Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 554 results
Active filter:tag: #vulnerability✕ clear
Cisco Unified CM critical flaw under active exploitation, root access riskcriticalbug_reportVulnerability
bug_reportVulnerability

Cisco Unified CM critical flaw under active exploitation, root access risk

Cisco Unified Communications Manager (CUCM) and Unified CM SME. Specific affected versions not provided in available data. Vulnerability affects HTTP request handling with unauthenticated remote attack vector.

CVE-2026-2023024 Jun · 04:50 UTC
Malicious AI skills in ClawHub marketplace evade scanners, deploy infostealershighbug_reportVulnerability
bug_reportVulnerability

Malicious AI skills in ClawHub marketplace evade scanners, deploy infostealers

ClawHub marketplace users consuming third-party AI skills. Specific affected products: OpenClaw and ClawHub platforms. Scope includes organizations deploying AI agents with marketplace-sourced skills that may contain evasive malware delivering infost…

OpenClaw, ClawHub23 Jun · 20:00 UTC
Cisco Unified Communications Manager SSRF under active exploitationhighbug_reportVulnerability
bug_reportVulnerability

Cisco Unified Communications Manager SSRF under active exploitation

Cisco Unified Communications Manager (CUCM). Specific affected versions not disclosed. SSRF vulnerability (CVE-2026-20230) allows attackers to force the server to make unauthorized requests to internal or external resources.

CVE-2026-2023023 Jun · 19:48 UTC
GitHub blocks pwn request attacks in actions/checkout starting June 2026highbug_reportVulnerability
bug_reportVulnerability

GitHub blocks pwn request attacks in actions/checkout starting June 2026

GitHub Actions workflows using actions/checkout with pull_request_target trigger. Organizations using GitHub Actions for CI/CD pipelines are affected. The security update applies to all repositories using the actions/checkout action after June 18, 20…

GitHub23 Jun · 12:22 UTC
LastPass breached via Klue supply chain attack; OAuth tokens stolenhighbug_reportVulnerability
bug_reportVulnerability

LastPass breached via Klue supply chain attack; OAuth tokens stolen

LastPass customers. Attack vector: compromised Klue third-party service leading to OAuth token theft and unauthorized access to LastPass Salesforce environment containing customer data.

LastPass23 Jun · 11:58 UTC
Totolink EX1200L router vulnerable to stack buffer overflow (RCE)highbug_reportVulnerability
bug_reportVulnerability

Totolink EX1200L router vulnerable to stack buffer overflow (RCE)

Totolink EX1200L router software. Specific affected firmware versions not disclosed. Vulnerability is a stack-based buffer overflow enabling potential remote code execution.

CVE-2026-4408923 Jun · 08:55 UTC
Malicious npm packages deliver Windows RAT to JavaScript developershighbug_reportVulnerability
bug_reportVulnerability

Malicious npm packages deliver Windows RAT to JavaScript developers

Three npm packages (aes-decode-runner-pro, postcss-minify-selector, postcss-minify-selector-parser) published within the past month. Total downloads: 145-615 per package. Affects Windows-based development environments using npm package manager.

npm23 Jun · 06:54 UTC
WhatsApp malware campaign uses fake business docs to deploy VBScript RATshighbug_reportVulnerability
bug_reportVulnerability

WhatsApp malware campaign uses fake business docs to deploy VBScript RATs

WhatsApp users across multiple countries. Attack vector: social engineering via WhatsApp messages containing malicious VBScript files disguised as business documents. Enables remote access to Windows PCs.

BleepingComputer22 Jun · 20:42 UTC
Cloud bucket hijacking flaw exploits global namespace across AWS, Azure, GCPhighbug_reportVulnerability
bug_reportVulnerability

Cloud bucket hijacking flaw exploits global namespace across AWS, Azure, GCP

AWS S3, Azure Blob Storage, and Google Cloud Storage bucket naming systems. Affects organizations using cloud storage services across all three major cloud providers.

Amazon Web Services22 Jun · 20:00 UTC
FFmpeg 'PixelSmash' flaw enables RCE on Jellyfin, DoS on multiple appshighbug_reportVulnerability
bug_reportVulnerability

FFmpeg 'PixelSmash' flaw enables RCE on Jellyfin, DoS on multiple apps

FFmpeg (version details not specified). Downstream impact: Jellyfin (remote code execution), Kodi, Emby, Nextcloud, PhotoPrism, OBS Studio (denial-of-service). Affects media processing and streaming applications using vulnerable FFmpeg libraries.

