Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 415 results
Active filter:tag: #geopolitical✕ clear
Critical RCE in Veeam Backup & Replication requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical RCE in Veeam Backup & Replication requires immediate patching

Veeam Backup & Replication (specific versions not disclosed in summary). Remote code execution vulnerability allows attackers to execute arbitrary code on affected systems.

Veeam10 Jun · 16:20 UTC
China-Nexus Actors Expand JDY Botnet to 1,500+ IoT/SOHO Deviceshighperson_alertThreat Actor
person_alertThreat Actor

China-Nexus Actors Expand JDY Botnet to 1,500+ IoT/SOHO Devices

China-nexus state-sponsored threat actors operating the JDY botnet infrastructure. The actors leverage compromised small office/home office (SOHO) routers and IoT devices to build a distributed scanning platform for cyber reconnaissance operations.

The Hacker News10 Jun · 14:08 UTC
Microsoft June 2025 Patch Tuesday: 206 vulnerabilities, 33 criticalcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft June 2025 Patch Tuesday: 206 vulnerabilities, 33 critical

Microsoft products across the ecosystem. 206 total vulnerabilities: 33 critical, 173 important severity. Specific affected products and CVE identifiers not yet detailed in available information.

Microsoft10 Jun · 13:47 UTC
Volt Typhoon Expands JDY Botnet Operations Against U.S. Militaryhighperson_alertThreat Actor
person_alertThreat Actor

Volt Typhoon Expands JDY Botnet Operations Against U.S. Military

Volt Typhoon (also tracked as BRONZE SILHOUETTE, Vanguard Panda, DEV-0391, and UNC3236) is a Chinese state-sponsored APT group attributed to conducting cyber espionage operations targeting critical infrastructure.

BleepingComputer10 Jun · 13:00 UTC
Cisco Catalyst SD-WAN Manager actively exploited (CVE-2026-20245)highbug_reportVulnerability
bug_reportVulnerability

Cisco Catalyst SD-WAN Manager actively exploited (CVE-2026-20245)

Cisco Catalyst SD-WAN Manager. Specific affected versions not disclosed. Vulnerability involves improper encoding or escaping of output (CVSS 7.8). Also affects products from Google and Arista (details not provided).

CVE-2026-2024510 Jun · 12:44 UTC
Aix-DB missing authentication flaw allows unauthorized critical accesshighbug_reportVulnerability
bug_reportVulnerability

Aix-DB missing authentication flaw allows unauthorized critical access

Aix-DB software (vendor: Aix-DB). Specific affected versions not disclosed. Vulnerability allows unauthenticated access to critical functions (CWE-306).

CVE-2026-833510 Jun · 08:55 UTC
Windows Server domain controllers under active RCE attackcriticalbug_reportVulnerability
bug_reportVulnerability

Windows Server domain controllers under active RCE attack

Windows Server domain controllers (all supported versions). Specific version details not yet published by Microsoft. Unauthenticated remote code execution vulnerability.

Microsoft10 Jun · 06:47 UTC
SAP releases critical patches for multiple productscriticalbug_reportVulnerability
bug_reportVulnerability

SAP releases critical patches for multiple products

Multiple SAP products affected. Specific product names and versions not disclosed in available information. Patches released by SAP to address critical-severity vulnerabilities.

SAP9 Jun · 12:23 UTC
WinRAR CVE-2025-8088 path traversal exploited by Russian APTs vs Ukrainehighbug_reportVulnerability
bug_reportVulnerability

WinRAR CVE-2025-8088 path traversal exploited by Russian APTs vs Ukraine

WinRAR versions prior to patched release (approximately one year old). Primary targets: Ukrainian organizations. Threat actors: Earth Dahu (Gamaredon) and SHADOW-EARTH-066 (UAC-0226), Russia-aligned APT groups.

CVE-2025-80889 Jun · 10:26 UTC
Check Point VPN authentication flaw under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Check Point VPN authentication flaw under active exploitation

Check Point VPN products with user authentication functionality. Specific affected versions not disclosed. CVE identifier not yet assigned.

