Threat Intelligence & Security News

Threat Intelligence & Security News

CyberDesserts covers the threat landscape as it happens, ransomware campaigns, vulnerability disclosures, and emerging attack techniques. Written for security practitioners who need to understand what's happening, why it matters, and what to do about it. No vendor noise. No recycled press releases. Just analysis grounded in 20+ years of defending real organisations.
29
Jan
Fortinet critical SSP bypass

CVE-2026-24858: The Fortinet Patch That Wasn't

Organisations running the latest FortiOS firmware, fully patched against December's critical SSO bypass, still got compromised in January.
5 min read
01
Jan
Feature image for the article: the word "ClickFix" beside a stylised cursor selecting a dotted-outline UI element, representing the click-driven nature of the attack technique.

ClickFix in 2026: Trust-Flow Patterns, Named Variants, and What Stops Them

Updated April 2026 - The trust-flow patterns behind ClickFix, the variants and vectors carrying it, and the defences that work
31 min read
27
Dec
MongoBleed Exploit CVE-2025-14847

MongoBleed Exploit: The MongoDB Memory Leak Hitting 87,000 Servers

Updated January 10, 2026: CISA's remediation deadline for federal agencies is January 19. Ubuntu has retracted its claim
10 min read
04
Dec
React2Shell vulnerability concept showing React Server Components leaking into a remote shell execution (CVE-2025-55182)

CVE-2025-55182: React2Shell Detection and Fix Guide

UPDATE (Jan 1, 2026): RondoDox botnet now weaponizing React2Shell. Shadowserver reports 90,300 instances still vulnerable. Multiple nation-state actors
19 min read
03
Aug
Infostealers - What are they ?

Top Infostealers in 2026: How They Work and How to Stop Them

Updated March 2026: Expanded MFA bypass section with Adversary-in-the-Middle (AitM) and the return of Lumma LinkedIn Post
17 min read