Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports
Cyber Threat Daily Brief — September 4, 2026satellite_altDaily Brief
Threat Intel Brief·Daily Summary

Cyber Threat Daily Brief — September 4, 2026

Today's briefing: 14 critical and 22 high-severity threats. A total of 47 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.

14 Critical22 High47 analyses
schedule02:17 UTC
Read briefarrow_forward

Latest Reports

29 / 1107 results
Russian Espionage Group Exploited Zimbra Zero-Day for Email Theftcriticalperson_alertThreat Actor
person_alertThreat Actor

Russian Espionage Group Exploited Zimbra Zero-Day for Email Theft

A Russian state-sponsored espionage group conducted a sustained campaign exploiting a zero-day vulnerability in Zimbra's webmail client. The actor, tracked as TA488 by Proofpoint and CL-STA-1114 by Unit 42, operated undetected for at least five month…

Zimbra23 Jul · 16:36 UTC
Laundry Bear exploits Zimbra XSS zero-day for email thefthighperson_alertThreat Actor
person_alertThreat Actor

Laundry Bear exploits Zimbra XSS zero-day for email theft

Laundry Bear (also tracked as Void Blizzard by Microsoft) is a Russian state-sponsored APT group first publicly attributed by Dutch intelligence agencies in May 2025 following their 2024 compromise of the Dutch National Police.

Zimbra23 Jul · 14:49 UTC
UAC-0099 abuses Notepad++ plugin loading to deploy LunchPoke malwarehighbug_reportVulnerability
bug_reportVulnerability

UAC-0099 abuses Notepad++ plugin loading to deploy LunchPoke malware

Organizations in Ukraine using Notepad++ 8.8.3. The attack does not exploit a vulnerability in Notepad++; it abuses legitimate plugin-loading functionality to deploy LunchPoke, BurnyBear, and MatchBoil V2 malware loaders via social engineering (malic…

Notepad++23 Jul · 14:32 UTC
Progress Telerik UI for AJAX RCE vulnerability requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Progress Telerik UI for AJAX RCE vulnerability requires immediate patching

Progress Telerik UI for AJAX - specific affected versions not disclosed in available information. Vulnerability enables remote code execution.

Progress23 Jul · 13:51 UTC
Microsoft 365 outage disrupts cloud services across North AmericahighpublicGeopolitical
publicGeopolitical

Microsoft 365 outage disrupts cloud services across North America

The incident represents a technical service disruption affecting critical cloud infrastructure rather than a geopolitical cyber event. Microsoft 365's position as backbone infrastructure for government, defense, and commercial operations in North Ame…

Microsoft23 Jul · 13:34 UTC
Check Point privilege escalation flaws under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Check Point privilege escalation flaws under active exploitation

Check Point products (specific versions not disclosed in available data). Three privilege escalation vulnerabilities identified, including one actively exploited flaw enabling full admin authentication bypass.

Check Point23 Jul · 13:19 UTC
Russian cyberespionage campaign targets Zimbra via JavaScript injectionhighperson_alertThreat Actor
person_alertThreat Actor

Russian cyberespionage campaign targets Zimbra via JavaScript injection

This campaign is attributed by Unit 42 to Russian cyberespionage interests. The actor's motivation centers on intelligence gathering through compromise of email infrastructure.

Zimbra23 Jul · 12:10 UTC
Claude Cowork sandbox escape lets AI agent access macOS host fileshighbug_reportVulnerability
bug_reportVulnerability

Claude Cowork sandbox escape lets AI agent access macOS host files

Anthropic Claude Cowork macOS desktop app running local sessions. Approximately 500,000 macOS users affected prior to mitigation. Users who continue to run local execution (not cloud) remain vulnerable.

Anthropic23 Jul · 11:27 UTC
Chaos Ransomware Group Deploys msaRAT Rust Implant via Headless Browsershighperson_alertThreat Actor
person_alertThreat Actor

Chaos Ransomware Group Deploys msaRAT Rust Implant via Headless Browsers

Chaos is a ransomware group that operates through spam floods, vishing campaigns, Quick Assist abuse, and RMM tools for initial access and persistence. The group deploys custom tooling including the msaRAT Rust-based implant as a pre-ransomware stage…

Microsoft23 Jul · 11:11 UTC
JadeProx Deploys TriBack Loader Against Asian, Latin American Targetshighperson_alertThreat Actor
person_alertThreat Actor

JadeProx Deploys TriBack Loader Against Asian, Latin American Targets

JadeProx is a China-nexus threat actor tracked by Group-IB, discovered through an exposed Alibaba Cloud server in Singapore in mid-April 2026. The actor targets government, healthcare, and education organizations across Asia and Latin America.

