Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 675 results
Active filter:✕ clear
SprySOCKS malware expands to Windows in government-targeted attackshighbug_reportVulnerability
bug_reportVulnerability

SprySOCKS malware expands to Windows in government-targeted attacks

Government organizations in at least four countries. Windows systems now targeted alongside previously known Linux variants. Specific Windows versions and attack vector not disclosed.

BleepingComputer16 Jun · 07:00 UTC
Cisco Catalyst SD-WAN Manager under active exploit (CVE-2026-20262)highbug_reportVulnerability
bug_reportVulnerability

Cisco Catalyst SD-WAN Manager under active exploit (CVE-2026-20262)

Cisco Catalyst SD-WAN Manager. Specific vulnerable versions not provided in summary. Affects web UI component accessible to authenticated remote users.

CVE-2026-2026216 Jun · 04:05 UTC
CISA adds LiteSpeed cPanel Plugin privilege escalation to KEV cataloghighbug_reportVulnerability
bug_reportVulnerability

CISA adds LiteSpeed cPanel Plugin privilege escalation to KEV catalog

LiteSpeed cPanel Plugin (specific versions not disclosed). Affects web hosting environments using cPanel with LiteSpeed integration. Federal agencies and hosting providers running this plugin are in scope.

CVE-2026-5442016 Jun · 03:41 UTC
SimpleHelp OIDC flaw allows unauthenticated account creationhighbug_reportVulnerability
bug_reportVulnerability

SimpleHelp OIDC flaw allows unauthenticated account creation

SimpleHelp remote management software servers with OpenID Connect (OIDC) authentication enabled. Specific affected versions not disclosed. All SimpleHelp deployments using OIDC for technician authentication are potentially vulnerable.

SimpleHelp15 Jun · 18:06 UTC
Awesome Motive CDN breach compromises WordPress plugins in supply-chain attackhighbug_reportVulnerability
bug_reportVulnerability

Awesome Motive CDN breach compromises WordPress plugins in supply-chain attack

WordPress plugins OptinMonster, TrustPulse, and PushEngage distributed via Awesome Motive's CDN. All versions served through the compromised CDN infrastructure are potentially affected.

Awesome Motive15 Jun · 15:37 UTC
Cisco Catalyst SD-WAN Manager root privilege escalation under attackcriticalbug_reportVulnerability
bug_reportVulnerability

Cisco Catalyst SD-WAN Manager root privilege escalation under attack

Cisco Catalyst SD-WAN Manager (specific versions not provided). Vulnerability allows privilege escalation to root level on affected systems.

CVE-2026-2026215 Jun · 15:12 UTC
LiteLLM AI gateway vulnerable to privilege escalation and RCEcriticalbug_reportVulnerability
bug_reportVulnerability

LiteLLM AI gateway vulnerable to privilege escalation and RCE

LiteLLM open-source AI gateway. Specific affected versions not disclosed. Impacts organizations using LiteLLM to manage API keys and route requests to AI providers (OpenAI, Anthropic, etc.).

LiteLLM15 Jun · 14:39 UTC
Microsoft 365 Copilot SearchLeak allows data exfiltration via trusted linkhighbug_reportVulnerability
bug_reportVulnerability

Microsoft 365 Copilot SearchLeak allows data exfiltration via trusted link

Microsoft 365 Copilot Enterprise Search. All organizations using M365 Copilot with Enterprise Search enabled are potentially affected. Specific version details not disclosed.

Microsoft15 Jun · 13:09 UTC
SearchLeak in Microsoft 365 Copilot enables data theft via crafted URLscriticalbug_reportVulnerability
bug_reportVulnerability

SearchLeak in Microsoft 365 Copilot enables data theft via crafted URLs

Microsoft 365 Copilot Enterprise. All organizations using Copilot with access to mailbox, OneDrive, or SharePoint data are potentially affected. Specific vulnerable versions not disclosed.

Microsoft15 Jun · 11:00 UTC
Responsive FileManager RCE via unrestricted file upload (CVE-2026-5482)highbug_reportVulnerability
bug_reportVulnerability

Responsive FileManager RCE via unrestricted file upload (CVE-2026-5482)

Responsive FileManager (versions not specified). The vulnerability affects file upload mechanisms allowing unrestricted file uploads leading to remote code execution.

