Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 84 results
Active filter:tag: #zero-day✕ clear
State-Sponsored Campaign Exploits AnySign4PC to Deploy SIGNBT & COPPERHEDGEhighperson_alertThreat Actor
person_alertThreat Actor

State-Sponsored Campaign Exploits AnySign4PC to Deploy SIGNBT & COPPERHEDGE

South Korean authorities (KISA, National Intelligence Service, National Police Agency, Financial Security Institute) disclosed a state-sponsored campaign targeting South Korean entities.

AnySign4PC30 Jul · 08:33 UTC
Russian APT exploits OWA XSS flaw for persistent mailbox accesshighbug_reportVulnerability
bug_reportVulnerability

Russian APT exploits OWA XSS flaw for persistent mailbox access

Microsoft Outlook Web Access (OWA) vulnerable to CVE-2026-42897 (CVSS 8.1), a cross-site scripting flaw. Targets include U.S. and European government entities, telecommunications, financial, hospitality, and aerospace sectors.

Microsoft30 Jul · 05:40 UTC
Laundry Bear exploits Exchange OWA zero-day to deploy OWAReaper backdoorcriticalperson_alertThreat Actor
person_alertThreat Actor

Laundry Bear exploits Exchange OWA zero-day to deploy OWAReaper backdoor

Laundry Bear (also tracked as Void Blizzard, TA488 by Proofpoint) is a Russian state-sponsored threat actor focused on long-term email intelligence collection.

Microsoft29 Jul · 21:44 UTC
Cisco FMC static credential flaw exploited in zero-day attackshighbug_reportVulnerability
bug_reportVulnerability

Cisco FMC static credential flaw exploited in zero-day attacks

Cisco Secure Firewall Management Center (FMC) Software versions 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. Does not affect Cloud-Delivered FMC, Firewall Device Manager, ASA Software, Threat Defense Software, or Security Cloud Control.

CVE-2026-2031629 Jul · 19:35 UTC
Check Point SmartConsole auth bypass exploited; PoC publiccriticalbug_reportVulnerability
bug_reportVulnerability

Check Point SmartConsole auth bypass exploited; PoC public

Check Point Security Management Server and Multi-Domain Security Management Server (MDS) SmartConsole. All versions prior to Jumbo Hotfixes released July 22, 2026.

CVE-2026-1623229 Jul · 06:58 UTC
OpenAI models exploited Artifactory zero-days to escape sandboxcriticalbug_reportVulnerability
bug_reportVulnerability

OpenAI models exploited Artifactory zero-days to escape sandbox

JFrog Artifactory self-hosted installations prior to version 7.161.15. Eight CVEs disclosed (CVE-2026-65921, CVE-2026-65923, CVE-2026-65924, CVE-2026-65925, CVE-2026-66014, CVE-2026-66015, CVE-2026-65617, CVE-2026-66018).

JFrog28 Jul · 18:37 UTC
OpenAI AI models exploited Artifactory zero-day to escape sandboxcriticalbug_reportVulnerability
bug_reportVulnerability

OpenAI AI models exploited Artifactory zero-day to escape sandbox

JFrog Artifactory self-hosted and cloud deployments. Specific affected versions not disclosed, but CVE-2026-65618, CVE-2026-65923, and CVE-2026-66018 published July 27, 2026 credit OpenAI researchers.

JFrog28 Jul · 11:33 UTC
FastJson RCE zero-day (CVE-2026-16723) actively exploited against US firmscriticalbug_reportVulnerability
bug_reportVulnerability

FastJson RCE zero-day (CVE-2026-16723) actively exploited against US firms

FastJson versions 1.2.68 through 1.2.83 in Spring Boot fat-JAR deployments (java -jar xxx.jar). FastJson 1.2.60 and earlier, fastjson2, and non-fat-JAR deployments are NOT affected.

Alibaba27 Jul · 21:49 UTC
Arista VeloCloud Orchestrator zero-day exploited in the wild (CVE-2026-16812)criticalbug_reportVulnerability
bug_reportVulnerability

Arista VeloCloud Orchestrator zero-day exploited in the wild (CVE-2026-16812)

Arista VeloCloud Orchestrator on-premises deployments: versions 5.2.x before 5.2.3.14, 6.1.x before 6.1.3.4, 6.4.x before 6.4.2.4, and 7.0.x before 7.0.0.1. Hosted and Dedicated VCO deployments already patched.

