Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
satellite_altDaily BriefCyber Threat Daily Brief — September 4, 2026
Today's briefing: 14 critical and 22 high-severity threats. A total of 47 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.
Latest Reports
29 / 1107 results
criticalperson_alertThreat ActorRussian Espionage Group Exploited Zimbra Zero-Day for Email Theft
A Russian state-sponsored espionage group conducted a sustained campaign exploiting a zero-day vulnerability in Zimbra's webmail client. The actor, tracked as TA488 by Proofpoint and CL-STA-1114 by Unit 42, operated undetected for at least five month…
highperson_alertThreat ActorLaundry Bear exploits Zimbra XSS zero-day for email theft
Laundry Bear (also tracked as Void Blizzard by Microsoft) is a Russian state-sponsored APT group first publicly attributed by Dutch intelligence agencies in May 2025 following their 2024 compromise of the Dutch National Police.
highbug_reportVulnerabilityUAC-0099 abuses Notepad++ plugin loading to deploy LunchPoke malware
Organizations in Ukraine using Notepad++ 8.8.3. The attack does not exploit a vulnerability in Notepad++; it abuses legitimate plugin-loading functionality to deploy LunchPoke, BurnyBear, and MatchBoil V2 malware loaders via social engineering (malic…
criticalbug_reportVulnerabilityProgress Telerik UI for AJAX RCE vulnerability requires immediate patching
Progress Telerik UI for AJAX - specific affected versions not disclosed in available information. Vulnerability enables remote code execution.
highpublicGeopoliticalMicrosoft 365 outage disrupts cloud services across North America
The incident represents a technical service disruption affecting critical cloud infrastructure rather than a geopolitical cyber event. Microsoft 365's position as backbone infrastructure for government, defense, and commercial operations in North Ame…
criticalbug_reportVulnerabilityCheck Point privilege escalation flaws under active exploitation
Check Point products (specific versions not disclosed in available data). Three privilege escalation vulnerabilities identified, including one actively exploited flaw enabling full admin authentication bypass.
highperson_alertThreat ActorRussian cyberespionage campaign targets Zimbra via JavaScript injection
This campaign is attributed by Unit 42 to Russian cyberespionage interests. The actor's motivation centers on intelligence gathering through compromise of email infrastructure.
highbug_reportVulnerabilityClaude Cowork sandbox escape lets AI agent access macOS host files
Anthropic Claude Cowork macOS desktop app running local sessions. Approximately 500,000 macOS users affected prior to mitigation. Users who continue to run local execution (not cloud) remain vulnerable.
highperson_alertThreat ActorChaos Ransomware Group Deploys msaRAT Rust Implant via Headless Browsers
Chaos is a ransomware group that operates through spam floods, vishing campaigns, Quick Assist abuse, and RMM tools for initial access and persistence. The group deploys custom tooling including the msaRAT Rust-based implant as a pre-ransomware stage…
highperson_alertThreat ActorJadeProx Deploys TriBack Loader Against Asian, Latin American Targets
JadeProx is a China-nexus threat actor tracked by Group-IB, discovered through an exposed Alibaba Cloud server in Singapore in mid-April 2026. The actor targets government, healthcare, and education organizations across Asia and Latin America.
highperson_alertThreat ActorLaundry Bear: Russian APT deploys zero-click phishing via Zimbra exploit
Laundry Bear is an advanced persistent threat (APT) group attributed to Russian state support, specializing in covert email data acquisition. The group conducts espionage operations targeting Western organizations and NATO members.
highbug_reportVulnerabilityLinux XFS race condition CVE-2026-64600 enables local root escalation
Linux kernel v4.11 and later (since February 2017) with XFS filesystem and reflink enabled (default on RHEL, Oracle Linux, Amazon Linux, Fedora, CentOS Stream, Rocky Linux, AlmaLinux, CloudLinux).
highperson_alertThreat ActorGitHub Actions Abused to Scan and Exploit cPanel/WHM Servers
The threat actor behind this campaign remains unattributed. The operation demonstrates sophisticated understanding of GitHub Actions infrastructure and supply chain attack vectors.
highperson_alertThreat ActorChaos ransomware gang deploys msaRAT backdoor via browser hijacking
Chaos is a ransomware gang that emerged in early 2025, distinct from the earlier same-named ransomware family active since 2021. The group has been linked to Iranian state-backed threat actor MuddyWater, who reportedly leveraged Chaos ransomware to d…
highbug_reportVulnerabilityFortiBleed campaign targets Fortinet globally; Finland unaffected
Fortinet products (specific models and versions not disclosed). Campaign active globally as of June 2026, Finland not impacted to date.
