L/BLAB BOTSPUBLIC THREAT INTELLIGENCE NODE
CVE KNOWLEDGE BASE

Intelligence
Explorer.

Investigue vulnerabilidades por identificador, produto afetado ou descrição. Use severidade, CVSS e EPSS juntos para orientar a prioridade.

// THREAT ACTIVITY

Grupos & malware emergente

Atividade pública observada em leak sites e repositórios comunitários. Alegações de vítimas não representam confirmação independente de incidente.

RANSOMWARE GROUPSRECENT CLAIMS
qilin12 menções
safepay10 menções
krybit9 menções
Booba Project7 menções
thegentlemen6 menções
Storm4 menções
akira4 menções
emperador4 menções
lamashtu4 menções
BYOD3 menções
INFOSTEALERSOBSERVED

Sem famílias correlacionadas no recorte recente.

RECENT RANSOMWARE CLAIMSRANSOMWARE.LIVE
safepaydd-automation.chCZ · Technology · 2026-10-05
safepaystuecheli.chCH · Retail & E-Commerce · 2026-10-05
safepaybwi-bau.deDE · Professional Services · 2026-10-05
safepayhalservice.itIT · Professional Services · 2026-10-05
safepaygrundens.comUS · Retail & E-Commerce · 2026-10-05
safepayt-systems.comDE · Technology · 2026-10-05
SilentRansomGroupNelson Mullins Riley & ScarboroughUS · Professional Services · 2026-10-05
SilentRansomGroupSheppard, Mullin, Richter & HamptonUS · Professional Services · 2026-10-05
Global Secret GroupTurn5US · Other · 2026-10-05
safepayanwo.clCL · Not Found · 2026-10-05
safepayduhaas.skSK · Other · 2026-10-05
safepayikhasas.comKE · Not Found · 2026-10-05
MALWARE FAMILIES / 7 DAYSMALWAREBAZAAR
Configure a Auth-Key gratuita do abuse.ch para habilitar detecções recentes do MalwareBazaar.

FONTES: RANSOMWARE.LIVE + MALWAREBAZAAR / ABUSE.CH · CACHE 1H

11641 REGISTROS ENCONTRADOSFEED 2026-09-29
CVE-2026-65179HIGH

NVIDIA NeMo contains a vulnerability in the TabularTokenizer class where it deserializes an untrusted, attacker-controlled .pkl file via pickle.load() without validation. A successful exploit of this vulnerability may lead to code execution, data tampering, denial of service, and information disclosure.

AFFECTED SURFACEProduct not specified
CVSS 8.8EPSS 0.67%
CVE-2026-65178HIGH

NVIDIA NeMo contains a vulnerability in its dataset-loading workflow where a maliciously crafted model_config.yaml can inject unsafe parameters. A successful exploit of this vulnerability may lead to code execution, data tampering, denial of service, and information disclosure.

AFFECTED SURFACEProduct not specified
CVSS 7.8EPSS 0.38%
CVE-2026-65130HIGH

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.

AFFECTED SURFACEProduct not specified
CVSS 8.0EPSS 2.10%
CVE-2026-65129MEDIUM

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service.

AFFECTED SURFACEProduct not specified
CVSS 6.7EPSS 0.13%
CVE-2026-65128HIGH

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause SQL injection. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.

AFFECTED SURFACEProduct not specified
CVSS 8.8EPSS 0.59%
CVE-2026-65127MEDIUM

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause exposure of sensitive system information due to uncleared debug information. A successful exploit of this vulnerability might lead to information disclosure.

AFFECTED SURFACEProduct not specified
CVSS 4.1EPSS 0.15%
CVE-2026-65126MEDIUM

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper enforcement of a behavioral workflow. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure.

AFFECTED SURFACEProduct not specified
CVSS 5.0EPSS 0.31%
CVE-2026-65125MEDIUM

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause external control of a file name or path. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and denial of service.

AFFECTED SURFACEProduct not specified
CVSS 6.6EPSS 0.61%
CVE-2026-65124MEDIUM

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an XML injection. A successful exploit of this vulnerability might lead to data tampering and denial of service.

AFFECTED SURFACEProduct not specified
CVSS 5.9EPSS 0.52%
CVE-2026-65121HIGH

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an improper authentication issue. A successful exploit of this vulnerability might lead to escalation of privileges, information disclosure, and data tampering.

