Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-20 · 02:03 UTC
articleTotal: 593 reports

Filtered Reports

30 / 346 results
Active filter:✕ clear
16-year KVM hypervisor flaw enables guest-to-host kernel corruptioncriticalbug_reportVulnerability
bug_reportVulnerability

16-year KVM hypervisor flaw enables guest-to-host kernel corruption

Linux KVM hypervisor on Intel and AMD x86 systems. All Linux kernel versions containing the vulnerable shadow MMU code (approximately 16 years of releases).

CVE-2026-5335915:37 UTC
Gitea Docker auth bypass under active probing (CVE-2026-20896)criticalbug_reportVulnerability
bug_reportVulnerability

Gitea Docker auth bypass under active probing (CVE-2026-20896)

Gitea Docker images with improper X-WEBAUTH-USER header validation. Specific vulnerable versions not provided; affects deployments trusting reverse proxy authentication headers without IP restrictions.

CVE-2026-2089614:28 UTC
Adobe ColdFusion CVE-2026-48282 under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Adobe ColdFusion CVE-2026-48282 under active exploitation

Adobe ColdFusion (specific versions not disclosed). Maximum severity vulnerability actively exploited in the wild.

CVE-2026-4828211:18 UTC
Opera GX patched silent add-on install flaw enabling data thefthighbug_reportVulnerability
bug_reportVulnerability

Opera GX patched silent add-on install flaw enabling data theft

Opera GX browser (specific versions not disclosed). Vulnerability allowed malicious websites to install browser extensions without user consent, enabling content extraction from visited pages including email addresses and other sensitive data.

Opera05:27 UTC
North Korean actors deploy 108 malicious packages in PolinRider campaignhighbug_reportVulnerability
bug_reportVulnerability

North Korean actors deploy 108 malicious packages in PolinRider campaign

npm, Packagist (PHP), Go modules, and Google Chrome Web Store. 108 malicious packages and extensions published. Maintainer accounts actively compromised. Campaign linked to North Korean Contagious Interview threat group.

The Hacker News09:17 UTC
Seven unpatched flaws in FatFs library affect millions of embedded deviceshighbug_reportVulnerability
bug_reportVulnerability

Seven unpatched flaws in FatFs library affect millions of embedded devices

FatFs filesystem library used in embedded devices including security cameras, drones, industrial controllers, and hardware crypto wallets. Affects devices reading/writing FAT and exFAT formats on USB drives and SD cards.

FatFs18:19 UTC
Linux kernel "Bad Epoll" flaw grants unprivileged root accesscriticalbug_reportVulnerability
bug_reportVulnerability

Linux kernel "Bad Epoll" flaw grants unprivileged root access

Linux kernel (version range not specified) on desktops, servers, and Android devices. Affects both traditional Linux distributions and Android-based systems. Exploitable by unprivileged local users.

CVE-2026-4624217:40 UTC
North Korean actors deploy malicious npm packages to steal developer secretshighbug_reportVulnerability
bug_reportVulnerability

North Korean actors deploy malicious npm packages to steal developer secrets

npm ecosystem: malicious packages "rollup-packages-polyfill-core" and "rollup-runtime-polyfill-core" impersonating legitimate "rollup-plugin-polyfill-node".

npm14:07 UTC
ConsentFix and ClickFix campaigns hijack M365 accounts via OAuth token thefthighbug_reportVulnerability
bug_reportVulnerability

ConsentFix and ClickFix campaigns hijack M365 accounts via OAuth token theft

Microsoft 365 accounts across all organizations using OAuth authentication. Campaigns target users through social engineering to approve malicious OAuth consent prompts, bypassing MFA protections by stealing valid authentication tokens.

Microsoft12:00 UTC
Cisco Unified CM vulnerability under active exploitation post-patchhighbug_reportVulnerability
bug_reportVulnerability

Cisco Unified CM vulnerability under active exploitation post-patch

Cisco Unified Communications Manager (Unified CM). Specific vulnerable versions not disclosed; patched versions available since early June 2024. Affects organizations running unpatched Unified CM deployments.

