Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-21 · 02:09 UTC
articleTotal: 606 reports
Cyber Threat Daily Brief — July 21, 2026satellite_altDaily Brief
Threat Intel Brief·Daily Summary

Cyber Threat Daily Brief — July 21, 2026

Today's briefing: 3 critical and 16 high-severity threats. A total of 23 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.

3 Critical16 High23 analyses
schedule02:09 UTC
Read briefarrow_forward

Latest Reports

26 / 606 results
npm supply chain attack: 50+ packages deliver IronWorm stealer and rootkitcriticalbug_reportVulnerability
bug_reportVulnerability

npm supply chain attack: 50+ packages deliver IronWorm stealer and rootkit

npm ecosystem: over 50 compromised legitimate packages. Affects developers using npm for JavaScript/Node.js projects. IronWorm targets developer credentials and source code with eBPF kernel-level persistence.

npm16:05 UTC
Prompt injection in Claude Code GitHub Action exposes workflow secretshighbug_reportVulnerability
bug_reportVulnerability

Prompt injection in Claude Code GitHub Action exposes workflow secrets

Anthropic's Claude Code GitHub Action (prior to mitigation). Affects GitHub workflows using the action with access to repository secrets. Vulnerability exploitable when action processes untrusted input from pull requests or external sources.

Anthropic14:46 UTC
Asin Android spyware targets Arabic-speaking users via fake appshighbug_reportVulnerability
bug_reportVulnerability

Asin Android spyware targets Arabic-speaking users via fake apps

Android devices used by Arabic-speaking populations. Malware distributed through fake applications impersonating news sources, PDF utilities, and war-related content. Active campaigns identified since early 2025.

Android12:53 UTC
900+ US fuel tank monitoring systems exposed online, vulnerable to attackhighbug_reportVulnerability
bug_reportVulnerability

900+ US fuel tank monitoring systems exposed online, vulnerable to attack

Over 900 automatic tank gauge (ATG) systems in the United States used to monitor fuel and chemical storage tanks in critical infrastructure. Specific vendors and product versions not disclosed.

BleepingComputer12:50 UTC
Active exploitation of PAN-OS CVE-2026-0257 reported by Unit 42highbug_reportVulnerability
bug_reportVulnerability

Active exploitation of PAN-OS CVE-2026-0257 reported by Unit 42

Palo Alto Networks PAN-OS (specific affected versions not provided in available data)

CVE-2026-025712:05 UTC
OP-512 Targets IIS Servers with Custom Web Shell Frameworkhighperson_alertThreat Actor
person_alertThreat Actor

OP-512 Targets IIS Servers with Custom Web Shell Framework

OP-512 is a previously unreported threat cluster assessed by ReliaQuest with moderate to high confidence to be linked to China. The actor demonstrates espionage-focused objectives, leveraging custom web shell frameworks to compromise Microsoft Intern…

Microsoft10:33 UTC
Active exploitation of RCE flaw in Everest Forms Pro WordPress plugincriticalbug_reportVulnerability
bug_reportVulnerability

Active exploitation of RCE flaw in Everest Forms Pro WordPress plugin

Everest Forms Pro WordPress plugin versions up to 1.9.12. Approximately 4,000 active installations at risk.

CVE-2026-330006:38 UTC
FBI Warns of FIFA World Cup 2026 Fraud Campaign with Banking Malwarehighperson_alertThreat Actor
person_alertThreat Actor

FBI Warns of FIFA World Cup 2026 Fraud Campaign with Banking Malware

This is a cybercrime campaign leveraging the FIFA World Cup 2026 tournament as a lure, rather than a single named threat actor. The campaign involves multiple financially motivated threat actors exploiting public interest in the tournament to distrib…

The Hacker News05:01 UTC
Cisco SD-WAN Manager zero-day CVE-2026-20245 exploited for root accesscriticalbug_reportVulnerability
bug_reportVulnerability

Cisco SD-WAN Manager zero-day CVE-2026-20245 exploited for root access

Cisco Catalyst SD-WAN Manager, all versions (specific affected versions not disclosed). Unpatched zero-day vulnerability enabling root privilege escalation.

CVE-2026-2024504:24 UTC
Critical vulnerabilities in Gladinet Triofox require immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical vulnerabilities in Gladinet Triofox require immediate patching

Gladinet Triofox file sharing and collaboration platform. Specific affected versions not disclosed in available data. All unpatched instances should be considered at risk.

Gladinet03:54 UTC
PCPJack Hijacks 230+ Cloud Servers for Covert SMTP Relay Networkhighperson_alertThreat Actor
person_alertThreat Actor

PCPJack Hijacks 230+ Cloud Servers for Covert SMTP Relay Network

PCPJack is a threat actor focused on compromising cloud infrastructure to establish illicit email relay networks. The actor has demonstrated capability to breach business servers across major cloud service providers (AWS, Google Cloud, Microsoft Azur…

Amazon Web Services03:34 UTC
Cisco Unified Communications Manager high severity flaw with public PoChighbug_reportVulnerability
bug_reportVulnerability

Cisco Unified Communications Manager high severity flaw with public PoC

Cisco Unified Communications Manager (CUCM). Specific affected versions not disclosed in alert. CVE identifier not yet assigned or published.

