NATHANIELPETTUSCYBER INTELLIGENCE
NEW POST DAILY
DAILY CYBER BLOG · FACTS + OPINION

Know what happened.
Know where I stand.

I explain cybersecurity news, active attacks, privacy, surveillance technology, vulnerabilities, and OSINT in plain English, then give my independent analysis.

GLOBAL THREAT ACTIVITYPREVIEW
World map preview with representative activity markersNorth AmericaEuropeMiddle EastEast AsiaOceania
Representative preview—not live observations. Open the Live Threat Center for sourced data and map limitations.
LIVE THREAT FEED

Actively exploited vulnerabilities

Current entries from CISA’s official Known Exploited Vulnerabilities catalog. These are confirmed weaknesses attackers have used, not simulated attack-map traffic.

REFRESHES EVERY 15 MINUTES
ACTIVE EXPLOITATION

CVE-2015-5477: ISC BIND

ISC BIND Data Processing Errors Vulnerability

ISC BIND contains a data processing errors vulnerability that could allow remote attackers to cause a denial of service via TKEY queries.
ACTIVE EXPLOITATION

CVE-2016-3081: Apache Struts

Apache Struts Command Injection Vulnerability

Apache Struts contains a command injection vulnerability that could allow remote attackers to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled.
ACTIVE EXPLOITATION

CVE-2023-22894: Strapi Strapi

Strapi Cleartext Storage of Sensitive Information Vulnerability

Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. This vulnerability can be chained with CVE-2023-22621 to achieve remote code execution.
ACTIVE EXPLOITATION

CVE-2021-3199: ONLYOFFICE Docs

ONLYOFFICE Docs Server Path Traversal Vulnerability

ONLYOFFICE Docs contains a path traversal vulnerability that can occur when JWT is used, via a /.. sequence in an image upload parameter and could allow for remote code execution.
ACTIVE EXPLOITATION

CVE-2015-3306: ProFTPD ProFTPD

ProFTPD Improper Access Control Vulnerability

ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
ACTIVE EXPLOITATION

CVE-2026-88779: Citrix NetScaler

Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for a denial of service.
VIEW THE OFFICIAL CISA CATALOG

“Live” means the feed updates from current public reporting. It does not identify every attack or prove the physical location of an attacker.

CHOOSE WHAT YOU NEED

You do not need a cybersecurity background.

Each section answers a different question. Start with the one that sounds most useful to you.

LATEST BLOG POST

The newest story, explained and analyzed.

IMPORTANT UPDATE

8,547 European wind and solar systems exposed online, researchers find

Joint research from Modat and the Dutch National Cyber Security Centre identified 8,547 internet-facing systems linked to European solar parks and wind farms. Most were administrative or login pages, but researchers believe about 181 sites may have exposed operational control.

READ THE FULL POST & OPINION
HOW POSTS ARE ORGANIZED

Every post separates reporting from opinion.

  1. 1What happened?A clear summary of confirmed facts.
  2. 2How does it work?Technical context without unnecessary jargon.
  3. 3My analysisA direct opinion, clearly labeled.
  4. 4What should happen next?Practical action and accountability.