Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 675 results
highbug_reportVulnerabilityCertighost PoC released: AD CS flaw enables domain takeover via rogue CA
Microsoft Active Directory Certificate Services (AD CS) in Windows domains. CVE-2026-54121 patched in July 2026 Patch Tuesday. Affects environments using AD CS for certificate-based authentication where attackers have low-privileged domain user acces…
criticalbug_reportVulnerabilityvBulletin pre-auth RCE exploit public; patch released 4 weeks prior
vBulletin 6.2.1 and earlier, 6.1.6 and earlier. Fixed in version 6.2.2 (released July 1, 2026) and patches for 6.2.1, 6.2.0, 6.1.6. vBulletin Cloud already patched. CVE-2026-61511 assigned but no NVD record or CVSS score available yet.
highbug_reportVulnerabilityn8n sandbox escape lets authenticated editors run OS commands
n8n workflow automation platform versions <2.31.5 and 2.32.0 to <2.32.1. Exploitation requires authenticated workflow editor account. n8n Cloud impact status not disclosed. No patched 1.x release mentioned.
highbug_reportVulnerabilityMalvertising campaign targets crypto users with in-memory malware assembly
Users of Solana, Luno, and TradingView platforms targeted via malicious advertisements. Campaign uses fake webpages that deliver JavaScript-based malware assembled directly in browser memory, affecting users across all platforms and browsers.
criticalbug_reportVulnerabilityFastjson 1.x RCE under active attack; no patch available
Alibaba Fastjson versions 1.2.68 through 1.2.83 in Spring Boot executable fat-JAR deployments. Requires network-reachable JSON parsing endpoint and default SafeMode disabled. Plain JARs, generic uber-JARs, and WAR deployments are not affected.
highbug_reportVulnerabilityGitLab RCE PoC published for unpatched self-managed instances ≤18.11.3
GitLab CE/EE self-managed instances: versions 15.2.0–18.10.7, 18.11.0–18.11.4, and 19.0.0–19.0.1. All tiers (Free through Ultimate) affected. Underlying flaw in Oj gem 3.13.0–3.17.1. GitLab.com SaaS not affected.
highbug_reportVulnerabilityInsurance phishing evolves to real-time account hijacking via OTP relay
Insurance providers globally, with primary focus on Saudi Arabia; additional activity in Europe, US, and India. Affects customers of multiple insurance brands using online portals for policy management, claims, and payments.
highbug_reportVulnerabilityDNS hijacking on hotel Wi-Fi redirects users to fake Microsoft 365 logins
Wi-Fi gateways at hotels and conference centers in multiple U.S. cities, India, and Saudi Arabia. Targets traveling employees from financial services, professional services, legal, healthcare, energy, and retail sectors accessing Microsoft 365.
highbug_reportVulnerabilityCertighost exploit public for AD CS flaw allowing DC impersonation
Microsoft Active Directory Certificate Services (AD CS) on Windows Server 2012 through 2025 (including Server Core) and Windows 10 versions 1607 and 1809. Environments with Enterprise CA and default Machine certificate template are vulnerable.
criticalbug_reportVulnerabilityChatGPT Workspace Agents CSRF flaw enabled rogue AI agent deployment
OpenAI ChatGPT Workspace Agents (Agent Builder tool) used by organizations with authorized connectors (Outlook, Gmail, Google Drive, Slack, Teams, etc.). Patched as of June 8, 2026. Product being deprecated November 30, 2026.
criticalbug_reportVulnerabilityBing Images SVG flaw allowed unauthenticated RCE as SYSTEM on servers
Microsoft Bing Images service (CVE-2026-32194, CVE-2026-32191). Both Windows Server 2022 and Linux image-processing workers. Vulnerability exploitable via public "Search by Image" upload and URL-based image crawler.
highbug_reportVulnerabilityNodeBB forum software patches 8 high-severity flaws with public exploits
NodeBB forum software, all versions before 4.14.0. Fixes available in version 4.14.2 and later. Five of eight flaws affect only forums with ActivityPub federation enabled (default in v4 fresh installs, disabled in v3 upgrades).
criticalbug_reportVulnerabilityRedis patches authenticated RCE flaws in versions 6.2–8.8
Redis versions 6.2.22, 7.2.14, 7.4.9, 8.2.7, 8.4.4, 8.6.4, and 8.8.0. Exploitation requires authenticated access and RESTORE command privileges. Streams-based chain also requires EVAL and XGROUP commands; RedisBloom chain (8.8.0) requires EVAL and bu…
highbug_reportVulnerabilityDolphin X RAT uses AI profiling to prioritize high-value victims
Organizations and individuals infected with Dolphin X remote access trojan. No specific vendor products or CVEs associated; threat affects Windows endpoints where the malware is deployed via social engineering or other distribution methods.
