// LIVE
INTELCritical Citrix NetScaler memory flaw actively exploited in attacks
INTELTelnyx joins LiteLLM in latest PyPI package poisoning tied to Trivy breach
INTELStorm Brews Over Critical, No-Click Telegram Flaw
INTELFTC Action Against Match and OkCupid for Deceiving Users, Sharing Personal Data
INTELTeamPCP Supply Chain Campaign: Update 004 - Databricks Investigating Alleged Com
INTELHealthcare IT Platform CareCloud Probing Potential Data Breach
INTELSecurity updates for Monday
INTEL'When intelligence and trust move together, AI stops being an experiment and sta
INTELRussian APT Star Blizzard Adopts DarkSword iOS Exploit Kit
INTELDisclosure of Replay Attack Vulnerability in Signed References
INTELHackers now exploit critical F5 BIG-IP flaw in attacks, patch now
INTELTelnyx Targeted in Growing TeamPCP Supply Chain Attack
CVE(Pwn2Own) Canon imageCLASS MF654Cdw TTF Parsing Out-Of-Bounds Write Remote Code
CVEZDI-26-204: Canon imageCLASS MF654Cdw XPS Parser Vulnerability
CVEZDI-26-202: QNAP TS-453E Hyper Data Protector Plugin SQL Injection RCE Vulnerabi
INTELCritical Citrix NetScaler memory flaw actively exploited in attacks
INTELTelnyx joins LiteLLM in latest PyPI package poisoning tied to Trivy breach
INTELStorm Brews Over Critical, No-Click Telegram Flaw
INTELFTC Action Against Match and OkCupid for Deceiving Users, Sharing Personal Data
INTELTeamPCP Supply Chain Campaign: Update 004 - Databricks Investigating Alleged Com
INTELHealthcare IT Platform CareCloud Probing Potential Data Breach
INTELSecurity updates for Monday
INTEL'When intelligence and trust move together, AI stops being an experiment and sta
INTELRussian APT Star Blizzard Adopts DarkSword iOS Exploit Kit
INTELDisclosure of Replay Attack Vulnerability in Signed References
INTELHackers now exploit critical F5 BIG-IP flaw in attacks, patch now
INTELTelnyx Targeted in Growing TeamPCP Supply Chain Attack
CVE(Pwn2Own) Canon imageCLASS MF654Cdw TTF Parsing Out-Of-Bounds Write Remote Code
CVEZDI-26-204: Canon imageCLASS MF654Cdw XPS Parser Vulnerability
CVEZDI-26-202: QNAP TS-453E Hyper Data Protector Plugin SQL Injection RCE Vulnerabi
nsysops@ops-intel:~$ ls -lt --range live

OPS INTEL

266 items · ARIA-monitored · page 37 of 54
266
TOTAL
CRITICAL
HIGH
ACTIONABLE
WALLBOARD ↗
AUTO-APPROVED TODAY
LLM STATUS
CRITICAL (page) 0
HIGH (page) 4
MEDIUM (page) 1
LOW (page) 0
HIGH 95% confidence cve

ZDI-26-104: Sante DICOM Viewer Pro Buffer Overflow Vulnerability

Remote code execution vulnerability in Sante DICOM Viewer Pro requires user interaction to exploit. CVE-2026-2034. Includes severity, confidence, and actionable

['User must interact with malicious content to trigger vulnerability', 'Exploitation requires visiting compromised or attacker-controlled sites, opening of malicious files']

Healthcare IT SystemsMedical Imaging Departments
action items (2)
  • Apply available security updates
  • Conduct a risk assessment for DICOM Viewer Pro usage

Zero Day Initiative ·

HIGH 95% confidence cve

ZDI-26-103: Oracle VirtualBox VMSVGA OOB Access Local Privilege Escalation Vulnerability

A critical local privilege escalation vulnerability (CVE-2026-21956) in Oracle VirtualBox's VMSVGA component allows attackers to execute high-privileged code.

['Understanding and mitigating vulnerabilities is crucial for maintaining system security.', 'This vulnerability can lead to unauthorized access and control of systems running affected software.']

Oracle VirtualBox usersEnterprise IT environments
action items (2)
  • Review system configurations and update to the latest version of Oracle VirtualBox.
  • Implement strict access controls on guest systems running affected software.

Zero Day Initiative ·

HIGH 95% confidence cve

ZDI-26-102 Oracle VirtualBox VMSVGA OOB Write LPE Vulnerability

A local privilege escalation vulnerability in Oracle VirtualBox allows attackers to escalate privileges on affected systems after gaining high-privileged code.

['Local attacker can exploit this vulnerability after gaining high-privileged code execution rights to escalate privileges']

AdministratorsSecurity TeamsVirtualization Users
action items (2)
  • Update to the latest version of Oracle VirtualBox
  • Review and restrict user permissions for critical operations

Zero Day Initiative ·

MEDIUM 95% confidence cve

ZDI-26-101 Oracle VirtualBox BusLogic Vulnerability

A critical information disclosure flaw in Oracle VirtualBox's BusLogic component can be exploited by attackers to gain sensitive data. Includes severity, confid

['Local attackers can exploit the flaw after gaining high-privilege code execution to disclose sensitive information', 'CVSS severity rated at 6.0 indicating medium risk']

Oracle VirtualBox usersEnterprise environments with virtualization
action items (2)
  • Update to the latest version of Oracle VirtualBox
  • Review system configurations to prevent unauthorized access

Zero Day Initiative ·

HIGH 95% confidence cve

ZDI-26-100: Oracle VirtualBox LsiLogic Info Disclosure Vulnerability

Learn about the ZDI-26-100 info disclosure vuln in Oracle VirtualBox. Local attackers can exploit this to access sensitive data on affected systems. Includes se

['This issue allows local attackers with high-privilege access on the guest system to read sensitive data from memory']

System AdministratorsSecurity Teams
action items (2)
  • Apply the latest security updates for VirtualBox
  • Review and restrict high-privilege access

Zero Day Initiative ·