Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
satellite_altDaily BriefCyber Threat Daily Brief — September 4, 2026
Today's briefing: 14 critical and 22 high-severity threats. A total of 47 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.
Latest Reports
28 / 1172 results
criticalbug_reportVulnerabilityMicrosoft SharePoint JWT auth bypass exploited in wild after PoC release
Microsoft SharePoint Enterprise Server 2016 and SharePoint Server 2019. CVE-2026-55040 is a critical authentication bypass in JWT token validation allowing unauthenticated attackers to impersonate SharePoint users or administrators.
criticalbug_reportVulnerabilityMicrosoft August 2026 Patch Tuesday: 398 vulnerabilities, 42 critical
Microsoft products and services across the ecosystem. Specific affected products, versions, and CVE identifiers not disclosed in available information. 398 total vulnerabilities addressed, including 42 rated critical severity.
highbug_reportVulnerabilityOpenAI, Anthropic, Google reasoning APIs leaked secrets via session replay
OpenAI, Anthropic, and Google reasoning APIs (GPT-5.6 Luna, Claude Haiku 4.5, Gemini Robotics ER-1.6). Affects developers who published raw agent logs containing encrypted reasoning objects.
criticalbug_reportVulnerabilityAdobe patches three CVSS 10.0 flaws in ColdFusion and Campaign Classic
Adobe ColdFusion 2025.0.x (prior to 2025.0.12) and 2023.0.x (prior to 2023.0.23); Adobe Campaign Classic v7 (prior to 7.4.4 build 9400) on-premise and hybrid deployments; Adobe Commerce (version not specified).
criticalbug_reportVulnerabilityVMware vCenter CVE-2026-59310 exploited in wild for RCE and persistence
Broadcom VMware vCenter Server (all unpatched versions prior to late July 2026 patch release). Affects 361+ confirmed victim IPs across 47 countries, primarily Germany, US, Turkey, Iran, and France.
criticalbug_reportVulnerabilityMalicious LiteLLM PyPI packages stole credentials from 2,100+ orgs
LiteLLM versions 1.82.7 and 1.82.8 published on PyPI on March 24, 2026 (10:39-11:19 UTC, treat installs through 16:00 UTC as suspect). Any system that installed these versions or pulled them as transitive dependencies via agent frameworks or orchestr…
criticalbug_reportVulnerabilitySAP Commerce Cloud critical flaw allows unauthenticated RCE (CVSS 10.0)
SAP Commerce Cloud (Data Hub Adapter). All unpatched versions are affected. The vulnerability impacts the default authentication client and certain functions lacking input validation.
highbug_reportVulnerabilityShieldBreak zero-day bypasses Microsoft Defender patch, grants SYSTEM access
Microsoft Defender for Windows on Windows 11 25H2, Windows Server 2025, and Windows 10 (all editions). The vulnerability bypasses the patch for CVE-2026-50656 (RoguePlanet) in the Microsoft Malware Protection Engine (mpengine.dll).
highbug_reportVulnerabilityCisco ASA/FTD remote DoS flaw exploited in wild, CISA orders patch by Aug 14
Cisco Secure Firewall ASA Software (versions 9.16.1, 9.18.1, 9.20, 9.22, 9.23, 9.24) and FTD Software (versions 7.0, 7.2, 7.4, 7.6, 7.7, 10.0) with IKEv2 Remote Access VPN, SSL-VPN, or Zero Trust Network Access enabled.
highperson_alertThreat ActorDeadLock ransomware uses blockchain infrastructure to evade takedown
DeadLock is a ransomware-as-a-service (RaaS) operation that emerged in mid-2025, employing double-extortion tactics combining data theft with file encryption.
highbug_reportVulnerabilityMicrosoft patches 398 flaws including one actively exploited zero-day
Microsoft Windows operating systems and supported software. All Windows endpoints are affected. Critical focus: CVE-2026-68820 (afd.sys driver privilege escalation, actively exploited), CVE-2026-62832 (Windows User Profile Service privilege escalatio…
highperson_alertThreat ActorSandworm deploys trojanized WireGuard VPN via fake IT job offers
Sandworm (also tracked as APT44, UAC-0145 sub-cluster) is a Russian-linked advanced persistent threat group notorious for targeting critical infrastructure and government entities, particularly in Ukraine and other countries.
criticalbug_reportVulnerabilityWindows kernel driver zero-day CVE-2026-68820 exploited by Lazarus APT
Windows kernel driver afd.sys (Ancillary Function Driver for WinSock) across all supported Windows versions. CVE-2026-68820 is a use-after-free vulnerability enabling local privilege escalation to SYSTEM level. CVSS 7.0.
highbug_reportVulnerabilityCisco ASA/FTD VPN flaw CVE-2026-20349 actively exploited for DoS
Cisco Secure Firewall ASA (versions 9.16, 9.18, 9.20, 9.22, 9.23, 9.24) and Threat Defense FTD (versions 7.0, 7.2, 7.4, 7.6, 7.7, 10.0) with Remote Access SSL VPN, IKEv2 Remote Access VPN with client services, or Zero Trust Network Access enabled.
