Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-21 · 02:09 UTC
articleTotal: 606 reports
Cyber Threat Daily Brief — July 21, 2026satellite_altDaily Brief
Threat Intel Brief·Daily Summary

Cyber Threat Daily Brief — July 21, 2026

Today's briefing: 3 critical and 16 high-severity threats. A total of 23 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.

3 Critical16 High23 analyses
schedule02:09 UTC
Read briefarrow_forward

Latest Reports

28 / 606 results
UNC1151/Ghostwriter Targets Polish Gmail Accounts in Phishing Campaignhighperson_alertThreat Actor
person_alertThreat Actor

UNC1151/Ghostwriter Targets Polish Gmail Accounts in Phishing Campaign

UNC1151, also known as Ghostwriter, is a threat actor group attributed by FireEye/Mandiant that has conducted sustained information operations and cyber espionage activities.

Google09:00 UTC
Novo Nordisk discloses clinical trial data breach in DenmarkhighpublicGeopolitical
publicGeopolitical

Novo Nordisk discloses clinical trial data breach in Denmark

The breach at Novo Nordisk, a Danish pharmaceutical giant controlling approximately 50% of the global insulin market, highlights the strategic vulnerability of critical healthcare infrastructure.

Novo Nordisk08:13 UTC
LangGraph AI framework patched for critical RCE via SQL injection chaincriticalbug_reportVulnerability
bug_reportVulnerability

LangGraph AI framework patched for critical RCE via SQL injection chain

LangGraph (LangChain's open-source AI agent framework). Specific vulnerable versions not disclosed; patches available. Affects deployments using LangGraph for AI agent orchestration.

LangChain07:50 UTC
INTERPOL arrests Guedz, admin of Sniper Dz phishing-as-a-service platformhighperson_alertThreat Actor
person_alertThreat Actor

INTERPOL arrests Guedz, admin of Sniper Dz phishing-as-a-service platform

Guedz is identified as the primary administrator of Sniper Dz, a phishing-as-a-service (PhaaS) platform that operated for approximately a decade across the Middle East and North Africa (MENA) region.

The Hacker News06:52 UTC
CISA orders federal agencies to patch exploited Ivanti Sentry flawcriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders federal agencies to patch exploited Ivanti Sentry flaw

Ivanti Sentry (specific versions not disclosed in summary). U.S. federal agencies under BOD 26-04 mandate, but all Ivanti Sentry deployments at risk given active exploitation.

Ivanti06:26 UTC
French Government Messaging Platform Tchap Breached, 73,000 Accounts AffectedhighpublicGeopolitical
publicGeopolitical

French Government Messaging Platform Tchap Breached, 73,000 Accounts Affected

The compromise of Tchap, France's sovereign encrypted messaging solution developed as an alternative to foreign platforms, represents a significant breach of government communications infrastructure.

Tchap05:09 UTC
Europol Disrupts AudiA6 Cryptocurrency Laundering Servicehighperson_alertThreat Actor
person_alertThreat Actor

Europol Disrupts AudiA6 Cryptocurrency Laundering Service

AudiA6 was a cryptocurrency laundering service utilized by ransomware gangs and cybercriminal networks to obfuscate and legitimize illicit proceeds. The service facilitated the conversion and movement of cryptocurrency obtained through ransomware ope…

The Hacker News04:38 UTC
Japanese utility loses drive with 10.9M customer recordshighpublicGeopolitical
publicGeopolitical

Japanese utility loses drive with 10.9M customer records

The incident at Kyushu Electric Power Co., Inc. represents a physical security failure rather than a cyber intrusion, but underscores the vulnerability of critical infrastructure operators to data exposure.

Kyushu Electric Power Co., Inc.21:14 UTC
Oracle PeopleSoft zero-day CVE-2026-35273 exploited by ShinyHunterscriticalbug_reportVulnerability
bug_reportVulnerability

Oracle PeopleSoft zero-day CVE-2026-35273 exploited by ShinyHunters

Oracle PeopleSoft (all versions prior to June 10 patch). Confirmed exploitation targeting enterprise systems and universities. Vulnerability was unpatched during active exploitation window (May 27 - June 9).

CVE-2026-3527318:29 UTC
Oracle PeopleSoft zero-day CVE-2026-35273 exploited for RCE by ShinyHuntercriticalbug_reportVulnerability
bug_reportVulnerability

Oracle PeopleSoft zero-day CVE-2026-35273 exploited for RCE by ShinyHunter

Oracle PeopleSoft Suite, all versions (specific affected versions not disclosed). Unauthenticated remote code execution vulnerability affecting internet-facing PeopleSoft instances.

CVE-2026-3527317:39 UTC
OpenClaw AI agent vulnerable to prompt injection via vCards and location pinshighbug_reportVulnerability
bug_reportVulnerability

OpenClaw AI agent vulnerable to prompt injection via vCards and location pins

OpenClaw self-hosted AI agent platform, all versions. Vulnerability affects input processing mechanisms for vCards, location pins, and potentially other structured data formats.

OpenClaw15:46 UTC
BitLocker bypass via recovery partition XML files (GreatXML)highbug_reportVulnerability
bug_reportVulnerability

BitLocker bypass via recovery partition XML files (GreatXML)

Windows BitLocker encryption on systems with recovery partitions. All Windows versions with BitLocker enabled are potentially affected. Specific version scope not yet published.

