Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 415 results
criticalbug_reportVulnerabilityLiteSpeed cPanel/WHM plugin under active exploit (CVE-2026-48172)
LiteSpeed plugin for cPanel/WHM. Specific vulnerable versions not disclosed in provided data. Affects web hosting environments using LiteSpeed with cPanel/WHM integration.
criticalbug_reportVulnerabilityUbiquiti patches critical UniFi OS vulnerabilities
Ubiquiti UniFi OS (specific versions not disclosed). Affects UniFi network management appliances including Dream Machine, Cloud Key, and similar devices running UniFi OS.
highperson_alertThreat ActorMuddyWater Q1 2026 espionage campaign hits nine countries via DLL side-loading
MuddyWater (also tracked as Earth Vetala, MERCURY, Static Kitten, and Seedworm) is an Iranian state-sponsored APT group attributed to Iran's Ministry of Intelligence and Security (MOIS).
criticalbug_reportVulnerabilityTrend Micro Apex One & Vision One SEP flaws under active exploit
Trend Micro Apex One and Trend Micro Vision One Endpoint Security (SEP). Specific vulnerable versions not disclosed in summary; multiple vulnerabilities confirmed under active exploitation.
highpublicGeopoliticalIndia mandates 12-hour patching for critical vulnerabilities
India's Computer Emergency Response Team (CERT-In) has introduced stringent vulnerability management requirements, mandating that organizations patch critical security flaws in internet-facing systems within 12 hours of notification.
criticalbug_reportVulnerabilityCritical vulnerability in Cisco Secure Workload requires immediate patching
Cisco Secure Workload (specific versions not disclosed in advisory). CVE identifier not yet assigned or published.
criticalbug_reportVulnerabilityCISA orders emergency patching of exploited Drupal SQL injection flaw
Drupal CMS (specific versions not provided in alert). Affects U.S. government agencies and all organizations running vulnerable Drupal instances.
highperson_alertThreat ActorNimbus Manticore deploys MiniFast and MiniJunk V2 via phishing and SEO poisoning
Nimbus Manticore (also tracked as Screening Serpens and UNC1549) is an Iranian state-sponsored threat actor attributed to Iran's intelligence apparatus.
highperson_alertThreat ActorShinyHunters Breaches 7-Eleven, Exfiltrates 183K Records
ShinyHunters is a financially motivated cybercrime group known for large-scale data breaches and extortion operations targeting organizations across multiple sectors.
highbug_reportVulnerabilityDigital Knowledge LMS exploited via hardcoded ASP.NET keys (CVE-2026-5426)
Digital Knowledge KnowledgeDeliver LMS (specific versions not disclosed). Vulnerability stems from hard-coded ASP.NET machine keys enabling authentication bypass and remote code execution.
highperson_alertThreat ActorDutch Authorities Disrupt Hosting Infrastructure Linked to Russian Ops
This operation involves Russian state-sponsored cyber activity facilitated through compromised Internet hosting infrastructure in the Netherlands. The arrested co-owners operated hosting companies that assumed control of Stark Industries Solutions' t…
highbug_reportVulnerabilityOutSystems Lifetime authorization bypass via user-controlled key
OutSystems Lifetime software. Specific affected versions not disclosed. Vulnerability allows authorization bypass through improper handling of user-controlled keys.
highperson_alertThreat ActorLazarus Group deploys RemotePE cross-platform RAT against finance sector
Lazarus Group is a North Korean state-sponsored advanced persistent threat (APT) actor attributed to the Reconnaissance General Bureau (RGB). The group is financially motivated, conducting operations to generate revenue for the DPRK regime through th…
highpublicGeopoliticalItaly Dismantles CINEMAGOAL Piracy Network Targeting Streaming Platforms
The disruption of the CINEMAGOAL piracy ecosystem represents a law enforcement action against organized digital piracy infrastructure rather than a state-sponsored cyber operation.
highperson_alertThreat ActorFirst VPN Service dismantled by European and North American authorities
First VPN Service was a criminal VPN infrastructure provider that facilitated cybercrime operations for approximately 25 ransomware groups. The service enabled threat actors to obscure their geographic origins and true IP addresses during malicious a…
highpublicGeopoliticalDutch authorities dismantle hosting infrastructure linked to cyber ops
The Netherlands has emerged as a key jurisdiction for enforcement against cyber-enabling infrastructure, reflecting both its role as a European internet hub and its proactive stance on transnational cybercrime.
