Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports
Cyber Threat Daily Brief — September 4, 2026satellite_altDaily Brief
Threat Intel Brief·Daily Summary

Cyber Threat Daily Brief — September 4, 2026

Today's briefing: 14 critical and 22 high-severity threats. A total of 47 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.

14 Critical22 High47 analyses
schedule02:17 UTC
Read briefarrow_forward

Latest Reports

27 / 1083 results
Malware can hijack Google Password Manager passkeys on Windows via TPM abusehighbug_reportVulnerability
bug_reportVulnerability

Malware can hijack Google Password Manager passkeys on Windows via TPM abuse

Google Password Manager synced passkeys on Chrome for Windows with TPM. All three attacks require pre-existing malware on the victim's Windows device. Services that do not properly validate user verification flags (e.g., eBay, now patched) are vulner…

Google3 Aug · 21:58 UTC
DOUBLECUP loader-as-a-service delivers malware via ClickFix attackshighperson_alertThreat Actor
person_alertThreat Actor

DOUBLECUP loader-as-a-service delivers malware via ClickFix attacks

DOUBLECUP is a Russian loader-as-a-service platform that has operated since early June 2026. The service provides customers with licenses and a Go-based Windows tool for creating malicious ClickFix campaigns.

Microsoft3 Aug · 18:01 UTC
Fake Xeno Executor installers infect Roblox players with RAT malwarehighbug_reportVulnerability
bug_reportVulnerability

Fake Xeno Executor installers infect Roblox players with RAT malware

Roblox players downloading fake Xeno Executor script launcher installers from gaming forums, Discord communities, and compromised accounts. Campaign active since January 2026 with sharp increase in March.

BleepingComputer3 Aug · 17:25 UTC
18 malicious npm packages deliver cross-platform RAT to Alibaba developershighbug_reportVulnerability
bug_reportVulnerability

18 malicious npm packages deliver cross-platform RAT to Alibaba developers

18 npm packages targeting Alibaba developer tool users, primarily Chinese-speaking environments. Key packages: lib-mtop (v1.0.1-1.0.3), aone-kit, aone-kit-cli, aone-sandbox, local-config-parser, smart-config-manager, and 12 others.

Alibaba3 Aug · 16:43 UTC
N-able N-central auth bypass exploited; affects all pre-2026.3 versionshighbug_reportVulnerability
bug_reportVulnerability

N-able N-central auth bypass exploited; affects all pre-2026.3 versions

N-able N-central RMM platform, all versions prior to 2026.3. Affects both hosted and on-premises deployments. Hosted instances patched automatically; on-premises require manual hotfix 2026.3.1.7 installation.

CVE-2026-185773 Aug · 15:00 UTC
Chrome Password Manager passkey bypass allows malware to hijack accountshighbug_reportVulnerability
bug_reportVulnerability

Chrome Password Manager passkey bypass allows malware to hijack accounts

Google Chrome Password Manager on Windows systems with TPM. All three attack paths require malware already running as an ordinary user. Specific affected Chrome versions not disclosed.

Google3 Aug · 14:24 UTC
INC Ransomware Exploits SonicWall SMA 1000 Zero-Dayshighperson_alertThreat Actor
person_alertThreat Actor

INC Ransomware Exploits SonicWall SMA 1000 Zero-Days

INC Ransomware is a cybercrime operation conducting data extortion and ransomware attacks. The group has claimed 885 victims to date as of August 2, 2026, according to Ransomware.Live statistics.

SonicWall3 Aug · 14:15 UTC
ExfilSquad Breaches UK Police Database, Leaks 100K+ Recordshighperson_alertThreat Actor
person_alertThreat Actor

ExfilSquad Breaches UK Police Database, Leaks 100K+ Records

ExfilSquad is a data extortion group that conducts targeted intrusions to steal sensitive information and leverage it for ransom demands. The group operates by exfiltrating data from compromised organizations, publishing proof samples, and threatenin…

Police National Legal Database3 Aug · 13:04 UTC
BTMOB Android RAT ecosystem fragments into resellers and source-code saleshighbug_reportVulnerability
bug_reportVulnerability

BTMOB Android RAT ecosystem fragments into resellers and source-code sales

Organizations and individuals targeted by BTMOB Android RAT malware-as-a-service (MaaS). BTMOB is an Android remote access trojan distributed through multiple channels including official operators, resellers, and source-code buyers.

