Threat Intelligence & Security News

Threat Intelligence & Security News

CyberDesserts covers the threat landscape as it happens, ransomware campaigns, vulnerability disclosures, and emerging attack techniques. Written for security practitioners who need to understand what's happening, why it matters, and what to do about it. No vendor noise. No recycled press releases. Just analysis grounded in 20+ years of defending real organisations.
12
Feb
Notepad CVE-2026-20841

Two Notepad Attacks in One Week: Your Tools Are the Target

Software supply chain attacks more than doubled in 2025, with developer workstations identified as high-value targets across multiple industry reports
5 min read
05
Feb
OpenClaw security risks concept showing hidden keyboard under torn paper, representing malicious skills, exposed instances, and system-level vulnerabilities in AI agents.

OpenClaw Security Risks: Malicious Skills, Exposed Instances and Real Exploits

Latest updates (March 2026): NemoClaw announced, CVE count now 60+, and independent analysis using Censys identified 63,070 live instances
20 min read
04
Feb
Notepad++ update server compromise

Notepad++ Compromised for 6 Months: Check Your Version Now

Notepad++ update servers were compromised from June through December 2025 by a Chinese state-sponsored threat group. The attackers hijacked the
6 min read
29
Jan
Fortinet critical SSP bypass

CVE-2026-24858: The Fortinet Patch That Wasn't

Organisations running the latest FortiOS firmware, fully patched against December's critical SSO bypass, still got compromised in January.
5 min read
01
Jan
What is ClickFix? The Social Engineering Attack That Became the #1 Initial Access Method

What is ClickFix? The Social Engineering Attack That Became the #1 Initial Access Method

Updated March 2026: Added Windows terminal variant, crashfix and DNS-based delivery, MIMICRAT campaign, and compromised Chrome extension attacks from Q1
14 min read
27
Dec
MongoBleed Exploit CVE-2025-14847

MongoBleed Exploit: The MongoDB Memory Leak Hitting 87,000 Servers

Updated January 10, 2026: CISA's remediation deadline for federal agencies is January 19. Ubuntu has retracted its claim
10 min read
04
Dec
React2Shell vulnerability concept showing React Server Components leaking into a remote shell execution (CVE-2025-55182)

CVE-2025-55182: React2Shell Detection and Fix Guide

UPDATE (Jan 1, 2026): RondoDox botnet now weaponizing React2Shell. Shadowserver reports 90,300 instances still vulnerable. Multiple nation-state actors actively
19 min read