Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 685 results
Active filter:tag: #high✕ clear
Windows June updates break Office launch from third-party appshighbug_reportVulnerability
bug_reportVulnerability

Windows June updates break Office launch from third-party apps

Windows systems with June 2024 updates installed. Affects third-party applications attempting to launch Microsoft Office applications or open Office documents. Specific Windows versions not yet disclosed by Microsoft.

Microsoft17 Jun · 09:54 UTC
Microsoft Defender zero-day "RoguePlanet" awaits patch after disclosurehighbug_reportVulnerability
bug_reportVulnerability

Microsoft Defender zero-day "RoguePlanet" awaits patch after disclosure

Microsoft Defender (all versions currently deployed). Specific affected versions not disclosed. Impacts organizations relying on Defender for endpoint protection.

Microsoft17 Jun · 06:32 UTC
ShinyHunters Claims Responsibility for Kodak Data Breachhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Claims Responsibility for Kodak Data Breach

ShinyHunters is a financially motivated cybercrime group known for conducting data theft and extortion operations against organizations across multiple sectors.

Kodak17 Jun · 05:07 UTC
Malicious JetBrains IDE plugins steal AI API keys from developershighbug_reportVulnerability
bug_reportVulnerability

Malicious JetBrains IDE plugins steal AI API keys from developers

JetBrains Marketplace users who installed any of the 15+ malicious plugins. Affects developers using JetBrains IDEs (IntelliJ IDEA, PyCharm, WebStorm, etc.) with AI API keys configured. Specific plugin names and versions not provided in summary.

JetBrains16 Jun · 19:54 UTC
Rokarolla Android banking trojan targets 217 banking and crypto appshighbug_reportVulnerability
bug_reportVulnerability

Rokarolla Android banking trojan targets 217 banking and crypto apps

Android devices with 217 targeted banking and cryptocurrency applications. Malware features 137 commands for comprehensive device control and data exfiltration. Specific app list and Android version scope not disclosed.

BleepingComputer16 Jun · 18:04 UTC
Google Cloud Vertex AI SDK flaw enables ML model hijacking via pickle attackhighbug_reportVulnerability
bug_reportVulnerability

Google Cloud Vertex AI SDK flaw enables ML model hijacking via pickle attack

Google Cloud Vertex AI SDK for Python. Specific affected versions not disclosed. Impacts organizations using the SDK to upload and deploy machine learning models to Google Cloud's serving infrastructure.

Google16 Jun · 17:05 UTC
Malware campaign abuses Steam Workshop via Wallpaper Engine packageshighbug_reportVulnerability
bug_reportVulnerability

Malware campaign abuses Steam Workshop via Wallpaper Engine packages

Valve Steam Workshop users, specifically those using Wallpaper Engine application. All versions of Wallpaper Engine that integrate with Steam Workshop are potentially affected. Scope includes users downloading community-created wallpaper content.

Valve16 Jun · 16:27 UTC
ClickFix campaigns deploy three malware loaders via fake updateshighbug_reportVulnerability
bug_reportVulnerability

ClickFix campaigns deploy three malware loaders via fake updates

Education and financial sector organizations targeted by ClickFix social engineering campaigns delivering BabaDeda Loader, Lorem Ipsum Loader, and Potemkin malware loaders through fake software update lures.

The Hacker News16 Jun · 15:41 UTC
GhostTree Abuses NTFS Junctions to Evade Microsoft Defender Scanshighperson_alertThreat Actor
person_alertThreat Actor

GhostTree Abuses NTFS Junctions to Evade Microsoft Defender Scans

GhostTree is a threat actor that has developed an evasion technique exploiting recursive NTFS junctions to bypass antivirus scanning. The actor targets the information technology sector and leverages inherent Windows file system features to create in…

Microsoft16 Jun · 12:17 UTC
Heap buffer overflow in jansi library enables code executionhighbug_reportVulnerability
bug_reportVulnerability

Heap buffer overflow in jansi library enables code execution

jansi library (all versions not specified). The jansi library is a Java library for ANSI escape sequences, commonly used in console applications and logging frameworks across Java ecosystems.