Check Point9 Jun · 10:15 UTC
FROST attack enables website-based user tracking via SSD timing analysishighbug_reportVulnerability
bug_reportVulnerability

FROST attack enables website-based user tracking via SSD timing analysis

All systems with SSDs accessed via web browsers supporting high-resolution JavaScript timers. Attack affects users across Windows, Linux, and macOS platforms. No specific browser, SSD model, or OS version is immune.

The Hacker News9 Jun · 07:50 UTC
BerriAI LiteLLM command injection under active exploitation (CISA KEV)highbug_reportVulnerability
bug_reportVulnerability

BerriAI LiteLLM command injection under active exploitation (CISA KEV)

BerriAI LiteLLM - specific vulnerable versions not disclosed in summary. Command injection vulnerability (CVE-2026-42271) affects authenticated users with access to the system.

CVE-2026-422719 Jun · 04:26 UTC
SoFi Hong Kong reports third-party vendor breach exposing customer datahighpublicGeopolitical
publicGeopolitical

SoFi Hong Kong reports third-party vendor breach exposing customer data

The incident reflects the persistent vulnerability of financial services supply chains in Hong Kong, a major international financial hub operating under the "One Country, Two Systems" framework.

SoFi8 Jun · 19:55 UTC
Meta blocks NSO Group spear-phishing targeting WhatsApp usershighperson_alertThreat Actor
person_alertThreat Actor

Meta blocks NSO Group spear-phishing targeting WhatsApp users

NSO Group is an Israeli commercial surveillance vendor that develops and sells offensive cyber capabilities, primarily the Pegasus spyware platform, to government clients.

Meta8 Jun · 15:08 UTC
Three high-severity XSS flaws in VMware Telco Cloud and Aria Operationshighbug_reportVulnerability
bug_reportVulnerability

Three high-severity XSS flaws in VMware Telco Cloud and Aria Operations

VMware Telco Cloud/vSphere Foundation and VMware Aria Operations. Specific affected versions not provided in advisory; consult VMware security bulletin for version details.

VMware8 Jun · 13:05 UTC
SolarWinds Serv-U actively exploited for resource exhaustion attackscriticalbug_reportVulnerability
bug_reportVulnerability

SolarWinds Serv-U actively exploited for resource exhaustion attacks

SolarWinds Serv-U file transfer software, unpatched versions. Specific vulnerable version range not disclosed in summary. CVE identifier not yet assigned.

SolarWinds8 Jun · 13:04 UTC
Check Point patches zero-day in VPN/Mobile Access exploited by Qilincriticalbug_reportVulnerability
bug_reportVulnerability

Check Point patches zero-day in VPN/Mobile Access exploited by Qilin

Check Point Remote Access VPN and Mobile Access deployments. Specific product versions not disclosed in summary; refer to vendor advisory for affected releases and patched versions.

Check Point8 Jun · 11:05 UTC
Oxford University CareerConnect platform breached via third-party providerhighpublicGeopolitical
publicGeopolitical

Oxford University CareerConnect platform breached via third-party provider

The breach of Oxford University's CareerConnect platform represents a supply chain compromise affecting a high-value target within the United Kingdom's higher education sector.

Group GTI8 Jun · 09:14 UTC
VerdantBamboo deploys BSD BRICKSTORM variant with Linux malwarehighperson_alertThreat Actor
person_alertThreat Actor

VerdantBamboo deploys BSD BRICKSTORM variant with Linux malware

VerdantBamboo is a China-nexus cyber espionage group attributed by Volexity, with operational overlap with the threat cluster known as Clay Typhoon. The actor focuses on intelligence collection operations and has demonstrated cross-platform capabilit…

The Hacker News8 Jun · 08:27 UTC
Critical vulnerability in MISP requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical vulnerability in MISP requires immediate patching

MISP (Malware Information Sharing Platform) - specific versions not disclosed in advisory. All unpatched instances potentially affected.

