Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
satellite_altDaily BriefCyber Threat Daily Brief — July 21, 2026
Today's briefing: 3 critical and 16 high-severity threats. A total of 23 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.
Latest Reports
28 / 606 results
highbug_reportVulnerabilityKidsview authentication bypass allows unauthorized access (CVE-2026-8990)
Kidsview application (specific versions not disclosed). Authentication mechanisms can be bypassed, potentially affecting all deployments until patched versions are confirmed.
highperson_alertThreat ActorRomanian National Sentenced for Hacking Oregon Government Network
A Romanian national individual actor who conducted unauthorized access operations targeting U.S. government and private sector networks. The actor's motivation appears to be financially driven cybercrime, operating from Romania to compromise Oregon s…
highbug_reportVulnerabilityOut-of-bounds write in bzip2 enables code execution or DoS
bzip2 compression software, all versions not yet patched. Affects systems using bzip2 for file compression/decompression, including Linux distributions, BSD variants, and applications embedding libbz2.
highperson_alertThreat ActorShinyHunters Claims Breach of Carnival Corporation, 6M Records
ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has been active since at least 2020, specializing in breaching corporate databases and exfiltrating customer and employee re…
highperson_alertThreat ActorJINX-0164 Targets Cryptocurrency Orgs with macOS Malware
JINX-0164 is a previously undocumented threat actor with a financial motivation focused on digital asset theft. The group demonstrates technical sophistication through the development of custom macOS malware and operational tradecraft centered on soc…
highbug_reportVulnerabilityCryptojacking campaign uses SEO poisoning and AI chatbots for GPU malware
High-performance systems with GPUs accessed via search engines and AI chatbot platforms. No specific vendor or product vulnerability; targets users searching for legitimate software or information through poisoned search results and manipulated chatb…
criticalbug_reportVulnerabilityApache ActiveMQ NMS AMQP Client deserialization flaw enables RCE
Apache ActiveMQ NMS AMQP Client - specific vulnerable versions not provided. Affects .NET/C# applications using the NMS AMQP client library for message queue operations.
criticalbug_reportVulnerabilityMicrosoft SharePoint RCE vulnerability requires immediate patching
Microsoft SharePoint Server (specific versions not disclosed in advisory). Organizations running on-premises SharePoint deployments are affected. SharePoint Online managed by Microsoft likely already patched.
highbug_reportVulnerabilityBanking trojans Grandoreiro and BTMOB target LATAM and Europe
Windows and Android devices in Latin America (Brazil, Mexico) and Europe (Spain, Portugal). Grandoreiro targets Windows systems at companies; BTMOB RAT targets Android mobile users in Brazil.
highbug_reportVulnerabilityMalicious npm package targets Claude AI user data directory
npm package "mouse5212-super-formatter" (all versions). Targets developers using Anthropic Claude AI tools with access to /mnt/user-data directory. Affects Node.js development environments where the malicious package was installed.
highbug_reportVulnerabilityGlassworm botnet targeting developers disrupted via C2 takedown
Software developers and development environments targeted by Glassworm botnet. The botnet leveraged Solana blockchain and BitTorrent DHT for command-and-control infrastructure, indicating attacks against software supply chains.
highperson_alertThreat ActorSilent Ransom Group Shifts to Physical Data Theft at U.S. Law Firms
Silent Ransom Group (SRG) is an extortion-focused threat actor that has evolved from traditional ransomware operations to conducting physical, in-person data theft attacks.
highbug_reportVulnerabilityCrowdStrike, Google disrupt GlassWorm C2 targeting software developers
Software developers using third-party packages and browser extensions. GlassWorm campaign active since early 2025, distributing malware through supply chain vectors including malicious packages and extensions.
highbug_reportVulnerabilityGitea auth bypass exposes private container images to unauthenticated users
Gitea versions prior to 1.26.2. All deployments using Gitea's container registry feature are affected. Unauthenticated remote attackers can pull private container images without credentials.
criticalbug_reportVulnerabilityCISA orders federal agencies to patch LiteSpeed cPanel plugin in 4 days
LiteSpeed cPanel user-end plugin. Specific vulnerable versions not disclosed. Affects organizations using cPanel with LiteSpeed integration.
highbug_reportVulnerabilityAI chatbot abuse delivers cryptojacking malware via social engineering
Users of AI chatbots (platform-agnostic); Windows systems targeted for cryptojacking payload deployment. Campaign actively observed by Microsoft; no specific product vulnerability, relies on social engineering.
highbug_reportVulnerabilityCryptojacking campaign uses SEO poisoning and ScreenConnect for GPU mining
Organizations using ScreenConnect remote access software; high-performance PCs with GPUs; users searching for compromised topics via search engines and AI chatbots. Campaign leverages Microsoft .NET utilities for execution.
criticalbug_reportVulnerabilityZero-day in KnowledgeDeliver LMS exploited to deploy Godzilla web shell
KnowledgeDeliver learning management system (specific versions unknown). Exploitation results in web shell deployment enabling persistent remote access to affected servers.
highperson_alertThreat ActorShinyHunters Extorts Charter Communications After Data Breach
ShinyHunters is a financially motivated cybercrime group known for large-scale data breaches and extortion operations targeting organizations across multiple sectors.
criticalbug_reportVulnerabilityLiteSpeed cPanel/WHM plugin under active exploit (CVE-2026-48172)
LiteSpeed plugin for cPanel/WHM. Specific vulnerable versions not disclosed in provided data. Affects web hosting environments using LiteSpeed with cPanel/WHM integration.
criticalbug_reportVulnerabilityUbiquiti patches critical UniFi OS vulnerabilities
Ubiquiti UniFi OS (specific versions not disclosed). Affects UniFi network management appliances including Dream Machine, Cloud Key, and similar devices running UniFi OS.
highperson_alertThreat ActorMuddyWater Q1 2026 espionage campaign hits nine countries via DLL side-loading
MuddyWater (also tracked as Earth Vetala, MERCURY, Static Kitten, and Seedworm) is an Iranian state-sponsored APT group attributed to Iran's Ministry of Intelligence and Security (MOIS).
highbug_reportVulnerabilityMicrosoft patches SharePoint RCE flaw via unsafe deserialization
Microsoft SharePoint Server (specific versions not disclosed). Vulnerability involves deserialization of untrusted data leading to remote code execution with CVSS 8.8.
criticalbug_reportVulnerabilityTrend Micro Apex One & Vision One SEP flaws under active exploit
Trend Micro Apex One and Trend Micro Vision One Endpoint Security (SEP). Specific vulnerable versions not disclosed in summary; multiple vulnerabilities confirmed under active exploitation.
highpublicGeopoliticalIndia mandates 12-hour patching for critical vulnerabilities
India's Computer Emergency Response Team (CERT-In) has introduced stringent vulnerability management requirements, mandating that organizations patch critical security flaws in internet-facing systems within 12 hours of notification.
criticalbug_reportVulnerabilityCritical vulnerability in Cisco Secure Workload requires immediate patching
Cisco Secure Workload (specific versions not disclosed in advisory). CVE identifier not yet assigned or published.
criticalbug_reportVulnerabilityCISA orders emergency patching of exploited Drupal SQL injection flaw
Drupal CMS (specific versions not provided in alert). Affects U.S. government agencies and all organizations running vulnerable Drupal instances.
highbug_reportVulnerabilityWindows Server 2016 domain controller lookups fail after KB5087537 update
Windows Server 2016 domain controllers running KB5087537 (May 2026 security update). Impacts Active Directory domain controller lookup functionality and domain connectivity.