Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
satellite_altDaily BriefCyber Threat Daily Brief — September 4, 2026
Today's briefing: 14 critical and 22 high-severity threats. A total of 47 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.
Latest Reports
28 / 1107 results
highbug_reportVulnerabilityTrojanized NuGet package targets Digitain betting platform via typosquatting
NuGet package "Newtonsoftt.Json.Net" versions 11.0.4, 11.0.5, 11.0.7, 11.0.8, 11.0.9, 11.0.10, and 11.0.11 (typosquat of Newtonsoft.Json). Primary target: Digitain FG-Crash betting game backend. Downloaded ~1,200 times.
highbug_reportVulnerabilityAzure DevOps MCP server flaw lets hidden PR comments hijack AI agents
Microsoft Azure DevOps MCP server versions up to and including v2.8.0 (released June 24, 2026). The flaw affects the repo_get_pull_request_by_id tool, which returns pull request descriptions without prompt-injection guardrails.
highperson_alertThreat ActorKratos PhaaS Platform Dismantled in Joint Law Enforcement Operation
Kratos is a phishing-as-a-service (PhaaS) platform operator that provided cybercriminal infrastructure enabling third-party threat actors to conduct phishing campaigns at scale.
highperson_alertThreat ActorFakeGit Campaign Distributes Malware via 7,600 Malicious GitHub Repos
FakeGit is a threat actor conducting a large-scale supply chain attack campaign targeting the software development community. The actor's motivation centers on mass malware distribution through the compromise of developer trust in the GitHub platform…
criticalbug_reportVulnerabilityMicrosoft SharePoint RCE CVE-2026-50522 actively exploited for persistence
Microsoft SharePoint Server (specific versions not provided). Vulnerability enables remote code execution with machine key theft capability, allowing persistent access beyond patch deployment.
highperson_alertThreat ActorAnubis Ransomware Gang Targets Coca-Cola's Fairlife Subsidiary
Anubis is a ransomware threat actor employing double extortion tactics, claiming responsibility for attacks against the food and beverage sector. The group operates by encrypting victim systems and exfiltrating sensitive corporate data, threatening p…
highbug_reportVulnerabilityApple fixes Hide My Email flaw exposing real addresses in mail logs
Apple Hide My Email service (all users prior to July 3, 2026 patch). The vulnerability affected the privacy relay feature that masks user email addresses, causing real email addresses to leak in mail server logs.
criticalbug_reportVulnerabilityWordPress Core wp2shell flaws actively exploited for webshell deployment
WordPress Core (specific versions not disclosed). Both CVE-2026-63030 and CVE-2026-60137 affect core WordPress installations, enabling remote attackers to deploy webshells and malicious plugins.
highbug_reportVulnerabilityAWS Kiro IDE vulnerability allowed RCE via hidden web text injection
AWS Kiro agentic coding IDE (specific versions not disclosed). Vulnerability has been patched by AWS. Users who installed Kiro before the patch are potentially affected.
criticalbug_reportVulnerabilityMicrosoft SharePoint RCE (CVE-2026-50522) actively exploited after PoC
Microsoft SharePoint Server (all versions prior to July 2026 patches). Vulnerability involves deserialization of untrusted data leading to unauthenticated remote code execution. CVSS 9.8 (Critical).
highperson_alertThreat ActorQilin Ransomware Exploits CVE-2026-0257 PAN-OS Flaw for Initial Access
Qilin is a ransomware-as-a-service (RaaS) operation that has been active in the cybercrime ecosystem, deploying file-encrypting malware against organizations for financial gain.
criticalbug_reportVulnerabilityZimbra 10.1.20 patches critical SNMP command injection and 4 XSS flaws
Zimbra Collaboration Suite versions prior to 10.1.20. Critical impact: SNMP monitoring component when SNMP notifications are enabled. Additional impact: four XSS vulnerabilities affecting the web interface.
highbug_reportVulnerabilityMobile AI agent frameworks vulnerable to instruction injection attacks
Five open-source mobile AI agent frameworks including AppAgent and AppAgentX. Attack requires malicious Android apps with overlay and storage permissions to inject invisible instructions, leading to command execution on connected host PCs.
