Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 420 results
Active filter:tag: #geopolitical✕ clear
Oracle WebLogic & HTTP Server CVE-2026-21962 actively exploited (CVSS 10.0)criticalbug_reportVulnerability
bug_reportVulnerability

Oracle WebLogic & HTTP Server CVE-2026-21962 actively exploited (CVSS 10.0)

Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in (all versions prior to January 2026 patch). Affects unauthenticated attackers with network access via HTTP.

CVE-2026-2196225 Aug · 04:12 UTC
Calix GS7 XGS routers expose UPnP on WAN, allow unauthenticated NAT bypasshighbug_reportVulnerability
bug_reportVulnerability

Calix GS7 XGS routers expose UPnP on WAN, allow unauthenticated NAT bypass

Calix GS7 XGS (GS5239XG / GigaSpire 7u10txg) residential routers running EXOS/6.6.47 firmware. Deployed by multiple U.S. ISPs including Cox Communications, Brightspeed, ALLO, CityFibre, and Conexon. No patch available.

Calix24 Aug · 19:14 UTC
South Korean gov't platform breach exposes 5,000 via key management flawhighpublicGeopolitical
publicGeopolitical

South Korean gov't platform breach exposes 5,000 via key management flaw

The breach of South Korea's Ministry of SMEs and Startups-backed platform represents a significant governance failure in a state seeking to position itself as a regional technology leader.

BleepingComputer24 Aug · 12:00 UTC
PostgreSQL RCE vulnerability with PoC exploit requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

PostgreSQL RCE vulnerability with PoC exploit requires immediate patching

PostgreSQL database servers (specific affected versions not disclosed in available information). Scope: remote code execution vulnerability affecting PostgreSQL installations.

PostgreSQL24 Aug · 11:29 UTC
Operation QUICSILVER: China-nexus campaign targets Myanmar with QUICAgenthighperson_alertThreat Actor
person_alertThreat Actor

Operation QUICSILVER: China-nexus campaign targets Myanmar with QUICAgent

Operation QUICSILVER is attributed with moderate confidence to a China-nexus threat actor conducting cyber espionage operations against Myanmar. The actor demonstrates sophisticated tradecraft, leveraging social engineering lures themed around govern…

The Hacker News24 Aug · 09:51 UTC
CISA orders 3-day patch for exploited Zimbra RCE (CVE-2026-73570)criticalbug_reportVulnerability
bug_reportVulnerability

CISA orders 3-day patch for exploited Zimbra RCE (CVE-2026-73570)

Zimbra Collaboration Suite (ZCS) versions prior to 10.1.20. Exploitation requires SNMP notifications to be enabled. Over 12,000 Zimbra servers exposed online; 270+ confirmed compromised instances detected by Shadowserver.

Zimbra24 Aug · 08:45 UTC
UAT-10147 Deploys AI-Assisted Attacks and SPECTRE Malware Globallyhighperson_alertThreat Actor
person_alertThreat Actor

UAT-10147 Deploys AI-Assisted Attacks and SPECTRE Malware Globally

UAT-10147 is a Chinese-speaking cybercrime group conducting large-scale attacks against Windows and Linux web servers globally. The actor's primary motivation appears to be SEO fraud and data theft.

The Hacker News24 Aug · 06:08 UTC
CISA orders patching of two actively exploited TrueConf Server flawscriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders patching of two actively exploited TrueConf Server flaws

TrueConf Server, a self-hosted corporate messaging and video conferencing platform. CVE-2026-72529 (critical missing authentication allowing remote script execution via TCP port 4307) and CVE-2026-72530 (critical sandbox escape enabling arbitrary OS…

TrueConf21 Aug · 10:25 UTC
UNC6293, UNC7005, UNC5976 Abuse OAuth and WhatsApp Linking for Espionagehighperson_alertThreat Actor
person_alertThreat Actor

UNC6293, UNC7005, UNC5976 Abuse OAuth and WhatsApp Linking for Espionage

UNC6293, UNC7005, and UNC5976 are three distinct suspected Russian cyber espionage threat clusters conducting persistent account compromise operations. UNC6293 is assessed to be a sub-cluster of Ice Relic (formerly APT29, also tracked as Cozy Bear an…

Google20 Aug · 17:59 UTC
AI-Generated Exploits Target Siemens S7 PLCs in U.S. Critical Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

AI-Generated Exploits Target Siemens S7 PLCs in U.S. Critical Infrastructure

This campaign involves unattributed threat actors leveraging artificial intelligence to generate exploitation scripts targeting industrial control systems.

