Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports
Cyber Threat Daily Brief — September 4, 2026satellite_altDaily Brief
Threat Intel Brief·Daily Summary

Cyber Threat Daily Brief — September 4, 2026

Today's briefing: 14 critical and 22 high-severity threats. A total of 47 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.

14 Critical22 High47 analyses
schedule02:17 UTC
Read briefarrow_forward

Latest Reports

25 / 1107 results
Phishing campaign targets marketing professionals via fake job interviewshighbug_reportVulnerability
bug_reportVulnerability

Phishing campaign targets marketing professionals via fake job interviews

Marketing professionals with Google accounts; campaign impersonates 30+ brands including Adobe, Netflix, Coca-Cola, OpenAI. Credential theft targeting Google accounts specifically.

Adobe6 Jul · 18:27 UTC
Attackers impersonate IT support on Teams calls to deploy EtherRAThighbug_reportVulnerability
bug_reportVulnerability

Attackers impersonate IT support on Teams calls to deploy EtherRAT

Organizations using Microsoft Teams for internal communications. All industries are potential targets. The campaign exploits user trust in voice-based IT support interactions rather than a technical vulnerability in Teams itself.

Microsoft6 Jul · 18:23 UTC
Iran-linked MOIS group deploys Cavern C2 framework against Israelhighperson_alertThreat Actor
person_alertThreat Actor

Iran-linked MOIS group deploys Cavern C2 framework against Israel

An Iranian threat actor affiliated with Iran's Ministry of Intelligence and Security (MOIS), tracked by Check Point Research. The group operates in support of Iranian state intelligence objectives, focusing on espionage operations against adversary n…

The Hacker News6 Jul · 16:34 UTC
16-year KVM hypervisor flaw enables guest-to-host kernel corruptioncriticalbug_reportVulnerability
bug_reportVulnerability

16-year KVM hypervisor flaw enables guest-to-host kernel corruption

Linux KVM hypervisor on Intel and AMD x86 systems. All Linux kernel versions containing the vulnerable shadow MMU code (approximately 16 years of releases).

CVE-2026-533596 Jul · 15:37 UTC
Gitea Docker auth bypass under active probing (CVE-2026-20896)criticalbug_reportVulnerability
bug_reportVulnerability

Gitea Docker auth bypass under active probing (CVE-2026-20896)

Gitea Docker images with improper X-WEBAUTH-USER header validation. Specific vulnerable versions not provided; affects deployments trusting reverse proxy authentication headers without IP restrictions.

CVE-2026-208966 Jul · 14:28 UTC
Adobe ColdFusion CVE-2026-48282 under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Adobe ColdFusion CVE-2026-48282 under active exploitation

Adobe ColdFusion (specific versions not disclosed). Maximum severity vulnerability actively exploited in the wild.

CVE-2026-482826 Jul · 11:18 UTC
China-nexus actor targets Indian finance sector via DcRAT malwarehighperson_alertThreat Actor
person_alertThreat Actor

China-nexus actor targets Indian finance sector via DcRAT malware

A suspected China-nexus threat actor is conducting Operation DragonReturn, a targeted espionage campaign against Indian taxpayers and finance professionals.

The Hacker News6 Jul · 08:58 UTC
Opera GX patched silent add-on install flaw enabling data thefthighbug_reportVulnerability
bug_reportVulnerability

Opera GX patched silent add-on install flaw enabling data theft

Opera GX browser (specific versions not disclosed). Vulnerability allowed malicious websites to install browser extensions without user consent, enabling content extraction from visited pages including email addresses and other sensitive data.

Opera6 Jul · 05:27 UTC
JadePuffer: First LLM-Driven Ransomware Operation Documentedhighperson_alertThreat Actor
person_alertThreat Actor

JadePuffer: First LLM-Driven Ransomware Operation Documented

JadePuffer is a ransomware family representing the first documented instance of a ransomware operation conducted entirely by a large language model (LLM) agent.

BleepingComputer4 Jul · 12:16 UTC
Kairos extorts $1M from U.S. government via data theft without encryptionhighperson_alertThreat Actor
person_alertThreat Actor

Kairos extorts $1M from U.S. government via data theft without encryption

Kairos is a financially motivated threat actor that employs extortion tactics focused on data theft without deploying traditional ransomware encryption. The group targeted a U.S.

The Hacker News4 Jul · 10:47 UTC
North Korean actors deploy 108 malicious packages in PolinRider campaignhighbug_reportVulnerability
bug_reportVulnerability

North Korean actors deploy 108 malicious packages in PolinRider campaign

npm, Packagist (PHP), Go modules, and Google Chrome Web Store. 108 malicious packages and extensions published. Maintainer accounts actively compromised. Campaign linked to North Korean Contagious Interview threat group.

The Hacker News4 Jul · 09:17 UTC
Seven unpatched flaws in FatFs library affect millions of embedded deviceshighbug_reportVulnerability
bug_reportVulnerability

Seven unpatched flaws in FatFs library affect millions of embedded devices

FatFs filesystem library used in embedded devices including security cameras, drones, industrial controllers, and hardware crypto wallets. Affects devices reading/writing FAT and exFAT formats on USB drives and SD cards.

FatFs3 Jul · 18:19 UTC
Linux kernel "Bad Epoll" flaw grants unprivileged root accesscriticalbug_reportVulnerability
bug_reportVulnerability

Linux kernel "Bad Epoll" flaw grants unprivileged root access

Linux kernel (version range not specified) on desktops, servers, and Android devices. Affects both traditional Linux distributions and Android-based systems. Exploitable by unprivileged local users.

