Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-21 · 02:09 UTC
articleTotal: 606 reports
Cyber Threat Daily Brief — July 21, 2026satellite_altDaily Brief
Threat Intel Brief·Daily Summary

Cyber Threat Daily Brief — July 21, 2026

Today's briefing: 3 critical and 16 high-severity threats. A total of 23 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.

3 Critical16 High23 analyses
schedule02:09 UTC
Read briefarrow_forward

Latest Reports

28 / 606 results
Windows June updates break Office launch from third-party appshighbug_reportVulnerability
bug_reportVulnerability

Windows June updates break Office launch from third-party apps

Windows systems with June 2024 updates installed. Affects third-party applications attempting to launch Microsoft Office applications or open Office documents. Specific Windows versions not yet disclosed by Microsoft.

Microsoft09:54 UTC
CISA orders patching of actively exploited Joomla JCE plugin flawcriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders patching of actively exploited Joomla JCE plugin flaw

Widget Factory Joomla Content Editor (JCE) plugin for Joomla CMS. Specific vulnerable versions not disclosed in provided data. Maximum severity rating indicates critical impact.

Widget Factory08:09 UTC
Microsoft Defender zero-day "RoguePlanet" awaits patch after disclosurehighbug_reportVulnerability
bug_reportVulnerability

Microsoft Defender zero-day "RoguePlanet" awaits patch after disclosure

Microsoft Defender (all versions currently deployed). Specific affected versions not disclosed. Impacts organizations relying on Defender for endpoint protection.

Microsoft06:32 UTC
Supply chain attack compromises 144 Mastra npm packages via hijacked accountcriticalbug_reportVulnerability
bug_reportVulnerability

Supply chain attack compromises 144 Mastra npm packages via hijacked account

144 npm packages in the @mastra/* namespace (Mastra AI framework for JavaScript/TypeScript). Attack vector: compromised npm contributor account (ehindero). All downstream projects using affected Mastra packages are potentially impacted.

Mastra05:38 UTC
ShinyHunters Claims Responsibility for Kodak Data Breachhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Claims Responsibility for Kodak Data Breach

ShinyHunters is a financially motivated cybercrime group known for conducting data theft and extortion operations against organizations across multiple sectors.

Kodak05:07 UTC
CISA: Widget Factory Joomla JCE flaw exploited in the wild (CVSS 10.0)criticalbug_reportVulnerability
bug_reportVulnerability

CISA: Widget Factory Joomla JCE flaw exploited in the wild (CVSS 10.0)

Widget Factory Joomla Content Editor (JCE). Specific affected versions not disclosed. Impacts Joomla CMS installations using the JCE component.

CVE-2026-4890703:50 UTC
Malicious JetBrains IDE plugins steal AI API keys from developershighbug_reportVulnerability
bug_reportVulnerability

Malicious JetBrains IDE plugins steal AI API keys from developers

JetBrains Marketplace users who installed any of the 15+ malicious plugins. Affects developers using JetBrains IDEs (IntelliJ IDEA, PyCharm, WebStorm, etc.) with AI API keys configured. Specific plugin names and versions not provided in summary.

JetBrains19:54 UTC
Rokarolla Android banking trojan targets 217 banking and crypto appshighbug_reportVulnerability
bug_reportVulnerability

Rokarolla Android banking trojan targets 217 banking and crypto apps

Android devices with 217 targeted banking and cryptocurrency applications. Malware features 137 commands for comprehensive device control and data exfiltration. Specific app list and Android version scope not disclosed.

BleepingComputer18:04 UTC
Google Cloud Vertex AI SDK flaw enables ML model hijacking via pickle attackhighbug_reportVulnerability
bug_reportVulnerability

Google Cloud Vertex AI SDK flaw enables ML model hijacking via pickle attack

Google Cloud Vertex AI SDK for Python. Specific affected versions not disclosed. Impacts organizations using the SDK to upload and deploy machine learning models to Google Cloud's serving infrastructure.

