Skip to content
Signals
NVD · CVE-2026-18907 · Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filenameNVD · CVE-2026-18897 · 8.8 · A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strcpy of the file /goform/getOneApConfTempENVD · CVE-2026-18896 · 6.3 · A vulnerability was determined in lavkush-maurya Student-Registration-System 1.0. The affected element is an unknown function of the file /student/changepass.phNVD · CVE-2026-18895 · 8.8 · A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /goform/APSecurity_5g. Performing a manipulCISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07CISA KEV · CVE-2026-34486 · 7.5 · Apache Tomcat Missing Encryption of Sensitive Data Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-18907 · Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filenameNVD · CVE-2026-18897 · 8.8 · A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strcpy of the file /goform/getOneApConfTempENVD · CVE-2026-18896 · 6.3 · A vulnerability was determined in lavkush-maurya Student-Registration-System 1.0. The affected element is an unknown function of the file /student/changepass.phNVD · CVE-2026-18895 · 8.8 · A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /goform/APSecurity_5g. Performing a manipulCISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07CISA KEV · CVE-2026-34486 · 7.5 · Apache Tomcat Missing Encryption of Sensitive Data Vulnerability · Added 2026-08-04 · Due 2026-08-07

Threat Actor

Threat Actor API

Access threat actor profiles with aliases, TTPs, target sectors and campaign history. All profiles are fictional and for educational/defensive use only.

Safety level: Restricted. All responses are editorially reviewed, redacted and safe for enterprise consumption. No raw IOC data, dark web content, exploit code or stolen credentials.

Example use cases

  • Threat landscape briefings
  • MITRE ATT&CK mapping for detection engineering
  • Executive risk reporting
  • Red team scenario planning

Endpoints

Threat Actor Response

Threat actor profile with aliases, TTPs and targeting information.

id*

Actor profile identifier

string

name*

Primary actor name

string

type*

Actor type: apt, ransomware, cybercrime, hacktivist

string

aliases

Known aliases

string[]

targetSectors*

Targeted industry sectors

string[]

observedTtps

MITRE ATT&CK technique IDs

string[]

confidence*

Attribution confidence: low, medium, high

string
{ "id": "ta-001", "name": "Fictional APT Group", "type": "apt", "aliases": "[\"Mock Alias\"]", "targetSectors": "[\"Technology\", \"Finance\"]", "observedTtps": "[\"T1566.001\"]", "confidence": "high" }

Safety notes

All threat actor profiles are entirely fictional.

No real group identities, operational capabilities or tooling specifics disclosed.

MITRE ATT&CK references are for educational mapping only.

Threat Actor API — Enterprise API | Dragons Community