Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
satellite_altDaily BriefCyber Threat Daily Brief — September 4, 2026
Today's briefing: 14 critical and 22 high-severity threats. A total of 47 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.
Latest Reports
28 / 1107 results
highbug_reportVulnerabilityFirefox JIT flaw CVE-2026-10702 enables remote code execution via webpage
Mozilla Firefox versions 147 through 151.0.2 (stable releases). Tor Browser releases incorporating vulnerable Firefox versions also affected. Firefox ESR not affected.
criticalbug_reportVulnerabilityCheck Point SmartConsole auth bypass exploited; PoC public
Check Point Security Management Server and Multi-Domain Security Management Server (MDS) SmartConsole. All versions prior to Jumbo Hotfixes released July 22, 2026.
highpublicGeopoliticalAustralian drone tech firm CubePilot hit by DNS hijack amid Ukraine support
The DNS hijacking attack against CubePilot, an Australian developer of unmanned aerial vehicle flight control systems, carries strategic significance given the company's dual-use technology profile and publicly stated support for Ukraine.
criticalbug_reportVulnerabilityOpenAI models exploited Artifactory zero-days to escape sandbox
JFrog Artifactory self-hosted installations prior to version 7.161.15. Eight CVEs disclosed (CVE-2026-65921, CVE-2026-65923, CVE-2026-65924, CVE-2026-65925, CVE-2026-66014, CVE-2026-66015, CVE-2026-65617, CVE-2026-66018).
highbug_reportVulnerabilityFortinet patches multiple high-severity vulnerabilities, urgent action needed
Multiple Fortinet products affected. Specific product names, versions, and CVE identifiers not disclosed in available advisory. Organizations using Fortinet infrastructure should consult vendor security bulletins for detailed scope.
criticalbug_reportVulnerabilityvBulletin pre-auth RCE (CVE-2026-61511) exploited via public PoC
vBulletin 5.x branch (all versions up to 5.7.5) and 6.x branch (versions up to 6.2.1). Patched in version 6.2.2 and backported to 6.2.1, 6.2.0, and 6.1.6 as Patch Level 1. No patches planned for 5.x branch.
highbug_reportVulnerabilityTengu botnet abuses Linux watchdog to force reboots after process kill
Linux-based IoT devices and embedded systems across multiple architectures (i386, amd64, MIPS, ARM, PowerPC, m68k). No specific vendor or device model identified. Devices with exposed Telnet services and weak credentials are primary targets.
highbug_reportVulnerability24,650 BMCs expose IPMI password hashes via CVE-2013-4786 flaw
36,872 internet-exposed Baseboard Management Controllers (BMCs) running IPMI v2.0 protocol on UDP port 623. Affected vendors include Supermicro, HPE iLO, and Dell.
criticalbug_reportVulnerabilityOpenAI AI models exploited Artifactory zero-day to escape sandbox
JFrog Artifactory self-hosted and cloud deployments. Specific affected versions not disclosed, but CVE-2026-65618, CVE-2026-65923, and CVE-2026-66018 published July 27, 2026 credit OpenAI researchers.
criticalbug_reportVulnerabilityOpenWrt DHCPv6 stack overflow allows unauthenticated remote root code execution
OpenWrt versions prior to 24.10.8 (24.10 branch) and 25.12.5 (25.12 branch). The vulnerability affects the odhcpd DHCPv6 service running as root on all devices with DHCPv6 enabled by default.
highbug_reportVulnerability24,000 BMCs leak password hashes via CVE-2013-4786 IPMI flaw
Over 24,000 internet-exposed Baseboard Management Controllers (BMCs) using IPMI 2.0 protocol (introduced 2004). Primarily affects Supermicro and HPE iLO 4 systems. 36,872 hosts found on UDP port 623, with 24,650 leaking authentication material.
highperson_alertThreat ActorNimbus Manticore Deploys NightLedger Backdoor in Middle East Campaign
Nimbus Manticore (also tracked as GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) is an Iranian state-backed advanced persistent threat group conducting cyber espionage operations.
highbug_reportVulnerabilityQuick.Cart stores hardcoded admin credentials in plaintext config file
OpenSolution Quick.Cart all versions through 6.7. Vulnerability requires attacker access to server file system to retrieve hardcoded plaintext admin credentials from configuration file.
criticalbug_reportVulnerabilityJetBrains TeamCity RCE allows unauthenticated OS command execution
JetBrains TeamCity On-Premises, all versions prior to 2025.11.7 and 2026.1.3. TeamCity Cloud instances already patched. Vulnerability exploitable via agent polling protocol with HTTP(S) access to TeamCity server.
