Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports
Cyber Threat Daily Brief — September 4, 2026satellite_altDaily Brief
Threat Intel Brief·Daily Summary

Cyber Threat Daily Brief — September 4, 2026

Today's briefing: 14 critical and 22 high-severity threats. A total of 47 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.

14 Critical22 High47 analyses
schedule02:17 UTC
Read briefarrow_forward

Latest Reports

28 / 1172 results
GeoNetwork RCE chain exploitable without authentication on gov geoportalscriticalbug_reportVulnerability
bug_reportVulnerability

GeoNetwork RCE chain exploitable without authentication on gov geoportals

GeoNetwork open-source geospatial metadata catalog: all 4.4.x versions up to 4.4.11 and all 4.2.x versions up to 4.2.16. Widely deployed in government, military, and national agency Spatial Data Infrastructure backends across 39 countries, including…

GeoNetwork2 Sep · 07:18 UTC
Russian National Charged for 2016-2017 Excel Malware Campaignhighperson_alertThreat Actor
person_alertThreat Actor

Russian National Charged for 2016-2017 Excel Malware Campaign

Searzhudin Tamirlanovich Aktulaev is a 40-year-old Russian national charged by the U.S. Department of Justice for orchestrating a large-scale malware distribution campaign between June 2016 and November 2017.

The Hacker News2 Sep · 07:10 UTC
Russian National Indicted for TVRAT/DarkVNC Phishing Campaignhighperson_alertThreat Actor
person_alertThreat Actor

Russian National Indicted for TVRAT/DarkVNC Phishing Campaign

Searzhudin Tamirlanovich Aktulaev, a 40-year-old Russian national, orchestrated a large-scale phishing campaign between June 2016 and November 2017. Motivated by financial fraud and credential theft, Aktulaev targeted freelancers on an unnamed freela…

BleepingComputer2 Sep · 07:06 UTC
Sality P2P botnet dismantled after 20+ years of operationhighbug_reportVulnerability
bug_reportVulnerability

Sality P2P botnet dismantled after 20+ years of operation

Sality botnet infrastructure (active since 2003), affecting 15,000+ infected devices globally. Primary payload in recent years: EggJagger clipjacking malware targeting cryptocurrency wallets.

BleepingComputer2 Sep · 06:00 UTC
SonicWall SMA1000 zero-days CVE-2026-83548/83549 chained for RCEcriticalbug_reportVulnerability
bug_reportVulnerability

SonicWall SMA1000 zero-days CVE-2026-83548/83549 chained for RCE

SonicWall SMA1000 appliances (models 6210, 7210, 8200v). Does not affect SSL-VPN on SonicWall firewalls or SMA 100 Series. Approximately 400+ appliances exposed online per Shadowserver tracking.

SonicWall2 Sep · 04:39 UTC
Active malware campaign uses fake vendor sites to deliver Silver Fox malwarehighbug_reportVulnerability
bug_reportVulnerability

Active malware campaign uses fake vendor sites to deliver Silver Fox malware

Organizations with China-based operations and Chinese-speaking users across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors.

Microsoft1 Sep · 20:48 UTC
Dark Web Service Sells 153M+ Driver Licenses from Identity Verification Breachcriticalperson_alertThreat Actor
person_alertThreat Actor

Dark Web Service Sells 153M+ Driver Licenses from Identity Verification Breach

The threat actor operates "Nexus," a dark web identity theft service launched on the Russian cybercrime forum Exploit in August 2025. The operator claims to have continuously exfiltrated data for over a year from an alleged breach at a major Louisian…

identity verification company based in Louisiana1 Sep · 20:40 UTC
Phishing Actors Abuse Faronics Deploy for ScreenConnect Installationhighperson_alertThreat Actor
person_alertThreat Actor

Phishing Actors Abuse Faronics Deploy for ScreenConnect Installation

The actors are unattributed phishing operators conducting opportunistic attacks against organizations using social engineering lures. Between July 21 and August 20, 2026, they targeted over 457 endpoints with phishing emails disguised as invoices, ta…

Faronics1 Sep · 18:53 UTC
Langflow CVE-2026-0768 exploited to steal OpenAI and AWS credentialscriticalbug_reportVulnerability
bug_reportVulnerability

Langflow CVE-2026-0768 exploited to steal OpenAI and AWS credentials

Langflow versions 1.4.2 and earlier. The vulnerability exists in the code validator of the custom component editor's validate endpoint. Patched in version 1.11.6.