AFFECTED SURFACEProduct not specified
CVSS 8.2EPSS 0.32%
CVE-2026-65118HIGH

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.13%
CVE-2026-65117MEDIUM

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of a hard-coded password. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure.

AFFECTED SURFACEProduct not specified
CVSS 5.0EPSS 0.23%
CVE-2026-65115MEDIUM

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker may cause uncontrolled resource consumption. A successful exploit of this vulnerability may lead to denial of service.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.53%
CVE-2026-65114HIGH

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure.

AFFECTED SURFACEProduct not specified
CVSS 8.3EPSS 0.41%
CVE-2026-65113CRITICAL

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of hard-coded credentials. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, denial of service, and information disclosure.

AFFECTED SURFACEProduct not specified
CVSS 9.8EPSS 0.61%
CVE-2026-65112MEDIUM

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.53%
CVE-2026-65111HIGH

NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious input created by an attacker could cause a code injection. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.

AFFECTED SURFACEnvidia nemo speech
CVSS 7.8EPSS 0.25%
CVE-2026-24267HIGH

NVIDIA NeMo Speech for all platforms contains a vulnerability in the speech data explorer component, where malicious data created by an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.

AFFECTED SURFACEnvidia nemo speech
CVSS 7.8EPSS 0.35%
CVE-2026-24239HIGH

NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious data created by an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.

AFFECTED SURFACEnvidia nemo speech
CVSS 7.8EPSS 0.35%
CVE-2026-19915HIGH

A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.55.10.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls.

AFFECTED SURFACEProduct not specified
CVSS 7.3EPSS 0.11%
CVE-2026-95661MEDIUM

MISP contains a reflected cross-site scripting (XSS) vulnerability in the attribute histogram view. The $selectedTypes variable, which is derived from the URL path segment , was interpolated directly into a JavaScript array literal inside an onClick HTML attribute without any encoding or escaping. An attacker who can cause an authenticated MISP user to visit a crafted URL containing a malicious type value can execute arbitrary JavaScript in the victim's browser within the MISP application origin. Successful exploitation allows the attacker to read session cookies, perform actions on behalf of the victim, or exfiltrate sensitive data accessible from the MISP interface.  The vulnerability requires the victim to be authenticated and to actively navigate to the attacker-supplied URL.

AFFECTED SURFACEProduct not specified
CVSS 5.1EPSS 0.00%
CVE-2026-95659MEDIUM

MISP contains a reflected cross-site scripting (XSS) vulnerability in the AnalystDataController::viewForObject action. The method accepted a parent object type parameter from the URL without validation and passed it to the Overmind-themed AnalystData thread view element, where it was interpolated into two translated strings and rendered into the HTML response without output encoding. An authenticated attacker who can induce a victim to navigate to a crafted URL can inject arbitrary JavaScript that executes in the victim's browser within the MISP application context. This may allow the attacker to read session data, manipulate the page, or perform actions on behalf of the victim.  The vulnerability requires the victim to be authenticated to MISP and to actively visit the attacker-supplied URL. The affected component is the AnalystData controller and the Overmind theme's AnalystData thread element. Version affected: <2.5.47

AFFECTED SURFACEProduct not specified
CVSS 4.8EPSS 0.00%
CVE-2026-95658MEDIUM

MISP's WorkflowsController exposed the moduleStatelessExecution action in the Security component's unlockedActions list. In CakePHP, listing an action in unlockedActions disables both the CSRF token check and the field hash validation for that action. Because moduleStatelessExecution executes a workflow module's exec() method with caller-supplied input and parameters, the absence of CSRF protection allowed an attacker to craft a cross-site form post (or equivalent cross-origin request) that, when submitted by an authenticated site administrator, would cause the administrator's browser to invoke the action on the MISP instance.  The attacker could select any workflow module to execute, including action modules that write blocklist and warninglist entries, and supply arbitrary input and parameters of their choosing. This constitutes a cross-site request forgery (CSRF) vulnerability with high integrity impact on the MISP instance's security-related data.  The vulnerability was identified during an internal security review and was not externally reported. The fix is included in MISP v2.5.47.

AFFECTED SURFACEProduct not specified
CVSS 6.9EPSS 0.00%
CVE-2026-95619HIGH

A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the C++ `new` operator. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability.

AFFECTED SURFACEProduct not specified
CVSS 7.7EPSS 0.00%