criticalperson_alertThreat ActorCISA Contractor Leaks AWS GovCloud Keys on Public GitHub Repository
The threat actor is an insider—a contractor working for the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The individual intentionally published sensitive AWS GovCloud credentials and agency secrets to a public GitHub repository.
highperson_alertThreat ActorGhostwriter Targets Ukrainian Government with Prometheus-Themed Phishing
Ghostwriter (also tracked as UAC-0057 and UNC1151) is a Belarus-aligned threat actor known for conducting information operations and cyber espionage campaigns.
criticalbug_reportVulnerabilityTrend Micro Apex One zero-day actively exploited in the wild
Trend Micro Apex One on Windows systems. Specific affected versions not disclosed. Zero-day vulnerability with no CVE assigned yet.
highperson_alertThreat ActorScreening Serpens: Iranian APT Targets Tech and Defense with RAT Malware
Screening Serpens is an Iranian APT group attributed by Unit 42, conducting cyber espionage operations. The group is motivated by intelligence collection targeting technology and defense sectors, consistent with Iranian state interests in acquiring s…
highperson_alertThreat ActorCanadian National Arrested for Operating KimWolf DDoS Botnet
A Canadian national arrested by U.S. and Canadian authorities for operating the KimWolf DDoS botnet infrastructure. The operator managed a large-scale botnet that compromised nearly two million devices globally, offering DDoS-for-hire services.
highperson_alertThreat ActorJacob Butler Arrested for Operating Kimwolf DDoS Botnet
Jacob Butler, also known as "Dort," is a 23-year-old Canadian national from Ottawa arrested by the U.S. Department of Justice for developing and operating the Kimwolf DDoS botnet.
criticalbug_reportVulnerabilityCISA: Langflow and Trend Micro Apex One flaws actively exploited
Langflow (CVE-2025-34291, CVSS 9.4, origin validation error) and Trend Micro Apex One (CVE unspecified). Both products confirmed under active exploitation. Specific affected versions not disclosed in summary.
highperson_alertThreat ActorDort Arrested for Operating Kimwolf IoT Botnet in Multi-Million Device DDoS Campaign
Dort is a 23-year-old cybercriminal based in Ottawa, Canada, suspected of developing and operating the Kimwolf IoT botnet. Motivated by launching large-scale DDoS attacks, doxing, and swatting campaigns, Dort leveraged compromised IoT devices to buil…
criticalbug_reportVulnerabilityCritical SQL injection in Drupal Core requires immediate patching
Drupal Core, all versions (specific affected versions not disclosed in alert). Impacts all Drupal installations until patched.
highbug_reportVulnerabilityNLnet Labs patches DoS vulnerabilities in Unbound DNS resolver
Unbound DNS resolver by NLnet Labs. Specific vulnerable versions not provided in advisory; patched versions available. Affects organizations running Unbound for DNS resolution services.
highperson_alertThreat ActorShowboat Linux Malware Targets Middle East Telecom Since Mid-2022
The threat actor behind Showboat remains unattributed. The campaign demonstrates sophisticated targeting of telecommunications infrastructure in the Middle East, suggesting a motivated adversary with strategic intelligence collection objectives.
highperson_alertThreat ActorChinese APT Deploys Showboat and JFMBackdoor Against Telecom Sector
Chinese state-sponsored threat actors conducting cyber-espionage operations against telecommunications infrastructure. The actors demonstrate cross-platform capabilities with custom Linux and Windows malware tooling.
criticalbug_reportVulnerabilityCritical flaws in Sparx Pro Cloud Server actively exploited in the wild
Sparx Systems Pro Cloud Server and Enterprise Architect products. Specific vulnerable versions not disclosed in summary; CERT.BE advisory should be consulted for version details.
highperson_alertThreat Actor18-Year-Old Infostealer Operator Arrested for Compromising 28K Accounts
An 18-year-old individual from Odesa, Ukraine, identified by Ukrainian cyberpolice in coordination with U.S. law enforcement. The operator is suspected of deploying infostealer malware to harvest credentials and compromise user accounts.