Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 390 results
highperson_alertThreat Actor18-Year-Old Infostealer Operator Arrested for Compromising 28K Accounts
An 18-year-old individual from Odesa, Ukraine, identified by Ukrainian cyberpolice in coordination with U.S. law enforcement. The operator is suspected of deploying infostealer malware to harvest credentials and compromise user accounts.
highbug_reportVulnerabilityGrafana breach via unrotated GitHub token after TanStack npm compromise
Grafana Labs infrastructure. Organizations using Grafana products are not directly affected by the breach itself, but should monitor for potential secondary impacts.
highperson_alertThreat ActorWebworm Deploys EchoCreep and GraphWorm Backdoors via Discord and Graph API
Webworm is a China-aligned advanced persistent threat (APT) actor first documented by Symantec in September 2022, with activity traced back to at least 2022.
highbug_reportVulnerabilityPinTheft Linux privilege escalation PoC released for Arch Linux
Arch Linux systems. Specific affected package versions not disclosed; vulnerability has been patched in recent updates. Other Linux distributions may be affected depending on package configurations.
highbug_reportVulnerabilityMicrosoft mitigates YellowKey BitLocker bypass (CVE-2026-45585)
Microsoft BitLocker on Windows systems. Specific affected versions not disclosed. Vulnerability allows bypass of BitLocker disk encryption protections.
highbug_reportVulnerabilityMicrosoft mitigates YellowKey BitLocker zero-day bypass vulnerability
Windows BitLocker across all supported Windows versions. The vulnerability allows unauthorized access to BitLocker-protected drives. No CVE assigned yet.
highbug_reportVulnerabilityPostgreSQL patches multiple high-severity flaws; version 14 EOL announced
PostgreSQL database server, multiple versions affected by security vulnerabilities. Version 14 reaching end-of-life, no longer receiving security updates after EOL date.
highperson_alertThreat ActorTeamPCP Lists GitHub Source Code for Sale After Repository Breach
TeamPCP is a threat actor that has emerged in the cybercrime ecosystem, demonstrating capability to compromise high-value technology platforms. The actor's motivation appears financially driven, as evidenced by their decision to monetize stolen GitHu…
highperson_alertThreat ActorMicrosoft Disrupts Malware-Signing-as-a-Service Operation
This operation involved cybercriminals abusing Microsoft's Artifact Signing service to provide malware-signing-as-a-service capabilities. The actors exploited legitimate code-signing infrastructure to generate fraudulent certificates, which were then…
highperson_alertThreat ActorFox Tempest Provides Malware-Signing Services to Ransomware Operators
Fox Tempest is a financially motivated cybercriminal actor that operates as a malware-signing service provider within the ransomware ecosystem. Rather than conducting attacks directly, Fox Tempest enables other threat actors—including Vanilla Tempest…
highbug_reportVulnerabilityPoC released for DirtyDecrypt LPE in Linux kernel (CVE-2026-31635)
Linux kernel - specific vulnerable versions not provided. Local privilege escalation vulnerability affecting systems running vulnerable kernel versions.
highbug_reportVulnerabilityOver 600 malicious npm packages published in Shai-Hulud campaign
npm ecosystem: 600+ malicious packages published by threat actors. Affects organizations using npm for JavaScript/Node.js dependency management. Specific package names not provided in summary.
highbug_reportVulnerabilitySonicWall releases patches for multiple high-severity vulnerabilities
SonicWall products (specific models and versions not disclosed in summary). CERT.BE advisory indicates multiple vulnerabilities requiring immediate patching across SonicWall product line.
highperson_alertThreat ActorShinyHunters Claims 7-Eleven Data Breach
ShinyHunters is a financially motivated cybercrime group known for large-scale data breaches and database theft. The group emerged around 2020 and has been linked to numerous high-profile data exfiltration incidents targeting organizations across var…
highbug_reportVulnerabilityMicrosoft sees rise in privilege escalation and identity abuse flaws
Microsoft products and services experiencing increased critical vulnerabilities focused on privilege escalation and identity abuse. Specific affected products and versions not detailed in available data.
