Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
satellite_altDaily BriefCyber Threat Daily Brief — July 21, 2026
Today's briefing: 3 critical and 16 high-severity threats. A total of 23 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.
Latest Reports
28 / 606 results
highperson_alertThreat ActorUNC1151/Ghostwriter Targets Polish Gmail Accounts in Phishing Campaign
UNC1151, also known as Ghostwriter, is a threat actor group attributed by FireEye/Mandiant that has conducted sustained information operations and cyber espionage activities.
highpublicGeopoliticalNovo Nordisk discloses clinical trial data breach in Denmark
The breach at Novo Nordisk, a Danish pharmaceutical giant controlling approximately 50% of the global insulin market, highlights the strategic vulnerability of critical healthcare infrastructure.
criticalbug_reportVulnerabilityLangGraph AI framework patched for critical RCE via SQL injection chain
LangGraph (LangChain's open-source AI agent framework). Specific vulnerable versions not disclosed; patches available. Affects deployments using LangGraph for AI agent orchestration.
highperson_alertThreat ActorINTERPOL arrests Guedz, admin of Sniper Dz phishing-as-a-service platform
Guedz is identified as the primary administrator of Sniper Dz, a phishing-as-a-service (PhaaS) platform that operated for approximately a decade across the Middle East and North Africa (MENA) region.
criticalbug_reportVulnerabilityCISA orders federal agencies to patch exploited Ivanti Sentry flaw
Ivanti Sentry (specific versions not disclosed in summary). U.S. federal agencies under BOD 26-04 mandate, but all Ivanti Sentry deployments at risk given active exploitation.
highpublicGeopoliticalFrench Government Messaging Platform Tchap Breached, 73,000 Accounts Affected
The compromise of Tchap, France's sovereign encrypted messaging solution developed as an alternative to foreign platforms, represents a significant breach of government communications infrastructure.
highperson_alertThreat ActorEuropol Disrupts AudiA6 Cryptocurrency Laundering Service
AudiA6 was a cryptocurrency laundering service utilized by ransomware gangs and cybercriminal networks to obfuscate and legitimize illicit proceeds. The service facilitated the conversion and movement of cryptocurrency obtained through ransomware ope…
highpublicGeopoliticalJapanese utility loses drive with 10.9M customer records
The incident at Kyushu Electric Power Co., Inc. represents a physical security failure rather than a cyber intrusion, but underscores the vulnerability of critical infrastructure operators to data exposure.
criticalbug_reportVulnerabilityOracle PeopleSoft zero-day CVE-2026-35273 exploited by ShinyHunters
Oracle PeopleSoft (all versions prior to June 10 patch). Confirmed exploitation targeting enterprise systems and universities. Vulnerability was unpatched during active exploitation window (May 27 - June 9).
criticalbug_reportVulnerabilityOracle PeopleSoft zero-day CVE-2026-35273 exploited for RCE by ShinyHunter
Oracle PeopleSoft Suite, all versions (specific affected versions not disclosed). Unauthenticated remote code execution vulnerability affecting internet-facing PeopleSoft instances.
highbug_reportVulnerabilityOpenClaw AI agent vulnerable to prompt injection via vCards and location pins
OpenClaw self-hosted AI agent platform, all versions. Vulnerability affects input processing mechanisms for vCards, location pins, and potentially other structured data formats.
highbug_reportVulnerabilityBitLocker bypass via recovery partition XML files (GreatXML)
Windows BitLocker encryption on systems with recovery partitions. All Windows versions with BitLocker enabled are potentially affected. Specific version scope not yet published.
