Criminal IP Threat Intelligence Reports

Criminal IP The latest news and developments for Cyber Threat Intelligence Reports.

CIP Blog Criminal IP Blog · The latest news and developments for Criminal IP. Cyber Threat Intelligence Reports.

  • Domain Phishing Scan AI Analysis Multilingual Support
    by Criminal IP on September 4, 2026 at 3:27 am

    This update adds multilingual support for AI analysis results in Criminal IP Domain Phishing Scan, allowing users to view analysis explanations in five supported languages based on their language settings. Maintenance Schedule v1.105.0: 2026.09.03 (05:00-10:00 UTC) Overview 📃 Criminal IP Domain Phishing Scan now supports multilingual AI analysis explanations in English, Korean, Japanese, Arabic, and French. The […] The post Domain Phishing Scan AI Analysis Multilingual Support appeared first on CIP Blog.

  • PaperCut NG/MF Vulnerabilities Exploited in Active Attacks: Analysis of Internet-Exposed Print Management Servers
    by Criminal IP on September 3, 2026 at 12:00 am

    Companies, schools, public institutions, and other organizations use centralized print management solutions to efficiently manage printers and multifunction devices. PaperCut NG/MF is one of the leading print management solutions widely used in these environments. An attack chain has recently been identified in PaperCut NG/MF in which an authentication bypass vulnerability and an unsafe dynamic class […] The post PaperCut NG/MF Vulnerabilities Exploited in Active Attacks: Analysis of Internet-Exposed Print Management Servers appeared first on CIP Blog.

  • NetScaler ADC·Gateway Authentication Bypass Vulnerability CVE-2026-19490 Analysis
    by Criminal IP on September 1, 2026 at 12:35 am

    On August 19, 2026, a critical authentication bypass vulnerability, CVE-2026-19490, was disclosed in NetScaler ADC and NetScaler Gateway, widely deployed enterprise appliances positioned at network perimeters. The vulnerability is rated CVSS v4.0 9.3 (Critical) and is classified as an authentication bypass through an alternate path (CWE-288). A remote, unauthenticated attacker may bypass authentication checks on […] The post NetScaler ADC·Gateway Authentication Bypass Vulnerability CVE-2026-19490 Analysis appeared first on CIP Blog.

  • Zimbra Vulnerability Allowing Unauthenticated OS Command Execution: CVE-2026-73570 and External Exposure Analysis
    by Criminal IP on August 28, 2026 at 12:00 am

    CVE-2026-73570, a vulnerability in Zimbra Collaboration that can lead to unauthenticated remote code execution, has been confirmed to be actively exploited. Zimbra Collaboration is a collaboration platform used by companies and public institutions to operate email, calendars, address books, and other services on their own infrastructure. This vulnerability occurs because Zimbra’s SNMP monitoring component does […] The post Zimbra Vulnerability Allowing Unauthenticated OS Command Execution: CVE-2026-73570 and External Exposure Analysis appeared first on CIP Blog.

  • GitLab GraphQL Code Injection Vulnerability CVE-2026-19478 Analysis
    by Criminal IP on August 26, 2026 at 12:57 am

    On August 17, 2026, GitLab, the self-managed Git platform, released an emergency security update outside its regular update cycle to address the critical vulnerability CVE-2026-19478. The vulnerability, rated CVSS v3.1 9.4 (Critical), is a code injection flaw (CWE-94) involving GraphQL directives. An unauthenticated remote attacker can modify or delete public projects and user data with a single […] The post GitLab GraphQL Code Injection Vulnerability CVE-2026-19478 Analysis appeared first on CIP Blog.

  • Privacy Policy Update (Effective September 3, 2026)
    by Criminal IP on August 26, 2026 at 12:00 am

    Criminal IP will update its Privacy Policy effective September 3, 2026.This update reflects applicable laws and guidelines, current service operations, and improvements to how information regarding the processing of personal data is organized and presented. Key Updates (v1.3) Improved policy structure: Sections have been reorganized and a table of contents has been added for easier […] The post Privacy Policy Update (Effective September 3, 2026) appeared first on CIP Blog.

  • A CVSS 10.0 Vulnerability That Can Lead to Metabase Admin Compromise: CVE-2026-72898
    by Criminal IP on August 24, 2026 at 12:00 am

    In August 2026, a remotely exploitable SQL Injection vulnerability affecting the open-source analytics platform Metabase, tracked as CVE-2026-72898, was disclosed. The vulnerability was assigned a CVSS score of 10.0 (Critical), and it allows attackers to inject arbitrary SQL into the Metabase application database by abusing the password reset functionality, without requiring login credentials or any […] The post A CVSS 10.0 Vulnerability That Can Lead to Metabase Admin Compromise: CVE-2026-72898 appeared first on CIP Blog.

  • VPN Vulnerability That Can Reboot Firewalls: Cisco ASA·FTD CVE-2026-20349
    by Criminal IP on August 20, 2026 at 5:27 am

    On August 11, 2026, Cisco warned that CVE-2026-20349, a denial-of-service (DoS) vulnerability affecting Secure Firewall ASA (Adaptive Security Appliance) and Secure Firewall Threat Defense (FTD) software, was being actively exploited in the wild. The vulnerability is rated 8.6 (High) under CVSS v3.1 and allows an unauthenticated remote attacker to send specially crafted HTTP requests to the Remote Access […] The post VPN Vulnerability That Can Reboot Firewalls: Cisco ASA·FTD CVE-2026-20349 appeared first on CIP Blog.

  • Unauthenticated Server-Side Code Execution in Adobe ColdFusion: CVE-2026-48362 and Analysis of Internet-Exposed Assets
    by Criminal IP on August 18, 2026 at 2:09 am

    On August 11, 2026, Adobe released security update APSB26-90 to address multiple vulnerabilities identified in ColdFusion 2025 and ColdFusion 2023. The update includes vulnerabilities that could lead to arbitrary code execution, privilege escalation, security feature bypass, denial of service (DoS), and memory disclosure. Adobe assigned the update its highest Priority 1 rating and recommends upgrading […] The post Unauthenticated Server-Side Code Execution in Adobe ColdFusion: CVE-2026-48362 and Analysis of Internet-Exposed Assets appeared first on CIP Blog.

  • WordPress Vulnerability CVE-2026-64638: Login Page XSS to Server-Side Code Execution
    by Criminal IP on August 13, 2026 at 5:18 am

    In August 2026, a pre-authentication XSS vulnerability, CVE-2026-64638, was disclosed in the WordPress Core login screen. Dubbed XSS2Shell, the vulnerability originates from a Reflected XSS in the input-handling process of wp-login.php and can potentially be chained with the WordPress REST API, Application Passwords, and administrator sessions to ultimately execute PHP code on the server. While the vulnerability itself […] The post WordPress Vulnerability CVE-2026-64638: Login Page XSS to Server-Side Code Execution appeared first on CIP Blog.

Share Websitecyber
We are an ethical website cyber security team and we perform security assessments to protect our clients.