CVE-2026-548215 Jun · 09:55 UTC
Quick.CMS deserialization flaw enables potential remote code executionhighbug_reportVulnerability
bug_reportVulnerability

Quick.CMS deserialization flaw enables potential remote code execution

Quick.CMS software (specific versions not disclosed). Affects systems where untrusted data is deserialized without proper validation.

CVE-2026-1186015 Jun · 08:55 UTC
Supply chain attack hits PushEngage, OptinMonster, TrustPulse pluginscriticalbug_reportVulnerability
bug_reportVulnerability

Supply chain attack hits PushEngage, OptinMonster, TrustPulse plugins

WordPress sites using PushEngage, OptinMonster, and TrustPulse plugins. All versions loading compromised JavaScript files from vendor infrastructure are affected.

PushEngage15 Jun · 07:59 UTC
Multiple high-severity vulnerabilities in GitLab CE and EE require patchinghighbug_reportVulnerability
bug_reportVulnerability

Multiple high-severity vulnerabilities in GitLab CE and EE require patching

GitLab Community Edition (CE) and Enterprise Edition (EE). Specific affected versions not provided in advisory; typically affects versions prior to latest security release.

GitLab15 Jun · 06:25 UTC
Palo Alto PAN-OS GlobalProtect auth bypass under active exploitationhighbug_reportVulnerability
bug_reportVulnerability

Palo Alto PAN-OS GlobalProtect auth bypass under active exploitation

Palo Alto Networks PAN-OS GlobalProtect VPN portal and gateway components. Specific affected versions not disclosed in provided data. CVE-2026-0257, CVSS 7.8 (High).

CVE-2026-025715 Jun · 04:17 UTC
Splunk Enterprise RCE flaw allows unauthenticated remote code executioncriticalbug_reportVulnerability
bug_reportVulnerability

Splunk Enterprise RCE flaw allows unauthenticated remote code execution

Splunk Enterprise versions below 10.2.4 and 10.0.7. The vulnerability enables unauthenticated attackers to perform arbitrary file operations and achieve remote code execution. CVSS score 9.8 (Critical).

CVE-2026-2025313 Jun · 11:23 UTC
Arch User Repository supply chain attack: 400+ packages backdooredcriticalbug_reportVulnerability
bug_reportVulnerability

Arch User Repository supply chain attack: 400+ packages backdoored

Arch Linux users who installed or updated packages from the Arch User Repository (AUR) during the compromise window. Over 400 AUR packages contained malicious build scripts deploying a Rust-based infostealer.

Arch Linux12 Jun · 17:33 UTC
10-year-old phpBB auth bypass enables attacker login as any userhighbug_reportVulnerability
bug_reportVulnerability

10-year-old phpBB auth bypass enables attacker login as any user

phpBB forum software, versions spanning approximately 10 years (specific affected versions not disclosed). All installations running unpatched versions are vulnerable.

phpBB12 Jun · 16:19 UTC
400+ Arch User Repository packages compromised with rootkit and infostealercriticalbug_reportVulnerability
bug_reportVulnerability

400+ Arch User Repository packages compromised with rootkit and infostealer

Arch Linux users who installed or updated packages from the Arch User Repository (AUR). Over 400 AUR packages confirmed compromised. Specific package names and versions not yet disclosed.

Arch Linux12 Jun · 15:03 UTC
Oracle PeopleSoft RCE actively exploited, immediate patching requiredcriticalbug_reportVulnerability
bug_reportVulnerability

Oracle PeopleSoft RCE actively exploited, immediate patching required

Oracle PeopleSoft (specific versions not disclosed in alert). Remote code execution vulnerability affecting internet-facing PeopleSoft instances.

Oracle12 Jun · 12:39 UTC
AI coding agents vulnerable to code execution via crafted Sentry errorshighbug_reportVulnerability
bug_reportVulnerability

AI coding agents vulnerable to code execution via crafted Sentry errors

AI coding agents (e.g., GitHub Copilot, Cursor, Aider) integrated with Sentry error-tracking platform. Affects development environments where AI agents have code execution permissions and process Sentry error reports.

