Skip to content
Latest
OWAReaper Shows Why Exchange Mailboxes Need Post-Patch Compromise ReviewApache Ant Path Traversal Shows Why Build Pipelines Need SandboxesTeams Helpdesk Impersonation Shows Why Remote Support Needs GuardrailsPaperCut RCE Shows Why Print Servers Need Compromise ReviewEdge AI Moves the Trust Boundary Into Customer-Owned EnvironmentsToy Ghouls Shows Why Custom C2 Needs Protocol-Aware MonitoringTed Backdoor Shows Why Edge Load Balancers Need Compromise ReviewNisos DPRK Investigation Shows Why Remote Hiring Is a Security ControlFake Claude Opus 5 App Shows Why AI Tooling Needs Software ControlNodeRabbit and PollCat Show Why Developer Workstations Need Recruiting-Lure ControlsJSCeal Shows Why Compiled Script Malware Needs Bytecode-Aware DefenseWatershed 250 Shows Water Cybersecurity Needs Practical Field TestsFire Ant Shows Why Trusted Infrastructure Needs First-Class DetectionLLM Safety Fragility Shows Why AI Workflows Need Runtime Guardrails

IOC Passport

CVE-2026-65400

CVEArticle-derived observationCurrent reporting windowReported in 2 articlesWatch this →

A CVE identifier referenced in published reporting. It is vulnerability context, not a malicious indicator or feed verdict.

This value remains inside its 90-day contextual reporting window. Current reporting status is separate from verified-feed admission. Archive-cleared or archived does not mean clean, inactive, benign, remediated, resolved, or safe, and this lifecycle does not change current verified-feed admission.

Current verified-feed status

Checking live guard…

Article reporting and current malicious-feed admission are evaluated separately.

First reported
Last reported
Article count
2
Admission policy
Context only
Research lifecycle
Current

Related indicators

Observables that appear alongside this one in the same reporting. Co-occurrence can suggest shared infrastructure, but it does not establish common ownership, campaign identity, or actor attribution.

CVE-2025-625936897b649f29e54d8910459963bbf94ed5c7a4fe66a56bc5962540b226b8e48c4acocdn[.]comasecdns[.]comctipilot[.]chCVE-2026-42897dnsrecursive[.]eufolder[.]idhxxp://schemas[.]xmlsoap[.]org/soap/envelope/hxxps://ctipilot[.]ch/entries/2026-08-11/cve-2026-65400-screensharingd-remote-root-two-preauth-bugs/hxxps://github[.]com/panchocosil/CVE-2026-65400-poc[.]githxxps://images[.]weserv[.]nl/?url=hxxps://acocdn[.]com/assets/v1_SGVsbG8gV29ybGQhxxps://reverse[.]put[.]as/2026/07/29/its-a-pre-auth-stupid/i3[.]wp[.]comimages[.]weserv[.]nlreverse[.]put[.]asschemas[.]xmlsoap[.]orgslack-imgs[.]comtdndns[.]com

Newsletter

The House-Of-L Brief.

Two short reads a day on markets, cyber threats, AI, and geopolitics. A "why it matters" line on every story.

Double opt-in. One-click unsubscribe on every issue. We never share your address.