Programmatic feed

SecOpsAI JSON Feed

A structured JSON feed for applications, scripts, and automation workflows that consume SecOpsAI advisories and research.

Intelligence Categories
ORIGINAL RESEARCH 0 posts

No posts yet. Coming soon.

SECURITY NEWS 9 posts

9 posts with SecOpsAI context, detections, or operator guidance.

THREAT INTELLIGENCE 8 posts

8 posts with SecOpsAI context, detections, or operator guidance.

SUPPLY CHAIN 2 posts

2 posts with SecOpsAI context, detections, or operator guidance.

DETECTION ENGINEERING 1 post

1 posts with SecOpsAI context, detections, or operator guidance.

MITIGATION 1 post

1 posts with SecOpsAI context, detections, or operator guidance.

OPENCLAW 0 posts

No posts yet. Coming soon.

PRODUCT UPDATES 0 posts

No posts yet. Coming soon.

2026-07-15T18:04:45Z

VU#529388: Privilege escalation vulnerability via unprotected IOCTL interface in Pegatron Tdelo64.sys

Overview A privilege escalation vulnerability exists in the tdeio64.sys driver due to an unprotected input/output control (IOCTL) dispatch routine that fails to validate the origin and permissions of user-supplied requests. An unprivileged local attacker can abuse exposed IOCTL dispatch routines [RM1.1][MB1.2]to perform arbitrary kernel memory read and write operations, ultimately obtaining NT AUTHORITY\SYSTEM privileges and compromising the security of the affected system. Description The tdeio

2026-07-11T21:47:53Z

CISA KEV: Balbooa Forms CVE-2026-56291

Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE.

2026-07-09T07:02:27Z

CISA KEV: JoomShaper SP Page Builder CVE-2026-48908

JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

2026-06-04T00:28:14Z

Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign

A large-scale npm supply chain attack compromised over 90 versions of @redhat-cloud-services packages, silently infecting CI/CD environments and developer systems. The malicious code steals credentials from GitHub, cloud platforms, and local machines, then spreads like a worm by republishing trusted packages. Discover how the attack works, what data is at risk, and the steps you can take to protect your organization. The post Preinstall to persistence: Inside the Red Hat npm Miasma credential-st

2026-06-04T00:28:14Z

CISA KEV: Mirasvit Full Page Cache Warmer CVE-2026-45247

Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie.

2026-06-01T20:20:55Z

CISA KEV: Oracle WebLogic Server CVE-2024-21182

Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data.

2026-05-31T21:16:48Z

CISA KEV: Palo Alto Networks PAN-OS CVE-2026-0257

Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.