Sentry12 Jun · 10:04 UTC
LangGraph AI framework patched for critical RCE via SQL injection chaincriticalbug_reportVulnerability
bug_reportVulnerability

LangGraph AI framework patched for critical RCE via SQL injection chain

LangGraph (LangChain's open-source AI agent framework). Specific vulnerable versions not disclosed; patches available. Affects deployments using LangGraph for AI agent orchestration.

LangChain12 Jun · 07:50 UTC
CISA orders federal agencies to patch exploited Ivanti Sentry flawcriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders federal agencies to patch exploited Ivanti Sentry flaw

Ivanti Sentry (specific versions not disclosed in summary). U.S. federal agencies under BOD 26-04 mandate, but all Ivanti Sentry deployments at risk given active exploitation.

Ivanti12 Jun · 06:26 UTC
Oracle PeopleSoft zero-day CVE-2026-35273 exploited by ShinyHunterscriticalbug_reportVulnerability
bug_reportVulnerability

Oracle PeopleSoft zero-day CVE-2026-35273 exploited by ShinyHunters

Oracle PeopleSoft (all versions prior to June 10 patch). Confirmed exploitation targeting enterprise systems and universities. Vulnerability was unpatched during active exploitation window (May 27 - June 9).

CVE-2026-3527311 Jun · 18:29 UTC
Oracle PeopleSoft zero-day CVE-2026-35273 exploited for RCE by ShinyHuntercriticalbug_reportVulnerability
bug_reportVulnerability

Oracle PeopleSoft zero-day CVE-2026-35273 exploited for RCE by ShinyHunter

Oracle PeopleSoft Suite, all versions (specific affected versions not disclosed). Unauthenticated remote code execution vulnerability affecting internet-facing PeopleSoft instances.

CVE-2026-3527311 Jun · 17:39 UTC
OpenClaw AI agent vulnerable to prompt injection via vCards and location pinshighbug_reportVulnerability
bug_reportVulnerability

OpenClaw AI agent vulnerable to prompt injection via vCards and location pins

OpenClaw self-hosted AI agent platform, all versions. Vulnerability affects input processing mechanisms for vCards, location pins, and potentially other structured data formats.

OpenClaw11 Jun · 15:46 UTC
BitLocker bypass via recovery partition XML files (GreatXML)highbug_reportVulnerability
bug_reportVulnerability

BitLocker bypass via recovery partition XML files (GreatXML)

Windows BitLocker encryption on systems with recovery partitions. All Windows versions with BitLocker enabled are potentially affected. Specific version scope not yet published.

Microsoft11 Jun · 15:43 UTC
Critical command injection flaw in Fortinet FortiSandbox requires patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical command injection flaw in Fortinet FortiSandbox requires patching

Fortinet FortiSandbox (specific versions not disclosed in available data). Command injection vulnerability allows unauthorized command execution.

Fortinet11 Jun · 12:31 UTC
npm v12 disables install scripts by default to block supply chain attackshighbug_reportVulnerability
bug_reportVulnerability

npm v12 disables install scripts by default to block supply chain attacks

npm version 12 and later. All Node.js projects using npm for package management. Breaking change affects packages that legitimately rely on install/postinstall lifecycle hooks.

GitHub11 Jun · 04:23 UTC
Ivanti Sentry RCE flaw under active exploitation, root access possiblecriticalbug_reportVulnerability
bug_reportVulnerability

Ivanti Sentry RCE flaw under active exploitation, root access possible

Ivanti Sentry (formerly MobileIron Sentry) - Internet-exposed secure mobile gateways. Specific vulnerable versions not provided in summary, but patch recently released.

Ivanti11 Jun · 04:20 UTC
Active exploitation of path traversal in Langflow AI platformhighbug_reportVulnerability
bug_reportVulnerability

Active exploitation of path traversal in Langflow AI platform

Langflow AI development platform. Specific affected versions not disclosed. Impacts internet-exposed Langflow servers vulnerable to arbitrary file write via path traversal (CVE-2026-5027).

CVE-2026-502710 Jun · 19:23 UTC