Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
satellite_altDaily BriefCyber Threat Daily Brief — September 4, 2026
Today's briefing: 14 critical and 22 high-severity threats. A total of 47 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.
Latest Reports
29 / 1107 results
highpublicGeopoliticalMount Royal University in Calgary confirms data breach and deletion
The breach of Mount Royal University represents a typical pattern in the current cyber threat landscape affecting higher education institutions across North America.
highbug_reportVulnerabilityMalicious npm and PyPI packages impersonate Paysafe payment SDKs
Developers using npm and PyPI repositories who may have installed counterfeit packages impersonating Paysafe, Skrill, and Neteller payment SDKs. Affects development environments and potentially downstream applications integrating these malicious pack…
highperson_alertThreat ActorChina-Linked Cluster Exploits Roundcube at Universities
This China-linked threat cluster targets academic institutions in North America, focusing on credential theft and persistent access through exploitation of vulnerable Roundcube webmail servers.
highperson_alertThreat ActorVishing Campaign Targets Microsoft 365 Users with Entra Passkey Scam
The threat actor behind this campaign remains unattributed. The operation demonstrates sophistication in social engineering tactics, specifically targeting Microsoft 365 environments through voice-based phishing (vishing).
highbug_reportVulnerabilityHalluSquatting attack exploits AI coding assistants to distribute malware
AI coding assistants (GitHub Copilot, ChatGPT, Claude, etc.) and developers using AI-generated package recommendations. All package ecosystems (npm, PyPI, Maven, etc.) are potential targets.
criticalbug_reportVulnerabilityUbiquiti patches critical flaws in UniFi products, CVE-2026-50746 CVSS 10.0
Ubiquiti UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS. Specific vulnerable versions not provided in available data. CVE-2026-50746 rated CVSS 10.0 (critical).
highperson_alertThreat ActorEvilTokens Ghost Phishing Campaign Targets US and European Businesses
EvilTokens is a campaign leveraging "ghost phishing" techniques to target business entities across the United States and Europe. The campaign's primary motivation appears to be credential theft and unauthorized access to Microsoft 365 environments, w…
highperson_alertThreat ActorREF6045 targets Mexican banking sector with SCMBANKER via ClickFix lures
REF6045 is a financially motivated threat actor conducting banking fraud operations against Mexican financial institutions and their customers. The actor targets banking, fintech, and cryptocurrency exchange users in Mexico, leveraging social enginee…
highbug_reportVulnerabilityGitHub commit verification flaw allows signature reuse on rewritten commits
GitHub's commit verification system for GPG/SSH-signed commits. All repositories using signed commits with GitHub's "Verified" badge are potentially affected. The flaw is in GitHub's verification logic, not Git itself.
highpublicGeopoliticalKDDI breach exposes 12M records across Japanese ISP ecosystem
The breach of KDDI, one of Japan's three major telecommunications carriers, represents a significant compromise of critical infrastructure in a key U.S. Indo-Pacific ally.
criticalbug_reportVulnerabilityCISA orders federal patch for exploited Langflow auth bypass by Friday
Langflow visual AI agent framework - specific versions not disclosed in summary. Federal agencies mandated to patch; private sector should assume all unpatched instances at risk.
highperson_alertThreat ActorUAT-7810 Expands ORB Network with LONGLEASH Malware on Edge Devices
UAT-7810 is a China-linked advanced persistent threat (APT) actor focused on compromising internet-facing networking and infrastructure devices to build and maintain an Operational Relay Box (ORB) network designated LapDogs.
criticalbug_reportVulnerabilityUbiquiti patches 7 critical flaws in UniFi OS, including max-severity RCE
Ubiquiti UniFi OS - specific vulnerable versions not disclosed. Seven critical vulnerabilities patched, including one maximum-severity (CVSS 10.0) command injection flaw enabling remote code execution.
criticalbug_reportVulnerabilityCISA orders patching of actively exploited Adobe ColdFusion flaw
Adobe ColdFusion commercial web application development platform. Specific affected versions not disclosed in summary, but CISA mandatory patching order indicates government-facing installations are priority targets.
