Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 675 results
Active filter:✕ clear
Certighost PoC released: AD CS flaw enables domain takeover via rogue CAhighbug_reportVulnerability
bug_reportVulnerability

Certighost PoC released: AD CS flaw enables domain takeover via rogue CA

Microsoft Active Directory Certificate Services (AD CS) in Windows domains. CVE-2026-54121 patched in July 2026 Patch Tuesday. Affects environments using AD CS for certificate-based authentication where attackers have low-privileged domain user acces…

Microsoft27 Jul · 19:00 UTC
vBulletin pre-auth RCE exploit public; patch released 4 weeks priorcriticalbug_reportVulnerability
bug_reportVulnerability

vBulletin pre-auth RCE exploit public; patch released 4 weeks prior

vBulletin 6.2.1 and earlier, 6.1.6 and earlier. Fixed in version 6.2.2 (released July 1, 2026) and patches for 6.2.1, 6.2.0, 6.1.6. vBulletin Cloud already patched. CVE-2026-61511 assigned but no NVD record or CVSS score available yet.

vBulletin27 Jul · 12:40 UTC
n8n sandbox escape lets authenticated editors run OS commandshighbug_reportVulnerability
bug_reportVulnerability

n8n sandbox escape lets authenticated editors run OS commands

n8n workflow automation platform versions <2.31.5 and 2.32.0 to <2.32.1. Exploitation requires authenticated workflow editor account. n8n Cloud impact status not disclosed. No patched 1.x release mentioned.

CVE-2026-2757727 Jul · 11:05 UTC
Malvertising campaign targets crypto users with in-memory malware assemblyhighbug_reportVulnerability
bug_reportVulnerability

Malvertising campaign targets crypto users with in-memory malware assembly

Users of Solana, Luno, and TradingView platforms targeted via malicious advertisements. Campaign uses fake webpages that deliver JavaScript-based malware assembled directly in browser memory, affecting users across all platforms and browsers.

Solana25 Jul · 13:21 UTC
Fastjson 1.x RCE under active attack; no patch availablecriticalbug_reportVulnerability
bug_reportVulnerability

Fastjson 1.x RCE under active attack; no patch available

Alibaba Fastjson versions 1.2.68 through 1.2.83 in Spring Boot executable fat-JAR deployments. Requires network-reachable JSON parsing endpoint and default SafeMode disabled. Plain JARs, generic uber-JARs, and WAR deployments are not affected.

CVE-2026-1672325 Jul · 10:52 UTC
GitLab RCE PoC published for unpatched self-managed instances ≤18.11.3highbug_reportVulnerability
bug_reportVulnerability

GitLab RCE PoC published for unpatched self-managed instances ≤18.11.3

GitLab CE/EE self-managed instances: versions 15.2.0–18.10.7, 18.11.0–18.11.4, and 19.0.0–19.0.1. All tiers (Free through Ultimate) affected. Underlying flaw in Oj gem 3.13.0–3.17.1. GitLab.com SaaS not affected.

GitLab25 Jul · 08:14 UTC
Insurance phishing evolves to real-time account hijacking via OTP relayhighbug_reportVulnerability
bug_reportVulnerability

Insurance phishing evolves to real-time account hijacking via OTP relay

Insurance providers globally, with primary focus on Saudi Arabia; additional activity in Europe, US, and India. Affects customers of multiple insurance brands using online portals for policy management, claims, and payments.

The Hacker News25 Jul · 08:14 UTC
DNS hijacking on hotel Wi-Fi redirects users to fake Microsoft 365 loginshighbug_reportVulnerability
bug_reportVulnerability

DNS hijacking on hotel Wi-Fi redirects users to fake Microsoft 365 logins

Wi-Fi gateways at hotels and conference centers in multiple U.S. cities, India, and Saudi Arabia. Targets traveling employees from financial services, professional services, legal, healthcare, energy, and retail sectors accessing Microsoft 365.

Microsoft24 Jul · 15:50 UTC
Certighost exploit public for AD CS flaw allowing DC impersonationhighbug_reportVulnerability
bug_reportVulnerability

Certighost exploit public for AD CS flaw allowing DC impersonation

Microsoft Active Directory Certificate Services (AD CS) on Windows Server 2012 through 2025 (including Server Core) and Windows 10 versions 1607 and 1809. Environments with Enterprise CA and default Machine certificate template are vulnerable.

Microsoft24 Jul · 12:15 UTC
ChatGPT Workspace Agents CSRF flaw enabled rogue AI agent deploymentcriticalbug_reportVulnerability
bug_reportVulnerability

ChatGPT Workspace Agents CSRF flaw enabled rogue AI agent deployment

OpenAI ChatGPT Workspace Agents (Agent Builder tool) used by organizations with authorized connectors (Outlook, Gmail, Google Drive, Slack, Teams, etc.). Patched as of June 8, 2026. Product being deprecated November 30, 2026.

