Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 420 results
criticalbug_reportVulnerabilityOracle WebLogic & HTTP Server CVE-2026-21962 actively exploited (CVSS 10.0)
Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in (all versions prior to January 2026 patch). Affects unauthenticated attackers with network access via HTTP.
highbug_reportVulnerabilityCalix GS7 XGS routers expose UPnP on WAN, allow unauthenticated NAT bypass
Calix GS7 XGS (GS5239XG / GigaSpire 7u10txg) residential routers running EXOS/6.6.47 firmware. Deployed by multiple U.S. ISPs including Cox Communications, Brightspeed, ALLO, CityFibre, and Conexon. No patch available.
highpublicGeopoliticalSouth Korean gov't platform breach exposes 5,000 via key management flaw
The breach of South Korea's Ministry of SMEs and Startups-backed platform represents a significant governance failure in a state seeking to position itself as a regional technology leader.
criticalbug_reportVulnerabilityPostgreSQL RCE vulnerability with PoC exploit requires immediate patching
PostgreSQL database servers (specific affected versions not disclosed in available information). Scope: remote code execution vulnerability affecting PostgreSQL installations.
highperson_alertThreat ActorOperation QUICSILVER: China-nexus campaign targets Myanmar with QUICAgent
Operation QUICSILVER is attributed with moderate confidence to a China-nexus threat actor conducting cyber espionage operations against Myanmar. The actor demonstrates sophisticated tradecraft, leveraging social engineering lures themed around govern…
criticalbug_reportVulnerabilityCISA orders 3-day patch for exploited Zimbra RCE (CVE-2026-73570)
Zimbra Collaboration Suite (ZCS) versions prior to 10.1.20. Exploitation requires SNMP notifications to be enabled. Over 12,000 Zimbra servers exposed online; 270+ confirmed compromised instances detected by Shadowserver.
highperson_alertThreat ActorUAT-10147 Deploys AI-Assisted Attacks and SPECTRE Malware Globally
UAT-10147 is a Chinese-speaking cybercrime group conducting large-scale attacks against Windows and Linux web servers globally. The actor's primary motivation appears to be SEO fraud and data theft.
criticalbug_reportVulnerabilityCISA orders patching of two actively exploited TrueConf Server flaws
TrueConf Server, a self-hosted corporate messaging and video conferencing platform. CVE-2026-72529 (critical missing authentication allowing remote script execution via TCP port 4307) and CVE-2026-72530 (critical sandbox escape enabling arbitrary OS…
highperson_alertThreat ActorUNC6293, UNC7005, UNC5976 Abuse OAuth and WhatsApp Linking for Espionage
UNC6293, UNC7005, and UNC5976 are three distinct suspected Russian cyber espionage threat clusters conducting persistent account compromise operations. UNC6293 is assessed to be a sub-cluster of Ice Relic (formerly APT29, also tracked as Cozy Bear an…
highperson_alertThreat ActorAI-Generated Exploits Target Siemens S7 PLCs in U.S. Critical Infrastructure
This campaign involves unattributed threat actors leveraging artificial intelligence to generate exploitation scripts targeting industrial control systems.
criticalbug_reportVulnerabilityRed Hat Keycloak password-reset flaw enables account takeover
Red Hat build of Keycloak, specific versions not disclosed in source. Vulnerability exists in the password-reset flow mechanism.
criticalbug_reportVulnerabilityCitrix NetScaler ADC/Gateway auth bypass requires immediate patching
Citrix NetScaler ADC and NetScaler Gateway products. Specific affected versions not disclosed in available information. Authentication bypass vulnerability allows unauthorized access.
highbug_reportVulnerabilityZimbra SNMP flaw CVE-2026-73570 under active exploitation for RCE
Zimbra Collaboration Server (ZCS) versions before 10.1.20, only when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Unauthenticated remote attackers can exploit this command injection flaw.
highbug_reportVulnerabilityZombie Card attack revives expired Visa contactless cards via NFC relay
Visa contactless credit cards using Kernel 3 specification. Attack requires physical card access or sustained NFC proximity, plus relay device between card and terminal. Five major US banks tested; three confirmed vulnerable with varying policies.
criticalbug_reportVulnerabilityCISA: Critical MLflow SSRF flaw (CVE-2026-64849) exploited in the wild
MLflow open-source AI engineering platform, all versions prior to 3.15.0. Default MLflow Tracking Server deployments without authentication are vulnerable.
