Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 675 results
Active filter:✕ clear
CISA orders urgent patching of exploited Langflow RCE (CVE-2026-0770)criticalbug_reportVulnerability
bug_reportVulnerability

CISA orders urgent patching of exploited Langflow RCE (CVE-2026-0770)

Langflow visual framework for building AI agents. All unpatched versions vulnerable. Affects unauthenticated remote attackers who can reach the /api/v1/validate/code endpoint. Federal agencies must patch by July 25, 2026.

Langflow22 Jul · 09:43 UTC
Microsoft SharePoint RCE flaws actively exploited; immediate patching requiredcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft SharePoint RCE flaws actively exploited; immediate patching required

Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. Five critical vulnerabilities: CVE-2026-50522 (CVSS 9.8, deserialization RCE), CVE-2026-58644 (CVSS 9.8, unauthenticated RCE), CVE-2026-5…

Microsoft22 Jul · 08:39 UTC
Trojanized NuGet package targets Digitain betting platform via typosquattinghighbug_reportVulnerability
bug_reportVulnerability

Trojanized NuGet package targets Digitain betting platform via typosquatting

NuGet package "Newtonsoftt.Json.Net" versions 11.0.4, 11.0.5, 11.0.7, 11.0.8, 11.0.9, 11.0.10, and 11.0.11 (typosquat of Newtonsoft.Json). Primary target: Digitain FG-Crash betting game backend. Downloaded ~1,200 times.

Newtonsoft22 Jul · 04:00 UTC
Azure DevOps MCP server flaw lets hidden PR comments hijack AI agentshighbug_reportVulnerability
bug_reportVulnerability

Azure DevOps MCP server flaw lets hidden PR comments hijack AI agents

Microsoft Azure DevOps MCP server versions up to and including v2.8.0 (released June 24, 2026). The flaw affects the repo_get_pull_request_by_id tool, which returns pull request descriptions without prompt-injection guardrails.

Microsoft22 Jul · 02:57 UTC
Microsoft SharePoint RCE CVE-2026-50522 actively exploited for persistencecriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft SharePoint RCE CVE-2026-50522 actively exploited for persistence

Microsoft SharePoint Server (specific versions not provided). Vulnerability enables remote code execution with machine key theft capability, allowing persistent access beyond patch deployment.

CVE-2026-5052221 Jul · 18:06 UTC
Apple fixes Hide My Email flaw exposing real addresses in mail logshighbug_reportVulnerability
bug_reportVulnerability

Apple fixes Hide My Email flaw exposing real addresses in mail logs

Apple Hide My Email service (all users prior to July 3, 2026 patch). The vulnerability affected the privacy relay feature that masks user email addresses, causing real email addresses to leak in mail server logs.

Apple21 Jul · 16:46 UTC
WordPress Core wp2shell flaws actively exploited for webshell deploymentcriticalbug_reportVulnerability
bug_reportVulnerability

WordPress Core wp2shell flaws actively exploited for webshell deployment

WordPress Core (specific versions not disclosed). Both CVE-2026-63030 and CVE-2026-60137 affect core WordPress installations, enabling remote attackers to deploy webshells and malicious plugins.

CVE-2026-6013721 Jul · 14:41 UTC
AWS Kiro IDE vulnerability allowed RCE via hidden web text injectionhighbug_reportVulnerability
bug_reportVulnerability

AWS Kiro IDE vulnerability allowed RCE via hidden web text injection

AWS Kiro agentic coding IDE (specific versions not disclosed). Vulnerability has been patched by AWS. Users who installed Kiro before the patch are potentially affected.

AWS21 Jul · 14:06 UTC
Microsoft SharePoint RCE (CVE-2026-50522) actively exploited after PoCcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft SharePoint RCE (CVE-2026-50522) actively exploited after PoC

Microsoft SharePoint Server (all versions prior to July 2026 patches). Vulnerability involves deserialization of untrusted data leading to unauthenticated remote code execution. CVSS 9.8 (Critical).

CVE-2026-5052221 Jul · 12:57 UTC
Zimbra 10.1.20 patches critical SNMP command injection and 4 XSS flawscriticalbug_reportVulnerability
bug_reportVulnerability

Zimbra 10.1.20 patches critical SNMP command injection and 4 XSS flaws

Zimbra Collaboration Suite versions prior to 10.1.20. Critical impact: SNMP monitoring component when SNMP notifications are enabled. Additional impact: four XSS vulnerabilities affecting the web interface.

