Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-21 · 02:09 UTC
articleTotal: 606 reports

Filtered Reports

13 / 343 results
Active filter:tag: #high✕ clear
Buffer overflow in PAN-OS User-ID portal enables unauthenticated RCEhighbug_reportVulnerability
bug_reportVulnerability

Buffer overflow in PAN-OS User-ID portal enables unauthenticated RCE

Palo Alto Networks PAN-OS on PA-Series and VM-Series firewalls; Siemens RUGGEDCOM APE1808 devices. Specific affected PAN-OS versions not provided in summary.

CVE-2026-030010:00 UTC
Ivanti releases security updates for multiple productshighbug_reportVulnerability
bug_reportVulnerability

Ivanti releases security updates for multiple products

Multiple Ivanti products affected. Specific product names, versions, and CVE identifiers not disclosed in available information. High severity rating indicates significant security risk.

Ivanti07:55 UTC
Code Runner MCP Server missing authentication flaw allows unauthorized accesshighbug_reportVulnerability
bug_reportVulnerability

Code Runner MCP Server missing authentication flaw allows unauthorized access

Code Runner MCP Server (all versions not specified). The vulnerability affects critical functions within the server, allowing unauthenticated access to protected operations. Specific version ranges have not been disclosed by CERT.PL.

CVE-2026-502908:55 UTC
3onedata GW1101 Modbus gateway vulnerable to OS command injectionhighbug_reportVulnerability
bug_reportVulnerability

3onedata GW1101 Modbus gateway vulnerable to OS command injection

3onedata GW1101-1D(RS-485)-TB-P Modbus gateways. Specific affected firmware versions not disclosed. These are industrial IoT devices used for Modbus protocol conversion in OT/ICS environments.

CVE-2025-1360512:55 UTC
NCSC UK Issues Guidance on China-Nexus Covert Device Networkshighperson_alertThreat Actor
person_alertThreat Actor

NCSC UK Issues Guidance on China-Nexus Covert Device Networks

China-nexus threat actors are state-sponsored groups linked to the People's Republic of China. These actors are motivated by strategic intelligence collection, espionage, and maintaining persistent access to foreign networks.

NCSC UK10:00 UTC
NCSC UK Issues Advisory on China-Linked Covert Network Tacticshighperson_alertThreat Actor
person_alertThreat Actor

NCSC UK Issues Advisory on China-Linked Covert Network Tactics

China-linked threat actors employing covert network tactics to conceal malicious cyber activity. These actors are characterized by their use of sophisticated techniques to maintain persistent, stealthy access to compromised networks.

NCSC UK10:00 UTC
UK NCSC Issues Guidance on China-Linked Covert Device NetworkshighpublicGeopolitical
publicGeopolitical

UK NCSC Issues Guidance on China-Linked Covert Device Networks

The UK National Cyber Security Centre's release of defensive guidance targeting China-nexus covert networks reflects ongoing strategic competition between Western democracies and Beijing in cyberspace.

NCSC UK10:00 UTC
Orca heat pumps lack authentication, transmit cleartext data to servershighbug_reportVulnerability
bug_reportVulnerability

Orca heat pumps lack authentication, transmit cleartext data to servers

Orca heat pumps (specific models and versions not disclosed). Vulnerability affects device-to-server communication and server-side data processing.

CVE-2026-2559903:11 UTC
MikroTik RouterOS auth bypass via certificate validation flawhighbug_reportVulnerability
bug_reportVulnerability

MikroTik RouterOS auth bypass via certificate validation flaw

MikroTik RouterOS - versions not specified. Affects OpenVPN, CAPsMAN (wireless management), and 802.1X (Dot1x) services that rely on certificate-based authentication.

CVE-2025-4261107:08 UTC
Latvia faces elevated cyber threats amid geopolitical tensions in Q4 2025highpublicGeopolitical
publicGeopolitical

Latvia faces elevated cyber threats amid geopolitical tensions in Q4 2025

Latvia's position as a NATO and EU member state on the eastern flank of the Alliance places it at the intersection of Western institutional security architecture and persistent regional tensions.

CERT.LV (Latvia)11:02 UTC
Fortinet FortiCloud SSO bypass exploited to extract LDAP passwordshighbug_reportVulnerability
bug_reportVulnerability

Fortinet FortiCloud SSO bypass exploited to extract LDAP passwords

Fortinet FortiGate appliances with FortiCloud SSO enabled. CVE-2025-59718 and CVE-2025-59719 allow authentication bypass. All FortiGate instances share a default static encryption key that enables decryption of LDAP credentials and private keys from…

CVE-2025-5971815:16 UTC
Fortinet patches high severity FortiOS vulnerabilityhighbug_reportVulnerability
bug_reportVulnerability

Fortinet patches high severity FortiOS vulnerability

FortiOS (specific versions not disclosed in summary). Fortinet advisory published October 14, 2025.

Fortinet18:41 UTC
Ransomware Campaigns Target Slovenia via Email, RDP, and Exploitshighperson_alertThreat Actor
person_alertThreat Actor

Ransomware Campaigns Target Slovenia via Email, RDP, and Exploits

Unattributed ransomware operators targeting Slovenia. Motivation appears financially driven, consistent with commodity ransomware campaigns. No specific actor attribution available; likely represents multiple threat groups employing common ransomware…

SI-CERT (Slovenia)08:32 UTC