Siemens20 Aug · 14:59 UTC
Red Hat Keycloak password-reset flaw enables account takeovercriticalbug_reportVulnerability
bug_reportVulnerability

Red Hat Keycloak password-reset flaw enables account takeover

Red Hat build of Keycloak, specific versions not disclosed in source. Vulnerability exists in the password-reset flow mechanism.

Red Hat20 Aug · 12:36 UTC
Citrix NetScaler ADC/Gateway auth bypass requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Citrix NetScaler ADC/Gateway auth bypass requires immediate patching

Citrix NetScaler ADC and NetScaler Gateway products. Specific affected versions not disclosed in available information. Authentication bypass vulnerability allows unauthorized access.

Citrix20 Aug · 12:25 UTC
Zimbra SNMP flaw CVE-2026-73570 under active exploitation for RCEhighbug_reportVulnerability
bug_reportVulnerability

Zimbra SNMP flaw CVE-2026-73570 under active exploitation for RCE

Zimbra Collaboration Server (ZCS) versions before 10.1.20, only when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Unauthenticated remote attackers can exploit this command injection flaw.

CVE-2026-7357020 Aug · 11:24 UTC
Zombie Card attack revives expired Visa contactless cards via NFC relayhighbug_reportVulnerability
bug_reportVulnerability

Zombie Card attack revives expired Visa contactless cards via NFC relay

Visa contactless credit cards using Kernel 3 specification. Attack requires physical card access or sustained NFC proximity, plus relay device between card and terminal. Five major US banks tested; three confirmed vulnerable with varying policies.

Visa20 Aug · 10:01 UTC
CISA: Critical MLflow SSRF flaw (CVE-2026-64849) exploited in the wildcriticalbug_reportVulnerability
bug_reportVulnerability

CISA: Critical MLflow SSRF flaw (CVE-2026-64849) exploited in the wild

MLflow open-source AI engineering platform, all versions prior to 3.15.0. Default MLflow Tracking Server deployments without authentication are vulnerable.

MLflow20 Aug · 09:06 UTC
Manic Android malware exfiltrates data via nearby infected deviceshighbug_reportVulnerability
bug_reportVulnerability

Manic Android malware exfiltrates data via nearby infected devices

Android users in Central and Western Europe (including UK), Russia, and primarily Ukraine. Targets 169 banking, government/eID, payment, crypto wallet, messaging, and 2FA apps. Active since at least February 2026.

BleepingComputer20 Aug · 08:02 UTC
Zimbra RCE flaw CVE-2026-73570 actively exploited in the wildcriticalbug_reportVulnerability
bug_reportVulnerability

Zimbra RCE flaw CVE-2026-73570 actively exploited in the wild

Zimbra Collaboration Suite (ZCS) versions prior to 10.1.20. Affects servers with SNMP notifications enabled. Over 12,100 Zimbra servers exposed online, primarily in Europe (4,382) and Asia (4,492). Impacts businesses and government agencies globally.

Zimbra20 Aug · 07:46 UTC
Sakura Internet breach exposes 1.36M accounts at Japan Gov Cloud providerhighpublicGeopolitical
publicGeopolitical

Sakura Internet breach exposes 1.36M accounts at Japan Gov Cloud provider

The breach of Sakura Internet carries strategic significance beyond typical commercial cloud incidents due to the company's designation as a domestic provider for Japan's Government Cloud program.

Sakura Internet19 Aug · 18:53 UTC
CareCloud breach exposes 3.7M patient records in AWS environmenthighpublicGeopolitical
publicGeopolitical

CareCloud breach exposes 3.7M patient records in AWS environment

The CareCloud incident reflects the persistent vulnerability of U.S. healthcare infrastructure to cyber intrusions, particularly cloud-hosted environments containing sensitive medical data.

CareCloud19 Aug · 18:07 UTC
Critical auth bypass and DoS flaws in Citrix NetScaler ADC/Gatewaycriticalbug_reportVulnerability
bug_reportVulnerability

Critical auth bypass and DoS flaws in Citrix NetScaler ADC/Gateway

Citrix NetScaler ADC and NetScaler Gateway versions 14.1 before 14.1-73.32, 13.1 before 13.1-63.21, NetScaler ADC FIPS before 14.1-73.32 FIPS, and FIPS/NDcPP before 13.1-37.277. CVE-2026-19489 affects devices with SIP ALG enabled on LSN groups.

