Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 685 results
highbug_reportVulnerability24 npm packages abuse unpkg mirrors as phishing infrastructure
24 malicious npm packages (e.g., bgzxcuite2, prezdentkxheiw, egair0810) hosted on npm registry and mirrored on unpkg.com and similar CDN services. Affects users who click links to these mirrored HTML pages, not developers installing packages directly…
highbug_reportVulnerabilityE4del and PINHOLE RATs abuse FTP banners as dead drop resolvers
Organizations globally; no specific vendor or product vulnerability. Attack targets Windows systems via social engineering (Spanish-language vouchers, ClickFix lures).
highperson_alertThreat ActorAfrican Crime Groups Targeted in 22-Country Cybercrime Crackdown
African crime groups, particularly West African criminal networks and the Black Axe cybercrime syndicate, are financially-motivated threat actors conducting global-scale cyber-enabled financial fraud.
highbug_reportVulnerabilityXecurify miniOrange SAML plugin flaws exploited for WordPress admin access
Xecurify miniOrange SAML 2.0 Single Sign On WordPress plugin, Standard edition versions prior to 17.0.6. CVE-2026-61979 (CVSS 8.1) fixed in 17.0.5; CVE-2026-15981 (CVSS 9.8) fixed in 17.0.6.
highbug_reportVulnerabilityCalix GS7 XGS routers expose UPnP on WAN, allow unauthenticated NAT bypass
Calix GS7 XGS (GS5239XG / GigaSpire 7u10txg) residential routers running EXOS/6.6.47 firmware. Deployed by multiple U.S. ISPs including Cox Communications, Brightspeed, ALLO, CityFibre, and Conexon. No patch available.
highperson_alertThreat ActorWeedhack Malware Targets Gamers via Fake Minecraft Clients and SEO
Weedhack is a malware family (not a named threat actor group) actively distributed through fake Minecraft client websites and SEO poisoning campaigns. The operators behind Weedhack remain unattributed.
highperson_alertThreat ActorShinyHunters targets ReliaQuest in failed social engineering attack
ShinyHunters is a notorious data extortion group known for large-scale data breaches and credential theft operations. In this incident, the group demonstrated advanced social engineering capabilities by impersonating ReliaQuest security personnel to…
highpublicGeopoliticalSouth Korean gov't platform breach exposes 5,000 via key management flaw
The breach of South Korea's Ministry of SMEs and Startups-backed platform represents a significant governance failure in a state seeking to position itself as a regional technology leader.
highbug_reportVulnerability.NET Framework August 2026 updates break WPF printing and PDF export
.NET Framework cumulative updates released August 2026 Patch Tuesday. Affects Windows Presentation Foundation (WPF) applications on Windows 10, Windows 11, Windows Server 2012 through Windows Server 2025.
highbug_reportVulnerabilityWordlistLoader and SynkLoader malware target Windows via ClickFix and Teams
Windows endpoints exposed to ClearFake/ClickFix campaigns (WordlistLoader delivering Amatera Stealer) and Microsoft Teams phishing (SynkLoader credential theft).
highperson_alertThreat ActorOperation QUICSILVER: China-nexus campaign targets Myanmar with QUICAgent
Operation QUICSILVER is attributed with moderate confidence to a China-nexus threat actor conducting cyber espionage operations against Myanmar. The actor demonstrates sophisticated tradecraft, leveraging social engineering lures themed around govern…
highperson_alertThreat ActorUAT-10147 Deploys AI-Assisted Attacks and SPECTRE Malware Globally
UAT-10147 is a Chinese-speaking cybercrime group conducting large-scale attacks against Windows and Linux web servers globally. The actor's primary motivation appears to be SEO fraud and data theft.
highbug_reportVulnerabilityToxicPanda 2.0 abuses VPN and ADB to evade Google Play Protect
Android devices running Android 11 or later (Wireless ADB support). Targets 349 banking, financial, cryptocurrency, and e-wallet apps across 16 countries. Specific OEM persistence mechanisms for Xiaomi, OPPO, Vivo, Samsung, and Huawei devices.
highbug_reportVulnerabilitySupply-chain attack targets Android car head units via update app
Android-based automotive head units receiving updates through a compromised legitimate device-update application. Specific vendors, models, and geographic distribution not disclosed.