highbug_reportVulnerabilityABB CoreSense path traversal flaw allows unauthenticated system access
ABB CoreSense HM (versions prior to v2.3.4) and CoreSense M10 (versions prior to v1.4.1.31). Path traversal vulnerability affects unauthenticated remote attackers.
highbug_reportVulnerabilityKieback & Peter DDC controllers vulnerable to XSS attacks
Kieback & Peter DDC (Direct Digital Control) Building Controllers. Specific affected versions not disclosed in available data.
highbug_reportVulnerabilityBuffer overflow in PAN-OS User-ID portal enables unauthenticated RCE
Palo Alto Networks PAN-OS on PA-Series and VM-Series firewalls; Siemens RUGGEDCOM APE1808 devices. Specific affected PAN-OS versions not provided in summary.
highbug_reportVulnerabilityIvanti releases security updates for multiple products
Multiple Ivanti products affected. Specific product names, versions, and CVE identifiers not disclosed in available information. High severity rating indicates significant security risk.
highbug_reportVulnerabilityCode Runner MCP Server missing authentication flaw allows unauthorized access
Code Runner MCP Server (all versions not specified). The vulnerability affects critical functions within the server, allowing unauthenticated access to protected operations. Specific version ranges have not been disclosed by CERT.PL.
highbug_reportVulnerability3onedata GW1101 Modbus gateway vulnerable to OS command injection
3onedata GW1101-1D(RS-485)-TB-P Modbus gateways. Specific affected firmware versions not disclosed. These are industrial IoT devices used for Modbus protocol conversion in OT/ICS environments.
highperson_alertThreat ActorNCSC UK Issues Guidance on China-Nexus Covert Device Networks
China-nexus threat actors are state-sponsored groups linked to the People's Republic of China. These actors are motivated by strategic intelligence collection, espionage, and maintaining persistent access to foreign networks.
highperson_alertThreat ActorNCSC UK Issues Advisory on China-Linked Covert Network Tactics
China-linked threat actors employing covert network tactics to conceal malicious cyber activity. These actors are characterized by their use of sophisticated techniques to maintain persistent, stealthy access to compromised networks.
highpublicGeopoliticalUK NCSC Issues Guidance on China-Linked Covert Device Networks
The UK National Cyber Security Centre's release of defensive guidance targeting China-nexus covert networks reflects ongoing strategic competition between Western democracies and Beijing in cyberspace.
highbug_reportVulnerabilityOrca heat pumps lack authentication, transmit cleartext data to servers
Orca heat pumps (specific models and versions not disclosed). Vulnerability affects device-to-server communication and server-side data processing.
highbug_reportVulnerabilityMikroTik RouterOS auth bypass via certificate validation flaw
MikroTik RouterOS - versions not specified. Affects OpenVPN, CAPsMAN (wireless management), and 802.1X (Dot1x) services that rely on certificate-based authentication.
highpublicGeopoliticalLatvia faces elevated cyber threats amid geopolitical tensions in Q4 2025
Latvia's position as a NATO and EU member state on the eastern flank of the Alliance places it at the intersection of Western institutional security architecture and persistent regional tensions.
highbug_reportVulnerabilityFortinet FortiCloud SSO bypass exploited to extract LDAP passwords
Fortinet FortiGate appliances with FortiCloud SSO enabled. CVE-2025-59718 and CVE-2025-59719 allow authentication bypass. All FortiGate instances share a default static encryption key that enables decryption of LDAP credentials and private keys from…
highbug_reportVulnerabilityFortinet patches high severity FortiOS vulnerability
FortiOS (specific versions not disclosed in summary). Fortinet advisory published October 14, 2025.
highperson_alertThreat ActorRansomware Campaigns Target Slovenia via Email, RDP, and Exploits
Unattributed ransomware operators targeting Slovenia. Motivation appears financially driven, consistent with commodity ransomware campaigns. No specific actor attribution available; likely represents multiple threat groups employing common ransomware…