Live Cyber Security Threat Dashboard
Hawkra Threat Dashboard
Your daily cyber security threat intelligence hub. Track the latest CVEs, active exploits, data breaches, and cyber attacks, all enriched with CISA KEV data, EPSS exploit predictions, and MITRE ATT&CK mapping. Free AI-generated threat briefings updated every 24 hours.
Today's Cyber Security Threats
AI Daily Threat Briefing
Tuesday, July 21, 2026
Active Exploits & Threat Groups
There have been no new additions to the CISA Known Exploited Vulnerabilities (KEV) catalog during this reporting period. This indicates a temporary pause in newly identified vulnerabilities being subjected to widespread, active exploitation in the wild. While no new threats have been added, organizations should continue to prioritize patching of all previously listed vulnerabilities in the KEV catalog, as these remain proven vectors for intrusion.
Consistent with the lack of new KEV entries, no specific threat groups have been newly linked to active campaigns exploiting recent zero-day vulnerabilities. Security teams should maintain awareness of established threat actor tactics, techniques, and procedures (TTPs), as groups like APT29 (Cozy Bear) and FIN7 continue to leverage older, unpatched vulnerabilities for initial access and lateral movement.
New Vulnerabilities
A significant number of critical vulnerabilities have been disclosed, affecting a wide range of products from core infrastructure to specialized applications. Multiple critical vulnerabilities, including CVE-2026-63795 and CVE-2026-64142, have been identified in the Linux kernel, each carrying high CVSS scores of 10.0 and 9.8 respectively. These flaws could allow for privilege escalation or denial of service, impacting a vast array of systems. Additionally, a critical supply chain vulnerability, CVE-2026-46412 (CVSS 10.0), was discovered in the @beproduct/nestjs-auth npm package, where a compromised version was published, enabling potential remote code execution.
The AI/ML development ecosystem is also facing new threats, with CVE-2026-63766 (CVSS 9.8) in GPT-SoVITS allowing for OS command injection and CVE-2026-63767 (CVSS 9.8) in ktransformers enabling remote code execution via unauthenticated pickle deserialization. For web administrators, CVE-2026-13439 (CVSS 9.8) presents a critical risk, as it permits unauthenticated privilege escalation in the "Easy Form Builder" WordPress plugin. Currently, there are no significant increases in Exploit Prediction Scoring System (EPSS) scores for these new CVEs, suggesting exploitation is not yet widespread.
In the News
- Hugging Face disclosed a security breach, noting it appears to be one of the first documented cases of an autonomous AI agent driving a cyberattack on its internal systems.
- Healthcare technology firm Craneware confirmed it suffered a cyberattack, resulting in the theft of a significant amount of customer, employee, and partner data.
- Insurance company AssuranceAmerica reported a data breach affecting over 6.9 million records after a threat actor successfully targeted an employee.
- Security researchers reported that threat actor UTA0533 has been actively exploiting two zero-day vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410.
Exploited in the Past 48 Hours
CISA KEV additions from the last 48 hours — confirmed active exploitation
Last 24 Hours of CVEs
Recently published and modified CVEs from the last 24 hours
Threat Intelligence Visualizations
Track These Threats in YOUR Network
Sign up for Hawkra to correlate these threats against your own infrastructure. Import scan results, map vulnerabilities to assets, and get prioritized remediation guidance.