Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 346 results
highbug_reportVulnerabilityCryptojacking campaign uses SEO poisoning and AI chatbots for GPU malware
High-performance systems with GPUs accessed via search engines and AI chatbot platforms. No specific vendor or product vulnerability; targets users searching for legitimate software or information through poisoned search results and manipulated chatb…
criticalbug_reportVulnerabilityApache ActiveMQ NMS AMQP Client deserialization flaw enables RCE
Apache ActiveMQ NMS AMQP Client - specific vulnerable versions not provided. Affects .NET/C# applications using the NMS AMQP client library for message queue operations.
criticalbug_reportVulnerabilityMicrosoft SharePoint RCE vulnerability requires immediate patching
Microsoft SharePoint Server (specific versions not disclosed in advisory). Organizations running on-premises SharePoint deployments are affected. SharePoint Online managed by Microsoft likely already patched.
highbug_reportVulnerabilityBanking trojans Grandoreiro and BTMOB target LATAM and Europe
Windows and Android devices in Latin America (Brazil, Mexico) and Europe (Spain, Portugal). Grandoreiro targets Windows systems at companies; BTMOB RAT targets Android mobile users in Brazil.
highbug_reportVulnerabilityMalicious npm package targets Claude AI user data directory
npm package "mouse5212-super-formatter" (all versions). Targets developers using Anthropic Claude AI tools with access to /mnt/user-data directory. Affects Node.js development environments where the malicious package was installed.
highbug_reportVulnerabilityGlassworm botnet targeting developers disrupted via C2 takedown
Software developers and development environments targeted by Glassworm botnet. The botnet leveraged Solana blockchain and BitTorrent DHT for command-and-control infrastructure, indicating attacks against software supply chains.
highbug_reportVulnerabilityCrowdStrike, Google disrupt GlassWorm C2 targeting software developers
Software developers using third-party packages and browser extensions. GlassWorm campaign active since early 2025, distributing malware through supply chain vectors including malicious packages and extensions.
highbug_reportVulnerabilityGitea auth bypass exposes private container images to unauthenticated users
Gitea versions prior to 1.26.2. All deployments using Gitea's container registry feature are affected. Unauthenticated remote attackers can pull private container images without credentials.
criticalbug_reportVulnerabilityCISA orders federal agencies to patch LiteSpeed cPanel plugin in 4 days
LiteSpeed cPanel user-end plugin. Specific vulnerable versions not disclosed. Affects organizations using cPanel with LiteSpeed integration.
highbug_reportVulnerabilityAI chatbot abuse delivers cryptojacking malware via social engineering
Users of AI chatbots (platform-agnostic); Windows systems targeted for cryptojacking payload deployment. Campaign actively observed by Microsoft; no specific product vulnerability, relies on social engineering.
highbug_reportVulnerabilityCryptojacking campaign uses SEO poisoning and ScreenConnect for GPU mining
Organizations using ScreenConnect remote access software; high-performance PCs with GPUs; users searching for compromised topics via search engines and AI chatbots. Campaign leverages Microsoft .NET utilities for execution.
criticalbug_reportVulnerabilityZero-day in KnowledgeDeliver LMS exploited to deploy Godzilla web shell
KnowledgeDeliver learning management system (specific versions unknown). Exploitation results in web shell deployment enabling persistent remote access to affected servers.
criticalbug_reportVulnerabilityLiteSpeed cPanel/WHM plugin under active exploit (CVE-2026-48172)
LiteSpeed plugin for cPanel/WHM. Specific vulnerable versions not disclosed in provided data. Affects web hosting environments using LiteSpeed with cPanel/WHM integration.
criticalbug_reportVulnerabilityUbiquiti patches critical UniFi OS vulnerabilities
Ubiquiti UniFi OS (specific versions not disclosed). Affects UniFi network management appliances including Dream Machine, Cloud Key, and similar devices running UniFi OS.
highbug_reportVulnerabilityMicrosoft patches SharePoint RCE flaw via unsafe deserialization
Microsoft SharePoint Server (specific versions not disclosed). Vulnerability involves deserialization of untrusted data leading to remote code execution with CVSS 8.8.