Google17:05 UTC
Malware campaign abuses Steam Workshop via Wallpaper Engine packageshighbug_reportVulnerability
bug_reportVulnerability

Malware campaign abuses Steam Workshop via Wallpaper Engine packages

Valve Steam Workshop users, specifically those using Wallpaper Engine application. All versions of Wallpaper Engine that integrate with Steam Workshop are potentially affected. Scope includes users downloading community-created wallpaper content.

Valve16:27 UTC
ClickFix campaigns deploy three malware loaders via fake updateshighbug_reportVulnerability
bug_reportVulnerability

ClickFix campaigns deploy three malware loaders via fake updates

Education and financial sector organizations targeted by ClickFix social engineering campaigns delivering BabaDeda Loader, Lorem Ipsum Loader, and Potemkin malware loaders through fake software update lures.

The Hacker News15:41 UTC
GhostTree Abuses NTFS Junctions to Evade Microsoft Defender Scanshighperson_alertThreat Actor
person_alertThreat Actor

GhostTree Abuses NTFS Junctions to Evade Microsoft Defender Scans

GhostTree is a threat actor that has developed an evasion technique exploiting recursive NTFS junctions to bypass antivirus scanning. The actor targets the information technology sector and leverages inherent Windows file system features to create in…

Microsoft12:17 UTC
Cisco SD-WAN vulnerability under active exploitation, patches releasedcriticalbug_reportVulnerability
bug_reportVulnerability

Cisco SD-WAN vulnerability under active exploitation, patches released

Cisco SD-WAN products. Specific affected versions not provided in available data. Organizations running Cisco SD-WAN infrastructure are potentially at risk.

Cisco11:40 UTC
Heap buffer overflow in jansi library enables code executionhighbug_reportVulnerability
bug_reportVulnerability

Heap buffer overflow in jansi library enables code execution

jansi library (all versions not specified). The jansi library is a Java library for ANSI escape sequences, commonly used in console applications and logging frameworks across Java ecosystems.

CVE-2026-848408:55 UTC
CISA orders patch for exploited LiteSpeed cPanel plugin flaw (3-day deadline)criticalbug_reportVulnerability
bug_reportVulnerability

CISA orders patch for exploited LiteSpeed cPanel plugin flaw (3-day deadline)

LiteSpeed cPanel user-end plugin (specific versions not disclosed). Affects web hosting environments using cPanel with LiteSpeed integration. U.S. federal agencies explicitly targeted by CISA directive.

CVE-2026-5442008:47 UTC
Fortinet FortiSandbox under active exploit for 3 CVEs including critical 9.1criticalbug_reportVulnerability
bug_reportVulnerability

Fortinet FortiSandbox under active exploit for 3 CVEs including critical 9.1

Fortinet FortiSandbox - specific affected versions not disclosed. Three CVEs: CVE-2026-39813 (CVSS 9.1 critical), CVE-2026-39808, CVE-2026-25089. At least one vulnerability recently patched; patch status of others unclear.

CVE-2026-2508908:30 UTC
DragonForce Ransomware Gang Deploys Backdoor.Turn via Teams Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

DragonForce Ransomware Gang Deploys Backdoor.Turn via Teams Infrastructure

DragonForce is a ransomware gang that has developed custom tooling to support their extortion operations. The group demonstrates advanced capabilities in developing bespoke malware and leveraging legitimate cloud infrastructure for command-and-contro…

Microsoft08:18 UTC
Vertex AI Python SDK vulnerable to RCE via bucket squatting attackshighbug_reportVulnerability
bug_reportVulnerability

Vertex AI Python SDK vulnerable to RCE via bucket squatting attacks

Google Vertex AI Python SDK. Affects users uploading models to Vertex AI. Vulnerability exploits bucket squatting during model upload process combined with pickle deserialization to achieve cross-tenant remote code execution.

