Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 702 results
Active filter:tag: #vulnerability✕ clear
BGP hijack delivers malicious Virtualizor updates to VPS management systemscriticalbug_reportVulnerability
bug_reportVulnerability

BGP hijack delivers malicious Virtualizor updates to VPS management systems

Virtualizor VPS management software (all versions prior to 3.2.9.9) from Softaculous. Attack window: August 28, 2026 20:57 UTC to August 30, 2026 06:10 UTC.

Virtualizor1 Sep · 12:45 UTC
13 malicious Packagist packages target iOS devices to steal crypto walletshighbug_reportVulnerability
bug_reportVulnerability

13 malicious Packagist packages target iOS devices to steal crypto wallets

Packagist/Composer ecosystem: 13 malicious theme packages across 5 vendor namespaces (vsmov, vsphim, haiau009, chilltvcms, ophimcms). Targets Vietnamese streaming sites using OphimCMS/KKPhim.

Packagist1 Sep · 12:07 UTC
22K Exchange servers unpatched for CVE-2026-62911 auth bypass flawhighbug_reportVulnerability
bug_reportVulnerability

22K Exchange servers unpatched for CVE-2026-62911 auth bypass flaw

Microsoft Exchange Server 2016, 2019, and Subscription Edition (SE). Approximately 21,899 internet-exposed servers remain unpatched globally, with highest concentrations in the United States (6,200) and Germany (5,100).

Microsoft1 Sep · 10:38 UTC
PaperCut NG/MF zero-days exploited for data theft via auth bypass and RCEhighbug_reportVulnerability
bug_reportVulnerability

PaperCut NG/MF zero-days exploited for data theft via auth bypass and RCE

PaperCut NG and MF print management software, all versions prior to Emergency Patch Release 3 (issued September 2026). Affects internet-facing Application Servers.

PaperCut1 Sep · 05:48 UTC
Langflow and Ruby on Rails flaws actively exploited for RCE and C2criticalbug_reportVulnerability
bug_reportVulnerability

Langflow and Ruby on Rails flaws actively exploited for RCE and C2

Langflow (CVE-2026-0768, CVSS 9.8): arbitrary Python code execution as root via improper input validation. Ruby on Rails (CVE-2026-66066 aka KindaRails2Shell, CVSS 9.5): unauthenticated arbitrary file read, secret leakage, and RCE in applications usi…

CVE-2026-07681 Sep · 05:22 UTC
TerminalFix campaign uses fake CAPTCHAs to deploy reverse tunnelshighbug_reportVulnerability
bug_reportVulnerability

TerminalFix campaign uses fake CAPTCHAs to deploy reverse tunnels

Windows systems with PowerShell and Windows Terminal enabled. Targets organizations with Active Directory environments. Attack vector: compromised websites displaying fake Cloudflare CAPTCHA prompts.

Microsoft31 Aug · 16:51 UTC
19 malicious Chrome/Edge extensions steal crypto and credentialshighbug_reportVulnerability
bug_reportVulnerability

19 malicious Chrome/Edge extensions steal crypto and credentials

Google Chrome and Microsoft Edge users who installed any of 19 malicious extensions, including "Enable Right Click & Copy" (70,000+ Chrome users, 10,000+ Edge users). Campaign active since early 2024.

Google30 Aug · 12:17 UTC
TerminalFix campaign uses fake CAPTCHAs to deploy reverse-tunnel backdoorhighbug_reportVulnerability
bug_reportVulnerability

TerminalFix campaign uses fake CAPTCHAs to deploy reverse-tunnel backdoor

Organizations across multiple sectors using Windows environments with PowerShell and Windows Terminal. Attack leverages compromised websites serving fake Cloudflare CAPTCHA pages to social engineer users into executing malicious PowerShell commands.

Microsoft30 Aug · 05:36 UTC
Critical WordPress plugin flaws enable auth bypass and RCE on popular sitescriticalbug_reportVulnerability
bug_reportVulnerability

Critical WordPress plugin flaws enable auth bypass and RCE on popular sites

WPMU DEV Dashboard plugin ≤5.0.1 (CVE-2026-76581), Avada theme ≤7.16 with Fusion Builder ≤3.16 (CVE-2026-18431), TranslatePress ≤3.3.1 with specific config (CVE-2026-19632), Pods plugin ≤3.3.9 (CVE-2026-19598), GiveWP plugin ≤4.16.7.1 (CVE-2026-82222…

CVE-2026-7658129 Aug · 14:25 UTC
Cosmos EVM balance flaw exploited on six chains after delayed patchcriticalbug_reportVulnerability
bug_reportVulnerability

Cosmos EVM balance flaw exploited on six chains after delayed patch

Cosmos EVM module versions < 0.6.2 and >= 0.7.0 < 0.7.2. All blockchains running Cosmos EVM with permissionless vesting account creation are vulnerable. Six chains were exploited August 20–25, 2026. Fixed in v0.6.2 and v0.7.2 (released August 19).

