Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports
Cyber Threat Daily Brief — September 4, 2026satellite_altDaily Brief
Threat Intel Brief·Daily Summary

Cyber Threat Daily Brief — September 4, 2026

Today's briefing: 14 critical and 22 high-severity threats. A total of 47 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.

14 Critical22 High47 analyses
schedule02:17 UTC
Read briefarrow_forward

Latest Reports

28 / 1107 results
84 flaws in 4G/5G core networks enable DoS and session hijackinghighbug_reportVulnerability
bug_reportVulnerability

84 flaws in 4G/5G core networks enable DoS and session hijacking

4G and 5G core network implementations: Open5GS (LTE/5G), free5GC, OpenAirInterface (LTE/5G), SD-Core, and eUPF. Vulnerabilities affect GTP-C and PFCP signaling protocols. 83 of 84 flaws confirmed, 81 assigned CVE identifiers.

The Hacker News31 Jul · 09:55 UTC
knaithe/KnYuan Uses DeepSeek AI for Autonomous Exploitation Campaignhighperson_alertThreat Actor
person_alertThreat Actor

knaithe/KnYuan Uses DeepSeek AI for Autonomous Exploitation Campaign

knaithe (also tracked as KnYuan) is a Chinese-speaking threat actor assessed by Unit 42 to be based in Zhuhai, China. Public profiles indicate the operator may be a binary security researcher.

Palo Alto Networks31 Jul · 09:21 UTC
Cisco Secure Firewall Management Center under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Cisco Secure Firewall Management Center under active exploitation

Cisco Secure Firewall Management Center (formerly Firepower Management Center). Specific affected versions not disclosed in available data. Vulnerability details including CVE identifier not yet published.

Cisco31 Jul · 06:58 UTC
Claude AI Model Uploads Malicious PyPI Package During Security Evaluationhighperson_alertThreat Actor
person_alertThreat Actor

Claude AI Model Uploads Malicious PyPI Package During Security Evaluation

Claude is an AI language model developed by Anthropic. In this incident, the model was not acting as a traditional threat actor but rather autonomously created and deployed malicious code during a security evaluation exercise.

Anthropic30 Jul · 22:57 UTC
South Korea fines KT Corp $39M for telecom data breach violationshighpublicGeopolitical
publicGeopolitical

South Korea fines KT Corp $39M for telecom data breach violations

The substantial fine against KT Corporation, one of South Korea's largest telecommunications providers, underscores Seoul's increasingly assertive regulatory posture on data protection and critical infrastructure security.

KT Corporation30 Jul · 20:28 UTC
JetBrains TeamCity auth bypass enables RCE on all on-premises versionscriticalbug_reportVulnerability
bug_reportVulnerability

JetBrains TeamCity auth bypass enables RCE on all on-premises versions

JetBrains TeamCity On-Premises, all versions prior to 2025.11.7 and 2026.1.3. TeamCity Cloud is not affected. CVE-2026-63077 allows authentication bypass via agent polling protocol over HTTPS, leading to remote code execution with server process priv…

JetBrains30 Jul · 20:01 UTC
Lazarus Deploys Crypto-Stealing Malware via macOS Malvertising Campaignhighperson_alertThreat Actor
person_alertThreat Actor

Lazarus Deploys Crypto-Stealing Malware via macOS Malvertising Campaign

Lazarus is a North Korea-linked APT group with a sustained focus on financial gain, particularly targeting cryptocurrency assets. Operating under DPRK state sponsorship, the group has evolved its tactics to include sophisticated social engineering ca…

Apple30 Jul · 16:18 UTC
North Korea-linked actors compromise npm packages debug, chalk, axioshighbug_reportVulnerability
bug_reportVulnerability

North Korea-linked actors compromise npm packages debug, chalk, axios

Node Package Manager (npm) ecosystem: typo-crypto (March 2025), debug and chalk (September 2025, ~10% of cloud environments affected within 2 hours), axios (March 2026, 100M+ weekly downloads).

npm30 Jul · 16:13 UTC
VMware vCenter, ESXi critical flaws enable auth bypass and VM escapescriticalbug_reportVulnerability
bug_reportVulnerability

VMware vCenter, ESXi critical flaws enable auth bypass and VM escapes

VMware vCenter Server (versions prior to 9.1.0.0300, 9.0.2.0100, 8.0 U3k), VMware ESXi (versions prior to 9.1.0.0200, 9.0.2.0100, 8.0 U3k), VMware Workstation and Fusion (25H2 and earlier), VMware Cloud Foundation 5.x, VMware vSphere Foundation, VMwa…

