Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 415 results
highpublicGeopoliticalSpanish Police Arrest Doxer Targeting National Cybersecurity Personnel
The arrest underscores Spain's efforts to protect critical cybersecurity infrastructure personnel from targeted information operations. Doxing of government cybersecurity staff represents a significant operational security risk, potentially enabling…
highbug_reportVulnerabilityMeta AI bot exploited to hijack high-profile Instagram accounts
Meta Instagram platform, specifically the AI-powered customer support bot used for account recovery. High-profile accounts including Obama White House and U.S. Space Force Chief Master Sergeant were compromised.
highbug_reportVulnerabilityHard-coded credentials in KS-SOMED software enable unauthorized access
KS-SOMED software (specific versions not disclosed). Hard-coded credentials embedded in application code allow unauthorized access to affected systems.
criticalbug_reportVulnerabilityWindows Netlogon RCE under active exploitation after patch release
Microsoft Windows Netlogon service, all versions prior to recent patch. Affects domain controllers and systems with Netlogon service enabled. Specific CVE and affected version details not provided in alert.
highperson_alertThreat ActorOperation Dragon Weave targets Czech and Taiwan entities with AdaptixC2
Operation Dragon Weave is a cyber espionage campaign linked to China-aligned threat actors. The campaign's motivation appears to be intelligence collection targeting government officials, researchers, academics, and professionals in the Czech Republi…
highbug_reportVulnerabilityDutch authorities dismantle botnet controlling 17M infected devices
At least 17 million infected devices globally including computers, tablets, smartphones, and IoT devices. Over 200 command-and-control servers located in the Netherlands were seized.
highpublicGeopoliticalCalifornia sues 23andMe over 2023 breach of genetic data
The lawsuit against 23andMe highlights growing regulatory enforcement around biometric and genetic data protection in the United States, particularly within the healthcare and biotechnology sectors.
criticalbug_reportVulnerabilityMicrosoft May 2026 Patch Tuesday: 118 vulnerabilities, 16 critical
Microsoft products and services across the ecosystem. 118 total vulnerabilities: 16 critical severity, 102 important severity. Specific affected products and CVE identifiers not yet detailed in available information.
highbug_reportVulnerabilityOracle releases critical security patches for multiple products
Multiple Oracle products affected by high-severity vulnerabilities. Specific product names, versions, and CVE identifiers not provided in CERT.BE advisory. Likely part of Oracle's quarterly Critical Patch Update (CPU).
highbug_reportVulnerabilityDutch authorities disrupt 17M-device botnet, seize 200+ servers
Approximately 17 million infected devices globally; over 200 servers seized from a Dutch hosting provider. Specific botnet malware family and affected device types not disclosed.
highperson_alertThreat ActorGREYVIBE: Russian-linked APT targeting Ukraine since August 2025
GREYVIBE is a previously undocumented threat actor attributed by WithSecure as Russian-linked, assessed to operate in support of Kremlin state interests. The group is characterized as Russian-speaking and operates within Russian time zones.
highpublicGeopoliticalUS national sentenced for selling 7M elderly records to Jamaican fraudsters
This case illustrates the transnational nature of cybercrime and data exploitation, where domestic actors facilitate cross-border fraud schemes targeting vulnerable populations.
highbug_reportVulnerabilityMalicious NuGet package "Sicoob.Sdk" steals banking credentials
NuGet package "Sicoob.Sdk" versions 2.0.0 through 2.0.4. Targets developers integrating with Sicoob (Brazilian cooperative banking system). Affects .NET development environments where the malicious package was installed.
highperson_alertThreat ActorShinyHunters Breaches Charter Communications, Exfiltrates 4.9M Records
ShinyHunters is a financially motivated cybercrime group known for large-scale data breaches and extortion operations targeting enterprises. The group specializes in exfiltrating sensitive customer data from corporate databases and either selling the…
highbug_reportVulnerabilityHard-coded secret in Trac PDBM enables unauthorized access
Trac d.o.o. Process Database Manager (PDBM) - specific affected versions not disclosed. Vulnerability involves hard-coded cryptographic secret embedded in executable binary.