OpenAI24 Jul · 09:53 UTC
Bing Images SVG flaw allowed unauthenticated RCE as SYSTEM on serverscriticalbug_reportVulnerability
bug_reportVulnerability

Bing Images SVG flaw allowed unauthenticated RCE as SYSTEM on servers

Microsoft Bing Images service (CVE-2026-32194, CVE-2026-32191). Both Windows Server 2022 and Linux image-processing workers. Vulnerability exploitable via public "Search by Image" upload and URL-based image crawler.

CVE-2026-3219424 Jul · 09:45 UTC
NodeBB forum software patches 8 high-severity flaws with public exploitshighbug_reportVulnerability
bug_reportVulnerability

NodeBB forum software patches 8 high-severity flaws with public exploits

NodeBB forum software, all versions before 4.14.0. Fixes available in version 4.14.2 and later. Five of eight flaws affect only forums with ActivityPub federation enabled (default in v4 fresh installs, disabled in v3 upgrades).

NodeBB24 Jul · 05:41 UTC
Redis patches authenticated RCE flaws in versions 6.2–8.8criticalbug_reportVulnerability
bug_reportVulnerability

Redis patches authenticated RCE flaws in versions 6.2–8.8

Redis versions 6.2.22, 7.2.14, 7.4.9, 8.2.7, 8.4.4, 8.6.4, and 8.8.0. Exploitation requires authenticated access and RESTORE command privileges. Streams-based chain also requires EVAL and XGROUP commands; RedisBloom chain (8.8.0) requires EVAL and bu…

Redis24 Jul · 04:58 UTC
Dolphin X RAT uses AI profiling to prioritize high-value victimshighbug_reportVulnerability
bug_reportVulnerability

Dolphin X RAT uses AI profiling to prioritize high-value victims

Organizations and individuals infected with Dolphin X remote access trojan. No specific vendor products or CVEs associated; threat affects Windows endpoints where the malware is deployed via social engineering or other distribution methods.

BleepingComputer23 Jul · 19:20 UTC
Bing malvertising pushes fake Claude installer delivering SectopRAThighbug_reportVulnerability
bug_reportVulnerability

Bing malvertising pushes fake Claude installer delivering SectopRAT

Microsoft Bing search users seeking Claude AI desktop app. Malicious Claude Artifact hosted on legitimate claude.ai domain (removed by Anthropic). At least 29 organizations compromised July 21-22, 2026.

Microsoft23 Jul · 17:48 UTC
UAC-0099 abuses Notepad++ plugin loading to deploy LunchPoke malwarehighbug_reportVulnerability
bug_reportVulnerability

UAC-0099 abuses Notepad++ plugin loading to deploy LunchPoke malware

Organizations in Ukraine using Notepad++ 8.8.3. The attack does not exploit a vulnerability in Notepad++; it abuses legitimate plugin-loading functionality to deploy LunchPoke, BurnyBear, and MatchBoil V2 malware loaders via social engineering (malic…

Notepad++23 Jul · 14:32 UTC
Progress Telerik UI for AJAX RCE vulnerability requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Progress Telerik UI for AJAX RCE vulnerability requires immediate patching

Progress Telerik UI for AJAX - specific affected versions not disclosed in available information. Vulnerability enables remote code execution.

Progress23 Jul · 13:51 UTC
Check Point privilege escalation flaws under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Check Point privilege escalation flaws under active exploitation

Check Point products (specific versions not disclosed in available data). Three privilege escalation vulnerabilities identified, including one actively exploited flaw enabling full admin authentication bypass.

Check Point23 Jul · 13:19 UTC
Claude Cowork sandbox escape lets AI agent access macOS host fileshighbug_reportVulnerability
bug_reportVulnerability

Claude Cowork sandbox escape lets AI agent access macOS host files

Anthropic Claude Cowork macOS desktop app running local sessions. Approximately 500,000 macOS users affected prior to mitigation. Users who continue to run local execution (not cloud) remain vulnerable.

Anthropic23 Jul · 11:27 UTC
Linux XFS race condition CVE-2026-64600 enables local root escalationhighbug_reportVulnerability
bug_reportVulnerability

Linux XFS race condition CVE-2026-64600 enables local root escalation

Linux kernel v4.11 and later (since February 2017) with XFS filesystem and reflink enabled (default on RHEL, Oracle Linux, Amazon Linux, Fedora, CentOS Stream, Rocky Linux, AlmaLinux, CloudLinux).