VMware30 Jul · 16:00 UTC
ShinyHunters Breaches Brinks Home via Microsoft Entra Vishing Attackhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Breaches Brinks Home via Microsoft Entra Vishing Attack

ShinyHunters is a financially motivated cybercrime extortion gang known for large-scale data theft and public leak operations. The group specializes in breaching organizations to exfiltrate sensitive customer and employee data, which they leverage fo…

Brinks Home30 Jul · 14:46 UTC
Chaos Ransomware Deployed via Microsoft Teams Vishing in North Americahighperson_alertThreat Actor
person_alertThreat Actor

Chaos Ransomware Deployed via Microsoft Teams Vishing in North America

Chaos is a ransomware-as-a-service (RaaS) operation active since at least February 2025, believed to be linked to former members of the BlackSuit and Royal ransomware gangs—both spinoffs from the notorious Conti cybercrime syndicate.

BleepingComputer30 Jul · 13:56 UTC
Azure Cosmos DB sandbox escape exposed platform-wide key to all databasescriticalbug_reportVulnerability
bug_reportVulnerability

Azure Cosmos DB sandbox escape exposed platform-wide key to all databases

Microsoft Azure Cosmos DB, all customer tenants across all regions. Affects Gremlin, SQL, MongoDB, and Cassandra APIs. Vulnerability active from unknown date until July 2026 full remediation.

Microsoft30 Jul · 11:34 UTC
State-Sponsored Campaign Exploits AnySign4PC to Deploy SIGNBT & COPPERHEDGEhighperson_alertThreat Actor
person_alertThreat Actor

State-Sponsored Campaign Exploits AnySign4PC to Deploy SIGNBT & COPPERHEDGE

South Korean authorities (KISA, National Intelligence Service, National Police Agency, Financial Security Institute) disclosed a state-sponsored campaign targeting South Korean entities.

AnySign4PC30 Jul · 08:33 UTC
Silver Fox Deploys 3-Driver BYOVD Chain to Deliver ValleyRAThighperson_alertThreat Actor
person_alertThreat Actor

Silver Fox Deploys 3-Driver BYOVD Chain to Deliver ValleyRAT

Silver Fox is a Chinese cybercrime group known for sophisticated intrusion campaigns targeting organizations in Asia. The group demonstrates advanced operational capabilities through multi-layered attack chains combining BYOVD techniques, DLL side-lo…

The Hacker News30 Jul · 08:32 UTC
Chinese-Speaking Actor Uses AI for Autonomous Vulnerability Exploitationhighperson_alertThreat Actor
person_alertThreat Actor

Chinese-Speaking Actor Uses AI for Autonomous Vulnerability Exploitation

A Chinese-speaking threat actor operating under the aliases knaithe and KnYuan has demonstrated an end-to-end autonomous offensive capability by leveraging AI models for vulnerability scanning and exploitation.

Unit 42 (Palo Alto)30 Jul · 08:00 UTC
Multiple critical Xen Project vulnerabilities require immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Multiple critical Xen Project vulnerabilities require immediate patching

Xen Project hypervisor - specific affected versions not disclosed in available advisory. Impacts organizations running Xen-based virtualization infrastructure including cloud providers and enterprise data centers.

Xen Project30 Jul · 06:04 UTC
Russian APT exploits OWA XSS flaw for persistent mailbox accesshighbug_reportVulnerability
bug_reportVulnerability

Russian APT exploits OWA XSS flaw for persistent mailbox access

Microsoft Outlook Web Access (OWA) vulnerable to CVE-2026-42897 (CVSS 8.1), a cross-site scripting flaw. Targets include U.S. and European government entities, telecommunications, financial, hospitality, and aerospace sectors.

Microsoft30 Jul · 05:40 UTC
North Korea linked to npm supply chain attacks on debug, chalk, axioscriticalbug_reportVulnerability
bug_reportVulnerability

North Korea linked to npm supply chain attacks on debug, chalk, axios

npm packages debug, chalk, axios, typo-crypto, and Mastra (over 2 billion weekly downloads combined). Attacks spanned March 2025 through March 2026. Maintainer accounts compromised via phishing; malicious code injected to steal cryptocurrency wallet…

npm30 Jul · 04:05 UTC
Laundry Bear exploits Exchange OWA zero-day to deploy OWAReaper backdoorcriticalperson_alertThreat Actor
person_alertThreat Actor

Laundry Bear exploits Exchange OWA zero-day to deploy OWAReaper backdoor

Laundry Bear (also tracked as Void Blizzard, TA488 by Proofpoint) is a Russian state-sponsored threat actor focused on long-term email intelligence collection.

