Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-20 · 02:03 UTC
articleTotal: 593 reports
Cyber Threat Daily Brief — July 20, 2026satellite_altDaily Brief
Threat Intel Brief·Daily Summary

Cyber Threat Daily Brief — July 20, 2026

Today's briefing: 3 critical and 4 high-severity threats. A total of 10 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.

3 Critical4 High10 analyses
schedule02:03 UTC
Read briefarrow_forward

Latest Reports

30 / 584 results
Drupal critical core vulnerability with imminent exploit riskcriticalbug_reportVulnerability
bug_reportVulnerability

Drupal critical core vulnerability with imminent exploit risk

Drupal core (specific versions not disclosed). All Drupal installations should be considered at risk until patched.

Drupal10:52 UTC
Webworm Deploys EchoCreep and GraphWorm Backdoors via Discord and Graph APIhighperson_alertThreat Actor
person_alertThreat Actor

Webworm Deploys EchoCreep and GraphWorm Backdoors via Discord and Graph API

Webworm is a China-aligned advanced persistent threat (APT) actor first documented by Symantec in September 2022, with activity traced back to at least 2022.

Microsoft10:51 UTC
PinTheft Linux privilege escalation PoC released for Arch Linuxhighbug_reportVulnerability
bug_reportVulnerability

PinTheft Linux privilege escalation PoC released for Arch Linux

Arch Linux systems. Specific affected package versions not disclosed; vulnerability has been patched in recent updates. Other Linux distributions may be affected depending on package configurations.

Arch Linux08:52 UTC
Microsoft mitigates YellowKey BitLocker bypass (CVE-2026-45585)highbug_reportVulnerability
bug_reportVulnerability

Microsoft mitigates YellowKey BitLocker bypass (CVE-2026-45585)

Microsoft BitLocker on Windows systems. Specific affected versions not disclosed. Vulnerability allows bypass of BitLocker disk encryption protections.

CVE-2026-4558506:28 UTC
Microsoft mitigates YellowKey BitLocker zero-day bypass vulnerabilityhighbug_reportVulnerability
bug_reportVulnerability

Microsoft mitigates YellowKey BitLocker zero-day bypass vulnerability

Windows BitLocker across all supported Windows versions. The vulnerability allows unauthorized access to BitLocker-protected drives. No CVE assigned yet.

Microsoft05:31 UTC
PostgreSQL patches multiple high-severity flaws; version 14 EOL announcedhighbug_reportVulnerability
bug_reportVulnerability

PostgreSQL patches multiple high-severity flaws; version 14 EOL announced

PostgreSQL database server, multiple versions affected by security vulnerabilities. Version 14 reaching end-of-life, no longer receiving security updates after EOL date.

PostgreSQL04:05 UTC
Critical Portainer vulnerabilities enable full host takeovercriticalbug_reportVulnerability
bug_reportVulnerability

Critical Portainer vulnerabilities enable full host takeover

Portainer container management platform. Specific affected versions not disclosed in summary; CERT.BE advisory should be consulted for version details. Impacts organizations using Portainer for Docker/Kubernetes management.

Portainer03:56 UTC
TeamPCP Lists GitHub Source Code for Sale After Repository Breachhighperson_alertThreat Actor
person_alertThreat Actor

TeamPCP Lists GitHub Source Code for Sale After Repository Breach

TeamPCP is a threat actor that has emerged in the cybercrime ecosystem, demonstrating capability to compromise high-value technology platforms. The actor's motivation appears financially driven, as evidenced by their decision to monetize stolen GitHu…

The Hacker News02:01 UTC
ChromaDB FastAPI RCE allows unauthenticated arbitrary code executioncriticalbug_reportVulnerability
bug_reportVulnerability

ChromaDB FastAPI RCE allows unauthenticated arbitrary code execution

ChromaDB latest Python FastAPI version. Affects exposed ChromaDB servers accessible over the network. No CVE assigned yet.