CVE-2026-6460023 Jul · 09:40 UTC
FortiBleed campaign targets Fortinet globally; Finland unaffectedhighbug_reportVulnerability
bug_reportVulnerability

FortiBleed campaign targets Fortinet globally; Finland unaffected

Fortinet products (specific models and versions not disclosed). Campaign active globally as of June 2026, Finland not impacted to date.

Fortinet23 Jul · 06:15 UTC
Check Point SmartConsole auth bypass zero-day exploited in the wildcriticalbug_reportVulnerability
bug_reportVulnerability

Check Point SmartConsole auth bypass zero-day exploited in the wild

Check Point SmartConsole (GUI admin panel for Security Management Server and Multi-Domain Security Management Server). CVE-2026-16232. Vulnerable configurations: Management Server IP exposed to Internet without Trusted Client IP restrictions.

Check Point Software23 Jul · 06:13 UTC
RefluXFS kernel flaw grants local root on default RHEL, Fedora, Amazon Linuxcriticalbug_reportVulnerability
bug_reportVulnerability

RefluXFS kernel flaw grants local root on default RHEL, Fedora, Amazon Linux

Linux kernel 4.11+ (2017–July 2026) on systems with XFS filesystems created with reflink=1. Default installations of RHEL/CentOS Stream/Oracle/Rocky/AlmaLinux/CloudLinux 8/9/10, Fedora Server 31+, Amazon Linux 2023, and Amazon Linux 2 (Dec 2022+) are…

CVE-2026-6460023 Jul · 06:04 UTC
Check Point SmartConsole auth bypass (CVE-2026-16232) exploited in wildcriticalbug_reportVulnerability
bug_reportVulnerability

Check Point SmartConsole auth bypass (CVE-2026-16232) exploited in wild

Check Point Security Management and Multi-Domain Management (MDSM) products: R77.30, R80, R80.10, R80.20, R80.30, R81, R81.10, R81.20, R82, R82.10. Affects SmartConsole login process when Management Server is exposed to internet without IP restrictio…

CVE-2026-1623223 Jul · 04:34 UTC
Ubuntu snap-confine race condition grants local users root accesshighbug_reportVulnerability
bug_reportVulnerability

Ubuntu snap-confine race condition grants local users root access

Ubuntu Desktop 24.04, 25.10, and 26.04 (default installations). Vulnerable component: snap-confine in snapd. Affects systems using the set-capabilities model for privilege enforcement.

CVE-2026-893322 Jul · 16:07 UTC
WordPress Core RCE flaws CVE-2026-63030, CVE-2026-60137 under active exploitcriticalbug_reportVulnerability
bug_reportVulnerability

WordPress Core RCE flaws CVE-2026-63030, CVE-2026-60137 under active exploit

WordPress Core (specific versions not disclosed in advisory). Two remote code execution vulnerabilities (CVE-2026-63030, CVE-2026-60137) affecting the core platform.

CVE-2026-6013722 Jul · 14:09 UTC
Adobe Acrobat Chrome extension flaw allows WhatsApp data theft via UXSShighbug_reportVulnerability
bug_reportVulnerability

Adobe Acrobat Chrome extension flaw allows WhatsApp data theft via UXSS

Adobe Acrobat Chrome extension (ID: efaidnbmnnnibpcajpcglclefindmkaj) versions up to and including 26.5.2.2. Affects 314+ million users. Exploitation impacts any web application data accessible in victim's browser, demonstrated against WhatsApp Web.

CVE-2026-4829422 Jul · 13:01 UTC
Microsoft July 2026 Patch Tuesday: 569 vulnerabilities, 56 criticalcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft July 2026 Patch Tuesday: 569 vulnerabilities, 56 critical

Microsoft product portfolio (specific products and versions not disclosed in available data). 569 total vulnerabilities patched, including 56 rated critical severity.

Microsoft22 Jul · 12:32 UTC
Adobe Acrobat Chrome extension flaw exposed WhatsApp Web chatshighbug_reportVulnerability
bug_reportVulnerability

Adobe Acrobat Chrome extension flaw exposed WhatsApp Web chats

Adobe Acrobat extension for Chrome versions 26.5.2.1 and below. Affects approximately 329 million browser installations. Exploitation requires victim to visit attacker-controlled webpage while extension is installed and WhatsApp Web is in use.

Adobe22 Jul · 11:22 UTC
Windmill path traversal flaw exploited to read server files unauthenticatedhighbug_reportVulnerability
bug_reportVulnerability

Windmill path traversal flaw exploited to read server files unauthenticated

Windmill open-source developer platform versions prior to 1.603.3. The vulnerability affects the "get_log_file" endpoint (/api/w/{workspace}/jobs_u/get_log_file/{filename}). Approximately 170 vulnerable systems identified across 24 countries.

CVE-2026-2905922 Jul · 10:36 UTC