Skip to content
Threat Feed

CRAFTEDSIGNAL THREAT INTELLIGENCE FEED

Threat intelligence feed for SOC and IR teams

Fresh threat briefs from the CraftedSignal pipeline, with MITRE ATT&CK coverage, CVE references, rule metadata, and IOCs when available. Full rule logic and test data stay inside the platform; this feed shows what is changing now.

Recent activity

1712 briefs
57.1 briefs/day
40.3 vulns/day
9.1 crits/day
Jul 6 crits vulns Aug 4

Latest briefs

View all →
medium advisory

Vulnerabilities in MISP cti-transmute

The MISP project has patched multiple security vulnerabilities in the cti-transmute tool, including arbitrary file/network access and improper authorization controls for user management.

cti-transmute vulnerability misp patch-management
3i
high advisory

Unrestricted File Upload Vulnerability in ResponsiveFilemanager

A publicly disclosed, unpatched unrestricted file upload vulnerability in Trippo ResponsiveFilemanager up to version 9.14.0 allows remote attackers to execute arbitrary code.

ResponsiveFilemanager
1r 1t 1c
critical threat

Improper Access Control in Atlas-Livre Admin Controllers

An unauthenticated access control flaw in Atlas-Livre allows attackers to bypass authentication and execute privileged database operations due to a failure to terminate script execution following HTTP redirects.

exploited Atlas-Livre vulnerability web-application cve-2026-69703
1r 2t 1c
high advisory

Security Updates for cPanel and WP Squared

WebPros has issued a security advisory addressing HTTP request smuggling and database privilege escalation vulnerabilities in cPanel and WP Squared products.

WP Squared +1 web-application-vulnerability vulnerability-management
2c
high advisory

Command Injection Vulnerability in GL.iNet AX1800 RPC Endpoint

An authenticated remote command injection vulnerability in the RPC component of GL.iNet AX1800 routers (firmware <= 4.8.3) allows attackers to execute arbitrary system commands via the 'remove_rule' function.

AX1800
1t 1c
critical advisory

Unauthenticated Remote Code Execution in kotaemon

An insecure deserialization vulnerability (CVE-2026-69098) in the kotaemon check_connection endpoint allows unauthenticated attackers to achieve remote code execution by injecting malicious __type__ fields.

kotaemon
1r 2t 1c
high advisory

Flowise Broken Access Control in /api/v1/files

A broken access control vulnerability in Flowise versions 3.1.2 and earlier allows authenticated users with low-privileged API keys to list and delete files across different workspaces within the same organization.

Flowise
1r 1t 1c
critical advisory

Flowise Unauthenticated RCE via Environment Variable Bypass

Flowise v3.1.2 and earlier are vulnerable to unauthenticated remote code execution because the CVE-2025-8943 patch relies on an incomplete environment variable blocklist, allowing attackers to inject configuration variables that force arbitrary package installation.

Flowise +4 rce injection cve-2026-69263 python-injection authentication-bypass oauth cve-2026-70478 web-vulnerability +7
6r 11t 2c
high advisory

Flowise Sandbox Escape to Remote Code Execution

Authenticated attackers can exploit an insecure JavaScript sandbox configuration in FlowiseAI to execute arbitrary system commands via a chained injection and path traversal payload.

Flowise +1
2t 1c
high advisory

Hard-Coded Cryptographic Key in Acrisure KARR BT and DR-100

A hard-coded cryptographic key vulnerability (CVE-2026-18411) in Acrisure KARR BT and DR-100 automotive anti-theft systems allows nearby attackers to issue unauthorized commands to vehicles.

KARR BT +1 ics transportation-security bluetooth vulnerability
1t
medium advisory

Integrity Vulnerability in Thermo Fisher Genetic Analyzer Software

Thermo Fisher Applied Biosystems Genetic Analyzer software lacks integrity checks for output data files, enabling local users to modify DNA analysis results (CVE-2026-17583).

Applied Biosystems 3500/3500xL Series Data Collection Software +7
high advisory

Unauthenticated Remote Code Execution in Perspective 5.0.0

Perspective version 5.0.0 is vulnerable to unauthenticated remote code execution via unsafe Python eval() calls within the PolarsVirtualServer backend triggered by crafted protobuf messages.

Perspective remote-code-execution cve-2026-67195 denial-of-service vulnerability CVE-2026-67198
3t 3c