Live Cyber Security Threat Dashboard

Hawkra Threat Dashboard

Your daily cyber security threat intelligence hub. Track the latest CVEs, active exploits, data breaches, and cyber attacks, all enriched with CISA KEV data, EPSS exploit predictions, and MITRE ATT&CK mapping. Free AI-generated threat briefings updated every 24 hours.

Today's Cyber Security Threats

534
New CVEs (24h)
1
CISA KEV (24h)
29
Critical (24h)
135
High (24h)
168
Medium (24h)
202
Low (24h)

AI Daily Threat Briefing

Friday, September 4, 2026

Active Exploits & Threat Groups

CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild. These vulnerabilities affect a diverse range of products, highlighting a broad attack surface for threat actors. The additions include improper authentication flaws in BerriAI LiteLLM (CVE-2026-59822) and JFrog Artifactory (CVE-2026-82329), which could allow unauthorized access to sensitive systems. Additionally, two command injection vulnerabilities in Kestra OSS (CVE-2026-49869) and SonicWall SMA1000 Appliances (CVE-2026-83549) provide pathways for remote code execution. The SonicWall appliances are further impacted by a Server-Side Request Forgery (SSRF) flaw (CVE-2026-83548), compounding the risk to network perimeters.

Analysis of these exploit types reveals connections to numerous state-sponsored and financially motivated threat groups. Fox Kitten, an Iranian-nexus group, is linked to the highest number of similar CVEs, frequently leveraging initial access and command-and-control tactics. Other prominent actors include APT41, Volt Typhoon, and Sandworm Team, all known for exploiting perimeter devices and web-facing applications to gain initial access and establish stealthy persistence. Financially motivated groups like FIN7 also utilize these types of vulnerabilities for execution and initial access as part of their ransomware and data theft operations. The widespread adoption of these exploitation techniques across multiple advanced groups underscores the critical need for timely patching.

New Vulnerabilities

Several critical vulnerabilities have been disclosed, with four receiving a maximum CVSS score of 10.0. These include an authorization bypass in Microsoft Azure Active Directory B2C (CVE-2026-83711) and a missing authentication flaw in Azure AI Language (CVE-2026-70352), both of which could allow attackers to elevate privileges within cloud environments. Another critical vulnerability, CVE-2026-4357, affects a WordPress plugin for embedding HTML5 games, permitting unauthenticated attackers to upload arbitrary files. The fourth, CVE-2026-85061, impacts the MapLibre GL JS library, posing a significant risk to web applications that utilize it.

The disclosures also highlight continued risks in WordPress ecosystems and network-attached devices. Multiple plugins, including WatchMan-Site7 (CVE-2026-77009) and Divi Ajax Filter (CVE-2026-11613), contain critical flaws enabling code execution or file inclusion. Additionally, vulnerabilities in D-Link (CVE-2026-85223) and TOTOLINK (CVE-2026-85031) devices could lead to remote compromise. Despite the high severity of these new CVEs, there have been no significant increases in their Exploit Prediction Scoring System (EPSS) scores, suggesting that widespread exploitation has not yet been observed or predicted.

In the News

No major incidents reported today.

Exploited in the Past 48 Hours

CISA KEV additions from the last 48 hours — confirmed active exploitation

Last 24 Hours of CVEs

Recently published and modified CVEs from the last 24 hours

Threat Intelligence Visualizations

Track These Threats in YOUR Network

Sign up for Hawkra to correlate these threats against your own infrastructure. Import scan results, map vulnerabilities to assets, and get prioritized remediation guidance.