CVE-2026-462423 Jul · 17:40 UTC
Avalon Modular Malware Framework Delivers CrownX Ransomwarehighperson_alertThreat Actor
person_alertThreat Actor

Avalon Modular Malware Framework Delivers CrownX Ransomware

Avalon is a previously undocumented modular malware framework discovered by cybersecurity researchers. The framework is distributed through multi-stage phishing campaigns and represents a comprehensive attack platform integrating multiple offensive c…

The Hacker News3 Jul · 16:55 UTC
NetNut Residential Proxy Network Disrupted After Compromising 2M Deviceshighperson_alertThreat Actor
person_alertThreat Actor

NetNut Residential Proxy Network Disrupted After Compromising 2M Devices

NetNut operated a residential proxy network that leveraged approximately 2 million compromised Android devices to provide unauthorized proxy services. The actor monetized access to infected devices including smart TVs and streaming boxes, selling res…

Google3 Jul · 15:50 UTC
North Korean actors deploy malicious npm packages to steal developer secretshighbug_reportVulnerability
bug_reportVulnerability

North Korean actors deploy malicious npm packages to steal developer secrets

npm ecosystem: malicious packages "rollup-packages-polyfill-core" and "rollup-runtime-polyfill-core" impersonating legitimate "rollup-plugin-polyfill-node".

npm3 Jul · 14:07 UTC
EvilTokens Affiliate ARToken Exposes M365 Phishing-as-a-Service Platformhighperson_alertThreat Actor
person_alertThreat Actor

EvilTokens Affiliate ARToken Exposes M365 Phishing-as-a-Service Platform

EvilTokens is a threat actor operating a phishing-as-a-service (PhaaS) ecosystem targeting Microsoft 365 credentials. The group utilizes an affiliate model, with ARToken identified as one operational affiliate platform.

Microsoft3 Jul · 12:12 UTC
Armored Likho targets government and energy sectors with BusySnakehighperson_alertThreat Actor
person_alertThreat Actor

Armored Likho targets government and energy sectors with BusySnake

Armored Likho is a previously undocumented threat actor attributed by Kaspersky to cyber attacks targeting government agencies and the electric power sector.

The Hacker News3 Jul · 11:36 UTC
NSO Group's Pegasus Targets EU Parliament Member Investigating Spywarehighperson_alertThreat Actor
person_alertThreat Actor

NSO Group's Pegasus Targets EU Parliament Member Investigating Spyware

NSO Group is an Israeli-based commercial surveillance vendor that develops and sells the Pegasus spyware to government clients. The company markets its tools as lawful intercept solutions for counterterrorism and law enforcement, but has faced repeat…

The Hacker News3 Jul · 09:05 UTC
PamStealer: macOS Info Stealer Masquerades as Maccy Clipboard Managerhighperson_alertThreat Actor
person_alertThreat Actor

PamStealer: macOS Info Stealer Masquerades as Maccy Clipboard Manager

PamStealer is a newly discovered macOS information stealer malware family identified by Jamf Threat Labs. The malware is distributed through social engineering, masquerading as a legitimate Maccy clipboard manager application to deceive users into in…

Apple3 Jul · 06:03 UTC
FBI seizes NetNut proxy domains linked to two-million-device botnethighpublicGeopolitical
publicGeopolitical

FBI seizes NetNut proxy domains linked to two-million-device botnet

The FBI's seizure of domains associated with NetNut, a residential proxy service operated by Israeli firm Alarum Technologies, represents a significant law enforcement action targeting the infrastructure enabling large-scale botnet operations.

Alarum Technologies2 Jul · 17:27 UTC
NetNut (Popa) Residential Proxy Botnet Disrupted by Google, FBIhighperson_alertThreat Actor
person_alertThreat Actor

NetNut (Popa) Residential Proxy Botnet Disrupted by Google, FBI

NetNut, also tracked as Popa, operates a residential proxy network built on approximately 2 million compromised home devices. The actor monetizes this infrastructure by selling proxy services that route malicious traffic through legitimate residentia…

Google2 Jul · 16:54 UTC
Anubis Ransomware Exploits Citrix Bleed 2 (CVE-2025-5777) for Accesshighperson_alertThreat Actor
person_alertThreat Actor

Anubis Ransomware Exploits Citrix Bleed 2 (CVE-2025-5777) for Access

Anubis is a threat actor group operating the Anubis ransomware. The group demonstrates sophisticated tradecraft by exploiting recent vulnerabilities in enterprise infrastructure to gain initial access.

CVE-2025-57772 Jul · 16:30 UTC
ConsentFix and ClickFix campaigns hijack M365 accounts via OAuth token thefthighbug_reportVulnerability
bug_reportVulnerability

ConsentFix and ClickFix campaigns hijack M365 accounts via OAuth token theft

Microsoft 365 accounts across all organizations using OAuth authentication. Campaigns target users through social engineering to approve malicious OAuth consent prompts, bypassing MFA protections by stealing valid authentication tokens.

Microsoft2 Jul · 12:00 UTC
ToddyCat Deploys Umbrij Malware to Hijack Gmail via OAuth Abusehighperson_alertThreat Actor
person_alertThreat Actor

ToddyCat Deploys Umbrij Malware to Hijack Gmail via OAuth Abuse

ToddyCat (G1022) is an advanced persistent threat group that has demonstrated sophisticated capabilities in targeting corporate and enterprise environments.

Google2 Jul · 11:04 UTC