highbug_reportVulnerabilityAttackers shift focus to CI/CD pipelines and developer tools in SDLC
All organizations using modern software development practices with CI/CD pipelines, open-source dependencies, and developer tools. Specific recent attacks include ChainDrop npm worm (400+ packages including keyv and cacheable-request), XZ Utils (CVE-…
highbug_reportVulnerability14 trojanized npm packages deliver AI-powered RedC2 4.0 Linux backdoor
14 npm packages (streak-metrics-math, kit-map-vim, streak-map-cache, streak-map-kit, map-streak-kit, streak-cache-map, streak-calc-metrics, streak-calc-math, streak-math-abz, streak-metricsaz, streak-math-metrics, streak-metricazbd, streak-metricsazb…
highbug_reportVulnerabilitySynkLoader malware spreads via Microsoft Teams phishing campaigns
Microsoft Teams users across all organizations. SynkLoader is a new credential-stealing malware family delivered through phishing messages on the Teams platform. No specific product versions or CVEs identified.
highbug_reportVulnerabilityMicrosoft Defender BTR.sys driver weaponized for kernel-level sabotage
Microsoft Defender BTR.sys driver on all Windows versions from Windows 7 through Windows 11 25H2. The driver is a required component shipped with every Windows installation and cannot be blocked without breaking Defender functionality.
highbug_reportVulnerabilityThreat actors abuse FTP banners to deliver E4del and PINHOLE RATs
Windows systems targeted via phishing campaigns delivering LNK files. Two RATs deployed: E4del (Node.js/Electron-based, masquerading as Discord) and PINHOLE (memory-resident, using Pinterest/SurveyMonkey for C2).
highperson_alertThreat ActorUNC6293, UNC7005, UNC5976 Abuse OAuth and WhatsApp Linking for Espionage
UNC6293, UNC7005, and UNC5976 are three distinct suspected Russian cyber espionage threat clusters conducting persistent account compromise operations. UNC6293 is assessed to be a sub-cluster of Ice Relic (formerly APT29, also tracked as Cozy Bear an…
highbug_reportVulnerabilityGogs 10.0 RCE and n8n workflow-to-RCE vulnerabilities disclosed
Gogs version 10.0 (Git service) and n8n (workflow automation platform) - specific n8n versions not provided. Multiple attack vectors disclosed including signed driver abuse (Microsoft Defender BTR.sys), DLL sideloading via Grandoreiro, and ErrTraffic…
highperson_alertThreat ActorAI-Generated Exploits Target Siemens S7 PLCs in U.S. Critical Infrastructure
This campaign involves unattributed threat actors leveraging artificial intelligence to generate exploitation scripts targeting industrial control systems.
highbug_reportVulnerabilityGrok chatbot vulnerable to data exfiltration via encrypted prompt injection
xAI Grok 4.5 Fast (web chat at grok.com). Google Gemini 3 Flash (Web) in Deep Thinking mode also demonstrated vulnerable in March 2026. Affects users requesting web page summaries through the chatbot interface.
highbug_reportVulnerabilityZimbra SNMP flaw CVE-2026-73570 under active exploitation for RCE
Zimbra Collaboration Server (ZCS) versions before 10.1.20, only when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Unauthenticated remote attackers can exploit this command injection flaw.
highbug_reportVulnerabilityCitrix urges immediate patching of NetScaler auth bypass and DoS flaws
Citrix NetScaler ADC and NetScaler Gateway appliances (all supported versions prior to 14.1-73.32 and 13.1-63.21). CVE-2026-19490 affects appliances configured as AAA virtual server or Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) with SAML authentic…
highbug_reportVulnerabilityZombie Card attack revives expired Visa contactless cards via NFC relay
Visa contactless credit cards using Kernel 3 specification. Attack requires physical card access or sustained NFC proximity, plus relay device between card and terminal. Five major US banks tested; three confirmed vulnerable with varying policies.
highbug_reportVulnerabilityManic Android malware exfiltrates data via nearby infected devices
Android users in Central and Western Europe (including UK), Russia, and primarily Ukraine. Targets 169 banking, government/eID, payment, crypto wallet, messaging, and 2FA apps. Active since at least February 2026.
highperson_alertThreat ActorRansom Busters: Rogue Affiliate Impersonates Recovery Firm
Ransom Busters is a suspected ransomware affiliate operating across multiple Ransomware-as-a-Service (RaaS) platforms, including DragonForce, Settra, and Anubis.
highpublicGeopoliticalSakura Internet breach exposes 1.36M accounts at Japan Gov Cloud provider
The breach of Sakura Internet carries strategic significance beyond typical commercial cloud incidents due to the company's designation as a domestic provider for Japan's Government Cloud program.
highpublicGeopoliticalCareCloud breach exposes 3.7M patient records in AWS environment
The CareCloud incident reflects the persistent vulnerability of U.S. healthcare infrastructure to cyber intrusions, particularly cloud-hosted environments containing sensitive medical data.