Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 675 results
Active filter:✕ clear
Veeam ONE authentication bypass requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Veeam ONE authentication bypass requires immediate patching

Veeam ONE backup management platform. Specific affected versions not disclosed in available information. Authentication bypass vulnerability allows unauthorized access.

Veeam27 Aug · 12:51 UTC
Amazon Kiro IDE prompt injection enables data exfiltration via Powershighbug_reportVulnerability
bug_reportVulnerability

Amazon Kiro IDE prompt injection enables data exfiltration via Powers

Amazon Kiro IDE version 0.7.45 on Windows. Vulnerability fixed in version 0.8.140. Latest version is 1.0.337. Affects both trusted and untrusted workspaces when malicious workspace files are opened.

Amazon27 Aug · 11:39 UTC
Australia arrests two TeamPCP members behind global supply chain attackshighbug_reportVulnerability
bug_reportVulnerability

Australia arrests two TeamPCP members behind global supply chain attacks

Over 1,000 organizations worldwide affected by supply chain attacks targeting open-source software and developer platforms. Confirmed victims include Trivy, LiteLLM, Telnyx, SAP, TanStack packages, European Commission, Mistral AI, OpenAI, and GitHub.…

BleepingComputer27 Aug · 11:31 UTC
NCSC warns of increased targeting of internet-exposed OT systems globallyhighbug_reportVulnerability
bug_reportVulnerability

NCSC warns of increased targeting of internet-exposed OT systems globally

Organizations with operational technology (OT) systems exposed to the internet across multiple sectors globally, including UK critical national infrastructure and non-CNI sectors.

NCSC UK27 Aug · 10:00 UTC
TeamPCP supply chain attack compromised Trivy, KICS, LiteLLM; 1000+ orgs hitcriticalbug_reportVulnerability
bug_reportVulnerability

TeamPCP supply chain attack compromised Trivy, KICS, LiteLLM; 1000+ orgs hit

Open-source tools: Trivy scanner, Checkmarx KICS, LiteLLM AI gateway. Attack spanned GitHub Actions, Docker Hub, npm, PyPI, OpenVSX ecosystems. Over 1,000 organizations potentially compromised, 500,000+ credentials stolen, 300GB+ data exfiltrated.

Trivy27 Aug · 09:56 UTC
Australian police arrest two TeamPCP members behind supply chain attackshighbug_reportVulnerability
bug_reportVulnerability

Australian police arrest two TeamPCP members behind supply chain attacks

Global software supply chain: hundreds of open-source packages on GitHub, NPM, and other repositories compromised since late 2023. Victims include 2,500+ organizations using LiteLLM AI gateway, 3,800+ GitHub repositories, and developers across major…

Krebs on Security27 Aug · 09:04 UTC
Spark RAT campaign targets Cambodia via OPSWAT driver exploithighbug_reportVulnerability
bug_reportVulnerability

Spark RAT campaign targets Cambodia via OPSWAT driver exploit

Organizations and individuals in Cambodia. Campaign abuses vulnerable OPSWAT AppRemover driver (ardrv.sys, CVE-2026-36425) via BYOVD technique. Targets systems running Microsoft Defender, Huorong Internet Security, Tencent PC Manager, and Qihoo 360.

OPSWAT27 Aug · 09:00 UTC
CISA orders federal agencies to patch exploited Citrix NetScaler RCE by Aug 29criticalbug_reportVulnerability
bug_reportVulnerability

CISA orders federal agencies to patch exploited Citrix NetScaler RCE by Aug 29

Citrix NetScaler ADC and NetScaler Gateway appliances with Gateway VPN or AAA virtual server configurations. CVE-2026-8452 (high severity). Over 22,000 NetScaler ADC and 1,800 Gateway instances exposed online globally.

Citrix27 Aug · 07:16 UTC
GPUThor Rowhammer defeats ECC on NVIDIA RTX A6000, enables root escalationhighbug_reportVulnerability
bug_reportVulnerability

GPUThor Rowhammer defeats ECC on NVIDIA RTX A6000, enables root escalation

NVIDIA Ampere workstation GPUs with GDDR6 memory: RTX A6000 (48GB), RTX A5000 (24GB), RTX A4500 (20GB), RTX A4000 (16GB). Attack requires unprivileged CUDA kernel execution. Other NVIDIA GPUs tested (A10, L4, L40, RTX 4090, A30) showed no bit flips.

NVIDIA27 Aug · 06:13 UTC
WatchGuard Agent RCE flaws require immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

WatchGuard Agent RCE flaws require immediate patching

WatchGuard Agent (specific versions not disclosed in available data). Remote code execution vulnerabilities affecting WatchGuard Agent software used for endpoint management and authentication.