Cosmos Labs28 Aug · 18:38 UTC
PaperCut NG/MF actively exploited; second emergency patch releasedcriticalbug_reportVulnerability
bug_reportVulnerability

PaperCut NG/MF actively exploited; second emergency patch released

PaperCut NG and MF print management software versions 24, 25, and 26 on Windows, Linux, and macOS. CVE-2026-81578 (CVSS 8.8) authentication bypass and CVE-2026-82078 (CVSS 9.4) unsafe class-loading vulnerability can be chained for pre-auth RCE.

PaperCut28 Aug · 17:08 UTC
GiveWP WordPress plugin RCE allows unauthenticated server takeovercriticalbug_reportVulnerability
bug_reportVulnerability

GiveWP WordPress plugin RCE allows unauthenticated server takeover

GiveWP WordPress donation plugin versions 4.16.6 through 4.16.7.1. Over 100,000 active installations. Exploitation requires legacy donation forms without 'formBuilderSettings' (common in upgraded sites or when using option-based form editor).

GiveWP28 Aug · 16:18 UTC
PaperCut NG/MF flaws chained for unauthenticated RCE, active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

PaperCut NG/MF flaws chained for unauthenticated RCE, active exploitation

PaperCut NG and PaperCut MF (all unpatched versions). CVE-2026-81578 (CVSS 8.8, improper access control) and CVE-2026-82078 (CVSS 9.4, unsafe dynamic class loading) are chained to bypass authentication and execute arbitrary Java code.

PaperCut28 Aug · 15:12 UTC
ownCloud CVE-2023-49105 exploited to steal nuclear records from Philippinescriticalbug_reportVulnerability
bug_reportVulnerability

ownCloud CVE-2023-49105 exploited to steal nuclear records from Philippines

ownCloud core versions 10.6.0 through 10.13.0. The vulnerability is a WebDAV API authentication bypass allowing unauthenticated file access when usernames are known and no signing-key is configured (default state). Fixed in version 10.13.1.

CVE-2023-4910528 Aug · 13:56 UTC
19 malicious Chrome/Edge extensions drain crypto wallets via auto-updateshighbug_reportVulnerability
bug_reportVulnerability

19 malicious Chrome/Edge extensions drain crypto wallets via auto-updates

19 browser extensions (18 Chrome, 1 Edge) published since February 2024, with "Enable Right Click & Copy — Smart Unlock + OCR" having 80,000 installs. Extensions either created by threat actor or purchased from legitimate owners.

Google28 Aug · 13:27 UTC
WatchGuard Fireware OS vulnerabilities require immediate patchinghighbug_reportVulnerability
bug_reportVulnerability

WatchGuard Fireware OS vulnerabilities require immediate patching

WatchGuard Fireware OS - specific versions not provided in advisory. Affects WatchGuard firewall appliances running vulnerable Fireware OS versions.

WatchGuard28 Aug · 13:08 UTC
Critical vulnerabilities in PaperCut software require immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical vulnerabilities in PaperCut software require immediate patching

PaperCut software (specific versions not disclosed in advisory). Affects organizations using PaperCut print management solutions.

PaperCut28 Aug · 13:03 UTC
ServiceNow platforms face critical vulnerabilities requiring urgent patchingcriticalbug_reportVulnerability
bug_reportVulnerability

ServiceNow platforms face critical vulnerabilities requiring urgent patching

ServiceNow platforms (specific versions not disclosed in advisory). Scope and affected components not detailed in available information.

ServiceNow28 Aug · 12:09 UTC
8,300+ Gitea servers unpatched against exploited RCE flaw CVE-2026-60004criticalbug_reportVulnerability
bug_reportVulnerability

8,300+ Gitea servers unpatched against exploited RCE flaw CVE-2026-60004

Gitea versions prior to 1.27.1. Over 8,300 Internet-exposed instances remain vulnerable. Affects self-hosted Gitea installations with default open registration enabled.

Gitea28 Aug · 10:58 UTC
Unitree G1 EDU robot vulnerable to dual root RCE via network and BLEcriticalbug_reportVulnerability
bug_reportVulnerability

Unitree G1 EDU robot vulnerable to dual root RCE via network and BLE

Unitree G1 EDU humanoid robot. Firmware versions not definitively confirmed; researcher tested V1.5.2. G1 (non-EDU) and other Unitree robot models have unconfirmed applicability. Both vulnerabilities grant root access on the Locomotion PC.

