Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 173 results
highbug_reportVulnerabilityOpenAI, Anthropic, Google reasoning APIs leaked secrets via session replay
OpenAI, Anthropic, and Google reasoning APIs (GPT-5.6 Luna, Claude Haiku 4.5, Gemini Robotics ER-1.6). Affects developers who published raw agent logs containing encrypted reasoning objects.
criticalbug_reportVulnerabilityMalicious LiteLLM PyPI packages stole credentials from 2,100+ orgs
LiteLLM versions 1.82.7 and 1.82.8 published on PyPI on March 24, 2026 (10:39-11:19 UTC, treat installs through 16:00 UTC as suspect). Any system that installed these versions or pulled them as transitive dependencies via agent frameworks or orchestr…
highbug_reportVulnerabilityShieldBreak zero-day bypasses Microsoft Defender patch, grants SYSTEM access
Microsoft Defender for Windows on Windows 11 25H2, Windows Server 2025, and Windows 10 (all editions). The vulnerability bypasses the patch for CVE-2026-50656 (RoguePlanet) in the Microsoft Malware Protection Engine (mpengine.dll).
highbug_reportVulnerabilityMicrosoft patches 398 flaws including one actively exploited zero-day
Microsoft Windows operating systems and supported software. All Windows endpoints are affected. Critical focus: CVE-2026-68820 (afd.sys driver privilege escalation, actively exploited), CVE-2026-62832 (Windows User Profile Service privilege escalatio…
criticalbug_reportVulnerabilityWindows kernel driver zero-day CVE-2026-68820 exploited by Lazarus APT
Windows kernel driver afd.sys (Ancillary Function Driver for WinSock) across all supported Windows versions. CVE-2026-68820 is a use-after-free vulnerability enabling local privilege escalation to SYSTEM level. CVSS 7.0.
highbug_reportVulnerabilityCisco ASA/FTD VPN flaw CVE-2026-20349 actively exploited for DoS
Cisco Secure Firewall ASA (versions 9.16, 9.18, 9.20, 9.22, 9.23, 9.24) and Threat Defense FTD (versions 7.0, 7.2, 7.4, 7.6, 7.7, 10.0) with Remote Access SSL VPN, IKEv2 Remote Access VPN with client services, or Zero Trust Network Access enabled.
highperson_alertThreat ActorNorth Korea IT Worker Infiltration Targets Crypto and Tech Firms
North Korean IT worker operations, attributed by researchers to Famous Chollima (a CrowdStrike designation under the Lazarus umbrella), involve operatives seeking employment at Western technology and cryptocurrency companies under fraudulent identiti…
criticalbug_reportVulnerabilityProgress Kemp LoadMaster command injection flaw exploited in the wild
Progress Kemp LoadMaster GA v7.2.63.1 and older, LTSF v7.2.54.17 and older; MOVEit WAF all versions before GA v7.2.63.2. Approximately 300 instances exposed online. Used by Fortune 500 companies and government agencies including Amazon and U.S.
criticalbug_reportVulnerabilityMetabase SQL injection zero-day exploited to steal customer data
Metabase (specific versions not disclosed). Confirmed victims include Framework and Tally customer instances. All unpatched Metabase deployments potentially at risk.
highbug_reportVulnerabilityClickFix attacks deliver macOS stealer targeting crypto wallets and Keychain
macOS systems (all CPU architectures). Users tricked into pasting malicious commands into Terminal. Targets cryptocurrency wallets (Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, XRP), browser passwords, Apple iCloud Keychain, and cached credentials.
criticalbug_reportVulnerability18-year-old Linux SCTP flaw enables local root and container escape
Linux kernel versions since 2.6.25 (2008) through 7.1.5, 6.18.41, 6.12.100, and 6.6.147. Affects systems with SCTP networking enabled. Confirmed vulnerable: Debian 13, Ubuntu 24.04, Rocky Linux 9, RHEL 9, OpenCloudOS.
highbug_reportVulnerabilityNatJack attacks hijack TCP sessions via NAT manipulation; Windows & Linux CVEs
Windows NAT (Hyper-V): Windows 11 24H2 <26100.8875, 25H2 <26200.8875, 26H1 <28000.2525, Server 2025 <26100.33158 (CVE-2026-56181, CVSS 8.3). Linux Netfilter conntrack: kernel <5.10.259, <5.15.210, <6.1.176, <6.6.143, <6.12.93, <6.18.35, <7.0.12, <7.1…
highbug_reportVulnerabilityAI system finds HTTP desync techniques; Apache Traffic Server zero-day patched
Apache Traffic Server (CVE-2026-63078, specific versions unknown); 700+ websites vulnerable to HTTP desynchronization including banks, government infrastructure, security products, and airports.
highbug_reportVulnerabilityClickFix campaign delivers Go-based macOS stealer targeting crypto wallets
macOS users across all versions; targets cryptocurrency wallets (Bitcoin, Ethereum, Litecoin, Dogecoin, Monero, XRP), browser password databases, Apple Keychain, and cached browser credentials.