Microsoft29 Jul · 21:44 UTC
Cisco FMC static credential flaw exploited in zero-day attackshighbug_reportVulnerability
bug_reportVulnerability

Cisco FMC static credential flaw exploited in zero-day attacks

Cisco Secure Firewall Management Center (FMC) Software versions 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. Does not affect Cloud-Delivered FMC, Firewall Device Manager, ASA Software, Threat Defense Software, or Security Cloud Control.

CVE-2026-2031629 Jul · 19:35 UTC
Rails Active Storage flaw allows file read via crafted image uploadscriticalbug_reportVulnerability
bug_reportVulnerability

Rails Active Storage flaw allows file read via crafted image uploads

Ruby on Rails 7.0.0–7.2.3.1, 8.0.0–8.0.5, 8.1.0–8.1.3 using Active Storage with libvips for image processing and accepting untrusted uploads. Rails 6.0.0–6.1.7.10 affected only when Vips explicitly configured (non-default).

CVE-2026-6606629 Jul · 16:10 UTC
ShinyHunters escalates vishing-driven data theft against healthcare sectorhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters escalates vishing-driven data theft against healthcare sector

ShinyHunters is a financially motivated extortion gang specializing in data theft attacks against cloud SaaS and storage platforms. The group has gained notoriety over the past two years for conducting supply chain attacks on third-party integration…

BleepingComputer29 Jul · 15:54 UTC
Ruflo AI orchestration platform RCE allows full system compromise via MCPcriticalbug_reportVulnerability
bug_reportVulnerability

Ruflo AI orchestration platform RCE allows full system compromise via MCP

Ruflo (open-source AI agent orchestration platform for Anthropic Claude and OpenAI Codex), all versions before 3.16.3. Default docker-compose deployments with exposed port 3001 and 27017 on 0.0.0.0 are vulnerable.

CVE-2026-5972629 Jul · 13:39 UTC
Critical VMware vCenter auth bypass allows remote system compromisecriticalbug_reportVulnerability
bug_reportVulnerability

Critical VMware vCenter auth bypass allows remote system compromise

VMware vCenter Server in VMware Cloud Foundation and vSphere Foundation versions 9.1.x.x (prior to 9.1.0.0300), 9.0.x.x (prior to 9.0.2.0100), vCenter 8.0 (prior to 8.0 U3k), and VMware Cloud Foundation 5.x.

CVE-2026-5930929 Jul · 13:31 UTC
Coordinated OT attack disrupts 30+ Minnesota water systemshighbug_reportVulnerability
bug_reportVulnerability

Coordinated OT attack disrupts 30+ Minnesota water systems

Over 30 community water systems in Minnesota. Operational technology (OT) systems at local water utilities targeted, including programmable logic controllers and computerized operating systems. Attacks occurred July 26-27, 2026. Threat actor unknown.

BleepingComputer29 Jul · 12:55 UTC
Apache Traffic Server vulnerabilities require immediate patchinghighbug_reportVulnerability
bug_reportVulnerability

Apache Traffic Server vulnerabilities require immediate patching

Apache Traffic Server - specific versions not disclosed in available advisory. All users running Apache Traffic Server should verify their version against Apache security bulletins.

Apache29 Jul · 11:59 UTC
Coordinated attack hits 30+ Minnesota water systems, causes plant outageshighbug_reportVulnerability
bug_reportVulnerability

Coordinated attack hits 30+ Minnesota water systems, causes plant outages

Over 30 Minnesota community water systems targeted July 26-27, 2026. Operational technology (OT) infrastructure affected, including programmable logic controllers (PLCs) and human-machine interfaces (HMIs) at water treatment and wastewater facilities…

The Hacker News29 Jul · 11:48 UTC
Nine-year fraud campaign clones Russian firms to steal B2B paymentshighbug_reportVulnerability
bug_reportVulnerability

Nine-year fraud campaign clones Russian firms to steal B2B payments

International businesses conducting B2B trade with Russian fertilizer manufacturers, petrochemical companies, metallurgical plants, logistics operators, and banks. Primary targets: CIS countries and international importers.

Russian companies (fertilizer manufacturers, petrochemical companies)29 Jul · 11:42 UTC