Alibaba Cloud23 Jul · 10:20 UTC
Laundry Bear: Russian APT deploys zero-click phishing via Zimbra exploithighperson_alertThreat Actor
person_alertThreat Actor

Laundry Bear: Russian APT deploys zero-click phishing via Zimbra exploit

Laundry Bear is an advanced persistent threat (APT) group attributed to Russian state support, specializing in covert email data acquisition. The group conducts espionage operations targeting Western organizations and NATO members.

NCSC UK23 Jul · 10:00 UTC
Linux XFS race condition CVE-2026-64600 enables local root escalationhighbug_reportVulnerability
bug_reportVulnerability

Linux XFS race condition CVE-2026-64600 enables local root escalation

Linux kernel v4.11 and later (since February 2017) with XFS filesystem and reflink enabled (default on RHEL, Oracle Linux, Amazon Linux, Fedora, CentOS Stream, Rocky Linux, AlmaLinux, CloudLinux).

CVE-2026-6460023 Jul · 09:40 UTC
GitHub Actions Abused to Scan and Exploit cPanel/WHM Servershighperson_alertThreat Actor
person_alertThreat Actor

GitHub Actions Abused to Scan and Exploit cPanel/WHM Servers

The threat actor behind this campaign remains unattributed. The operation demonstrates sophisticated understanding of GitHub Actions infrastructure and supply chain attack vectors.

GitHub23 Jul · 09:28 UTC
Chaos ransomware gang deploys msaRAT backdoor via browser hijackinghighperson_alertThreat Actor
person_alertThreat Actor

Chaos ransomware gang deploys msaRAT backdoor via browser hijacking

Chaos is a ransomware gang that emerged in early 2025, distinct from the earlier same-named ransomware family active since 2021. The group has been linked to Iranian state-backed threat actor MuddyWater, who reportedly leveraged Chaos ransomware to d…

Google23 Jul · 07:59 UTC
FortiBleed campaign targets Fortinet globally; Finland unaffectedhighbug_reportVulnerability
bug_reportVulnerability

FortiBleed campaign targets Fortinet globally; Finland unaffected

Fortinet products (specific models and versions not disclosed). Campaign active globally as of June 2026, Finland not impacted to date.

Fortinet23 Jul · 06:15 UTC
Check Point SmartConsole auth bypass zero-day exploited in the wildcriticalbug_reportVulnerability
bug_reportVulnerability

Check Point SmartConsole auth bypass zero-day exploited in the wild

Check Point SmartConsole (GUI admin panel for Security Management Server and Multi-Domain Security Management Server). CVE-2026-16232. Vulnerable configurations: Management Server IP exposed to Internet without Trusted Client IP restrictions.

Check Point Software23 Jul · 06:13 UTC
RefluXFS kernel flaw grants local root on default RHEL, Fedora, Amazon Linuxcriticalbug_reportVulnerability
bug_reportVulnerability

RefluXFS kernel flaw grants local root on default RHEL, Fedora, Amazon Linux

Linux kernel 4.11+ (2017–July 2026) on systems with XFS filesystems created with reflink=1. Default installations of RHEL/CentOS Stream/Oracle/Rocky/AlmaLinux/CloudLinux 8/9/10, Fedora Server 31+, Amazon Linux 2023, and Amazon Linux 2 (Dec 2022+) are…

CVE-2026-6460023 Jul · 06:04 UTC
Check Point SmartConsole auth bypass (CVE-2026-16232) exploited in wildcriticalbug_reportVulnerability
bug_reportVulnerability

Check Point SmartConsole auth bypass (CVE-2026-16232) exploited in wild

Check Point Security Management and Multi-Domain Management (MDSM) products: R77.30, R80, R80.10, R80.20, R80.30, R81, R81.10, R81.20, R82, R82.10. Affects SmartConsole login process when Management Server is exposed to internet without IP restrictio…

CVE-2026-1623223 Jul · 04:34 UTC
South Korea discloses 10-month breach of diplomatic training platformhighpublicGeopolitical
publicGeopolitical

South Korea discloses 10-month breach of diplomatic training platform

The compromise of South Korea's National Diplomatic Academy represents a significant intelligence collection operation targeting a key U.S. ally in Northeast Asia.