highbug_reportVulnerabilityBing malvertising pushes fake Claude installer delivering SectopRAT
Microsoft Bing search users seeking Claude AI desktop app. Malicious Claude Artifact hosted on legitimate claude.ai domain (removed by Anthropic). At least 29 organizations compromised July 21-22, 2026.
highbug_reportVulnerabilityUAC-0099 abuses Notepad++ plugin loading to deploy LunchPoke malware
Organizations in Ukraine using Notepad++ 8.8.3. The attack does not exploit a vulnerability in Notepad++; it abuses legitimate plugin-loading functionality to deploy LunchPoke, BurnyBear, and MatchBoil V2 malware loaders via social engineering (malic…
criticalbug_reportVulnerabilityProgress Telerik UI for AJAX RCE vulnerability requires immediate patching
Progress Telerik UI for AJAX - specific affected versions not disclosed in available information. Vulnerability enables remote code execution.
criticalbug_reportVulnerabilityCheck Point privilege escalation flaws under active exploitation
Check Point products (specific versions not disclosed in available data). Three privilege escalation vulnerabilities identified, including one actively exploited flaw enabling full admin authentication bypass.
highbug_reportVulnerabilityClaude Cowork sandbox escape lets AI agent access macOS host files
Anthropic Claude Cowork macOS desktop app running local sessions. Approximately 500,000 macOS users affected prior to mitigation. Users who continue to run local execution (not cloud) remain vulnerable.
highbug_reportVulnerabilityLinux XFS race condition CVE-2026-64600 enables local root escalation
Linux kernel v4.11 and later (since February 2017) with XFS filesystem and reflink enabled (default on RHEL, Oracle Linux, Amazon Linux, Fedora, CentOS Stream, Rocky Linux, AlmaLinux, CloudLinux).
highbug_reportVulnerabilityFortiBleed campaign targets Fortinet globally; Finland unaffected
Fortinet products (specific models and versions not disclosed). Campaign active globally as of June 2026, Finland not impacted to date.
criticalbug_reportVulnerabilityCheck Point SmartConsole auth bypass zero-day exploited in the wild
Check Point SmartConsole (GUI admin panel for Security Management Server and Multi-Domain Security Management Server). CVE-2026-16232. Vulnerable configurations: Management Server IP exposed to Internet without Trusted Client IP restrictions.
criticalbug_reportVulnerabilityRefluXFS kernel flaw grants local root on default RHEL, Fedora, Amazon Linux
Linux kernel 4.11+ (2017–July 2026) on systems with XFS filesystems created with reflink=1. Default installations of RHEL/CentOS Stream/Oracle/Rocky/AlmaLinux/CloudLinux 8/9/10, Fedora Server 31+, Amazon Linux 2023, and Amazon Linux 2 (Dec 2022+) are…
criticalbug_reportVulnerabilityCheck Point SmartConsole auth bypass (CVE-2026-16232) exploited in wild
Check Point Security Management and Multi-Domain Management (MDSM) products: R77.30, R80, R80.10, R80.20, R80.30, R81, R81.10, R81.20, R82, R82.10. Affects SmartConsole login process when Management Server is exposed to internet without IP restrictio…
highbug_reportVulnerabilityUbuntu snap-confine race condition grants local users root access
Ubuntu Desktop 24.04, 25.10, and 26.04 (default installations). Vulnerable component: snap-confine in snapd. Affects systems using the set-capabilities model for privilege enforcement.
criticalbug_reportVulnerabilityWordPress Core RCE flaws CVE-2026-63030, CVE-2026-60137 under active exploit
WordPress Core (specific versions not disclosed in advisory). Two remote code execution vulnerabilities (CVE-2026-63030, CVE-2026-60137) affecting the core platform.
highbug_reportVulnerabilityAdobe Acrobat Chrome extension flaw allows WhatsApp data theft via UXSS
Adobe Acrobat Chrome extension (ID: efaidnbmnnnibpcajpcglclefindmkaj) versions up to and including 26.5.2.2. Affects 314+ million users. Exploitation impacts any web application data accessible in victim's browser, demonstrated against WhatsApp Web.
criticalbug_reportVulnerabilityMicrosoft July 2026 Patch Tuesday: 569 vulnerabilities, 56 critical
Microsoft product portfolio (specific products and versions not disclosed in available data). 569 total vulnerabilities patched, including 56 rated critical severity.
highbug_reportVulnerabilityAdobe Acrobat Chrome extension flaw exposed WhatsApp Web chats
Adobe Acrobat extension for Chrome versions 26.5.2.1 and below. Affects approximately 329 million browser installations. Exploitation requires victim to visit attacker-controlled webpage while extension is installed and WhatsApp Web is in use.
highbug_reportVulnerabilityWindmill path traversal flaw exploited to read server files unauthenticated
Windmill open-source developer platform versions prior to 1.603.3. The vulnerability affects the "get_log_file" endpoint (/api/w/{workspace}/jobs_u/get_log_file/{filename}). Approximately 170 vulnerable systems identified across 24 countries.