Storm-1567
| CVE-2025-55182 suspected | A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints. | CVSS 10.0 KEVransomware |
| CVE-2024-55591 suspected | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module. | CVSS 9.8 KEVransomware |
| CVE-2024-40766 suspected | SonicWall SonicOS contains an improper access control vulnerability that could lead to unauthorized resource access and, under certain conditions, may cause the firewall to crash. | KEVransomware |
| CVE-2025-32433 suspected | Erlang Erlang/OTP SSH server contains a missing authentication for critical function vulnerability. This could allow an attacker to execute arbitrary commands without valid credentials, potentially leading to unauthenticated remote code execution (RCE). By exploiting a flaw in how SSH protocol messages are handled, a malicious actor could gain unauthorized access to affected systems. This vulnerability could affect various products that implement Erlang/OTP SSH server, including—but not limited to—Cisco, NetApp, and SUSE. | KEV |
| CVE-2025-33073 suspected | Microsoft Windows SMB Client contains an improper access control vulnerability that could allow for privilege escalation. An attacker could execute a specially crafted malicious script to coerce the victim machine to connect back to the attack system using SMB and authenticate. | KEV |
| CVE-2025-7771 suspected | — |
| No Manners Here: The Ruthless Rise of The Gentlemen Ransomware | matched as Howling Scorpius | 2026-07-10 |
| Tune In: The Future of AI-Powered Vulnerability Discovery | matched as PUNK SPIDER | 2026-05-01 |
| Nowhere, man: The 2026 Active Adversary Report | matched as Gold Sahara | 2026-02-24 |
| Russian Ransomware Gangs Weaponize Open-Source AdaptixC2 for Advanced Attacks | matched as Akira | 2025-10-31 |