GhostEmperor
| CVE-2026-48842 suspected | Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass. | CVSS 8.1 |
| CVE-2026-87902 suspected | An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE. | CVSS 8.1 KEV |
| CVE-2026-42542 suspected | TDengine is an open source, time-series database optimized for Internet of Things devices. In versions 3.4.0.0 through 3.4.1.5, an unauthenticated remote attacker can crash the taosd server process by sending a single crafted RPC packet. No credentials or prior session state are required. Version 3.4.1.6 fixes the issue. | CVSS 7.5 |
| domain | third-party.com | — | 2026-09-25 |
| ip | 38.60.224.235 | — | 2026-09-18 |
| ip | 27.102.113.240 | — | 2026-09-18 |
| sha1 | 76c430b55f180a85f4e1a1e40e4a2ea37db97599 | — | 2026-09-18 |
| sha1 | cc350ba25947b7f9ec5d11ea8269407c0fd74095 | — | 2026-09-18 |
| sha1 | e2b0851e2e281cc7bca3d6d9b2fa0c4b7ac5a02b | — | 2026-09-18 |
| ip | 38.60.241.127 | — | 2026-09-18 |
| sha1 | bb2f5b573ac7a761015daad0b7ff03b294dc60f6 | — | 2026-09-18 |
| sha1 | ebc93a546bcdf6cc1eb61d7174bcb85407bbd892 | — | 2026-09-18 |
| ip | 149.104.90.203 | — | 2026-09-18 |
| sha1 | 0dc20b2f11118d5c0cc46b082d7f5dc060276157 | — | 2026-09-18 |
| sha1 | c36ecd2e0f38294e1290f4b9b36f602167e33614 | — | 2026-09-18 |
| sha1 | 5265e8edc9b5f7dd00fc772522511b8f3be217e3 | — | 2026-09-18 |
| sha1 | 7d66b550ea68a86fcc0958e7c159531d4431b788 | — | 2026-09-18 |
| sha1 | b9601e60f87545441bf8579b2f62668c56507f4a | — | 2026-09-18 |
| sha1 | f35ce62abeedfb8c6a38ceac50a250f48c41e65e | — | 2026-09-18 |
| sha1 | 1b06e877c2c12d74336e7532bc0ecf761e5fa5d4 | — | 2026-09-18 |
| sha1 | d03fd329627a58b40e805f4f55b5d821063ac27f | — | 2026-09-18 |
| sha1 | a91b42e5062fef608f285002debaff9358162b25 | — | 2026-09-18 |
| sha1 | 44f0a22b143b79fa760bf31e14c8fff714c8a2a1 | — | 2026-09-18 |
| sha1 | 23e228d5603b4802398b2e7419187aef71ff9dd5 | — | 2026-09-18 |
| ip | 38.54.57.17 | — | 2026-09-18 |
| sha1 | 4df896624695ea2780552e9ea3c40661dc84efc8 | — | 2026-09-18 |
| ip | 38.60.209.106 | — | 2026-09-18 |
| ip | 103.85.25.166 | — | 2026-09-18 |
| sha1 | aa823148eea6f43d8eb9bf20412402a7739d91c2 | — | 2026-09-18 |
| sha1 | 5f1553f3af9425ef5d68341e991b6c5ec96a82eb | — | 2026-09-18 |
| domain | credits.offices-analytics.com | — | 2026-09-18 |
| md5 | 922c1edb47fba94b548edca863165fb1 | — | 2026-09-18 |
| ip | 130.94.101.82 | — | 2026-09-18 |
| sha1 | fdc44057e87d7c350e6df84bb72541236a770ba2 | — | 2026-09-18 |
| ip | 38.60.224.51 | — | 2026-09-18 |
| sha1 | 5df3c882db6be14887182b7439b72a86bd28b83f | — | 2026-09-18 |
| sha1 | ef189737fb7d61b110b9293e8838526dce920127 | — | 2026-09-18 |
| sha1 | db1591c6e23160a94f6312ca46da2d0bb243322c | — | 2026-09-18 |
| sha1 | 0925f24082971f50edd987d82f708845a6a9d7c9 | — | 2026-09-18 |
| domain | amelicen.com | — | 2026-09-18 |
| sha1 | 2560b7e28b322bb7a56d0b1da1b2652e1efe76ea | — | 2026-09-18 |
| ip | 38.60.241.65 | — | 2026-09-18 |
| sha256 | e0b6f8535e19f0a4938e3317de0c4493ecea17aa906fd0454805ba2086cbf3a8 | — | 2026-09-18 |
| ip | 45.131.179.24 | — | 2026-09-18 |
| sha1 | 3a395daaf518be113fcff2e5e48acd9b9c0de69d | — | 2026-09-18 |
| ip | 38.60.241.193 | — | 2026-09-18 |
| ip | 43.254.216.195 | — | 2026-09-18 |
| sha1 | 873f98caf234c3a8a9db18343dad7b42117e85d4 | — | 2026-09-18 |
| ip | 38.60.197.55 | — | 2026-09-18 |
| sha1 | c26f04790c6fb7950d89ab1b08207ace01efb536 | — | 2026-09-18 |
| ip | 149.104.87.228 | — | 2026-09-18 |
| sha1 | d6d32a1f17d48fe695c0778018c0d51626db4a3b | — | 2026-09-18 |
| CISA urges critical infrastructure to operate in isolation during conflicts | matched as Salt Typhoon | 2026-05-08 |
| Ongoing Exploitation of Cisco IOS XE Vulnerability with BadCandy Implant | matched as Salt Typhoon | 2025-12-12 |
| Ongoing Exploitation of Cisco IOS XE Vulnerability with BadCandy Implant | matched as Salt Typhoon | 2025-11-08 |
| Chinese Hackers Breach US Telecoms via Unpatched Cisco Routers | matched as FamousSparrow | 2025-02-14 |
| Chinese Hackers Breach US Telecoms via Unpatched Cisco Routers | matched as RedMike | 2025-02-14 |
| Chinese Hackers Breach US Telecoms via Unpatched Cisco Routers | matched as Salt Typhoon | 2025-02-14 |
| Chinese Hackers Breach US Telecoms via Unpatched Cisco Routers | matched as UNC2286 | 2025-02-14 |