WatchGuard27 Aug · 04:36 UTC
Avada WordPress theme RCE chain affects sites with theme + plugin activecriticalbug_reportVulnerability
bug_reportVulnerability

Avada WordPress theme RCE chain affects sites with theme + plugin active

Avada WordPress theme versions up to 7.16 and Fusion Builder plugin versions up to 3.16. Exploitation requires both components to be active simultaneously.

Avada26 Aug · 19:33 UTC
GPUThor Rowhammer attack bypasses NVIDIA GPU ECC for DoS and root accesshighbug_reportVulnerability
bug_reportVulnerability

GPUThor Rowhammer attack bypasses NVIDIA GPU ECC for DoS and root access

NVIDIA Ampere-class workstation GPUs with GDDR6 memory: RTX A4000, RTX A4500, RTX A5000, RTX A6000. Server-class A100 GPUs vulnerable to privilege escalation.

NVIDIA26 Aug · 16:48 UTC
Coordinated attacks target AI infrastructure for credential theft and cryptomininghighbug_reportVulnerability
bug_reportVulnerability

Coordinated attacks target AI infrastructure for credential theft and cryptomining

AI infrastructure platforms: LiteLLM gateways (CVE-2026-42271, CVE-2026-48710), RAGFlow deployments, and Kestra workflow environments. All exposed instances with administrative surfaces reachable from the internet are at risk.

Microsoft26 Aug · 14:43 UTC
Microsoft SharePoint RCE chain (CVE-2026-55040 + CVE-2026-63520) exploitedhighbug_reportVulnerability
bug_reportVulnerability

Microsoft SharePoint RCE chain (CVE-2026-55040 + CVE-2026-63520) exploited

Microsoft SharePoint Server (on-premises). CVE-2026-55040: JWT authentication bypass. CVE-2026-63520: Business Connectivity Services RCE. Over 8,700 SharePoint servers exposed online. Specific vulnerable versions not disclosed in article.

Microsoft26 Aug · 12:47 UTC
Ubiquiti patches three max-severity RCE flaws in UniFi productscriticalbug_reportVulnerability
bug_reportVulnerability

Ubiquiti patches three max-severity RCE flaws in UniFi products

Ubiquiti UniFi Protect Application (fixed in 7.2.105+), UniFi Talk Application (fixed in 5.3.2+), and UniFi OS Server (5.1.21 and earlier). Over 100,000 UniFi OS instances exposed online.

Ubiquiti26 Aug · 11:17 UTC
Unpatched Kaltura mwEmbed flaws enable file read and RCE via deserializationcriticalbug_reportVulnerability
bug_reportVulnerability

Unpatched Kaltura mwEmbed flaws enable file read and RCE via deserialization

Kaltura mwEmbed (html5lib) v2.45, v2.103, and all earlier v2.x releases exposing mwEmbedLoader.php. Affects customer installations and Kaltura's shared multi-tenant CDN infrastructure.

CVE-2026-1991226 Aug · 09:55 UTC
Gitea CVE-2026-60004 RCE exploited in wild; CISA orders 3-day patchcriticalbug_reportVulnerability
bug_reportVulnerability

Gitea CVE-2026-60004 RCE exploited in wild; CISA orders 3-day patch

Gitea self-hosted Git service versions prior to 1.27.1. Approximately 5,000 instances exposed online. Default configurations with self-registration enabled are exploitable by unauthenticated attackers.

Gitea26 Aug · 09:07 UTC
Attackers abuse npm mirrors as free hosting for Cloudflare phishing pageshighbug_reportVulnerability
bug_reportVulnerability

Attackers abuse npm mirrors as free hosting for Cloudflare phishing pages

npm registry and public mirrors (UNPKG, npmmirror). Organizations using these mirrors to serve package content. At least 24 malicious packages identified hosting fake Cloudflare CAPTCHA pages.

npm25 Aug · 19:39 UTC
BEC fraud campaign surges against Austrian orgs via impersonationhighbug_reportVulnerability
bug_reportVulnerability

BEC fraud campaign surges against Austrian orgs via impersonation

Austrian organizations across all sectors; targets finance, accounting, and HR departments. Attack vectors include email impersonation, compromised supplier accounts, and hijacked email threads. No specific product vulnerabilities exploited.

CERT.at (Austria)25 Aug · 18:04 UTC
DDoS campaign disrupts Norway's shared government digital infrastructurehighbug_reportVulnerability
bug_reportVulnerability

DDoS campaign disrupts Norway's shared government digital infrastructure

Norway's Digitaliseringsdirektoratet (Digdir) shared government infrastructure, including ID-porten (public login), eSignering (electronic signatures), secure digital mail, government forms, and data exchange services.

