Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 358 results
highbug_reportVulnerabilityWindows Server 2016 domain controller lookups fail after KB5087537 update
Windows Server 2016 domain controllers running KB5087537 (May 2026 security update). Impacts Active Directory domain controller lookup functionality and domain connectivity.
highbug_reportVulnerabilityDigital Knowledge LMS exploited via hardcoded ASP.NET keys (CVE-2026-5426)
Digital Knowledge KnowledgeDeliver LMS (specific versions not disclosed). Vulnerability stems from hard-coded ASP.NET machine keys enabling authentication bypass and remote code execution.
criticalbug_reportVulnerabilityGhost CMS SQL injection (CVE-2026-26980) exploited in ClickFix campaign
Ghost CMS Content API, all versions prior to patch. Over 700 sites confirmed compromised. Unauthenticated attackers can exploit the SQL injection vulnerability remotely.
highbug_reportVulnerabilityOutSystems Lifetime authorization bypass via user-controlled key
OutSystems Lifetime software. Specific affected versions not disclosed. Vulnerability allows authorization bypass through improper handling of user-controlled keys.
criticalbug_reportVulnerabilityTrapDoor campaign deploys credential stealers across npm, PyPI, Crates.io
34+ malicious packages (384+ versions) distributed across npm (Node.js), PyPI (Python), and Crates.io (Rust) repositories. Campaign active since May 2026. Affects developers and CI/CD pipelines consuming packages from these ecosystems.
highbug_reportVulnerabilityLaravel Lang packages compromised to deliver credential-stealing malware
Laravel Lang localization packages distributed via Composer. Affects developers who installed or updated compromised packages during the attack window. Specific package names and versions not yet publicly disclosed.
highbug_reportVulnerabilitySupply chain attack compromises 8 Packagist packages with malicious binary
Eight Composer packages on Packagist containing JavaScript components. Malicious code injected into package.json files executes a Linux binary from GitHub Releases. Downstream projects using these packages are affected.
highbug_reportVulnerabilityAnthropic Glasswing project finds 10,000+ critical flaws in key software
Widely used, systemically important software (specific products not disclosed). Over 10,000 high- or critical-severity vulnerabilities identified since project launch last month.
highbug_reportVulnerabilityLaravel-Lang packages compromised to deliver credential-stealing malware
Multiple Laravel-Lang PHP packages compromised: laravel-lang/lang, laravel-lang/http-statuses, laravel-lang/attributes, and laravel-lang/actions. Affects Laravel PHP applications using these localization packages.
criticalbug_reportVulnerabilityTrend Micro Apex One zero-day actively exploited in the wild
Trend Micro Apex One on Windows systems. Specific affected versions not disclosed. Zero-day vulnerability with no CVE assigned yet.
criticalbug_reportVulnerabilityDrupal SQL injection under active exploitation, patch immediately
Drupal CMS installations. Specific affected versions not provided in available data. Critical SQL injection vulnerability announced this week, now actively exploited.
criticalbug_reportVulnerabilityUbiquiti patches three critical unauthenticated RCE flaws in UniFi OS
Ubiquiti UniFi OS (specific versions not disclosed). Affects UniFi network management appliances including Dream Machine, Cloud Key, and other UniFi OS-based devices.
criticalbug_reportVulnerabilityCISA: Langflow and Trend Micro Apex One flaws actively exploited
Langflow (CVE-2025-34291, CVSS 9.4, origin validation error) and Trend Micro Apex One (CVE unspecified). Both products confirmed under active exploitation. Specific affected versions not disclosed in summary.
criticalbug_reportVulnerabilityCisco Secure Workload REST API flaw allows unauthenticated data access
Cisco Secure Workload (formerly Tetration). Specific affected versions not provided in available data. Vulnerability impacts REST API endpoints with insufficient authentication controls.
highbug_reportVulnerabilityChromium zero-day disclosed: JavaScript persists after browser close
Chromium-based browsers (Google Chrome, Microsoft Edge, Brave, Opera, Vivaldi) - specific affected versions not disclosed. Vulnerability remains unpatched at time of disclosure.
