Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
satellite_altDaily BriefCyber Threat Daily Brief — July 21, 2026
Today's briefing: 3 critical and 16 high-severity threats. A total of 23 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.
Latest Reports
28 / 606 results
highbug_reportVulnerabilityCIFSwitch: Linux kernel CIFS flaw enables local privilege escalation
Linux kernel CIFS implementation across multiple distributions. Specific affected kernel versions not yet disclosed. Requires local access to exploit.
highbug_reportVulnerabilityPalo Alto PAN-OS auth bypass (CVE-2026-0257) exploited in the wild
Palo Alto Networks PAN-OS and Prisma Access. Specific affected versions not disclosed in provided data. Vulnerability impacts VPN authentication mechanisms.
highbug_reportVulnerability33 malicious npm packages deployed in dependency confusion recon campaign
npm ecosystem; organizations using private npm packages with names vulnerable to dependency confusion attacks. Affects developer workstations, CI/CD pipelines, and build environments that may inadvertently install public packages instead of intended…
highbug_reportVulnerabilityThreat actors abuse ChatGPT sharing to host fake OpenAI outage pages
OpenAI ChatGPT users globally. Threat actors exploit ChatGPT's legitimate content-sharing feature (chatgpt.com shared links) to host convincing phishing pages that impersonate OpenAI outage notifications and distribute malware posing as the ChatGPT d…
highpublicGeopoliticalCalifornia sues 23andMe over 2023 breach of genetic data
The lawsuit against 23andMe highlights growing regulatory enforcement around biometric and genetic data protection in the United States, particularly within the healthcare and biotechnology sectors.
highbug_reportVulnerabilityChatGPT Markdown renderer vulnerable to prompt injection and phishing
OpenAI ChatGPT web summary response renderer. All users interacting with ChatGPT's web interface that processes Markdown links and images are potentially affected. Specific version details not disclosed.
criticalbug_reportVulnerabilityMicrosoft May 2026 Patch Tuesday: 118 vulnerabilities, 16 critical
Microsoft products and services across the ecosystem. 118 total vulnerabilities: 16 critical severity, 102 important severity. Specific affected products and CVE identifiers not yet detailed in available information.
highbug_reportVulnerabilityOracle releases critical security patches for multiple products
Multiple Oracle products affected by high-severity vulnerabilities. Specific product names, versions, and CVE identifiers not provided in CERT.BE advisory. Likely part of Oracle's quarterly Critical Patch Update (CPU).
highbug_reportVulnerabilityCVE-2026-39987 in Marimo actively exploited for cloud credential theft
Marimo notebook platform (specific versions not disclosed). Affects internet-exposed Marimo notebook instances vulnerable to CVE-2026-39987.
highbug_reportVulnerabilityDutch authorities disrupt 17M-device botnet, seize 200+ servers
Approximately 17 million infected devices globally; over 200 servers seized from a Dutch hosting provider. Specific botnet malware family and affected device types not disclosed.
highperson_alertThreat ActorGREYVIBE: Russian-linked APT targeting Ukraine since August 2025
GREYVIBE is a previously undocumented threat actor attributed by WithSecure as Russian-linked, assessed to operate in support of Kremlin state interests. The group is characterized as Russian-speaking and operates within Russian time zones.
highpublicGeopoliticalUS national sentenced for selling 7M elderly records to Jamaican fraudsters
This case illustrates the transnational nature of cybercrime and data exploitation, where domestic actors facilitate cross-border fraud schemes targeting vulnerable populations.
highbug_reportVulnerabilityMalicious NuGet package "Sicoob.Sdk" steals banking credentials
NuGet package "Sicoob.Sdk" versions 2.0.0 through 2.0.4. Targets developers integrating with Sicoob (Brazilian cooperative banking system). Affects .NET development environments where the malicious package was installed.
