Skip to content
Threat Feed

May 2026 (30)

medium advisory

Google Workspace Drive Data Transfer or Takeout Export Initiated

This rule detects when Google Workspace administrators initiate bulk movement or export of user Drive data, including admin data transfer requests and Customer Takeout export jobs which can be abused by adversaries with administrative access to stage or exfiltrate sensitive files.

Google Workspace +1 google_workspace data_exfiltration cloud
2r 2t
critical threat

The Gentlemen Ransomware: Self-Propagating Go Encryptor

The Gentlemen ransomware, operated by Storm-2697 as a RaaS, employs a combination of strong per-file encryption with aggressive self-propagation to achieve broad network compromise, targeting Windows environments and using double extortion tactics.

Microsoft Defender Storm-2697 ransomware raas lateral-movement encryption
2r 4t
critical threat

CVE-2026-8380: WordPress Frontend File Manager Arbitrary Post Deletion

CVE-2026-8380 is a critical authorization bypass vulnerability in the WordPress Frontend File Manager plugin <= 23.6 that allows authenticated low-privilege users, or unauthenticated users with guest uploads enabled, to permanently delete arbitrary WordPress posts, pages, attachments, and custom post types.

Frontend File Manager cve wordpress authorization privilege-escalation arbitrary-deletion plugin-vulnerability
2r 1t
critical threat

Gogs Zero-Day Vulnerability Enables Remote Code Execution

An unpatched argument injection vulnerability in Gogs (versions 0.14.2 and 0.15.0+dev) allows authenticated attackers to achieve remote code execution (RCE) on vulnerable instances, potentially leading to complete server compromise.

exploited Gogs 0.14.2 +1 rce zero-day argument injection
2r 1t 5c
medium advisory

Zimbra Security Advisory Addresses Vulnerabilities in Zimbra Daffodil

Zimbra released a security advisory on May 28, 2026, addressing unspecified vulnerabilities in Zimbra Daffodil versions prior to v10.1.17, urging users to apply necessary updates.

Zimbra Daffodil < v10.1.17 zimbra vulnerability patch
2r
medium advisory

Google Workspace Device Registration Burst for Single User

Detects bursts of Google Workspace device registration events for a single user exceeding three distinct device registrations within one minute, indicative of AiTM phishing or stolen OAuth token replay attacks.

Google Workspace google_workspace device_registration persistence initial_access credential_access
1r 3t
medium advisory

Google Workspace User Sign-in from Atypical Device Type

This rule detects when a Google Workspace user authenticates from a device type that hasn't been observed for that user in the past 14 days, potentially indicating account compromise via AiTM kits or stolen OAuth refresh tokens.

Google Workspace google_workspace persistence account_compromise device_registration
2r 2t
critical advisory

Multiple Vulnerabilities in Veeam Products Allow Remote Code Execution

Multiple vulnerabilities in Veeam ONE and Service Provider Console allow remote code execution (CVE-2026-32998) and an unspecified security issue, potentially leading to complete system compromise.

ONE +1 veeam rce vulnerability
2r 1t 1c
medium advisory

Multiple Vulnerabilities in GitLab Lead to DoS and Security Policy Bypass

Multiple vulnerabilities in GitLab CE/EE allow attackers to cause remote denial of service and bypass security policies in versions 18.11.x before 18.11.4, 19.x before 19.0.1, and before 18.10.7; these vulnerabilities are tracked as CVE-2026-1402, CVE-2026-2601, CVE-2026-2710, CVE-2026-4868, CVE-2026-5296, CVE-2026-6713, and CVE-2026-8716.

GitLab Community Edition +1 gitlab vulnerability denial-of-service security-bypass CVE-2026-1402 CVE-2026-2601 CVE-2026-2710 CVE-2026-4868 +3
2r 2t 5c
critical advisory

NetApp Active IQ Unified Manager and OnCommand Insight Remote Code Execution Vulnerability

CVE-2023-22102 describes a vulnerability in NetApp Active IQ Unified Manager and OnCommand Insight that allows a remote attacker to execute arbitrary code.

