ervik.as
Free · Live · No Signup Required

Real-Time Cyber
Threat Intelligence

The same live CVE, zero-day, and ransomware data enterprise platforms charge for — free, with no account and no paywall. Updated continuously, not on a delay.

CVEs, zero-days, ransomware campaigns, threat actors, OT/ICS advisories, and global attack activity from a single platform.

Subscribe via RSS — get every update the moment it's published
Global Cyber Threat Intelligence
Live intelligence from
0+
CVEs
0+
Threat Actors
0
Active Zero Days
0+
Ransomware Victims
Updated every 15 minutes · running totals tracked since this dashboard went live
[The Hacker News]Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data[Dark Reading]Threat Actor Generates 1M Personalized Fraud Emails in 3 Days[Krebs on Security]Microsoft Plugs Nearly 1,000 Security Holes[The Hacker News]CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV[Dark Reading]CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate[Krebs on Security]FBI Probes Service Selling 153M+ Drivers Licenses[The Hacker News]When the Whole Company Adopts AI: What It Does to Your SOC[Dark Reading]Why AI Is So Good at Scamming Humans[Krebs on Security]Two Alleged ‘TeamPCP’ Hackers Arrested in Australia[The Hacker News]OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers[Dark Reading]AI Governance Can't Wait[Krebs on Security]Who’s Tracking You? Use This New Service to Find Out[The Hacker News]GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure[Dark Reading]Papercut AI Swarm Attack Heralds Changes for Cyber Kill Chain[Krebs on Security]Microsoft Plugs Nearly 400 Security Holes[The Hacker News]Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks[Dark Reading]Indonesia Hit by Android Banking App-Cloning Campaign[Krebs on Security]Canadian Man Pleads Guilty in Snowflake Extortions[The Hacker News]Claude Used to Automate Exploitation and Data Theft Across Multiple Victims[Dark Reading]Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data[Krebs on Security]Read This Before You Buy That TV Streaming Stick[The Hacker News]Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection[Dark Reading]Nightmare-Eclipse Strikes Again With 'ShieldCrash' Windows Exploit[Krebs on Security]LG to Ban Residential Proxies from Smart TV Apps[The Hacker News]Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data[Dark Reading]Threat Actor Generates 1M Personalized Fraud Emails in 3 Days[Krebs on Security]Microsoft Plugs Nearly 1,000 Security Holes[The Hacker News]CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV[Dark Reading]CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate[Krebs on Security]FBI Probes Service Selling 153M+ Drivers Licenses[The Hacker News]When the Whole Company Adopts AI: What It Does to Your SOC[Dark Reading]Why AI Is So Good at Scamming Humans[Krebs on Security]Two Alleged ‘TeamPCP’ Hackers Arrested in Australia[The Hacker News]OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers[Dark Reading]AI Governance Can't Wait[Krebs on Security]Who’s Tracking You? Use This New Service to Find Out[The Hacker News]GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure[Dark Reading]Papercut AI Swarm Attack Heralds Changes for Cyber Kill Chain[Krebs on Security]Microsoft Plugs Nearly 400 Security Holes[The Hacker News]Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks[Dark Reading]Indonesia Hit by Android Banking App-Cloning Campaign[Krebs on Security]Canadian Man Pleads Guilty in Snowflake Extortions[The Hacker News]Claude Used to Automate Exploitation and Data Theft Across Multiple Victims[Dark Reading]Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data[Krebs on Security]Read This Before You Buy That TV Streaming Stick[The Hacker News]Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection[Dark Reading]Nightmare-Eclipse Strikes Again With 'ShieldCrash' Windows Exploit[Krebs on Security]LG to Ban Residential Proxies from Smart TV Apps

Global Threat Map

Live attack telemetry from the SANS ISC DShield sensor network.

Open full map

Latest CVEs

Newly disclosed vulnerabilities ranked by exploitability.

Full database
CVE-2026-90606critical · 9.9

A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the file …

A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the file /boafrm/formIpv6Setup of the component boa. The manipulation of the argument static_ipv6 leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.

· · 9/14/2026
CVE-2026-90605critical · 9.9

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm…

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6addr can lead to buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.

· · 9/14/2026
CVE-2026-90604low · 3.5

A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. This affects an unknown part of the component Anchor Tag Handler.…

A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. This affects an unknown part of the component Anchor Tag Handler. Performing a manipulation results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.

· · 9/14/2026
CVE-2025-63842medium · 5.4

A Cross-Site Scripting (XSS) vulnerability in the web backend for the Repetico app 1.9.7.31 for Android allows a remote authenticated user t…

A Cross-Site Scripting (XSS) vulnerability in the web backend for the Repetico app 1.9.7.31 for Android allows a remote authenticated user to execute arbitrary JavaScript code in the app's context via crafted input in the multiple-choice question text field.

· · 9/14/2026

OT & ICS Security

Industrial control system advisories from CISA's official CSAF repository.

All advisories

Active Zero-Days

Vulnerabilities being weaponized before patches are available.

All zero-days
CVE-2026-42016actively exploited

JFrog Artifactory Incorrect Authorization Vulnerability

JFrog Artifactory contains an incorrect authorization vulnerability that allows leads to privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

JFrog Artifactory
CVE-2026-42018actively exploited

JFrog Artifactory Improper Authentication Vulnerability

JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

JFrog Artifactory
CVE-2026-84869actively exploited

ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability

ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation.

ConnectWise ScreenConnect

Latest Ransomware Victims

Fresh victim disclosures from active ransomware campaigns.

All victims

Threat Intel Briefings

Active campaigns from tracked actors over the last 72 hours.

All briefings
threatfox-1917052VShellpayload — 46f4cd435ca39c8fc2f1814fd9740a7ee9716207f5351d21008672ab466149ebOpportunistic / untargetedGlobal9/14/2026
threatfox-1917050Unknown Stealerpayload — 4f92f1b658856b2662100c26dcd5f81525a74482b4fdebb16923ec27234f0a7eOpportunistic / untargetedGlobal9/14/2026
threatfox-1917051VShellpayload — 9d24316bd0f8af89c590f6c37070f905cb60a15745fbe748b525e67d2a05b640Opportunistic / untargetedGlobal9/14/2026
threatfox-1917049VShellpayload — a2a067ca282f9034391e2cf1b4d2fe681cbe0326588d507b3cff5b2fab70bc7eOpportunistic / untargetedGlobal9/14/2026
threatfox-1917048Miraipayload — 6492bc2bfaa40a1a4c783fde77be26cd0381038f13deacce833ae84a6dbc5712Opportunistic / untargetedGlobal9/14/2026
Advertisement