Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
satellite_altDaily BriefCyber Threat Daily Brief — September 4, 2026
Today's briefing: 14 critical and 22 high-severity threats. A total of 47 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.
Latest Reports
27 / 1083 results
highbug_reportVulnerabilityMalware can hijack Google Password Manager passkeys on Windows via TPM abuse
Google Password Manager synced passkeys on Chrome for Windows with TPM. All three attacks require pre-existing malware on the victim's Windows device. Services that do not properly validate user verification flags (e.g., eBay, now patched) are vulner…
highperson_alertThreat ActorDOUBLECUP loader-as-a-service delivers malware via ClickFix attacks
DOUBLECUP is a Russian loader-as-a-service platform that has operated since early June 2026. The service provides customers with licenses and a Go-based Windows tool for creating malicious ClickFix campaigns.
highbug_reportVulnerabilityFake Xeno Executor installers infect Roblox players with RAT malware
Roblox players downloading fake Xeno Executor script launcher installers from gaming forums, Discord communities, and compromised accounts. Campaign active since January 2026 with sharp increase in March.
highbug_reportVulnerability18 malicious npm packages deliver cross-platform RAT to Alibaba developers
18 npm packages targeting Alibaba developer tool users, primarily Chinese-speaking environments. Key packages: lib-mtop (v1.0.1-1.0.3), aone-kit, aone-kit-cli, aone-sandbox, local-config-parser, smart-config-manager, and 12 others.
highbug_reportVulnerabilityN-able N-central auth bypass exploited; affects all pre-2026.3 versions
N-able N-central RMM platform, all versions prior to 2026.3. Affects both hosted and on-premises deployments. Hosted instances patched automatically; on-premises require manual hotfix 2026.3.1.7 installation.
highbug_reportVulnerabilityChrome Password Manager passkey bypass allows malware to hijack accounts
Google Chrome Password Manager on Windows systems with TPM. All three attack paths require malware already running as an ordinary user. Specific affected Chrome versions not disclosed.
highperson_alertThreat ActorINC Ransomware Exploits SonicWall SMA 1000 Zero-Days
INC Ransomware is a cybercrime operation conducting data extortion and ransomware attacks. The group has claimed 885 victims to date as of August 2, 2026, according to Ransomware.Live statistics.
highperson_alertThreat ActorExfilSquad Breaches UK Police Database, Leaks 100K+ Records
ExfilSquad is a data extortion group that conducts targeted intrusions to steal sensitive information and leverage it for ransom demands. The group operates by exfiltrating data from compromised organizations, publishing proof samples, and threatenin…
highbug_reportVulnerabilityBTMOB Android RAT ecosystem fragments into resellers and source-code sales
Organizations and individuals targeted by BTMOB Android RAT malware-as-a-service (MaaS). BTMOB is an Android remote access trojan distributed through multiple channels including official operators, resellers, and source-code buyers.
criticalbug_reportVulnerabilityN-Central actively exploited vulnerability requires immediate patching
N-Central remote monitoring and management (RMM) platform. Specific affected versions not disclosed in available advisory. CVE identifier not yet assigned or published.
highperson_alertThreat ActorChinese-Speaking Actor Deploys GHOSTBLADE via Leaked DarkSword iOS Kit
An unidentified Chinese-speaking threat actor conducting mobile exploitation campaigns against iOS devices. The actor operates extensive infrastructure spanning over 100 web properties concentrated in Hong Kong with reach into Japan, the United State…
highbug_reportVulnerabilityPasskey auth bypass via User Verified flag validation gap in relying parties
Relying parties (websites/services) implementing passkey authentication that fail to validate the User Verified (UV) flag in WebAuthn assertions. Affects passwordless authentication systems across multiple platforms.
highpublicGeopoliticalU.K. Police Legal Database Breach Exposes Officer Contact Data on Dark Web
The breach of the Police National Legal Database represents a targeted exposure of U.K. law enforcement and criminal justice infrastructure, albeit limited to contact metadata rather than operational intelligence.
highbug_reportVulnerabilityThermo Fisher patches DNA analysis file tampering flaw in forensic software
Thermo Fisher Applied Biosystems human identification software: 3500/3500xL Series Data Collection ≤4.0.2, 3730/3730xL Series ≤5.0.2, SeqStudio Genetic Analyzer ≤1.2.5, SeqStudio Flex ≤1.2.0, GeneMapper ID-X ≤v1.7.3.
