Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-20 · 02:03 UTC
articleTotal: 593 reports
Cyber Threat Daily Brief — July 20, 2026satellite_altDaily Brief
Threat Intel Brief·Daily Summary

Cyber Threat Daily Brief — July 20, 2026

Today's briefing: 3 critical and 4 high-severity threats. A total of 10 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.

3 Critical4 High10 analyses
schedule02:03 UTC
Read briefarrow_forward

Latest Reports

28 / 588 results
KDDI breach exposes 12M records across Japanese ISP ecosystemhighpublicGeopolitical
publicGeopolitical

KDDI breach exposes 12M records across Japanese ISP ecosystem

The breach of KDDI, one of Japan's three major telecommunications carriers, represents a significant compromise of critical infrastructure in a key U.S. Indo-Pacific ally.

KDDI09:24 UTC
CISA orders federal patch for exploited Langflow auth bypass by Fridaycriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders federal patch for exploited Langflow auth bypass by Friday

Langflow visual AI agent framework - specific versions not disclosed in summary. Federal agencies mandated to patch; private sector should assume all unpatched instances at risk.

Langflow07:58 UTC
UAT-7810 Expands ORB Network with LONGLEASH Malware on Edge Deviceshighperson_alertThreat Actor
person_alertThreat Actor

UAT-7810 Expands ORB Network with LONGLEASH Malware on Edge Devices

UAT-7810 is a China-linked advanced persistent threat (APT) actor focused on compromising internet-facing networking and infrastructure devices to build and maintain an Operational Relay Box (ORB) network designated LapDogs.

The Hacker News07:04 UTC
Ubiquiti patches 7 critical flaws in UniFi OS, including max-severity RCEcriticalbug_reportVulnerability
bug_reportVulnerability

Ubiquiti patches 7 critical flaws in UniFi OS, including max-severity RCE

Ubiquiti UniFi OS - specific vulnerable versions not disclosed. Seven critical vulnerabilities patched, including one maximum-severity (CVSS 10.0) command injection flaw enabling remote code execution.

Ubiquiti06:15 UTC
CISA orders patching of actively exploited Adobe ColdFusion flawcriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders patching of actively exploited Adobe ColdFusion flaw

Adobe ColdFusion commercial web application development platform. Specific affected versions not disclosed in summary, but CISA mandatory patching order indicates government-facing installations are priority targets.

Adobe05:16 UTC
15-year-old Linux kernel flaw allows local privilege escalation to rootcriticalbug_reportVulnerability
bug_reportVulnerability

15-year-old Linux kernel flaw allows local privilege escalation to root

Linux kernel versions since 2011 across all mainstream distributions (Ubuntu, RHEL, Debian, SUSE, etc.). Any system running an unpatched kernel containing CVE-2026-43499 is vulnerable. Requires local authenticated access to exploit.

CVE-2026-4349904:16 UTC
Vidar Stealer campaign uses Go-based DLL sideloading and code signing abusehighbug_reportVulnerability
bug_reportVulnerability

Vidar Stealer campaign uses Go-based DLL sideloading and code signing abuse

Organizations using Windows systems are targeted. Campaign abuses legitimate Windows Defender components (MpClient.dll sideloading) via loader-as-a-service framework.

Unit 42 (Palo Alto)20:00 UTC
UAT-7810 Deploys LONGLEASH Malware Against Network Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

UAT-7810 Deploys LONGLEASH Malware Against Network Infrastructure

UAT-7810 is a Chinese-linked threat actor focused on compromising internet-facing networking devices to expand their Operational Relay Box (ORB) network infrastructure.

Ruckus16:52 UTC
Hidden backdoor in Tenda routers grants admin access to web panelhighbug_reportVulnerability
bug_reportVulnerability

Hidden backdoor in Tenda routers grants admin access to web panel

Multiple Tenda router models and firmware versions contain a hidden authentication backdoor affecting the web management interface. Specific affected models and versions not disclosed in available information.

Tenda15:27 UTC
RedWing Android MaaS enables bank fraud via credential thefthighbug_reportVulnerability
bug_reportVulnerability

RedWing Android MaaS enables bank fraud via credential theft

Android devices targeted by RedWing malware, distributed as Malware-as-a-Service on Telegram. Variant of Oblivion MaaS. Primarily affects banking applications and users with compromised devices.

The Hacker News15:10 UTC
Google Dialogflow CX flaw lets attackers hijack agents in same GCP projectcriticalbug_reportVulnerability
bug_reportVulnerability

Google Dialogflow CX flaw lets attackers hijack agents in same GCP project

Google Dialogflow CX agents with Code Block feature enabled, within shared Google Cloud projects. Requires attacker to have edit rights on at least one agent in the project.

Google14:37 UTC
DEBULL Campaign Exploits Microsoft Device Code Flow for M365 Phishinghighperson_alertThreat Actor
person_alertThreat Actor

DEBULL Campaign Exploits Microsoft Device Code Flow for M365 Phishing

DEBULL is a phishing campaign active from late June through early July 2026, targeting Microsoft 365 accounts through abuse of Microsoft's legitimate device-code flow authentication mechanism.

Microsoft13:14 UTC
GitHub Agentic Workflows leak private repo data via public issueshighbug_reportVulnerability
bug_reportVulnerability

GitHub Agentic Workflows leak private repo data via public issues

GitHub Agentic Workflows with cross-repository read access. Organizations using GitHub agents that can access both public and private repositories are vulnerable. No CVE assigned yet.

