TASK#STOMP, a Windows backdoor researchers dissected, uploads a victim's business documents and then stays to copy each new or edited one. Loss from a single infection keeps growing until someone finds and removes it.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence45
ShinyHunters is exploiting an unpatched CVSS 9.8 pre-login flaw in Oracle PeopleSoft, encoding one URL character to slip past WAF rules matching the raw path. Mandiant has confirmed JSP web shells on dozens of systems.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence50
CVE-2026-58231 is an unauthenticated, CVSS 10.0 code execution bug in Commerce Cloud's Data Hub Adapter. Defused says attempts hit its honeypots three days after patch day.
Perspective Coverage
5 publishers
- Builder
- Builder 26%
- Operator
- Operator 65%
- Investor
- Investor 9%
Reality
- Evidence70
- Adoption55
- Hype gap+25
- Incentives40
- Confidence68
The updated CISA-FBI advisory puts Medusa at more than 500 victims as of April 2026, up from 300, with exploits weaponized within 24 hours and sometimes a week before disclosure.
Perspective Coverage
7 publishers
- Builder
- Builder 12%
- Operator
- Operator 79%
- Investor
- Investor 9%
Reality
- Evidence76
- Adoption
- Insufficient
- Hype gap+20
- Incentives40
- Confidence74
ShinyHunters is mass-exploiting PeopleSoft systems that added firewall rules after the summer breaches but skipped Oracle's patch, Mandiant said. For operators that wrote a filter and stopped, the remedy in the report is the patch Oracle already shipped.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence40
The probes read Langflow's secret key file and grep the process environment for OpenAI and AWS credentials, which puts an AI orchestration tool on the same scanning clock as the Rails file-read bug of the same week.
Perspective Coverage
4 publishers
- Builder
- Builder 30%
- Operator
- Operator 60%
- Investor
- Investor 10%
Reality
- Evidence62
- Adoption40
- Hype gap+15
- Incentives65
- Confidence60
GreyNoise and Blackpoint Cyber trace the new PaperCut auth-bypass chain to one scanning address running AI agents against schools, which turns an unpatched print server from a maintenance ticket into a credential incident.
Perspective Coverage
6 publishers
- Builder
- Builder 31%
- Operator
- Operator 57%
- Investor
- Investor 12%
Reality
- Evidence62
- Adoption38
- Hype gap+20
- Incentives40
- Confidence66
Rapid7 published a Metasploit module for CVE-2026-85706, an unauthenticated file read it says is already exploited against self-hosted GitLab. Every CE and EE build from 18.7 stays exposed until 19.1.8, 19.2.6 or 19.3.2.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives35
- Confidence55
The fix ships in 19.3.2, 19.2.6 and 19.1.8, and scanning for the flaw started the day after disclosure. Whether you can tell if a read succeeded on your instance depends on whether your proxy logs request bodies.
Publishers:dev.to · docs.gitlab.com · watchtowr.com Perspective Coverage
3 publishers
- Builder
- Builder 22%
- Operator
- Operator 73%
- Investor
- Investor 5%
Reality
- Evidence80
- Adoption
- Insufficient
- Hype gap+15
- Incentives45
- Confidence74
Wiz observed multiple actors chaining CVE-2026-42018 and CVE-2026-42016 against self-hosted JFrog Artifactory between August 15 and September 8, creating admin accounts, loading Groovy plugins and dropping a Rust backdoor.
Perspective Coverage
4 publishers
- Builder
- Builder 34%
- Operator
- Operator 61%
- Investor
- Investor 5%
Reality
- Evidence68
- Adoption35
- Hype gap+10
- Incentives35
- Confidence70
CVE-2026-59310 gave a suspected APT crew persistence on vCenter systems in August. CISA has now flagged the same directory traversal as abused by ransomware operators. Broadcom patched it on July 29.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+15
- Incentives40
- Confidence65
WSO2 published the fix in May. watchTowr saw forged tokens arrive at its honeypot in September. Its own replay against a correctly targeted deployment came back with the credentials the gateway holds.
Publishers:dev.to · security.docs.wso2.com Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence62
The flaw reaches code execution only where the active theme has a top-level directory starting with page- and a readable local .php file such as pearcmd.php sits on the server. Previdian has logged 68 attempts.
Reality
- Evidence66
- Adoption45
- Hype gap+12
- Incentives68
- Confidence60
Cisco Talos says three separate clusters, one sharing tooling with Sandworm, worked the same CVSS 10.0 bypass in Secure Firewall Management Center. The scope change in that vector reaches every firewall the console manages.
Reality
- Evidence72
- Adoption61
- Hype gap+8
- Incentives38
- Confidence68
Cisco patched CVE-2026-20079 in March 2026 and confirmed in September that attackers had used it in August. Talos ties three clusters to the console, including one it links to Sandworm tooling and a Qilin affiliate.
Reality
- Evidence74
- Adoption72
- Hype gap+5
- Incentives38
- Confidence62
Exploitation is now the top initial-access vector at 31% of breaches. The median defender needs 43 days to close a known-exploited flaw. Both figures reach operators through a guide selling the fix.
Reality
- Evidence45
- Adoption22
- Hype gap+40
- Incentives88
- Confidence58
The 7.8-rated privilege escalation in Acronis' cPanel and WHM backup plugin needs a local account on the server to work. The hosting providers and MSPs that run those servers are the only party who can install the fix.
Perspective Coverage
4 publishers
- Builder
- Builder 28%
- Operator
- Operator 61%
- Investor
- Investor 11%
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+25
- Incentives65
- Confidence65
VulnCheck's first-half figures put the median at 80 days, down from 120 in 2025, while the count of CVEs exploited within a month of publication held flat near 200. The tier that breaks is the 90-day one.
Reality
- Evidence58
- Adoption62
- Hype gap−12
- Incentives70
- Confidence55
VulnCheck logged 884 vulnerabilities with first-time exploitation evidence in 2025, and 28.96% of them were already being exploited by the day their CVE appeared, up from 23.6% a year earlier. The same report calls the year's timing highly consistent with 2024.
Reality
- Evidence52
- Adoption
- Insufficient
- Hype gap+18
- Incentives78
- Confidence48
CVE-2026-14894 gives an unauthenticated attacker code execution on a WordPress site, and the fix is Super Forms 6.3.314. Microsoft separately reports invisible Unicode tag characters at up to 2.37 million messages a day.
Reality
- Evidence45
- Adoption30
- Hype gap+10
- Incentives40
- Confidence45