Open threat center
Cyber Dash
First page of an open threat center. Not a wall of alerts — a count. CVEs, KEV, and Singapore notices.
One-page exec memo, PDF
disclosed
73,384CVEs
2026 through 5 Oct
daily count
264/ day
rejected IDs excluded
a note
count ≠ exploit
exploitation is still rare
24hPast 24 hours
major events
12 items in the last 24 hours. Critical vulnerabilities 5, breaches 3, APT 1, AI security 5. No Singapore item in this window. Headlines stay in the source language.
local snapshot · 6 Oct, 10:08 SGT
APT · AI security · Dark Reading · 5 Oct, 23:52
Chinese Hackers Impersonate US Officials for AI Cyber EspionageAn emerging threat group known as TA419 established seemingly legitimate professional relationships with AI policy experts working for US think tanks, universities, and legal organizations.
Critical · AI security · SecurityWeek · 5 Oct, 19:00
Exploitation Hits Rejetto HFS Vulnerability Discovered by AICVE-2026-61500 allows attackers to recover the session-cookie signing key and gain administrative access and RCE. The post Exploitation Hits Rejetto HFS Vulnerability Discovered by AI appeared first on SecurityWeek .
AI security · The Record · 6 Oct, 05:26
Wikimedia Foundation: OpenAI agents tried to edit pages and compromise notes toolBeyond the potential misuses of its services, Wikimedia said activity by AI agents can be a drain on web platforms that are already operating with limited resources.
Critical · CyberScoop · 6 Oct, 07:07
Citrix discloses third actively exploited NetScaler zero-day in less than a weekThe vendor was much quicker and consistent in its response to the latest defect, and researchers consider the impact relatively low compared to the previous pair of zero-days.…
Breaches · The Record · 6 Oct, 03:15
Alleged ShinyHunters member reportedly detained in Jordan, assisting law enforcementSaif al-Din Khader is cooperating with the FBI, reports said, as the bureau responds to a massive breach that exposed employee data.
Breaches · The Record · 5 Oct, 23:30
University of Illinois Chicago affected by ransomware attack on medical schoolA ransomware attack that affected the University of Illinois Chicago (UIC) College of Medicine resulted in the theft of some information from its servers.
01Monthly counts
monthly counts
In 2026 (through 5 Oct), WordPress ecology 7,777, Windows / Microsoft 3,566 — about 2.2×. Density of public IDs, not a risk ranking.
severity strata
- Crit 7,356 · 10%
- High 29,047 · 40%
- Med 31,189 · 43%
- Low 5,792 · 8%
02Stacks
the main stacks
Tap a card to hide that stack from the monthly chart. WordPress counts plugins and themes; Windows counts the Microsoft line.
Fig · large leftovers in 2026 (circa early Sep)
The named leftovers in 2026’s rest. IBM is there: 623, just past Apple. Cisco’s public volume is two-fifths of IBM’s — and it still leads IBM on KEV.
- IBMWebSphere / AIX / QRadar623KEV added 1
Yes. Just past Apple by volume. Enterprise long tail. Almost never on KEV.
- MozillaFirefox413KEV added 0
Browser disclosures. Higher average score, little in-the-wild use.
- AdobeAEM / Acrobat289KEV added 5
Seasonal AEM and Reader patches. Hits KEV more often than IBM.
- Cisconetwork gear244KEV added 17
Small public volume. Second in 2026 KEV additions.
- D-LinkSOHO routers227KEV added 0
Home routers. Tenda and Totolink add still more, all in the rest.
- SamsungAndroid OEM174KEV added 0
Phones and appliance firmware, paced with Android patches.
- GitLabDevOps158KEV added 1
Self-hosted DevOps. Mid volume, occasional catalog entries.
- SAPERP143KEV added 0
Enterprise ERP. Long patch windows, never the monthly headline.
Vendor public-ID ranks, not a row-by-row split of this center’s rest. Homework sites (SourceCodester, code-projects) and Tenda-class routers pad the rest further, and almost never enter KEV.
03Volume vs exploited
volume is not exploitation
In 2026 the WordPress ecology discloses far more than Windows. CISA KEV reverses it: Microsoft added 39, WordPress core 4. A large count is not the first to be exploited.
