Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 159 results
criticalbug_reportVulnerabilitySimpleHelp CVE-2026-48558 exploited to deploy Djinn Stealer malware
SimpleHelp remote support software (specific versions not disclosed). Affects organizations using SimpleHelp for remote access and support operations across Windows, macOS, and Linux environments.
criticalbug_reportVulnerabilityOracle E-Business Suite under active exploit via CVE-2026-46817
Oracle E-Business Suite (EBS) financial application. Specific affected versions not disclosed in available intelligence.
criticalbug_reportVulnerabilityCritical RCE flaw in PTC Windchill and FlexPLM requires immediate patching
PTC Windchill and FlexPLM products. Specific affected versions not disclosed in available data. Both products are enterprise Product Lifecycle Management (PLM) platforms widely used in manufacturing and engineering environments.
criticalbug_reportVulnerabilitylibssh2 RCE via malicious SSH server (CVE-2026-55200), PoC public
libssh2 library versions up to and including 1.11.1. Affects any application or system using libssh2 for SSH client connections, including Git, curl, rsync wrappers, and custom SSH clients.
criticalbug_reportVulnerabilityCISA orders federal patch for exploited Cisco Unified Comms flaw
Cisco Unified Communications Manager Server. Specific versions not disclosed. Federal agencies mandated to patch; all organizations running this product should consider affected.
criticalbug_reportVulnerabilityLinux kernel traffic-control flaw grants local root via public exploit
Linux kernel traffic-control subsystem (act_pedit module). All distributions running vulnerable kernel versions are affected. Specific patched versions not provided; assume unpatched kernels prior to June 16, 2026 vendor advisories are vulnerable.
criticalbug_reportVulnerabilityPTC Windchill and FlexPLM RCE actively exploited in web shell attacks
PTC Windchill PDMlink and PTC FlexPLM Product Lifecycle Management systems. Specific affected versions not disclosed in summary; consult CISA KEV catalog and PTC security advisories for version details.
criticalbug_reportVulnerabilityGogs Git service vulnerable to remote code execution, patch immediately
Gogs Git service (specific versions not disclosed in advisory). All internet-facing Gogs instances should be considered at risk until patched.
criticalbug_reportVulnerabilityCisco Catalyst SD-WAN zero-day exploited for root access (CVE-2026-20245)
Cisco Catalyst SD-WAN devices. Specific affected versions not disclosed in available information. Attackers gain root-level access and can create persistent rogue accounts.
criticalbug_reportVulnerabilityCISA warns: Lantronix EDS5000 code injection under active exploit
Lantronix EDS5000 Series devices. Specific vulnerable firmware versions not disclosed in provided data. Critical code injection vulnerability (CVE-2025-67038, CVSS 9.8).
criticalbug_reportVulnerabilityCISA warns: Critical flaws in Ubiquiti UniFi OS and Lantronix exploited
Ubiquiti UniFi OS and Lantronix serial-to-ethernet servers. Specific affected versions not disclosed in summary. Both products commonly deployed in enterprise network infrastructure and IoT/OT environments.
criticalbug_reportVulnerabilityCI/CD flaw "Cordyceps" exposes 300+ GitHub repos to supply-chain takeover
300+ GitHub repositories across major organizations including Microsoft, Google, and Apache. Vulnerability affects GitHub Actions CI/CD workflows. Specific products and versions not disclosed in available data.
criticalbug_reportVulnerabilityCisco Unified CM critical flaw under active exploitation, root access risk
Cisco Unified Communications Manager (CUCM) and Unified CM SME. Specific affected versions not provided in available data. Vulnerability affects HTTP request handling with unauthenticated remote attack vector.
criticalperson_alertThreat ActorFortiBleed: Russian IAB harvests 110M credentials from FortiGate devices
FortiBleed is attributed to a Russian-speaking initial access broker (IAB) conducting large-scale credential harvesting operations since February 2026. The actor demonstrates advanced operational capabilities through systematic targeting of over 430,…
criticalbug_reportVulnerabilityCritical RCE and XSS flaws in pgAdmin 4 enable credential theft
pgAdmin 4 (specific vulnerable versions not provided in alert). pgAdmin is a web-based administration tool for PostgreSQL databases, commonly deployed in enterprise environments for database management.
