Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-21 · 02:09 UTC
articleTotal: 606 reports
Cyber Threat Daily Brief — July 21, 2026satellite_altDaily Brief
Threat Intel Brief·Daily Summary

Cyber Threat Daily Brief — July 21, 2026

Today's briefing: 3 critical and 16 high-severity threats. A total of 23 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.

3 Critical16 High23 analyses
schedule02:09 UTC
Read briefarrow_forward

Latest Reports

27 / 606 results
Awesome Motive CDN breach compromises WordPress plugins in supply-chain attackhighbug_reportVulnerability
bug_reportVulnerability

Awesome Motive CDN breach compromises WordPress plugins in supply-chain attack

WordPress plugins OptinMonster, TrustPulse, and PushEngage distributed via Awesome Motive's CDN. All versions served through the compromised CDN infrastructure are potentially affected.

Awesome Motive15:37 UTC
Cisco Catalyst SD-WAN Manager root privilege escalation under attackcriticalbug_reportVulnerability
bug_reportVulnerability

Cisco Catalyst SD-WAN Manager root privilege escalation under attack

Cisco Catalyst SD-WAN Manager (specific versions not provided). Vulnerability allows privilege escalation to root level on affected systems.

CVE-2026-2026215:12 UTC
LiteLLM AI gateway vulnerable to privilege escalation and RCEcriticalbug_reportVulnerability
bug_reportVulnerability

LiteLLM AI gateway vulnerable to privilege escalation and RCE

LiteLLM open-source AI gateway. Specific affected versions not disclosed. Impacts organizations using LiteLLM to manage API keys and route requests to AI providers (OpenAI, Anthropic, etc.).

LiteLLM14:39 UTC
ShinyHunters Claims Council of Europe Data Breachhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Claims Council of Europe Data Breach

ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has been active since at least 2020, targeting organizations across multiple sectors to steal sensitive databases and person…

Council of Europe14:37 UTC
Microsoft 365 Copilot SearchLeak allows data exfiltration via trusted linkhighbug_reportVulnerability
bug_reportVulnerability

Microsoft 365 Copilot SearchLeak allows data exfiltration via trusted link

Microsoft 365 Copilot Enterprise Search. All organizations using M365 Copilot with Enterprise Search enabled are potentially affected. Specific version details not disclosed.

Microsoft13:09 UTC
China-Linked Espionage Group Deploys InfiniteRed via REDCap Servershighperson_alertThreat Actor
person_alertThreat Actor

China-Linked Espionage Group Deploys InfiniteRed via REDCap Servers

This activity is attributed to a China-linked espionage group targeting healthcare and medical research sectors. The actor's motivation appears to be intelligence collection focused on sensitive medical research data, consistent with strategic intere…

REDCap12:00 UTC
SearchLeak in Microsoft 365 Copilot enables data theft via crafted URLscriticalbug_reportVulnerability
bug_reportVulnerability

SearchLeak in Microsoft 365 Copilot enables data theft via crafted URLs

Microsoft 365 Copilot Enterprise. All organizations using Copilot with access to mailbox, OneDrive, or SharePoint data are potentially affected. Specific vulnerable versions not disclosed.

Microsoft11:00 UTC
ShinyHunters Breaches 137K+ School Staff via Salesforce Attackhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Breaches 137K+ School Staff via Salesforce Attack

ShinyHunters is a financially motivated cybercrime actor specializing in large-scale data theft and extortion operations. The group has established a reputation for targeting cloud-based platforms and third-party service providers to compromise downs…

Salesforce10:38 UTC
Responsive FileManager RCE via unrestricted file upload (CVE-2026-5482)highbug_reportVulnerability
bug_reportVulnerability

Responsive FileManager RCE via unrestricted file upload (CVE-2026-5482)

Responsive FileManager (versions not specified). The vulnerability affects file upload mechanisms allowing unrestricted file uploads leading to remote code execution.

CVE-2026-548209:55 UTC
Quick.CMS deserialization flaw enables potential remote code executionhighbug_reportVulnerability
bug_reportVulnerability

Quick.CMS deserialization flaw enables potential remote code execution

Quick.CMS software (specific versions not disclosed). Affects systems where untrusted data is deserialized without proper validation.

CVE-2026-1186008:55 UTC
Supply chain attack hits PushEngage, OptinMonster, TrustPulse pluginscriticalbug_reportVulnerability
bug_reportVulnerability

Supply chain attack hits PushEngage, OptinMonster, TrustPulse plugins

WordPress sites using PushEngage, OptinMonster, and TrustPulse plugins. All versions loading compromised JavaScript files from vendor infrastructure are affected.

PushEngage07:59 UTC
Multiple high-severity vulnerabilities in GitLab CE and EE require patchinghighbug_reportVulnerability
bug_reportVulnerability

Multiple high-severity vulnerabilities in GitLab CE and EE require patching

GitLab Community Edition (CE) and Enterprise Edition (EE). Specific affected versions not provided in advisory; typically affects versions prior to latest security release.

GitLab06:25 UTC
Palo Alto PAN-OS GlobalProtect auth bypass under active exploitationhighbug_reportVulnerability
bug_reportVulnerability

Palo Alto PAN-OS GlobalProtect auth bypass under active exploitation

Palo Alto Networks PAN-OS GlobalProtect VPN portal and gateway components. Specific affected versions not disclosed in provided data. CVE-2026-0257, CVSS 7.8 (High).

