Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
satellite_altDaily BriefCyber Threat Daily Brief — September 4, 2026
Today's briefing: 14 critical and 22 high-severity threats. A total of 47 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.
Latest Reports
28 / 1172 results
criticalbug_reportVulnerabilityGeoNetwork RCE chain exploitable without authentication on gov geoportals
GeoNetwork open-source geospatial metadata catalog: all 4.4.x versions up to 4.4.11 and all 4.2.x versions up to 4.2.16. Widely deployed in government, military, and national agency Spatial Data Infrastructure backends across 39 countries, including…
highperson_alertThreat ActorRussian National Charged for 2016-2017 Excel Malware Campaign
Searzhudin Tamirlanovich Aktulaev is a 40-year-old Russian national charged by the U.S. Department of Justice for orchestrating a large-scale malware distribution campaign between June 2016 and November 2017.
highperson_alertThreat ActorRussian National Indicted for TVRAT/DarkVNC Phishing Campaign
Searzhudin Tamirlanovich Aktulaev, a 40-year-old Russian national, orchestrated a large-scale phishing campaign between June 2016 and November 2017. Motivated by financial fraud and credential theft, Aktulaev targeted freelancers on an unnamed freela…
highbug_reportVulnerabilitySality P2P botnet dismantled after 20+ years of operation
Sality botnet infrastructure (active since 2003), affecting 15,000+ infected devices globally. Primary payload in recent years: EggJagger clipjacking malware targeting cryptocurrency wallets.
criticalbug_reportVulnerabilitySonicWall SMA1000 zero-days CVE-2026-83548/83549 chained for RCE
SonicWall SMA1000 appliances (models 6210, 7210, 8200v). Does not affect SSL-VPN on SonicWall firewalls or SMA 100 Series. Approximately 400+ appliances exposed online per Shadowserver tracking.
highbug_reportVulnerabilityActive malware campaign uses fake vendor sites to deliver Silver Fox malware
Organizations with China-based operations and Chinese-speaking users across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors.
criticalperson_alertThreat ActorDark Web Service Sells 153M+ Driver Licenses from Identity Verification Breach
The threat actor operates "Nexus," a dark web identity theft service launched on the Russian cybercrime forum Exploit in August 2025. The operator claims to have continuously exfiltrated data for over a year from an alleged breach at a major Louisian…
highperson_alertThreat ActorPhishing Actors Abuse Faronics Deploy for ScreenConnect Installation
The actors are unattributed phishing operators conducting opportunistic attacks against organizations using social engineering lures. Between July 21 and August 20, 2026, they targeted over 457 endpoints with phishing emails disguised as invoices, ta…
criticalbug_reportVulnerabilityLangflow CVE-2026-0768 exploited to steal OpenAI and AWS credentials
Langflow versions 1.4.2 and earlier. The vulnerability exists in the code validator of the custom component editor's validate endpoint. Patched in version 1.11.6.
criticalbug_reportVulnerabilityJFrog Artifactory auth bypass CVE-2026-82329 under active exploitation
JFrog Artifactory versions 7.161.0-7.161.19, 7.146.0-7.146.36, 7.133.0-7.133.28, 7.125.0-7.125.19, 7.117.0-7.117.27, and 7.111.4-7.111.21. Affects default configurations of self-managed instances. JFrog Access component specifically vulnerable.
highperson_alertThreat ActorBreeze Comet Targets Brazilian Financial Sector for Payment Fraud
Breeze Comet (formerly UNC5669, overlaps with Plump Spider and SHADOW-AETHER-064) is a financially motivated threat actor operating out of Brazil since September 2023.
criticalbug_reportVulnerabilityJFrog Artifactory authentication bypass requires immediate patching
JFrog Artifactory - specific affected versions not disclosed in advisory. Authentication bypass vulnerability allows unauthorized access to artifact repository.
criticalbug_reportVulnerabilityBGP hijack delivers malicious Virtualizor updates to VPS management systems
Virtualizor VPS management software (all versions prior to 3.2.9.9) from Softaculous. Attack window: August 28, 2026 20:57 UTC to August 30, 2026 06:10 UTC.
highpublicGeopoliticalNovocure breach exposes 1,400+ U.S. cancer patient records
The Novocure incident reflects the sustained targeting of healthcare infrastructure, particularly oncology and patient data repositories, which has intensified across North American providers since late 2025.