Active IQ Unified Manager +3 rce netapp cve-2023-22102
2r 1t 1c
high advisory

Langflow Multiple Vulnerabilities Allow Remote Code Execution and Denial of Service

Multiple vulnerabilities in Langflow allow a remote, anonymous attacker to execute arbitrary code or cause a denial of service.

Langflow vulnerability rce dos
2r 2t
high advisory

Multiple Vulnerabilities in Linux Kernel Allow Privilege Escalation and Denial of Service

A local attacker can exploit multiple vulnerabilities in the Linux Kernel to escalate privileges, cause a denial-of-service condition, disclose sensitive information, or perform an unspecified attack.

linux kernel linux kernel privilege-escalation denial-of-service
2r 3t
medium advisory

AWS S3 Credential File Retrieved from Bucket

This rule detects successful S3 GetObject calls targeting high-value credential and secret files commonly stored in S3 buckets, indicating potential credential access.

Amazon S3 credential-access cloud aws
2r 2t
critical threat

Multiple Vulnerabilities in Jenkins Plugins

Multiple vulnerabilities exist in Jenkins Plugins that could allow an attacker to disclose information, manipulate files, conduct cross-site scripting attacks, execute arbitrary code, and bypass security measures.

Jenkins Plugins jenkins vulnerability xss code-execution
3r 4t
high threat

2026 FIFA World Cup: Cyber Threats and Attack Surface Analysis

The 2026 FIFA World Cup faces significant cyber threats from ransomware groups, state-aligned entities like Iran-nexus Handala Hack Team and Russia-nexus NoName057(16), and financially motivated cybercriminals, anticipating disruptive intrusions, large-scale criminal fraud, and politically driven DDoS and hack-and-leak operations targeting fans, hospitality services, and tournament infrastructure.

programmable logic controllers +5 Handala Hack Team 2026 World Cup cybersecurity threat intelligence ransomware DDoS phishing
2r 3t
high advisory

DICOM Heap Overflow in Orthanc Server

A heap overflow vulnerability exists within the DICOM file format, potentially allowing an attacker to target an Orthanc server during image uploads, leading to an out-of-bounds write.

Orthanc +2 dicom heap overflow medical imaging
2r
high advisory

KubeVirt virt-exportserver Path Traversal Vulnerability (CVE-2026-9804)

A path traversal vulnerability exists in KubeVirt's virt-exportserver component, where an attacker with namespace-level access can exploit this flaw by creating a symbolic link within an exported filesystem PVC to read arbitrary files from the exporter pod, leading to information disclosure.

virt-exportserver kube-virt path-traversal vulnerability cloud
2r 1t 1c
critical advisory

CVE-2026-6226 - Frontend Admin WordPress Plugin Unauthenticated Privilege Escalation

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthenticated privilege escalation in versions up to and including 3.29.2, allowing attackers to create administrator accounts by injecting a custom form configuration with a spoofed role field.

Frontend Admin by DynamiApps plugin for WordPress <= 3.29.2 cve wordpress privilege-escalation unauthenticated
2r 1t 1c
critical threat

CVE-2026-4408: Samba Remote Command Execution via Misconfigured Password Check Script

CVE-2026-4408 describes a remote command execution vulnerability in Samba file servers and classic domain controllers where a misconfigured 'check password script' feature, using the %u substitution character without proper escaping, allows attackers to execute arbitrary commands.

Samba cve rce
2r 1t 1c
high advisory

CVE-2026-9227: GutenBee WordPress Plugin Arbitrary File Upload

The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to arbitrary file upload, allowing authenticated attackers with author-level access to achieve remote code execution by uploading executable files with double extensions.

