Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
satellite_altDaily BriefCyber Threat Daily Brief — July 20, 2026
Today's briefing: 3 critical and 4 high-severity threats. A total of 10 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.
Latest Reports
28 / 588 results
highpublicGeopoliticalKDDI breach exposes 12M records across Japanese ISP ecosystem
The breach of KDDI, one of Japan's three major telecommunications carriers, represents a significant compromise of critical infrastructure in a key U.S. Indo-Pacific ally.
criticalbug_reportVulnerabilityCISA orders federal patch for exploited Langflow auth bypass by Friday
Langflow visual AI agent framework - specific versions not disclosed in summary. Federal agencies mandated to patch; private sector should assume all unpatched instances at risk.
highperson_alertThreat ActorUAT-7810 Expands ORB Network with LONGLEASH Malware on Edge Devices
UAT-7810 is a China-linked advanced persistent threat (APT) actor focused on compromising internet-facing networking and infrastructure devices to build and maintain an Operational Relay Box (ORB) network designated LapDogs.
criticalbug_reportVulnerabilityUbiquiti patches 7 critical flaws in UniFi OS, including max-severity RCE
Ubiquiti UniFi OS - specific vulnerable versions not disclosed. Seven critical vulnerabilities patched, including one maximum-severity (CVSS 10.0) command injection flaw enabling remote code execution.
criticalbug_reportVulnerabilityCISA orders patching of actively exploited Adobe ColdFusion flaw
Adobe ColdFusion commercial web application development platform. Specific affected versions not disclosed in summary, but CISA mandatory patching order indicates government-facing installations are priority targets.
criticalbug_reportVulnerability15-year-old Linux kernel flaw allows local privilege escalation to root
Linux kernel versions since 2011 across all mainstream distributions (Ubuntu, RHEL, Debian, SUSE, etc.). Any system running an unpatched kernel containing CVE-2026-43499 is vulnerable. Requires local authenticated access to exploit.
highbug_reportVulnerabilityVidar Stealer campaign uses Go-based DLL sideloading and code signing abuse
Organizations using Windows systems are targeted. Campaign abuses legitimate Windows Defender components (MpClient.dll sideloading) via loader-as-a-service framework.
highperson_alertThreat ActorUAT-7810 Deploys LONGLEASH Malware Against Network Infrastructure
UAT-7810 is a Chinese-linked threat actor focused on compromising internet-facing networking devices to expand their Operational Relay Box (ORB) network infrastructure.
highbug_reportVulnerabilityHidden backdoor in Tenda routers grants admin access to web panel
Multiple Tenda router models and firmware versions contain a hidden authentication backdoor affecting the web management interface. Specific affected models and versions not disclosed in available information.
highbug_reportVulnerabilityRedWing Android MaaS enables bank fraud via credential theft
Android devices targeted by RedWing malware, distributed as Malware-as-a-Service on Telegram. Variant of Oblivion MaaS. Primarily affects banking applications and users with compromised devices.
criticalbug_reportVulnerabilityGoogle Dialogflow CX flaw lets attackers hijack agents in same GCP project
Google Dialogflow CX agents with Code Block feature enabled, within shared Google Cloud projects. Requires attacker to have edit rights on at least one agent in the project.
highperson_alertThreat ActorDEBULL Campaign Exploits Microsoft Device Code Flow for M365 Phishing
DEBULL is a phishing campaign active from late June through early July 2026, targeting Microsoft 365 accounts through abuse of Microsoft's legitimate device-code flow authentication mechanism.
highbug_reportVulnerabilityGitHub Agentic Workflows leak private repo data via public issues
GitHub Agentic Workflows with cross-repository read access. Organizations using GitHub agents that can access both public and private repositories are vulnerable. No CVE assigned yet.
highperson_alertThreat ActorScattered Spider Linked to U.S. Luxury Retail Breach via Device ID
Scattered Spider (also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944) is a financially motivated threat actor known for sophisticated social engineering and identity-focused attacks.
criticalbug_reportVulnerabilityWriter AI platform session isolation flaw enables cross-tenant access
Writer enterprise AI platform. Specific affected versions not disclosed. Vulnerability impacts agent preview functionality allowing cross-tenant session token leakage and unauthorized access.
highbug_reportVulnerability16-year-old Linux kernel flaw enables VM escape on Intel and AMD hosts
Linux kernel (specific versions not disclosed); affects virtualization environments on Intel and AMD processors. VM escape vulnerability impacts hypervisors relying on affected kernel versions.
highperson_alertThreat ActorChina-Aligned Cluster Exploits Roundcube Flaws at Universities
This activity cluster is attributed to China-aligned threat actors targeting academic institutions in North America. The group demonstrates a clear strategic interest in research and development sectors, specifically physics and engineering departmen…
criticalbug_reportVulnerabilityBeyondTrust RS and PRA authentication bypass flaws require patching
BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) software. Specific affected versions not provided in available data.
criticalbug_reportVulnerabilityTenda router backdoor allows admin access bypass (CVE-2026-11405)
Tenda routers running vulnerable firmware versions. Specific models and version ranges not disclosed in available data. Affects web management interface authentication mechanism.
criticalbug_reportVulnerabilityBeyondTrust Remote Support/PRA critical auth bypass (CVE-2026-40138)
BeyondTrust Remote Support and Privileged Remote Access (PRA) products. Specific affected versions not provided in available data. CVE-2026-40138 is a pre-authentication vulnerability with CVSS 9.2.
highbug_reportVulnerabilityPhishing campaign targets marketing professionals via fake job interviews
Marketing professionals with Google accounts; campaign impersonates 30+ brands including Adobe, Netflix, Coca-Cola, OpenAI. Credential theft targeting Google accounts specifically.
highbug_reportVulnerabilityAttackers impersonate IT support on Teams calls to deploy EtherRAT
Organizations using Microsoft Teams for internal communications. All industries are potential targets. The campaign exploits user trust in voice-based IT support interactions rather than a technical vulnerability in Teams itself.
highperson_alertThreat ActorIran-linked MOIS group deploys Cavern C2 framework against Israel
An Iranian threat actor affiliated with Iran's Ministry of Intelligence and Security (MOIS), tracked by Check Point Research. The group operates in support of Iranian state intelligence objectives, focusing on espionage operations against adversary n…
criticalbug_reportVulnerability16-year KVM hypervisor flaw enables guest-to-host kernel corruption
Linux KVM hypervisor on Intel and AMD x86 systems. All Linux kernel versions containing the vulnerable shadow MMU code (approximately 16 years of releases).
criticalbug_reportVulnerabilityGitea Docker auth bypass under active probing (CVE-2026-20896)
Gitea Docker images with improper X-WEBAUTH-USER header validation. Specific vulnerable versions not provided; affects deployments trusting reverse proxy authentication headers without IP restrictions.
criticalbug_reportVulnerabilityAdobe ColdFusion CVE-2026-48282 under active exploitation
Adobe ColdFusion (specific versions not disclosed). Maximum severity vulnerability actively exploited in the wild.
highperson_alertThreat ActorChina-nexus actor targets Indian finance sector via DcRAT malware
A suspected China-nexus threat actor is conducting Operation DragonReturn, a targeted espionage campaign against Indian taxpayers and finance professionals.
highbug_reportVulnerabilityOpera GX patched silent add-on install flaw enabling data theft
Opera GX browser (specific versions not disclosed). Vulnerability allowed malicious websites to install browser extensions without user consent, enabling content extraction from visited pages including email addresses and other sensitive data.