Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports
Cyber Threat Daily Brief — September 4, 2026satellite_altDaily Brief
Threat Intel Brief·Daily Summary

Cyber Threat Daily Brief — September 4, 2026

Today's briefing: 14 critical and 22 high-severity threats. A total of 47 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.

14 Critical22 High47 analyses
schedule02:17 UTC
Read briefarrow_forward

Latest Reports

28 / 1172 results
Microsoft SharePoint JWT auth bypass exploited in wild after PoC releasecriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft SharePoint JWT auth bypass exploited in wild after PoC release

Microsoft SharePoint Enterprise Server 2016 and SharePoint Server 2019. CVE-2026-55040 is a critical authentication bypass in JWT token validation allowing unauthenticated attackers to impersonate SharePoint users or administrators.

Microsoft12 Aug · 10:25 UTC
Microsoft August 2026 Patch Tuesday: 398 vulnerabilities, 42 criticalcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft August 2026 Patch Tuesday: 398 vulnerabilities, 42 critical

Microsoft products and services across the ecosystem. Specific affected products, versions, and CVE identifiers not disclosed in available information. 398 total vulnerabilities addressed, including 42 rated critical severity.

Microsoft12 Aug · 10:11 UTC
OpenAI, Anthropic, Google reasoning APIs leaked secrets via session replayhighbug_reportVulnerability
bug_reportVulnerability

OpenAI, Anthropic, Google reasoning APIs leaked secrets via session replay

OpenAI, Anthropic, and Google reasoning APIs (GPT-5.6 Luna, Claude Haiku 4.5, Gemini Robotics ER-1.6). Affects developers who published raw agent logs containing encrypted reasoning objects.

OpenAI12 Aug · 09:47 UTC
Adobe patches three CVSS 10.0 flaws in ColdFusion and Campaign Classiccriticalbug_reportVulnerability
bug_reportVulnerability

Adobe patches three CVSS 10.0 flaws in ColdFusion and Campaign Classic

Adobe ColdFusion 2025.0.x (prior to 2025.0.12) and 2023.0.x (prior to 2023.0.23); Adobe Campaign Classic v7 (prior to 7.4.4 build 9400) on-premise and hybrid deployments; Adobe Commerce (version not specified).

CVE-2026-4836212 Aug · 09:13 UTC
VMware vCenter CVE-2026-59310 exploited in wild for RCE and persistencecriticalbug_reportVulnerability
bug_reportVulnerability

VMware vCenter CVE-2026-59310 exploited in wild for RCE and persistence

Broadcom VMware vCenter Server (all unpatched versions prior to late July 2026 patch release). Affects 361+ confirmed victim IPs across 47 countries, primarily Germany, US, Turkey, Iran, and France.

CVE-2026-5931012 Aug · 07:01 UTC
Malicious LiteLLM PyPI packages stole credentials from 2,100+ orgscriticalbug_reportVulnerability
bug_reportVulnerability

Malicious LiteLLM PyPI packages stole credentials from 2,100+ orgs

LiteLLM versions 1.82.7 and 1.82.8 published on PyPI on March 24, 2026 (10:39-11:19 UTC, treat installs through 16:00 UTC as suspect). Any system that installed these versions or pulled them as transitive dependencies via agent frameworks or orchestr…

LiteLLM12 Aug · 06:04 UTC
SAP Commerce Cloud critical flaw allows unauthenticated RCE (CVSS 10.0)criticalbug_reportVulnerability
bug_reportVulnerability

SAP Commerce Cloud critical flaw allows unauthenticated RCE (CVSS 10.0)

SAP Commerce Cloud (Data Hub Adapter). All unpatched versions are affected. The vulnerability impacts the default authentication client and certain functions lacking input validation.

CVE-2026-5823112 Aug · 05:31 UTC
ShieldBreak zero-day bypasses Microsoft Defender patch, grants SYSTEM accesshighbug_reportVulnerability
bug_reportVulnerability

ShieldBreak zero-day bypasses Microsoft Defender patch, grants SYSTEM access

Microsoft Defender for Windows on Windows 11 25H2, Windows Server 2025, and Windows 10 (all editions). The vulnerability bypasses the patch for CVE-2026-50656 (RoguePlanet) in the Microsoft Malware Protection Engine (mpengine.dll).

CVE-2026-5065612 Aug · 04:41 UTC
Cisco ASA/FTD remote DoS flaw exploited in wild, CISA orders patch by Aug 14highbug_reportVulnerability
bug_reportVulnerability

Cisco ASA/FTD remote DoS flaw exploited in wild, CISA orders patch by Aug 14

Cisco Secure Firewall ASA Software (versions 9.16.1, 9.18.1, 9.20, 9.22, 9.23, 9.24) and FTD Software (versions 7.0, 7.2, 7.4, 7.6, 7.7, 10.0) with IKEv2 Remote Access VPN, SSL-VPN, or Zero Trust Network Access enabled.