Citrix19 Aug · 16:13 UTC
14,500 Dahua IP cameras compromised via brute-force and known CVEshighbug_reportVulnerability
bug_reportVulnerability

14,500 Dahua IP cameras compromised via brute-force and known CVEs

Dahua IP cameras globally, with concentration in Ukraine and Russia. Devices vulnerable to CVE-2021-33044 and CVE-2021-33045, those exposed on TCP port 37777, and cloud-registered cameras accessible via serial number recovery codes.

Dahua19 Aug · 16:09 UTC
AI-Generated Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

AI-Generated Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure

No specific threat actor or group has been attributed to this campaign. The advisory describes ongoing activity by unidentified threat actors targeting Siemens S7 Series programmable logic controllers in U.S. critical infrastructure.

Siemens19 Aug · 15:50 UTC
U.S. charges 17 Mabna Institute members for $3.4B IP theft campaignhighperson_alertThreat Actor
person_alertThreat Actor

U.S. charges 17 Mabna Institute members for $3.4B IP theft campaign

Mabna Institute is an Iranian hacking-for-hire organization linked to cyber operations conducted on behalf of Iran's Islamic Revolutionary Guard Corps (IRGC), other Iranian government bodies, universities, and private paying customers.

BleepingComputer19 Aug · 13:56 UTC
Zimbra Collaboration RCE under active exploitation, patch immediatelycriticalbug_reportVulnerability
bug_reportVulnerability

Zimbra Collaboration RCE under active exploitation, patch immediately

Zimbra Collaboration Suite - specific vulnerable versions not disclosed in advisory. Remote code execution vulnerability affecting internet-facing Zimbra instances.

Zimbra19 Aug · 11:28 UTC
SilkParasite Targets Central Asian Governments with Five New RATshighperson_alertThreat Actor
person_alertThreat Actor

SilkParasite Targets Central Asian Governments with Five New RATs

SilkParasite is a previously unreported cyber espionage operation first discovered in late 2025, assessed with medium confidence to be a China-nexus threat cluster.

The Hacker News19 Aug · 11:12 UTC
CERT.BE warns of critical Oracle vulnerabilities requiring urgent patchinghighbug_reportVulnerability
bug_reportVulnerability

CERT.BE warns of critical Oracle vulnerabilities requiring urgent patching

Multiple Oracle products affected. Specific product names, versions, and CVE identifiers not provided in advisory. Scope appears broad across Oracle product portfolio based on CERT.BE warning classification.

Oracle19 Aug · 11:01 UTC
CISA flags 4 critical flaws in macOS, SharePoint, vCenter, IKE under attackcriticalbug_reportVulnerability
bug_reportVulnerability

CISA flags 4 critical flaws in macOS, SharePoint, vCenter, IKE under attack

Apple macOS (CVE-2026-65400, Screen Sharing authentication bypass), Microsoft SharePoint (CVE-2026-55040, weak authentication), Broadcom VMware vCenter (CVE-2026-59310, path traversal RCE), Microsoft IKE Service Extensions (CVE-2026-33824, double fre…

CVE-2026-6540019 Aug · 09:01 UTC
Windows IKE Extension RCE (CVE-2026-33824) actively exploitedcriticalbug_reportVulnerability
bug_reportVulnerability

Windows IKE Extension RCE (CVE-2026-33824) actively exploited

All supported Windows 10, Windows 11, and Windows Server versions. The vulnerability affects the Windows Internet Key Exchange (IKE) Service Extensions (MS-IKEE) component accessible via UDP ports 500 and 4500.

Microsoft19 Aug · 08:12 UTC
Medusa Ransomware Gang Breaches 500+ US Critical Infrastructure Orgscriticalperson_alertThreat Actor
person_alertThreat Actor

Medusa Ransomware Gang Breaches 500+ US Critical Infrastructure Orgs

Medusa is a ransomware operation active since January 2021 that evolved from a closed ransomware variant into a Ransomware-as-a-Service (RaaS) model with an affiliate program.

BleepingComputer19 Aug · 06:00 UTC
GitLab CE/EE critical code injection flaw with public PoC exploitcriticalbug_reportVulnerability
bug_reportVulnerability

GitLab CE/EE critical code injection flaw with public PoC exploit

GitLab Community Edition (CE) and Enterprise Edition (EE). Specific affected versions not provided in source material. CVE identifier not yet assigned or disclosed.

GitLab18 Aug · 13:12 UTC