Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-21 · 02:09 UTC
articleTotal: 606 reports

Filtered Reports

30 / 358 results
Active filter:tag: #vulnerability✕ clear
Windows Server 2016 domain controller lookups fail after KB5087537 updatehighbug_reportVulnerability
bug_reportVulnerability

Windows Server 2016 domain controller lookups fail after KB5087537 update

Windows Server 2016 domain controllers running KB5087537 (May 2026 security update). Impacts Active Directory domain controller lookup functionality and domain connectivity.

Microsoft05:41 UTC
Digital Knowledge LMS exploited via hardcoded ASP.NET keys (CVE-2026-5426)highbug_reportVulnerability
bug_reportVulnerability

Digital Knowledge LMS exploited via hardcoded ASP.NET keys (CVE-2026-5426)

Digital Knowledge KnowledgeDeliver LMS (specific versions not disclosed). Vulnerability stems from hard-coded ASP.NET machine keys enabling authentication bypass and remote code execution.

CVE-2026-542603:19 UTC
Ghost CMS SQL injection (CVE-2026-26980) exploited in ClickFix campaigncriticalbug_reportVulnerability
bug_reportVulnerability

Ghost CMS SQL injection (CVE-2026-26980) exploited in ClickFix campaign

Ghost CMS Content API, all versions prior to patch. Over 700 sites confirmed compromised. Unauthenticated attackers can exploit the SQL injection vulnerability remotely.

CVE-2026-2698010:02 UTC
OutSystems Lifetime authorization bypass via user-controlled keyhighbug_reportVulnerability
bug_reportVulnerability

OutSystems Lifetime authorization bypass via user-controlled key

OutSystems Lifetime software. Specific affected versions not disclosed. Vulnerability allows authorization bypass through improper handling of user-controlled keys.

CVE-2026-4012708:55 UTC
TrapDoor campaign deploys credential stealers across npm, PyPI, Crates.iocriticalbug_reportVulnerability
bug_reportVulnerability

TrapDoor campaign deploys credential stealers across npm, PyPI, Crates.io

34+ malicious packages (384+ versions) distributed across npm (Node.js), PyPI (Python), and Crates.io (Rust) repositories. Campaign active since May 2026. Affects developers and CI/CD pipelines consuming packages from these ecosystems.

npm03:59 UTC
Laravel Lang packages compromised to deliver credential-stealing malwarehighbug_reportVulnerability
bug_reportVulnerability

Laravel Lang packages compromised to deliver credential-stealing malware

Laravel Lang localization packages distributed via Composer. Affects developers who installed or updated compromised packages during the attack window. Specific package names and versions not yet publicly disclosed.

Laravel18:48 UTC
Supply chain attack compromises 8 Packagist packages with malicious binaryhighbug_reportVulnerability
bug_reportVulnerability

Supply chain attack compromises 8 Packagist packages with malicious binary

Eight Composer packages on Packagist containing JavaScript components. Malicious code injected into package.json files executes a Linux binary from GitHub Releases. Downstream projects using these packages are affected.

Packagist14:07 UTC
Anthropic Glasswing project finds 10,000+ critical flaws in key softwarehighbug_reportVulnerability
bug_reportVulnerability

Anthropic Glasswing project finds 10,000+ critical flaws in key software

Widely used, systemically important software (specific products not disclosed). Over 10,000 high- or critical-severity vulnerabilities identified since project launch last month.

<UNKNOWN>09:55 UTC
Laravel-Lang packages compromised to deliver credential-stealing malwarehighbug_reportVulnerability
bug_reportVulnerability

Laravel-Lang packages compromised to deliver credential-stealing malware

Multiple Laravel-Lang PHP packages compromised: laravel-lang/lang, laravel-lang/http-statuses, laravel-lang/attributes, and laravel-lang/actions. Affects Laravel PHP applications using these localization packages.