Cisco09:35 UTC
CISA: Active exploitation of RCE flaw in Microsoft SharePointhighbug_reportVulnerability
bug_reportVulnerability

CISA: Active exploitation of RCE flaw in Microsoft SharePoint

Microsoft SharePoint servers vulnerable prior to May 2024 security updates. Affects on-premises SharePoint deployments; unauthenticated remote code execution possible on unpatched systems.

Microsoft08:52 UTC
Fake GitHub PoC repos deliver ChocoPoC trojan to security researchershighbug_reportVulnerability
bug_reportVulnerability

Fake GitHub PoC repos deliver ChocoPoC trojan to security researchers

Vulnerability researchers and security professionals using GitHub to access proof-of-concept exploit code. The ChocoPoC malware targets Windows systems, stealing credentials, browser data, and files while establishing remote shell access.

GitHub05:24 UTC
Microsoft SharePoint RCE flaw under active exploitation (CVE-2026-45659)criticalbug_reportVulnerability
bug_reportVulnerability

Microsoft SharePoint RCE flaw under active exploitation (CVE-2026-45659)

Microsoft SharePoint Server, all versions vulnerable to deserialization attacks. Specific affected versions not yet disclosed.

CVE-2026-4565903:46 UTC
Trojanized GitHub PoC exploits deliver ChocoPoC RAT to researchershighbug_reportVulnerability
bug_reportVulnerability

Trojanized GitHub PoC exploits deliver ChocoPoC RAT to researchers

Cybersecurity researchers and security teams downloading proof-of-concept exploit code from GitHub repositories. ChocoPoC is a Python-based remote access trojan with command execution and data exfiltration capabilities.

BleepingComputer18:08 UTC
Argo CD repo-server RCE enables cluster takeover, no patch availablecriticalbug_reportVulnerability
bug_reportVulnerability

Argo CD repo-server RCE enables cluster takeover, no patch available

Argo CD repo-server component, all versions (specific affected versions not disclosed). Exploitation requires access to internal network port where repo-server listens.

Argo CD17:40 UTC
Password-spray campaign hits Microsoft 365 with 81M login attemptshighbug_reportVulnerability
bug_reportVulnerability

Password-spray campaign hits Microsoft 365 with 81M login attempts

Microsoft 365 environments (Exchange Online, Azure AD/Entra ID, SharePoint, Teams). All organizations using M365 cloud services are potential targets. Attack focuses on user authentication endpoints.

Microsoft14:38 UTC
Ousaban banking trojan targets Spain and Portugal via phishinghighbug_reportVulnerability
bug_reportVulnerability

Ousaban banking trojan targets Spain and Portugal via phishing

Windows users in Spain and Portugal. Ousaban banking trojan campaign using fake PDF lures with geolocation filtering and steganography techniques. No specific product vulnerability; threat actor campaign identified by Fortinet FortiGuard Labs in May…

Fortinet13:26 UTC
Adobe patches CVSS 10.0 flaws in ColdFusion and Campaign Classiccriticalbug_reportVulnerability
bug_reportVulnerability

Adobe patches CVSS 10.0 flaws in ColdFusion and Campaign Classic

Adobe ColdFusion and Adobe Campaign Classic (specific versions not provided). Vulnerabilities include arbitrary code execution, privilege escalation, arbitrary file system read, and security feature bypass.

Adobe13:25 UTC
Cursor AI editor vulnerable to sandbox escape via prompt injectioncriticalbug_reportVulnerability
bug_reportVulnerability

Cursor AI editor vulnerable to sandbox escape via prompt injection

Cursor AI code editor, all versions prior to patch. Both CVE-2026-50548 (CVSS 9.8) and CVE-2026-50549 (CVSS 9.3) enable sandbox escape and arbitrary command execution via prompt injection without user interaction.

CVE-2026-5054812:42 UTC
Progress Kemp LoadMaster RCE under active exploitation (CVE-2026-8037)criticalbug_reportVulnerability
bug_reportVulnerability

Progress Kemp LoadMaster RCE under active exploitation (CVE-2026-8037)

Progress Kemp LoadMaster load balancers. Specific affected versions not disclosed. Pre-authentication vulnerability allows unauthenticated remote attackers to execute OS commands.