highbug_reportVulnerabilityZapscape KVM flaw allows L1 guest escape to host with nested virtualization
Linux kernel KVM/x86 shadow MMU in versions 5.9 through 7.1.5. Fixed in stable releases 6.6.148, 6.12.101, 6.18.42, 7.1.6, and 7.2-rc5. Affects systems running KVM hosts with nested virtualization exposed to untrusted guests.
highbug_reportVulnerabilityApple iCloud Private Relay leaks real IP via WebKit proxy bypasses
Apple iCloud Private Relay on iOS 15+, macOS, and iPadOS. Affects Safari and all WebKit-based browsers (Chrome, Edge, Firefox, Brave) on Apple platforms. Impacts users with iCloud+ subscriptions using Private Relay for privacy protection.
highperson_alertThreat ActorCybercriminals Steal AI API Keys via Token Jacking for Resale
Cybercriminals targeting the AI development ecosystem are motivated by financial gain through the theft and resale of API keys (tokens) for premium AI platforms.
highperson_alertThreat ActorClickFix Campaign Uses Browser Fingerprinting to Target macOS Users
ClickFix is a macOS-focused social engineering campaign tracked by Microsoft Threat Intelligence. The operators remain unidentified, but the campaign demonstrates sophisticated evasion capabilities through server-side browser fingerprinting across mo…
highbug_reportVulnerabilityLinux kernel Open vSwitch flaw grants local root; public exploit available
Linux kernel Open vSwitch datapath. Fixed in stable kernels 5.15.212, 6.1.178, 6.6.145, 6.12.97, 6.18.40, and 7.1.5. Affects default configurations of AlmaLinux 9/10, Alpine 3.22-3.24, Amazon Linux 2023, Arch, CentOS Stream 9/10, Debian 12/13, Fedora…
highperson_alertThreat ActorGreatness PhaaS Expands to AiTM and Device-Code Phishing via RingCentral
Greatness is a phishing-as-a-service (PhaaS) platform active since at least mid-2022, operated by cybercriminals who sell access for $289/month via a Telegram channel with thousands of subscribers.
highbug_reportVulnerabilityXCSSET v40 malware targets macOS developers via poisoned Xcode projects
macOS developers using Xcode and downloading projects from compromised Git/GitHub repositories. XCSSET v40 observed in attacks mid-April and early May 2026. All macOS versions with Xcode are at risk; specific version details not provided.
highbug_reportVulnerability77 malicious Open VSX extensions harvested developer environment metadata
Open VSX marketplace users who installed any of 77 counterfeit "evil twin" extensions between July 26 and August 1, 2026. Extensions impersonated legitimate tools from AMD, Azure, Salesforce, Hyperledger, LEGO Education, IOTA, and a U.S.
highperson_alertThreat ActorMicrosoft Defender auto-isolates endpoint in 128 seconds at QNET
No specific threat actor is identified in this incident. The attack represents a common adversary pattern: initial access achieved directly on an endpoint, followed by attempted multi-stage payload delivery using living-off-the-land techniques.
criticalbug_reportVulnerabilityChainDrop worm compromises 1,300+ npm packages with 2B monthly downloads
Over 1,300 npm packages (1,381 versions) including Keyv, Cacheable, flat-cache, and file-entry-cache. Attack originated from compromised GitHub account of Keyv maintainer.
highbug_reportVulnerabilityMalware can hijack Google Password Manager passkeys on Windows via TPM abuse
Google Password Manager synced passkeys on Chrome for Windows with TPM. All three attacks require pre-existing malware on the victim's Windows device. Services that do not properly validate user verification flags (e.g., eBay, now patched) are vulner…
highperson_alertThreat ActorDOUBLECUP loader-as-a-service delivers malware via ClickFix attacks
DOUBLECUP is a Russian loader-as-a-service platform that has operated since early June 2026. The service provides customers with licenses and a Go-based Windows tool for creating malicious ClickFix campaigns.
highbug_reportVulnerability18 malicious npm packages deliver cross-platform RAT to Alibaba developers
18 npm packages targeting Alibaba developer tool users, primarily Chinese-speaking environments. Key packages: lib-mtop (v1.0.1-1.0.3), aone-kit, aone-kit-cli, aone-sandbox, local-config-parser, smart-config-manager, and 12 others.
highbug_reportVulnerabilityChrome Password Manager passkey bypass allows malware to hijack accounts
Google Chrome Password Manager on Windows systems with TPM. All three attack paths require malware already running as an ordinary user. Specific affected Chrome versions not disclosed.
highperson_alertThreat ActorChinese-Speaking Actor Deploys GHOSTBLADE via Leaked DarkSword iOS Kit
An unidentified Chinese-speaking threat actor conducting mobile exploitation campaigns against iOS devices. The actor operates extensive infrastructure spanning over 100 web properties concentrated in Hong Kong with reach into Japan, the United State…
highbug_reportVulnerabilityAdform ad platform compromised to inject crypto-stealing clipboard scripts
Adform ad platform and all websites embedding Adform advertising scripts. Any site visitor copying cryptocurrency wallet addresses during the compromise window was at risk of clipboard hijacking.