Intelligence · Updated daily

Security Intelligence

AI-analysed threats, vulnerabilities and campaigns. Not just what happened — what it means, who's affected, and what to do about it.

Priority

highVulnerabilityEmerging

Six RCE and DoS vulnerabilities in protobuf.js demonstrate risks of untrusted schema deserialization in Node.js ecosystems

Six vulnerabilities in protobuf.js, a widely-used Protocol Buffers library for JavaScript/TypeScript, allow remote code execution and denial-of-service attacks when processing malicious protobuf schemas or payloads. The widespread adoption of protobuf.js in Node.js applications makes this a significant supply-chain concern.

protobuf.js, Node.js applications using protobuf.js

All intelligence

Showing 19 of 632
criticalVulnerabilityActive

Public exploit for Linux kernel use-after-free escalates unprivileged users to root across distributions

CVE-2026-23111, a use-after-free in the Linux kernel's nf_tables packet-filtering subsystem, has a public working exploit that enables local privilege escalation to root and container escape. The vulnerability was patched upstream in February 2026, but widespread deployment of the fix remains incomplete.

CVE-2026-23111
Linux kernel, Linux distributions (all versions with vulnerable nf_tables code), Container platforms (Docker, Kubernetes, systemd-nspawn)
highSupply ChainActive

Bright Data SDK Weaponises Consumer Smart TVs as Covert Residential Proxies for Web Scraping

Bright Data embeds a reverse-engineered SDK in free consumer applications that converts devices, particularly always-on smart TVs, into unwitting exit nodes for its residential proxy network, enabling large-scale web scraping operations marketed to AI companies without explicit user consent.

iOS applications embedding Bright Data SDK, Smart TV devices, Consumer endpoints used as proxy infrastructure
highCampaignActive

UNC3753 Executing Sustained Vishing Campaign Against US Legal Services

UNC3753 conducted a financially motivated data theft extortion campaign from January to May 2026 targeting US law firms and financial services using vishing and social engineering to gain remote access. The group's focus on high-value professional services sectors and reliance on human manipulation rather than technical exploits makes this a persistent threat requiring non-technical defences.

US law firms, professional services sector, financial services organisations