Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 307 results
Active filter:tag: #critical✕ clear
LiteSpeed cPanel/WHM plugin under active exploit (CVE-2026-48172)criticalbug_reportVulnerability
bug_reportVulnerability

LiteSpeed cPanel/WHM plugin under active exploit (CVE-2026-48172)

LiteSpeed plugin for cPanel/WHM. Specific vulnerable versions not disclosed in provided data. Affects web hosting environments using LiteSpeed with cPanel/WHM integration.

CVE-2026-4817226 May · 14:28 UTC
Ubiquiti patches critical UniFi OS vulnerabilitiescriticalbug_reportVulnerability
bug_reportVulnerability

Ubiquiti patches critical UniFi OS vulnerabilities

Ubiquiti UniFi OS (specific versions not disclosed). Affects UniFi network management appliances including Dream Machine, Cloud Key, and similar devices running UniFi OS.

Ubiquiti26 May · 14:13 UTC
Trend Micro Apex One & Vision One SEP flaws under active exploitcriticalbug_reportVulnerability
bug_reportVulnerability

Trend Micro Apex One & Vision One SEP flaws under active exploit

Trend Micro Apex One and Trend Micro Vision One Endpoint Security (SEP). Specific vulnerable versions not disclosed in summary; multiple vulnerabilities confirmed under active exploitation.

Trend Micro26 May · 08:17 UTC
Critical vulnerability in Cisco Secure Workload requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical vulnerability in Cisco Secure Workload requires immediate patching

Cisco Secure Workload (specific versions not disclosed in advisory). CVE identifier not yet assigned or published.

Cisco26 May · 06:50 UTC
CISA orders emergency patching of exploited Drupal SQL injection flawcriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders emergency patching of exploited Drupal SQL injection flaw

Drupal CMS (specific versions not provided in alert). Affects U.S. government agencies and all organizations running vulnerable Drupal instances.

Drupal26 May · 06:46 UTC
Ghost CMS SQL injection (CVE-2026-26980) exploited in ClickFix campaigncriticalbug_reportVulnerability
bug_reportVulnerability

Ghost CMS SQL injection (CVE-2026-26980) exploited in ClickFix campaign

Ghost CMS Content API, all versions prior to patch. Over 700 sites confirmed compromised. Unauthenticated attackers can exploit the SQL injection vulnerability remotely.

CVE-2026-2698025 May · 10:02 UTC
TrapDoor campaign deploys credential stealers across npm, PyPI, Crates.iocriticalbug_reportVulnerability
bug_reportVulnerability

TrapDoor campaign deploys credential stealers across npm, PyPI, Crates.io

34+ malicious packages (384+ versions) distributed across npm (Node.js), PyPI (Python), and Crates.io (Rust) repositories. Campaign active since May 2026. Affects developers and CI/CD pipelines consuming packages from these ecosystems.

npm25 May · 03:59 UTC
ClickFix Campaign Exploits Ghost CMS SQLi to Inject Malicious JavaScriptcriticalperson_alertThreat Actor
person_alertThreat Actor

ClickFix Campaign Exploits Ghost CMS SQLi to Inject Malicious JavaScript

The threat actor behind this campaign remains unattributed. Motivation appears to be financially driven, leveraging ClickFix social engineering tactics to deliver malware or steal credentials.

CVE-2026-2698024 May · 12:12 UTC
CISA Contractor Leaks AWS GovCloud Keys on Public GitHub Repositorycriticalperson_alertThreat Actor
person_alertThreat Actor

CISA Contractor Leaks AWS GovCloud Keys on Public GitHub Repository

The threat actor is an insider—a contractor working for the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The individual intentionally published sensitive AWS GovCloud credentials and agency secrets to a public GitHub repository.

Amazon Web Services22 May · 14:34 UTC
Trend Micro Apex One zero-day actively exploited in the wildcriticalbug_reportVulnerability
bug_reportVulnerability

Trend Micro Apex One zero-day actively exploited in the wild

Trend Micro Apex One on Windows systems. Specific affected versions not disclosed. Zero-day vulnerability with no CVE assigned yet.