highbug_reportVulnerability13 malicious Packagist packages target iOS devices to steal crypto wallets
Packagist/Composer ecosystem: 13 malicious theme packages across 5 vendor namespaces (vsmov, vsphim, haiau009, chilltvcms, ophimcms). Targets Vietnamese streaming sites using OphimCMS/KKPhim.
highperson_alertThreat ActorNimbus Manticore Deploys Cross-Platform RATs via Fake Job Coding Tests
Nimbus Manticore is an Iranian threat actor also tracked as Iranian Dream Job, known for using recruitment-themed social engineering lures to compromise targets.
highbug_reportVulnerability22K Exchange servers unpatched for CVE-2026-62911 auth bypass flaw
Microsoft Exchange Server 2016, 2019, and Subscription Edition (SE). Approximately 21,899 internet-exposed servers remain unpatched globally, with highest concentrations in the United States (6,200) and Germany (5,100).
highperson_alertThreat ActorClickFix Operators Dominate Initial Access via Social Engineering
ClickFix operators are threat actors leveraging a social engineering technique that manipulates users into executing malicious commands through clipboard manipulation.
highpublicGeopoliticalLatvia's cyber threat level remains high amid Russia-linked activity
Latvia's elevated cybersecurity posture reflects its position as a NATO frontline state and vocal supporter of Ukraine. CERT.LV's Q2 2026 report indicates that while incident volumes have moderated from peak levels, they remain substantially above hi…
highperson_alertThreat ActorVenezuelan ATM Jackpotting Group Targets U.S. Financial Infrastructure
This threat actor is a coordinated group of Venezuelan nationals conducting ATM jackpotting operations targeting financial institutions in the United States.
highperson_alertThreat ActorUAC-0099 Deploys GuardBreaker to Sabotage AI-Assisted Malware Analysis
UAC-0099 is a Russia-aligned threat actor with a history of targeting Ukraine's transportation and energy sectors. The group demonstrates tactical innovation by adapting emerging anti-AI analysis techniques to evade detection.
highbug_reportVulnerabilityPaperCut NG/MF zero-days exploited for data theft via auth bypass and RCE
PaperCut NG and MF print management software, all versions prior to Emergency Patch Release 3 (issued September 2026). Affects internet-facing Application Servers.
criticalbug_reportVulnerabilityLangflow and Ruby on Rails flaws actively exploited for RCE and C2
Langflow (CVE-2026-0768, CVSS 9.8): arbitrary Python code execution as root via improper input validation. Ruby on Rails (CVE-2026-66066 aka KindaRails2Shell, CVSS 9.5): unauthenticated arbitrary file read, secret leakage, and RCE in applications usi…
highbug_reportVulnerabilityTerminalFix campaign uses fake CAPTCHAs to deploy reverse tunnels
Windows systems with PowerShell and Windows Terminal enabled. Targets organizations with Active Directory environments. Attack vector: compromised websites displaying fake Cloudflare CAPTCHA prompts.
highperson_alertThreat ActorNorth Korean IT Worker Scheme Expands Into Healthcare and Sales Roles
North Korean state-sponsored threat actors, tracked as Famous Chollima, Jasper Sleet, Nickel Tapestry, PurpleDelta (formerly TAG-121), UNC5267, and Wagemole, operate a sophisticated job fraud scheme to generate revenue for the DPRK's nuclear weapons…
highperson_alertThreat ActorFire Ant compromises Cisco routers for network surveillance
Fire Ant is a Chinese espionage-focused threat actor attributed by Sygnia, with operational overlap to UNC3886 (previously documented by Google). The group targets critical infrastructure and high-value networks through a "target behind the target" s…
highperson_alertThreat ActorRhysida ransomware gang breaches Berlin city administration
Rhysida is a ransomware-as-a-service (RaaS) operation active since mid-2023, conducting double-extortion attacks against high-value targets. The group exfiltrates sensitive data before deploying ransomware, then threatens public disclosure to pressur…
highperson_alertThreat ActorSilver Fox Distributes ValleyRAT via Signed Chinese Adware
Silver Fox is a threat actor attributed by Kaspersky to campaigns distributing the ValleyRAT backdoor (also tracked as Winos 4.0). The group has demonstrated consistent use of DLL sideloading techniques leveraging legitimate, signed software to evade…