CVE-2026-025704:17 UTC
FBI disrupts Outsider Enterprise Chinese phishing-as-a-service platformhighperson_alertThreat Actor
person_alertThreat Actor

FBI disrupts Outsider Enterprise Chinese phishing-as-a-service platform

Outsider Enterprise is a Chinese phishing-as-a-service (PhaaS) operation disrupted by the FBI in coordination with Google and Black Lotus Labs. The actor operated thousands of phishing websites designed to harvest credit card data and passwords from…

BleepingComputer12:36 UTC
Former Iowa school IT employee sentenced for insider cyberattackhighpublicGeopolitical
publicGeopolitical

Former Iowa school IT employee sentenced for insider cyberattack

This incident represents a domestic insider threat case within the United States education sector, rather than a state-sponsored or geopolitically motivated cyberattack. The prosecution and sentencing reflect U.S.

BleepingComputer18:53 UTC
Chinese state-sponsored hackers maintain 10-year persistent accesscriticalperson_alertThreat Actor
person_alertThreat Actor

Chinese state-sponsored hackers maintain 10-year persistent access

Chinese state-sponsored hackers, likely an advanced persistent threat (APT) group operating on behalf of the People's Republic of China. The actor demonstrated exceptional operational security and patience, maintaining covert access to a target organ…

BleepingComputer12:06 UTC
Splunk Enterprise RCE flaw allows unauthenticated remote code executioncriticalbug_reportVulnerability
bug_reportVulnerability

Splunk Enterprise RCE flaw allows unauthenticated remote code execution

Splunk Enterprise versions below 10.2.4 and 10.0.7. The vulnerability enables unauthenticated attackers to perform arbitrary file operations and achieve remote code execution. CVSS score 9.8 (Critical).

CVE-2026-2025311:23 UTC
US orders Anthropic to restrict foreign access to advanced AI modelshighpublicGeopolitical
publicGeopolitical

US orders Anthropic to restrict foreign access to advanced AI models

The directive appears to represent an expansion of US export control philosophy into the AI domain, treating advanced language models as dual-use technologies with national security implications.

Anthropic08:01 UTC
U.S. orders Anthropic to suspend foreign access to advanced AI modelshighpublicGeopolitical
publicGeopolitical

U.S. orders Anthropic to suspend foreign access to advanced AI models

The directive represents an escalation in U.S. efforts to control the diffusion of advanced artificial intelligence capabilities, treating frontier AI models as dual-use technologies with strategic implications.

Anthropic03:42 UTC
Arch User Repository supply chain attack: 400+ packages backdooredcriticalbug_reportVulnerability
bug_reportVulnerability

Arch User Repository supply chain attack: 400+ packages backdoored

Arch Linux users who installed or updated packages from the Arch User Repository (AUR) during the compromise window. Over 400 AUR packages contained malicious build scripts deploying a Rust-based infostealer.

Arch Linux17:33 UTC
Chinese Cybercrime Network Weaponizes Google Gemini AI for SMS Phishinghighperson_alertThreat Actor
person_alertThreat Actor

Chinese Cybercrime Network Weaponizes Google Gemini AI for SMS Phishing

A Chinese cybercrime network operating a phishing-as-a-service (PhaaS) platform called Outsider. The group weaponizes Google's Gemini AI to craft and conduct SMS-based phishing attacks (smishing) targeting American victims.

Google16:59 UTC
10-year-old phpBB auth bypass enables attacker login as any userhighbug_reportVulnerability
bug_reportVulnerability

10-year-old phpBB auth bypass enables attacker login as any user

phpBB forum software, versions spanning approximately 10 years (specific affected versions not disclosed). All installations running unpatched versions are vulnerable.

phpBB16:19 UTC
Velvet Ant: China-linked APT backdoors Linux auth for decade-long accesscriticalperson_alertThreat Actor
person_alertThreat Actor

Velvet Ant: China-linked APT backdoors Linux auth for decade-long access

Velvet Ant (G1047) is a China-linked advanced persistent threat actor characterized by exceptional operational security and long-term persistence capabilities.

Linux16:17 UTC
Conti Operator Pleads Guilty After Extradition to United Stateshighperson_alertThreat Actor
person_alertThreat Actor

Conti Operator Pleads Guilty After Extradition to United States

Conti is a prolific ransomware-as-a-service (RaaS) operation that emerged in 2020 and became one of the most active and financially successful cybercrime groups before its infrastructure was leaked and operations fragmented in 2022.

BleepingComputer15:54 UTC
400+ Arch User Repository packages compromised with rootkit and infostealercriticalbug_reportVulnerability
bug_reportVulnerability

400+ Arch User Repository packages compromised with rootkit and infostealer

Arch Linux users who installed or updated packages from the Arch User Repository (AUR). Over 400 AUR packages confirmed compromised. Specific package names and versions not yet disclosed.

Arch Linux15:03 UTC
Oracle PeopleSoft RCE actively exploited, immediate patching requiredcriticalbug_reportVulnerability
bug_reportVulnerability

Oracle PeopleSoft RCE actively exploited, immediate patching required

Oracle PeopleSoft (specific versions not disclosed in alert). Remote code execution vulnerability affecting internet-facing PeopleSoft instances.

Oracle12:39 UTC
AI coding agents vulnerable to code execution via crafted Sentry errorshighbug_reportVulnerability
bug_reportVulnerability

AI coding agents vulnerable to code execution via crafted Sentry errors

AI coding agents (e.g., GitHub Copilot, Cursor, Aider) integrated with Sentry error-tracking platform. Affects development environments where AI agents have code execution permissions and process Sentry error reports.

Sentry10:04 UTC