Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 139 results
criticalbug_reportVulnerabilitySharePoint Server auth bypass chained to RCE, no credentials required
Microsoft SharePoint Server Subscription Edition, 2019, and 2016 (CVE-2026-55040, CVSS 9.1). Chained RCE flaw CVE-2026-63520 (CVSS 8.1) also affects Project Server 2013 SP1 and Office Web Apps 2013 SP1. SharePoint Online is not affected.
highperson_alertThreat ActorStorm-1175 Deploys StormEncryptor Ransomware via N-central Exploit
Storm-1175 is a China-linked, financially motivated threat actor tracked by Microsoft. The group specializes in high-velocity ransomware operations, exploiting both zero-day and N-day vulnerabilities in internet-facing enterprise software to gain ini…
highperson_alertThreat ActorDeadLock Ransomware: Rust-Based Encryptor with Decentralized Infrastructure
DeadLock is a financially motivated ransomware operation first observed in July 2025. It is not attributed to a single threat actor but has been deployed by multiple groups, including affiliates of the Lynx and INC ransomware ecosystems.
highbug_reportVulnerabilityPasskey bypass attacks target Windows, Chrome, and Entra ID implementations
Microsoft Windows 10, Windows 11, Windows Server (CVE-2026-34348); Microsoft Entra ID passkey validation; Google Password Manager synced passkeys in Chrome on Windows; Windows Hello for Business.
highbug_reportVulnerabilityMalicious VS Code extensions steal crypto wallets and credentials from devs
Microsoft Visual Studio Code users who installed "Solidity Pro" extensions (helper-beeps.solidity-pro or web3devtoolsx.solidity-pro) from Open VSX marketplace. Extensions targeted Ethereum/Web3 developers.
highbug_reportVulnerabilityCSS attacks bypass webmail sanitizers to steal passwords and tokens
Microsoft Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail webmail interfaces. Attacks exploit CSS and HTML parsing discrepancies to escape message boundaries.
highbug_reportVulnerabilityNatJack attacks hijack TCP sessions via NAT manipulation; Windows & Linux CVEs
Windows NAT (Hyper-V): Windows 11 24H2 <26100.8875, 25H2 <26200.8875, 26H1 <28000.2525, Server 2025 <26100.33158 (CVE-2026-56181, CVSS 8.3). Linux Netfilter conntrack: kernel <5.10.259, <5.15.210, <6.1.176, <6.6.143, <6.12.93, <6.18.35, <7.0.12, <7.1…
highbug_reportVulnerabilityAitM phishing campaign targets Microsoft 365 for payroll email theft
Microsoft 365 accounts across healthcare, education, manufacturing, government, and professional services sectors in the U.S., Canada, and Europe. Hundreds of organizations targeted in July 2026, with focus on payroll, HR, and finance personnel.
highbug_reportVulnerabilityMalware can abuse Windows Hello for Business keys for persistent Entra ID access
Windows Hello for Business on all Windows versions with Entra ID integration. Affects organizations using Windows Hello for Business as phishing-resistant authentication. TPM-backed and non-TPM deployments both vulnerable.
highpublicGeopoliticalSwiss government SharePoint breach exposes 200 accounts via July flaws
The breach of Switzerland's Federal Office for Information Technology and Telecommunication (BIT) represents a significant compromise of neutral state infrastructure.
highperson_alertThreat ActorKali365 Campaign Weaponizes Microsoft Device Code Flow Against US Firms
Kali365 is a device code phishing campaign targeting US organizations through abuse of legitimate Microsoft authentication mechanisms. The campaign leverages a phishing kit designed to trick victims into approving attacker-controlled device codes on…
highperson_alertThreat ActorGreatness PhaaS Expands to AiTM and Device-Code Phishing via RingCentral
Greatness is a phishing-as-a-service (PhaaS) platform active since at least mid-2022, operated by cybercriminals who sell access for $289/month via a Telegram channel with thousands of subscribers.
highperson_alertThreat ActorMicrosoft Defender auto-isolates endpoint in 128 seconds at QNET
No specific threat actor is identified in this incident. The attack represents a common adversary pattern: initial access achieved directly on an endpoint, followed by attempted multi-stage payload delivery using living-off-the-land techniques.
highperson_alertThreat ActorMidnight Blizzard targets hospitality Wi-Fi in CaptiveCrunch campaign
Midnight Blizzard (APT29, also tracked as Storm-2945, IRON RITUAL, IRON HEMLOCK, NobleBaron, Dark Halo) is a Russian-attributed advanced persistent threat group linked to intelligence collection operations.
highperson_alertThreat ActorDOUBLECUP loader-as-a-service delivers malware via ClickFix attacks
DOUBLECUP is a Russian loader-as-a-service platform that has operated since early June 2026. The service provides customers with licenses and a Go-based Windows tool for creating malicious ClickFix campaigns.