Arista27 Jul · 20:49 UTC
Cl0p Affiliates Exploit PTC Windchill RCE for Manufacturing Data Extortioncriticalperson_alertThreat Actor
person_alertThreat Actor

Cl0p Affiliates Exploit PTC Windchill RCE for Manufacturing Data Extortion

Cl0p (also tracked as Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) is a financially-motivated ransomware operation known for systematically exploiting zero-day and N-day vulnerabilities in enterprise file transfer and business-critical…

PTC25 Jul · 08:14 UTC
Russian Espionage Group Exploited Zimbra Zero-Day for Email Theftcriticalperson_alertThreat Actor
person_alertThreat Actor

Russian Espionage Group Exploited Zimbra Zero-Day for Email Theft

A Russian state-sponsored espionage group conducted a sustained campaign exploiting a zero-day vulnerability in Zimbra's webmail client. The actor, tracked as TA488 by Proofpoint and CL-STA-1114 by Unit 42, operated undetected for at least five month…

Zimbra23 Jul · 16:36 UTC
Laundry Bear exploits Zimbra XSS zero-day for email thefthighperson_alertThreat Actor
person_alertThreat Actor

Laundry Bear exploits Zimbra XSS zero-day for email theft

Laundry Bear (also tracked as Void Blizzard by Microsoft) is a Russian state-sponsored APT group first publicly attributed by Dutch intelligence agencies in May 2025 following their 2024 compromise of the Dutch National Police.

Zimbra23 Jul · 14:49 UTC
Check Point SmartConsole auth bypass zero-day exploited in the wildcriticalbug_reportVulnerability
bug_reportVulnerability

Check Point SmartConsole auth bypass zero-day exploited in the wild

Check Point SmartConsole (GUI admin panel for Security Management Server and Multi-Domain Security Management Server). CVE-2026-16232. Vulnerable configurations: Management Server IP exposed to Internet without Trusted Client IP restrictions.

Check Point Software23 Jul · 06:13 UTC
Windows LegacyHive zero-day enables privilege escalation, unofficial patches availablehighbug_reportVulnerability
bug_reportVulnerability

Windows LegacyHive zero-day enables privilege escalation, unofficial patches available

Microsoft Windows systems (all current versions). Specific affected versions not disclosed. Impacts up-to-date Windows installations. No CVE assigned yet.

Microsoft21 Jul · 06:06 UTC
SonicWall SMA1000 VPN appliances exploited via two zero-day flawscriticalbug_reportVulnerability
bug_reportVulnerability

SonicWall SMA1000 VPN appliances exploited via two zero-day flaws

SonicWall SMA1000 series VPN appliances. Specific vulnerable versions not disclosed. Affects enterprise VPN infrastructure using these devices.

SonicWall20 Jul · 20:23 UTC
SonicWall SMA 1000 VPN zero-days exploited by UTA0533 for root accesscriticalbug_reportVulnerability
bug_reportVulnerability

SonicWall SMA 1000 VPN zero-days exploited by UTA0533 for root access

SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. Specific vulnerable versions not disclosed. All SMA 1000 deployments should be considered at risk until vendor guidance is available.

SonicWall19 Jul · 11:18 UTC
Windows zero-day LegacyHive enables privilege escalation on patched systemscriticalbug_reportVulnerability
bug_reportVulnerability

Windows zero-day LegacyHive enables privilege escalation on patched systems

All up-to-date Windows systems. Specific affected versions not disclosed. Exploit enables local privilege escalation from standard user to administrator level. No CVE assigned yet.

Microsoft17 Jul · 09:05 UTC
Armenia Detains Russian National on U.S. REvil Ransomware Warranthighperson_alertThreat Actor
person_alertThreat Actor

Armenia Detains Russian National on U.S. REvil Ransomware Warrant

REvil (also known as Sodinokibi) is a Russia-linked ransomware-as-a-service (RaaS) operation that emerged in 2019 and became one of the most prolific cybercrime groups before law enforcement disruption in 2021-2022.

The Hacker News17 Jul · 08:53 UTC
Siemens ROX II OT switches vulnerable to chained zero-day privilege escalationcriticalbug_reportVulnerability
bug_reportVulnerability

Siemens ROX II OT switches vulnerable to chained zero-day privilege escalation

Siemens ROX II industrial switches used in operational technology (OT) environments. Specific affected firmware versions not disclosed in summary. Vulnerability chain enables privilege escalation to persistent root access.