CVE-2026-848416 Jun · 08:55 UTC
DragonForce Ransomware Gang Deploys Backdoor.Turn via Teams Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

DragonForce Ransomware Gang Deploys Backdoor.Turn via Teams Infrastructure

DragonForce is a ransomware gang that has developed custom tooling to support their extortion operations. The group demonstrates advanced capabilities in developing bespoke malware and leveraging legitimate cloud infrastructure for command-and-contro…

Microsoft16 Jun · 08:18 UTC
Vertex AI Python SDK vulnerable to RCE via bucket squatting attackshighbug_reportVulnerability
bug_reportVulnerability

Vertex AI Python SDK vulnerable to RCE via bucket squatting attacks

Google Vertex AI Python SDK. Affects users uploading models to Vertex AI. Vulnerability exploits bucket squatting during model upload process combined with pickle deserialization to achieve cross-tenant remote code execution.

Google16 Jun · 08:00 UTC
China-Linked Actor Deploys Windows Variants of SprySOCKS Backdoorhighperson_alertThreat Actor
person_alertThreat Actor

China-Linked Actor Deploys Windows Variants of SprySOCKS Backdoor

A China-linked threat actor has expanded the SprySOCKS malware family beyond its original Linux platform. The actor demonstrates advanced development capabilities through the creation of two distinct Windows variants (WIN_DRV and WIN_PLUS) featuring…

Windows16 Jun · 07:44 UTC
SprySOCKS malware expands to Windows in government-targeted attackshighbug_reportVulnerability
bug_reportVulnerability

SprySOCKS malware expands to Windows in government-targeted attacks

Government organizations in at least four countries. Windows systems now targeted alongside previously known Linux variants. Specific Windows versions and attack vector not disclosed.

BleepingComputer16 Jun · 07:00 UTC
ScarCruft Deploys NarwhalRAT via Microsoft Account Phishing Lureshighperson_alertThreat Actor
person_alertThreat Actor

ScarCruft Deploys NarwhalRAT via Microsoft Account Phishing Lures

ScarCruft (also tracked as APT37, InkySquid, Reaper, and Group123) is a North Korean state-sponsored advanced persistent threat group. The actor is attributed to North Korea's intelligence apparatus and conducts espionage operations aligned with Pyon…

Microsoft16 Jun · 06:14 UTC
Cisco Catalyst SD-WAN Manager under active exploit (CVE-2026-20262)highbug_reportVulnerability
bug_reportVulnerability

Cisco Catalyst SD-WAN Manager under active exploit (CVE-2026-20262)

Cisco Catalyst SD-WAN Manager. Specific vulnerable versions not provided in summary. Affects web UI component accessible to authenticated remote users.

CVE-2026-2026216 Jun · 04:05 UTC
CISA adds LiteSpeed cPanel Plugin privilege escalation to KEV cataloghighbug_reportVulnerability
bug_reportVulnerability

CISA adds LiteSpeed cPanel Plugin privilege escalation to KEV catalog

LiteSpeed cPanel Plugin (specific versions not disclosed). Affects web hosting environments using cPanel with LiteSpeed integration. Federal agencies and hosting providers running this plugin are in scope.

CVE-2026-5442016 Jun · 03:41 UTC
DOJ seizes AI deepfake sites under new TAKE IT DOWN Act authorityhighpublicGeopolitical
publicGeopolitical

DOJ seizes AI deepfake sites under new TAKE IT DOWN Act authority

The seizure of CFAKE.com and SOCFAKE.com represents the first public enforcement action under the TAKE IT DOWN Act, signaling a U.S. policy shift toward proactive domain-level intervention against AI-enabled image-based sexual abuse.

BleepingComputer15 Jun · 19:56 UTC
SimpleHelp OIDC flaw allows unauthenticated account creationhighbug_reportVulnerability
bug_reportVulnerability

SimpleHelp OIDC flaw allows unauthenticated account creation

SimpleHelp remote management software servers with OpenID Connect (OIDC) authentication enabled. Specific affected versions not disclosed. All SimpleHelp deployments using OIDC for technician authentication are potentially vulnerable.

