Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 173 results
Active filter:tag: #technology✕ clear
OpenAI, Anthropic, Google reasoning APIs leaked secrets via session replayhighbug_reportVulnerability
bug_reportVulnerability

OpenAI, Anthropic, Google reasoning APIs leaked secrets via session replay

OpenAI, Anthropic, and Google reasoning APIs (GPT-5.6 Luna, Claude Haiku 4.5, Gemini Robotics ER-1.6). Affects developers who published raw agent logs containing encrypted reasoning objects.

OpenAI12 Aug · 09:47 UTC
Malicious LiteLLM PyPI packages stole credentials from 2,100+ orgscriticalbug_reportVulnerability
bug_reportVulnerability

Malicious LiteLLM PyPI packages stole credentials from 2,100+ orgs

LiteLLM versions 1.82.7 and 1.82.8 published on PyPI on March 24, 2026 (10:39-11:19 UTC, treat installs through 16:00 UTC as suspect). Any system that installed these versions or pulled them as transitive dependencies via agent frameworks or orchestr…

LiteLLM12 Aug · 06:04 UTC
ShieldBreak zero-day bypasses Microsoft Defender patch, grants SYSTEM accesshighbug_reportVulnerability
bug_reportVulnerability

ShieldBreak zero-day bypasses Microsoft Defender patch, grants SYSTEM access

Microsoft Defender for Windows on Windows 11 25H2, Windows Server 2025, and Windows 10 (all editions). The vulnerability bypasses the patch for CVE-2026-50656 (RoguePlanet) in the Microsoft Malware Protection Engine (mpengine.dll).

CVE-2026-5065612 Aug · 04:41 UTC
Microsoft patches 398 flaws including one actively exploited zero-dayhighbug_reportVulnerability
bug_reportVulnerability

Microsoft patches 398 flaws including one actively exploited zero-day

Microsoft Windows operating systems and supported software. All Windows endpoints are affected. Critical focus: CVE-2026-68820 (afd.sys driver privilege escalation, actively exploited), CVE-2026-62832 (Windows User Profile Service privilege escalatio…

Microsoft11 Aug · 19:28 UTC
Windows kernel driver zero-day CVE-2026-68820 exploited by Lazarus APTcriticalbug_reportVulnerability
bug_reportVulnerability

Windows kernel driver zero-day CVE-2026-68820 exploited by Lazarus APT

Windows kernel driver afd.sys (Ancillary Function Driver for WinSock) across all supported Windows versions. CVE-2026-68820 is a use-after-free vulnerability enabling local privilege escalation to SYSTEM level. CVSS 7.0.

CVE-2026-6882011 Aug · 18:10 UTC
Cisco ASA/FTD VPN flaw CVE-2026-20349 actively exploited for DoShighbug_reportVulnerability
bug_reportVulnerability

Cisco ASA/FTD VPN flaw CVE-2026-20349 actively exploited for DoS

Cisco Secure Firewall ASA (versions 9.16, 9.18, 9.20, 9.22, 9.23, 9.24) and Threat Defense FTD (versions 7.0, 7.2, 7.4, 7.6, 7.7, 10.0) with Remote Access SSL VPN, IKEv2 Remote Access VPN with client services, or Zero Trust Network Access enabled.

Cisco11 Aug · 17:45 UTC
North Korea IT Worker Infiltration Targets Crypto and Tech Firmshighperson_alertThreat Actor
person_alertThreat Actor

North Korea IT Worker Infiltration Targets Crypto and Tech Firms

North Korean IT worker operations, attributed by researchers to Famous Chollima (a CrowdStrike designation under the Lazarus umbrella), involve operatives seeking employment at Western technology and cryptocurrency companies under fraudulent identiti…

The Hacker News11 Aug · 09:35 UTC
Progress Kemp LoadMaster command injection flaw exploited in the wildcriticalbug_reportVulnerability
bug_reportVulnerability

Progress Kemp LoadMaster command injection flaw exploited in the wild

Progress Kemp LoadMaster GA v7.2.63.1 and older, LTSF v7.2.54.17 and older; MOVEit WAF all versions before GA v7.2.63.2. Approximately 300 instances exposed online. Used by Fortune 500 companies and government agencies including Amazon and U.S.

Progress10 Aug · 07:49 UTC
Metabase SQL injection zero-day exploited to steal customer datacriticalbug_reportVulnerability
bug_reportVulnerability

Metabase SQL injection zero-day exploited to steal customer data

Metabase (specific versions not disclosed). Confirmed victims include Framework and Tally customer instances. All unpatched Metabase deployments potentially at risk.

Metabase7 Aug · 18:14 UTC
ClickFix attacks deliver macOS stealer targeting crypto wallets and Keychainhighbug_reportVulnerability
bug_reportVulnerability

ClickFix attacks deliver macOS stealer targeting crypto wallets and Keychain

macOS systems (all CPU architectures). Users tricked into pasting malicious commands into Terminal. Targets cryptocurrency wallets (Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, XRP), browser passwords, Apple iCloud Keychain, and cached credentials.