WordPress
plugins & themes, not core
7,777
Windows
Microsoft product line
3,566
WordPress is about 2.2× Windows.
- Microsoft39
- Cisco18
- Linux8
- Google8
- Apple9
- Oracle4
- WordPress4
Counts follow the CISA KEV catalog, not third-party “exploited” tallies. Full register below.
04Known exploited
CISA KEV
Public IDs are a disclosure census. CISA KEV is confirmed exploitation. Catalog 1,734; 250 added in 2026. Microsoft 39, WordPress core 4. The largest stacks barely appear here.
catalog
1,734
v2026.10.04
added 2026
250
local snapshot
known ransomware use
361
Known ransomware
forensic triage
75
BOD 26-04 forensic
- Microsoft
- Cisco
- Apple
- Linux
- Fortinet
- Rest
- Rest160
- Microsoft39
- Cisco18
- Apple9
- Linux8
- Google8
- Fortinet8
250 rows · catalog 2026-10-04 · local snapshot
Showing the first 12. Narrow vendor or search to see the rest.
Source: CISA KEV catalog JSON (2026.10.04). Listing is not compromise — it is reliable evidence of in-the-wild use. BOD 22-01 / 26-04 due dates bind US federal civilian agencies; for everyone else this is a priority queue. WordPress plugins almost never enter. What does: the core chain (wp2shell) and a few historic plugins.
05Lion City notices
SingCERT
Public notices from Singapore’s cyber emergency team. 128 alerts in 2026, 24 of them naming active exploitation. A local priority queue, not the global census.
- 2026 alerts
- 128
- Active exploitation
- 24
- 2025–26
- 377
- Advisories
- 13
2026-10-03
2026
local snapshot
2026
- 1101
- 902
- 803
- 1704
- 1905
- 1606
- 1407
- 1608
- 1709
- 110
128 rows · through 2026-10-03
Source: CSA Singapore’s public SingCERT index. A notice is guidance for Singapore, not proof your estate is hit. Weekly bulletins are PDF digests and stay folded by default.
06Monthly ledger
the monthly ledger
Tap a row to highlight the same month in Fig. 1. The Jul–Aug 2026 jump is half Oracle’s quarterly spike, half the rest of the catalog rising.
| Mo | WP | Win | Linux | Oracle | Apple | Rest | Total | |
|---|---|---|---|---|---|---|---|---|
| Jan | 620 | 180 | 480 | 280 | 40 | 60 | 2,190 | 3,850 |
| Feb | 780 | 90 | 560 | 340 | 55 | 80 | 3,177 | 5,082 |
| Mar | 820 | 140 | 620 | 390 | 70 | 95 | 4,111 | 6,246 |
| Apr | 790 | 220 | 580 | 360 | 80 | 70 | 3,720 | 5,820 |
| May | 860 | 160 | 720 | 420 | 90 | 110 | 4,592 | 6,952 |
| Jun | 910 | 240 | 780 | 450 | 110 | 130 | 4,834 | 7,454 |
| Jul | 880 | 620 | 890 | 480 | 1,150 | 140 | 5,615 | 9,775 |
| Aug | 940 | 810 | 980 | 520 | 980 | 155 | 7,906 | 12,291 |
| Sep | 983 | 1,106 | 2,147 | 625 | 274 | 246 | 9,561 | 14,942 |
| Oct* | 194 | 0 | 0 | 0 | 0 | 0 | 778 | 972 |
| Total | 7,777 | 3,566 | 7,757 | 3,865 | 2,849 | 1,086 | 46,484 | 73,384 |
07Weakness mix
common classes
These are classes, not vendors. XSS is still the largest share, mostly on CMS extensions. Memory-safety bugs are fewer — and they hit harder.
- XSSCWE-7922%
Mostly WordPress plugins
- SQL injectionCWE-8911%
Still common in extensions
- Out-of-bounds writeCWE-7879%
Kernels and local software
- Path traversalCWE-228%
File and backup plugins
- Missing authenticationCWE-2878%
Unauthenticated admin interfaces
- CSRFCWE-3527%
CMS and admin panels
- Use after freeCWE-4166%
Browsers and kernels
- Missing authorizationCWE-8626%
Logged in, still out of bounds
- The restCWE-other23%
Long tail, scattered