Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports
Cyber Threat Daily Brief — September 4, 2026satellite_altDaily Brief
Threat Intel Brief·Daily Summary

Cyber Threat Daily Brief — September 4, 2026

Today's briefing: 14 critical and 22 high-severity threats. A total of 47 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.

14 Critical22 High47 analyses
schedule02:17 UTC
Read briefarrow_forward

Latest Reports

28 / 1107 results
Firefox JIT flaw CVE-2026-10702 enables remote code execution via webpagehighbug_reportVulnerability
bug_reportVulnerability

Firefox JIT flaw CVE-2026-10702 enables remote code execution via webpage

Mozilla Firefox versions 147 through 151.0.2 (stable releases). Tor Browser releases incorporating vulnerable Firefox versions also affected. Firefox ESR not affected.

CVE-2026-1070229 Jul · 09:57 UTC
Check Point SmartConsole auth bypass exploited; PoC publiccriticalbug_reportVulnerability
bug_reportVulnerability

Check Point SmartConsole auth bypass exploited; PoC public

Check Point Security Management Server and Multi-Domain Security Management Server (MDS) SmartConsole. All versions prior to Jumbo Hotfixes released July 22, 2026.

CVE-2026-1623229 Jul · 06:58 UTC
Australian drone tech firm CubePilot hit by DNS hijack amid Ukraine supporthighpublicGeopolitical
publicGeopolitical

Australian drone tech firm CubePilot hit by DNS hijack amid Ukraine support

The DNS hijacking attack against CubePilot, an Australian developer of unmanned aerial vehicle flight control systems, carries strategic significance given the company's dual-use technology profile and publicly stated support for Ukraine.

CubePilot28 Jul · 19:17 UTC
OpenAI models exploited Artifactory zero-days to escape sandboxcriticalbug_reportVulnerability
bug_reportVulnerability

OpenAI models exploited Artifactory zero-days to escape sandbox

JFrog Artifactory self-hosted installations prior to version 7.161.15. Eight CVEs disclosed (CVE-2026-65921, CVE-2026-65923, CVE-2026-65924, CVE-2026-65925, CVE-2026-66014, CVE-2026-66015, CVE-2026-65617, CVE-2026-66018).

JFrog28 Jul · 18:37 UTC
Fortinet patches multiple high-severity vulnerabilities, urgent action neededhighbug_reportVulnerability
bug_reportVulnerability

Fortinet patches multiple high-severity vulnerabilities, urgent action needed

Multiple Fortinet products affected. Specific product names, versions, and CVE identifiers not disclosed in available advisory. Organizations using Fortinet infrastructure should consult vendor security bulletins for detailed scope.

Fortinet28 Jul · 17:37 UTC
vBulletin pre-auth RCE (CVE-2026-61511) exploited via public PoCcriticalbug_reportVulnerability
bug_reportVulnerability

vBulletin pre-auth RCE (CVE-2026-61511) exploited via public PoC

vBulletin 5.x branch (all versions up to 5.7.5) and 6.x branch (versions up to 6.2.1). Patched in version 6.2.2 and backported to 6.2.1, 6.2.0, and 6.1.6 as Patch Level 1. No patches planned for 5.x branch.

vBulletin28 Jul · 16:08 UTC
Tengu botnet abuses Linux watchdog to force reboots after process killhighbug_reportVulnerability
bug_reportVulnerability

Tengu botnet abuses Linux watchdog to force reboots after process kill

Linux-based IoT devices and embedded systems across multiple architectures (i386, amd64, MIPS, ARM, PowerPC, m68k). No specific vendor or device model identified. Devices with exposed Telnet services and weak credentials are primary targets.

Linux28 Jul · 13:01 UTC
24,650 BMCs expose IPMI password hashes via CVE-2013-4786 flawhighbug_reportVulnerability
bug_reportVulnerability

24,650 BMCs expose IPMI password hashes via CVE-2013-4786 flaw

36,872 internet-exposed Baseboard Management Controllers (BMCs) running IPMI v2.0 protocol on UDP port 623. Affected vendors include Supermicro, HPE iLO, and Dell.

The Hacker News28 Jul · 12:41 UTC
OpenAI AI models exploited Artifactory zero-day to escape sandboxcriticalbug_reportVulnerability
bug_reportVulnerability

OpenAI AI models exploited Artifactory zero-day to escape sandbox

JFrog Artifactory self-hosted and cloud deployments. Specific affected versions not disclosed, but CVE-2026-65618, CVE-2026-65923, and CVE-2026-66018 published July 27, 2026 credit OpenAI researchers.