highperson_alertThreat ActorShinyHunters Breaches Charter Communications, Exfiltrates 4.9M Records
ShinyHunters is a financially motivated cybercrime group known for large-scale data breaches and extortion operations targeting enterprises. The group specializes in exfiltrating sensitive customer data from corporate databases and either selling the…
highbug_reportVulnerabilityHard-coded secret in Trac PDBM enables unauthorized access
Trac d.o.o. Process Database Manager (PDBM) - specific affected versions not disclosed. Vulnerability involves hard-coded cryptographic secret embedded in executable binary.
highperson_alertThreat ActorKimsuky Targets South Korean Military and Corporate Sectors
Kimsuky (also tracked as Velvet Chollima, Black Banshee, Emerald Sleet, and THALLIUM) is a North Korean state-sponsored advanced persistent threat group.
highperson_alertThreat ActorMini Shai-Hulud: Typosquatted npm Packages Target Developer Credentials
Mini Shai-Hulud is a threat actor campaign focused on compromising software development environments through supply chain attacks. The actor leverages typosquatting techniques against the npm package ecosystem to distribute malicious packages that ma…
highperson_alertThreat ActorGreyVibe Targets Ukraine with AI-Generated Lures and Custom Malware
GreyVibe is a threat cluster assessed with moderate confidence to be linked to Russian interests, based on targeting patterns and geopolitical alignment.
highbug_reportVulnerabilityBTMOB Android RAT offered as MaaS with custom phishing builder
Android devices targeted by BTMOB remote access trojan. No specific vendor or version restrictions; affects users who install malicious APKs distributed through phishing campaigns.
highperson_alertThreat ActorFBI warns of FIFA-impersonating fraud sites targeting 2026 World Cup
Unknown fraud operators are conducting financially motivated cybercrime campaigns targeting fans and consumers interested in the 2026 FIFA World Cup. These actors leverage social engineering and brand impersonation tactics to establish fraudulent web…
highbug_reportVulnerabilityFortinet FortiClient EMS auth bypass exploited to deploy EKZ malware
Fortinet FortiClient Enterprise Management Server (EMS). Specific vulnerable versions not provided in available data. Authentication bypass vulnerability CVE-2026-35616 allows unauthorized access.
criticalbug_reportVulnerabilityCritical RCE in Gogs Git service allows authenticated users to execute code
Gogs self-hosted Git service. Specific affected versions not disclosed. All authenticated users can exploit the vulnerability.
highperson_alertThreat ActorArctic Wolf exploits FortiClient EMS flaw for credential theft
Arctic Wolf is a threat actor exploiting a critical, patched vulnerability in FortiClient Endpoint Management Server (EMS) to deploy credential-stealing malware.
highperson_alertThreat ActorStorm-2697 Deploys The Gentlemen Go-Based Ransomware with Worm Capabilities
Storm-2697 is a threat actor tracked by Microsoft Threat Intelligence that operates as a ransomware affiliate group. The actor deploys The Gentlemen ransomware, a sophisticated Go-based encryption tool, suggesting technical proficiency in modern prog…
criticalbug_reportVulnerabilityStarlette and FastAPI authentication bypass flaw affects millions of servers
Starlette web framework and dependent frameworks including FastAPI. Specific vulnerable versions not provided in source data. Affects authentication mechanisms in applications built with these frameworks.
criticalbug_reportVulnerabilityUnpatched RCE zero-day in Gogs Git service actively threatens exposed instances
Gogs self-hosted Git service, all Internet-facing instances. Specific affected versions not disclosed. No patch currently available.
criticalbug_reportVulnerabilityCritical RCE vulnerability in LiquidJS requires immediate patching
LiquidJS templating engine, all versions prior to patched release. Specific vulnerable version range not provided in available data.
criticalbug_reportVulnerabilityDell Container Storage Modules info disclosure enables data exfiltration
Dell Container Storage Modules (specific versions not disclosed in summary). Vulnerability allows information disclosure that can lead to data exfiltration and lateral movement within containerized environments.