GutenBee – Gutenberg Blocks plugin <= 2.20.1 arbitrary-file-upload remote-code-execution wordpress
2r 1c
high advisory

CVE-2026-7797: WordPress Simply Schedule Appointments Plugin Time-Based Blind SQL Injection

The Appointment Booking Calendar WordPress plugin is vulnerable to time-based blind SQL Injection (CVE-2026-7797) via the 'append_where_sql' parameter, allowing unauthenticated attackers to extract sensitive information from the database by injecting SQL queries through the /appointments/bulk REST endpoint with a specific request format.

Appointment Booking Calendar - Simply Schedule Appointments Booking Plugin wordpress sqli cve-2026-7797 attack.initial_access
2r 1t 1c
medium advisory

WordPress SlimStat Analytics Plugin Stored XSS Vulnerability (CVE-2026-7634)

The SlimStat Analytics plugin for WordPress is vulnerable to stored cross-site scripting (XSS) via the User-Agent header, allowing unauthenticated attackers to inject arbitrary web scripts if the 'show_complete_user_agent_tooltip' setting is enabled.

SlimStat Analytics plugin <= 5.4.11 cve xss wordpress
2r 1t 1c
medium advisory

HT Contact Form WordPress Plugin Vulnerable to Stored XSS (CVE-2026-7052)

The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting (CVE-2026-7052) via the 'file_upload' parameter in versions up to 2.8.2, allowing unauthenticated attackers to inject arbitrary web scripts.

HT Contact Form – Drag & Drop Form Builder for WordPress plugin <= 2.8.2 stored-xss wordpress plugin CVE-2026-7052
2r 1t 1c
high threat

WP Contact Form 7 DB Handler Plugin CSRF leading to Arbitrary File Deletion (CVE-2026-6455)

The WP Contact Form 7 DB Handler plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF), leading to arbitrary file deletion via SQL injection and PHP object injection due to missing nonce verification and unsafe deserialization, allowing attackers to delete arbitrary files on the server.

WP Contact Form 7 DB Handler plugin cve csrf sqli php object injection wordpress
2r 3t 1c
high advisory

CVE-2026-44604: RPM rpmuncompress Command Injection Vulnerability

A command injection vulnerability (CVE-2026-44604) exists in the `rpmuncompress` utility of RPM; when extracting specially crafted ZIP, 7z, or GEM archives, an attacker can inject shell commands via a malicious top-level folder name, leading to arbitrary code execution as the user running the extraction.

RPM command-injection CVE-2026-44604 archive-extraction linux
2r 1t 1c
medium threat

Apache Tika Vulnerability Allows Information Disclosure or Manipulation

A remote, anonymous attacker can exploit a vulnerability in Apache Tika to read sensitive data or trigger malicious requests to internal resources or third-party servers.

Tika apache-tika vulnerability infoleak
2r 1t
medium threat

VMware Tanzu Spring Framework Denial of Service Vulnerability

A remote, anonymous attacker can exploit a vulnerability in VMware Tanzu Spring Framework to perform a denial of service attack.

Tanzu Spring Framework denial-of-service vmware tanzu
1r 1t
medium advisory

VMware Tanzu Spring Security Vulnerability Allows File Manipulation

A local attacker can exploit a vulnerability in VMware Tanzu Spring Security to manipulate files, potentially leading to privilege escalation.

Tanzu Spring Security vulnerability file-manipulation privilege-escalation
2r 1t
medium advisory

Multiple Vulnerabilities in Vim Could Lead to Arbitrary Code Execution or Denial of Service

Multiple vulnerabilities in Vim could allow an attacker to execute arbitrary code or cause a denial of service condition.

vim vulnerability code-execution denial-of-service
2r 3t
medium advisory

IBM DB2 Multiple Vulnerabilities Leading to Denial of Service

A remote, authenticated attacker can exploit multiple vulnerabilities in IBM DB2 to perform a denial of service attack, potentially disrupting database services.

DB2 denial-of-service
2r 1t