Skip to main content
All Sectors

Tech & SaaS

ireland

Technology companies, cloud providers, SaaS platforms

Total (30d)

2320

Critical

630

High

529

Medium

1113

2320 threats in last 30 days( 29% vs prior period)
Top ATT&CK Techniques
T1190Exploit Public-Facing Application3626x

Deploy WAF rules, patch public-facing apps within 48h of CVE disclosure, segment DMZ from internal networks, and run authenticated vulnerability scans weekly.

T1078Valid Accounts553x

Enforce MFA on all accounts, implement conditional access policies, audit privileged accounts quarterly, and monitor for impossible-travel logins.

T1059Command and Scripting Interpreter552x

Disable unused scripting interpreters, enforce PowerShell Constrained Language Mode, log all script block execution via ScriptBlockLogging.

T1498Network Denial of Service194x

Deploy upstream DDoS mitigation (Cloudflare/AWS Shield), configure rate limiting on public endpoints, and maintain a DDoS response runbook.

T1204User Execution96x

Block execution of downloaded files via Mark-of-the-Web + SmartScreen, train users on social engineering, and sandbox browser downloads.

T1566.002Spearphishing Link83x

Enable Safe Links / URL rewriting in email, block newly registered domains at the proxy, and train users to verify URLs before entering credentials.

T106869x
T1195.001Supply Chain Compromise64x

Lock dependency versions with lockfiles, run SBOM scanning in CI/CD, validate package signatures, and monitor for dependency confusion attacks.

T1566.003Phishing48x

Enforce DMARC (p=reject), SPF, and DKIM on all domains; block executable attachments at the mail gateway; conduct quarterly phishing simulations.

T1195.002Compromise Software Supply Chain38x

Pin and hash all software dependencies, verify publisher signatures before deployment, scan third-party software with SBOM tools, and isolate build pipelines.

Compliance Exposure
NIS2-Art21-2e(5542)NIS2-Art21-2b(295)DORA-Art17-23(280)NIS2-Art21-2d(81)NIS2-Art21-2i(20)GDPR-Breach(15)NIS2-Art23(14)DORA-Art28-44(14)DORA-Art5-16(12)NIS2-Art21-2k(7)
Technologies
AWSAzureGCPKubernetesDockerTerraform

Recent Intelligence

Swagger.json Scans Detected

Scans for swagger.json files have been detected, indicating potential reconnaissance for vulnerable web services. This activity may affect enterprise applications using web services. Users should monitor their systems for suspicious activity and ensure proper security measures are in place.

3/6/2026Medium

Malware Distribution via Fake Software Sites

Researchers have uncovered a malware distribution ecosystem that uses fake software websites to trick users into downloading malicious software. Users searching for popular software on Google may be affected, and are advised to verify the authenticity of websites before downloading. This

3/6/2026Medium

WordPress Plugin Vulnerabilities

Threat actors are exploiting vulnerabilities in Kirki and Burst Statistics WordPress plugins to gain elevated privileges and take control of websites. WordPress users with these plugins are at risk. Immediate update and patching are recommended to prevent exploitation.

3/6/2026High

GitHub OAuth Token Theft

A one-click attack via Microsoft Visual Studio Code (VS Code) can steal a user's GitHub token, potentially allowing access to private repositories. Users who have linked their GitHub account to VS Code are affected. To mitigate the

3/6/2026High

AI-Driven Worm Targets Networks

Researchers have developed a proof-of-concept AI-driven worm that can analyze and attack corporate networks using a small language model. This worm can create strategies on the fly, potentially affecting any network with vulnerable machines. Organizations should review their security measures to prevent such attacks.

3/6/2026High

Linux Kernel Vulner

A Linux kernel vulnerability has been exploited, allowing attackers to escalate privileges and escape containers. Linux users and organizations are at risk and should update their systems immediately to prevent exploitation. Patching is necessary to prevent unauthorized access and potential data breaches.

3/6/2026High

Octopus Deploy Vulnerability

A vulnerability in Octopus Deploy allows a remote, authenticated attacker to manipulate server configurations, potentially affecting users of the deployment tool. Affected users should

3/6/2026Medium

Apache MINA

A critical deserialization vulnerability has been discovered in Apache MINA, allowing attackers to bypass the allow-list via resolveProxyClass. Users of Apache MINA are affected and should update to the latest version to mitigate the issue. The vulnerability has been fully addressed in recent updates.

3/6/2026Critical

SQL Injection in WordPress Plugin

A SQL injection vulnerability has been discovered in the WordPress School Management plugin, affecting versions up to 93.2.0. Users of this plugin are advised to update to a patched version to prevent potential data breaches. The vulnerability allows attackers to inject malicious SQL code, potentially leading to unauthorized data access.

3/6/2026High

WordPress Plugin Vulnerability

A privilege escalation vulnerability has been discovered in the WordPress School Management plugin, affecting versions up to 93.2.0. Users of this plugin are at risk of unauthorized access and should update immediately. The vulnerability allows attackers to exploit incorrect privilege assignments.

3/6/2026High

WordPress Plugin Vulnerability

A critical vulnerability has been detected in the Mojoomla School Management Plugin up to version 93.2

3/6/2026Critical

Apache MINA Des

A critical vulnerability has been discovered in Apache MINA, affecting versions up to 2.0.28/2.1.12/2.2.7, allowing remote deserialization attacks. Users of these versions are at risk. It is recommended to upgrade the affected component to prevent exploitation.

3/6/2026Critical

WordPress Plugin Vulnerability

A critical vulnerability has been discovered in the Mojoomla School Management Plugin for WordPress, affecting an unknown part of the plugin and allowing for SQL injection attacks. Users of

3/6/2026Critical

CISA Adds Android, Linux Flaws

The US Cybersecurity and Infrastructure Security Agency (CISA) has added Android and Linux Kernel vulnerabilities to its Known Exploited Vulnerabilities catalog, affecting users of these operating systems. Affected parties should prioritize patching and updating their systems to mitigate potential exploitation. Immediate action is recommended to prevent attacks.

3/6/2026High

Sitefinity Vulnerabilities

Progress Software Sitefinity has multiple vulnerabilities that can be exploited by a remote, anonymous attacker to bypass security measures and compromise confidentiality, integrity, and availability. Users of Sitefinity are affected and should take immediate action

3/6/2026High

Devolutions Server Vulnerabilities

A remote, authenticated attacker can exploit multiple vulnerabilities in Devolutions Server to bypass security measures and manipulate

3/6/2026Medium

Windows Search URI Vulnerability

An unpatched vulnerability in the Windows Search URI handler allows attackers to steal NTLMv2 hashes, potentially affecting all Windows users. The issue is similar to a

3/6/2026Medium

Microsoft Clarifies Zero-Day Disclosure Policy

Microsoft has responded to criticism over its handling of zero-day vulnerability disclosures, after threatening legal action against researchers who publicly disclosed unpatched vulnerabilities without prior

3/6/2026Medium

Android Flaw Patched

Google has released security updates for Android, patching 124 vulnerabilities, including an actively exploited privilege escalation bug. The bug, tracked as CVE-2025-48595, affects millions of devices and is linked to targeted attacks. Users should apply the June 2026 Android security updates to protect their devices.

3/6/2026High

mlflow/mlflow Env Var Vuln

A critical vulnerability in mlflow/mlflow allows attackers to exfiltrate sensitive server-side environment credentials. Users of versions prior to 3.11.0 are affected, and should update to the latest version to mitigate the issue. This vulnerability can be exploited by low-privileged authenticated users or unauthenticated users in default deployments.

3/6/2026Critical