ChromaDB20:25 UTC
Microsoft Disrupts Malware-Signing-as-a-Service Operationhighperson_alertThreat Actor
person_alertThreat Actor

Microsoft Disrupts Malware-Signing-as-a-Service Operation

This operation involved cybercriminals abusing Microsoft's Artifact Signing service to provide malware-signing-as-a-service capabilities. The actors exploited legitimate code-signing infrastructure to generate fraudulent certificates, which were then…

BleepingComputer19:47 UTC
Fox Tempest Provides Malware-Signing Services to Ransomware Operatorshighperson_alertThreat Actor
person_alertThreat Actor

Fox Tempest Provides Malware-Signing Services to Ransomware Operators

Fox Tempest is a financially motivated cybercriminal actor that operates as a malware-signing service provider within the ransomware ecosystem. Rather than conducting attacks directly, Fox Tempest enables other threat actors—including Vanilla Tempest…

Microsoft Security13:07 UTC
Critical nginx vulnerabilities enable RCE and rate-limit bypasscriticalbug_reportVulnerability
bug_reportVulnerability

Critical nginx vulnerabilities enable RCE and rate-limit bypass

nginx web server (specific versions not provided by CERT.BE advisory). Affects organizations running vulnerable nginx instances, particularly those exposed to the internet or untrusted networks.

nginx13:05 UTC
PoC released for DirtyDecrypt LPE in Linux kernel (CVE-2026-31635)highbug_reportVulnerability
bug_reportVulnerability

PoC released for DirtyDecrypt LPE in Linux kernel (CVE-2026-31635)

Linux kernel - specific vulnerable versions not provided. Local privilege escalation vulnerability affecting systems running vulnerable kernel versions.

CVE-2026-3163512:56 UTC
Over 600 malicious npm packages published in Shai-Hulud campaignhighbug_reportVulnerability
bug_reportVulnerability

Over 600 malicious npm packages published in Shai-Hulud campaign

npm ecosystem: 600+ malicious packages published by threat actors. Affects organizations using npm for JavaScript/Node.js dependency management. Specific package names not provided in summary.

npm12:30 UTC
SonicWall releases patches for multiple high-severity vulnerabilitieshighbug_reportVulnerability
bug_reportVulnerability

SonicWall releases patches for multiple high-severity vulnerabilities

SonicWall products (specific models and versions not disclosed in summary). CERT.BE advisory indicates multiple vulnerabilities requiring immediate patching across SonicWall product line.

SonicWall12:27 UTC
ShinyHunters Claims 7-Eleven Data Breachhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Claims 7-Eleven Data Breach

ShinyHunters is a financially motivated cybercrime group known for large-scale data breaches and database theft. The group emerged around 2020 and has been linked to numerous high-profile data exfiltration incidents targeting organizations across var…

7-Eleven12:16 UTC
Microsoft sees rise in privilege escalation and identity abuse flawshighbug_reportVulnerability
bug_reportVulnerability

Microsoft sees rise in privilege escalation and identity abuse flaws

Microsoft products and services experiencing increased critical vulnerabilities focused on privilege escalation and identity abuse. Specific affected products and versions not detailed in available data.

Microsoft12:00 UTC
ABB CoreSense path traversal flaw allows unauthenticated system accesshighbug_reportVulnerability
bug_reportVulnerability

ABB CoreSense path traversal flaw allows unauthenticated system access

ABB CoreSense HM (versions prior to v2.3.4) and CoreSense M10 (versions prior to v1.4.1.31). Path traversal vulnerability affects unauthenticated remote attackers.

CVE-2025-346510:00 UTC
ScadaBR 1.2.0 critical flaws enable unauthenticated remote code executioncriticalbug_reportVulnerability
bug_reportVulnerability

ScadaBR 1.2.0 critical flaws enable unauthenticated remote code execution

ScadaBR version 1.2.0, a SCADA system used in critical infrastructure sectors including energy, water, and manufacturing worldwide. All four CVEs affect the same version.

