function move_uploaded_file of the file pr…

A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. This affects the function move_uploaded_file of the file production/edit_picture.php of the component Profile Picture Upload. Performing a manipulation of the argument File results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made public and could be used.

· · 9/15/2026

OT & ICS Security

Industrial control system advisories from CISA's official CSAF repository.

All advisories

Active Zero-Days

Vulnerabilities being weaponized before patches are available.

All zero-days
CVE-2026-76461actively exploited

Cisco Secure Email Gateway SQL Injection Vulnerability

Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.

Cisco Secure Email Gateway
CVE-2026-42016actively exploited

JFrog Artifactory Incorrect Authorization Vulnerability

JFrog Artifactory contains an incorrect authorization vulnerability that allows leads to privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

JFrog Artifactory
CVE-2026-42018actively exploited

JFrog Artifactory Improper Authentication Vulnerability

JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

JFrog Artifactory

Latest Ransomware Victims

Fresh victim disclosures from active ransomware campaigns.

All victims

Threat Intel Briefings

Active campaigns from tracked actors over the last 72 hours.

All briefings
threatfox-1920270ClearFakepayload delivery — catechese.chOpportunistic / untargetedGlobal9/15/2026
threatfox-1920264Unknown malwarebotnet cc — 178.16.54.148:8081Opportunistic / untargetedGlobal9/15/2026
threatfox-1920265Unknown malwarebotnet cc — 195.20.115.77:3308Opportunistic / untargetedGlobal9/15/2026
threatfox-1920266Unknown malwarebotnet cc — 91.219.236.179:8080Opportunistic / untargetedGlobal9/15/2026
threatfox-1920269Cobalt Strikebotnet cc — 121.43.152.104:2202Opportunistic / untargetedGlobal9/15/2026
Advertisement