criticalbug_reportVulnerabilityN-able N-central auth bypass exploited; incomplete patch requires upgrade
N-able N-central builds prior to 2026.3.1.7. All versions before the August 2 emergency hotfix are vulnerable. Affects MSPs and IT teams using N-central for remote monitoring and management of customer endpoints.
highbug_reportVulnerabilityHugging Face Diffusers RCE flaws bypass trust_remote_code safeguard
Hugging Face Diffusers library versions prior to 0.38.0. Affects any user invoking DiffusionPipeline.from_pretrained with custom pipelines. The library has over 8.1 million downloads monthly and is widely embedded in enterprise AI production pipeline…
criticalbug_reportVulnerabilityCOLDCARD wallet RNG flaw exploited to steal $88.6M in Bitcoin
COLDCARD hardware wallets: Mk2/Mk3 firmware 4.0.1-4.1.9, Mk4/Mk5 before 5.6.0 (standard) or 6.6.0X (Edge), Q devices before 1.5.0Q (standard) or 6.6.0QX (Edge). Seeds generated using the flawed RNG are compromised.
criticalbug_reportVulnerabilityColdcard wallet PRNG flaw enabled $70M Bitcoin theft in 41 minutes
Coldcard hardware wallets (Coinkite): Mk2 and Mk3 firmware 4.0.0–4.1.9 (fixed in 4.2.0); Mk4 and Mk5 before 5.6.0; Q model before 1.5.0Q; Edge builds before 6.6.0X (Mk4/Mk5) and 6.6.0QX (Q).
criticalbug_reportVulnerabilityRails Active Storage flaw enables file read and RCE by unauthenticated users
Ruby on Rails applications using the Active Storage framework. Specific vulnerable versions not provided in available data. Patched versions released by Rails team.
highbug_reportVulnerabilityAdform supply chain attack injected crypto wallet swapper into customer sites
Adform advertising platform customers; specifically the trackpoint-async.js file served from s2.adform[.]net. Sites embedding this tracking script were affected on July 27, 2026 (confirmed date), with reports suggesting possible exposure up to one we…
criticalbug_reportVulnerabilityAdobe Campaign Classic CVSS 10.0 flaw allows code execution without interaction
Adobe Campaign Classic (ACC) v7 versions prior to 7.4.3 build 9398 on Windows and Linux. The vulnerability affects the enterprise marketing automation platform used for customer campaign management.
highperson_alertThreat ActorStorm-2945 Hijacks Hotel Wi-Fi to Deploy CornFlake Surveillance RAT
Storm-2945 is assessed by Microsoft to be an operational sub-cluster of Midnight Blizzard (APT29, Cozy Bear), which the U.S. and U.K. governments attribute to Russia's Foreign Intelligence Service (SVR). The U.K.
highbug_reportVulnerabilityArch Linux disables AUR package adoption after malicious takeovers
Arch Linux Arch User Repository (AUR) - all community-maintained packages. Users who installed or updated AUR packages during the compromise window are potentially affected. Scope limited to AUR; official Arch repositories unaffected.
highbug_reportVulnerabilityAdform ad platform compromised to inject crypto-stealing clipboard scripts
Adform ad platform and all websites embedding Adform advertising scripts. Any site visitor copying cryptocurrency wallet addresses during the compromise window was at risk of clipboard hijacking.
highperson_alertThreat ActorStorm-2945 Exploits Captive Portals in CaptiveCrunch Espionage Campaign
Storm-2945 is an operational sub-cluster of Midnight Blizzard (APT29), a Russia-based threat actor attributed by US and UK governments to the Foreign Intelligence Service of the Russian Federation (SVR).
highperson_alertThreat ActorChinese-Speaking Actor Deploys OctLurk & SilkLurk in Central Asia
A Chinese-speaking threat actor, not yet attributed to any known APT group, has been conducting targeted cyber espionage operations against government and strategic organizations in Central Asia and Syria since January 2025.
highperson_alertThreat ActorChinese-speaking actor uses DeepSeek AI with Hermes Agent for automation
A Chinese-speaking threat actor leveraging artificial intelligence models to conduct cyberattacks. The actor employs the DeepSeek AI model in combination with the open-source Hermes Agent framework to enable autonomous offensive operations against in…