Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 649 results
Active filter:tag: #vulnerability✕ clear
Cisco Catalyst SD-WAN zero-day exploited for root access (CVE-2026-20245)criticalbug_reportVulnerability
bug_reportVulnerability

Cisco Catalyst SD-WAN zero-day exploited for root access (CVE-2026-20245)

Cisco Catalyst SD-WAN devices. Specific affected versions not disclosed in available information. Attackers gain root-level access and can create persistent rogue accounts.

CVE-2026-2024524 Jun · 19:29 UTC
CISA warns: Lantronix EDS5000 code injection under active exploitcriticalbug_reportVulnerability
bug_reportVulnerability

CISA warns: Lantronix EDS5000 code injection under active exploit

Lantronix EDS5000 Series devices. Specific vulnerable firmware versions not disclosed in provided data. Critical code injection vulnerability (CVE-2025-67038, CVSS 9.8).

CVE-2025-6703824 Jun · 15:19 UTC
CISA warns: Critical flaws in Ubiquiti UniFi OS and Lantronix exploitedcriticalbug_reportVulnerability
bug_reportVulnerability

CISA warns: Critical flaws in Ubiquiti UniFi OS and Lantronix exploited

Ubiquiti UniFi OS and Lantronix serial-to-ethernet servers. Specific affected versions not disclosed in summary. Both products commonly deployed in enterprise network infrastructure and IoT/OT environments.

Ubiquiti24 Jun · 12:35 UTC
CI/CD flaw "Cordyceps" exposes 300+ GitHub repos to supply-chain takeovercriticalbug_reportVulnerability
bug_reportVulnerability

CI/CD flaw "Cordyceps" exposes 300+ GitHub repos to supply-chain takeover

300+ GitHub repositories across major organizations including Microsoft, Google, and Apache. Vulnerability affects GitHub Actions CI/CD workflows. Specific products and versions not disclosed in available data.

Microsoft24 Jun · 10:48 UTC
Microsoft DCU disrupts StealC and Amadey infostealer infrastructurehighbug_reportVulnerability
bug_reportVulnerability

Microsoft DCU disrupts StealC and Amadey infostealer infrastructure

Organizations globally using Windows systems targeted by StealC and Amadey infostealer malware-as-a-service operations. Infrastructure takedown executed June 24, 2026.

Microsoft24 Jun · 10:30 UTC
Cisco Unified CM critical flaw under active exploitation, root access riskcriticalbug_reportVulnerability
bug_reportVulnerability

Cisco Unified CM critical flaw under active exploitation, root access risk

Cisco Unified Communications Manager (CUCM) and Unified CM SME. Specific affected versions not provided in available data. Vulnerability affects HTTP request handling with unauthenticated remote attack vector.

CVE-2026-2023024 Jun · 04:50 UTC
Malicious AI skills in ClawHub marketplace evade scanners, deploy infostealershighbug_reportVulnerability
bug_reportVulnerability

Malicious AI skills in ClawHub marketplace evade scanners, deploy infostealers

ClawHub marketplace users consuming third-party AI skills. Specific affected products: OpenClaw and ClawHub platforms. Scope includes organizations deploying AI agents with marketplace-sourced skills that may contain evasive malware delivering infost…

OpenClaw, ClawHub23 Jun · 20:00 UTC
Cisco Unified Communications Manager SSRF under active exploitationhighbug_reportVulnerability
bug_reportVulnerability

Cisco Unified Communications Manager SSRF under active exploitation

Cisco Unified Communications Manager (CUCM). Specific affected versions not disclosed. SSRF vulnerability (CVE-2026-20230) allows attackers to force the server to make unauthorized requests to internal or external resources.

CVE-2026-2023023 Jun · 19:48 UTC
GitHub blocks pwn request attacks in actions/checkout starting June 2026highbug_reportVulnerability
bug_reportVulnerability

GitHub blocks pwn request attacks in actions/checkout starting June 2026

GitHub Actions workflows using actions/checkout with pull_request_target trigger. Organizations using GitHub Actions for CI/CD pipelines are affected. The security update applies to all repositories using the actions/checkout action after June 18, 20…

GitHub23 Jun · 12:22 UTC
LastPass breached via Klue supply chain attack; OAuth tokens stolenhighbug_reportVulnerability
bug_reportVulnerability

LastPass breached via Klue supply chain attack; OAuth tokens stolen

LastPass customers. Attack vector: compromised Klue third-party service leading to OAuth token theft and unauthorized access to LastPass Salesforce environment containing customer data.