CVE-2026-860210:00 UTC
ZKTeco CCTV cameras expose credentials via unauthenticated config portcriticalbug_reportVulnerability
bug_reportVulnerability

ZKTeco CCTV cameras expose credentials via unauthenticated config port

ZKTeco CCTV cameras, specifically model SSC335-GC2063-Face-0b77, running firmware versions prior to V5.0.1.2.20260421. Vulnerability affects an undocumented configuration export port that allows unauthenticated access to camera credentials and config…

CVE-2026-859810:00 UTC
Kieback & Peter DDC controllers vulnerable to XSS attackshighbug_reportVulnerability
bug_reportVulnerability

Kieback & Peter DDC controllers vulnerable to XSS attacks

Kieback & Peter DDC (Direct Digital Control) Building Controllers. Specific affected versions not disclosed in available data.

CVE-2026-429310:00 UTC
Buffer overflow in PAN-OS User-ID portal enables unauthenticated RCEhighbug_reportVulnerability
bug_reportVulnerability

Buffer overflow in PAN-OS User-ID portal enables unauthenticated RCE

Palo Alto Networks PAN-OS on PA-Series and VM-Series firewalls; Siemens RUGGEDCOM APE1808 devices. Specific affected PAN-OS versions not provided in summary.

CVE-2026-030010:00 UTC
Microsoft Exchange Server XSS flaw actively exploited for session hijackingcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft Exchange Server XSS flaw actively exploited for session hijacking

Microsoft Exchange Server (specific versions not disclosed). Cross-Site Scripting vulnerability enabling spoofing and session hijacking. No CVE assigned yet.

Microsoft13:25 UTC
Critical PAN-OS vulnerabilities enable auth bypass and code executioncriticalbug_reportVulnerability
bug_reportVulnerability

Critical PAN-OS vulnerabilities enable auth bypass and code execution

Palo Alto Networks PAN-OS (specific versions not provided in summary). Affects authentication controls, code execution surface, and availability.

Palo Alto Networks12:43 UTC
Cisco Catalyst SD-WAN auth bypass grants admin access to attackerscriticalbug_reportVulnerability
bug_reportVulnerability

Cisco Catalyst SD-WAN auth bypass grants admin access to attackers

Cisco Catalyst SD-WAN platform. Specific affected versions not disclosed. Vulnerability allows authentication bypass leading to administrative access on SD-WAN infrastructure components.

Cisco12:16 UTC
Ivanti releases security updates for multiple productshighbug_reportVulnerability
bug_reportVulnerability

Ivanti releases security updates for multiple products

Multiple Ivanti products affected. Specific product names, versions, and CVE identifiers not disclosed in available information. High severity rating indicates significant security risk.

Ivanti07:55 UTC
Multiple critical vulnerabilities in Fortinet products require patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Multiple critical vulnerabilities in Fortinet products require patching

Fortinet products: FortiSandbox, FortiOS, FortiAP, FortiAnalyzer, and FortiManager. Specific affected versions not provided in advisory. Multiple vulnerabilities ranging from critical to medium severity.

Fortinet05:08 UTC
Code Runner MCP Server missing authentication flaw allows unauthorized accesshighbug_reportVulnerability
bug_reportVulnerability

Code Runner MCP Server missing authentication flaw allows unauthorized access

Code Runner MCP Server (all versions not specified). The vulnerability affects critical functions within the server, allowing unauthenticated access to protected operations. Specific version ranges have not been disclosed by CERT.PL.

CVE-2026-502908:55 UTC
3onedata GW1101 Modbus gateway vulnerable to OS command injectionhighbug_reportVulnerability
bug_reportVulnerability

3onedata GW1101 Modbus gateway vulnerable to OS command injection

3onedata GW1101-1D(RS-485)-TB-P Modbus gateways. Specific affected firmware versions not disclosed. These are industrial IoT devices used for Modbus protocol conversion in OT/ICS environments.

CVE-2025-1360512:55 UTC
NCSC UK Issues Guidance on China-Nexus Covert Device Networkshighperson_alertThreat Actor
person_alertThreat Actor

NCSC UK Issues Guidance on China-Nexus Covert Device Networks

China-nexus threat actors are state-sponsored groups linked to the People's Republic of China. These actors are motivated by strategic intelligence collection, espionage, and maintaining persistent access to foreign networks.

NCSC UK10:00 UTC