CPE
Denial of Service Vulnerability in Red Hat Enterprise Linux opentelemetry-collector
1 TTP 1 CVEA vulnerability in the opentelemetry-collector package within Red Hat Enterprise Linux allows a remote, unauthenticated attacker to trigger a denial of service condition, potentially disrupting monitoring and telemetry data collection services.
Remote Code Execution Vulnerability in WebKitGTK
1 TTP 1 CVEA memory corruption vulnerability in WebKitGTK allows a remote, unauthenticated attacker to execute arbitrary code or trigger a denial-of-service condition by processing maliciously crafted web content.
Malicious Packagist Composer Themes Deploying iOS Spyware
4 TTPs 2 CVEs 1 IOCThreat actors are distributing 13 malicious Composer themes via Packagist to compromise streaming websites and deploy a WebKit-to-kernel exploit chain against iOS visitors for data exfiltration and cryptocurrency wallet theft.
Vulnerabilities in Nokogiri Vendored libxml2 and libxslt Libraries
3 CVEsNokogiri versions prior to 1.13.2 bundle vulnerable libxml2 2.9.12 and libxslt 1.1.34 libraries, exposing applications to denial of service, memory disclosure, and potential code execution.
Remote Code Execution Vulnerability in zlib
1 TTP 1 CVEA memory corruption vulnerability in the zlib library allows a remote, unauthenticated attacker to execute arbitrary code or trigger a denial of service.
Multiple Vulnerabilities in Apple macOS Tahoe
1 CVEMultiple memory management and web content processing vulnerabilities in Apple macOS Tahoe version 26.6.2 could allow attackers to trigger system crashes or exfiltrate sensitive memory data.
Cross-Site Scripting Vulnerability in IBM App Connect Enterprise
1 TTP 1 CVEIBM App Connect Enterprise contains a vulnerability, identified as CVE-2024-44280, that allows a remote, anonymous attacker to execute Cross-Site Scripting (XSS) attacks within the context of the affected application.
Apple Security Updates — July 2026
4 CVEs 10 IOCsRoundup of Apple security advisories published in July 2026.
CVE-2024-23222 Apple Safari Type Confusion Leading to Sandbox Escape
2 rules 2 TTPs 1 CVE 1 IOCA type confusion vulnerability exists in Apple Safari, as detailed in CVE-2024-23222. A public exploit demonstrates successful exploitation of the vulnerability on iOS 16.4.1, leading to a sandbox escape, which has been patched in iOS 17.3 and macOS 14.3.