Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
satellite_altDaily BriefCyber Threat Daily Brief — July 21, 2026
Today's briefing: 3 critical and 16 high-severity threats. A total of 23 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.
Latest Reports
28 / 606 results
highbug_reportVulnerabilityWindows June updates break Office launch from third-party apps
Windows systems with June 2024 updates installed. Affects third-party applications attempting to launch Microsoft Office applications or open Office documents. Specific Windows versions not yet disclosed by Microsoft.
criticalbug_reportVulnerabilityCISA orders patching of actively exploited Joomla JCE plugin flaw
Widget Factory Joomla Content Editor (JCE) plugin for Joomla CMS. Specific vulnerable versions not disclosed in provided data. Maximum severity rating indicates critical impact.
highbug_reportVulnerabilityMicrosoft Defender zero-day "RoguePlanet" awaits patch after disclosure
Microsoft Defender (all versions currently deployed). Specific affected versions not disclosed. Impacts organizations relying on Defender for endpoint protection.
criticalbug_reportVulnerabilitySupply chain attack compromises 144 Mastra npm packages via hijacked account
144 npm packages in the @mastra/* namespace (Mastra AI framework for JavaScript/TypeScript). Attack vector: compromised npm contributor account (ehindero). All downstream projects using affected Mastra packages are potentially impacted.
highperson_alertThreat ActorShinyHunters Claims Responsibility for Kodak Data Breach
ShinyHunters is a financially motivated cybercrime group known for conducting data theft and extortion operations against organizations across multiple sectors.
criticalbug_reportVulnerabilityCISA: Widget Factory Joomla JCE flaw exploited in the wild (CVSS 10.0)
Widget Factory Joomla Content Editor (JCE). Specific affected versions not disclosed. Impacts Joomla CMS installations using the JCE component.
highbug_reportVulnerabilityMalicious JetBrains IDE plugins steal AI API keys from developers
JetBrains Marketplace users who installed any of the 15+ malicious plugins. Affects developers using JetBrains IDEs (IntelliJ IDEA, PyCharm, WebStorm, etc.) with AI API keys configured. Specific plugin names and versions not provided in summary.
highbug_reportVulnerabilityRokarolla Android banking trojan targets 217 banking and crypto apps
Android devices with 217 targeted banking and cryptocurrency applications. Malware features 137 commands for comprehensive device control and data exfiltration. Specific app list and Android version scope not disclosed.
highbug_reportVulnerabilityGoogle Cloud Vertex AI SDK flaw enables ML model hijacking via pickle attack
Google Cloud Vertex AI SDK for Python. Specific affected versions not disclosed. Impacts organizations using the SDK to upload and deploy machine learning models to Google Cloud's serving infrastructure.
highbug_reportVulnerabilityMalware campaign abuses Steam Workshop via Wallpaper Engine packages
Valve Steam Workshop users, specifically those using Wallpaper Engine application. All versions of Wallpaper Engine that integrate with Steam Workshop are potentially affected. Scope includes users downloading community-created wallpaper content.
highbug_reportVulnerabilityClickFix campaigns deploy three malware loaders via fake updates
Education and financial sector organizations targeted by ClickFix social engineering campaigns delivering BabaDeda Loader, Lorem Ipsum Loader, and Potemkin malware loaders through fake software update lures.
highperson_alertThreat ActorGhostTree Abuses NTFS Junctions to Evade Microsoft Defender Scans
GhostTree is a threat actor that has developed an evasion technique exploiting recursive NTFS junctions to bypass antivirus scanning. The actor targets the information technology sector and leverages inherent Windows file system features to create in…
criticalbug_reportVulnerabilityCisco SD-WAN vulnerability under active exploitation, patches released
Cisco SD-WAN products. Specific affected versions not provided in available data. Organizations running Cisco SD-WAN infrastructure are potentially at risk.
highbug_reportVulnerabilityHeap buffer overflow in jansi library enables code execution
jansi library (all versions not specified). The jansi library is a Java library for ANSI escape sequences, commonly used in console applications and logging frameworks across Java ecosystems.