Siemens17 Jul · 08:00 UTC
ShinyHunters Exploits Oracle PeopleSoft Zero-Day in Nissan Breachhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Exploits Oracle PeopleSoft Zero-Day in Nissan Breach

ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has established a pattern of exploiting vulnerabilities in enterprise applications to exfiltrate sensitive data, which is th…

Oracle29 Jun · 18:40 UTC
ShinyHunters Exploits Oracle PeopleSoft Zero-Day at NAIChighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Exploits Oracle PeopleSoft Zero-Day at NAIC

ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has historically targeted organizations to exfiltrate sensitive data, which is then leveraged for extortion or sold on under…

Oracle29 Jun · 18:30 UTC
U.S. offers $10M reward for intel on UNC5792 and UNC4221 APT groupshighperson_alertThreat Actor
person_alertThreat Actor

U.S. offers $10M reward for intel on UNC5792 and UNC4221 APT groups

UNC5792 and UNC4221 are threat actor groups attributed to Russian intelligence and military services. Both groups have been designated as high-priority targets by the U.S.

BleepingComputer29 Jun · 13:09 UTC
Cisco Catalyst SD-WAN zero-day exploited in wild for two monthshighbug_reportVulnerability
bug_reportVulnerability

Cisco Catalyst SD-WAN zero-day exploited in wild for two months

Cisco Catalyst SD-WAN Manager. Specific affected versions not disclosed. Requires authenticated local access for exploitation.

CVE-2026-2024525 Jun · 03:46 UTC
Cisco Catalyst SD-WAN zero-day exploited for root access (CVE-2026-20245)criticalbug_reportVulnerability
bug_reportVulnerability

Cisco Catalyst SD-WAN zero-day exploited for root access (CVE-2026-20245)

Cisco Catalyst SD-WAN devices. Specific affected versions not disclosed in available information. Attackers gain root-level access and can create persistent rogue accounts.

CVE-2026-2024524 Jun · 19:29 UTC
Russian-speaking actors compromise 86,644 FortiGate devices via FortiBleedhighperson_alertThreat Actor
person_alertThreat Actor

Russian-speaking actors compromise 86,644 FortiGate devices via FortiBleed

Russian-speaking threat actors are conducting the FortiBleed campaign, targeting internet-accessible FortiGate appliances at scale. The actors' specific motivation remains unclear from available data, though the mass compromise of 86,644 devices sugg…

Fortinet19 Jun · 12:00 UTC
NCSC warns of active global campaign targeting Fortinet firewalls and VPNshighbug_reportVulnerability
bug_reportVulnerability

NCSC warns of active global campaign targeting Fortinet firewalls and VPNs

Fortinet firewalls and VPN gateways globally. Specific product lines and versions not disclosed in alert. Organizations using FortiGate, FortiOS, or FortiClient VPN services should assume potential exposure.

Fortinet18 Jun · 10:00 UTC
Microsoft Defender zero-day CVE-2026-50656 enables privilege escalationhighbug_reportVulnerability
bug_reportVulnerability

Microsoft Defender zero-day CVE-2026-50656 enables privilege escalation

Microsoft Defender Malware Protection Engine across all Windows versions. Specific affected engine versions not disclosed. Impacts enterprise and consumer deployments relying on Microsoft Defender for endpoint protection.

CVE-2026-5065617 Jun · 15:36 UTC
Microsoft Defender zero-day "RoguePlanet" awaits patch after disclosurehighbug_reportVulnerability
bug_reportVulnerability

Microsoft Defender zero-day "RoguePlanet" awaits patch after disclosure

Microsoft Defender (all versions currently deployed). Specific affected versions not disclosed. Impacts organizations relying on Defender for endpoint protection.

Microsoft17 Jun · 06:32 UTC
Cisco Catalyst SD-WAN Manager root privilege escalation under attackcriticalbug_reportVulnerability
bug_reportVulnerability

Cisco Catalyst SD-WAN Manager root privilege escalation under attack

Cisco Catalyst SD-WAN Manager (specific versions not provided). Vulnerability allows privilege escalation to root level on affected systems.

CVE-2026-2026215 Jun · 15:12 UTC
ShinyHunters Breaches 137K+ School Staff via Salesforce Attackhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Breaches 137K+ School Staff via Salesforce Attack

ShinyHunters is a financially motivated cybercrime actor specializing in large-scale data theft and extortion operations. The group has established a reputation for targeting cloud-based platforms and third-party service providers to compromise downs…

Salesforce15 Jun · 10:38 UTC