Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 390 results
highbug_reportVulnerabilityToshiba, Muji sites show credential-stealing prompts via polyfill supply chain
Toshiba and Muji public websites, potentially other sites using the compromised third-party polyfill library. Scope of affected sites and specific polyfill service not yet confirmed.
highbug_reportVulnerabilityCISA warns of active exploitation of SolarWinds Serv-U vulnerability
SolarWinds Serv-U managed file transfer software. Specific vulnerable versions not provided in summary; patch recently released by vendor.
highperson_alertThreat ActorUNC5221 Deploys Brickstorm, Plenet, AgentPSD in M365 Espionage Campaign
UNC5221 is a Chinese APT group attributed to conducting cyber espionage operations. The group demonstrates advanced capabilities in targeting cloud environments, specifically Microsoft 365 infrastructure.
highbug_reportVulnerabilityPrompt injection in Claude Code GitHub Action exposes workflow secrets
Anthropic's Claude Code GitHub Action (prior to mitigation). Affects GitHub workflows using the action with access to repository secrets. Vulnerability exploitable when action processes untrusted input from pull requests or external sources.
highbug_reportVulnerabilityAsin Android spyware targets Arabic-speaking users via fake apps
Android devices used by Arabic-speaking populations. Malware distributed through fake applications impersonating news sources, PDF utilities, and war-related content. Active campaigns identified since early 2025.
highbug_reportVulnerability900+ US fuel tank monitoring systems exposed online, vulnerable to attack
Over 900 automatic tank gauge (ATG) systems in the United States used to monitor fuel and chemical storage tanks in critical infrastructure. Specific vendors and product versions not disclosed.
highbug_reportVulnerabilityActive exploitation of PAN-OS CVE-2026-0257 reported by Unit 42
Palo Alto Networks PAN-OS (specific affected versions not provided in available data)
highperson_alertThreat ActorOP-512 Targets IIS Servers with Custom Web Shell Framework
OP-512 is a previously unreported threat cluster assessed by ReliaQuest with moderate to high confidence to be linked to China. The actor demonstrates espionage-focused objectives, leveraging custom web shell frameworks to compromise Microsoft Intern…
highperson_alertThreat ActorFBI Warns of FIFA World Cup 2026 Fraud Campaign with Banking Malware
This is a cybercrime campaign leveraging the FIFA World Cup 2026 tournament as a lure, rather than a single named threat actor. The campaign involves multiple financially motivated threat actors exploiting public interest in the tournament to distrib…
highperson_alertThreat ActorPCPJack Hijacks 230+ Cloud Servers for Covert SMTP Relay Network
PCPJack is a threat actor focused on compromising cloud infrastructure to establish illicit email relay networks. The actor has demonstrated capability to breach business servers across major cloud service providers (AWS, Google Cloud, Microsoft Azur…
highbug_reportVulnerabilityCisco Unified Communications Manager high severity flaw with public PoC
Cisco Unified Communications Manager (CUCM). Specific affected versions not disclosed in alert. CVE identifier not yet assigned or published.
highperson_alertThreat ActorDriveSurge Distributes Malware via ClickFix and FakeUpdate Campaigns
DriveSurge is a threat actor conducting large-scale malware distribution operations. The actor leverages compromised website infrastructure at scale, utilizing thousands of sites to host and deliver malicious payloads.
highbug_reportVulnerabilityRed Hat npm packages compromised with Miasma credential stealer
Over 30 npm packages in the '@redhat-cloud-services' namespace on npm registry. Affects developers and CI/CD pipelines consuming these packages. Specific package names and versions not yet disclosed.
highpublicGeopoliticalSpanish Police Arrest Doxer Targeting National Cybersecurity Personnel
The arrest underscores Spain's efforts to protect critical cybersecurity infrastructure personnel from targeted information operations. Doxing of government cybersecurity staff represents a significant operational security risk, potentially enabling…
highbug_reportVulnerabilityMeta AI bot exploited to hijack high-profile Instagram accounts
Meta Instagram platform, specifically the AI-powered customer support bot used for account recovery. High-profile accounts including Obama White House and U.S. Space Force Chief Master Sergeant were compromised.