CVE-2026-2034912 Aug · 04:15 UTC
DeadLock ransomware uses blockchain infrastructure to evade takedownhighperson_alertThreat Actor
person_alertThreat Actor

DeadLock ransomware uses blockchain infrastructure to evade takedown

DeadLock is a ransomware-as-a-service (RaaS) operation that emerged in mid-2025, employing double-extortion tactics combining data theft with file encryption.

BleepingComputer11 Aug · 20:15 UTC
Microsoft patches 398 flaws including one actively exploited zero-dayhighbug_reportVulnerability
bug_reportVulnerability

Microsoft patches 398 flaws including one actively exploited zero-day

Microsoft Windows operating systems and supported software. All Windows endpoints are affected. Critical focus: CVE-2026-68820 (afd.sys driver privilege escalation, actively exploited), CVE-2026-62832 (Windows User Profile Service privilege escalatio…

Microsoft11 Aug · 19:28 UTC
Sandworm deploys trojanized WireGuard VPN via fake IT job offershighperson_alertThreat Actor
person_alertThreat Actor

Sandworm deploys trojanized WireGuard VPN via fake IT job offers

Sandworm (also tracked as APT44, UAC-0145 sub-cluster) is a Russian-linked advanced persistent threat group notorious for targeting critical infrastructure and government entities, particularly in Ukraine and other countries.

BleepingComputer11 Aug · 19:07 UTC
Windows kernel driver zero-day CVE-2026-68820 exploited by Lazarus APTcriticalbug_reportVulnerability
bug_reportVulnerability

Windows kernel driver zero-day CVE-2026-68820 exploited by Lazarus APT

Windows kernel driver afd.sys (Ancillary Function Driver for WinSock) across all supported Windows versions. CVE-2026-68820 is a use-after-free vulnerability enabling local privilege escalation to SYSTEM level. CVSS 7.0.

CVE-2026-6882011 Aug · 18:10 UTC
Cisco ASA/FTD VPN flaw CVE-2026-20349 actively exploited for DoShighbug_reportVulnerability
bug_reportVulnerability

Cisco ASA/FTD VPN flaw CVE-2026-20349 actively exploited for DoS

Cisco Secure Firewall ASA (versions 9.16, 9.18, 9.20, 9.22, 9.23, 9.24) and Threat Defense FTD (versions 7.0, 7.2, 7.4, 7.6, 7.7, 10.0) with Remote Access SSL VPN, IKEv2 Remote Access VPN with client services, or Zero Trust Network Access enabled.

Cisco11 Aug · 17:45 UTC
Kimwolf v7 Botnet Adds HTTP/2 DDoS with Browser Fingerprintinghighperson_alertThreat Actor
person_alertThreat Actor

Kimwolf v7 Botnet Adds HTTP/2 DDoS with Browser Fingerprinting

Kimwolf (also tracked as AISURU) is an Android and IoT botnet operation active since at least mid-2024. The threat actors behind Kimwolf have demonstrated continuous evolution in their tooling, targeting Android TV boxes since August 2025 and Linux I…

Palo Alto Networks11 Aug · 17:36 UTC
Zoom annotation tool flaws enabled zero-click client hijackingcriticalbug_reportVulnerability
bug_reportVulnerability

Zoom annotation tool flaws enabled zero-click client hijacking

Zoom Workplace (all platforms) before 7.1.5 and 7.0.6; Zoom Workplace VDI Client for Windows before 7.0.11 and 6.6.16; Zoom Rooms and Zoom Meeting SDK (all platforms) before 7.1.0 and 7.1.5. Affects both screen sharers and meeting viewers.

Zoom11 Aug · 17:08 UTC
UAC-0145 Targets Ukrainian IT Workers via Fake Job Recruitment Campaignhighperson_alertThreat Actor
person_alertThreat Actor

UAC-0145 Targets Ukrainian IT Workers via Fake Job Recruitment Campaign

UAC-0145 is a threat cluster operating as a subgroup within Sandworm (also tracked as APT44, Seashell Blizzard, UAC-0002, ELECTRUM, Telebots, IRON VIKING), a sophisticated nation-state hacking group affiliated with Russia's GRU military intelligence.…

The Hacker News11 Aug · 16:36 UTC
Microsoft patches 400 flaws including 3 zero-days, one exploited by Lazaruscriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft patches 400 flaws including 3 zero-days, one exploited by Lazarus

All supported Windows versions (Windows 10, Windows 11). Three zero-day vulnerabilities: CVE-2026-68820 (Windows AFD.sys driver, actively exploited by Lazarus APT), CVE-2026-62832 (Windows User Profile Service, publicly disclosed as "LegacyHive"), an…

Microsoft11 Aug · 16:08 UTC
SharePoint Server auth bypass chained to RCE, no credentials requiredcriticalbug_reportVulnerability
bug_reportVulnerability

SharePoint Server auth bypass chained to RCE, no credentials required

Microsoft SharePoint Server Subscription Edition, 2019, and 2016 (CVE-2026-55040, CVSS 9.1). Chained RCE flaw CVE-2026-63520 (CVSS 8.1) also affects Project Server 2013 SP1 and Office Web Apps 2013 SP1. SharePoint Online is not affected.

