Search

Find the signal fast

Search published ThreatFrontier reporting across titles, summaries, categories, tags, slugs, and bylines.

Latest coverage

Ollama Cloud slowdown inference queue and tokens-per-second performance diagram
May 15, 2026, 6:09 PM EDT · AI Security · Patch Watch8 minOllama Cloud Slowdown Frustrates Users as Low Token Rates Raise Questions About Hosted Open-Model Economics

User-reported token rates as low as 8 tokens per second show why Ollama Cloud needs clearer performance metrics, queue visibility and paid-tier expectations.

FortiVoice CVE-2025-32756 zero-day RCE credential theft and network scanning diagram
May 15, 2026, 3:29 PM EDT · Exploits · Patch Watch5 minFortinet Patches Critical FortiVoice Zero-Day Exploited for Credential Theft and Network Scanning

Fortinet patched CVE-2025-32756, a critical unauthenticated RCE flaw exploited against FortiVoice systems for credential theft, FastCGI debugging and network scanning.

Intel Branch Privilege Injection CVE-2024-45332 speculative execution mitigation bypass diagram
May 15, 2026, 3:00 PM EDT · Exploits · Patch Watch5 minIntel Branch Privilege Injection Flaw Undermines Six Years of Spectre v2 Hardware Defenses

Intel issued microcode mitigations for CVE-2024-45332, a Branch Privilege Injection flaw that can bypass Spectre v2 hardware defenses and leak privileged memory from affected systems.

SAP NetWeaver Visual Composer chained zero-day attack path for CVE-2025-31324 and CVE-2025-42999
May 15, 2026, 1:34 PM EDT · Exploits · Patch Watch5 minSAP Patches Second Critical NetWeaver Flaw After Researchers Link It to Chained Zero-Day Attacks

SAP patched CVE-2025-42999, a critical NetWeaver Visual Composer deserialization flaw linked to chained attacks that followed exploitation of CVE-2025-31324.

Mini Shai-Hulud supply chain worm trusted publishing abuse diagram
May 15, 2026, 11:52 AM EDT · Supply Chain · Patch Watch5 minMini Shai-Hulud Worm Exposes Limits of Trusted Publishing After 170+ npm and PyPI Packages Hit

The Mini Shai-Hulud campaign compromised more than 170 reported npm and PyPI packages, exposing how trusted publishing and provenance can still be abused when CI/CD environments are compromised.

NGINX Rift CVE-2026-42945 rewrite module vulnerability diagram
May 15, 2026, 11:37 AM EDT · Exploits · Patch Watch4 minNGINX “Rift” Rewrite Module Flaw Confirmed as CVE-2026-42945

CVE-2026-42945 is now tracked as a heap-based buffer overflow in NGINX's rewrite module, affecting NGINX Open Source and NGINX Plus under specific rewrite-rule conditions.