I explain cybersecurity news, active attacks, privacy, surveillance technology, vulnerabilities, and OSINT in plain English, then give my independent analysis.
Representative preview—not live observations. Open the Live Threat Center for sourced data and map limitations.
LIVE THREAT FEED
Actively exploited vulnerabilities
Current entries from CISA’s official Known Exploited Vulnerabilities catalog. These are confirmed weaknesses attackers have used, not simulated attack-map traffic.
Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.
F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution.
ACTIVE EXPLOITATION
CVE-2026-93616: Check Point Multiple Products
Check Point Multiple Products Path Traversal Vulnerability
Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts.
ACTIVE EXPLOITATION
CVE-2026-85102: Check Point Multiple Products
Check Point Multiple Products Improper Certificate Validation Vulnerability
Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
ACTIVE EXPLOITATION
CVE-2026-7273: Zyxel GS1900 Series Switches
Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability
Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.
ACTIVE EXPLOITATION
CVE-2025-39964: Linux Kernel
Linux Kernel Race Condition Vulnerability
Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state.
ShinyHunters claims FBIJobs.gov breach and theft of FBI personnel data
The FBI says it is investigating claimed unauthorized activity affecting FBIJobs.gov. Reuters partially verified details in a sample attributed to ShinyHunters, but could not establish the data's source or confirm theft from FBI internal systems.