GitHub12:04 UTC
Scattered Spider Linked to U.S. Luxury Retail Breach via Device IDhighperson_alertThreat Actor
person_alertThreat Actor

Scattered Spider Linked to U.S. Luxury Retail Breach via Device ID

Scattered Spider (also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944) is a financially motivated threat actor known for sophisticated social engineering and identity-focused attacks.

The Hacker News11:27 UTC
Writer AI platform session isolation flaw enables cross-tenant accesscriticalbug_reportVulnerability
bug_reportVulnerability

Writer AI platform session isolation flaw enables cross-tenant access

Writer enterprise AI platform. Specific affected versions not disclosed. Vulnerability impacts agent preview functionality allowing cross-tenant session token leakage and unauthorized access.

Writer11:27 UTC
16-year-old Linux kernel flaw enables VM escape on Intel and AMD hostshighbug_reportVulnerability
bug_reportVulnerability

16-year-old Linux kernel flaw enables VM escape on Intel and AMD hosts

Linux kernel (specific versions not disclosed); affects virtualization environments on Intel and AMD processors. VM escape vulnerability impacts hypervisors relying on affected kernel versions.

Linux10:06 UTC
China-Aligned Cluster Exploits Roundcube Flaws at Universitieshighperson_alertThreat Actor
person_alertThreat Actor

China-Aligned Cluster Exploits Roundcube Flaws at Universities

This activity cluster is attributed to China-aligned threat actors targeting academic institutions in North America. The group demonstrates a clear strategic interest in research and development sectors, specifically physics and engineering departmen…

CVE-2024-4200907:10 UTC
BeyondTrust RS and PRA authentication bypass flaws require patchingcriticalbug_reportVulnerability
bug_reportVulnerability

BeyondTrust RS and PRA authentication bypass flaws require patching

BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) software. Specific affected versions not provided in available data.

BeyondTrust06:12 UTC
Tenda router backdoor allows admin access bypass (CVE-2026-11405)criticalbug_reportVulnerability
bug_reportVulnerability

Tenda router backdoor allows admin access bypass (CVE-2026-11405)

Tenda routers running vulnerable firmware versions. Specific models and version ranges not disclosed in available data. Affects web management interface authentication mechanism.

CVE-2026-1140504:40 UTC
BeyondTrust Remote Support/PRA critical auth bypass (CVE-2026-40138)criticalbug_reportVulnerability
bug_reportVulnerability

BeyondTrust Remote Support/PRA critical auth bypass (CVE-2026-40138)

BeyondTrust Remote Support and Privileged Remote Access (PRA) products. Specific affected versions not provided in available data. CVE-2026-40138 is a pre-authentication vulnerability with CVSS 9.2.

CVE-2026-4013803:16 UTC
Phishing campaign targets marketing professionals via fake job interviewshighbug_reportVulnerability
bug_reportVulnerability

Phishing campaign targets marketing professionals via fake job interviews

Marketing professionals with Google accounts; campaign impersonates 30+ brands including Adobe, Netflix, Coca-Cola, OpenAI. Credential theft targeting Google accounts specifically.

Adobe18:27 UTC
Attackers impersonate IT support on Teams calls to deploy EtherRAThighbug_reportVulnerability
bug_reportVulnerability

Attackers impersonate IT support on Teams calls to deploy EtherRAT

Organizations using Microsoft Teams for internal communications. All industries are potential targets. The campaign exploits user trust in voice-based IT support interactions rather than a technical vulnerability in Teams itself.

Microsoft18:23 UTC
Iran-linked MOIS group deploys Cavern C2 framework against Israelhighperson_alertThreat Actor
person_alertThreat Actor

Iran-linked MOIS group deploys Cavern C2 framework against Israel

An Iranian threat actor affiliated with Iran's Ministry of Intelligence and Security (MOIS), tracked by Check Point Research. The group operates in support of Iranian state intelligence objectives, focusing on espionage operations against adversary n…

The Hacker News16:34 UTC
16-year KVM hypervisor flaw enables guest-to-host kernel corruptioncriticalbug_reportVulnerability
bug_reportVulnerability

16-year KVM hypervisor flaw enables guest-to-host kernel corruption

Linux KVM hypervisor on Intel and AMD x86 systems. All Linux kernel versions containing the vulnerable shadow MMU code (approximately 16 years of releases).

CVE-2026-5335915:37 UTC
Gitea Docker auth bypass under active probing (CVE-2026-20896)criticalbug_reportVulnerability
bug_reportVulnerability

Gitea Docker auth bypass under active probing (CVE-2026-20896)

Gitea Docker images with improper X-WEBAUTH-USER header validation. Specific vulnerable versions not provided; affects deployments trusting reverse proxy authentication headers without IP restrictions.

CVE-2026-2089614:28 UTC
Adobe ColdFusion CVE-2026-48282 under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Adobe ColdFusion CVE-2026-48282 under active exploitation

Adobe ColdFusion (specific versions not disclosed). Maximum severity vulnerability actively exploited in the wild.

CVE-2026-4828211:18 UTC
China-nexus actor targets Indian finance sector via DcRAT malwarehighperson_alertThreat Actor
person_alertThreat Actor

China-nexus actor targets Indian finance sector via DcRAT malware

A suspected China-nexus threat actor is conducting Operation DragonReturn, a targeted espionage campaign against Indian taxpayers and finance professionals.

The Hacker News08:58 UTC
Opera GX patched silent add-on install flaw enabling data thefthighbug_reportVulnerability
bug_reportVulnerability

Opera GX patched silent add-on install flaw enabling data theft

Opera GX browser (specific versions not disclosed). Vulnerability allowed malicious websites to install browser extensions without user consent, enabling content extraction from visited pages including email addresses and other sensitive data.

Opera05:27 UTC