Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 675 results
criticalbug_reportVulnerabilityVeeam ONE authentication bypass requires immediate patching
Veeam ONE backup management platform. Specific affected versions not disclosed in available information. Authentication bypass vulnerability allows unauthorized access.
highbug_reportVulnerabilityAmazon Kiro IDE prompt injection enables data exfiltration via Powers
Amazon Kiro IDE version 0.7.45 on Windows. Vulnerability fixed in version 0.8.140. Latest version is 1.0.337. Affects both trusted and untrusted workspaces when malicious workspace files are opened.
highbug_reportVulnerabilityAustralia arrests two TeamPCP members behind global supply chain attacks
Over 1,000 organizations worldwide affected by supply chain attacks targeting open-source software and developer platforms. Confirmed victims include Trivy, LiteLLM, Telnyx, SAP, TanStack packages, European Commission, Mistral AI, OpenAI, and GitHub.…
highbug_reportVulnerabilityNCSC warns of increased targeting of internet-exposed OT systems globally
Organizations with operational technology (OT) systems exposed to the internet across multiple sectors globally, including UK critical national infrastructure and non-CNI sectors.
criticalbug_reportVulnerabilityTeamPCP supply chain attack compromised Trivy, KICS, LiteLLM; 1000+ orgs hit
Open-source tools: Trivy scanner, Checkmarx KICS, LiteLLM AI gateway. Attack spanned GitHub Actions, Docker Hub, npm, PyPI, OpenVSX ecosystems. Over 1,000 organizations potentially compromised, 500,000+ credentials stolen, 300GB+ data exfiltrated.
highbug_reportVulnerabilityAustralian police arrest two TeamPCP members behind supply chain attacks
Global software supply chain: hundreds of open-source packages on GitHub, NPM, and other repositories compromised since late 2023. Victims include 2,500+ organizations using LiteLLM AI gateway, 3,800+ GitHub repositories, and developers across major…
highbug_reportVulnerabilitySpark RAT campaign targets Cambodia via OPSWAT driver exploit
Organizations and individuals in Cambodia. Campaign abuses vulnerable OPSWAT AppRemover driver (ardrv.sys, CVE-2026-36425) via BYOVD technique. Targets systems running Microsoft Defender, Huorong Internet Security, Tencent PC Manager, and Qihoo 360.
criticalbug_reportVulnerabilityCISA orders federal agencies to patch exploited Citrix NetScaler RCE by Aug 29
Citrix NetScaler ADC and NetScaler Gateway appliances with Gateway VPN or AAA virtual server configurations. CVE-2026-8452 (high severity). Over 22,000 NetScaler ADC and 1,800 Gateway instances exposed online globally.
highbug_reportVulnerabilityGPUThor Rowhammer defeats ECC on NVIDIA RTX A6000, enables root escalation
NVIDIA Ampere workstation GPUs with GDDR6 memory: RTX A6000 (48GB), RTX A5000 (24GB), RTX A4500 (20GB), RTX A4000 (16GB). Attack requires unprivileged CUDA kernel execution. Other NVIDIA GPUs tested (A10, L4, L40, RTX 4090, A30) showed no bit flips.
criticalbug_reportVulnerabilityWatchGuard Agent RCE flaws require immediate patching
WatchGuard Agent (specific versions not disclosed in available data). Remote code execution vulnerabilities affecting WatchGuard Agent software used for endpoint management and authentication.
criticalbug_reportVulnerabilityAvada WordPress theme RCE chain affects sites with theme + plugin active
Avada WordPress theme versions up to 7.16 and Fusion Builder plugin versions up to 3.16. Exploitation requires both components to be active simultaneously.
highbug_reportVulnerabilityGPUThor Rowhammer attack bypasses NVIDIA GPU ECC for DoS and root access
NVIDIA Ampere-class workstation GPUs with GDDR6 memory: RTX A4000, RTX A4500, RTX A5000, RTX A6000. Server-class A100 GPUs vulnerable to privilege escalation.
highbug_reportVulnerabilityCoordinated attacks target AI infrastructure for credential theft and cryptomining
AI infrastructure platforms: LiteLLM gateways (CVE-2026-42271, CVE-2026-48710), RAGFlow deployments, and Kestra workflow environments. All exposed instances with administrative surfaces reachable from the internet are at risk.
highbug_reportVulnerabilityMicrosoft SharePoint RCE chain (CVE-2026-55040 + CVE-2026-63520) exploited
Microsoft SharePoint Server (on-premises). CVE-2026-55040: JWT authentication bypass. CVE-2026-63520: Business Connectivity Services RCE. Over 8,700 SharePoint servers exposed online. Specific vulnerable versions not disclosed in article.