CVE-2026-07681 Sep · 15:54 UTC
JFrog Artifactory auth bypass CVE-2026-82329 under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

JFrog Artifactory auth bypass CVE-2026-82329 under active exploitation

JFrog Artifactory versions 7.161.0-7.161.19, 7.146.0-7.146.36, 7.133.0-7.133.28, 7.125.0-7.125.19, 7.117.0-7.117.27, and 7.111.4-7.111.21. Affects default configurations of self-managed instances. JFrog Access component specifically vulnerable.

CVE-2026-823291 Sep · 15:53 UTC
Breeze Comet Targets Brazilian Financial Sector for Payment Fraudhighperson_alertThreat Actor
person_alertThreat Actor

Breeze Comet Targets Brazilian Financial Sector for Payment Fraud

Breeze Comet (formerly UNC5669, overlaps with Plump Spider and SHADOW-AETHER-064) is a financially motivated threat actor operating out of Brazil since September 2023.

The Hacker News1 Sep · 15:19 UTC
JFrog Artifactory authentication bypass requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

JFrog Artifactory authentication bypass requires immediate patching

JFrog Artifactory - specific affected versions not disclosed in advisory. Authentication bypass vulnerability allows unauthorized access to artifact repository.

JFrog1 Sep · 13:13 UTC
BGP hijack delivers malicious Virtualizor updates to VPS management systemscriticalbug_reportVulnerability
bug_reportVulnerability

BGP hijack delivers malicious Virtualizor updates to VPS management systems

Virtualizor VPS management software (all versions prior to 3.2.9.9) from Softaculous. Attack window: August 28, 2026 20:57 UTC to August 30, 2026 06:10 UTC.

Virtualizor1 Sep · 12:45 UTC
Novocure breach exposes 1,400+ U.S. cancer patient recordshighpublicGeopolitical
publicGeopolitical

Novocure breach exposes 1,400+ U.S. cancer patient records

The Novocure incident reflects the sustained targeting of healthcare infrastructure, particularly oncology and patient data repositories, which has intensified across North American providers since late 2025.

Novocure1 Sep · 12:28 UTC
13 malicious Packagist packages target iOS devices to steal crypto walletshighbug_reportVulnerability
bug_reportVulnerability

13 malicious Packagist packages target iOS devices to steal crypto wallets

Packagist/Composer ecosystem: 13 malicious theme packages across 5 vendor namespaces (vsmov, vsphim, haiau009, chilltvcms, ophimcms). Targets Vietnamese streaming sites using OphimCMS/KKPhim.

Packagist1 Sep · 12:07 UTC
Nimbus Manticore Deploys Cross-Platform RATs via Fake Job Coding Testshighperson_alertThreat Actor
person_alertThreat Actor

Nimbus Manticore Deploys Cross-Platform RATs via Fake Job Coding Tests

Nimbus Manticore is an Iranian threat actor also tracked as Iranian Dream Job, known for using recruitment-themed social engineering lures to compromise targets.

The Hacker News1 Sep · 11:08 UTC
22K Exchange servers unpatched for CVE-2026-62911 auth bypass flawhighbug_reportVulnerability
bug_reportVulnerability

22K Exchange servers unpatched for CVE-2026-62911 auth bypass flaw

Microsoft Exchange Server 2016, 2019, and Subscription Edition (SE). Approximately 21,899 internet-exposed servers remain unpatched globally, with highest concentrations in the United States (6,200) and Germany (5,100).

Microsoft1 Sep · 10:38 UTC
ClickFix Operators Dominate Initial Access via Social Engineeringhighperson_alertThreat Actor
person_alertThreat Actor

ClickFix Operators Dominate Initial Access via Social Engineering

ClickFix operators are threat actors leveraging a social engineering technique that manipulates users into executing malicious commands through clipboard manipulation.