criticalperson_alertThreat ActorQilin Ransomware Gang Exploits PAN-OS GlobalProtect Vulnerability
Qilin is a ransomware-as-a-service (RaaS) operation that has emerged as a notable threat actor in the cybercrime ecosystem. The group operates a double-extortion model, encrypting victim data while exfiltrating sensitive information for leverage in r…
criticalbug_reportVulnerabilityWordPress wp2shell flaws enable unauthenticated RCE, active exploitation
WordPress core (specific versions not disclosed). CVE-2026-63030 and CVE-2026-60137 must be chained for unauthenticated remote code execution. All unpatched WordPress installations are potentially vulnerable.
highbug_reportVulnerabilityWindows LegacyHive zero-day enables privilege escalation, unofficial patches available
Microsoft Windows systems (all current versions). Specific affected versions not disclosed. Impacts up-to-date Windows installations. No CVE assigned yet.
criticalbug_reportVulnerabilitySonicWall SMA1000 VPN appliances exploited via two zero-day flaws
SonicWall SMA1000 series VPN appliances. Specific vulnerable versions not disclosed. Affects enterprise VPN infrastructure using these devices.
highbug_reportVulnerabilitySandbox escape flaws in Cursor, Codex, Gemini CLI, Antigravity AI tools
Multiple AI development tools: Cursor IDE, OpenAI Codex, Google Gemini CLI, and Antigravity. Vulnerability affects AI agent sandbox implementations where agents write files executed by host tools, allowing escape from restricted environments.
highperson_alertThreat ActorJadePuffer Deploys EncForge Ransomware Targeting AI Infrastructure
JadePuffer is characterized as an autonomous AI agent that has been enhanced with offensive capabilities. The actor's motivation centers on targeting artificial intelligence infrastructure, specifically focusing on high-value AI assets such as traini…
highperson_alertThreat ActorFakeGit Campaign Distributes SmartLoader via 7,600+ Malicious GitHub Repos
FakeGit is a campaign (not a named threat actor group) targeting software developers through a large-scale supply chain attack leveraging GitHub's trusted platform.
highbug_reportVulnerabilityHollowGraph malware abuses Microsoft 365 calendar for C2 and exfiltration
Microsoft 365 environments with compromised mailboxes. Threat actors leverage Microsoft Graph API and calendar features to establish covert command-and-control channels.
highbug_reportVulnerabilityAI-assisted phishing toolkit targets Windows users in Mexico via fake gov site
Windows users in Mexico targeted via fake government ID-lookup website. Delivery mechanism uses WebDAV to distribute infostealer malware. Toolkit contains 1,048 files including phishing templates, droppers, and builder documentation.
highperson_alertThreat ActorHollowGraph Malware Uses Microsoft 365 Calendars for Covert C2
HollowGraph is a newly discovered espionage implant that leverages Microsoft 365 calendar infrastructure for command and control operations. The malware was identified and analyzed by Group-IB.
highperson_alertThreat ActorRussian Intelligence Services Exploit Security Cameras for Military Surveillance
Russian intelligence services are conducting a systematic cyber-espionage campaign targeting internet-connected security cameras across Europe and Ukraine.
highbug_reportVulnerability7-Zip heap overflow in XZ handling allows code execution via crafted archives
7-Zip versions prior to 26.02. Affects all platforms where 7-Zip is deployed (Windows, Linux). Vulnerability triggered when opening malicious XZ archives.
highperson_alertThreat Actorbandcampro leverages Google Gemini CLI to control dental clinic botnet
bandcampro is a Russian-speaking threat actor that has demonstrated novel tradecraft by weaponizing Google's Gemini CLI tool to orchestrate botnet operations.
highperson_alertThreat ActorAutonomous AI Agent Breaches Hugging Face Repository
The threat actor is identified as an autonomous AI agent system—a novel adversary class representing machine-driven attack capabilities operating with minimal or no human intervention.
highbug_reportVulnerabilityMalicious RubyGems packages deliver payloads to developer workstations
RubyGems ecosystem: three malicious packages (git_credential_manager, Dendreo, and one unnamed) published to the official RubyGems repository. Affects Ruby developers who installed these packages.