mitre-ta0040
762 articles with this tag
HIGH
CRITICAL
HIGH
HIGH
CRITICAL
CRITICAL
CRITICAL
MEDIUM
CRITICAL
HIGH
MEDIUM
MEDIUM
CRITICAL
CRITICAL
MEDIUM
MEDIUM
HIGH
CRITICAL
HIGH
HIGH
MEDIUM
HIGH
CRITICAL
HIGH
MEDIUM
HIGH
HIGH
HIGH
CRITICAL
HIGH
CRITICAL
HIGH
HIGH
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
MEDIUM
CRITICAL
CRITICAL
CRITICAL
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
HIGH
CRITICAL
HIGH
CRITICAL
HIGH
CRITICAL
HIGH
HIGH
HIGH
MEDIUM
HIGH
CRITICAL
HIGH
HIGH
CRITICAL
CRITICAL
HIGH
LOW
CRITICAL
MEDIUM
HIGH
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
MEDIUM
HIGH
CRITICAL
CRITICAL
CRITICAL
CRITICAL
HIGH
HIGH
CRITICAL
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
JetBrains says a crafted HTTP request could break TeamCity
Microsoft confirms an AI worm is propagating through Copilot and other MS apps
A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran
WordPress Core Unauthenticated RCE (WP2Shell)
VU#281278: SGLang contains six different vulnerabilities including RCE, data exfiltration, and credential disclosure
KindaRails2Shell: arbitrary file read to RCE in Rails Active Storage via libvips (CVE-2026-66066)
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Russian spies take their half-click email attack from Zimbra to Outlook
Iran-linked CyberAv3ngers suspected in attacks on Minnesota water systems
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks
Coordinated “cyberattack” on Minnesota water utilities: What you need to know
Arista patches maximum severity vulnerability that is already being exploited
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
PTC Windchill & FlexPLM RCE
Chaos in Teams vishing
Coca-Cola Reveals Subsidiary Fairlife Suffered Data Breach
Coca-Cola confirms hackers stole data in Fairlife ransomware attack
Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack
The Signs Were There: What the First Autonomous Ransomware Case Confirms
Ransomware Attacks Targeting Universities on the Rise
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
CVE-2026-63136 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
Ransomware Attack Puts a Chill On Japanese Frozen-Food Chain
NuGet typosquat targets Digitain game results
wp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command execution
GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware
JADEPUFFER agentic ransomware returns, targets AI assets with ENCFORGE payload
JadePuffer returns with ransomware built to target AI models and infrastructure
A new extortion cocktail: office printers, small ransoms, and BitLocker
JadePuffer Returns With Ransomware Designed to Wipe AI Models
wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core
Coca-Cola's Fairlife dairy subsidiary hit by ransomware attack, suspending US production
Government Agencies Falling Victim to Ransomware Daily, Warns Study
Spirals ransomware locks down victim systems in under 24 hours
Ransomware attack halts Coca-Cola’s Fairlife US milk production
Joomla SP Page Builder RCE
Attackers execute a complete ransomware operation in under 24 hours
VU#885548: Denial-of-service vulnerability in HTTP/2 servers via stalled flow-control conditions
SonicWall customers under threat as attackers exploit 2 zero-days
CVE-2026-15409, CVE-2026-15410: SonicWall SMA 1000 zero-day vulnerabilities exploited in the wild
(More) Unauthenticated Arbitrary Code Execution in ServiceNow
CVE-2026-50653 Azure Active Directory Denial of Service Vulnerability
CVE-2026-49788 HTTP/2 Denial of Service Vulnerability
Hacker Extradited from Ukraine Pleads Guilty to Ryuk Ransomware Charges
Armenian man pleads guilty to deploying Ryuk ransomware
Armenian national pleads guilty to Ryuk ransomware attacks
Destructive Windows backdoor stuffs multiple wipers and ransomware code into a single package
Microsoft Warns New 'GigaWiper' Malware Combines Espionage and Destructive Capabilities
This new Windows malware can take over your PC and wipe it clean
Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks
GigaWiper Combines Multiple Malware for System-Level Sabotage
Microsoft uncovers GigaWiper, a backdoor designed for destruction on demand
Microsoft details GigaWiper destructive backdoor assembled from older tools
Mount Royal University hit by ransomware attack, data stolen and deleted
Ubiquiti UniFi OS RCE
New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware
GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware
VU#734812: Xerte Online Toolkit contains an authentication bypass that allows for RCE
Mount Royal University Confirms Data Stolen in Ransomware Attack
North Korean PolinRider supply chain attack targets 108 unique repos
This AI agent autonomously hacked a network, adapted on the fly, and demanded a ransom
Warning Over “Industrialized” Cyber-Attacks After Ransomware Gang Partners With TeamPCP
Ctrl+Alt+Oops: FortiBleed criminal's logins stitch two gangs together
Microsoft said exploitation was 'less likely' ... but CISA just added SharePoint RCE to KEV list
FortiBleed Campaign Linked to INC, Lynx Ransomware Attacks
Cybercriminals Pose as Interpol in Phishing Emails to Infect Victims With Ransomware
‘Interpol’ emails spread custom ransomware with decryption key left inside
AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack
Catching ransomware on the wire before it locks the file server
Sandbox bypass flaws in Cursor IDE highlight prompt injection as an RCE vector
Critical SimpleHelp Vulnerability Exploited For Malware Delivery
BlueHammer Vulnerability Exploited in Ransomware Attacks
Over 300 UK Firms Hit by Ransomware in a Year
Russian Hackers Accused of Destructive Cyber-Attack on Jaguar Land Rover
Major Increase in Ransomware Attacks Targeting Europe, Warns New Report
Europol-Led Operation Endgame Takes Down StealC and Amadey Infostealers
Exploitable CI/CD Vulnerabilities Expose Millions of Repositories to Hijacking
FFmpeg fixes PixelSmash flaw in widely used video decoder
New Prinz Eugen ransomware targets recent files, avoids ransom notes
INTERPOL Warns Phishing, Ransomware, and AI Scams Are Rising Across Asia-Pacific
Chaining Security Bugs in Discuz! X5.0: from Race Condition to Pre-Auth RCE
Google’s Vertex AI SDK could allow RCE through bucket squatting
npm Supply Chain Cryptocurrency Malware
Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE
Mackay Sugar hit by cyberattack during crucial processing season
Ransomware Attack Shuts Down Mills of Australia’s Second-Largest Sugar Producer
Ukrainian national pleads guilty in connection with Conti ransomware
Ukrainian Man Pleads Guilty in US to Conti Ransomware Charges
Ukrainian national pleads guilty to role in Conti ransomware operation
ShinyHunters is actively extorting universities after exploiting an unpatched Oracle flaw
Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)
The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm
Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS
Miasma Supply Chain Worm Burrows Into 73 Microsoft Repositories
Microsoft investigates breach of open-source projects after malware injection
New Veeam vulnerability exposes backup servers to RCE attacks