Microsoft1 Sep · 09:30 UTC
Latvia's cyber threat level remains high amid Russia-linked activityhighpublicGeopolitical
publicGeopolitical

Latvia's cyber threat level remains high amid Russia-linked activity

Latvia's elevated cybersecurity posture reflects its position as a NATO frontline state and vocal supporter of Ukraine. CERT.LV's Q2 2026 report indicates that while incident volumes have moderated from peak levels, they remain substantially above hi…

CERT.LV (Latvia)1 Sep · 09:25 UTC
Venezuelan ATM Jackpotting Group Targets U.S. Financial Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

Venezuelan ATM Jackpotting Group Targets U.S. Financial Infrastructure

This threat actor is a coordinated group of Venezuelan nationals conducting ATM jackpotting operations targeting financial institutions in the United States.

BleepingComputer1 Sep · 07:15 UTC
UAC-0099 Deploys GuardBreaker to Sabotage AI-Assisted Malware Analysishighperson_alertThreat Actor
person_alertThreat Actor

UAC-0099 Deploys GuardBreaker to Sabotage AI-Assisted Malware Analysis

UAC-0099 is a Russia-aligned threat actor with a history of targeting Ukraine's transportation and energy sectors. The group demonstrates tactical innovation by adapting emerging anti-AI analysis techniques to evade detection.

The Hacker News1 Sep · 06:26 UTC
PaperCut NG/MF zero-days exploited for data theft via auth bypass and RCEhighbug_reportVulnerability
bug_reportVulnerability

PaperCut NG/MF zero-days exploited for data theft via auth bypass and RCE

PaperCut NG and MF print management software, all versions prior to Emergency Patch Release 3 (issued September 2026). Affects internet-facing Application Servers.

PaperCut1 Sep · 05:48 UTC
Langflow and Ruby on Rails flaws actively exploited for RCE and C2criticalbug_reportVulnerability
bug_reportVulnerability

Langflow and Ruby on Rails flaws actively exploited for RCE and C2

Langflow (CVE-2026-0768, CVSS 9.8): arbitrary Python code execution as root via improper input validation. Ruby on Rails (CVE-2026-66066 aka KindaRails2Shell, CVSS 9.5): unauthenticated arbitrary file read, secret leakage, and RCE in applications usi…

CVE-2026-07681 Sep · 05:22 UTC
TerminalFix campaign uses fake CAPTCHAs to deploy reverse tunnelshighbug_reportVulnerability
bug_reportVulnerability

TerminalFix campaign uses fake CAPTCHAs to deploy reverse tunnels

Windows systems with PowerShell and Windows Terminal enabled. Targets organizations with Active Directory environments. Attack vector: compromised websites displaying fake Cloudflare CAPTCHA prompts.

Microsoft31 Aug · 16:51 UTC
North Korean IT Worker Scheme Expands Into Healthcare and Sales Roleshighperson_alertThreat Actor
person_alertThreat Actor

North Korean IT Worker Scheme Expands Into Healthcare and Sales Roles

North Korean state-sponsored threat actors, tracked as Famous Chollima, Jasper Sleet, Nickel Tapestry, PurpleDelta (formerly TAG-121), UNC5267, and Wagemole, operate a sophisticated job fraud scheme to generate revenue for the DPRK's nuclear weapons…

The Hacker News31 Aug · 15:24 UTC
Fire Ant compromises Cisco routers for network surveillancehighperson_alertThreat Actor
person_alertThreat Actor

Fire Ant compromises Cisco routers for network surveillance

Fire Ant is a Chinese espionage-focused threat actor attributed by Sygnia, with operational overlap to UNC3886 (previously documented by Google). The group targets critical infrastructure and high-value networks through a "target behind the target" s…

Cisco31 Aug · 12:52 UTC
Rhysida ransomware gang breaches Berlin city administrationhighperson_alertThreat Actor
person_alertThreat Actor

Rhysida ransomware gang breaches Berlin city administration

Rhysida is a ransomware-as-a-service (RaaS) operation active since mid-2023, conducting double-extortion attacks against high-value targets. The group exfiltrates sensitive data before deploying ransomware, then threatens public disclosure to pressur…

Berlin city administration31 Aug · 11:30 UTC
Silver Fox Distributes ValleyRAT via Signed Chinese Adwarehighperson_alertThreat Actor
person_alertThreat Actor

Silver Fox Distributes ValleyRAT via Signed Chinese Adware

Silver Fox is a threat actor attributed by Kaspersky to campaigns distributing the ValleyRAT backdoor (also tracked as Winos 4.0). The group has demonstrated consistent use of DLL sideloading techniques leveraging legitimate, signed software to evade…

Kaspersky31 Aug · 10:14 UTC