Microsoft15:43 UTC
The Gentlemen ransomware group claims 478 victims via multi-RaaS modelhighperson_alertThreat Actor
person_alertThreat Actor

The Gentlemen ransomware group claims 478 victims via multi-RaaS model

The Gentlemen is a financially motivated ransomware threat group that has claimed 478 victims through a hybrid operational model. Initially operating as an affiliate leveraging multiple ransomware-as-a-service (RaaS) platforms—including LockBit, Qili…

The Hacker News14:50 UTC
Law Enforcement Dismantles AudiA6 Cryptocurrency Laundering Servicehighperson_alertThreat Actor
person_alertThreat Actor

Law Enforcement Dismantles AudiA6 Cryptocurrency Laundering Service

AudiA6 was a cryptocurrency laundering service that facilitated money laundering operations for ransomware actors and other cybercriminals. The service allegedly processed over $380 million in illicit proceeds before being dismantled by law enforceme…

BleepingComputer13:55 UTC
Critical command injection flaw in Fortinet FortiSandbox requires patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical command injection flaw in Fortinet FortiSandbox requires patching

Fortinet FortiSandbox (specific versions not disclosed in available data). Command injection vulnerability allows unauthorized command execution.

Fortinet12:31 UTC
South Korea issues record $409M fine to Coupang for 37M-user breachhighpublicGeopolitical
publicGeopolitical

South Korea issues record $409M fine to Coupang for 37M-user breach

The unprecedented fine against Coupang reflects South Korea's increasingly assertive regulatory posture on data protection, aligning Seoul with global trends toward stringent enforcement of privacy frameworks.

Coupang10:52 UTC
CISA mandates 3-day patching for exploited flaws in federal agencieshighpublicGeopolitical
publicGeopolitical

CISA mandates 3-day patching for exploited flaws in federal agencies

The directive represents a significant tightening of federal cybersecurity posture in response to persistent exploitation of known vulnerabilities by both state-sponsored and criminal actors.

BleepingComputer10:46 UTC
OceanLotus Targets Vietnamese Infrastructure with SPECTRALVIPER Backdoorhighperson_alertThreat Actor
person_alertThreat Actor

OceanLotus Targets Vietnamese Infrastructure with SPECTRALVIPER Backdoor

OceanLotus (also tracked as APT32, SeaLotus, APT-C-00, and Canvas Cyclone) is a Vietnam-aligned advanced persistent threat group attributed by multiple vendors to conducting cyber espionage operations.

The Hacker News07:45 UTC
University of Nottingham breach exposes 450,000+ student recordshighpublicGeopolitical
publicGeopolitical

University of Nottingham breach exposes 450,000+ student records

The breach at the University of Nottingham represents a significant compromise of a major UK higher education institution, affecting a substantial population of current and former students.

University of Nottingham05:27 UTC
npm v12 disables install scripts by default to block supply chain attackshighbug_reportVulnerability
bug_reportVulnerability

npm v12 disables install scripts by default to block supply chain attacks

npm version 12 and later. All Node.js projects using npm for package management. Breaking change affects packages that legitimately rely on install/postinstall lifecycle hooks.

GitHub04:23 UTC
Ivanti Sentry RCE flaw under active exploitation, root access possiblecriticalbug_reportVulnerability
bug_reportVulnerability

Ivanti Sentry RCE flaw under active exploitation, root access possible

Ivanti Sentry (formerly MobileIron Sentry) - Internet-exposed secure mobile gateways. Specific vulnerable versions not provided in summary, but patch recently released.

Ivanti04:20 UTC
Active exploitation of path traversal in Langflow AI platformhighbug_reportVulnerability
bug_reportVulnerability

Active exploitation of path traversal in Langflow AI platform

Langflow AI development platform. Specific affected versions not disclosed. Impacts internet-exposed Langflow servers vulnerable to arbitrary file write via path traversal (CVE-2026-5027).

CVE-2026-502719:23 UTC
Miasma credential-stealing framework source code leaked on GitHubhighbug_reportVulnerability
bug_reportVulnerability

Miasma credential-stealing framework source code leaked on GitHub

Open-source software ecosystems and their supply chains. Organizations consuming packages from public repositories (npm, PyPI, RubyGems, etc.) are at increased risk. No specific vendor or product version affected; threat is ecosystem-wide.

BleepingComputer18:27 UTC
ShinyHunters Targets Oracle PeopleSoft Servers in Mass Data Thefthighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Targets Oracle PeopleSoft Servers in Mass Data Theft

ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has gained notoriety for breaching numerous organizations and exfiltrating sensitive data, which is then used for extortion…

Oracle16:31 UTC
Critical RCE in Veeam Backup & Replication requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical RCE in Veeam Backup & Replication requires immediate patching

Veeam Backup & Replication (specific versions not disclosed in summary). Remote code execution vulnerability allows attackers to execute arbitrary code on affected systems.

Veeam16:20 UTC
China-Nexus Actors Expand JDY Botnet to 1,500+ IoT/SOHO Deviceshighperson_alertThreat Actor
person_alertThreat Actor

China-Nexus Actors Expand JDY Botnet to 1,500+ IoT/SOHO Devices

China-nexus state-sponsored threat actors operating the JDY botnet infrastructure. The actors leverage compromised small office/home office (SOHO) routers and IoT devices to build a distributed scanning platform for cyber reconnaissance operations.

The Hacker News14:08 UTC
Microsoft June 2025 Patch Tuesday: 206 vulnerabilities, 33 criticalcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft June 2025 Patch Tuesday: 206 vulnerabilities, 33 critical

Microsoft products across the ecosystem. 206 total vulnerabilities: 33 critical, 173 important severity. Specific affected products and CVE identifiers not yet detailed in available information.

Microsoft13:47 UTC
Ivanti Sentry critical RCE and auth bypass require immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Ivanti Sentry critical RCE and auth bypass require immediate patching

Ivanti Sentry (specific versions not disclosed in summary). Vulnerabilities enable root-level remote code execution and authentication bypass. CVE identifiers not yet assigned or published.

Ivanti13:13 UTC