Cisco03:28 UTC
DriveSurge Distributes Malware via ClickFix and FakeUpdate Campaignshighperson_alertThreat Actor
person_alertThreat Actor

DriveSurge Distributes Malware via ClickFix and FakeUpdate Campaigns

DriveSurge is a threat actor conducting large-scale malware distribution operations. The actor leverages compromised website infrastructure at scale, utilizing thousands of sites to host and deliver malicious payloads.

BleepingComputer20:14 UTC
Red Hat npm packages compromised with Miasma credential stealerhighbug_reportVulnerability
bug_reportVulnerability

Red Hat npm packages compromised with Miasma credential stealer

Over 30 npm packages in the '@redhat-cloud-services' namespace on npm registry. Affects developers and CI/CD pipelines consuming these packages. Specific package names and versions not yet disclosed.

Red Hat19:38 UTC
Spanish Police Arrest Doxer Targeting National Cybersecurity PersonnelhighpublicGeopolitical
publicGeopolitical

Spanish Police Arrest Doxer Targeting National Cybersecurity Personnel

The arrest underscores Spain's efforts to protect critical cybersecurity infrastructure personnel from targeted information operations. Doxing of government cybersecurity staff represents a significant operational security risk, potentially enabling…

BleepingComputer19:28 UTC
Miasma supply chain attack compromises Red Hat npm packagescriticalbug_reportVulnerability
bug_reportVulnerability

Miasma supply chain attack compromises Red Hat npm packages

Red Hat Cloud Services npm packages (@redhat-cloud-services scope). Affects developers and CI/CD pipelines using these packages. Scope includes any environment where compromised packages were installed.

Red Hat15:40 UTC
Meta AI bot exploited to hijack high-profile Instagram accountshighbug_reportVulnerability
bug_reportVulnerability

Meta AI bot exploited to hijack high-profile Instagram accounts

Meta Instagram platform, specifically the AI-powered customer support bot used for account recovery. High-profile accounts including Obama White House and U.S. Space Force Chief Master Sergeant were compromised.

Meta15:32 UTC
Malware campaign infects 2,000 WordPress sites using Steam profiles for C2highbug_reportVulnerability
bug_reportVulnerability

Malware campaign infects 2,000 WordPress sites using Steam profiles for C2

Nearly 2,000 WordPress websites compromised. All WordPress versions potentially affected depending on initial infection vector (likely vulnerable plugins, themes, or weak credentials).

WordPress15:04 UTC
Hard-coded credentials in KS-SOMED software enable unauthorized accesshighbug_reportVulnerability
bug_reportVulnerability

Hard-coded credentials in KS-SOMED software enable unauthorized access

KS-SOMED software (specific versions not disclosed). Hard-coded credentials embedded in application code allow unauthorized access to affected systems.

CVE-2026-4225110:55 UTC
Windows Netlogon RCE under active exploitation after patch releasecriticalbug_reportVulnerability
bug_reportVulnerability

Windows Netlogon RCE under active exploitation after patch release

Microsoft Windows Netlogon service, all versions prior to recent patch. Affects domain controllers and systems with Netlogon service enabled. Specific CVE and affected version details not provided in alert.

Microsoft10:30 UTC
Operation Dragon Weave targets Czech and Taiwan entities with AdaptixC2highperson_alertThreat Actor
person_alertThreat Actor

Operation Dragon Weave targets Czech and Taiwan entities with AdaptixC2

Operation Dragon Weave is a cyber espionage campaign linked to China-aligned threat actors. The campaign's motivation appears to be intelligence collection targeting government officials, researchers, academics, and professionals in the Czech Republi…

The Hacker News09:54 UTC
Malicious npm package codexui-android steals OpenAI tokens, 29K downloadshighbug_reportVulnerability
bug_reportVulnerability

Malicious npm package codexui-android steals OpenAI tokens, 29K downloads

npm package codexui-android (all versions). Targets developers using OpenAI Codex APIs. Affects organizations with Node.js/npm development environments where this package was installed.

OpenAI07:31 UTC
WP Maps Pro plugin exploited to create rogue admin accounts on WordPresscriticalbug_reportVulnerability
bug_reportVulnerability

WP Maps Pro plugin exploited to create rogue admin accounts on WordPress

WP Maps Pro WordPress plugin (all versions prior to patch). Over 15,000 installations via Envato Market. Affects WordPress sites using this plugin for Google Maps integration.

WP Maps Pro06:45 UTC
WP Maps Pro plugin under active attack via admin account creation flawhighbug_reportVulnerability
bug_reportVulnerability

WP Maps Pro plugin under active attack via admin account creation flaw

WP Maps Pro WordPress plugin (version details not specified). Affects WordPress sites with the plugin installed. Vulnerability allows unauthenticated attackers to create administrator accounts.

WP Maps Pro12:06 UTC
Dutch authorities dismantle botnet controlling 17M infected deviceshighbug_reportVulnerability
bug_reportVulnerability

Dutch authorities dismantle botnet controlling 17M infected devices

At least 17 million infected devices globally including computers, tablets, smartphones, and IoT devices. Over 200 command-and-control servers located in the Netherlands were seized.

The Hacker News10:22 UTC
PAN-OS GlobalProtect auth bypass CVE-2026-0257 under active exploitcriticalbug_reportVulnerability
bug_reportVulnerability

PAN-OS GlobalProtect auth bypass CVE-2026-0257 under active exploit

Palo Alto Networks PAN-OS GlobalProtect VPN. Specific affected versions not disclosed in provided data. Impacts corporate networks using GlobalProtect for remote access.

CVE-2026-025716:02 UTC