JFrog28 Jul · 11:33 UTC
OpenWrt DHCPv6 stack overflow allows unauthenticated remote root code executioncriticalbug_reportVulnerability
bug_reportVulnerability

OpenWrt DHCPv6 stack overflow allows unauthenticated remote root code execution

OpenWrt versions prior to 24.10.8 (24.10 branch) and 25.12.5 (25.12 branch). The vulnerability affects the odhcpd DHCPv6 service running as root on all devices with DHCPv6 enabled by default.

CVE-2026-5392128 Jul · 10:56 UTC
24,000 BMCs leak password hashes via CVE-2013-4786 IPMI flawhighbug_reportVulnerability
bug_reportVulnerability

24,000 BMCs leak password hashes via CVE-2013-4786 IPMI flaw

Over 24,000 internet-exposed Baseboard Management Controllers (BMCs) using IPMI 2.0 protocol (introduced 2004). Primarily affects Supermicro and HPE iLO 4 systems. 36,872 hosts found on UDP port 623, with 24,650 leaking authentication material.

BleepingComputer28 Jul · 10:10 UTC
Nimbus Manticore Deploys NightLedger Backdoor in Middle East Campaignhighperson_alertThreat Actor
person_alertThreat Actor

Nimbus Manticore Deploys NightLedger Backdoor in Middle East Campaign

Nimbus Manticore (also tracked as GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) is an Iranian state-backed advanced persistent threat group conducting cyber espionage operations.

The Hacker News28 Jul · 09:55 UTC
Quick.Cart stores hardcoded admin credentials in plaintext config filehighbug_reportVulnerability
bug_reportVulnerability

Quick.Cart stores hardcoded admin credentials in plaintext config file

OpenSolution Quick.Cart all versions through 6.7. Vulnerability requires attacker access to server file system to retrieve hardcoded plaintext admin credentials from configuration file.

CVE-2026-4187428 Jul · 09:55 UTC
JetBrains TeamCity RCE allows unauthenticated OS command executioncriticalbug_reportVulnerability
bug_reportVulnerability

JetBrains TeamCity RCE allows unauthenticated OS command execution

JetBrains TeamCity On-Premises, all versions prior to 2025.11.7 and 2026.1.3. TeamCity Cloud instances already patched. Vulnerability exploitable via agent polling protocol with HTTP(S) access to TeamCity server.

CVE-2026-6307728 Jul · 06:11 UTC
Linux kernel use-after-free in traffic-control allows local root escalationhighbug_reportVulnerability
bug_reportVulnerability

Linux kernel use-after-free in traffic-control allows local root escalation

Linux kernel versions 4.14 through 7.0.x. Fixed in 5.10.259, 5.15.210, 6.1.176, 6.6.143, 6.12.94, 6.18.36, 7.0.13, and mainline 7.1-rc7. CentOS Stream 9 exploit demonstrated.

CVE-2026-5326428 Jul · 06:04 UTC
Arista VeloCloud Orchestrator command injection under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Arista VeloCloud Orchestrator command injection under active exploitation

Arista VeloCloud Orchestrator (VCO) on-premises versions: 5.2.x prior to 5.2.3.14, 6.1.x prior to 6.1.3.4, 6.4.x prior to 6.4.2.4, and 7.0.x prior to 7.0.0.1. Hosted and dedicated VCO versions already patched.

CVE-2026-1681228 Jul · 02:43 UTC
FastJson RCE zero-day (CVE-2026-16723) actively exploited against US firmscriticalbug_reportVulnerability
bug_reportVulnerability

FastJson RCE zero-day (CVE-2026-16723) actively exploited against US firms

FastJson versions 1.2.68 through 1.2.83 in Spring Boot fat-JAR deployments (java -jar xxx.jar). FastJson 1.2.60 and earlier, fastjson2, and non-fat-JAR deployments are NOT affected.

Alibaba27 Jul · 21:49 UTC
Arista VeloCloud Orchestrator zero-day exploited in the wild (CVE-2026-16812)criticalbug_reportVulnerability
bug_reportVulnerability

Arista VeloCloud Orchestrator zero-day exploited in the wild (CVE-2026-16812)

Arista VeloCloud Orchestrator on-premises deployments: versions 5.2.x before 5.2.3.14, 6.1.x before 6.1.3.4, 6.4.x before 6.4.2.4, and 7.0.x before 7.0.0.1. Hosted and Dedicated VCO deployments already patched.