criticalbug_reportVulnerabilityCISA orders patch for exploited LiteSpeed cPanel plugin flaw (3-day deadline)
LiteSpeed cPanel user-end plugin (specific versions not disclosed). Affects web hosting environments using cPanel with LiteSpeed integration. U.S. federal agencies explicitly targeted by CISA directive.
criticalbug_reportVulnerabilityFortinet FortiSandbox under active exploit for 3 CVEs including critical 9.1
Fortinet FortiSandbox - specific affected versions not disclosed. Three CVEs: CVE-2026-39813 (CVSS 9.1 critical), CVE-2026-39808, CVE-2026-25089. At least one vulnerability recently patched; patch status of others unclear.
highperson_alertThreat ActorDragonForce Ransomware Gang Deploys Backdoor.Turn via Teams Infrastructure
DragonForce is a ransomware gang that has developed custom tooling to support their extortion operations. The group demonstrates advanced capabilities in developing bespoke malware and leveraging legitimate cloud infrastructure for command-and-contro…
highbug_reportVulnerabilityVertex AI Python SDK vulnerable to RCE via bucket squatting attacks
Google Vertex AI Python SDK. Affects users uploading models to Vertex AI. Vulnerability exploits bucket squatting during model upload process combined with pickle deserialization to achieve cross-tenant remote code execution.
highperson_alertThreat ActorChina-Linked Actor Deploys Windows Variants of SprySOCKS Backdoor
A China-linked threat actor has expanded the SprySOCKS malware family beyond its original Linux platform. The actor demonstrates advanced development capabilities through the creation of two distinct Windows variants (WIN_DRV and WIN_PLUS) featuring…
criticalbug_reportVulnerabilityActive exploitation of critical FortiSandbox vulnerabilities
Fortinet FortiSandbox cyber threat detection platform. Specific versions not disclosed. No CVE assigned yet.
highbug_reportVulnerabilitySprySOCKS malware expands to Windows in government-targeted attacks
Government organizations in at least four countries. Windows systems now targeted alongside previously known Linux variants. Specific Windows versions and attack vector not disclosed.
highperson_alertThreat ActorScarCruft Deploys NarwhalRAT via Microsoft Account Phishing Lures
ScarCruft (also tracked as APT37, InkySquid, Reaper, and Group123) is a North Korean state-sponsored advanced persistent threat group. The actor is attributed to North Korea's intelligence apparatus and conducts espionage operations aligned with Pyon…
highbug_reportVulnerabilityCisco Catalyst SD-WAN Manager under active exploit (CVE-2026-20262)
Cisco Catalyst SD-WAN Manager. Specific vulnerable versions not provided in summary. Affects web UI component accessible to authenticated remote users.
highbug_reportVulnerabilityCISA adds LiteSpeed cPanel Plugin privilege escalation to KEV catalog
LiteSpeed cPanel Plugin (specific versions not disclosed). Affects web hosting environments using cPanel with LiteSpeed integration. Federal agencies and hosting providers running this plugin are in scope.
highpublicGeopoliticalDOJ seizes AI deepfake sites under new TAKE IT DOWN Act authority
The seizure of CFAKE.com and SOCFAKE.com represents the first public enforcement action under the TAKE IT DOWN Act, signaling a U.S. policy shift toward proactive domain-level intervention against AI-enabled image-based sexual abuse.
highbug_reportVulnerabilitySimpleHelp OIDC flaw allows unauthenticated account creation
SimpleHelp remote management software servers with OpenID Connect (OIDC) authentication enabled. Specific affected versions not disclosed. All SimpleHelp deployments using OIDC for technician authentication are potentially vulnerable.
criticalperson_alertThreat ActorChina-linked espionage group targets North American research networks
A China-linked espionage group conducted a sustained intrusion campaign lasting over one year against North American institutions. The actor's motivation appears to be intelligence collection focused on medical research, academic intellectual propert…
highperson_alertThreat ActorContagious Interview targets developers via recruitment-themed phishing
Contagious Interview (also tracked as DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, and DEV#POPPER) is a North Korean-aligned threat actor cluster that specializes in social engineering attacks against software developers and technology secto…