highperson_alertThreat ActorKimwolf v7 Botnet Adds HTTP/2 DDoS with Browser Fingerprinting
Kimwolf (also tracked as AISURU) is an Android and IoT botnet operation active since at least mid-2024. The threat actors behind Kimwolf have demonstrated continuous evolution in their tooling, targeting Android TV boxes since August 2025 and Linux I…
criticalbug_reportVulnerabilityZoom annotation tool flaws enabled zero-click client hijacking
Zoom Workplace (all platforms) before 7.1.5 and 7.0.6; Zoom Workplace VDI Client for Windows before 7.0.11 and 6.6.16; Zoom Rooms and Zoom Meeting SDK (all platforms) before 7.1.0 and 7.1.5. Affects both screen sharers and meeting viewers.
highperson_alertThreat ActorUAC-0145 Targets Ukrainian IT Workers via Fake Job Recruitment Campaign
UAC-0145 is a threat cluster operating as a subgroup within Sandworm (also tracked as APT44, Seashell Blizzard, UAC-0002, ELECTRUM, Telebots, IRON VIKING), a sophisticated nation-state hacking group affiliated with Russia's GRU military intelligence.…
criticalbug_reportVulnerabilityMicrosoft patches 400 flaws including 3 zero-days, one exploited by Lazarus
All supported Windows versions (Windows 10, Windows 11). Three zero-day vulnerabilities: CVE-2026-68820 (Windows AFD.sys driver, actively exploited by Lazarus APT), CVE-2026-62832 (Windows User Profile Service, publicly disclosed as "LegacyHive"), an…
criticalbug_reportVulnerabilitySharePoint Server auth bypass chained to RCE, no credentials required
Microsoft SharePoint Server Subscription Edition, 2019, and 2016 (CVE-2026-55040, CVSS 9.1). Chained RCE flaw CVE-2026-63520 (CVSS 8.1) also affects Project Server 2013 SP1 and Office Web Apps 2013 SP1. SharePoint Online is not affected.
highperson_alertThreat ActorDeadLock Ransomware Leverages Polygon Blockchain for Resilient Extortion
DeadLock is a ransomware group first detected in July 2025, operating double extortion campaigns that encrypt victim environments and threaten public data release.
highperson_alertThreat ActorExfilSquad Claims 2.6M Records Stolen from Wesco CRM Environment
ExfilSquad is a data extortion group that specializes in exfiltrating sensitive information from organizations and leveraging it for ransom demands. The group operates a data leak site where they publish stolen data after ransom deadlines expire.
highbug_reportVulnerabilityMalicious SIM cards can execute code on IoT cellular modules via RUN AT
Cellular IoT modules (6 of 8 tested, primarily Quectel parts with Qualcomm processors) in EV chargers, industrial routers, car telematics units. Limited phone impact: OPPO Find X5, OPPO Reno 14 F 5G, ASUS Zenfone 9.
highbug_reportVulnerabilityMozilla revokes Firefox/Thunderbird Linux signing key after repo exposure
Mozilla Firefox and Thunderbird Linux downloads (all versions signed with subkey 09BE ED63 F346 2A2D FFAB 3B87 5ECB 6497 C1A2 0256 from April 2025 to August 2026).
highperson_alertThreat ActorNorth Korea IT Worker Infiltration Targets Crypto and Tech Firms
North Korean IT worker operations, attributed by researchers to Famous Chollima (a CrowdStrike designation under the Lazarus umbrella), involve operatives seeking employment at Western technology and cryptocurrency companies under fraudulent identiti…
highbug_reportVulnerabilityKimwolf v7 botnet targets Android IoT with HTTP/2 DDoS, ENS C2 resolution
Android TV boxes and set-top boxes with unauthenticated Android Debug Bridge (ADB) exposed on port 5555. Primarily affects devices accessible via residential proxy services. ARM-based Android IoT devices running vulnerable configurations.
highpublicGeopoliticalPolish energy plant breached via private APN in coordinated OT attack
The December 2025 incident represents a sophisticated multi-site campaign against Polish critical infrastructure, attributed by Polish authorities to the Russian Electrum threat group.
highbug_reportVulnerabilityAeternum botnet uses Polygon blockchain for decentralized C2 infrastructure
Windows systems infected with Aeternum C++ botnet loader (Build.exe). The malware targets Windows environments and uses Polygon blockchain smart contracts for command and control, making traditional domain/IP-based blocking ineffective.
highbug_reportVulnerabilityBdThemes WordPress plugins compromised to create rogue admin accounts
BdThemes WordPress plugins including Element Pack (100,000+ active installs), Prime Slider, Ultimate Post Kit, Pixel Gallery, and Ultimate Store Kit. All versions using the vulnerable Biggop Library introduced in March 2026.