LastPass23 Jun · 11:58 UTC
Totolink EX1200L router vulnerable to stack buffer overflow (RCE)highbug_reportVulnerability
bug_reportVulnerability

Totolink EX1200L router vulnerable to stack buffer overflow (RCE)

Totolink EX1200L router software. Specific affected firmware versions not disclosed. Vulnerability is a stack-based buffer overflow enabling potential remote code execution.

CVE-2026-4408923 Jun · 08:55 UTC
Malicious npm packages deliver Windows RAT to JavaScript developershighbug_reportVulnerability
bug_reportVulnerability

Malicious npm packages deliver Windows RAT to JavaScript developers

Three npm packages (aes-decode-runner-pro, postcss-minify-selector, postcss-minify-selector-parser) published within the past month. Total downloads: 145-615 per package. Affects Windows-based development environments using npm package manager.

npm23 Jun · 06:54 UTC
WhatsApp malware campaign uses fake business docs to deploy VBScript RATshighbug_reportVulnerability
bug_reportVulnerability

WhatsApp malware campaign uses fake business docs to deploy VBScript RATs

WhatsApp users across multiple countries. Attack vector: social engineering via WhatsApp messages containing malicious VBScript files disguised as business documents. Enables remote access to Windows PCs.

BleepingComputer22 Jun · 20:42 UTC
Cloud bucket hijacking flaw exploits global namespace across AWS, Azure, GCPhighbug_reportVulnerability
bug_reportVulnerability

Cloud bucket hijacking flaw exploits global namespace across AWS, Azure, GCP

AWS S3, Azure Blob Storage, and Google Cloud Storage bucket naming systems. Affects organizations using cloud storage services across all three major cloud providers.

Amazon Web Services22 Jun · 20:00 UTC
FFmpeg 'PixelSmash' flaw enables RCE on Jellyfin, DoS on multiple appshighbug_reportVulnerability
bug_reportVulnerability

FFmpeg 'PixelSmash' flaw enables RCE on Jellyfin, DoS on multiple apps

FFmpeg (version details not specified). Downstream impact: Jellyfin (remote code execution), Kodi, Emby, Nextcloud, PhotoPrism, OBS Studio (denial-of-service). Affects media processing and streaming applications using vulnerable FFmpeg libraries.

FFmpeg22 Jun · 19:05 UTC
ShapedPlugin WordPress Pro plugins backdoored via compromised update channelhighbug_reportVulnerability
bug_reportVulnerability

ShapedPlugin WordPress Pro plugins backdoored via compromised update channel

Multiple ShapedPlugin Pro WordPress plugins distributed through official licensed update channels. Exact plugin names and affected versions not specified.

ShapedPlugin22 Jun · 16:00 UTC
Microsoft patches AutoJack vulnerability chain in AutoGen Studiohighbug_reportVulnerability
bug_reportVulnerability

Microsoft patches AutoJack vulnerability chain in AutoGen Studio

Microsoft AutoGen Studio - all versions prior to the patched release. AutoGen Studio is a low-code interface for building and managing AI agents. The vulnerability chain affects users who interact with untrusted web content while AutoGen Studio is ru…

Microsoft22 Jun · 15:28 UTC
DifyTap flaws enable cross-tenant AI conversation theft in Dify platformhighbug_reportVulnerability
bug_reportVulnerability

DifyTap flaws enable cross-tenant AI conversation theft in Dify platform

Dify open-source agentic workflow platform. Specific affected versions not disclosed. Vulnerability enables cross-tenant data access, affecting multi-tenant deployments and cloud-hosted instances.

Dify22 Jun · 14:13 UTC
Dual ransomware actors operate simultaneously in Microsoft environmentshighbug_reportVulnerability
bug_reportVulnerability

Dual ransomware actors operate simultaneously in Microsoft environments

Organizations using Microsoft environments, particularly those with insufficient network segmentation and endpoint visibility. No specific product vulnerability; threat involves operational security gaps enabling parallel intrusions.