criticalbug_reportVulnerabilityProxySQL ACL bypass and heap corruption flaws threaten database security
ProxySQL (specific versions not provided). Vulnerabilities include ACL bypass allowing unauthorized access and heap memory corruption potentially enabling remote code execution. Database proxy infrastructure is at risk.
criticalbug_reportVulnerabilityUnpatchable SecureROM exploit for Apple A12/A13 chips published
Apple devices with A12 and A13 chips (iPhone XS/XR/11 series, iPad Air 3rd gen, iPad mini 5th gen, iPad 8th gen). SecureROM vulnerability is permanent and cannot be patched via software updates.
criticalbug_reportVulnerabilityCritical RCE in Splunk Enterprise under active exploitation
Splunk Enterprise (specific versions not disclosed in alert). The vulnerability enables remote code execution. CVE identifier not yet assigned or published.
criticalbug_reportVulnerabilityCISA orders federal agencies to patch exploited Splunk Enterprise flaw
Splunk Enterprise (specific versions not disclosed in summary). CISA directive targets U.S. federal agencies, but vulnerability affects all Splunk Enterprise deployments.
criticalbug_reportVulnerabilityCritical auth bypass in SimpleHelp remote support software (CVE-2026-48558)
SimpleHelp remote support software, specific versions not disclosed. Vendor patch available. Authentication bypass vulnerability allows unauthorized access.
criticalbug_reportVulnerabilityAutoJack exploit chain enables RCE on AI agent hosts via malicious webpage
Microsoft AutoGen Studio users running AI browsing agents. Affects deployments where AutoGen Studio's MCP WebSocket is accessible to localhost without authentication. Specific version range not disclosed.
criticalbug_reportVulnerabilityNGINX Open Source RCE via HTTP/3 use-after-free (CVE-2026-42530)
NGINX Open Source versions with ngx_http_v3_module enabled. Specific vulnerable versions not provided in summary. F5 NGINX products potentially affected.
criticalbug_reportVulnerabilityJenkins RCE vulnerability requires immediate patching per CERT.BE
Jenkins (specific versions not disclosed in alert). Vulnerability enables arbitrary remote code execution. CVE identifier not yet assigned or published.
criticalbug_reportVulnerabilityCritical vulnerability in Joomla Content Editor (JCE) requires urgent patching
Joomla Content Editor (JCE) extension for Joomla CMS. Specific affected versions not disclosed in advisory. All Joomla sites using the JCE extension should be considered at risk pending vendor confirmation.
criticalbug_reportVulnerabilityCISA orders patching of actively exploited Joomla JCE plugin flaw
Widget Factory Joomla Content Editor (JCE) plugin for Joomla CMS. Specific vulnerable versions not disclosed in provided data. Maximum severity rating indicates critical impact.
criticalbug_reportVulnerabilitySupply chain attack compromises 144 Mastra npm packages via hijacked account
144 npm packages in the @mastra/* namespace (Mastra AI framework for JavaScript/TypeScript). Attack vector: compromised npm contributor account (ehindero). All downstream projects using affected Mastra packages are potentially impacted.
criticalbug_reportVulnerabilityCISA: Widget Factory Joomla JCE flaw exploited in the wild (CVSS 10.0)
Widget Factory Joomla Content Editor (JCE). Specific affected versions not disclosed. Impacts Joomla CMS installations using the JCE component.
criticalbug_reportVulnerabilityCisco SD-WAN vulnerability under active exploitation, patches released
Cisco SD-WAN products. Specific affected versions not provided in available data. Organizations running Cisco SD-WAN infrastructure are potentially at risk.
criticalbug_reportVulnerabilityCISA orders patch for exploited LiteSpeed cPanel plugin flaw (3-day deadline)
LiteSpeed cPanel user-end plugin (specific versions not disclosed). Affects web hosting environments using cPanel with LiteSpeed integration. U.S. federal agencies explicitly targeted by CISA directive.
criticalbug_reportVulnerabilityFortinet FortiSandbox under active exploit for 3 CVEs including critical 9.1
Fortinet FortiSandbox - specific affected versions not disclosed. Three CVEs: CVE-2026-39813 (CVSS 9.1 critical), CVE-2026-39808, CVE-2026-25089. At least one vulnerability recently patched; patch status of others unclear.