BleepingComputer3 Aug · 12:45 UTC
N-Central actively exploited vulnerability requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

N-Central actively exploited vulnerability requires immediate patching

N-Central remote monitoring and management (RMM) platform. Specific affected versions not disclosed in available advisory. CVE identifier not yet assigned or published.

N-Central3 Aug · 11:45 UTC
Chinese-Speaking Actor Deploys GHOSTBLADE via Leaked DarkSword iOS Kithighperson_alertThreat Actor
person_alertThreat Actor

Chinese-Speaking Actor Deploys GHOSTBLADE via Leaked DarkSword iOS Kit

An unidentified Chinese-speaking threat actor conducting mobile exploitation campaigns against iOS devices. The actor operates extensive infrastructure spanning over 100 web properties concentrated in Hong Kong with reach into Japan, the United State…

Apple3 Aug · 08:49 UTC
Passkey auth bypass via User Verified flag validation gap in relying partieshighbug_reportVulnerability
bug_reportVulnerability

Passkey auth bypass via User Verified flag validation gap in relying parties

Relying parties (websites/services) implementing passkey authentication that fail to validate the User Verified (UV) flag in WebAuthn assertions. Affects passwordless authentication systems across multiple platforms.

Palo Alto Networks3 Aug · 08:00 UTC
U.K. Police Legal Database Breach Exposes Officer Contact Data on Dark WebhighpublicGeopolitical
publicGeopolitical

U.K. Police Legal Database Breach Exposes Officer Contact Data on Dark Web

The breach of the Police National Legal Database represents a targeted exposure of U.K. law enforcement and criminal justice infrastructure, albeit limited to contact metadata rather than operational intelligence.

Police National Legal Database (PNLD)3 Aug · 07:13 UTC
Thermo Fisher patches DNA analysis file tampering flaw in forensic softwarehighbug_reportVulnerability
bug_reportVulnerability

Thermo Fisher patches DNA analysis file tampering flaw in forensic software

Thermo Fisher Applied Biosystems human identification software: 3500/3500xL Series Data Collection ≤4.0.2, 3730/3730xL Series ≤5.0.2, SeqStudio Genetic Analyzer ≤1.2.5, SeqStudio Flex ≤1.2.0, GeneMapper ID-X ≤v1.7.3.

CVE-2026-175833 Aug · 06:05 UTC
N-able N-central auth bypass exploited; incomplete patch requires upgradecriticalbug_reportVulnerability
bug_reportVulnerability

N-able N-central auth bypass exploited; incomplete patch requires upgrade

N-able N-central builds prior to 2026.3.1.7. All versions before the August 2 emergency hotfix are vulnerable. Affects MSPs and IT teams using N-central for remote monitoring and management of customer endpoints.

CVE-2026-185773 Aug · 04:41 UTC
Hugging Face Diffusers RCE flaws bypass trust_remote_code safeguardhighbug_reportVulnerability
bug_reportVulnerability

Hugging Face Diffusers RCE flaws bypass trust_remote_code safeguard

Hugging Face Diffusers library versions prior to 0.38.0. Affects any user invoking DiffusionPipeline.from_pretrained with custom pipelines. The library has over 8.1 million downloads monthly and is widely embedded in enterprise AI production pipeline…

Hugging Face3 Aug · 04:40 UTC
COLDCARD wallet RNG flaw exploited to steal $88.6M in Bitcoincriticalbug_reportVulnerability
bug_reportVulnerability

COLDCARD wallet RNG flaw exploited to steal $88.6M in Bitcoin

COLDCARD hardware wallets: Mk2/Mk3 firmware 4.0.1-4.1.9, Mk4/Mk5 before 5.6.0 (standard) or 6.6.0X (Edge), Q devices before 1.5.0Q (standard) or 6.6.0QX (Edge). Seeds generated using the flawed RNG are compromised.

COLDCARD2 Aug · 19:14 UTC
Coldcard wallet PRNG flaw enabled $70M Bitcoin theft in 41 minutescriticalbug_reportVulnerability
bug_reportVulnerability

Coldcard wallet PRNG flaw enabled $70M Bitcoin theft in 41 minutes

Coldcard hardware wallets (Coinkite): Mk2 and Mk3 firmware 4.0.0–4.1.9 (fixed in 4.2.0); Mk4 and Mk5 before 5.6.0; Q model before 1.5.0Q; Edge builds before 6.6.0X (Mk4/Mk5) and 6.6.0QX (Q).