Microsoft22 Jun · 14:00 UTC
Critical RCE and XSS flaws in pgAdmin 4 enable credential theftcriticalbug_reportVulnerability
bug_reportVulnerability

Critical RCE and XSS flaws in pgAdmin 4 enable credential theft

pgAdmin 4 (specific vulnerable versions not provided in alert). pgAdmin is a web-based administration tool for PostgreSQL databases, commonly deployed in enterprise environments for database management.

pgAdmin22 Jun · 13:02 UTC
ProxySQL ACL bypass and heap corruption flaws threaten database securitycriticalbug_reportVulnerability
bug_reportVulnerability

ProxySQL ACL bypass and heap corruption flaws threaten database security

ProxySQL (specific versions not provided). Vulnerabilities include ACL bypass allowing unauthorized access and heap memory corruption potentially enabling remote code execution. Database proxy infrastructure is at risk.

ProxySQL22 Jun · 12:48 UTC
29-year-old Squid heap over-read leaks HTTP credentials in default confighighbug_reportVulnerability
bug_reportVulnerability

29-year-old Squid heap over-read leaks HTTP credentials in default config

Squid web proxy, all versions containing FTP parsing code from 1997 onward. Vulnerability present in default configuration. Affects organizations using Squid as forward or reverse proxy.

Squid22 Jun · 12:29 UTC
AryStinger botnet compromises 4,000+ legacy D-Link routers as proxieshighbug_reportVulnerability
bug_reportVulnerability

AryStinger botnet compromises 4,000+ legacy D-Link routers as proxies

Over 4,000 outdated D-Link routers worldwide, specifically legacy models no longer receiving security updates. Exact models not specified in available data.

D-Link21 Jun · 12:14 UTC
North Korean APT compromised 140+ npm packages via Mastra AI frameworkhighbug_reportVulnerability
bug_reportVulnerability

North Korean APT compromised 140+ npm packages via Mastra AI framework

Mastra AI framework and over 140 dependent npm packages. Organizations using Mastra AI or downstream dependencies in Node.js/JavaScript applications are affected.

Mastra AI20 Jun · 12:09 UTC
Unit 42 issues guidance on large-scale credential attack campaignshighbug_reportVulnerability
bug_reportVulnerability

Unit 42 issues guidance on large-scale credential attack campaigns

Organizations using security vendor devices targeted in recent credential-based attack campaigns. No specific CVE; threat involves coordinated credential compromise attempts across multiple vendors' products.

Unit 42 (Palo Alto)20 Jun · 00:05 UTC
Gravity SMTP WordPress plugin under active exploit for info disclosurehighbug_reportVulnerability
bug_reportVulnerability

Gravity SMTP WordPress plugin under active exploit for info disclosure

Gravity SMTP WordPress plugin, affecting approximately 100,000 websites. Specific vulnerable versions not disclosed in available data.

Gravity SMTP19 Jun · 18:25 UTC
Unpatchable SecureROM exploit for Apple A12/A13 chips publishedcriticalbug_reportVulnerability
bug_reportVulnerability

Unpatchable SecureROM exploit for Apple A12/A13 chips published

Apple devices with A12 and A13 chips (iPhone XS/XR/11 series, iPad Air 3rd gen, iPad mini 5th gen, iPad 8th gen). SecureROM vulnerability is permanent and cannot be patched via software updates.

Apple19 Jun · 16:37 UTC
Critical RCE in Splunk Enterprise under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Critical RCE in Splunk Enterprise under active exploitation

Splunk Enterprise (specific versions not disclosed in alert). The vulnerability enables remote code execution. CVE identifier not yet assigned or published.

Splunk19 Jun · 13:33 UTC
AutoJack exploit chain enables RCE on AI browsing agents via malicious pageshighbug_reportVulnerability
bug_reportVulnerability

AutoJack exploit chain enables RCE on AI browsing agents via malicious pages

AI browsing agents (autonomous web browsers with AI capabilities) that interact with privileged local services via JavaScript. Specific products and versions not disclosed in Microsoft's research disclosure.

Microsoft19 Jun · 13:30 UTC
CISA orders federal agencies to patch exploited Splunk Enterprise flawcriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders federal agencies to patch exploited Splunk Enterprise flaw

Splunk Enterprise (specific versions not disclosed in summary). CISA directive targets U.S. federal agencies, but vulnerability affects all Splunk Enterprise deployments.

Splunk19 Jun · 08:39 UTC