Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 91 results
criticalbug_reportVulnerabilityLangflow RCE (CVE-2026-33017) actively exploited for cryptomining
Langflow AI application framework, all exposed endpoints vulnerable to unauthenticated remote code execution. Specific affected versions not disclosed; assume all unpatched instances at risk.
highbug_reportVulnerabilityFake Perplexity AI Chrome extension hijacks search traffic on Web Store
Google Chrome users who installed the malicious Perplexity AI impersonator extension from the Chrome Web Store. Affects organizations and individuals using Chrome browser seeking AI productivity tools.
highperson_alertThreat ActorShinyHunters Exploits Oracle PeopleSoft Zero-Day in Nissan Breach
ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has established a pattern of exploiting vulnerabilities in enterprise applications to exfiltrate sensitive data, which is th…
highperson_alertThreat ActorMalicious Chrome Extension Impersonates Perplexity AI to Intercept Searches
The threat actor behind this campaign remains unattributed. The operation demonstrates a financially or espionage-motivated adversary leveraging social engineering through brand impersonation of Perplexity AI, a popular search technology.
highbug_reportVulnerability236K+ malicious sites use DCloud Uni-App templates for crypto scams
Organizations and users interacting with websites built using DCloud Uni-App framework templates. Over 236,000 malicious sites identified conducting cryptocurrency scams, phishing, wallet draining, pig-butchering schemes, and fake gambling platforms.
criticalbug_reportVulnerabilityLinux kernel traffic-control flaw grants local root via public exploit
Linux kernel traffic-control subsystem (act_pedit module). All distributions running vulnerable kernel versions are affected. Specific patched versions not provided; assume unpatched kernels prior to June 16, 2026 vendor advisories are vulnerable.
highbug_reportVulnerabilityDirtyClone Linux kernel flaw enables local privilege escalation to root
Linux kernel (specific vulnerable versions not disclosed). Affects systems where local users can trigger network packet cloning operations. Part of the DirtyFrag vulnerability family.
highperson_alertThreat ActorWhatsApp VBScript Campaign Deploys ManageEngine RMM Across 9 Countries
This campaign represents an unattributed threat activity leveraging WhatsApp as an initial access vector. The actor's motivation appears to be establishing persistent remote access to victim systems through legitimate remote monitoring and management…
highbug_reportVulnerabilityDifyTap flaws enable cross-tenant AI conversation theft in Dify platform
Dify open-source agentic workflow platform. Specific affected versions not disclosed. Vulnerability enables cross-tenant data access, affecting multi-tenant deployments and cloud-hosted instances.
highbug_reportVulnerability29-year-old Squid heap over-read leaks HTTP credentials in default config
Squid web proxy, all versions containing FTP parsing code from 1997 onward. Vulnerability present in default configuration. Affects organizations using Squid as forward or reverse proxy.
highbug_reportVulnerabilityAutoJack exploit chain enables RCE on AI browsing agents via malicious pages
AI browsing agents (autonomous web browsers with AI capabilities) that interact with privileged local services via JavaScript. Specific products and versions not disclosed in Microsoft's research disclosure.
highbug_reportVulnerabilityF5 patches high-severity flaws in NGINX Open Source and Gateway Fabric
NGINX Open Source and NGINX Gateway Fabric (specific versions not provided). Four CVEs: CVE-2026-11311, CVE-2026-42055, CVE-2026-42530, CVE-2026-50107. Affects organizations running NGINX web servers, reverse proxies, API gateways, and Kubernetes ing…
criticalbug_reportVulnerabilityNGINX Open Source RCE via HTTP/3 use-after-free (CVE-2026-42530)
NGINX Open Source versions with ngx_http_v3_module enabled. Specific vulnerable versions not provided in summary. F5 NGINX products potentially affected.
highbug_reportVulnerabilityWeekly threat roundup: Claude abuse, npm poisoning, phishing campaigns
Multiple platforms and products: Claude AI chat interface, npm package ecosystem (NastyC2), OAuth device-code flows, browser extensions (unspecified), macOS systems, cloud management agents, and internet-exposed edge devices.