BleepingComputer25 Aug · 13:52 UTC
OAuth2 Proxy authentication bypass allows unauthorized accesscriticalbug_reportVulnerability
bug_reportVulnerability

OAuth2 Proxy authentication bypass allows unauthorized access

OAuth2 Proxy (specific versions not disclosed in available data). All deployments using OAuth2 Proxy for authentication are potentially at risk.

OAuth2 Proxy25 Aug · 13:03 UTC
NVIDIA NemoClaw DNS rebinding flaw enables AI model poisoning via browserhighbug_reportVulnerability
bug_reportVulnerability

NVIDIA NemoClaw DNS rebinding flaw enables AI model poisoning via browser

NVIDIA NemoClaw versions prior to v0.0.35 on macOS and Linux. Windows and WSL installations remain vulnerable as of v0.0.34, which added a warning but no technical fix.

NVIDIA25 Aug · 12:07 UTC
Oracle critical vulnerability under active exploitation, patching urgentcriticalbug_reportVulnerability
bug_reportVulnerability

Oracle critical vulnerability under active exploitation, patching urgent

Multiple Oracle products affected. Specific product names, versions, and CVE identifiers not disclosed in available advisory. CERT.BE warning indicates at least one critical-severity vulnerability among multiple flaws.

Oracle25 Aug · 11:51 UTC
Marimo notebook code injection allows MCP command execution in edit modehighbug_reportVulnerability
bug_reportVulnerability

Marimo notebook code injection allows MCP command execution in edit mode

Marimo notebook software versions prior to 0.23.15. Vulnerability (CVE-2026-75149) affects users who open untrusted notebooks in edit mode. Fixed in version 0.23.15 (July 23, 2026); current release is 0.24.0.

Marimo25 Aug · 10:43 UTC
24 npm packages abuse unpkg mirrors as phishing infrastructurehighbug_reportVulnerability
bug_reportVulnerability

24 npm packages abuse unpkg mirrors as phishing infrastructure

24 malicious npm packages (e.g., bgzxcuite2, prezdentkxheiw, egair0810) hosted on npm registry and mirrored on unpkg.com and similar CDN services. Affects users who click links to these mirrored HTML pages, not developers installing packages directly…

npm25 Aug · 09:52 UTC
E4del and PINHOLE RATs abuse FTP banners as dead drop resolvershighbug_reportVulnerability
bug_reportVulnerability

E4del and PINHOLE RATs abuse FTP banners as dead drop resolvers

Organizations globally; no specific vendor or product vulnerability. Attack targets Windows systems via social engineering (Spanish-language vouchers, ClickFix lures).

The Hacker News25 Aug · 09:33 UTC
Xecurify miniOrange SAML plugin flaws exploited for WordPress admin accesshighbug_reportVulnerability
bug_reportVulnerability

Xecurify miniOrange SAML plugin flaws exploited for WordPress admin access

Xecurify miniOrange SAML 2.0 Single Sign On WordPress plugin, Standard edition versions prior to 17.0.6. CVE-2026-61979 (CVSS 8.1) fixed in 17.0.5; CVE-2026-15981 (CVSS 9.8) fixed in 17.0.6.

CVE-2026-6197925 Aug · 06:34 UTC
Oracle WebLogic & HTTP Server CVE-2026-21962 actively exploited (CVSS 10.0)criticalbug_reportVulnerability
bug_reportVulnerability

Oracle WebLogic & HTTP Server CVE-2026-21962 actively exploited (CVSS 10.0)

Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in (all versions prior to January 2026 patch). Affects unauthenticated attackers with network access via HTTP.

CVE-2026-2196225 Aug · 04:12 UTC
Calix GS7 XGS routers expose UPnP on WAN, allow unauthenticated NAT bypasshighbug_reportVulnerability
bug_reportVulnerability

Calix GS7 XGS routers expose UPnP on WAN, allow unauthenticated NAT bypass

Calix GS7 XGS (GS5239XG / GigaSpire 7u10txg) residential routers running EXOS/6.6.47 firmware. Deployed by multiple U.S. ISPs including Cox Communications, Brightspeed, ALLO, CityFibre, and Conexon. No patch available.

Calix24 Aug · 19:14 UTC
miniOrange SAML SSO plugin flaws actively exploited for WordPress admin accesscriticalbug_reportVulnerability
bug_reportVulnerability

miniOrange SAML SSO plugin flaws actively exploited for WordPress admin access

miniOrange SAML 2.0 Single Sign On plugin for WordPress. Vulnerable versions: Free <5.4.5, Premium single-site <13.0.4, Standard single-site <17.06, Premium/Enterprise/All-Inclusive multisite <20.2.8, Enterprise/All-Inclusive single-site <26.0.3, VIP…

miniOrange24 Aug · 17:26 UTC