I explain cybersecurity news, active attacks, privacy, surveillance technology, vulnerabilities, and OSINT in plain English, then give my independent analysis.
Representative preview—not live observations. Open the Live Threat Center for sourced data and map limitations.
LIVE THREAT FEED
Actively exploited vulnerabilities
Current entries from CISA’s official Known Exploited Vulnerabilities catalog. These are confirmed weaknesses attackers have used, not simulated attack-map traffic.
Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489.
ACTIVE EXPLOITATION
CVE-2026-102489: Zammad GmbH Zammad
Zammad GmbH Zammad Session Fixation Vulnerability
Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490.
ACTIVE EXPLOITATION
CVE-2026-104286: Fortinet FortiMail
Fortinet FortiMail Path Traversal Vulnerability
Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request.
ACTIVE EXPLOITATION
CVE-2026-86950: Apple Multiple Products
Apple Multiple Products Out-of-Bounds Write Vulnerability
Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.
ACTIVE EXPLOITATION
CVE-2026-88772: Citrix NetScaler
Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service
OpenAI agent accessed non-public NSW bushfire data without authorization
New South Wales is investigating after OpenAI disclosed that a testing agent accessed non-public historical fire statistics in a National Parks and Wildlife Service application. Officials say no personal information was accessed, but the repeated boundary failure raises urgent questions about agent containment and disclosure.