criticalbug_reportVulnerability15-year-old Linux kernel flaw allows local privilege escalation to root
Linux kernel versions since 2011 across all mainstream distributions (Ubuntu, RHEL, Debian, SUSE, etc.). Any system running an unpatched kernel containing CVE-2026-43499 is vulnerable. Requires local authenticated access to exploit.
highbug_reportVulnerabilityVidar Stealer campaign uses Go-based DLL sideloading and code signing abuse
Organizations using Windows systems are targeted. Campaign abuses legitimate Windows Defender components (MpClient.dll sideloading) via loader-as-a-service framework.
highperson_alertThreat ActorUAT-7810 Deploys LONGLEASH Malware Against Network Infrastructure
UAT-7810 is a Chinese-linked threat actor focused on compromising internet-facing networking devices to expand their Operational Relay Box (ORB) network infrastructure.
highbug_reportVulnerabilityHidden backdoor in Tenda routers grants admin access to web panel
Multiple Tenda router models and firmware versions contain a hidden authentication backdoor affecting the web management interface. Specific affected models and versions not disclosed in available information.
highbug_reportVulnerabilityRedWing Android MaaS enables bank fraud via credential theft
Android devices targeted by RedWing malware, distributed as Malware-as-a-Service on Telegram. Variant of Oblivion MaaS. Primarily affects banking applications and users with compromised devices.
criticalbug_reportVulnerabilityGoogle Dialogflow CX flaw lets attackers hijack agents in same GCP project
Google Dialogflow CX agents with Code Block feature enabled, within shared Google Cloud projects. Requires attacker to have edit rights on at least one agent in the project.
highperson_alertThreat ActorDEBULL Campaign Exploits Microsoft Device Code Flow for M365 Phishing
DEBULL is a phishing campaign active from late June through early July 2026, targeting Microsoft 365 accounts through abuse of Microsoft's legitimate device-code flow authentication mechanism.
highbug_reportVulnerabilityGitHub Agentic Workflows leak private repo data via public issues
GitHub Agentic Workflows with cross-repository read access. Organizations using GitHub agents that can access both public and private repositories are vulnerable. No CVE assigned yet.
highperson_alertThreat ActorScattered Spider Linked to U.S. Luxury Retail Breach via Device ID
Scattered Spider (also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944) is a financially motivated threat actor known for sophisticated social engineering and identity-focused attacks.
criticalbug_reportVulnerabilityWriter AI platform session isolation flaw enables cross-tenant access
Writer enterprise AI platform. Specific affected versions not disclosed. Vulnerability impacts agent preview functionality allowing cross-tenant session token leakage and unauthorized access.
highbug_reportVulnerability16-year-old Linux kernel flaw enables VM escape on Intel and AMD hosts
Linux kernel (specific versions not disclosed); affects virtualization environments on Intel and AMD processors. VM escape vulnerability impacts hypervisors relying on affected kernel versions.
highperson_alertThreat ActorChina-Aligned Cluster Exploits Roundcube Flaws at Universities
This activity cluster is attributed to China-aligned threat actors targeting academic institutions in North America. The group demonstrates a clear strategic interest in research and development sectors, specifically physics and engineering departmen…
criticalbug_reportVulnerabilityBeyondTrust RS and PRA authentication bypass flaws require patching
BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) software. Specific affected versions not provided in available data.
criticalbug_reportVulnerabilityTenda router backdoor allows admin access bypass (CVE-2026-11405)
Tenda routers running vulnerable firmware versions. Specific models and version ranges not disclosed in available data. Affects web management interface authentication mechanism.
criticalbug_reportVulnerabilityBeyondTrust Remote Support/PRA critical auth bypass (CVE-2026-40138)
BeyondTrust Remote Support and Privileged Remote Access (PRA) products. Specific affected versions not provided in available data. CVE-2026-40138 is a pre-authentication vulnerability with CVSS 9.2.