Laravel-Lang07:51 UTC
Trend Micro Apex One zero-day actively exploited in the wildcriticalbug_reportVulnerability
bug_reportVulnerability

Trend Micro Apex One zero-day actively exploited in the wild

Trend Micro Apex One on Windows systems. Specific affected versions not disclosed. Zero-day vulnerability with no CVE assigned yet.

Trend Micro11:39 UTC
Drupal SQL injection under active exploitation, patch immediatelycriticalbug_reportVulnerability
bug_reportVulnerability

Drupal SQL injection under active exploitation, patch immediately

Drupal CMS installations. Specific affected versions not provided in available data. Critical SQL injection vulnerability announced this week, now actively exploited.

Drupal11:14 UTC
Ubiquiti patches three critical unauthenticated RCE flaws in UniFi OScriticalbug_reportVulnerability
bug_reportVulnerability

Ubiquiti patches three critical unauthenticated RCE flaws in UniFi OS

Ubiquiti UniFi OS (specific versions not disclosed). Affects UniFi network management appliances including Dream Machine, Cloud Key, and other UniFi OS-based devices.

Ubiquiti10:00 UTC
CISA: Langflow and Trend Micro Apex One flaws actively exploitedcriticalbug_reportVulnerability
bug_reportVulnerability

CISA: Langflow and Trend Micro Apex One flaws actively exploited

Langflow (CVE-2025-34291, CVSS 9.4, origin validation error) and Trend Micro Apex One (CVE unspecified). Both products confirmed under active exploitation. Specific affected versions not disclosed in summary.

CVE-2025-3429103:47 UTC
Cisco Secure Workload REST API flaw allows unauthenticated data accesscriticalbug_reportVulnerability
bug_reportVulnerability

Cisco Secure Workload REST API flaw allows unauthenticated data access

Cisco Secure Workload (formerly Tetration). Specific affected versions not provided in available data. Vulnerability impacts REST API endpoints with insufficient authentication controls.

CVE-2026-2022303:36 UTC
Chromium zero-day disclosed: JavaScript persists after browser closehighbug_reportVulnerability
bug_reportVulnerability

Chromium zero-day disclosed: JavaScript persists after browser close

Chromium-based browsers (Google Chrome, Microsoft Edge, Brave, Opera, Vivaldi) - specific affected versions not disclosed. Vulnerability remains unpatched at time of disclosure.

Google16:13 UTC
Critical SQL injection in Drupal Core requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical SQL injection in Drupal Core requires immediate patching

Drupal Core, all versions (specific affected versions not disclosed in alert). Impacts all Drupal installations until patched.

Drupal14:42 UTC
NLnet Labs patches DoS vulnerabilities in Unbound DNS resolverhighbug_reportVulnerability
bug_reportVulnerability

NLnet Labs patches DoS vulnerabilities in Unbound DNS resolver

Unbound DNS resolver by NLnet Labs. Specific vulnerable versions not provided in advisory; patched versions available. Affects organizations running Unbound for DNS resolution services.

NLnet Labs14:21 UTC
Cisco Secure Workload max-severity flaw grants Site Admin privilegescriticalbug_reportVulnerability
bug_reportVulnerability

Cisco Secure Workload max-severity flaw grants Site Admin privileges

Cisco Secure Workload platform. Specific affected versions not provided in summary. Vulnerability allows privilege escalation to Site Admin level, affecting administrative access controls.

Cisco11:58 UTC
Microsoft Defender privilege escalation CVE-2026-41091 under active exploithighbug_reportVulnerability
bug_reportVulnerability

Microsoft Defender privilege escalation CVE-2026-41091 under active exploit

Microsoft Defender on Windows systems. Specific product versions not disclosed. Vulnerability allows local attackers to escalate privileges to SYSTEM level through improper link resolution handling.

CVE-2026-4109108:55 UTC
Critical flaws in Sparx Pro Cloud Server actively exploited in the wildcriticalbug_reportVulnerability
bug_reportVulnerability

Critical flaws in Sparx Pro Cloud Server actively exploited in the wild

Sparx Systems Pro Cloud Server and Enterprise Architect products. Specific vulnerable versions not disclosed in summary; CERT.BE advisory should be consulted for version details.