CVE-2026-5504011 Aug · 14:47 UTC
DeadLock Ransomware Leverages Polygon Blockchain for Resilient Extortionhighperson_alertThreat Actor
person_alertThreat Actor

DeadLock Ransomware Leverages Polygon Blockchain for Resilient Extortion

DeadLock is a ransomware group first detected in July 2025, operating double extortion campaigns that encrypt victim environments and threaten public data release.

Polygon11 Aug · 14:35 UTC
ExfilSquad Claims 2.6M Records Stolen from Wesco CRM Environmenthighperson_alertThreat Actor
person_alertThreat Actor

ExfilSquad Claims 2.6M Records Stolen from Wesco CRM Environment

ExfilSquad is a data extortion group that specializes in exfiltrating sensitive information from organizations and leveraging it for ransom demands. The group operates a data leak site where they publish stolen data after ransom deadlines expire.

Wesco11 Aug · 13:59 UTC
Malicious SIM cards can execute code on IoT cellular modules via RUN AThighbug_reportVulnerability
bug_reportVulnerability

Malicious SIM cards can execute code on IoT cellular modules via RUN AT

Cellular IoT modules (6 of 8 tested, primarily Quectel parts with Qualcomm processors) in EV chargers, industrial routers, car telematics units. Limited phone impact: OPPO Find X5, OPPO Reno 14 F 5G, ASUS Zenfone 9.

The Hacker News11 Aug · 10:05 UTC
Mozilla revokes Firefox/Thunderbird Linux signing key after repo exposurehighbug_reportVulnerability
bug_reportVulnerability

Mozilla revokes Firefox/Thunderbird Linux signing key after repo exposure

Mozilla Firefox and Thunderbird Linux downloads (all versions signed with subkey 09BE ED63 F346 2A2D FFAB 3B87 5ECB 6497 C1A2 0256 from April 2025 to August 2026).

Mozilla11 Aug · 10:04 UTC
North Korea IT Worker Infiltration Targets Crypto and Tech Firmshighperson_alertThreat Actor
person_alertThreat Actor

North Korea IT Worker Infiltration Targets Crypto and Tech Firms

North Korean IT worker operations, attributed by researchers to Famous Chollima (a CrowdStrike designation under the Lazarus umbrella), involve operatives seeking employment at Western technology and cryptocurrency companies under fraudulent identiti…

The Hacker News11 Aug · 09:35 UTC
Kimwolf v7 botnet targets Android IoT with HTTP/2 DDoS, ENS C2 resolutionhighbug_reportVulnerability
bug_reportVulnerability

Kimwolf v7 botnet targets Android IoT with HTTP/2 DDoS, ENS C2 resolution

Android TV boxes and set-top boxes with unauthenticated Android Debug Bridge (ADB) exposed on port 5555. Primarily affects devices accessible via residential proxy services. ARM-based Android IoT devices running vulnerable configurations.

Unit 42 (Palo Alto)11 Aug · 08:00 UTC
Polish energy plant breached via private APN in coordinated OT attackhighpublicGeopolitical
publicGeopolitical

Polish energy plant breached via private APN in coordinated OT attack

The December 2025 incident represents a sophisticated multi-site campaign against Polish critical infrastructure, attributed by Polish authorities to the Russian Electrum threat group.

BleepingComputer10 Aug · 21:07 UTC
Aeternum botnet uses Polygon blockchain for decentralized C2 infrastructurehighbug_reportVulnerability
bug_reportVulnerability

Aeternum botnet uses Polygon blockchain for decentralized C2 infrastructure

Windows systems infected with Aeternum C++ botnet loader (Build.exe). The malware targets Windows environments and uses Polygon blockchain smart contracts for command and control, making traditional domain/IP-based blocking ineffective.

Unit 42 (Palo Alto)10 Aug · 20:00 UTC
BdThemes WordPress plugins compromised to create rogue admin accountshighbug_reportVulnerability
bug_reportVulnerability

BdThemes WordPress plugins compromised to create rogue admin accounts

BdThemes WordPress plugins including Element Pack (100,000+ active installs), Prime Slider, Ultimate Post Kit, Pixel Gallery, and Ultimate Store Kit. All versions using the vulnerable Biggop Library introduced in March 2026.

BdThemes10 Aug · 19:12 UTC