Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-21 · 02:09 UTC
articleTotal: 606 reports
Cyber Threat Daily Brief — July 21, 2026satellite_altDaily Brief
Threat Intel Brief·Daily Summary

Cyber Threat Daily Brief — July 21, 2026

Today's briefing: 3 critical and 16 high-severity threats. A total of 23 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.

3 Critical16 High23 analyses
schedule02:09 UTC
Read briefarrow_forward

Latest Reports

28 / 606 results
CIFSwitch: Linux kernel CIFS flaw enables local privilege escalationhighbug_reportVulnerability
bug_reportVulnerability

CIFSwitch: Linux kernel CIFS flaw enables local privilege escalation

Linux kernel CIFS implementation across multiple distributions. Specific affected kernel versions not yet disclosed. Requires local access to exploit.

Linux12:16 UTC
Palo Alto PAN-OS auth bypass (CVE-2026-0257) exploited in the wildhighbug_reportVulnerability
bug_reportVulnerability

Palo Alto PAN-OS auth bypass (CVE-2026-0257) exploited in the wild

Palo Alto Networks PAN-OS and Prisma Access. Specific affected versions not disclosed in provided data. Vulnerability impacts VPN authentication mechanisms.

CVE-2026-025704:41 UTC
33 malicious npm packages deployed in dependency confusion recon campaignhighbug_reportVulnerability
bug_reportVulnerability

33 malicious npm packages deployed in dependency confusion recon campaign

npm ecosystem; organizations using private npm packages with names vulnerable to dependency confusion attacks. Affects developer workstations, CI/CD pipelines, and build environments that may inadvertently install public packages instead of intended…

npm22:06 UTC
Threat actors abuse ChatGPT sharing to host fake OpenAI outage pageshighbug_reportVulnerability
bug_reportVulnerability

Threat actors abuse ChatGPT sharing to host fake OpenAI outage pages

OpenAI ChatGPT users globally. Threat actors exploit ChatGPT's legitimate content-sharing feature (chatgpt.com shared links) to host convincing phishing pages that impersonate OpenAI outage notifications and distribute malware posing as the ChatGPT d…

OpenAI16:21 UTC
California sues 23andMe over 2023 breach of genetic datahighpublicGeopolitical
publicGeopolitical

California sues 23andMe over 2023 breach of genetic data

The lawsuit against 23andMe highlights growing regulatory enforcement around biometric and genetic data protection in the United States, particularly within the healthcare and biotechnology sectors.

23andMe16:08 UTC
ChatGPT Markdown renderer vulnerable to prompt injection and phishinghighbug_reportVulnerability
bug_reportVulnerability

ChatGPT Markdown renderer vulnerable to prompt injection and phishing

OpenAI ChatGPT web summary response renderer. All users interacting with ChatGPT's web interface that processes Markdown links and images are potentially affected. Specific version details not disclosed.

OpenAI16:07 UTC
Microsoft May 2026 Patch Tuesday: 118 vulnerabilities, 16 criticalcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft May 2026 Patch Tuesday: 118 vulnerabilities, 16 critical

Microsoft products and services across the ecosystem. 118 total vulnerabilities: 16 critical severity, 102 important severity. Specific affected products and CVE identifiers not yet detailed in available information.

Microsoft14:06 UTC
Oracle releases critical security patches for multiple productshighbug_reportVulnerability
bug_reportVulnerability

Oracle releases critical security patches for multiple products

Multiple Oracle products affected by high-severity vulnerabilities. Specific product names, versions, and CVE identifiers not provided in CERT.BE advisory. Likely part of Oracle's quarterly Critical Patch Update (CPU).

Oracle12:43 UTC
CVE-2026-39987 in Marimo actively exploited for cloud credential thefthighbug_reportVulnerability
bug_reportVulnerability

CVE-2026-39987 in Marimo actively exploited for cloud credential theft

Marimo notebook platform (specific versions not disclosed). Affects internet-exposed Marimo notebook instances vulnerable to CVE-2026-39987.

CVE-2026-3998712:39 UTC
Dutch authorities disrupt 17M-device botnet, seize 200+ servershighbug_reportVulnerability
bug_reportVulnerability

Dutch authorities disrupt 17M-device botnet, seize 200+ servers

Approximately 17 million infected devices globally; over 200 servers seized from a Dutch hosting provider. Specific botnet malware family and affected device types not disclosed.

BleepingComputer12:26 UTC
GREYVIBE: Russian-linked APT targeting Ukraine since August 2025highperson_alertThreat Actor
person_alertThreat Actor

GREYVIBE: Russian-linked APT targeting Ukraine since August 2025

GREYVIBE is a previously undocumented threat actor attributed by WithSecure as Russian-linked, assessed to operate in support of Kremlin state interests. The group is characterized as Russian-speaking and operates within Russian time zones.

The Hacker News09:31 UTC
US national sentenced for selling 7M elderly records to Jamaican fraudstershighpublicGeopolitical
publicGeopolitical

US national sentenced for selling 7M elderly records to Jamaican fraudsters

This case illustrates the transnational nature of cybercrime and data exploitation, where domestic actors facilitate cross-border fraud schemes targeting vulnerable populations.

BleepingComputer09:07 UTC
Malicious NuGet package "Sicoob.Sdk" steals banking credentialshighbug_reportVulnerability
bug_reportVulnerability

Malicious NuGet package "Sicoob.Sdk" steals banking credentials

NuGet package "Sicoob.Sdk" versions 2.0.0 through 2.0.4. Targets developers integrating with Sicoob (Brazilian cooperative banking system). Affects .NET development environments where the malicious package was installed.

