KEVIntel

38 posts

KEVIntel banner
KEVIntel

KEVIntel

@kev_intel

Real-time exploited vulnerability intelligence, backed by sensor telemetry

Katılım Haziran 2026
37 Takip Edilen29 Takipçiler
KEVIntel
KEVIntel@kev_intel·
@HackingLZ And everyone who didn’t land it saying their solution would have found it… like yea, with hindsight our cat could have found it
English
0
0
1
194
Justin Elze
Justin Elze@HackingLZ·
The fun thing about the latest WordPress RCE is knowing everyone has been running bug hunting harnesses with every model imaginable against the same code for months and one person still landed it. So much for the space being dead.
English
10
8
81
6.8K
KEVIntel
KEVIntel@kev_intel·
Friday. Your answer is Friday... You maniacs!
KEVIntel tweet media
English
0
0
0
11
KEVIntel
KEVIntel@kev_intel·
We’re seeing this AI-slop "PoC" scanning our FortiSandbox sensors: github.com/0xBlackash/CVE… A request hitting a sensor does not automatically equal real exploitation. This activity will not be classified as exploitation or added as a KEV by KEVIntel.
English
0
0
1
22
KEVIntel
KEVIntel@kev_intel·
Guys. Listen. Listen! We don't need anymore wp2shell PoCs. You can stop asking AI to create them now. There's enough to go around.
English
0
0
1
61
KEVIntel
KEVIntel@kev_intel·
Dust off your forum signature. phpBB exploitation is back! Over the weekend, KEVIntel detected in-the-wild exploitation attempts targeting CVE-2026-48611, a phpBB authentication bypass. The scale of activity currently appears limited, but a public Nuclei template is available.
KEVIntel tweet media
English
1
0
2
921
KEVIntel
KEVIntel@kev_intel·
What’s the best day for you all to release a WordPress Core RCE?
English
0
0
2
556
KEVIntel
KEVIntel@kev_intel·
CVE-2026-46442 is hitting KEVIntel’s Flowise sensor. First seen July 13, with attempts increasing: 20 from 7 attacker IPs. The odd part? It’s an authenticated RCE, but attackers are running the exploit unauthenticated. Now in our KEV Feed: kevintel.com/CVE-2026-46442
KEVIntel tweet media
English
0
3
7
779
KEVIntel retweetledi
Rick de Jager
Rick de Jager@rdjgr·
Here’s the Age of Empires RCE from yesterday’s Patch Tuesday: CVE-2026-50663. Join an attacker’s lobby, (auto-)accept UCG, and you get remote code execution.
English
44
251
2.4K
233.3K
KEVIntel
KEVIntel@kev_intel·
The vulnerability can be exploited remotely without authentication or user interaction. CVSS Score: 10.0 CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CWE-918: Server-Side Request Forgery (SSRF) SonicWall advisory: psirt.global.sonicwall.com/vuln-detail/SN…
English
0
0
0
45
KEVIntel
KEVIntel@kev_intel·
🚨 Critical SonicWall SMA1000 flaw exploited in the wild. CVE-2026-15409 is a pre-auth SSRF rated CVSS 10.0. The CVE record is not yet public. Running SMA1000? Patch now: • 12.4.3-03453+ • 12.5.0-02835+ KEVIntel sensors have not observed exploitation so far.
English
1
1
3
1.3K
KEVIntel
KEVIntel@kev_intel·
Microsoft has patched two vulnerabilities exploited in the wild in July’s Patch Tuesday release: • CVE-2026-56164 • CVE-2026-56155 Both are now tracked in the KEVIntel feed.
English
1
2
3
1.4K
KEVIntel
KEVIntel@kev_intel·
New in KEVIntel: Observed Attackers and Attacker IP Profiles. See which IPs are most active, which CVEs each IP is targeting, and the activity behind every profile. Export attacker IPs as CSV for blocklist and enrichment workflows. Product demo 👇
English
0
0
2
2.7K
KEVIntel retweetledi
Ryan Dewhurst
Ryan Dewhurst@ethicalhack3r·
Anyone want to help this guy escape from Belarus? 😬 Captured by KEVIntel sensors.
Ryan Dewhurst tweet media
English
25
50
2.1K
263.6K
KEVIntel
KEVIntel@kev_intel·
A KEVIntel Virtual Patch for CVE-2026-2699 is now available for teams that need time before shutting down affected servers. We are actively monitoring for exploitation, suspicious activity and signs of a possible 0-day.
English
0
0
0
15
KEVIntel
KEVIntel@kev_intel·
This morning, we added CVE-2026-2699 to the KEVIntel KEV Feed based on partner intelligence. It is an authentication bypass with public PoCs. We have not observed exploitation in our global sensor network and cannot link it to the ShareFile reports.
English
1
0
0
22
KEVIntel
KEVIntel@kev_intel·
⚠️ The vulnerability behind reported Progress ShareFile SZC exploitation remains unknown. Yesterday, KEVIntel alerted subscribers to credible reports of active exploitation. No CVE was attributed, and a 0-day remains possible.
English
1
0
0
25