criticalbug_reportVulnerabilityCheck Point SmartConsole auth bypass zero-day exploited in the wild
Check Point SmartConsole (GUI admin panel for Security Management Server and Multi-Domain Security Management Server). CVE-2026-16232. Vulnerable configurations: Management Server IP exposed to Internet without Trusted Client IP restrictions.
criticalbug_reportVulnerabilityRefluXFS kernel flaw grants local root on default RHEL, Fedora, Amazon Linux
Linux kernel 4.11+ (2017–July 2026) on systems with XFS filesystems created with reflink=1. Default installations of RHEL/CentOS Stream/Oracle/Rocky/AlmaLinux/CloudLinux 8/9/10, Fedora Server 31+, Amazon Linux 2023, and Amazon Linux 2 (Dec 2022+) are…
criticalbug_reportVulnerabilityCheck Point SmartConsole auth bypass (CVE-2026-16232) exploited in wild
Check Point Security Management and Multi-Domain Management (MDSM) products: R77.30, R80, R80.10, R80.20, R80.30, R81, R81.10, R81.20, R82, R82.10. Affects SmartConsole login process when Management Server is exposed to internet without IP restrictio…
highpublicGeopoliticalSouth Korea discloses 10-month breach of diplomatic training platform
The compromise of South Korea's National Diplomatic Academy represents a significant intelligence collection operation targeting a key U.S. ally in Northeast Asia.
highbug_reportVulnerabilityUbuntu snap-confine race condition grants local users root access
Ubuntu Desktop 24.04, 25.10, and 26.04 (default installations). Vulnerable component: snap-confine in snapd. Affects systems using the set-capabilities model for privilege enforcement.
highperson_alertThreat ActorEverest Gang Demands $12.3M from Stadler Rail After Supplier Breach
Everest is a ransomware operation that emerged in 2020, initially deploying file encryption but later pivoted to pure data theft extortion tactics. The group threatens to leak stolen data unless ransom demands are met.
criticalbug_reportVulnerabilityWordPress Core RCE flaws CVE-2026-63030, CVE-2026-60137 under active exploit
WordPress Core (specific versions not disclosed in advisory). Two remote code execution vulnerabilities (CVE-2026-63030, CVE-2026-60137) affecting the core platform.
highbug_reportVulnerabilityAdobe Acrobat Chrome extension flaw allows WhatsApp data theft via UXSS
Adobe Acrobat Chrome extension (ID: efaidnbmnnnibpcajpcglclefindmkaj) versions up to and including 26.5.2.2. Affects 314+ million users. Exploitation impacts any web application data accessible in victim's browser, demonstrated against WhatsApp Web.
criticalbug_reportVulnerabilityMicrosoft July 2026 Patch Tuesday: 569 vulnerabilities, 56 critical
Microsoft product portfolio (specific products and versions not disclosed in available data). 569 total vulnerabilities patched, including 56 rated critical severity.
highbug_reportVulnerabilityAdobe Acrobat Chrome extension flaw exposed WhatsApp Web chats
Adobe Acrobat extension for Chrome versions 26.5.2.1 and below. Affects approximately 329 million browser installations. Exploitation requires victim to visit attacker-controlled webpage while extension is installed and WhatsApp Web is in use.
highbug_reportVulnerabilityWindmill path traversal flaw exploited to read server files unauthenticated
Windmill open-source developer platform versions prior to 1.603.3. The vulnerability affects the "get_log_file" endpoint (/api/w/{workspace}/jobs_u/get_log_file/{filename}). Approximately 170 vulnerable systems identified across 24 countries.
criticalbug_reportVulnerabilityCISA orders urgent patching of exploited Langflow RCE (CVE-2026-0770)
Langflow visual framework for building AI agents. All unpatched versions vulnerable. Affects unauthenticated remote attackers who can reach the /api/v1/validate/code endpoint. Federal agencies must patch by July 25, 2026.
criticalbug_reportVulnerabilityMicrosoft SharePoint RCE flaws actively exploited; immediate patching required
Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. Five critical vulnerabilities: CVE-2026-50522 (CVSS 9.8, deserialization RCE), CVE-2026-58644 (CVSS 9.8, unauthenticated RCE), CVE-2026-5…
highperson_alertThreat ActorKratos Phishing Kit Dismantled After Stealing Microsoft 365 Sessions
The Kratos operator is an Indonesian individual arrested by local authorities for allegedly developing and operating the Kratos phishing-as-a-service (PhaaS) platform.