Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
satellite_altDaily BriefCyber Threat Daily Brief — July 21, 2026
Today's briefing: 3 critical and 16 high-severity threats. A total of 23 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.
Latest Reports
29 / 606 results
criticalbug_reportVulnerabilityFortinet FortiSandbox command injection flaw enables remote code execution
Fortinet FortiSandbox products affected by CVE-2026-25089 (CVSS 9.1). Specific vulnerable versions not disclosed in provided data. Ivanti and SAP also released patches for separate critical vulnerabilities.
criticalbug_reportVulnerabilityLangflow path traversal flaw (CVE-2026-5027) exploited for RCE
Langflow open-source low-code AI platform, all unpatched versions. Vulnerability allows unauthenticated path traversal leading to arbitrary file write and remote code execution.
highperson_alertThreat ActorVolt Typhoon Expands JDY Botnet Operations Against U.S. Military
Volt Typhoon (also tracked as BRONZE SILHOUETTE, Vanguard Panda, DEV-0391, and UNC3236) is a Chinese state-sponsored APT group attributed to conducting cyber espionage operations targeting critical infrastructure.
highbug_reportVulnerabilityCisco Catalyst SD-WAN Manager actively exploited (CVE-2026-20245)
Cisco Catalyst SD-WAN Manager. Specific affected versions not disclosed. Vulnerability involves improper encoding or escaping of output (CVSS 7.8). Also affects products from Google and Arista (details not provided).
highperson_alertThreat ActorThe Gentlemen Ransomware: Aggressive Affiliate Model Drives Rapid Growth
The Gentlemen is a ransomware-as-a-service (RaaS) operation that has rapidly ascended to become the second most active ransomware group by victim count.
criticalbug_reportVulnerabilityIvanti Sentry critical RCE flaws allow unauthenticated remote attacks
Ivanti Sentry products (specific versions not provided). Two critical vulnerabilities enable unauthenticated remote code execution on exposed devices.
highbug_reportVulnerabilityMicrosoft patches actively exploited XSS zero-day in Exchange Server OWA
Microsoft Exchange Server (all versions with Outlook Web Access enabled). Specific patched versions not provided. Affects organizations exposing OWA to users.
highbug_reportVulnerabilityAix-DB missing authentication flaw allows unauthorized critical access
Aix-DB software (vendor: Aix-DB). Specific affected versions not disclosed. Vulnerability allows unauthenticated access to critical functions (CWE-306).
criticalbug_reportVulnerabilityMicrosoft patches 3 zero-days: YellowKey, GreenPlasma, MiniPlasma
All fully patched Windows systems prior to latest patch release. YellowKey and GreenPlasma enable SYSTEM privilege escalation; MiniPlasma bypasses BitLocker encryption on protected drives.
criticalbug_reportVulnerabilityMicrosoft patches 206 vulnerabilities including 3 zero-days, 39 critical
Microsoft software portfolio: 206 vulnerabilities patched including 56 remote code execution (RCE) flaws, 63 privilege escalation issues, 39 critical-severity vulnerabilities, and 3 actively exploited zero-day flaws.
criticalbug_reportVulnerabilityWindows Server domain controllers under active RCE attack
Windows Server domain controllers (all supported versions). Specific version details not yet published by Microsoft. Unauthenticated remote code execution vulnerability.
highbug_reportVulnerabilityServiceNow patches actively exploited auth bypass on hosted instances
ServiceNow hosted customer instances (specific versions not disclosed). On-premise deployments may also be affected pending vendor guidance.
criticalbug_reportVulnerabilityIvanti Sentry critical RCE allows unauthenticated root code execution
Ivanti Sentry secure mobile gateway solution. Specific affected versions not disclosed. Two critical vulnerabilities patched, including one maximum-severity (likely CVSS 10.0) remote code execution flaw enabling unauthenticated attackers to execute a…
criticalbug_reportVulnerabilityMicrosoft Defender zero-day "RoguePlanet" exploited for SYSTEM access
Microsoft Defender on all updated Windows systems. No CVE assigned yet. Vulnerability is a race condition enabling local privilege escalation to SYSTEM.