Coinkite1 Aug · 15:17 UTC
Rails Active Storage flaw enables file read and RCE by unauthenticated userscriticalbug_reportVulnerability
bug_reportVulnerability

Rails Active Storage flaw enables file read and RCE by unauthenticated users

Ruby on Rails applications using the Active Storage framework. Specific vulnerable versions not provided in available data. Patched versions released by Rails team.

Ruby on Rails1 Aug · 12:20 UTC
Adform supply chain attack injected crypto wallet swapper into customer siteshighbug_reportVulnerability
bug_reportVulnerability

Adform supply chain attack injected crypto wallet swapper into customer sites

Adform advertising platform customers; specifically the trackpoint-async.js file served from s2.adform[.]net. Sites embedding this tracking script were affected on July 27, 2026 (confirmed date), with reports suggesting possible exposure up to one we…

Adform1 Aug · 07:03 UTC
Adobe Campaign Classic CVSS 10.0 flaw allows code execution without interactioncriticalbug_reportVulnerability
bug_reportVulnerability

Adobe Campaign Classic CVSS 10.0 flaw allows code execution without interaction

Adobe Campaign Classic (ACC) v7 versions prior to 7.4.3 build 9398 on Windows and Linux. The vulnerability affects the enterprise marketing automation platform used for customer campaign management.

CVE-2026-484491 Aug · 05:12 UTC
Storm-2945 Hijacks Hotel Wi-Fi to Deploy CornFlake Surveillance RAThighperson_alertThreat Actor
person_alertThreat Actor

Storm-2945 Hijacks Hotel Wi-Fi to Deploy CornFlake Surveillance RAT

Storm-2945 is assessed by Microsoft to be an operational sub-cluster of Midnight Blizzard (APT29, Cozy Bear), which the U.S. and U.K. governments attribute to Russia's Foreign Intelligence Service (SVR). The U.K.

Microsoft1 Aug · 04:29 UTC
Arch Linux disables AUR package adoption after malicious takeovershighbug_reportVulnerability
bug_reportVulnerability

Arch Linux disables AUR package adoption after malicious takeovers

Arch Linux Arch User Repository (AUR) - all community-maintained packages. Users who installed or updated AUR packages during the compromise window are potentially affected. Scope limited to AUR; official Arch repositories unaffected.

Arch Linux31 Jul · 19:38 UTC
Adform ad platform compromised to inject crypto-stealing clipboard scriptshighbug_reportVulnerability
bug_reportVulnerability

Adform ad platform compromised to inject crypto-stealing clipboard scripts

Adform ad platform and all websites embedding Adform advertising scripts. Any site visitor copying cryptocurrency wallet addresses during the compromise window was at risk of clipboard hijacking.

Adform31 Jul · 19:09 UTC
Storm-2945 Exploits Captive Portals in CaptiveCrunch Espionage Campaignhighperson_alertThreat Actor
person_alertThreat Actor

Storm-2945 Exploits Captive Portals in CaptiveCrunch Espionage Campaign

Storm-2945 is an operational sub-cluster of Midnight Blizzard (APT29), a Russia-based threat actor attributed by US and UK governments to the Foreign Intelligence Service of the Russian Federation (SVR).

Microsoft Security31 Jul · 19:01 UTC
Chinese-Speaking Actor Deploys OctLurk & SilkLurk in Central Asiahighperson_alertThreat Actor
person_alertThreat Actor

Chinese-Speaking Actor Deploys OctLurk & SilkLurk in Central Asia

A Chinese-speaking threat actor, not yet attributed to any known APT group, has been conducting targeted cyber espionage operations against government and strategic organizations in Central Asia and Syria since January 2025.

The Hacker News31 Jul · 16:52 UTC
Chinese-speaking actor uses DeepSeek AI with Hermes Agent for automationhighperson_alertThreat Actor
person_alertThreat Actor

Chinese-speaking actor uses DeepSeek AI with Hermes Agent for automation

A Chinese-speaking threat actor leveraging artificial intelligence models to conduct cyberattacks. The actor employs the DeepSeek AI model in combination with the open-source Hermes Agent framework to enable autonomous offensive operations against in…

BleepingComputer31 Jul · 15:35 UTC