criticalbug_reportVulnerabilityUbiquiti patches three max-severity RCE flaws in UniFi products
Ubiquiti UniFi Protect Application (fixed in 7.2.105+), UniFi Talk Application (fixed in 5.3.2+), and UniFi OS Server (5.1.21 and earlier). Over 100,000 UniFi OS instances exposed online.
criticalbug_reportVulnerabilityUnpatched Kaltura mwEmbed flaws enable file read and RCE via deserialization
Kaltura mwEmbed (html5lib) v2.45, v2.103, and all earlier v2.x releases exposing mwEmbedLoader.php. Affects customer installations and Kaltura's shared multi-tenant CDN infrastructure.
criticalbug_reportVulnerabilityGitea CVE-2026-60004 RCE exploited in wild; CISA orders 3-day patch
Gitea self-hosted Git service versions prior to 1.27.1. Approximately 5,000 instances exposed online. Default configurations with self-registration enabled are exploitable by unauthenticated attackers.
highbug_reportVulnerabilityAttackers abuse npm mirrors as free hosting for Cloudflare phishing pages
npm registry and public mirrors (UNPKG, npmmirror). Organizations using these mirrors to serve package content. At least 24 malicious packages identified hosting fake Cloudflare CAPTCHA pages.
highbug_reportVulnerabilityBEC fraud campaign surges against Austrian orgs via impersonation
Austrian organizations across all sectors; targets finance, accounting, and HR departments. Attack vectors include email impersonation, compromised supplier accounts, and hijacked email threads. No specific product vulnerabilities exploited.
highbug_reportVulnerabilityDDoS campaign disrupts Norway's shared government digital infrastructure
Norway's Digitaliseringsdirektoratet (Digdir) shared government infrastructure, including ID-porten (public login), eSignering (electronic signatures), secure digital mail, government forms, and data exchange services.
criticalbug_reportVulnerabilityOAuth2 Proxy authentication bypass allows unauthorized access
OAuth2 Proxy (specific versions not disclosed in available data). All deployments using OAuth2 Proxy for authentication are potentially at risk.
highbug_reportVulnerabilityNVIDIA NemoClaw DNS rebinding flaw enables AI model poisoning via browser
NVIDIA NemoClaw versions prior to v0.0.35 on macOS and Linux. Windows and WSL installations remain vulnerable as of v0.0.34, which added a warning but no technical fix.
criticalbug_reportVulnerabilityOracle critical vulnerability under active exploitation, patching urgent
Multiple Oracle products affected. Specific product names, versions, and CVE identifiers not disclosed in available advisory. CERT.BE warning indicates at least one critical-severity vulnerability among multiple flaws.
highbug_reportVulnerabilityMarimo notebook code injection allows MCP command execution in edit mode
Marimo notebook software versions prior to 0.23.15. Vulnerability (CVE-2026-75149) affects users who open untrusted notebooks in edit mode. Fixed in version 0.23.15 (July 23, 2026); current release is 0.24.0.
highbug_reportVulnerability24 npm packages abuse unpkg mirrors as phishing infrastructure
24 malicious npm packages (e.g., bgzxcuite2, prezdentkxheiw, egair0810) hosted on npm registry and mirrored on unpkg.com and similar CDN services. Affects users who click links to these mirrored HTML pages, not developers installing packages directly…
highbug_reportVulnerabilityE4del and PINHOLE RATs abuse FTP banners as dead drop resolvers
Organizations globally; no specific vendor or product vulnerability. Attack targets Windows systems via social engineering (Spanish-language vouchers, ClickFix lures).
highbug_reportVulnerabilityXecurify miniOrange SAML plugin flaws exploited for WordPress admin access
Xecurify miniOrange SAML 2.0 Single Sign On WordPress plugin, Standard edition versions prior to 17.0.6. CVE-2026-61979 (CVSS 8.1) fixed in 17.0.5; CVE-2026-15981 (CVSS 9.8) fixed in 17.0.6.
criticalbug_reportVulnerabilityOracle WebLogic & HTTP Server CVE-2026-21962 actively exploited (CVSS 10.0)
Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in (all versions prior to January 2026 patch). Affects unauthenticated attackers with network access via HTTP.
highbug_reportVulnerabilityCalix GS7 XGS routers expose UPnP on WAN, allow unauthenticated NAT bypass
Calix GS7 XGS (GS5239XG / GigaSpire 7u10txg) residential routers running EXOS/6.6.47 firmware. Deployed by multiple U.S. ISPs including Cox Communications, Brightspeed, ALLO, CityFibre, and Conexon. No patch available.
criticalbug_reportVulnerabilityminiOrange SAML SSO plugin flaws actively exploited for WordPress admin access
miniOrange SAML 2.0 Single Sign On plugin for WordPress. Vulnerable versions: Free <5.4.5, Premium single-site <13.0.4, Standard single-site <17.06, Premium/Enterprise/All-Inclusive multisite <20.2.8, Enterprise/All-Inclusive single-site <26.0.3, VIP…