BleepingComputer22 Jul · 18:06 UTC
Ubuntu snap-confine race condition grants local users root accesshighbug_reportVulnerability
bug_reportVulnerability

Ubuntu snap-confine race condition grants local users root access

Ubuntu Desktop 24.04, 25.10, and 26.04 (default installations). Vulnerable component: snap-confine in snapd. Affects systems using the set-capabilities model for privilege enforcement.

CVE-2026-893322 Jul · 16:07 UTC
Everest Gang Demands $12.3M from Stadler Rail After Supplier Breachhighperson_alertThreat Actor
person_alertThreat Actor

Everest Gang Demands $12.3M from Stadler Rail After Supplier Breach

Everest is a ransomware operation that emerged in 2020, initially deploying file encryption but later pivoted to pure data theft extortion tactics. The group threatens to leak stolen data unless ransom demands are met.

Stadler Rail22 Jul · 14:59 UTC
WordPress Core RCE flaws CVE-2026-63030, CVE-2026-60137 under active exploitcriticalbug_reportVulnerability
bug_reportVulnerability

WordPress Core RCE flaws CVE-2026-63030, CVE-2026-60137 under active exploit

WordPress Core (specific versions not disclosed in advisory). Two remote code execution vulnerabilities (CVE-2026-63030, CVE-2026-60137) affecting the core platform.

CVE-2026-6013722 Jul · 14:09 UTC
Adobe Acrobat Chrome extension flaw allows WhatsApp data theft via UXSShighbug_reportVulnerability
bug_reportVulnerability

Adobe Acrobat Chrome extension flaw allows WhatsApp data theft via UXSS

Adobe Acrobat Chrome extension (ID: efaidnbmnnnibpcajpcglclefindmkaj) versions up to and including 26.5.2.2. Affects 314+ million users. Exploitation impacts any web application data accessible in victim's browser, demonstrated against WhatsApp Web.

CVE-2026-4829422 Jul · 13:01 UTC
Microsoft July 2026 Patch Tuesday: 569 vulnerabilities, 56 criticalcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft July 2026 Patch Tuesday: 569 vulnerabilities, 56 critical

Microsoft product portfolio (specific products and versions not disclosed in available data). 569 total vulnerabilities patched, including 56 rated critical severity.

Microsoft22 Jul · 12:32 UTC
Adobe Acrobat Chrome extension flaw exposed WhatsApp Web chatshighbug_reportVulnerability
bug_reportVulnerability

Adobe Acrobat Chrome extension flaw exposed WhatsApp Web chats

Adobe Acrobat extension for Chrome versions 26.5.2.1 and below. Affects approximately 329 million browser installations. Exploitation requires victim to visit attacker-controlled webpage while extension is installed and WhatsApp Web is in use.

Adobe22 Jul · 11:22 UTC
Windmill path traversal flaw exploited to read server files unauthenticatedhighbug_reportVulnerability
bug_reportVulnerability

Windmill path traversal flaw exploited to read server files unauthenticated

Windmill open-source developer platform versions prior to 1.603.3. The vulnerability affects the "get_log_file" endpoint (/api/w/{workspace}/jobs_u/get_log_file/{filename}). Approximately 170 vulnerable systems identified across 24 countries.

CVE-2026-2905922 Jul · 10:36 UTC
CISA orders urgent patching of exploited Langflow RCE (CVE-2026-0770)criticalbug_reportVulnerability
bug_reportVulnerability

CISA orders urgent patching of exploited Langflow RCE (CVE-2026-0770)

Langflow visual framework for building AI agents. All unpatched versions vulnerable. Affects unauthenticated remote attackers who can reach the /api/v1/validate/code endpoint. Federal agencies must patch by July 25, 2026.

Langflow22 Jul · 09:43 UTC
Microsoft SharePoint RCE flaws actively exploited; immediate patching requiredcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft SharePoint RCE flaws actively exploited; immediate patching required

Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. Five critical vulnerabilities: CVE-2026-50522 (CVSS 9.8, deserialization RCE), CVE-2026-58644 (CVSS 9.8, unauthenticated RCE), CVE-2026-5…

Microsoft22 Jul · 08:39 UTC
Kratos Phishing Kit Dismantled After Stealing Microsoft 365 Sessionshighperson_alertThreat Actor
person_alertThreat Actor

Kratos Phishing Kit Dismantled After Stealing Microsoft 365 Sessions

The Kratos operator is an Indonesian individual arrested by local authorities for allegedly developing and operating the Kratos phishing-as-a-service (PhaaS) platform.

Microsoft22 Jul · 04:38 UTC