Zimbra21 Jul · 11:18 UTC
Mobile AI agent frameworks vulnerable to instruction injection attackshighbug_reportVulnerability
bug_reportVulnerability

Mobile AI agent frameworks vulnerable to instruction injection attacks

Five open-source mobile AI agent frameworks including AppAgent and AppAgentX. Attack requires malicious Android apps with overlay and storage permissions to inject invisible instructions, leading to command execution on connected host PCs.

AppAgent21 Jul · 09:58 UTC
WordPress wp2shell flaws enable unauthenticated RCE, active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

WordPress wp2shell flaws enable unauthenticated RCE, active exploitation

WordPress core (specific versions not disclosed). CVE-2026-63030 and CVE-2026-60137 must be chained for unauthenticated remote code execution. All unpatched WordPress installations are potentially vulnerable.

CVE-2026-6013721 Jul · 06:59 UTC
Windows LegacyHive zero-day enables privilege escalation, unofficial patches availablehighbug_reportVulnerability
bug_reportVulnerability

Windows LegacyHive zero-day enables privilege escalation, unofficial patches available

Microsoft Windows systems (all current versions). Specific affected versions not disclosed. Impacts up-to-date Windows installations. No CVE assigned yet.

Microsoft21 Jul · 06:06 UTC
SonicWall SMA1000 VPN appliances exploited via two zero-day flawscriticalbug_reportVulnerability
bug_reportVulnerability

SonicWall SMA1000 VPN appliances exploited via two zero-day flaws

SonicWall SMA1000 series VPN appliances. Specific vulnerable versions not disclosed. Affects enterprise VPN infrastructure using these devices.

SonicWall20 Jul · 20:23 UTC
Sandbox escape flaws in Cursor, Codex, Gemini CLI, Antigravity AI toolshighbug_reportVulnerability
bug_reportVulnerability

Sandbox escape flaws in Cursor, Codex, Gemini CLI, Antigravity AI tools

Multiple AI development tools: Cursor IDE, OpenAI Codex, Google Gemini CLI, and Antigravity. Vulnerability affects AI agent sandbox implementations where agents write files executed by host tools, allowing escape from restricted environments.

Cursor20 Jul · 19:14 UTC
HollowGraph malware abuses Microsoft 365 calendar for C2 and exfiltrationhighbug_reportVulnerability
bug_reportVulnerability

HollowGraph malware abuses Microsoft 365 calendar for C2 and exfiltration

Microsoft 365 environments with compromised mailboxes. Threat actors leverage Microsoft Graph API and calendar features to establish covert command-and-control channels.

Microsoft20 Jul · 15:43 UTC
AI-assisted phishing toolkit targets Windows users in Mexico via fake gov sitehighbug_reportVulnerability
bug_reportVulnerability

AI-assisted phishing toolkit targets Windows users in Mexico via fake gov site

Windows users in Mexico targeted via fake government ID-lookup website. Delivery mechanism uses WebDAV to distribute infostealer malware. Toolkit contains 1,048 files including phishing templates, droppers, and builder documentation.

Microsoft20 Jul · 15:29 UTC
7-Zip heap overflow in XZ handling allows code execution via crafted archiveshighbug_reportVulnerability
bug_reportVulnerability

7-Zip heap overflow in XZ handling allows code execution via crafted archives

7-Zip versions prior to 26.02. Affects all platforms where 7-Zip is deployed (Windows, Linux). Vulnerability triggered when opening malicious XZ archives.

CVE-2026-1426620 Jul · 07:10 UTC
Malicious RubyGems packages deliver payloads to developer workstationshighbug_reportVulnerability
bug_reportVulnerability

Malicious RubyGems packages deliver payloads to developer workstations

RubyGems ecosystem: three malicious packages (git_credential_manager, Dendreo, and one unnamed) published to the official RubyGems repository. Affects Ruby developers who installed these packages.

RubyGems20 Jul · 03:15 UTC
Critical NGINX heap overflow enables RCE via crafted HTTP requestscriticalbug_reportVulnerability
bug_reportVulnerability

Critical NGINX heap overflow enables RCE via crafted HTTP requests

NGINX open source versions prior to 1.30.4 and 1.31.3, and NGINX Plus versions prior to 37.0.3.1. All deployments accepting HTTP requests from untrusted networks are at risk.