FFmpeg22 Jun · 19:05 UTC
ShapedPlugin WordPress Pro plugins backdoored via compromised update channelhighbug_reportVulnerability
bug_reportVulnerability

ShapedPlugin WordPress Pro plugins backdoored via compromised update channel

Multiple ShapedPlugin Pro WordPress plugins distributed through official licensed update channels. Exact plugin names and affected versions not specified.

ShapedPlugin22 Jun · 16:00 UTC
Microsoft patches AutoJack vulnerability chain in AutoGen Studiohighbug_reportVulnerability
bug_reportVulnerability

Microsoft patches AutoJack vulnerability chain in AutoGen Studio

Microsoft AutoGen Studio - all versions prior to the patched release. AutoGen Studio is a low-code interface for building and managing AI agents. The vulnerability chain affects users who interact with untrusted web content while AutoGen Studio is ru…

Microsoft22 Jun · 15:28 UTC
DifyTap flaws enable cross-tenant AI conversation theft in Dify platformhighbug_reportVulnerability
bug_reportVulnerability

DifyTap flaws enable cross-tenant AI conversation theft in Dify platform

Dify open-source agentic workflow platform. Specific affected versions not disclosed. Vulnerability enables cross-tenant data access, affecting multi-tenant deployments and cloud-hosted instances.

Dify22 Jun · 14:13 UTC
Dual ransomware actors operate simultaneously in Microsoft environmentshighbug_reportVulnerability
bug_reportVulnerability

Dual ransomware actors operate simultaneously in Microsoft environments

Organizations using Microsoft environments, particularly those with insufficient network segmentation and endpoint visibility. No specific product vulnerability; threat involves operational security gaps enabling parallel intrusions.

Microsoft22 Jun · 14:00 UTC
Critical RCE and XSS flaws in pgAdmin 4 enable credential theftcriticalbug_reportVulnerability
bug_reportVulnerability

Critical RCE and XSS flaws in pgAdmin 4 enable credential theft

pgAdmin 4 (specific vulnerable versions not provided in alert). pgAdmin is a web-based administration tool for PostgreSQL databases, commonly deployed in enterprise environments for database management.

pgAdmin22 Jun · 13:02 UTC
ProxySQL ACL bypass and heap corruption flaws threaten database securitycriticalbug_reportVulnerability
bug_reportVulnerability

ProxySQL ACL bypass and heap corruption flaws threaten database security

ProxySQL (specific versions not provided). Vulnerabilities include ACL bypass allowing unauthorized access and heap memory corruption potentially enabling remote code execution. Database proxy infrastructure is at risk.

ProxySQL22 Jun · 12:48 UTC
29-year-old Squid heap over-read leaks HTTP credentials in default confighighbug_reportVulnerability
bug_reportVulnerability

29-year-old Squid heap over-read leaks HTTP credentials in default config

Squid web proxy, all versions containing FTP parsing code from 1997 onward. Vulnerability present in default configuration. Affects organizations using Squid as forward or reverse proxy.

Squid22 Jun · 12:29 UTC
AryStinger botnet compromises 4,000+ legacy D-Link routers as proxieshighbug_reportVulnerability
bug_reportVulnerability

AryStinger botnet compromises 4,000+ legacy D-Link routers as proxies

Over 4,000 outdated D-Link routers worldwide, specifically legacy models no longer receiving security updates. Exact models not specified in available data.

D-Link21 Jun · 12:14 UTC
North Korean APT compromised 140+ npm packages via Mastra AI frameworkhighbug_reportVulnerability
bug_reportVulnerability

North Korean APT compromised 140+ npm packages via Mastra AI framework

Mastra AI framework and over 140 dependent npm packages. Organizations using Mastra AI or downstream dependencies in Node.js/JavaScript applications are affected.

Mastra AI20 Jun · 12:09 UTC
Unit 42 issues guidance on large-scale credential attack campaignshighbug_reportVulnerability
bug_reportVulnerability

Unit 42 issues guidance on large-scale credential attack campaigns

Organizations using security vendor devices targeted in recent credential-based attack campaigns. No specific CVE; threat involves coordinated credential compromise attempts across multiple vendors' products.