highperson_alertThreat ActorThe Gentlemen ransomware group claims 478 victims via multi-RaaS model
The Gentlemen is a financially motivated ransomware threat group that has claimed 478 victims through a hybrid operational model. Initially operating as an affiliate leveraging multiple ransomware-as-a-service (RaaS) platforms—including LockBit, Qili…
highperson_alertThreat ActorLaw Enforcement Dismantles AudiA6 Cryptocurrency Laundering Service
AudiA6 was a cryptocurrency laundering service that facilitated money laundering operations for ransomware actors and other cybercriminals. The service allegedly processed over $380 million in illicit proceeds before being dismantled by law enforceme…
criticalbug_reportVulnerabilityCritical command injection flaw in Fortinet FortiSandbox requires patching
Fortinet FortiSandbox (specific versions not disclosed in available data). Command injection vulnerability allows unauthorized command execution.
highpublicGeopoliticalSouth Korea issues record $409M fine to Coupang for 37M-user breach
The unprecedented fine against Coupang reflects South Korea's increasingly assertive regulatory posture on data protection, aligning Seoul with global trends toward stringent enforcement of privacy frameworks.
highpublicGeopoliticalCISA mandates 3-day patching for exploited flaws in federal agencies
The directive represents a significant tightening of federal cybersecurity posture in response to persistent exploitation of known vulnerabilities by both state-sponsored and criminal actors.
highperson_alertThreat ActorOceanLotus Targets Vietnamese Infrastructure with SPECTRALVIPER Backdoor
OceanLotus (also tracked as APT32, SeaLotus, APT-C-00, and Canvas Cyclone) is a Vietnam-aligned advanced persistent threat group attributed by multiple vendors to conducting cyber espionage operations.
highpublicGeopoliticalUniversity of Nottingham breach exposes 450,000+ student records
The breach at the University of Nottingham represents a significant compromise of a major UK higher education institution, affecting a substantial population of current and former students.
highbug_reportVulnerabilitynpm v12 disables install scripts by default to block supply chain attacks
npm version 12 and later. All Node.js projects using npm for package management. Breaking change affects packages that legitimately rely on install/postinstall lifecycle hooks.
criticalbug_reportVulnerabilityIvanti Sentry RCE flaw under active exploitation, root access possible
Ivanti Sentry (formerly MobileIron Sentry) - Internet-exposed secure mobile gateways. Specific vulnerable versions not provided in summary, but patch recently released.
highbug_reportVulnerabilityActive exploitation of path traversal in Langflow AI platform
Langflow AI development platform. Specific affected versions not disclosed. Impacts internet-exposed Langflow servers vulnerable to arbitrary file write via path traversal (CVE-2026-5027).
highbug_reportVulnerabilityMiasma credential-stealing framework source code leaked on GitHub
Open-source software ecosystems and their supply chains. Organizations consuming packages from public repositories (npm, PyPI, RubyGems, etc.) are at increased risk. No specific vendor or product version affected; threat is ecosystem-wide.
highperson_alertThreat ActorShinyHunters Targets Oracle PeopleSoft Servers in Mass Data Theft
ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has gained notoriety for breaching numerous organizations and exfiltrating sensitive data, which is then used for extortion…
criticalbug_reportVulnerabilityCritical RCE in Veeam Backup & Replication requires immediate patching
Veeam Backup & Replication (specific versions not disclosed in summary). Remote code execution vulnerability allows attackers to execute arbitrary code on affected systems.
highperson_alertThreat ActorChina-Nexus Actors Expand JDY Botnet to 1,500+ IoT/SOHO Devices
China-nexus state-sponsored threat actors operating the JDY botnet infrastructure. The actors leverage compromised small office/home office (SOHO) routers and IoT devices to build a distributed scanning platform for cyber reconnaissance operations.
criticalbug_reportVulnerabilityMicrosoft June 2025 Patch Tuesday: 206 vulnerabilities, 33 critical
Microsoft products across the ecosystem. 206 total vulnerabilities: 33 critical, 173 important severity. Specific affected products and CVE identifiers not yet detailed in available information.
criticalbug_reportVulnerabilityIvanti Sentry critical RCE and auth bypass require immediate patching
Ivanti Sentry (specific versions not disclosed in summary). Vulnerabilities enable root-level remote code execution and authentication bypass. CVE identifiers not yet assigned or published.