criticalbug_reportVulnerabilityTrend Micro Apex One & Vision One SEP flaws under active exploit
Trend Micro Apex One and Trend Micro Vision One Endpoint Security (SEP). Specific vulnerable versions not disclosed in summary; multiple vulnerabilities confirmed under active exploitation.
criticalbug_reportVulnerabilityCritical vulnerability in Cisco Secure Workload requires immediate patching
Cisco Secure Workload (specific versions not disclosed in advisory). CVE identifier not yet assigned or published.
criticalbug_reportVulnerabilityCISA orders emergency patching of exploited Drupal SQL injection flaw
Drupal CMS (specific versions not provided in alert). Affects U.S. government agencies and all organizations running vulnerable Drupal instances.
highbug_reportVulnerabilityWindows Server 2016 domain controller lookups fail after KB5087537 update
Windows Server 2016 domain controllers running KB5087537 (May 2026 security update). Impacts Active Directory domain controller lookup functionality and domain connectivity.
highbug_reportVulnerabilityDigital Knowledge LMS exploited via hardcoded ASP.NET keys (CVE-2026-5426)
Digital Knowledge KnowledgeDeliver LMS (specific versions not disclosed). Vulnerability stems from hard-coded ASP.NET machine keys enabling authentication bypass and remote code execution.
criticalbug_reportVulnerabilityGhost CMS SQL injection (CVE-2026-26980) exploited in ClickFix campaign
Ghost CMS Content API, all versions prior to patch. Over 700 sites confirmed compromised. Unauthenticated attackers can exploit the SQL injection vulnerability remotely.
highbug_reportVulnerabilityOutSystems Lifetime authorization bypass via user-controlled key
OutSystems Lifetime software. Specific affected versions not disclosed. Vulnerability allows authorization bypass through improper handling of user-controlled keys.
criticalbug_reportVulnerabilityTrapDoor campaign deploys credential stealers across npm, PyPI, Crates.io
34+ malicious packages (384+ versions) distributed across npm (Node.js), PyPI (Python), and Crates.io (Rust) repositories. Campaign active since May 2026. Affects developers and CI/CD pipelines consuming packages from these ecosystems.
highbug_reportVulnerabilityLaravel Lang packages compromised to deliver credential-stealing malware
Laravel Lang localization packages distributed via Composer. Affects developers who installed or updated compromised packages during the attack window. Specific package names and versions not yet publicly disclosed.
highbug_reportVulnerabilitySupply chain attack compromises 8 Packagist packages with malicious binary
Eight Composer packages on Packagist containing JavaScript components. Malicious code injected into package.json files executes a Linux binary from GitHub Releases. Downstream projects using these packages are affected.
highbug_reportVulnerabilityAnthropic Glasswing project finds 10,000+ critical flaws in key software
Widely used, systemically important software (specific products not disclosed). Over 10,000 high- or critical-severity vulnerabilities identified since project launch last month.
highbug_reportVulnerabilityLaravel-Lang packages compromised to deliver credential-stealing malware
Multiple Laravel-Lang PHP packages compromised: laravel-lang/lang, laravel-lang/http-statuses, laravel-lang/attributes, and laravel-lang/actions. Affects Laravel PHP applications using these localization packages.
criticalbug_reportVulnerabilityTrend Micro Apex One zero-day actively exploited in the wild
Trend Micro Apex One on Windows systems. Specific affected versions not disclosed. Zero-day vulnerability with no CVE assigned yet.
criticalbug_reportVulnerabilityDrupal SQL injection under active exploitation, patch immediately
Drupal CMS installations. Specific affected versions not provided in available data. Critical SQL injection vulnerability announced this week, now actively exploited.
criticalbug_reportVulnerabilityUbiquiti patches three critical unauthenticated RCE flaws in UniFi OS
Ubiquiti UniFi OS (specific versions not disclosed). Affects UniFi network management appliances including Dream Machine, Cloud Key, and other UniFi OS-based devices.