Skip to content
Threat Feed

CRAFTEDSIGNAL THREAT INTELLIGENCE FEED

Threat intelligence feed for SOC and IR teams

Fresh threat briefs from the CraftedSignal pipeline, with MITRE ATT&CK coverage, CVE references, rule metadata, and IOCs when available. Full rule logic and test data stay inside the platform; this feed shows what is changing now.

Recent activity

1892 briefs
63.1 briefs/day
56.3 vulns/day
8.9 crits/day
Aug 13 crits vulns Sep 11

Latest briefs

View all →
high advisory

Information Disclosure Vulnerability in multicluster-observability-addon

A configuration reference vulnerability in the multicluster-observability-addon allows a managed cluster identity to bypass namespace restrictions and exfiltrate sensitive hub-level secrets.

multicluster-observability-addon vulnerability cloud-native kubernetes
1t 1c
critical threat

Active Exploitation of JFrog Artifactory Vulnerabilities

Attackers are actively exploiting a chain of three critical vulnerabilities (CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329) in JFrog Artifactory to bypass authentication and achieve full administrative control.

exploited Artifactory supply-chain vulnerability authentication-bypass
3t 3c
high advisory

Stored XSS in Simple Ajax Chat WordPress Plugin via CVE-2026-81825

The Simple Ajax Chat plugin for WordPress contains a stored cross-site scripting vulnerability in versions <= 20260811, allowing unauthenticated attackers to inject malicious scripts due to exposed nonces and insufficient input sanitization.

Simple Ajax Chat – Add a Fast, Secure Chat Box xss web-security wordpress vulnerability
2t 1c
high advisory

Stored XSS in The Vigilant Security Plugin for WordPress

The Vigilant security plugin for WordPress version 2.10.2 and earlier is vulnerable to Stored Cross-Site Scripting via the User-Agent header, allowing unauthenticated attackers to execute arbitrary scripts in the dashboard.

The Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner… xss wordpress cve-2026-81754
1t 1c
high advisory

Arbitrary File Deletion in UsersWP WordPress Plugin

The UsersWP plugin for WordPress versions up to 1.2.70 allows authenticated attackers to delete arbitrary files on the web server via a path traversal vulnerability in the upload_file_remove() AJAX handler.

UsersWP
1r 1t 1c
high advisory

Stored XSS Vulnerability in WP Photo Album Plus Plugin

An unauthenticated stored XSS vulnerability in WP Photo Album Plus versions 9.2.08.003 and earlier allows attackers to inject malicious scripts via the HTTP_X_FORWARDED_FOR header, which is logged without sanitization.

WP Photo Album Plus web-application xss wordpress
1r 2t 1c
high advisory

SQL Injection Vulnerability in Unlimited Elements For Elementor

The Unlimited Elements For Elementor WordPress plugin contains an unauthenticated SQL injection vulnerability via the addontype parameter, allowing attackers to perform unauthorized database extraction.

Unlimited Elements For Elementor
1r 1t 1c
high advisory

SQL Injection in Sticky Chat Widget WordPress Plugin

The Sticky Chat Widget plugin for WordPress (<= 1.4.2) is vulnerable to unauthenticated SQL injection via the 'scw_save_form_data' AJAX action, allowing potential exfiltration of sensitive database information.

Sticky Chat Widget web-application-vulnerability sqli wordpress
1r 1t 1c
critical advisory

Unauthenticated Arbitrary File Upload in MIPL Grouped Checkout Fields for WooCommerce

The MIPL Grouped Checkout Fields plugin for WordPress is vulnerable to unauthenticated arbitrary file uploads via the mipl_wc_upload_file function, potentially resulting in remote code execution.

Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields wordpress file-upload rce web-application
2t 1c
high advisory

Path Traversal Vulnerability in AcyMailing WordPress Plugin

The AcyMailing WordPress plugin is vulnerable to unauthenticated directory traversal, allowing attackers to read arbitrary files on the server when the Embed images feature is enabled.

AcyMailing web-application vulnerability directory-traversal
1r 1t 1c
high advisory

Remote Code Execution Vulnerability in SAP Extended Passport Processing

A critical unauthenticated remote code execution vulnerability in the SAP Extended Passport (EPP) kernel component allows attackers to execute arbitrary system commands via RFC or HTTP communication layers.

SAP Kernel sap rce kernel vulnerability
2t
high advisory

SQL Injection in Pimcore CustomReportsBundle

An authenticated SQL injection vulnerability in Pimcore's CustomReportsBundle allows users with specific permissions to execute arbitrary database commands by bypassing a weak keyword blacklist.

Pimcore +2 sql-injection web-application cms
1r 2t