highbug_reportVulnerabilityMalware campaign infects 2,000 WordPress sites using Steam profiles for C2
Nearly 2,000 WordPress websites compromised. All WordPress versions potentially affected depending on initial infection vector (likely vulnerable plugins, themes, or weak credentials).
highbug_reportVulnerabilityHard-coded credentials in KS-SOMED software enable unauthorized access
KS-SOMED software (specific versions not disclosed). Hard-coded credentials embedded in application code allow unauthorized access to affected systems.
highperson_alertThreat ActorOperation Dragon Weave targets Czech and Taiwan entities with AdaptixC2
Operation Dragon Weave is a cyber espionage campaign linked to China-aligned threat actors. The campaign's motivation appears to be intelligence collection targeting government officials, researchers, academics, and professionals in the Czech Republi…
highbug_reportVulnerabilityMalicious npm package codexui-android steals OpenAI tokens, 29K downloads
npm package codexui-android (all versions). Targets developers using OpenAI Codex APIs. Affects organizations with Node.js/npm development environments where this package was installed.
highbug_reportVulnerabilityWP Maps Pro plugin under active attack via admin account creation flaw
WP Maps Pro WordPress plugin (version details not specified). Affects WordPress sites with the plugin installed. Vulnerability allows unauthenticated attackers to create administrator accounts.
highbug_reportVulnerabilityDutch authorities dismantle botnet controlling 17M infected devices
At least 17 million infected devices globally including computers, tablets, smartphones, and IoT devices. Over 200 command-and-control servers located in the Netherlands were seized.
highbug_reportVulnerabilityCIFSwitch: Linux kernel CIFS flaw enables local privilege escalation
Linux kernel CIFS implementation across multiple distributions. Specific affected kernel versions not yet disclosed. Requires local access to exploit.
highbug_reportVulnerabilityPalo Alto PAN-OS auth bypass (CVE-2026-0257) exploited in the wild
Palo Alto Networks PAN-OS and Prisma Access. Specific affected versions not disclosed in provided data. Vulnerability impacts VPN authentication mechanisms.
highbug_reportVulnerability33 malicious npm packages deployed in dependency confusion recon campaign
npm ecosystem; organizations using private npm packages with names vulnerable to dependency confusion attacks. Affects developer workstations, CI/CD pipelines, and build environments that may inadvertently install public packages instead of intended…
highbug_reportVulnerabilityThreat actors abuse ChatGPT sharing to host fake OpenAI outage pages
OpenAI ChatGPT users globally. Threat actors exploit ChatGPT's legitimate content-sharing feature (chatgpt.com shared links) to host convincing phishing pages that impersonate OpenAI outage notifications and distribute malware posing as the ChatGPT d…
highpublicGeopoliticalCalifornia sues 23andMe over 2023 breach of genetic data
The lawsuit against 23andMe highlights growing regulatory enforcement around biometric and genetic data protection in the United States, particularly within the healthcare and biotechnology sectors.
highbug_reportVulnerabilityChatGPT Markdown renderer vulnerable to prompt injection and phishing
OpenAI ChatGPT web summary response renderer. All users interacting with ChatGPT's web interface that processes Markdown links and images are potentially affected. Specific version details not disclosed.
highbug_reportVulnerabilityOracle releases critical security patches for multiple products
Multiple Oracle products affected by high-severity vulnerabilities. Specific product names, versions, and CVE identifiers not provided in CERT.BE advisory. Likely part of Oracle's quarterly Critical Patch Update (CPU).
highbug_reportVulnerabilityCVE-2026-39987 in Marimo actively exploited for cloud credential theft
Marimo notebook platform (specific versions not disclosed). Affects internet-exposed Marimo notebook instances vulnerable to CVE-2026-39987.
highbug_reportVulnerabilityDutch authorities disrupt 17M-device botnet, seize 200+ servers
Approximately 17 million infected devices globally; over 200 servers seized from a Dutch hosting provider. Specific botnet malware family and affected device types not disclosed.