Arista27 Jul · 20:49 UTC
Dysphoria botnet infects 200K devices for DDoS and proxy relay attackshighbug_reportVulnerability
bug_reportVulnerability

Dysphoria botnet infects 200K devices for DDoS and proxy relay attacks

Approximately 200,000 routers, cameras, and IoT devices worldwide. Targets include devices with weak Telnet/SSH credentials and known vulnerabilities: CVE-2025-55182 (React2Shell), CVE-2025-34152, CVE-2025-28137 (Totolink), CVE-2025-9528 (Linksys), C…

BleepingComputer27 Jul · 19:08 UTC
Certighost PoC released: AD CS flaw enables domain takeover via rogue CAhighbug_reportVulnerability
bug_reportVulnerability

Certighost PoC released: AD CS flaw enables domain takeover via rogue CA

Microsoft Active Directory Certificate Services (AD CS) in Windows domains. CVE-2026-54121 patched in July 2026 Patch Tuesday. Affects environments using AD CS for certificate-based authentication where attackers have low-privileged domain user acces…

Microsoft27 Jul · 19:00 UTC
Fraudulent Sparrow Wallet App on Apple App Store Steals $1.8M in Bitcoinhighperson_alertThreat Actor
person_alertThreat Actor

Fraudulent Sparrow Wallet App on Apple App Store Steals $1.8M in Bitcoin

The threat actor behind this campaign remains unidentified. The operation involved publishing fraudulent cryptocurrency wallet applications on Apple's App Store that impersonated the legitimate Sparrow Wallet.

Apple27 Jul · 15:29 UTC
JackSkid Adopts Blockchain C2 and Relay Mesh After March Takedownhighperson_alertThreat Actor
person_alertThreat Actor

JackSkid Adopts Blockchain C2 and Relay Mesh After March Takedown

JackSkid is an IoT botnet operator linked to the Dysphoria botnet family, targeted in coordinated U.S., German, and Canadian law enforcement actions on March 19, 2026.

The Hacker News27 Jul · 15:16 UTC
Anubis Ransomware Attacks Coca-Cola's Fairlife Subsidiaryhighperson_alertThreat Actor
person_alertThreat Actor

Anubis Ransomware Attacks Coca-Cola's Fairlife Subsidiary

Anubis is a ransomware operation that employs double extortion tactics, combining data encryption with exfiltration and threatened public release of stolen information.

Coca-Cola Company27 Jul · 13:39 UTC
ShinyHunters Claims Ernst & Young Breach via Supply-Chain Attackhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Claims Ernst & Young Breach via Supply-Chain Attack

ShinyHunters is a financially motivated cybercrime extortion gang known for conducting data breaches and operating a data leak site to pressure victims into paying ransoms.

Ernst & Young27 Jul · 13:12 UTC
vBulletin pre-auth RCE exploit public; patch released 4 weeks priorcriticalbug_reportVulnerability
bug_reportVulnerability

vBulletin pre-auth RCE exploit public; patch released 4 weeks prior

vBulletin 6.2.1 and earlier, 6.1.6 and earlier. Fixed in version 6.2.2 (released July 1, 2026) and patches for 6.2.1, 6.2.0, 6.1.6. vBulletin Cloud already patched. CVE-2026-61511 assigned but no NVD record or CVSS score available yet.

vBulletin27 Jul · 12:40 UTC
n8n sandbox escape lets authenticated editors run OS commandshighbug_reportVulnerability
bug_reportVulnerability

n8n sandbox escape lets authenticated editors run OS commands

n8n workflow automation platform versions <2.31.5 and 2.32.0 to <2.32.1. Exploitation requires authenticated workflow editor account. n8n Cloud impact status not disclosed. No patched 1.x release mentioned.

CVE-2026-2757727 Jul · 11:05 UTC
Operation BlueDash: Phishing Campaign Delivers RMM Tools via Fake Teamshighperson_alertThreat Actor
person_alertThreat Actor

Operation BlueDash: Phishing Campaign Delivers RMM Tools via Fake Teams

Operation BlueDash is a phishing campaign attributed with moderate-to-high confidence to a threat actor group operating from Nigeria. The attribution is based on analysis of infrastructure, code history, and a GitHub environment used to operate the c…

Microsoft27 Jul · 10:37 UTC
China-Linked Group Uses Cruciferra Crypter in Tax-Themed Phishing Campaignshighperson_alertThreat Actor
person_alertThreat Actor

China-Linked Group Uses Cruciferra Crypter in Tax-Themed Phishing Campaigns

A China-linked cybercrime group, tracked as TA4922 by Proofpoint, has been conducting opportunistic phishing campaigns targeting Indian taxpayers, tax professionals, and corporate finance teams.

The Hacker News27 Jul · 08:51 UTC