Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 358 results
highbug_reportVulnerabilityVidar Stealer campaign uses Go-based DLL sideloading and code signing abuse
Organizations using Windows systems are targeted. Campaign abuses legitimate Windows Defender components (MpClient.dll sideloading) via loader-as-a-service framework.
highbug_reportVulnerabilityHidden backdoor in Tenda routers grants admin access to web panel
Multiple Tenda router models and firmware versions contain a hidden authentication backdoor affecting the web management interface. Specific affected models and versions not disclosed in available information.
highbug_reportVulnerabilityRedWing Android MaaS enables bank fraud via credential theft
Android devices targeted by RedWing malware, distributed as Malware-as-a-Service on Telegram. Variant of Oblivion MaaS. Primarily affects banking applications and users with compromised devices.
criticalbug_reportVulnerabilityGoogle Dialogflow CX flaw lets attackers hijack agents in same GCP project
Google Dialogflow CX agents with Code Block feature enabled, within shared Google Cloud projects. Requires attacker to have edit rights on at least one agent in the project.
highbug_reportVulnerabilityGitHub Agentic Workflows leak private repo data via public issues
GitHub Agentic Workflows with cross-repository read access. Organizations using GitHub agents that can access both public and private repositories are vulnerable. No CVE assigned yet.
criticalbug_reportVulnerabilityWriter AI platform session isolation flaw enables cross-tenant access
Writer enterprise AI platform. Specific affected versions not disclosed. Vulnerability impacts agent preview functionality allowing cross-tenant session token leakage and unauthorized access.
highbug_reportVulnerability16-year-old Linux kernel flaw enables VM escape on Intel and AMD hosts
Linux kernel (specific versions not disclosed); affects virtualization environments on Intel and AMD processors. VM escape vulnerability impacts hypervisors relying on affected kernel versions.
criticalbug_reportVulnerabilityBeyondTrust RS and PRA authentication bypass flaws require patching
BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) software. Specific affected versions not provided in available data.
criticalbug_reportVulnerabilityTenda router backdoor allows admin access bypass (CVE-2026-11405)
Tenda routers running vulnerable firmware versions. Specific models and version ranges not disclosed in available data. Affects web management interface authentication mechanism.
criticalbug_reportVulnerabilityBeyondTrust Remote Support/PRA critical auth bypass (CVE-2026-40138)
BeyondTrust Remote Support and Privileged Remote Access (PRA) products. Specific affected versions not provided in available data. CVE-2026-40138 is a pre-authentication vulnerability with CVSS 9.2.
highbug_reportVulnerabilityPhishing campaign targets marketing professionals via fake job interviews
Marketing professionals with Google accounts; campaign impersonates 30+ brands including Adobe, Netflix, Coca-Cola, OpenAI. Credential theft targeting Google accounts specifically.
highbug_reportVulnerabilityAttackers impersonate IT support on Teams calls to deploy EtherRAT
Organizations using Microsoft Teams for internal communications. All industries are potential targets. The campaign exploits user trust in voice-based IT support interactions rather than a technical vulnerability in Teams itself.
criticalbug_reportVulnerability16-year KVM hypervisor flaw enables guest-to-host kernel corruption
Linux KVM hypervisor on Intel and AMD x86 systems. All Linux kernel versions containing the vulnerable shadow MMU code (approximately 16 years of releases).
criticalbug_reportVulnerabilityGitea Docker auth bypass under active probing (CVE-2026-20896)
Gitea Docker images with improper X-WEBAUTH-USER header validation. Specific vulnerable versions not provided; affects deployments trusting reverse proxy authentication headers without IP restrictions.
criticalbug_reportVulnerabilityAdobe ColdFusion CVE-2026-48282 under active exploitation
Adobe ColdFusion (specific versions not disclosed). Maximum severity vulnerability actively exploited in the wild.
highbug_reportVulnerabilityOpera GX patched silent add-on install flaw enabling data theft
Opera GX browser (specific versions not disclosed). Vulnerability allowed malicious websites to install browser extensions without user consent, enabling content extraction from visited pages including email addresses and other sensitive data.