highbug_reportVulnerabilityManic Android malware exfiltrates data via nearby infected devices
Android users in Central and Western Europe (including UK), Russia, and primarily Ukraine. Targets 169 banking, government/eID, payment, crypto wallet, messaging, and 2FA apps. Active since at least February 2026.
criticalbug_reportVulnerabilityZimbra RCE flaw CVE-2026-73570 actively exploited in the wild
Zimbra Collaboration Suite (ZCS) versions prior to 10.1.20. Affects servers with SNMP notifications enabled. Over 12,100 Zimbra servers exposed online, primarily in Europe (4,382) and Asia (4,492). Impacts businesses and government agencies globally.
highpublicGeopoliticalSakura Internet breach exposes 1.36M accounts at Japan Gov Cloud provider
The breach of Sakura Internet carries strategic significance beyond typical commercial cloud incidents due to the company's designation as a domestic provider for Japan's Government Cloud program.
highpublicGeopoliticalCareCloud breach exposes 3.7M patient records in AWS environment
The CareCloud incident reflects the persistent vulnerability of U.S. healthcare infrastructure to cyber intrusions, particularly cloud-hosted environments containing sensitive medical data.
criticalbug_reportVulnerabilityCritical auth bypass and DoS flaws in Citrix NetScaler ADC/Gateway
Citrix NetScaler ADC and NetScaler Gateway versions 14.1 before 14.1-73.32, 13.1 before 13.1-63.21, NetScaler ADC FIPS before 14.1-73.32 FIPS, and FIPS/NDcPP before 13.1-37.277. CVE-2026-19489 affects devices with SIP ALG enabled on LSN groups.
highbug_reportVulnerability14,500 Dahua IP cameras compromised via brute-force and known CVEs
Dahua IP cameras globally, with concentration in Ukraine and Russia. Devices vulnerable to CVE-2021-33044 and CVE-2021-33045, those exposed on TCP port 37777, and cloud-registered cameras accessible via serial number recovery codes.
highperson_alertThreat ActorAI-Generated Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure
No specific threat actor or group has been attributed to this campaign. The advisory describes ongoing activity by unidentified threat actors targeting Siemens S7 Series programmable logic controllers in U.S. critical infrastructure.
highperson_alertThreat ActorU.S. charges 17 Mabna Institute members for $3.4B IP theft campaign
Mabna Institute is an Iranian hacking-for-hire organization linked to cyber operations conducted on behalf of Iran's Islamic Revolutionary Guard Corps (IRGC), other Iranian government bodies, universities, and private paying customers.
criticalbug_reportVulnerabilityZimbra Collaboration RCE under active exploitation, patch immediately
Zimbra Collaboration Suite - specific vulnerable versions not disclosed in advisory. Remote code execution vulnerability affecting internet-facing Zimbra instances.
highperson_alertThreat ActorSilkParasite Targets Central Asian Governments with Five New RATs
SilkParasite is a previously unreported cyber espionage operation first discovered in late 2025, assessed with medium confidence to be a China-nexus threat cluster.
highbug_reportVulnerabilityCERT.BE warns of critical Oracle vulnerabilities requiring urgent patching
Multiple Oracle products affected. Specific product names, versions, and CVE identifiers not provided in advisory. Scope appears broad across Oracle product portfolio based on CERT.BE warning classification.
criticalbug_reportVulnerabilityCISA flags 4 critical flaws in macOS, SharePoint, vCenter, IKE under attack
Apple macOS (CVE-2026-65400, Screen Sharing authentication bypass), Microsoft SharePoint (CVE-2026-55040, weak authentication), Broadcom VMware vCenter (CVE-2026-59310, path traversal RCE), Microsoft IKE Service Extensions (CVE-2026-33824, double fre…
criticalbug_reportVulnerabilityWindows IKE Extension RCE (CVE-2026-33824) actively exploited
All supported Windows 10, Windows 11, and Windows Server versions. The vulnerability affects the Windows Internet Key Exchange (IKE) Service Extensions (MS-IKEE) component accessible via UDP ports 500 and 4500.
criticalperson_alertThreat ActorMedusa Ransomware Gang Breaches 500+ US Critical Infrastructure Orgs
Medusa is a ransomware operation active since January 2021 that evolved from a closed ransomware variant into a Ransomware-as-a-Service (RaaS) model with an affiliate program.
criticalbug_reportVulnerabilityGitLab CE/EE critical code injection flaw with public PoC exploit
GitLab Community Edition (CE) and Enterprise Edition (EE). Specific affected versions not provided in source material. CVE identifier not yet assigned or disclosed.