NeoShield Security logo NeoShield Security Quantum X
AUTONOMOUS AI · ONLINE / LAST SCAN 20m ago / STORE DB / SYNC 20:53:33 / ALERTS 0

AI-assisted threat intelligence

Live critical cyber signals

A Claude-powered agent continuously scans official global threat feeds, triages the most dangerous activity, and maps each one to concrete defensive action — automatically.

5
GUARDED

AI analyst live situational brief

5 critical campaign clusters active; Edge/VPN and zero-days dominate—patch Microsoft & Adobe today

Threat level GUARDED with 11 critical and 9 high-severity signals. Five distinct attack clusters are tracked: Edge/VPN device exploitation (7 critical), actively exploited zero-days (5 critical), cloud/container attacks (2), web CMS (1), and ransomware (1). Microsoft Patch Tuesday (Aug 11) and Adobe CVSS 10.0 flaws require immediate deployment; Lazarus and Sandworm campaigns actively exploit Windows and perimeter devices.

Do this today: Deploy Microsoft August patches and Adobe ColdFusion/Commerce fixes within 48 hours; prioritize Cisco ASA/FTD (CVE-2026-20349) and edge device inventory review.

Perimeter Breach Wave 7 Lazarus Zero-Day Spree 5 Cloud Infrastructure Targeting 2 CMS Plugin Exploitation 1 DeadLock Ransomware 1
AI-triaged Priority One

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

The Hacker News · threat news · 1d ago

Adobe released patches for three CVSS 10.0 vulnerabilities in ColdFusion and Campaign Classic that enable arbitrary code execution and privilege escalation. Immediate patching is required for all affected systems.

  • Immediately apply Adobe security updates to all ColdFusion and Campaign Classic instances
  • Audit ColdFusion servers for signs of exploitation including unusual process execution and command injection attempts
  • Restrict network access to ColdFusion administrative interfaces and Campaign Classic servers
  • Monitor for suspicious command execution patterns in ColdFusion logs
6
Critical
15
High
37
Tracked
● Live
CRITICAL Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws CRITICAL Hackers exploit critical Adobe Commerce flaw to hijack customer accounts CRITICAL Android malware combo takes out loans and relays victims' credit cards CRITICAL Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor CRITICAL DeadLock ransomware uses blockchain to resist infrastructure takedown CRITICAL Microsoft patches LegacyHive Windows zero-day vulnerability HIGH Plug and Pwn attack uses fake USB devices for Windows SYSTEM access HIGH "City-Forum" data-theft attacks target Salesforce, ServiceNow portals HIGH Mira Hormone Monitor, Mira Android App HIGH Pulsetto Vagus Nerve Stimulator HIGH Johnson Controls C-CURE 9000 and Victor application server (Update A) HIGH Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE HIGH Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands HIGH Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing HIGH Critical VMware vCenter RCE flaw exploited for reverse SSH access HIGH Trezor discloses data breach affecting nearly 14,000 customers HIGH Siemens Parasolid HIGH Johnson Controls Inc. Airwall HIGH Johnson Controls Metasys HIGH Attackers Exploit SharePoint Authentication Bypass After Public PoC Release HIGH Using Gemma4 with Ollama - Testing File Hash Analysis and Recommendations with AI, (Wed, Aug 12th) CRITICAL Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws CRITICAL Hackers exploit critical Adobe Commerce flaw to hijack customer accounts CRITICAL Android malware combo takes out loans and relays victims' credit cards CRITICAL Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor CRITICAL DeadLock ransomware uses blockchain to resist infrastructure takedown CRITICAL Microsoft patches LegacyHive Windows zero-day vulnerability HIGH Plug and Pwn attack uses fake USB devices for Windows SYSTEM access HIGH "City-Forum" data-theft attacks target Salesforce, ServiceNow portals HIGH Mira Hormone Monitor, Mira Android App HIGH Pulsetto Vagus Nerve Stimulator HIGH Johnson Controls C-CURE 9000 and Victor application server (Update A) HIGH Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE HIGH Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands HIGH Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing HIGH Critical VMware vCenter RCE flaw exploited for reverse SSH access HIGH Trezor discloses data breach affecting nearly 14,000 customers HIGH Siemens Parasolid HIGH Johnson Controls Inc. Airwall HIGH Johnson Controls Metasys HIGH Attackers Exploit SharePoint Authentication Bypass After Public PoC Release HIGH Using Gemma4 with Ollama - Testing File Hash Analysis and Recommendations with AI, (Wed, Aug 12th)

Triaged intelligence feed

refreshes automatically · severity-first
CRITICAL The Hacker News

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

Adobe released patches for three CVSS 10.0 vulnerabilities in ColdFusion and Campaign Classic that enable arbitrary code execution and privilege escalation. Immediate patching is required for all affected systems.