Google08:00 UTC
China-Linked Actor Deploys Windows Variants of SprySOCKS Backdoorhighperson_alertThreat Actor
person_alertThreat Actor

China-Linked Actor Deploys Windows Variants of SprySOCKS Backdoor

A China-linked threat actor has expanded the SprySOCKS malware family beyond its original Linux platform. The actor demonstrates advanced development capabilities through the creation of two distinct Windows variants (WIN_DRV and WIN_PLUS) featuring…

Windows07:44 UTC
Active exploitation of critical FortiSandbox vulnerabilitiescriticalbug_reportVulnerability
bug_reportVulnerability

Active exploitation of critical FortiSandbox vulnerabilities

Fortinet FortiSandbox cyber threat detection platform. Specific versions not disclosed. No CVE assigned yet.

Fortinet07:19 UTC
SprySOCKS malware expands to Windows in government-targeted attackshighbug_reportVulnerability
bug_reportVulnerability

SprySOCKS malware expands to Windows in government-targeted attacks

Government organizations in at least four countries. Windows systems now targeted alongside previously known Linux variants. Specific Windows versions and attack vector not disclosed.

BleepingComputer07:00 UTC
ScarCruft Deploys NarwhalRAT via Microsoft Account Phishing Lureshighperson_alertThreat Actor
person_alertThreat Actor

ScarCruft Deploys NarwhalRAT via Microsoft Account Phishing Lures

ScarCruft (also tracked as APT37, InkySquid, Reaper, and Group123) is a North Korean state-sponsored advanced persistent threat group. The actor is attributed to North Korea's intelligence apparatus and conducts espionage operations aligned with Pyon…

Microsoft06:14 UTC
Cisco Catalyst SD-WAN Manager under active exploit (CVE-2026-20262)highbug_reportVulnerability
bug_reportVulnerability

Cisco Catalyst SD-WAN Manager under active exploit (CVE-2026-20262)

Cisco Catalyst SD-WAN Manager. Specific vulnerable versions not provided in summary. Affects web UI component accessible to authenticated remote users.

CVE-2026-2026204:05 UTC
CISA adds LiteSpeed cPanel Plugin privilege escalation to KEV cataloghighbug_reportVulnerability
bug_reportVulnerability

CISA adds LiteSpeed cPanel Plugin privilege escalation to KEV catalog

LiteSpeed cPanel Plugin (specific versions not disclosed). Affects web hosting environments using cPanel with LiteSpeed integration. Federal agencies and hosting providers running this plugin are in scope.

CVE-2026-5442003:41 UTC
DOJ seizes AI deepfake sites under new TAKE IT DOWN Act authorityhighpublicGeopolitical
publicGeopolitical

DOJ seizes AI deepfake sites under new TAKE IT DOWN Act authority

The seizure of CFAKE.com and SOCFAKE.com represents the first public enforcement action under the TAKE IT DOWN Act, signaling a U.S. policy shift toward proactive domain-level intervention against AI-enabled image-based sexual abuse.

BleepingComputer19:56 UTC
SimpleHelp OIDC flaw allows unauthenticated account creationhighbug_reportVulnerability
bug_reportVulnerability

SimpleHelp OIDC flaw allows unauthenticated account creation

SimpleHelp remote management software servers with OpenID Connect (OIDC) authentication enabled. Specific affected versions not disclosed. All SimpleHelp deployments using OIDC for technician authentication are potentially vulnerable.

SimpleHelp18:06 UTC
China-linked espionage group targets North American research networkscriticalperson_alertThreat Actor
person_alertThreat Actor

China-linked espionage group targets North American research networks

A China-linked espionage group conducted a sustained intrusion campaign lasting over one year against North American institutions. The actor's motivation appears to be intelligence collection focused on medical research, academic intellectual propert…

Google Workspace17:44 UTC
Contagious Interview targets developers via recruitment-themed phishinghighperson_alertThreat Actor
person_alertThreat Actor

Contagious Interview targets developers via recruitment-themed phishing

Contagious Interview (also tracked as DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, and DEV#POPPER) is a North Korean-aligned threat actor cluster that specializes in social engineering attacks against software developers and technology secto…

The Hacker News17:32 UTC