Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
10 / 23 results
highperson_alertThreat ActorMassive SEO-Poisoned Campaign Distributes AsyncRAT via ScreenConnect
The threat actor behind this campaign remains unattributed. Motivation appears to be financially driven, consistent with commodity RAT deployment for access brokering, credential theft, or follow-on ransomware operations.
criticalbug_reportVulnerabilitySimpleHelp OpenID auth bypass (CVE-2026-48558) exploited in wild
SimpleHelp remote support software, all versions using OpenID Connect authentication. CVE-2026-48558 is a critical authentication bypass (CVSS 10.0) in the OpenID Connect flow.
highperson_alertThreat ActorMalicious Chrome Extension Impersonates Perplexity AI to Intercept Searches
The threat actor behind this campaign remains unattributed. The operation demonstrates a financially or espionage-motivated adversary leveraging social engineering through brand impersonation of Perplexity AI, a popular search technology.
highbug_reportVulnerabilityCisco Catalyst SD-WAN zero-day exploited in wild for two months
Cisco Catalyst SD-WAN Manager. Specific affected versions not disclosed. Requires authenticated local access for exploitation.
highbug_reportVulnerabilityShapedPlugin WordPress Pro plugins backdoored via compromised update channel
Multiple ShapedPlugin Pro WordPress plugins distributed through official licensed update channels. Exact plugin names and affected versions not specified.
criticalbug_reportVulnerabilityFortinet FortiSandbox under active exploit for 3 CVEs including critical 9.1
Fortinet FortiSandbox - specific affected versions not disclosed. Three CVEs: CVE-2026-39813 (CVSS 9.1 critical), CVE-2026-39808, CVE-2026-25089. At least one vulnerability recently patched; patch status of others unclear.
highbug_reportVulnerabilityPalo Alto PAN-OS GlobalProtect auth bypass under active exploitation
Palo Alto Networks PAN-OS GlobalProtect VPN portal and gateway components. Specific affected versions not disclosed in provided data. CVE-2026-0257, CVSS 7.8 (High).
highbug_reportVulnerabilityServiceNow patches actively exploited auth bypass on hosted instances
ServiceNow hosted customer instances (specific versions not disclosed). On-premise deployments may also be affected pending vendor guidance.
highbug_reportVulnerabilityCVE-2026-39987 in Marimo actively exploited for cloud credential theft
Marimo notebook platform (specific versions not disclosed). Affects internet-exposed Marimo notebook instances vulnerable to CVE-2026-39987.
highbug_reportVulnerabilityFortinet FortiCloud SSO bypass exploited to extract LDAP passwords
Fortinet FortiGate appliances with FortiCloud SSO enabled. CVE-2025-59718 and CVE-2025-59719 allow authentication bypass. All FortiGate instances share a default static encryption key that enables decryption of LDAP credentials and private keys from…