▸ countermeasure Immediately apply Adobe security updates to all ColdFusion and Campaign Classic instances
Claude triage 1d ago
CRITICAL BleepingComputer

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

Critical vulnerability CVE-2026-71362 in Adobe Commerce/Magento enables account hijacking attacks. Immediate patching and account monitoring required for all e-commerce deployments.

▸ countermeasure Apply Adobe security patches immediately to all Commerce/Magento instances
Claude triage 23h ago
CRITICAL BleepingComputer

Android malware combo takes out loans and relays victims' credit cards

WindRelay Android malware combined with SpyNote RAT enables real-time NFC card data theft and fraudulent loan applications. Immediate detection and containment of infected devices is critical to prevent financial fraud and identity theft.

▸ countermeasure Block known WindRelay/SpyNote command and control domains at network perimeter
Claude triage 22h ago
CRITICAL The Hacker News

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

Lazarus Group exploits Windows zero-day to achieve SYSTEM-level access and deploy novel backdoor against defense/aerospace sectors in France, Germany, Brazil, and India. Immediate patching and threat hunting required for vulnerable systems.

▸ countermeasure Apply latest Windows security patches immediately, prioritizing defense and aerospace organizations
Claude triage 1d ago
CRITICAL BleepingComputer

DeadLock ransomware uses blockchain to resist infrastructure takedown

DeadLock ransomware employs blockchain-based infrastructure to evade traditional takedown methods and maintain resilient command-and-control communications. Organizations must implement enhanced detection and response capabilities against decentralized threat infrastructure.

▸ countermeasure Monitor network traffic for blockchain-related domains and cryptocurrency transaction patterns associated with ransom payments
Claude triage 1d ago
CRITICAL BleepingComputer

Microsoft patches LegacyHive Windows zero-day vulnerability

Microsoft has released security patches to address a Windows zero-day vulnerability known as "LegacyHive," disclosed after the July 2026 Patch Tuesday. [...]

▸ countermeasure Confirm exposure, apply vendor patches, add temporary WAF/IPS rules, and run post-patch vulnerability validation.
heuristic 3h ago
HIGH BleepingComputer

Plug and Pwn attack uses fake USB devices for Windows SYSTEM access

Plug and Play feature can be exploited via malicious USB devices to force installation of vulnerable drivers, leading to SYSTEM privilege escalation. Organizations must restrict USB device installation and monitor driver loading.

▸ countermeasure Disable or restrict Plug and Play device installation via Group Policy (Computer Configuration > Administrative Templates > System > Device Installation)
Claude triage 1d ago
HIGH BleepingComputer

"City-Forum" data-theft attacks target Salesforce, ServiceNow portals

Threat actors are actively exploiting misconfigured Salesforce Experience Cloud and ServiceNow portals to steal data exposed to anonymous users. Organizations must audit portal access controls and data exposure settings immediately.

▸ countermeasure Audit all Salesforce Experience Cloud and ServiceNow portal configurations to identify data accessible to anonymous users
Claude triage 21h ago
HIGH CISA News

Mira Hormone Monitor, Mira Android App

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access unauthorized health profile information, make changes to health information, cause a denial-of-service condition, disclose session token information, and obtain control of user accounts. The following versions of Mira Hormone Monitor, Mira Android App are affected: Mira Monitor Firmware 1.7.1.47 (C

▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
heuristic 2d ago
HIGH CISA News

Pulsetto Vagus Nerve Stimulator

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to use hidden commands to disable electrical safety mechanisms or modify other stimulation output settings. The following versions of Pulsetto Vagus Nerve Stimulator are affected: Pulsetto Vagus Nerve Stimulator vers:all/* (CVE-2026-18844) CVSS Vendor Equipment Vulnerabilities v3 8.1 Pulsetto Pulsetto Vagus Ner

▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
heuristic 2d ago
HIGH CISA News

Johnson Controls C-CURE 9000 and Victor application server (Update A)

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution. The following versions of Johnson Controls C-CURE 9000 and Victor application server (Update A) are affected: C-CURE 9000 <=v3.10.1 (CVE-2026-21655) victor Application Server <=v4.10 (CVE-2026-21655) victor <=v7.0 (CVE-2026-21655) victor Web vict

▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
heuristic 2d ago
HIGH The Hacker News

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was done through an AI agent. The flaw, tracked as CVE-2026-55040 (CVSS 9.1), affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Microsoft's

▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
heuristic 2d ago
HIGH The Hacker News

Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands

The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new social engineering campaign orchestrated by Russian nation-state threat actors targeting IT workers in the country by masquerading as recruiters to trick them into installing malware. CERT-UA pinned the activity on a threat cluster it tracks as UAC-0145, which is a subgroup within Sandworm (aka APT44,

▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
heuristic 2d ago
HIGH The Hacker News

Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

Cybersecurity researchers have discovered a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet that comes with significant improvements to improve its operational resilience and conduct distributed denial-of-service (DDoS) attacks. The new version, tracked as Kimwolf v7, was discovered by Palo Alto Networks Unit 42 in February 2026. "Kimwolf v7 adds an HTTP/2-based

▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
heuristic 2d ago
HIGH BleepingComputer

Critical VMware vCenter RCE flaw exploited for reverse SSH access

A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access. [...]

▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
heuristic 4h ago
HIGH BleepingComputer

Trezor discloses data breach affecting nearly 14,000 customers

Hardware wallet manufacturer Trezor disclosed a data breach affecting nearly 14,000 of its customers after ShipMonk, its shipping and logistics provider, was hacked [...]

▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
heuristic 5h ago
HIGH CISA News

Siemens Parasolid

View CSAF Summary Parasolid is affected by an out of bounds read vulnerability that could be triggered when the application reads files in X_T format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Parasolid are affected: Parasolid V38.0 vers:

▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
heuristic 8h ago
HIGH CISA News

Johnson Controls Inc. Airwall

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to decrypt sensitive data, bypass authentication controls, gaining unauthorized access to read arbitrary files on the system, or gain unauthorized access to protected system resources. The following versions of Johnson Controls Inc. Airwall are affected: Airwall <=4.0.4 (CVE-2026-64887, CVE-2026-34492) CVSS Vendor Equipment

▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
heuristic 8h ago
HIGH CISA News

Johnson Controls Metasys

View CSAF Summary Successful exploitation of this vulnerability could allow a low-privilege user or attacker to inject a persistent malicious payload via a crafted URL that executes in the context of other users' sessions, including administrators, potentially leading to session hijacking and unauthorized access. The following versions of Johnson Controls Metasys are affected: Metasys 12 vers:all/* (CVE-2026-34491) M

▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
heuristic 8h ago
HIGH The Hacker News

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is CVE-2026-55040 (CVSS score: 9.1), which refers to a critical security feature bypass that stems from weak authentication. It was patched by Microsoft as part of its July 2026 Patch Tuesday updates. "The authentication

▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
heuristic 14h ago
HIGH SANS ISC

Using Gemma4 with Ollama - Testing File Hash Analysis and Recommendations with AI, (Wed, Aug 12th)

In the past few weeks, I have been using Gemma4 as a Large Language Model (LLM) to see how useful it can be to analyze some of the malware hashes uploaded to the DShield sensor over the past 30 days and figure out how its recommendation can be considered useful about the activity my DShield sensor is collecting and tracking. The model I use for this testing is gemma4:e4b [2] using two sites to compare the d

▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
heuristic 19h ago
MEDIUM BleepingComputer

Microsoft releases Windows 10 KB5120249 extended security update

Microsoft has released Windows 10 KB5120249 Extended Security Updates for versions 22H2 and 21H2 to fix security vulnerabilities and bugs. [...]

▸ countermeasure Apply security updates, prioritize domain controllers and internet-facing Windows services, then monitor authentication anomalies.
heuristic 2d ago
MEDIUM CISA News

Siemens License Server (SLS)

View CSAF Summary Siemens License Server is affected by multiple vulnerabilities which could allow an attacker to elevate its privileges and read arbitrary files on the system. Siemens has released a new version for Siemens License Server (SLS) and recommends to update to the latest version. The following versions of Siemens License Server (SLS) are affected: Siemens License Server (SLS) vers:intdot/<5.1, vers:int

▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
heuristic 8h ago
MEDIUM CISA News

Siemens Desigo DXR and PXC Controllers

View CSAF Summary A vulnerability in Desigo DXR and PXC controllers has been identified that could allow an attacker to cause denial of service conditions by sending malformed BACnet packets. Recovery requires a device reset or reboot to restore normal functionality. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Desigo DX

▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
heuristic 8h ago
Feeds: CISA KEV · NVD · CISA News · SANS ISC · The Hacker News · BleepingComputer · Krebs on Security · triaged by NeoShield's AI agent Full defense feed →
How to use Threat Live Manual & worked example — inputs, output, limits, what it does not do, and a worked example. Open the reference →