highperson_alertThreat ActorIcarus Threat Actor Exploits OAuth to Steal Salesforce Data via Klue
Icarus is a threat actor conducting an ongoing extortion campaign targeting organizations through supply chain compromise. The actor exploited OAuth authentication mechanisms to breach Klue, a market intelligence platform, gaining unauthorized access…
highbug_reportVulnerabilityMicrosoft Defender zero-day CVE-2026-50656 enables privilege escalation
Microsoft Defender Malware Protection Engine across all Windows versions. Specific affected engine versions not disclosed. Impacts enterprise and consumer deployments relying on Microsoft Defender for endpoint protection.
highbug_reportVulnerabilityMalicious AI plugins on JetBrains Marketplace exfiltrate developer API keys
JetBrains Marketplace users who installed any of 15+ malicious plugins impersonating AI coding assistants (DeepSeek and other LLM-based tools). Affects developers using JetBrains IDEs (IntelliJ IDEA, PyCharm, WebStorm, etc.).
highbug_reportVulnerabilityMicrosoft Defender zero-day "RoguePlanet" awaits patch after disclosure
Microsoft Defender (all versions currently deployed). Specific affected versions not disclosed. Impacts organizations relying on Defender for endpoint protection.
highbug_reportVulnerabilityMalicious JetBrains IDE plugins steal AI API keys from developers
JetBrains Marketplace users who installed any of the 15+ malicious plugins. Affects developers using JetBrains IDEs (IntelliJ IDEA, PyCharm, WebStorm, etc.) with AI API keys configured. Specific plugin names and versions not provided in summary.
highperson_alertThreat ActorContagious Interview targets developers via recruitment-themed phishing
Contagious Interview (also tracked as DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, and DEV#POPPER) is a North Korean-aligned threat actor cluster that specializes in social engineering attacks against software developers and technology secto…
criticalbug_reportVulnerabilityLiteLLM AI gateway vulnerable to privilege escalation and RCE
LiteLLM open-source AI gateway. Specific affected versions not disclosed. Impacts organizations using LiteLLM to manage API keys and route requests to AI providers (OpenAI, Anthropic, etc.).
highperson_alertThreat ActorChinese Cybercrime Network Weaponizes Google Gemini AI for SMS Phishing
A Chinese cybercrime network operating a phishing-as-a-service (PhaaS) platform called Outsider. The group weaponizes Google's Gemini AI to craft and conduct SMS-based phishing attacks (smishing) targeting American victims.
highbug_reportVulnerabilityOpenClaw AI agent vulnerable to prompt injection via vCards and location pins
OpenClaw self-hosted AI agent platform, all versions. Vulnerability affects input processing mechanisms for vCards, location pins, and potentially other structured data formats.
highbug_reportVulnerabilityBitLocker bypass via recovery partition XML files (GreatXML)
Windows BitLocker encryption on systems with recovery partitions. All Windows versions with BitLocker enabled are potentially affected. Specific version scope not yet published.
criticalbug_reportVulnerabilityFortinet FortiSandbox command injection flaw enables remote code execution
Fortinet FortiSandbox products affected by CVE-2026-25089 (CVSS 9.1). Specific vulnerable versions not disclosed in provided data. Ivanti and SAP also released patches for separate critical vulnerabilities.
criticalbug_reportVulnerabilityLangflow path traversal flaw (CVE-2026-5027) exploited for RCE
Langflow open-source low-code AI platform, all unpatched versions. Vulnerability allows unauthenticated path traversal leading to arbitrary file write and remote code execution.
highbug_reportVulnerabilityCisco Catalyst SD-WAN Manager actively exploited (CVE-2026-20245)
Cisco Catalyst SD-WAN Manager. Specific affected versions not disclosed. Vulnerability involves improper encoding or escaping of output (CVSS 7.8). Also affects products from Google and Arista (details not provided).
criticalbug_reportVulnerabilityMicrosoft patches 3 zero-days: YellowKey, GreenPlasma, MiniPlasma
All fully patched Windows systems prior to latest patch release. YellowKey and GreenPlasma enable SYSTEM privilege escalation; MiniPlasma bypasses BitLocker encryption on protected drives.
criticalbug_reportVulnerabilityMicrosoft Defender zero-day "RoguePlanet" exploited for SYSTEM access
Microsoft Defender on all updated Windows systems. No CVE assigned yet. Vulnerability is a race condition enabling local privilege escalation to SYSTEM.
highbug_reportVulnerabilitySix RCE and DoS flaws found in protobuf.js for Node.js applications
protobuf.js library (JavaScript/TypeScript implementation of Protocol Buffers) used in Node.js applications. Specific vulnerable versions not provided in summary.