Trend Micro22 May · 11:39 UTC
Drupal SQL injection under active exploitation, patch immediatelycriticalbug_reportVulnerability
bug_reportVulnerability

Drupal SQL injection under active exploitation, patch immediately

Drupal CMS installations. Specific affected versions not provided in available data. Critical SQL injection vulnerability announced this week, now actively exploited.

Drupal22 May · 11:14 UTC
Ubiquiti patches three critical unauthenticated RCE flaws in UniFi OScriticalbug_reportVulnerability
bug_reportVulnerability

Ubiquiti patches three critical unauthenticated RCE flaws in UniFi OS

Ubiquiti UniFi OS (specific versions not disclosed). Affects UniFi network management appliances including Dream Machine, Cloud Key, and other UniFi OS-based devices.

Ubiquiti22 May · 10:00 UTC
CISA: Langflow and Trend Micro Apex One flaws actively exploitedcriticalbug_reportVulnerability
bug_reportVulnerability

CISA: Langflow and Trend Micro Apex One flaws actively exploited

Langflow (CVE-2025-34291, CVSS 9.4, origin validation error) and Trend Micro Apex One (CVE unspecified). Both products confirmed under active exploitation. Specific affected versions not disclosed in summary.

CVE-2025-3429122 May · 03:47 UTC
Cisco Secure Workload REST API flaw allows unauthenticated data accesscriticalbug_reportVulnerability
bug_reportVulnerability

Cisco Secure Workload REST API flaw allows unauthenticated data access

Cisco Secure Workload (formerly Tetration). Specific affected versions not provided in available data. Vulnerability impacts REST API endpoints with insufficient authentication controls.

CVE-2026-2022322 May · 03:36 UTC
Critical SQL injection in Drupal Core requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical SQL injection in Drupal Core requires immediate patching

Drupal Core, all versions (specific affected versions not disclosed in alert). Impacts all Drupal installations until patched.

Drupal21 May · 14:42 UTC
Cisco Secure Workload max-severity flaw grants Site Admin privilegescriticalbug_reportVulnerability
bug_reportVulnerability

Cisco Secure Workload max-severity flaw grants Site Admin privileges

Cisco Secure Workload platform. Specific affected versions not provided in summary. Vulnerability allows privilege escalation to Site Admin level, affecting administrative access controls.

Cisco21 May · 11:58 UTC
Critical flaws in Sparx Pro Cloud Server actively exploited in the wildcriticalbug_reportVulnerability
bug_reportVulnerability

Critical flaws in Sparx Pro Cloud Server actively exploited in the wild

Sparx Systems Pro Cloud Server and Enterprise Architect products. Specific vulnerable versions not disclosed in summary; CERT.BE advisory should be consulted for version details.

Sparx Systems21 May · 06:49 UTC
SonicWall Gen6 SSL-VPN exploited for credential brute-force and MFA bypasscriticalbug_reportVulnerability
bug_reportVulnerability

SonicWall Gen6 SSL-VPN exploited for credential brute-force and MFA bypass

SonicWall Gen6 SSL-VPN appliances with incomplete patching. Specific firmware versions not disclosed. Affects organizations using SonicWall SSL-VPN for remote access.

SonicWall20 May · 19:19 UTC
Compromised @antv npm packages deploy credential-stealing malwarecriticalbug_reportVulnerability
bug_reportVulnerability

Compromised @antv npm packages deploy credential-stealing malware

Multiple @antv npm packages compromised with Mini Shai-Hulud malware. Affects Linux-based CI/CD pipelines using npm install. Targets credentials from GitHub, AWS, Kubernetes, HashiCorp Vault, npm, and 1Password.

npm20 May · 15:48 UTC
PgBouncer integer overflow under active exploitation, patch immediatelycriticalbug_reportVulnerability
bug_reportVulnerability

PgBouncer integer overflow under active exploitation, patch immediately

PgBouncer (PostgreSQL connection pooler) - specific affected versions not disclosed by CERT.BE. All unpatched instances should be considered at risk.

