Live Cyber Security Threat Dashboard
Hawkra Threat Dashboard
Your daily cyber security threat intelligence hub. Track the latest CVEs, active exploits, data breaches, and cyber attacks, all enriched with CISA KEV data, EPSS exploit predictions, and MITRE ATT&CK mapping. Free AI-generated threat briefings updated every 24 hours.
Today's Cyber Security Threats
AI Daily Threat Briefing
Friday, September 4, 2026
Active Exploits & Threat Groups
CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild. These vulnerabilities affect a diverse range of products, highlighting a broad attack surface for threat actors. The additions include improper authentication flaws in BerriAI LiteLLM (CVE-2026-59822) and JFrog Artifactory (CVE-2026-82329), which could allow unauthorized access to sensitive systems. Additionally, two command injection vulnerabilities in Kestra OSS (CVE-2026-49869) and SonicWall SMA1000 Appliances (CVE-2026-83549) provide pathways for remote code execution. The SonicWall appliances are further impacted by a Server-Side Request Forgery (SSRF) flaw (CVE-2026-83548), compounding the risk to network perimeters.
Analysis of these exploit types reveals connections to numerous state-sponsored and financially motivated threat groups. Fox Kitten, an Iranian-nexus group, is linked to the highest number of similar CVEs, frequently leveraging initial access and command-and-control tactics. Other prominent actors include APT41, Volt Typhoon, and Sandworm Team, all known for exploiting perimeter devices and web-facing applications to gain initial access and establish stealthy persistence. Financially motivated groups like FIN7 also utilize these types of vulnerabilities for execution and initial access as part of their ransomware and data theft operations. The widespread adoption of these exploitation techniques across multiple advanced groups underscores the critical need for timely patching.
New Vulnerabilities
Several critical vulnerabilities have been disclosed, with four receiving a maximum CVSS score of 10.0. These include an authorization bypass in Microsoft Azure Active Directory B2C (CVE-2026-83711) and a missing authentication flaw in Azure AI Language (CVE-2026-70352), both of which could allow attackers to elevate privileges within cloud environments. Another critical vulnerability, CVE-2026-4357, affects a WordPress plugin for embedding HTML5 games, permitting unauthenticated attackers to upload arbitrary files. The fourth, CVE-2026-85061, impacts the MapLibre GL JS library, posing a significant risk to web applications that utilize it.
The disclosures also highlight continued risks in WordPress ecosystems and network-attached devices. Multiple plugins, including WatchMan-Site7 (CVE-2026-77009) and Divi Ajax Filter (CVE-2026-11613), contain critical flaws enabling code execution or file inclusion. Additionally, vulnerabilities in D-Link (CVE-2026-85223) and TOTOLINK (CVE-2026-85031) devices could lead to remote compromise. Despite the high severity of these new CVEs, there have been no significant increases in their Exploit Prediction Scoring System (EPSS) scores, suggesting that widespread exploitation has not yet been observed or predicted.
In the News
No major incidents reported today.
Exploited in the Past 48 Hours
CISA KEV additions from the last 48 hours — confirmed active exploitation
Last 24 Hours of CVEs
Recently published and modified CVEs from the last 24 hours
Threat Intelligence Visualizations
Track These Threats in YOUR Network
Sign up for Hawkra to correlate these threats against your own infrastructure. Import scan results, map vulnerabilities to assets, and get prioritized remediation guidance.