MISP8 Jun · 06:28 UTC
UNC3753 Conducts Data Theft Extortion via Vishing and Physical Intrusionhighperson_alertThreat Actor
person_alertThreat Actor

UNC3753 Conducts Data Theft Extortion via Vishing and Physical Intrusion

UNC3753 is a financially motivated threat actor attributed by Mandiant. The group conducted a data theft extortion campaign targeting dozens of organizations in the United States between January and May 2026.

The Hacker News8 Jun · 05:39 UTC
Silent Ransom Group targets U.S. legal sector via fake IT supporthighperson_alertThreat Actor
person_alertThreat Actor

Silent Ransom Group targets U.S. legal sector via fake IT support

Silent Ransom Group is a threat actor conducting social engineering-driven intrusions against U.S. legal services and professional services organizations.

BleepingComputer7 Jun · 12:09 UTC
SolarWinds Serv-U DoS flaw actively exploited, added to CISA KEVhighbug_reportVulnerability
bug_reportVulnerability

SolarWinds Serv-U DoS flaw actively exploited, added to CISA KEV

SolarWinds Serv-U multi-protocol file server. Specific affected versions not disclosed in provided data. The vulnerability causes service crashes via denial-of-service attacks.

CVE-2026-283186 Jun · 06:14 UTC
UNC5221 Deploys Brickstorm, Plenet, AgentPSD in M365 Espionage Campaignhighperson_alertThreat Actor
person_alertThreat Actor

UNC5221 Deploys Brickstorm, Plenet, AgentPSD in M365 Espionage Campaign

UNC5221 is a Chinese APT group attributed to conducting cyber espionage operations. The group demonstrates advanced capabilities in targeting cloud environments, specifically Microsoft 365 infrastructure.

Microsoft5 Jun · 16:09 UTC
Asin Android spyware targets Arabic-speaking users via fake appshighbug_reportVulnerability
bug_reportVulnerability

Asin Android spyware targets Arabic-speaking users via fake apps

Android devices used by Arabic-speaking populations. Malware distributed through fake applications impersonating news sources, PDF utilities, and war-related content. Active campaigns identified since early 2025.

Android5 Jun · 12:53 UTC
900+ US fuel tank monitoring systems exposed online, vulnerable to attackhighbug_reportVulnerability
bug_reportVulnerability

900+ US fuel tank monitoring systems exposed online, vulnerable to attack

Over 900 automatic tank gauge (ATG) systems in the United States used to monitor fuel and chemical storage tanks in critical infrastructure. Specific vendors and product versions not disclosed.

BleepingComputer5 Jun · 12:50 UTC
OP-512 Targets IIS Servers with Custom Web Shell Frameworkhighperson_alertThreat Actor
person_alertThreat Actor

OP-512 Targets IIS Servers with Custom Web Shell Framework

OP-512 is a previously unreported threat cluster assessed by ReliaQuest with moderate to high confidence to be linked to China. The actor demonstrates espionage-focused objectives, leveraging custom web shell frameworks to compromise Microsoft Intern…

Microsoft5 Jun · 10:33 UTC
Critical vulnerabilities in Gladinet Triofox require immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical vulnerabilities in Gladinet Triofox require immediate patching

Gladinet Triofox file sharing and collaboration platform. Specific affected versions not disclosed in available data. All unpatched instances should be considered at risk.

Gladinet5 Jun · 03:54 UTC
PCPJack Hijacks 230+ Cloud Servers for Covert SMTP Relay Networkhighperson_alertThreat Actor
person_alertThreat Actor

PCPJack Hijacks 230+ Cloud Servers for Covert SMTP Relay Network

PCPJack is a threat actor focused on compromising cloud infrastructure to establish illicit email relay networks. The actor has demonstrated capability to breach business servers across major cloud service providers (AWS, Google Cloud, Microsoft Azur…

Amazon Web Services5 Jun · 03:34 UTC
Cisco Unified Communications Manager high severity flaw with public PoChighbug_reportVulnerability
bug_reportVulnerability

Cisco Unified Communications Manager high severity flaw with public PoC

Cisco Unified Communications Manager (CUCM). Specific affected versions not disclosed in alert. CVE identifier not yet assigned or published.

Cisco5 Jun · 03:28 UTC