Sparx Systems06:49 UTC
SonicWall Gen6 SSL-VPN exploited for credential brute-force and MFA bypasscriticalbug_reportVulnerability
bug_reportVulnerability

SonicWall Gen6 SSL-VPN exploited for credential brute-force and MFA bypass

SonicWall Gen6 SSL-VPN appliances with incomplete patching. Specific firmware versions not disclosed. Affects organizations using SonicWall SSL-VPN for remote access.

SonicWall19:19 UTC
Compromised @antv npm packages deploy credential-stealing malwarecriticalbug_reportVulnerability
bug_reportVulnerability

Compromised @antv npm packages deploy credential-stealing malware

Multiple @antv npm packages compromised with Mini Shai-Hulud malware. Affects Linux-based CI/CD pipelines using npm install. Targets credentials from GitHub, AWS, Kubernetes, HashiCorp Vault, npm, and 1Password.

npm15:48 UTC
Grafana breach via unrotated GitHub token after TanStack npm compromisehighbug_reportVulnerability
bug_reportVulnerability

Grafana breach via unrotated GitHub token after TanStack npm compromise

Grafana Labs infrastructure. Organizations using Grafana products are not directly affected by the breach itself, but should monitor for potential secondary impacts.

Grafana13:46 UTC
PgBouncer integer overflow under active exploitation, patch immediatelycriticalbug_reportVulnerability
bug_reportVulnerability

PgBouncer integer overflow under active exploitation, patch immediately

PgBouncer (PostgreSQL connection pooler) - specific affected versions not disclosed by CERT.BE. All unpatched instances should be considered at risk.

PgBouncer12:50 UTC
Drupal critical core vulnerability with imminent exploit riskcriticalbug_reportVulnerability
bug_reportVulnerability

Drupal critical core vulnerability with imminent exploit risk

Drupal core (specific versions not disclosed). All Drupal installations should be considered at risk until patched.

Drupal10:52 UTC
PinTheft Linux privilege escalation PoC released for Arch Linuxhighbug_reportVulnerability
bug_reportVulnerability

PinTheft Linux privilege escalation PoC released for Arch Linux

Arch Linux systems. Specific affected package versions not disclosed; vulnerability has been patched in recent updates. Other Linux distributions may be affected depending on package configurations.

Arch Linux08:52 UTC
Microsoft mitigates YellowKey BitLocker bypass (CVE-2026-45585)highbug_reportVulnerability
bug_reportVulnerability

Microsoft mitigates YellowKey BitLocker bypass (CVE-2026-45585)

Microsoft BitLocker on Windows systems. Specific affected versions not disclosed. Vulnerability allows bypass of BitLocker disk encryption protections.

CVE-2026-4558506:28 UTC
Microsoft mitigates YellowKey BitLocker zero-day bypass vulnerabilityhighbug_reportVulnerability
bug_reportVulnerability

Microsoft mitigates YellowKey BitLocker zero-day bypass vulnerability

Windows BitLocker across all supported Windows versions. The vulnerability allows unauthorized access to BitLocker-protected drives. No CVE assigned yet.

Microsoft05:31 UTC
PostgreSQL patches multiple high-severity flaws; version 14 EOL announcedhighbug_reportVulnerability
bug_reportVulnerability

PostgreSQL patches multiple high-severity flaws; version 14 EOL announced

PostgreSQL database server, multiple versions affected by security vulnerabilities. Version 14 reaching end-of-life, no longer receiving security updates after EOL date.

PostgreSQL04:05 UTC
Critical Portainer vulnerabilities enable full host takeovercriticalbug_reportVulnerability
bug_reportVulnerability

Critical Portainer vulnerabilities enable full host takeover

Portainer container management platform. Specific affected versions not disclosed in summary; CERT.BE advisory should be consulted for version details. Impacts organizations using Portainer for Docker/Kubernetes management.

Portainer03:56 UTC