Unit 42 (Palo Alto)20 Jun · 00:05 UTC
Gravity SMTP WordPress plugin under active exploit for info disclosurehighbug_reportVulnerability
bug_reportVulnerability

Gravity SMTP WordPress plugin under active exploit for info disclosure

Gravity SMTP WordPress plugin, affecting approximately 100,000 websites. Specific vulnerable versions not disclosed in available data.

Gravity SMTP19 Jun · 18:25 UTC
Unpatchable SecureROM exploit for Apple A12/A13 chips publishedcriticalbug_reportVulnerability
bug_reportVulnerability

Unpatchable SecureROM exploit for Apple A12/A13 chips published

Apple devices with A12 and A13 chips (iPhone XS/XR/11 series, iPad Air 3rd gen, iPad mini 5th gen, iPad 8th gen). SecureROM vulnerability is permanent and cannot be patched via software updates.

Apple19 Jun · 16:37 UTC
Critical RCE in Splunk Enterprise under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Critical RCE in Splunk Enterprise under active exploitation

Splunk Enterprise (specific versions not disclosed in alert). The vulnerability enables remote code execution. CVE identifier not yet assigned or published.

Splunk19 Jun · 13:33 UTC
AutoJack exploit chain enables RCE on AI browsing agents via malicious pageshighbug_reportVulnerability
bug_reportVulnerability

AutoJack exploit chain enables RCE on AI browsing agents via malicious pages

AI browsing agents (autonomous web browsers with AI capabilities) that interact with privileged local services via JavaScript. Specific products and versions not disclosed in Microsoft's research disclosure.

Microsoft19 Jun · 13:30 UTC
CISA orders federal agencies to patch exploited Splunk Enterprise flawcriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders federal agencies to patch exploited Splunk Enterprise flaw

Splunk Enterprise (specific versions not disclosed in summary). CISA directive targets U.S. federal agencies, but vulnerability affects all Splunk Enterprise deployments.

Splunk19 Jun · 08:39 UTC
Salesforce disables Klue integration after OAuth token abuse exposes datahighbug_reportVulnerability
bug_reportVulnerability

Salesforce disables Klue integration after OAuth token abuse exposes data

Salesforce customers using the Klue Battlecards app integration. OAuth tokens were abused to access customer data. Integration disabled as of June 11, 2026.

Salesforce19 Jun · 07:03 UTC
Critical auth bypass in SimpleHelp remote support software (CVE-2026-48558)criticalbug_reportVulnerability
bug_reportVulnerability

Critical auth bypass in SimpleHelp remote support software (CVE-2026-48558)

SimpleHelp remote support software, specific versions not disclosed. Vendor patch available. Authentication bypass vulnerability allows unauthorized access.

CVE-2026-4855819 Jun · 06:46 UTC
F5 patches high-severity flaws in NGINX Open Source and Gateway Fabrichighbug_reportVulnerability
bug_reportVulnerability

F5 patches high-severity flaws in NGINX Open Source and Gateway Fabric

NGINX Open Source and NGINX Gateway Fabric (specific versions not provided). Four CVEs: CVE-2026-11311, CVE-2026-42055, CVE-2026-42530, CVE-2026-50107. Affects organizations running NGINX web servers, reverse proxies, API gateways, and Kubernetes ing…

CVE-2026-1131119 Jun · 06:24 UTC
Apple Beats Studio Buds Bluetooth flaw allows unauthorized pairinghighbug_reportVulnerability
bug_reportVulnerability

Apple Beats Studio Buds Bluetooth flaw allows unauthorized pairing

Apple Beats Studio Buds using Airoha Bluetooth audio SDK. Vulnerability affects devices prior to firmware update released by Apple. Attackers must be within Bluetooth range (typically <10 meters).

CVE-2025-2070119 Jun · 04:36 UTC
AutoJack exploit chain enables RCE on AI agent hosts via malicious webpagecriticalbug_reportVulnerability
bug_reportVulnerability

AutoJack exploit chain enables RCE on AI agent hosts via malicious webpage

Microsoft AutoGen Studio users running AI browsing agents. Affects deployments where AutoGen Studio's MCP WebSocket is accessible to localhost without authentication. Specific version range not disclosed.

Microsoft18 Jun · 22:17 UTC