Intelligence · Updated daily

Security Intelligence

AI-analysed threats, vulnerabilities and campaigns. Not just what happened — what it means, who's affected, and what to do about it.

Page 9 of 26

201–225 of 632
criticalVulnerabilityActive

Grav CMS Multiple RCE Vectors: Unsafe Deserialization & Command Injection

Grav CMS contains five remote code execution vulnerabilities spanning unsafe unserialize() calls without class restrictions and unescaped shell parameters in git operations. This PoC is significant because it demonstrates ecosystem-wide deserialization hygiene gaps and highlights that security controls exist in the same codebase but are inconsistently applied.

GHSA-vj3m-2g9h-vm4p
getgrav/grav
criticalVulnerabilityActive

ArcadeDB Authorization Bypass via Uninitialized Security Context and Disabled Schema Enforcement

Two compounding defects in ArcadeDB allow authenticated users to bypass database and record-level authorization controls: uninitialized fileAccessMap treated as allow-all, and newly-created databases with disabled security factories. Any authenticated principal can read/write/mutate schemas across all databases on a shared server.

CVE-2026-44221
ArcadeData/arcadedb (<26.4.2)
highCampaignContained

Juvenile actor breaches French administrative identity system, highlighting insider threat and data commodification risks

A 15-year-old was detained for allegedly stealing and selling data from France Titres (ANTS), the agency managing national identity and administrative documents. The incident demonstrates how young threat actors with technical capability can compromise high-value government systems and monetise sensitive personal data.

France Titres (ANTS), French Ministry of Interior
highCampaignActive

Scattered Spider operator arrested in Finland: implications for distributed social engineering campaigns

A 19-year-old dual US-Estonian national arrested in Finland faces federal charges for membership in Scattered Spider, a prolific collective known for social engineering and financial fraud targeting critical sectors. The arrest demonstrates law enforcement coordination across jurisdictions but does not significantly disrupt the group's operational capacity.

Financial services, Technology sectors, Healthcare organisations