criticalbug_reportVulnerabilityCritical SQL injection in Drupal Core requires immediate patching
Drupal Core, all versions (specific affected versions not disclosed in alert). Impacts all Drupal installations until patched.
highbug_reportVulnerabilityNLnet Labs patches DoS vulnerabilities in Unbound DNS resolver
Unbound DNS resolver by NLnet Labs. Specific vulnerable versions not provided in advisory; patched versions available. Affects organizations running Unbound for DNS resolution services.
criticalbug_reportVulnerabilityCisco Secure Workload max-severity flaw grants Site Admin privileges
Cisco Secure Workload platform. Specific affected versions not provided in summary. Vulnerability allows privilege escalation to Site Admin level, affecting administrative access controls.
highbug_reportVulnerabilityMicrosoft Defender privilege escalation CVE-2026-41091 under active exploit
Microsoft Defender on Windows systems. Specific product versions not disclosed. Vulnerability allows local attackers to escalate privileges to SYSTEM level through improper link resolution handling.
criticalbug_reportVulnerabilityCritical flaws in Sparx Pro Cloud Server actively exploited in the wild
Sparx Systems Pro Cloud Server and Enterprise Architect products. Specific vulnerable versions not disclosed in summary; CERT.BE advisory should be consulted for version details.
criticalbug_reportVulnerabilitySonicWall Gen6 SSL-VPN exploited for credential brute-force and MFA bypass
SonicWall Gen6 SSL-VPN appliances with incomplete patching. Specific firmware versions not disclosed. Affects organizations using SonicWall SSL-VPN for remote access.
criticalbug_reportVulnerabilityCompromised @antv npm packages deploy credential-stealing malware
Multiple @antv npm packages compromised with Mini Shai-Hulud malware. Affects Linux-based CI/CD pipelines using npm install. Targets credentials from GitHub, AWS, Kubernetes, HashiCorp Vault, npm, and 1Password.
highbug_reportVulnerabilityGrafana breach via unrotated GitHub token after TanStack npm compromise
Grafana Labs infrastructure. Organizations using Grafana products are not directly affected by the breach itself, but should monitor for potential secondary impacts.
criticalbug_reportVulnerabilityPgBouncer integer overflow under active exploitation, patch immediately
PgBouncer (PostgreSQL connection pooler) - specific affected versions not disclosed by CERT.BE. All unpatched instances should be considered at risk.
criticalbug_reportVulnerabilityDrupal critical core vulnerability with imminent exploit risk
Drupal core (specific versions not disclosed). All Drupal installations should be considered at risk until patched.
highbug_reportVulnerabilityPinTheft Linux privilege escalation PoC released for Arch Linux
Arch Linux systems. Specific affected package versions not disclosed; vulnerability has been patched in recent updates. Other Linux distributions may be affected depending on package configurations.
highbug_reportVulnerabilityMicrosoft mitigates YellowKey BitLocker bypass (CVE-2026-45585)
Microsoft BitLocker on Windows systems. Specific affected versions not disclosed. Vulnerability allows bypass of BitLocker disk encryption protections.
highbug_reportVulnerabilityMicrosoft mitigates YellowKey BitLocker zero-day bypass vulnerability
Windows BitLocker across all supported Windows versions. The vulnerability allows unauthorized access to BitLocker-protected drives. No CVE assigned yet.
highbug_reportVulnerabilityPostgreSQL patches multiple high-severity flaws; version 14 EOL announced
PostgreSQL database server, multiple versions affected by security vulnerabilities. Version 14 reaching end-of-life, no longer receiving security updates after EOL date.
criticalbug_reportVulnerabilityCritical Portainer vulnerabilities enable full host takeover
Portainer container management platform. Specific affected versions not disclosed in summary; CERT.BE advisory should be consulted for version details. Impacts organizations using Portainer for Docker/Kubernetes management.