CVE-2026-803711:56 UTC
900+ Oracle E-Business Suite instances exposed, under active attackcriticalbug_reportVulnerability
bug_reportVulnerability

900+ Oracle E-Business Suite instances exposed, under active attack

Oracle E-Business Suite instances exposed to the internet (900+ confirmed). Specific vulnerable versions not disclosed; critical severity vulnerability being exploited.

Oracle10:30 UTC
LLM hallucinations exploited for supply chain attacks via phantom domainshighbug_reportVulnerability
bug_reportVulnerability

LLM hallucinations exploited for supply chain attacks via phantom domains

Organizations using LLMs for development assistance, code generation, or package recommendations. Developers relying on AI-generated domain/package suggestions without verification.

Unit 42 (Palo Alto)23:00 UTC
Trojanized Pyrogram forks on PyPI target Telegram bot developershighbug_reportVulnerability
bug_reportVulnerability

Trojanized Pyrogram forks on PyPI target Telegram bot developers

Python developers using PyPI packages for Telegram bot development. Malicious forks of Pyrogram library active since November 2024. Affects developers who may have installed compromised packages instead of legitimate Pyrogram.

PyPI19:02 UTC
AI agents using Model Context Protocol vulnerable to tool poisoning attackshighbug_reportVulnerability
bug_reportVulnerability

AI agents using Model Context Protocol vulnerable to tool poisoning attacks

AI agents implementing Microsoft's Model Context Protocol (MCP). Specific products and versions not disclosed. Affects organizations deploying MCP-based AI agents with access to sensitive internal data and external tool integrations.

Microsoft15:46 UTC
Langflow RCE (CVE-2026-33017) actively exploited for cryptominingcriticalbug_reportVulnerability
bug_reportVulnerability

Langflow RCE (CVE-2026-33017) actively exploited for cryptomining

Langflow AI application framework, all exposed endpoints vulnerable to unauthenticated remote code execution. Specific affected versions not disclosed; assume all unpatched instances at risk.

CVE-2026-3301713:47 UTC
Fake Perplexity AI Chrome extension hijacks search traffic on Web Storehighbug_reportVulnerability
bug_reportVulnerability

Fake Perplexity AI Chrome extension hijacks search traffic on Web Store

Google Chrome users who installed the malicious Perplexity AI impersonator extension from the Chrome Web Store. Affects organizations and individuals using Chrome browser seeking AI productivity tools.

Google13:46 UTC
GuardFall shell injection bypasses safety checks in 10 of 11 AI coding agentshighbug_reportVulnerability
bug_reportVulnerability

GuardFall shell injection bypasses safety checks in 10 of 11 AI coding agents

10 out of 11 tested open-source AI coding and computer-use agents are vulnerable to GuardFall shell injection bypass. Only "Continue" agent demonstrated resistance.

Adversa AI12:26 UTC
63% of iOS AI chatbot apps leak API keys via unencrypted network traffichighbug_reportVulnerability
bug_reportVulnerability

63% of iOS AI chatbot apps leak API keys via unencrypted network traffic

282 out of 444 iOS AI chatbot applications expose paid AI service credentials (API keys, tokens, backend endpoints) in plaintext network traffic. Affects apps integrating third-party AI services (OpenAI, Anthropic, Google, etc.).

The Hacker News11:49 UTC
SimpleHelp OpenID auth bypass (CVE-2026-48558) exploited in wildcriticalbug_reportVulnerability
bug_reportVulnerability

SimpleHelp OpenID auth bypass (CVE-2026-48558) exploited in wild

SimpleHelp remote support software, all versions using OpenID Connect authentication. CVE-2026-48558 is a critical authentication bypass (CVSS 10.0) in the OpenID Connect flow.

CVE-2026-4855809:18 UTC
AirDrop and Quick Share flaws enable wireless DoS and security bypasshighbug_reportVulnerability
bug_reportVulnerability

AirDrop and Quick Share flaws enable wireless DoS and security bypass

Apple AirDrop and Google Quick Share wireless file transfer features on iOS, macOS, and Android devices. Specific affected versions not disclosed. Attack requires physical proximity (wireless range).

Apple07:27 UTC