Sicoob07:11 UTC
ShinyHunters Breaches Charter Communications, Exfiltrates 4.9M Recordshighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Breaches Charter Communications, Exfiltrates 4.9M Records

ShinyHunters is a financially motivated cybercrime group known for large-scale data breaches and extortion operations targeting enterprises. The group specializes in exfiltrating sensitive customer data from corporate databases and either selling the…

Charter Communications06:29 UTC
Hard-coded secret in Trac PDBM enables unauthorized accesshighbug_reportVulnerability
bug_reportVulnerability

Hard-coded secret in Trac PDBM enables unauthorized access

Trac d.o.o. Process Database Manager (PDBM) - specific affected versions not disclosed. Vulnerability involves hard-coded cryptographic secret embedded in executable binary.

CVE-2026-2560005:16 UTC
Kimsuky Targets South Korean Military and Corporate Sectorshighperson_alertThreat Actor
person_alertThreat Actor

Kimsuky Targets South Korean Military and Corporate Sectors

Kimsuky (also tracked as Velvet Chollima, Black Banshee, Emerald Sleet, and THALLIUM) is a North Korean state-sponsored advanced persistent threat group.

The Hacker News03:57 UTC
Mini Shai-Hulud: Typosquatted npm Packages Target Developer Credentialshighperson_alertThreat Actor
person_alertThreat Actor

Mini Shai-Hulud: Typosquatted npm Packages Target Developer Credentials

Mini Shai-Hulud is a threat actor campaign focused on compromising software development environments through supply chain attacks. The actor leverages typosquatting techniques against the npm package ecosystem to distribute malicious packages that ma…

npm01:04 UTC
GreyVibe Targets Ukraine with AI-Generated Lures and Custom Malwarehighperson_alertThreat Actor
person_alertThreat Actor

GreyVibe Targets Ukraine with AI-Generated Lures and Custom Malware

GreyVibe is a threat cluster assessed with moderate confidence to be linked to Russian interests, based on targeting patterns and geopolitical alignment.

BleepingComputer20:24 UTC
BTMOB Android RAT offered as MaaS with custom phishing builderhighbug_reportVulnerability
bug_reportVulnerability

BTMOB Android RAT offered as MaaS with custom phishing builder

Android devices targeted by BTMOB remote access trojan. No specific vendor or version restrictions; affects users who install malicious APKs distributed through phishing campaigns.

BleepingComputer19:10 UTC
FBI warns of FIFA-impersonating fraud sites targeting 2026 World Cuphighperson_alertThreat Actor
person_alertThreat Actor

FBI warns of FIFA-impersonating fraud sites targeting 2026 World Cup

Unknown fraud operators are conducting financially motivated cybercrime campaigns targeting fans and consumers interested in the 2026 FIFA World Cup. These actors leverage social engineering and brand impersonation tactics to establish fraudulent web…

BleepingComputer17:08 UTC
Fortinet FortiClient EMS auth bypass exploited to deploy EKZ malwarehighbug_reportVulnerability
bug_reportVulnerability

Fortinet FortiClient EMS auth bypass exploited to deploy EKZ malware

Fortinet FortiClient Enterprise Management Server (EMS). Specific vulnerable versions not provided in available data. Authentication bypass vulnerability CVE-2026-35616 allows unauthorized access.

CVE-2026-3561615:25 UTC
Critical RCE in Gogs Git service allows authenticated users to execute codecriticalbug_reportVulnerability
bug_reportVulnerability

Critical RCE in Gogs Git service allows authenticated users to execute code

Gogs self-hosted Git service. Specific affected versions not disclosed. All authenticated users can exploit the vulnerability.

Gogs15:24 UTC
Arctic Wolf exploits FortiClient EMS flaw for credential thefthighperson_alertThreat Actor
person_alertThreat Actor

Arctic Wolf exploits FortiClient EMS flaw for credential theft

Arctic Wolf is a threat actor exploiting a critical, patched vulnerability in FortiClient Endpoint Management Server (EMS) to deploy credential-stealing malware.

Fortinet13:26 UTC
Storm-2697 Deploys The Gentlemen Go-Based Ransomware with Worm Capabilitieshighperson_alertThreat Actor
person_alertThreat Actor

Storm-2697 Deploys The Gentlemen Go-Based Ransomware with Worm Capabilities

Storm-2697 is a threat actor tracked by Microsoft Threat Intelligence that operates as a ransomware affiliate group. The actor deploys The Gentlemen ransomware, a sophisticated Go-based encryption tool, suggesting technical proficiency in modern prog…

Microsoft13:00 UTC
Starlette and FastAPI authentication bypass flaw affects millions of serverscriticalbug_reportVulnerability
bug_reportVulnerability

Starlette and FastAPI authentication bypass flaw affects millions of servers

Starlette web framework and dependent frameworks including FastAPI. Specific vulnerable versions not provided in source data. Affects authentication mechanisms in applications built with these frameworks.

Starlette12:32 UTC
Unpatched RCE zero-day in Gogs Git service actively threatens exposed instancescriticalbug_reportVulnerability
bug_reportVulnerability

Unpatched RCE zero-day in Gogs Git service actively threatens exposed instances

Gogs self-hosted Git service, all Internet-facing instances. Specific affected versions not disclosed. No patch currently available.

Gogs12:25 UTC
Critical RCE vulnerability in LiquidJS requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical RCE vulnerability in LiquidJS requires immediate patching

LiquidJS templating engine, all versions prior to patched release. Specific vulnerable version range not provided in available data.

LiquidJS12:20 UTC
Dell Container Storage Modules info disclosure enables data exfiltrationcriticalbug_reportVulnerability
bug_reportVulnerability

Dell Container Storage Modules info disclosure enables data exfiltration

Dell Container Storage Modules (specific versions not disclosed in summary). Vulnerability allows information disclosure that can lead to data exfiltration and lateral movement within containerized environments.

Dell11:55 UTC