SimpleHelp15 Jun · 18:06 UTC
Contagious Interview targets developers via recruitment-themed phishinghighperson_alertThreat Actor
person_alertThreat Actor

Contagious Interview targets developers via recruitment-themed phishing

Contagious Interview (also tracked as DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, and DEV#POPPER) is a North Korean-aligned threat actor cluster that specializes in social engineering attacks against software developers and technology secto…

The Hacker News15 Jun · 17:32 UTC
Awesome Motive CDN breach compromises WordPress plugins in supply-chain attackhighbug_reportVulnerability
bug_reportVulnerability

Awesome Motive CDN breach compromises WordPress plugins in supply-chain attack

WordPress plugins OptinMonster, TrustPulse, and PushEngage distributed via Awesome Motive's CDN. All versions served through the compromised CDN infrastructure are potentially affected.

Awesome Motive15 Jun · 15:37 UTC
ShinyHunters Claims Council of Europe Data Breachhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Claims Council of Europe Data Breach

ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has been active since at least 2020, targeting organizations across multiple sectors to steal sensitive databases and person…

Council of Europe15 Jun · 14:37 UTC
Microsoft 365 Copilot SearchLeak allows data exfiltration via trusted linkhighbug_reportVulnerability
bug_reportVulnerability

Microsoft 365 Copilot SearchLeak allows data exfiltration via trusted link

Microsoft 365 Copilot Enterprise Search. All organizations using M365 Copilot with Enterprise Search enabled are potentially affected. Specific version details not disclosed.

Microsoft15 Jun · 13:09 UTC
China-Linked Espionage Group Deploys InfiniteRed via REDCap Servershighperson_alertThreat Actor
person_alertThreat Actor

China-Linked Espionage Group Deploys InfiniteRed via REDCap Servers

This activity is attributed to a China-linked espionage group targeting healthcare and medical research sectors. The actor's motivation appears to be intelligence collection focused on sensitive medical research data, consistent with strategic intere…

REDCap15 Jun · 12:00 UTC
ShinyHunters Breaches 137K+ School Staff via Salesforce Attackhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Breaches 137K+ School Staff via Salesforce Attack

ShinyHunters is a financially motivated cybercrime actor specializing in large-scale data theft and extortion operations. The group has established a reputation for targeting cloud-based platforms and third-party service providers to compromise downs…

Salesforce15 Jun · 10:38 UTC
Responsive FileManager RCE via unrestricted file upload (CVE-2026-5482)highbug_reportVulnerability
bug_reportVulnerability

Responsive FileManager RCE via unrestricted file upload (CVE-2026-5482)

Responsive FileManager (versions not specified). The vulnerability affects file upload mechanisms allowing unrestricted file uploads leading to remote code execution.

CVE-2026-548215 Jun · 09:55 UTC
Quick.CMS deserialization flaw enables potential remote code executionhighbug_reportVulnerability
bug_reportVulnerability

Quick.CMS deserialization flaw enables potential remote code execution

Quick.CMS software (specific versions not disclosed). Affects systems where untrusted data is deserialized without proper validation.

CVE-2026-1186015 Jun · 08:55 UTC
Multiple high-severity vulnerabilities in GitLab CE and EE require patchinghighbug_reportVulnerability
bug_reportVulnerability

Multiple high-severity vulnerabilities in GitLab CE and EE require patching

GitLab Community Edition (CE) and Enterprise Edition (EE). Specific affected versions not provided in advisory; typically affects versions prior to latest security release.

GitLab15 Jun · 06:25 UTC
Palo Alto PAN-OS GlobalProtect auth bypass under active exploitationhighbug_reportVulnerability
bug_reportVulnerability

Palo Alto PAN-OS GlobalProtect auth bypass under active exploitation

Palo Alto Networks PAN-OS GlobalProtect VPN portal and gateway components. Specific affected versions not disclosed in provided data. CVE-2026-0257, CVSS 7.8 (High).

CVE-2026-025715 Jun · 04:17 UTC
FBI disrupts Outsider Enterprise Chinese phishing-as-a-service platformhighperson_alertThreat Actor
person_alertThreat Actor

FBI disrupts Outsider Enterprise Chinese phishing-as-a-service platform

Outsider Enterprise is a Chinese phishing-as-a-service (PhaaS) operation disrupted by the FBI in coordination with Google and Black Lotus Labs. The actor operated thousands of phishing websites designed to harvest credit card data and passwords from…

BleepingComputer14 Jun · 12:36 UTC