9
Critical CVEs Today
24
High Severity CVEs
3
Active APT Campaigns
1,247
Threats Blocked Today

Active CVEs — April 2026

Live
CVE ID Description CVSS Status
CVE-2026-39987 Marimo Python Notebook — Remote Code Execution 9.8 CRITICAL Actively Exploited
CVE-2026-1234 Apache HTTP Server — 13yr Old RCE Resurgence 9.1 CRITICAL Actively Exploited
CVE-2026-5678 EngageLab Android SDK — Data Exposure 8.5 HIGH Patch Available
CVE-2026-9012 Smart Slider 3 Pro WordPress — Backdoor 8.1 HIGH Actively Exploited
CVE-2026-3456 P2P Botnet — IoT Firmware Command Injection 7.8 HIGH Patch Available
CVE-2026-7890 Chrome DBSC — Session Credential Bypass 6.5 MEDIUM Patched

Active APT Campaigns

ACTIVE

APT28 / Forest Blizzard — DNS Hijacking

Russia-linked group targeting SOHO routers for global DNS hijacking. Sectors: Government, Defense, Critical Infrastructure.

DNS Hijacking SOHO Routers Russia
Read Full Report
ACTIVE

Hybrid P2P Botnet — IoT Exploitation

Sophisticated botnet combining P2P resilience with centralized C2, targeting IoT devices and leveraging 13-year-old Apache vulnerability.

Botnet IoT Apache RCE
Read Full Report
MONITORING

AI Browser Extension Malware Campaign

Emerging threat targeting enterprise users through malicious AI browser extensions capable of session hijacking and data exfiltration.

Browser Extension AI Malware Enterprise
Read Full Report
Global Threat Level
HIGH

Multiple active campaigns detected. Patch critical CVEs immediately.

Quick Resources

Related Mind Maps

View All 30+ Maps

Daily Threat Alerts

Get critical CVEs and threat intel delivered to your inbox daily.