Apple7 Aug · 16:29 UTC
18-year-old Linux SCTP flaw enables local root and container escapecriticalbug_reportVulnerability
bug_reportVulnerability

18-year-old Linux SCTP flaw enables local root and container escape

Linux kernel versions since 2.6.25 (2008) through 7.1.5, 6.18.41, 6.12.100, and 6.6.147. Affects systems with SCTP networking enabled. Confirmed vulnerable: Debian 13, Ubuntu 24.04, Rocky Linux 9, RHEL 9, OpenCloudOS.

Linux7 Aug · 09:10 UTC
NatJack attacks hijack TCP sessions via NAT manipulation; Windows & Linux CVEshighbug_reportVulnerability
bug_reportVulnerability

NatJack attacks hijack TCP sessions via NAT manipulation; Windows & Linux CVEs

Windows NAT (Hyper-V): Windows 11 24H2 <26100.8875, 25H2 <26200.8875, 26H1 <28000.2525, Server 2025 <26100.33158 (CVE-2026-56181, CVSS 8.3). Linux Netfilter conntrack: kernel <5.10.259, <5.15.210, <6.1.176, <6.6.143, <6.12.93, <6.18.35, <7.0.12, <7.1…

Microsoft7 Aug · 08:58 UTC
AI system finds HTTP desync techniques; Apache Traffic Server zero-day patchedhighbug_reportVulnerability
bug_reportVulnerability

AI system finds HTTP desync techniques; Apache Traffic Server zero-day patched

Apache Traffic Server (CVE-2026-63078, specific versions unknown); 700+ websites vulnerable to HTTP desynchronization including banks, government infrastructure, security products, and airports.

Apache7 Aug · 08:09 UTC
ClickFix campaign delivers Go-based macOS stealer targeting crypto walletshighbug_reportVulnerability
bug_reportVulnerability

ClickFix campaign delivers Go-based macOS stealer targeting crypto wallets

macOS users across all versions; targets cryptocurrency wallets (Bitcoin, Ethereum, Litecoin, Dogecoin, Monero, XRP), browser password databases, Apple Keychain, and cached browser credentials.

BleepingComputer6 Aug · 20:37 UTC
Zapscape KVM flaw allows L1 guest escape to host with nested virtualizationhighbug_reportVulnerability
bug_reportVulnerability

Zapscape KVM flaw allows L1 guest escape to host with nested virtualization

Linux kernel KVM/x86 shadow MMU in versions 5.9 through 7.1.5. Fixed in stable releases 6.6.148, 6.12.101, 6.18.42, 7.1.6, and 7.2-rc5. Affects systems running KVM hosts with nested virtualization exposed to untrusted guests.

CVE-2026-645616 Aug · 15:58 UTC
Apple iCloud Private Relay leaks real IP via WebKit proxy bypasseshighbug_reportVulnerability
bug_reportVulnerability

Apple iCloud Private Relay leaks real IP via WebKit proxy bypasses

Apple iCloud Private Relay on iOS 15+, macOS, and iPadOS. Affects Safari and all WebKit-based browsers (Chrome, Edge, Firefox, Brave) on Apple platforms. Impacts users with iCloud+ subscriptions using Private Relay for privacy protection.

Apple6 Aug · 09:33 UTC
Cybercriminals Steal AI API Keys via Token Jacking for Resalehighperson_alertThreat Actor
person_alertThreat Actor

Cybercriminals Steal AI API Keys via Token Jacking for Resale

Cybercriminals targeting the AI development ecosystem are motivated by financial gain through the theft and resale of API keys (tokens) for premium AI platforms.

Unit 42 (Palo Alto)6 Aug · 08:00 UTC
ClickFix Campaign Uses Browser Fingerprinting to Target macOS Usershighperson_alertThreat Actor
person_alertThreat Actor

ClickFix Campaign Uses Browser Fingerprinting to Target macOS Users

ClickFix is a macOS-focused social engineering campaign tracked by Microsoft Threat Intelligence. The operators remain unidentified, but the campaign demonstrates sophisticated evasion capabilities through server-side browser fingerprinting across mo…

Apple5 Aug · 16:44 UTC
Linux kernel Open vSwitch flaw grants local root; public exploit availablehighbug_reportVulnerability
bug_reportVulnerability

Linux kernel Open vSwitch flaw grants local root; public exploit available

Linux kernel Open vSwitch datapath. Fixed in stable kernels 5.15.212, 6.1.178, 6.6.145, 6.12.97, 6.18.40, and 7.1.5. Affects default configurations of AlmaLinux 9/10, Alpine 3.22-3.24, Amazon Linux 2023, Arch, CentOS Stream 9/10, Debian 12/13, Fedora…

CVE-2026-645315 Aug · 09:43 UTC
Greatness PhaaS Expands to AiTM and Device-Code Phishing via RingCentralhighperson_alertThreat Actor
person_alertThreat Actor

Greatness PhaaS Expands to AiTM and Device-Code Phishing via RingCentral

Greatness is a phishing-as-a-service (PhaaS) platform active since at least mid-2022, operated by cybercriminals who sell access for $289/month via a Telegram channel with thousands of subscribers.