PgBouncer20 May · 12:50 UTC
Microsoft Disrupts Fox Tempest Malware-Signing-as-a-Service Operationcriticalperson_alertThreat Actor
person_alertThreat Actor

Microsoft Disrupts Fox Tempest Malware-Signing-as-a-Service Operation

Fox Tempest is a threat actor attributed by Microsoft as operating a malware-signing-as-a-service (MSaaS) business model. The actor exploited Microsoft's Artifact Signing system to provide malicious code signing services to other cybercriminals, enab…

Microsoft20 May · 12:36 UTC
Drupal critical core vulnerability with imminent exploit riskcriticalbug_reportVulnerability
bug_reportVulnerability

Drupal critical core vulnerability with imminent exploit risk

Drupal core (specific versions not disclosed). All Drupal installations should be considered at risk until patched.

Drupal20 May · 10:52 UTC
Critical Portainer vulnerabilities enable full host takeovercriticalbug_reportVulnerability
bug_reportVulnerability

Critical Portainer vulnerabilities enable full host takeover

Portainer container management platform. Specific affected versions not disclosed in summary; CERT.BE advisory should be consulted for version details. Impacts organizations using Portainer for Docker/Kubernetes management.

Portainer20 May · 03:56 UTC
ChromaDB FastAPI RCE allows unauthenticated arbitrary code executioncriticalbug_reportVulnerability
bug_reportVulnerability

ChromaDB FastAPI RCE allows unauthenticated arbitrary code execution

ChromaDB latest Python FastAPI version. Affects exposed ChromaDB servers accessible over the network. No CVE assigned yet.

ChromaDB19 May · 20:25 UTC
Critical nginx vulnerabilities enable RCE and rate-limit bypasscriticalbug_reportVulnerability
bug_reportVulnerability

Critical nginx vulnerabilities enable RCE and rate-limit bypass

nginx web server (specific versions not provided by CERT.BE advisory). Affects organizations running vulnerable nginx instances, particularly those exposed to the internet or untrusted networks.

nginx19 May · 13:05 UTC
ScadaBR 1.2.0 critical flaws enable unauthenticated remote code executioncriticalbug_reportVulnerability
bug_reportVulnerability

ScadaBR 1.2.0 critical flaws enable unauthenticated remote code execution

ScadaBR version 1.2.0, a SCADA system used in critical infrastructure sectors including energy, water, and manufacturing worldwide. All four CVEs affect the same version.

CVE-2026-860219 May · 10:00 UTC
ZKTeco CCTV cameras expose credentials via unauthenticated config portcriticalbug_reportVulnerability
bug_reportVulnerability

ZKTeco CCTV cameras expose credentials via unauthenticated config port

ZKTeco CCTV cameras, specifically model SSC335-GC2063-Face-0b77, running firmware versions prior to V5.0.1.2.20260421. Vulnerability affects an undocumented configuration export port that allows unauthenticated access to camera credentials and config…

CVE-2026-859819 May · 10:00 UTC
Microsoft Exchange Server XSS flaw actively exploited for session hijackingcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft Exchange Server XSS flaw actively exploited for session hijacking

Microsoft Exchange Server (specific versions not disclosed). Cross-Site Scripting vulnerability enabling spoofing and session hijacking. No CVE assigned yet.

Microsoft18 May · 13:25 UTC
Critical PAN-OS vulnerabilities enable auth bypass and code executioncriticalbug_reportVulnerability
bug_reportVulnerability

Critical PAN-OS vulnerabilities enable auth bypass and code execution

Palo Alto Networks PAN-OS (specific versions not provided in summary). Affects authentication controls, code execution surface, and availability.

Palo Alto Networks18 May · 12:43 UTC
Cisco Catalyst SD-WAN auth bypass grants admin access to attackerscriticalbug_reportVulnerability
bug_reportVulnerability

Cisco Catalyst SD-WAN auth bypass grants admin access to attackers

Cisco Catalyst SD-WAN platform. Specific affected versions not disclosed. Vulnerability allows authentication bypass leading to administrative access on SD-WAN infrastructure components.

Cisco18 May · 12:16 UTC