highperson_alertThreat ActorStorm-2945 Hijacks Hotel Wi-Fi to Deploy CornFlake Surveillance RAT
Storm-2945 is assessed by Microsoft to be an operational sub-cluster of Midnight Blizzard (APT29, Cozy Bear), which the U.S. and U.K. governments attribute to Russia's Foreign Intelligence Service (SVR). The U.K.
criticalbug_reportVulnerabilityAzure Cosmos DB sandbox escape exposed platform-wide key to all databases
Microsoft Azure Cosmos DB, all customer tenants across all regions. Affects Gremlin, SQL, MongoDB, and Cassandra APIs. Vulnerability active from unknown date until July 2026 full remediation.
highbug_reportVulnerabilityRussian APT exploits OWA XSS flaw for persistent mailbox access
Microsoft Outlook Web Access (OWA) vulnerable to CVE-2026-42897 (CVSS 8.1), a cross-site scripting flaw. Targets include U.S. and European government entities, telecommunications, financial, hospitality, and aerospace sectors.
criticalperson_alertThreat ActorLaundry Bear exploits Exchange OWA zero-day to deploy OWAReaper backdoor
Laundry Bear (also tracked as Void Blizzard, TA488 by Proofpoint) is a Russian state-sponsored threat actor focused on long-term email intelligence collection.
highbug_reportVulnerabilityCertighost PoC released: AD CS flaw enables domain takeover via rogue CA
Microsoft Active Directory Certificate Services (AD CS) in Windows domains. CVE-2026-54121 patched in July 2026 Patch Tuesday. Affects environments using AD CS for certificate-based authentication where attackers have low-privileged domain user acces…
highperson_alertThreat ActorOperation BlueDash: Phishing Campaign Delivers RMM Tools via Fake Teams
Operation BlueDash is a phishing campaign attributed with moderate-to-high confidence to a threat actor group operating from Nigeria. The attribution is based on analysis of infrastructure, code history, and a GitHub environment used to operate the c…
highbug_reportVulnerabilityDNS hijacking on hotel Wi-Fi redirects users to fake Microsoft 365 logins
Wi-Fi gateways at hotels and conference centers in multiple U.S. cities, India, and Saudi Arabia. Targets traveling employees from financial services, professional services, legal, healthcare, energy, and retail sectors accessing Microsoft 365.
highperson_alertThreat ActorBlueNoroff Phishing Kit Profiles Crypto Wallets Before Malware Delivery
BlueNoroff (also tracked as APT38, NICKEL GLADSTONE, BeagleBoyz, Stardust Chollima) is a North Korean state-sponsored threat actor attributed to financially motivated operations targeting the cryptocurrency and technology sectors.
highbug_reportVulnerabilityCertighost exploit public for AD CS flaw allowing DC impersonation
Microsoft Active Directory Certificate Services (AD CS) on Windows Server 2012 through 2025 (including Server Core) and Windows 10 versions 1607 and 1809. Environments with Enterprise CA and default Machine certificate template are vulnerable.
criticalbug_reportVulnerabilityBing Images SVG flaw allowed unauthenticated RCE as SYSTEM on servers
Microsoft Bing Images service (CVE-2026-32194, CVE-2026-32191). Both Windows Server 2022 and Linux image-processing workers. Vulnerability exploitable via public "Search by Image" upload and URL-based image crawler.
highbug_reportVulnerabilityBing malvertising pushes fake Claude installer delivering SectopRAT
Microsoft Bing search users seeking Claude AI desktop app. Malicious Claude Artifact hosted on legitimate claude.ai domain (removed by Anthropic). At least 29 organizations compromised July 21-22, 2026.
highpublicGeopoliticalMicrosoft 365 outage disrupts cloud services across North America
The incident represents a technical service disruption affecting critical cloud infrastructure rather than a geopolitical cyber event. Microsoft 365's position as backbone infrastructure for government, defense, and commercial operations in North Ame…
highperson_alertThreat ActorChaos Ransomware Group Deploys msaRAT Rust Implant via Headless Browsers
Chaos is a ransomware group that operates through spam floods, vishing campaigns, Quick Assist abuse, and RMM tools for initial access and persistence. The group deploys custom tooling including the msaRAT Rust-based implant as a pre-ransomware stage…
highperson_alertThreat ActorChaos ransomware gang deploys msaRAT backdoor via browser hijacking
Chaos is a ransomware gang that emerged in early 2025, distinct from the earlier same-named ransomware family active since 2021. The group has been linked to Iranian state-backed threat actor MuddyWater, who reportedly leveraged Chaos ransomware to d…
criticalbug_reportVulnerabilityMicrosoft July 2026 Patch Tuesday: 569 vulnerabilities, 56 critical
Microsoft product portfolio (specific products and versions not disclosed in available data). 569 total vulnerabilities patched, including 56 rated critical severity.