Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
satellite_altDaily BriefCyber Threat Daily Brief — July 21, 2026
Today's briefing: 3 critical and 16 high-severity threats. A total of 23 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.
Latest Reports
26 / 606 results
criticalbug_reportVulnerabilitynpm supply chain attack: 50+ packages deliver IronWorm stealer and rootkit
npm ecosystem: over 50 compromised legitimate packages. Affects developers using npm for JavaScript/Node.js projects. IronWorm targets developer credentials and source code with eBPF kernel-level persistence.
highbug_reportVulnerabilityPrompt injection in Claude Code GitHub Action exposes workflow secrets
Anthropic's Claude Code GitHub Action (prior to mitigation). Affects GitHub workflows using the action with access to repository secrets. Vulnerability exploitable when action processes untrusted input from pull requests or external sources.
highbug_reportVulnerabilityAsin Android spyware targets Arabic-speaking users via fake apps
Android devices used by Arabic-speaking populations. Malware distributed through fake applications impersonating news sources, PDF utilities, and war-related content. Active campaigns identified since early 2025.
highbug_reportVulnerability900+ US fuel tank monitoring systems exposed online, vulnerable to attack
Over 900 automatic tank gauge (ATG) systems in the United States used to monitor fuel and chemical storage tanks in critical infrastructure. Specific vendors and product versions not disclosed.
highbug_reportVulnerabilityActive exploitation of PAN-OS CVE-2026-0257 reported by Unit 42
Palo Alto Networks PAN-OS (specific affected versions not provided in available data)
highperson_alertThreat ActorOP-512 Targets IIS Servers with Custom Web Shell Framework
OP-512 is a previously unreported threat cluster assessed by ReliaQuest with moderate to high confidence to be linked to China. The actor demonstrates espionage-focused objectives, leveraging custom web shell frameworks to compromise Microsoft Intern…
criticalbug_reportVulnerabilityActive exploitation of RCE flaw in Everest Forms Pro WordPress plugin
Everest Forms Pro WordPress plugin versions up to 1.9.12. Approximately 4,000 active installations at risk.
highperson_alertThreat ActorFBI Warns of FIFA World Cup 2026 Fraud Campaign with Banking Malware
This is a cybercrime campaign leveraging the FIFA World Cup 2026 tournament as a lure, rather than a single named threat actor. The campaign involves multiple financially motivated threat actors exploiting public interest in the tournament to distrib…
criticalbug_reportVulnerabilityCisco SD-WAN Manager zero-day CVE-2026-20245 exploited for root access
Cisco Catalyst SD-WAN Manager, all versions (specific affected versions not disclosed). Unpatched zero-day vulnerability enabling root privilege escalation.
criticalbug_reportVulnerabilityCritical vulnerabilities in Gladinet Triofox require immediate patching
Gladinet Triofox file sharing and collaboration platform. Specific affected versions not disclosed in available data. All unpatched instances should be considered at risk.
highperson_alertThreat ActorPCPJack Hijacks 230+ Cloud Servers for Covert SMTP Relay Network
PCPJack is a threat actor focused on compromising cloud infrastructure to establish illicit email relay networks. The actor has demonstrated capability to breach business servers across major cloud service providers (AWS, Google Cloud, Microsoft Azur…
highbug_reportVulnerabilityCisco Unified Communications Manager high severity flaw with public PoC
Cisco Unified Communications Manager (CUCM). Specific affected versions not disclosed in alert. CVE identifier not yet assigned or published.
highperson_alertThreat ActorDriveSurge Distributes Malware via ClickFix and FakeUpdate Campaigns
DriveSurge is a threat actor conducting large-scale malware distribution operations. The actor leverages compromised website infrastructure at scale, utilizing thousands of sites to host and deliver malicious payloads.
highbug_reportVulnerabilityRed Hat npm packages compromised with Miasma credential stealer
Over 30 npm packages in the '@redhat-cloud-services' namespace on npm registry. Affects developers and CI/CD pipelines consuming these packages. Specific package names and versions not yet disclosed.
highpublicGeopoliticalSpanish Police Arrest Doxer Targeting National Cybersecurity Personnel
The arrest underscores Spain's efforts to protect critical cybersecurity infrastructure personnel from targeted information operations. Doxing of government cybersecurity staff represents a significant operational security risk, potentially enabling…
criticalbug_reportVulnerabilityMiasma supply chain attack compromises Red Hat npm packages
Red Hat Cloud Services npm packages (@redhat-cloud-services scope). Affects developers and CI/CD pipelines using these packages. Scope includes any environment where compromised packages were installed.
highbug_reportVulnerabilityMeta AI bot exploited to hijack high-profile Instagram accounts
Meta Instagram platform, specifically the AI-powered customer support bot used for account recovery. High-profile accounts including Obama White House and U.S. Space Force Chief Master Sergeant were compromised.
highbug_reportVulnerabilityMalware campaign infects 2,000 WordPress sites using Steam profiles for C2
Nearly 2,000 WordPress websites compromised. All WordPress versions potentially affected depending on initial infection vector (likely vulnerable plugins, themes, or weak credentials).
highbug_reportVulnerabilityHard-coded credentials in KS-SOMED software enable unauthorized access
KS-SOMED software (specific versions not disclosed). Hard-coded credentials embedded in application code allow unauthorized access to affected systems.
criticalbug_reportVulnerabilityWindows Netlogon RCE under active exploitation after patch release
Microsoft Windows Netlogon service, all versions prior to recent patch. Affects domain controllers and systems with Netlogon service enabled. Specific CVE and affected version details not provided in alert.
highperson_alertThreat ActorOperation Dragon Weave targets Czech and Taiwan entities with AdaptixC2
Operation Dragon Weave is a cyber espionage campaign linked to China-aligned threat actors. The campaign's motivation appears to be intelligence collection targeting government officials, researchers, academics, and professionals in the Czech Republi…
highbug_reportVulnerabilityMalicious npm package codexui-android steals OpenAI tokens, 29K downloads
npm package codexui-android (all versions). Targets developers using OpenAI Codex APIs. Affects organizations with Node.js/npm development environments where this package was installed.
criticalbug_reportVulnerabilityWP Maps Pro plugin exploited to create rogue admin accounts on WordPress
WP Maps Pro WordPress plugin (all versions prior to patch). Over 15,000 installations via Envato Market. Affects WordPress sites using this plugin for Google Maps integration.
highbug_reportVulnerabilityWP Maps Pro plugin under active attack via admin account creation flaw
WP Maps Pro WordPress plugin (version details not specified). Affects WordPress sites with the plugin installed. Vulnerability allows unauthenticated attackers to create administrator accounts.
highbug_reportVulnerabilityDutch authorities dismantle botnet controlling 17M infected devices
At least 17 million infected devices globally including computers, tablets, smartphones, and IoT devices. Over 200 command-and-control servers located in the Netherlands were seized.
criticalbug_reportVulnerabilityPAN-OS GlobalProtect auth bypass CVE-2026-0257 under active exploit
Palo Alto Networks PAN-OS GlobalProtect VPN. Specific affected versions not disclosed in provided data. Impacts corporate networks using GlobalProtect for remote access.