ervik.as
Free · Live · No Signup Required

Real-Time Cyber
Threat Intelligence

The same live CVE, zero-day, and ransomware data enterprise platforms charge for — free, with no account and no paywall. Updated continuously, not on a delay.

CVEs, zero-days, ransomware campaigns, threat actors, OT/ICS advisories, and global attack activity from a single platform.

Subscribe via RSS — get every update the moment it's published
Global Cyber Threat Intelligence
Live intelligence from
0+
CVEs
0+
Threat Actors
0
Active Zero Days
0+
Ransomware Victims
Updated every 15 minutes · running totals tracked since this dashboard went live
[The Hacker News]New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing[Dark Reading]Anthropic CEO: Time to Shift From Improving to Controlling AI[Krebs on Security]Microsoft Plugs Nearly 1,000 Security Holes[The Hacker News]Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries[Dark Reading]Threat Actor Generates 1M Personalized Fraud Emails in 3 Days[Krebs on Security]FBI Probes Service Selling 153M+ Drivers Licenses[The Hacker News]WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution[Dark Reading]CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate[Krebs on Security]Two Alleged ‘TeamPCP’ Hackers Arrested in Australia[The Hacker News]⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits[Dark Reading]SpiderSilk Hunts External Threats With AI-Based Scanner[Krebs on Security]Who’s Tracking You? Use This New Service to Find Out[The Hacker News]AI Changed the Exposure Problem. Validation Needs to Change With It.[Dark Reading]Why AI Is So Good at Scamming Humans[Krebs on Security]Microsoft Plugs Nearly 400 Security Holes[The Hacker News]Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users[Dark Reading]AI Governance Can't Wait[Krebs on Security]Canadian Man Pleads Guilty in Snowflake Extortions[The Hacker News]Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data[Dark Reading]Papercut AI Swarm Attack Heralds Changes for Cyber Kill Chain[Krebs on Security]Read This Before You Buy That TV Streaming Stick[The Hacker News]CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV[Dark Reading]Indonesia Hit by Android Banking App-Cloning Campaign[Krebs on Security]LG to Ban Residential Proxies from Smart TV Apps[The Hacker News]New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing[Dark Reading]Anthropic CEO: Time to Shift From Improving to Controlling AI[Krebs on Security]Microsoft Plugs Nearly 1,000 Security Holes[The Hacker News]Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries[Dark Reading]Threat Actor Generates 1M Personalized Fraud Emails in 3 Days[Krebs on Security]FBI Probes Service Selling 153M+ Drivers Licenses[The Hacker News]WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution[Dark Reading]CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate[Krebs on Security]Two Alleged ‘TeamPCP’ Hackers Arrested in Australia[The Hacker News]⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits[Dark Reading]SpiderSilk Hunts External Threats With AI-Based Scanner[Krebs on Security]Who’s Tracking You? Use This New Service to Find Out[The Hacker News]AI Changed the Exposure Problem. Validation Needs to Change With It.[Dark Reading]Why AI Is So Good at Scamming Humans[Krebs on Security]Microsoft Plugs Nearly 400 Security Holes[The Hacker News]Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users[Dark Reading]AI Governance Can't Wait[Krebs on Security]Canadian Man Pleads Guilty in Snowflake Extortions[The Hacker News]Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data[Dark Reading]Papercut AI Swarm Attack Heralds Changes for Cyber Kill Chain[Krebs on Security]Read This Before You Buy That TV Streaming Stick[The Hacker News]CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV[Dark Reading]Indonesia Hit by Android Banking App-Cloning Campaign[Krebs on Security]LG to Ban Residential Proxies from Smart TV Apps

Global Threat Map

Live attack telemetry from the SANS ISC DShield sensor network.

Open full map

Latest CVEs

Newly disclosed vulnerabilities ranked by exploitability.

Full database
CVE-2026-90804medium · 4.8

A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/el…

A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_size/write_offset results in buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet.

· · 9/14/2026
CVE-2026-90803medium · 5.3

A security vulnerability has been detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_64_relocate_section …

A security vulnerability has been detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_64_relocate_section of the file bfd/elf64-x86-64.c of the component ld. Such manipulation of the argument roff leads to buffer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 addresses this issue. The name of the patch is 471130b39c03623ec6d78ece377ff4da3f6bfe7b. It is recommended to upgrade the affected component.

· · 9/14/2026
CVE-2026-90802medium · 4.4

A weakness has been identified in GNU Binutils 2.47. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. This …

A weakness has been identified in GNU Binutils 2.47. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. This manipulation causes null pointer dereference. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet.

· · 9/14/2026
CVE-2026-90801medium · 5.3

A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld…

A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld. The manipulation of the argument nbytes results in buffer overflow. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet.

· · 9/14/2026

OT & ICS Security

Industrial control system advisories from CISA's official CSAF repository.

All advisories

Active Zero-Days

Vulnerabilities being weaponized before patches are available.

All zero-days
CVE-2026-42016actively exploited

JFrog Artifactory Incorrect Authorization Vulnerability

JFrog Artifactory contains an incorrect authorization vulnerability that allows leads to privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

JFrog Artifactory
CVE-2026-42018actively exploited

JFrog Artifactory Improper Authentication Vulnerability

JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

JFrog Artifactory
CVE-2026-84869actively exploited

ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability

ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation.

ConnectWise ScreenConnect

Latest Ransomware Victims

Fresh victim disclosures from active ransomware campaigns.

All victims

Threat Intel Briefings

Active campaigns from tracked actors over the last 72 hours.

All briefings
threatfox-1917871Jackskidbotnet cc — 38.54.43.76:443Opportunistic / untargetedGlobal9/14/2026
threatfox-1917905Vidarbotnet cc — https://guest.v-panel.asia/Opportunistic / untargetedGlobal9/14/2026
threatfox-1917907Vidarbotnet cc — guest.v-panel.asiaOpportunistic / untargetedGlobal9/14/2026
threatfox-1917906IClickFixpayload delivery — parsebazar.comOpportunistic / untargetedGlobal9/14/2026
threatfox-1917904IClickFixpayload delivery — lan-trad.frOpportunistic / untargetedGlobal9/14/2026
Advertisement