Storm-1567
| CVE-2025-55182 suspected | A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints. | CVSS 10.0 KEVransomware |
| CVE-2024-40766 suspected | An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions. | CVSS 9.8 KEVransomware |
| CVE-2024-55591 suspected | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module. | CVSS 9.8 KEVransomware |
| CVE-2025-32433 suspected | Erlang Erlang/OTP SSH server contains a missing authentication for critical function vulnerability. This could allow an attacker to execute arbitrary commands without valid credentials, potentially leading to unauthenticated remote code execution (RCE). By exploiting a flaw in how SSH protocol messages are handled, a malicious actor could gain unauthorized access to affected systems. This vulnerability could affect various products that implement Erlang/OTP SSH server, including—but not limited to—Cisco, NetApp, and SUSE. | KEV |
| CVE-2025-33073 suspected | Microsoft Windows SMB Client contains an improper access control vulnerability that could allow for privilege escalation. An attacker could execute a specially crafted malicious script to coerce the victim machine to connect back to the attack system using SMB and authenticate. | KEV |
| CVE-2025-7771 suspected | — |
| md5 | 61a1ad1b6a028a1833c85e6544383999 | — | 2026-09-11 |
| sha256 | e2356c742c74cce5c6b6100162d0071a3f71e2fed2ed895c2011061a95b3299a | — | 2026-09-11 |
| sha1 | bb6f97878c8cbf762d69717b3480658fe9157ff0 | — | 2026-09-11 |
| sha256 | 414b9985f46714f44dd1bd63860d2a48dcfababcfe5c712a4b4f575378127a56 | — | 2026-09-11 |
| ip | 72.23.77.35 | — | 2026-08-13 |
| No Manners Here: The Ruthless Rise of The Gentlemen Ransomware | matched as Howling Scorpius | 2026-07-10 |
| Tune In: The Future of AI-Powered Vulnerability Discovery | matched as PUNK SPIDER | 2026-05-01 |
| Nowhere, man: The 2026 Active Adversary Report | matched as Gold Sahara | 2026-02-24 |
| Russian Ransomware Gangs Weaponize Open-Source AdaptixC2 for Advanced Attacks | matched as Akira | 2025-10-31 |