- Cyber Threat Intelligence, Trending Vulnerabilities List
HVL – High-Risk Vulnerabilities List – Aug 7 to Aug 21
Top 10 critical flaws in Cisco, Fortinet, Trend Micro, WinRAR, PostgreSQL & VirtualBox. Several actively exploited — patch now.
- Cyber Threat Intelligence, Vulnerability Notification
VN Extraordinary – WinRAR
A critical WinRAR for Windows flaw is being exploited by the Russian RomCom group in spear-phishing campaigns, enabling system compromise simply by extracting files.
- Cyber Threat Intelligence, Intelligence Bulletin
Intelligence Bulletin – Tycoon 2FA: AiTM Attacks via Quishing Compromise MFA in Brazilian Companies
Sophisticated QR-based phishing is bypassing MFA and hijacking corporate sessions. A growing threat to organizations.
- Cyber Threat Intelligence, Vulnerability Notification
VN Extraordinary – Trend Micro Apex One
Two critical flaws in Trend Micro Apex One are under active exploitation, allowing unauthenticated remote code execution. No official patch yet, but a mitigation tool is available.
- News
Extraordinary VN – SonicWall SMA 100 Series
Vulnerability CVE-2025-40599 (CVSS 9.1) allows arbitrary file upload, leading to remote code execution and enabling advanced attacks like OVERSTEP malware from UNC6148.
- Cyber Threat Intelligence, Vulnerability Notification
VN Extraordinary – Sophos Firewall
Sophos Firewall hit by 5 critical vulnerabilities! Flaws allow pre-auth remote code execution, SQL and command injection, impacting environments with HA and SPX enabled.
- Cyber Threat Intelligence, Notificação de Vulnerabilidades OT/ICS
Monthly OT‑ICS VN – July/2025
Discover the main vulnerabilities that could compromise your industrial systems this month. The VN provides crucial guidance to strengthen OT security and prevent attacks.
- Emergency Announcement
Extraordinary NDV – Microsoft Sharepoint
This NVD alerts about Microsoft Sharepoint published in july 25, 2025.
- Cyber Threat Intelligence, Vulnerability Notification
Extraordinary NDV – Cisco Identity Services Engine (ISE)
This NDV alerts about a critical flaw in Cisco ISE and guides urgent actions to prevent exploitation.