Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
satellite_altDaily BriefCyber Threat Daily Brief — July 20, 2026
Today's briefing: 3 critical and 4 high-severity threats. A total of 10 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.
Latest Reports
30 / 584 results
criticalbug_reportVulnerabilityDrupal critical core vulnerability with imminent exploit risk
Drupal core (specific versions not disclosed). All Drupal installations should be considered at risk until patched.
highperson_alertThreat ActorWebworm Deploys EchoCreep and GraphWorm Backdoors via Discord and Graph API
Webworm is a China-aligned advanced persistent threat (APT) actor first documented by Symantec in September 2022, with activity traced back to at least 2022.
highbug_reportVulnerabilityPinTheft Linux privilege escalation PoC released for Arch Linux
Arch Linux systems. Specific affected package versions not disclosed; vulnerability has been patched in recent updates. Other Linux distributions may be affected depending on package configurations.
highbug_reportVulnerabilityMicrosoft mitigates YellowKey BitLocker bypass (CVE-2026-45585)
Microsoft BitLocker on Windows systems. Specific affected versions not disclosed. Vulnerability allows bypass of BitLocker disk encryption protections.
highbug_reportVulnerabilityMicrosoft mitigates YellowKey BitLocker zero-day bypass vulnerability
Windows BitLocker across all supported Windows versions. The vulnerability allows unauthorized access to BitLocker-protected drives. No CVE assigned yet.
highbug_reportVulnerabilityPostgreSQL patches multiple high-severity flaws; version 14 EOL announced
PostgreSQL database server, multiple versions affected by security vulnerabilities. Version 14 reaching end-of-life, no longer receiving security updates after EOL date.
criticalbug_reportVulnerabilityCritical Portainer vulnerabilities enable full host takeover
Portainer container management platform. Specific affected versions not disclosed in summary; CERT.BE advisory should be consulted for version details. Impacts organizations using Portainer for Docker/Kubernetes management.
highperson_alertThreat ActorTeamPCP Lists GitHub Source Code for Sale After Repository Breach
TeamPCP is a threat actor that has emerged in the cybercrime ecosystem, demonstrating capability to compromise high-value technology platforms. The actor's motivation appears financially driven, as evidenced by their decision to monetize stolen GitHu…
criticalbug_reportVulnerabilityChromaDB FastAPI RCE allows unauthenticated arbitrary code execution
ChromaDB latest Python FastAPI version. Affects exposed ChromaDB servers accessible over the network. No CVE assigned yet.
highperson_alertThreat ActorMicrosoft Disrupts Malware-Signing-as-a-Service Operation
This operation involved cybercriminals abusing Microsoft's Artifact Signing service to provide malware-signing-as-a-service capabilities. The actors exploited legitimate code-signing infrastructure to generate fraudulent certificates, which were then…
highperson_alertThreat ActorFox Tempest Provides Malware-Signing Services to Ransomware Operators
Fox Tempest is a financially motivated cybercriminal actor that operates as a malware-signing service provider within the ransomware ecosystem. Rather than conducting attacks directly, Fox Tempest enables other threat actors—including Vanilla Tempest…
criticalbug_reportVulnerabilityCritical nginx vulnerabilities enable RCE and rate-limit bypass
nginx web server (specific versions not provided by CERT.BE advisory). Affects organizations running vulnerable nginx instances, particularly those exposed to the internet or untrusted networks.
highbug_reportVulnerabilityPoC released for DirtyDecrypt LPE in Linux kernel (CVE-2026-31635)
Linux kernel - specific vulnerable versions not provided. Local privilege escalation vulnerability affecting systems running vulnerable kernel versions.
highbug_reportVulnerabilityOver 600 malicious npm packages published in Shai-Hulud campaign
npm ecosystem: 600+ malicious packages published by threat actors. Affects organizations using npm for JavaScript/Node.js dependency management. Specific package names not provided in summary.
highbug_reportVulnerabilitySonicWall releases patches for multiple high-severity vulnerabilities
SonicWall products (specific models and versions not disclosed in summary). CERT.BE advisory indicates multiple vulnerabilities requiring immediate patching across SonicWall product line.