CVE-2026-7663928 Aug · 10:07 UTC
ServiceNow AI Platform: Three CVSS 10.0 flaws enable unauthenticated RCEcriticalbug_reportVulnerability
bug_reportVulnerability

ServiceNow AI Platform: Three CVSS 10.0 flaws enable unauthenticated RCE

ServiceNow AI Platform versions: Xanadu (before Patch 11 HF 7a), Yokohama (before Patch 12 HF 3b / Patch 13 HF 4), Zurich (before Patch 7b HF 3 through Patch 12 depending on branch), Australia (before Patch 2 HF 3 through Patch 5).

ServiceNow28 Aug · 09:20 UTC
ZBT routers ship with factory implants granting root access via networkcriticalbug_reportVulnerability
bug_reportVulnerability

ZBT routers ship with factory implants granting root access via network

ZBT (Shenzhen Zhibotong Electronics) routers and white-labeled variants. CVE-2026-74233 (DARKLANTERN) affects 16+ models including WE1326, WE826-T2, WE5926, WG3526 on firmware builds from 2019-2020.

CVE-2026-7423228 Aug · 08:58 UTC
ServiceNow AI Platform: 3 critical unauthenticated flaws patchedcriticalbug_reportVulnerability
bug_reportVulnerability

ServiceNow AI Platform: 3 critical unauthenticated flaws patched

ServiceNow AI Platform (formerly Now Platform): Xanadu Patch 11, Yokohama Patch 12-13, Zurich Patch 7-12, Australia Patch 2-5. Affects cloud (auto-patched) and self-hosted instances.

ServiceNow28 Aug · 08:29 UTC
PaperCut NG/MF zero-day exploited in wild; all versions affectedcriticalbug_reportVulnerability
bug_reportVulnerability

PaperCut NG/MF zero-day exploited in wild; all versions affected

All versions of PaperCut NG and PaperCut MF print management software. Primary risk: Internet-exposed Application Servers with public-facing web interfaces.

PaperCut27 Aug · 14:31 UTC
Next.js critical RCE flaws in AVIF processing and Windows path traversalcriticalbug_reportVulnerability
bug_reportVulnerability

Next.js critical RCE flaws in AVIF processing and Windows path traversal

Next.js versions 13.4–15.5.23 and 16.0–16.3.2. CVE-2026-75604 (Windows path traversal, CVSS 9.0) affects Windows-hosted servers using Pages Router or App Router without Cache Components.

CVE-2026-7560427 Aug · 13:13 UTC
Weekly roundup: 296K IoT botnet, water system attacks, SharePoint RCEhighbug_reportVulnerability
bug_reportVulnerability

Weekly roundup: 296K IoT botnet, water system attacks, SharePoint RCE

Multiple products and sectors: 296,000 IoT devices compromised by Dysphoria botnet; 100+ water systems targeted (details not provided in excerpt); SharePoint RCE vulnerability chain (CVE/version unspecified); Android banking apps targeted by Octagon…

The Hacker News27 Aug · 13:12 UTC
Apache Log4j2 deserialization filter bypass enables remote code executioncriticalbug_reportVulnerability
bug_reportVulnerability

Apache Log4j2 deserialization filter bypass enables remote code execution

Apache Log4j2 logging library. Specific affected versions not disclosed in available information. Impacts Java applications using Log4j2 with deserialization features enabled.

Apache27 Aug · 12:57 UTC
Veeam ONE authentication bypass requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Veeam ONE authentication bypass requires immediate patching

Veeam ONE backup management platform. Specific affected versions not disclosed in available information. Authentication bypass vulnerability allows unauthorized access.

Veeam27 Aug · 12:51 UTC
Amazon Kiro IDE prompt injection enables data exfiltration via Powershighbug_reportVulnerability
bug_reportVulnerability

Amazon Kiro IDE prompt injection enables data exfiltration via Powers

Amazon Kiro IDE version 0.7.45 on Windows. Vulnerability fixed in version 0.8.140. Latest version is 1.0.337. Affects both trusted and untrusted workspaces when malicious workspace files are opened.

Amazon27 Aug · 11:39 UTC
Australia arrests two TeamPCP members behind global supply chain attackshighbug_reportVulnerability
bug_reportVulnerability

Australia arrests two TeamPCP members behind global supply chain attacks

Over 1,000 organizations worldwide affected by supply chain attacks targeting open-source software and developer platforms. Confirmed victims include Trivy, LiteLLM, Telnyx, SAP, TanStack packages, European Commission, Mistral AI, OpenAI, and GitHub.…

BleepingComputer27 Aug · 11:31 UTC