Microsoft4 Aug · 19:45 UTC
XCSSET v40 malware targets macOS developers via poisoned Xcode projectshighbug_reportVulnerability
bug_reportVulnerability

XCSSET v40 malware targets macOS developers via poisoned Xcode projects

macOS developers using Xcode and downloading projects from compromised Git/GitHub repositories. XCSSET v40 observed in attacks mid-April and early May 2026. All macOS versions with Xcode are at risk; specific version details not provided.

Apple4 Aug · 17:03 UTC
77 malicious Open VSX extensions harvested developer environment metadatahighbug_reportVulnerability
bug_reportVulnerability

77 malicious Open VSX extensions harvested developer environment metadata

Open VSX marketplace users who installed any of 77 counterfeit "evil twin" extensions between July 26 and August 1, 2026. Extensions impersonated legitimate tools from AMD, Azure, Salesforce, Hyperledger, LEGO Education, IOTA, and a U.S.

Open VSX4 Aug · 16:50 UTC
Microsoft Defender auto-isolates endpoint in 128 seconds at QNEThighperson_alertThreat Actor
person_alertThreat Actor

Microsoft Defender auto-isolates endpoint in 128 seconds at QNET

No specific threat actor is identified in this incident. The attack represents a common adversary pattern: initial access achieved directly on an endpoint, followed by attempted multi-stage payload delivery using living-off-the-land techniques.

Microsoft4 Aug · 15:54 UTC
ChainDrop worm compromises 1,300+ npm packages with 2B monthly downloadscriticalbug_reportVulnerability
bug_reportVulnerability

ChainDrop worm compromises 1,300+ npm packages with 2B monthly downloads

Over 1,300 npm packages (1,381 versions) including Keyv, Cacheable, flat-cache, and file-entry-cache. Attack originated from compromised GitHub account of Keyv maintainer.

npm4 Aug · 13:24 UTC
Malware can hijack Google Password Manager passkeys on Windows via TPM abusehighbug_reportVulnerability
bug_reportVulnerability

Malware can hijack Google Password Manager passkeys on Windows via TPM abuse

Google Password Manager synced passkeys on Chrome for Windows with TPM. All three attacks require pre-existing malware on the victim's Windows device. Services that do not properly validate user verification flags (e.g., eBay, now patched) are vulner…

Google3 Aug · 21:58 UTC
DOUBLECUP loader-as-a-service delivers malware via ClickFix attackshighperson_alertThreat Actor
person_alertThreat Actor

DOUBLECUP loader-as-a-service delivers malware via ClickFix attacks

DOUBLECUP is a Russian loader-as-a-service platform that has operated since early June 2026. The service provides customers with licenses and a Go-based Windows tool for creating malicious ClickFix campaigns.

Microsoft3 Aug · 18:01 UTC
18 malicious npm packages deliver cross-platform RAT to Alibaba developershighbug_reportVulnerability
bug_reportVulnerability

18 malicious npm packages deliver cross-platform RAT to Alibaba developers

18 npm packages targeting Alibaba developer tool users, primarily Chinese-speaking environments. Key packages: lib-mtop (v1.0.1-1.0.3), aone-kit, aone-kit-cli, aone-sandbox, local-config-parser, smart-config-manager, and 12 others.

Alibaba3 Aug · 16:43 UTC
Chrome Password Manager passkey bypass allows malware to hijack accountshighbug_reportVulnerability
bug_reportVulnerability

Chrome Password Manager passkey bypass allows malware to hijack accounts

Google Chrome Password Manager on Windows systems with TPM. All three attack paths require malware already running as an ordinary user. Specific affected Chrome versions not disclosed.

Google3 Aug · 14:24 UTC
Chinese-Speaking Actor Deploys GHOSTBLADE via Leaked DarkSword iOS Kithighperson_alertThreat Actor
person_alertThreat Actor

Chinese-Speaking Actor Deploys GHOSTBLADE via Leaked DarkSword iOS Kit

An unidentified Chinese-speaking threat actor conducting mobile exploitation campaigns against iOS devices. The actor operates extensive infrastructure spanning over 100 web properties concentrated in Hong Kong with reach into Japan, the United State…

Apple3 Aug · 08:49 UTC
Adform ad platform compromised to inject crypto-stealing clipboard scriptshighbug_reportVulnerability
bug_reportVulnerability

Adform ad platform compromised to inject crypto-stealing clipboard scripts

Adform ad platform and all websites embedding Adform advertising scripts. Any site visitor copying cryptocurrency wallet addresses during the compromise window was at risk of clipboard hijacking.

Adform31 Jul · 19:09 UTC