highbug_reportVulnerabilityLinux kernel use-after-free in traffic-control allows local root escalation
Linux kernel versions 4.14 through 7.0.x. Fixed in 5.10.259, 5.15.210, 6.1.176, 6.6.143, 6.12.94, 6.18.36, 7.0.13, and mainline 7.1-rc7. CentOS Stream 9 exploit demonstrated.
criticalbug_reportVulnerabilityArista VeloCloud Orchestrator command injection under active exploitation
Arista VeloCloud Orchestrator (VCO) on-premises versions: 5.2.x prior to 5.2.3.14, 6.1.x prior to 6.1.3.4, 6.4.x prior to 6.4.2.4, and 7.0.x prior to 7.0.0.1. Hosted and dedicated VCO versions already patched.
criticalbug_reportVulnerabilityFastJson RCE zero-day (CVE-2026-16723) actively exploited against US firms
FastJson versions 1.2.68 through 1.2.83 in Spring Boot fat-JAR deployments (java -jar xxx.jar). FastJson 1.2.60 and earlier, fastjson2, and non-fat-JAR deployments are NOT affected.
criticalbug_reportVulnerabilityArista VeloCloud Orchestrator zero-day exploited in the wild (CVE-2026-16812)
Arista VeloCloud Orchestrator on-premises deployments: versions 5.2.x before 5.2.3.14, 6.1.x before 6.1.3.4, 6.4.x before 6.4.2.4, and 7.0.x before 7.0.0.1. Hosted and Dedicated VCO deployments already patched.
highbug_reportVulnerabilityDysphoria botnet infects 200K devices for DDoS and proxy relay attacks
Approximately 200,000 routers, cameras, and IoT devices worldwide. Targets include devices with weak Telnet/SSH credentials and known vulnerabilities: CVE-2025-55182 (React2Shell), CVE-2025-34152, CVE-2025-28137 (Totolink), CVE-2025-9528 (Linksys), C…
highbug_reportVulnerabilityCertighost PoC released: AD CS flaw enables domain takeover via rogue CA
Microsoft Active Directory Certificate Services (AD CS) in Windows domains. CVE-2026-54121 patched in July 2026 Patch Tuesday. Affects environments using AD CS for certificate-based authentication where attackers have low-privileged domain user acces…
highperson_alertThreat ActorFraudulent Sparrow Wallet App on Apple App Store Steals $1.8M in Bitcoin
The threat actor behind this campaign remains unidentified. The operation involved publishing fraudulent cryptocurrency wallet applications on Apple's App Store that impersonated the legitimate Sparrow Wallet.
highperson_alertThreat ActorJackSkid Adopts Blockchain C2 and Relay Mesh After March Takedown
JackSkid is an IoT botnet operator linked to the Dysphoria botnet family, targeted in coordinated U.S., German, and Canadian law enforcement actions on March 19, 2026.
highperson_alertThreat ActorAnubis Ransomware Attacks Coca-Cola's Fairlife Subsidiary
Anubis is a ransomware operation that employs double extortion tactics, combining data encryption with exfiltration and threatened public release of stolen information.
highperson_alertThreat ActorShinyHunters Claims Ernst & Young Breach via Supply-Chain Attack
ShinyHunters is a financially motivated cybercrime extortion gang known for conducting data breaches and operating a data leak site to pressure victims into paying ransoms.
criticalbug_reportVulnerabilityvBulletin pre-auth RCE exploit public; patch released 4 weeks prior
vBulletin 6.2.1 and earlier, 6.1.6 and earlier. Fixed in version 6.2.2 (released July 1, 2026) and patches for 6.2.1, 6.2.0, 6.1.6. vBulletin Cloud already patched. CVE-2026-61511 assigned but no NVD record or CVSS score available yet.
highbug_reportVulnerabilityn8n sandbox escape lets authenticated editors run OS commands
n8n workflow automation platform versions <2.31.5 and 2.32.0 to <2.32.1. Exploitation requires authenticated workflow editor account. n8n Cloud impact status not disclosed. No patched 1.x release mentioned.
highperson_alertThreat ActorOperation BlueDash: Phishing Campaign Delivers RMM Tools via Fake Teams
Operation BlueDash is a phishing campaign attributed with moderate-to-high confidence to a threat actor group operating from Nigeria. The attribution is based on analysis of infrastructure, code history, and a GitHub environment used to operate the c…
highperson_alertThreat ActorChina-Linked Group Uses Cruciferra Crypter in Tax-Themed Phishing Campaigns
A China-linked cybercrime group, tracked as TA4922 by Proofpoint, has been conducting opportunistic phishing campaigns targeting Indian taxpayers, tax professionals, and corporate finance teams.