Skip to content
Threat Feed

Vendor

Zoom

13 briefs RSS
critical threat

CVE-2026-63030: Critical Remote Code Execution Vulnerability in WordPress Core

CVE-2026-63030 is a critical unauthenticated remote code execution vulnerability affecting WordPress Core versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1, allowing an unauthenticated attacker to execute arbitrary code via the WordPress REST API batch endpoint, potentially leading to complete website compromise.

exploited PoC WordPress Core 6.9.0 +51 wordpress rce web-vulnerability cve
2t 15c 8i updated
high advisory

Splunk Enterprise and Cloud Platform CSRF Vulnerability Leading to Arbitrary SPL Execution (CVE-2026-20296)

A Cross-Site Request Forgery (CSRF) vulnerability, identified as CVE-2026-20296, in Splunk Enterprise and Splunk Cloud Platform allows an attacker to trick a user with the `list_deployment_server` capability into executing arbitrary Search Processing Language (SPL) searches as the highly privileged `splunk-system-user`, potentially leading to unauthorized access of stored credentials and indexed data due to a lack of CSRF token validation and improper input neutralization.

Splunk Enterprise < 9.4.13 +14 splunk vulnerability csrf remote-code-execution credential-access data-exfiltration web-vulnerability
4t 3c updated
low advisory

Potential Proxy Execution via Systemd-run on Linux

This brief details how attackers may leverage the `systemd-run` utility on Linux systems for defense evasion and execution by running commands as detached, transient services or scopes to obscure their activities and parent-child process chains.

Acronis Cyber Protect +46 defense-evasion execution linux
1r 3t
high advisory

ClickFix Campaign Activity

Tracking brief for the ClickFix campaign; individual sightings are folded in as reported.

PoC open source packages +36 campaign clickfix
16i updated
high threat

Nimbus Manticore Resurfaces During Operation Epic Fury with New Techniques

Nimbus Manticore, an Iranian IRGC-affiliated threat actor, resurfaced during Operation Epic Fury, employing AppDomain Hijacking, SEO poisoning, and a new MiniFast backdoor while targeting the aviation and software sectors.

Setup.exe +3 Nimbus Manticore nimbus-manticore irgc appdomain-hijacking seo-poisoning minijunk minifast infostealer
2r 3t
high advisory

Zoom-themed Phishing Campaign Delivering ConnectWise ScreenConnect

A phishing campaign impersonates Zoom to trick users into downloading and installing ConnectWise ScreenConnect, a legitimate remote monitoring and management tool, allowing attackers to gain persistent remote access, harvest credentials, and deploy secondary malware such as ransomware.

Zoom +2 phishing remote_access social_engineering screenconnect
2r 5t 4i
medium advisory

Suspicious Child Processes from Communication Applications

The detection rule identifies suspicious child processes spawned from communication applications on Windows systems, potentially indicating masquerading or exploitation of vulnerabilities within these applications.

Elastic Defend +12 defense-evasion persistence windows
3r 3t
medium advisory

Zoom Meetings Created Without Passcodes

Detection of Zoom meetings created without a passcode, which are susceptible to Zoombombing and potential disruption or exposure of sensitive information.

Zoom Meetings zoom initial-access configuration-audit zoombombing
2r 2t
medium advisory

Suspicious Zoom Child Process Activity

The spawning of command interpreters (cmd.exe, powershell.exe, pwsh.exe) as child processes of Zoom.exe is indicative of potential exploitation or malicious masquerading, allowing attackers to execute arbitrary commands within the context of the Zoom application.

Zoom masquerading process-injection defense-evasion
2r 5t
medium advisory

Zoom High Video Latency Potentially Indicating Remote Employment Fraud

This analytic identifies Zoom users exhibiting high video latency, a potential indicator of Remote Employment Fraud (REF), by analyzing Zoom logs for average and overall latency and highlighting users with latency exceeding 300ms.

Zoom remote-employment-fraud identity
2r 1t 1i
critical threat

Zoom macOS Client Privilege Escalation Vulnerability

Zoom's macOS client contains a local privilege escalation vulnerability that allows an unprivileged attacker to gain root privileges by subverting the runwithroot script, due to the insecure use of the deprecated AuthorizationExecuteWithPrivileges API.

Zoom Client for Mac +1 privilege-escalation macos zoom
2r 1t
high advisory

Geographic Improbable Location Detection

Detection of user logins originating from geographically distant locations within a short timeframe, indicative of potential Remote Employment Fraud or compromised credentials.

Workday +6 remote-employment-fraud credential-compromise okta
2r 1t
medium advisory

Masquerading Business Application Installers

Attackers masquerade malicious executables as legitimate business application installers to trick users into downloading and executing malware, leveraging defense evasion and initial access techniques.

Elastic Defend +22 masquerading defense-evasion initial-access malware windows
2r 4t