highperson_alertThreat ActorKimsuky Targets South Korean Military and Corporate Sectors
Kimsuky (also tracked as Velvet Chollima, Black Banshee, Emerald Sleet, and THALLIUM) is a North Korean state-sponsored advanced persistent threat group.
highperson_alertThreat ActorGreyVibe Targets Ukraine with AI-Generated Lures and Custom Malware
GreyVibe is a threat cluster assessed with moderate confidence to be linked to Russian interests, based on targeting patterns and geopolitical alignment.
highperson_alertThreat ActorFBI warns of FIFA-impersonating fraud sites targeting 2026 World Cup
Unknown fraud operators are conducting financially motivated cybercrime campaigns targeting fans and consumers interested in the 2026 FIFA World Cup. These actors leverage social engineering and brand impersonation tactics to establish fraudulent web…
criticalbug_reportVulnerabilityStarlette and FastAPI authentication bypass flaw affects millions of servers
Starlette web framework and dependent frameworks including FastAPI. Specific vulnerable versions not provided in source data. Affects authentication mechanisms in applications built with these frameworks.
criticalbug_reportVulnerabilityCritical RCE vulnerability in LiquidJS requires immediate patching
LiquidJS templating engine, all versions prior to patched release. Specific vulnerable version range not provided in available data.
criticalbug_reportVulnerabilityDell Container Storage Modules info disclosure enables data exfiltration
Dell Container Storage Modules (specific versions not disclosed in summary). Vulnerability allows information disclosure that can lead to data exfiltration and lateral movement within containerized environments.
highbug_reportVulnerabilityKidsview authentication bypass allows unauthorized access (CVE-2026-8990)
Kidsview application (specific versions not disclosed). Authentication mechanisms can be bypassed, potentially affecting all deployments until patched versions are confirmed.
highperson_alertThreat ActorRomanian National Sentenced for Hacking Oregon Government Network
A Romanian national individual actor who conducted unauthorized access operations targeting U.S. government and private sector networks. The actor's motivation appears to be financially driven cybercrime, operating from Romania to compromise Oregon s…
highbug_reportVulnerabilityOut-of-bounds write in bzip2 enables code execution or DoS
bzip2 compression software, all versions not yet patched. Affects systems using bzip2 for file compression/decompression, including Linux distributions, BSD variants, and applications embedding libbz2.
criticalbug_reportVulnerabilityApache ActiveMQ NMS AMQP Client deserialization flaw enables RCE
Apache ActiveMQ NMS AMQP Client - specific vulnerable versions not provided. Affects .NET/C# applications using the NMS AMQP client library for message queue operations.
criticalbug_reportVulnerabilityMicrosoft SharePoint RCE vulnerability requires immediate patching
Microsoft SharePoint Server (specific versions not disclosed in advisory). Organizations running on-premises SharePoint deployments are affected. SharePoint Online managed by Microsoft likely already patched.
highbug_reportVulnerabilityBanking trojans Grandoreiro and BTMOB target LATAM and Europe
Windows and Android devices in Latin America (Brazil, Mexico) and Europe (Spain, Portugal). Grandoreiro targets Windows systems at companies; BTMOB RAT targets Android mobile users in Brazil.
highperson_alertThreat ActorSilent Ransom Group Shifts to Physical Data Theft at U.S. Law Firms
Silent Ransom Group (SRG) is an extortion-focused threat actor that has evolved from traditional ransomware operations to conducting physical, in-person data theft attacks.
criticalbug_reportVulnerabilityCISA orders federal agencies to patch LiteSpeed cPanel plugin in 4 days
LiteSpeed cPanel user-end plugin. Specific vulnerable versions not disclosed. Affects organizations using cPanel with LiteSpeed integration.
highperson_alertThreat ActorShinyHunters Extorts Charter Communications After Data Breach
ShinyHunters is a financially motivated cybercrime group known for large-scale data breaches and extortion operations targeting organizations across multiple sectors.