CVE-2026-4253319 Jul · 18:42 UTC
ViPNet update mechanism compromised to target Russian government agencieshighbug_reportVulnerability
bug_reportVulnerability

ViPNet update mechanism compromised to target Russian government agencies

ViPNet private networking software users, primarily Russian government agencies and organizations. All versions using the compromised update delivery mechanism are potentially affected. Specific version range not disclosed.

ViPNet19 Jul · 12:23 UTC
SonicWall SMA 1000 VPN zero-days exploited by UTA0533 for root accesscriticalbug_reportVulnerability
bug_reportVulnerability

SonicWall SMA 1000 VPN zero-days exploited by UTA0533 for root access

SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. Specific vulnerable versions not disclosed. All SMA 1000 deployments should be considered at risk until vendor guidance is available.

SonicWall19 Jul · 11:18 UTC
7-Zip 26.02 patches RCE flaw via malicious compressed fileshighbug_reportVulnerability
bug_reportVulnerability

7-Zip 26.02 patches RCE flaw via malicious compressed files

7-Zip versions prior to 26.02. All platforms (Windows, Linux, macOS) where 7-Zip is installed and users handle compressed archives from untrusted sources.

7-Zip18 Jul · 17:32 UTC
WordPress Core RCE "wp2shell" exploits now public, patch immediatelycriticalbug_reportVulnerability
bug_reportVulnerability

WordPress Core RCE "wp2shell" exploits now public, patch immediately

WordPress Core (specific versions not disclosed in provided data). Vulnerability enables remote code execution. Public exploits available under the name "wp2shell".

WordPress18 Jul · 15:22 UTC
ACR Stealer campaign targets Microsoft enterprise customershighbug_reportVulnerability
bug_reportVulnerability

ACR Stealer campaign targets Microsoft enterprise customers

Microsoft enterprise customers; targets browser-stored credentials, authentication tokens, and sensitive documents across enterprise environments

Microsoft18 Jul · 12:17 UTC
WordPress 6.9–7.0 unauthenticated RCE patched, forced auto-update activecriticalbug_reportVulnerability
bug_reportVulnerability

WordPress 6.9–7.0 unauthenticated RCE patched, forced auto-update active

WordPress core versions 6.9.0–6.9.4 and 7.0.0–7.0.1. All sites running these versions are vulnerable to unauthenticated remote code execution via anonymous HTTP requests. Patched in 6.9.5 and 7.0.2.

WordPress17 Jul · 19:20 UTC
OpenSSL "HollowByte" DoS allows 11-byte requests to freeze server memoryhighbug_reportVulnerability
bug_reportVulnerability

OpenSSL "HollowByte" DoS allows 11-byte requests to freeze server memory

OpenSSL versions prior to June 2024 patch. Affects TLS servers running on glibc-based Linux systems. Specific vulnerable versions not disclosed; patch applied without CVE or public advisory.

OpenSSL17 Jul · 18:20 UTC
Seven malicious npm packages target Vite ecosystem with blockchain C2 RAThighbug_reportVulnerability
bug_reportVulnerability

Seven malicious npm packages target Vite ecosystem with blockchain C2 RAT

npm package ecosystem, specifically projects using Vite frontend tooling. Seven malicious packages identified in the ViteVenom campaign. Any JavaScript/Node.js development environments that installed these packages are compromised.

npm17 Jul · 16:54 UTC
HollowByte flaw enables DoS on OpenSSL servers via 11-byte payloadhighbug_reportVulnerability
bug_reportVulnerability

HollowByte flaw enables DoS on OpenSSL servers via 11-byte payload

OpenSSL servers (specific versions not disclosed). Unauthenticated remote attackers can exploit the vulnerability. Scope includes any internet-facing OpenSSL server implementations susceptible to the malicious payload.

OpenSSL17 Jul · 15:56 UTC
DigiCert breach linked to Chinese APT; code-signing certs stolencriticalbug_reportVulnerability
bug_reportVulnerability

DigiCert breach linked to Chinese APT; code-signing certs stolen

DigiCert certificate authority infrastructure compromised in April 2026. Code-signing certificates stolen by CylindricalCanine (GoldenEyeDog/APT-Q-27 subgroup).

DigiCert17 Jul · 14:39 UTC