highbug_reportVulnerabilityNorth Korean actors deploy 108 malicious packages in PolinRider campaign
npm, Packagist (PHP), Go modules, and Google Chrome Web Store. 108 malicious packages and extensions published. Maintainer accounts actively compromised. Campaign linked to North Korean Contagious Interview threat group.
highbug_reportVulnerabilitySeven unpatched flaws in FatFs library affect millions of embedded devices
FatFs filesystem library used in embedded devices including security cameras, drones, industrial controllers, and hardware crypto wallets. Affects devices reading/writing FAT and exFAT formats on USB drives and SD cards.
criticalbug_reportVulnerabilityLinux kernel "Bad Epoll" flaw grants unprivileged root access
Linux kernel (version range not specified) on desktops, servers, and Android devices. Affects both traditional Linux distributions and Android-based systems. Exploitable by unprivileged local users.
highbug_reportVulnerabilityNorth Korean actors deploy malicious npm packages to steal developer secrets
npm ecosystem: malicious packages "rollup-packages-polyfill-core" and "rollup-runtime-polyfill-core" impersonating legitimate "rollup-plugin-polyfill-node".
highbug_reportVulnerabilityConsentFix and ClickFix campaigns hijack M365 accounts via OAuth token theft
Microsoft 365 accounts across all organizations using OAuth authentication. Campaigns target users through social engineering to approve malicious OAuth consent prompts, bypassing MFA protections by stealing valid authentication tokens.
highbug_reportVulnerabilityCisco Unified CM vulnerability under active exploitation post-patch
Cisco Unified Communications Manager (Unified CM). Specific vulnerable versions not disclosed; patched versions available since early June 2024. Affects organizations running unpatched Unified CM deployments.
highbug_reportVulnerabilityCISA: Active exploitation of RCE flaw in Microsoft SharePoint
Microsoft SharePoint servers vulnerable prior to May 2024 security updates. Affects on-premises SharePoint deployments; unauthenticated remote code execution possible on unpatched systems.
highbug_reportVulnerabilityFake GitHub PoC repos deliver ChocoPoC trojan to security researchers
Vulnerability researchers and security professionals using GitHub to access proof-of-concept exploit code. The ChocoPoC malware targets Windows systems, stealing credentials, browser data, and files while establishing remote shell access.
criticalbug_reportVulnerabilityMicrosoft SharePoint RCE flaw under active exploitation (CVE-2026-45659)
Microsoft SharePoint Server, all versions vulnerable to deserialization attacks. Specific affected versions not yet disclosed.
highbug_reportVulnerabilityTrojanized GitHub PoC exploits deliver ChocoPoC RAT to researchers
Cybersecurity researchers and security teams downloading proof-of-concept exploit code from GitHub repositories. ChocoPoC is a Python-based remote access trojan with command execution and data exfiltration capabilities.
criticalbug_reportVulnerabilityArgo CD repo-server RCE enables cluster takeover, no patch available
Argo CD repo-server component, all versions (specific affected versions not disclosed). Exploitation requires access to internal network port where repo-server listens.
highbug_reportVulnerabilityPassword-spray campaign hits Microsoft 365 with 81M login attempts
Microsoft 365 environments (Exchange Online, Azure AD/Entra ID, SharePoint, Teams). All organizations using M365 cloud services are potential targets. Attack focuses on user authentication endpoints.
highbug_reportVulnerabilityOusaban banking trojan targets Spain and Portugal via phishing
Windows users in Spain and Portugal. Ousaban banking trojan campaign using fake PDF lures with geolocation filtering and steganography techniques. No specific product vulnerability; threat actor campaign identified by Fortinet FortiGuard Labs in May…
criticalbug_reportVulnerabilityAdobe patches CVSS 10.0 flaws in ColdFusion and Campaign Classic
Adobe ColdFusion and Adobe Campaign Classic (specific versions not provided). Vulnerabilities include arbitrary code execution, privilege escalation, arbitrary file system read, and security feature bypass.