highperson_alertThreat ActorShinyHunters Claims 7-Eleven Data Breach
ShinyHunters is a financially motivated cybercrime group known for large-scale data breaches and database theft. The group emerged around 2020 and has been linked to numerous high-profile data exfiltration incidents targeting organizations across var…
highbug_reportVulnerabilityMicrosoft sees rise in privilege escalation and identity abuse flaws
Microsoft products and services experiencing increased critical vulnerabilities focused on privilege escalation and identity abuse. Specific affected products and versions not detailed in available data.
highbug_reportVulnerabilityABB CoreSense path traversal flaw allows unauthenticated system access
ABB CoreSense HM (versions prior to v2.3.4) and CoreSense M10 (versions prior to v1.4.1.31). Path traversal vulnerability affects unauthenticated remote attackers.
criticalbug_reportVulnerabilityScadaBR 1.2.0 critical flaws enable unauthenticated remote code execution
ScadaBR version 1.2.0, a SCADA system used in critical infrastructure sectors including energy, water, and manufacturing worldwide. All four CVEs affect the same version.
criticalbug_reportVulnerabilityZKTeco CCTV cameras expose credentials via unauthenticated config port
ZKTeco CCTV cameras, specifically model SSC335-GC2063-Face-0b77, running firmware versions prior to V5.0.1.2.20260421. Vulnerability affects an undocumented configuration export port that allows unauthenticated access to camera credentials and config…
highbug_reportVulnerabilityKieback & Peter DDC controllers vulnerable to XSS attacks
Kieback & Peter DDC (Direct Digital Control) Building Controllers. Specific affected versions not disclosed in available data.
highbug_reportVulnerabilityBuffer overflow in PAN-OS User-ID portal enables unauthenticated RCE
Palo Alto Networks PAN-OS on PA-Series and VM-Series firewalls; Siemens RUGGEDCOM APE1808 devices. Specific affected PAN-OS versions not provided in summary.
criticalbug_reportVulnerabilityMicrosoft Exchange Server XSS flaw actively exploited for session hijacking
Microsoft Exchange Server (specific versions not disclosed). Cross-Site Scripting vulnerability enabling spoofing and session hijacking. No CVE assigned yet.
criticalbug_reportVulnerabilityCritical PAN-OS vulnerabilities enable auth bypass and code execution
Palo Alto Networks PAN-OS (specific versions not provided in summary). Affects authentication controls, code execution surface, and availability.
criticalbug_reportVulnerabilityCisco Catalyst SD-WAN auth bypass grants admin access to attackers
Cisco Catalyst SD-WAN platform. Specific affected versions not disclosed. Vulnerability allows authentication bypass leading to administrative access on SD-WAN infrastructure components.
highbug_reportVulnerabilityIvanti releases security updates for multiple products
Multiple Ivanti products affected. Specific product names, versions, and CVE identifiers not disclosed in available information. High severity rating indicates significant security risk.
criticalbug_reportVulnerabilityMultiple critical vulnerabilities in Fortinet products require patching
Fortinet products: FortiSandbox, FortiOS, FortiAP, FortiAnalyzer, and FortiManager. Specific affected versions not provided in advisory. Multiple vulnerabilities ranging from critical to medium severity.
highbug_reportVulnerabilityCode Runner MCP Server missing authentication flaw allows unauthorized access
Code Runner MCP Server (all versions not specified). The vulnerability affects critical functions within the server, allowing unauthenticated access to protected operations. Specific version ranges have not been disclosed by CERT.PL.
highbug_reportVulnerability3onedata GW1101 Modbus gateway vulnerable to OS command injection
3onedata GW1101-1D(RS-485)-TB-P Modbus gateways. Specific affected firmware versions not disclosed. These are industrial IoT devices used for Modbus protocol conversion in OT/ICS environments.
highperson_alertThreat ActorNCSC UK Issues Guidance on China-Nexus Covert Device Networks
China-nexus threat actors are state-sponsored groups linked to the People's Republic of China. These actors are motivated by strategic intelligence collection, espionage, and maintaining persistent access to foreign networks.