highbug_reportVulnerabilitySix RCE and DoS flaws found in protobuf.js for Node.js applications
protobuf.js library (JavaScript/TypeScript implementation of Protocol Buffers) used in Node.js applications. Specific vulnerable versions not provided in summary.
criticalbug_reportVulnerabilityMicrosoft Defender zero-day 'RoguePlanet' enables SYSTEM privilege escalation
Microsoft Defender on Windows systems. Specific affected versions not disclosed. Given Defender's deployment, scope includes enterprise endpoints, servers running Defender, and consumer Windows installations with default security configuration.
criticalbug_reportVulnerabilityMicrosoft June 2026 Patch Tuesday: ~200 patches, 36 critical, 3 with PoCs
Microsoft products across the portfolio. Approximately 200 vulnerabilities patched, including ~36 critical-severity issues. At least 3 vulnerabilities have public proof-of-concept exploit code available.
highbug_reportVulnerabilityOpenClaw AI email agent vulnerable to phishing attacks
OpenClaw AI email agent (all versions). Scope: AI-powered email processing systems that handle user communications and may access sensitive user data.
criticalbug_reportVulnerabilitySAP June 2026 patches fix 4 critical flaws in NetWeaver, Commerce Cloud
SAP NetWeaver and SAP Commerce Cloud products. Total of 15 vulnerabilities patched, including 4 critical-severity issues. Specific affected versions not disclosed in summary.
highbug_reportVulnerabilityMicrosoft June 2026 Patch Tuesday: 200 flaws, 3 disclosed zero-days
Microsoft products across the ecosystem. 200 vulnerabilities patched, including 3 publicly disclosed zero-day vulnerabilities. Specific affected products and CVE identifiers not yet detailed in available information.
criticalbug_reportVulnerabilityVeeam Backup & Replication RCE flaw (CVE-2026-44963) patched, CVSS 9.4
Veeam Backup & Replication software. Specific affected versions not disclosed in available data. Requires authenticated domain user access to exploit.
highbug_reportVulnerabilityMicrosoft GitHub repos compromised, 73 disabled for distributing malware
73 repositories across Microsoft's official GitHub organizations (Azure, microsoft, Azure-Samples, MicrosoftDocs). Organizations using Microsoft sample code, Azure templates, or CI/CD pipelines referencing these repositories are potentially affected.
criticalbug_reportVulnerabilitySAP releases critical patches for multiple products
Multiple SAP products affected. Specific product names and versions not disclosed in available information. Patches released by SAP to address critical-severity vulnerabilities.
highbug_reportVulnerabilityWinRAR CVE-2025-8088 path traversal exploited by Russian APTs vs Ukraine
WinRAR versions prior to patched release (approximately one year old). Primary targets: Ukrainian organizations. Threat actors: Earth Dahu (Gamaredon) and SHADOW-EARTH-066 (UAC-0226), Russia-aligned APT groups.
criticalbug_reportVulnerabilityCheck Point VPN authentication flaw under active exploitation
Check Point VPN products with user authentication functionality. Specific affected versions not disclosed. CVE identifier not yet assigned.
criticalbug_reportVulnerabilityChrome V8 zero-day CVE-2026-11645 exploited in wild, patch immediately
Google Chrome versions prior to 149.0.7827.103 on all platforms. The vulnerability resides in the V8 JavaScript engine, affecting out-of-bounds memory access.
FROST attack enables website-based user tracking via SSD timing analysis
All systems with SSDs accessed via web browsers supporting high-resolution JavaScript timers. Attack affects users across Windows, Linux, and macOS platforms. No specific browser, SSD model, or OS version is immune.
highbug_reportVulnerabilityPyPI supply chain attack: 19 packages with auto-executing credential stealer
PyPI repository: 19 compromised packages containing 37 malicious wheel artifacts. Affects Python developers who installed these packages. Attack uses .pth files for automatic execution during pip install, targeting credential theft via Bun-based stea…
highbug_reportVulnerabilityBerriAI LiteLLM command injection under active exploitation (CISA KEV)
BerriAI LiteLLM - specific vulnerable versions not disclosed in summary. Command injection vulnerability (CVE-2026-42271) affects authenticated users with access to the system.