Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 675 results
Active filter:✕ clear
Meta AI bot exploited to hijack high-profile Instagram accountshighbug_reportVulnerability
bug_reportVulnerability

Meta AI bot exploited to hijack high-profile Instagram accounts

Meta Instagram platform, specifically the AI-powered customer support bot used for account recovery. High-profile accounts including Obama White House and U.S. Space Force Chief Master Sergeant were compromised.

Meta1 Jun · 15:32 UTC
Malware campaign infects 2,000 WordPress sites using Steam profiles for C2highbug_reportVulnerability
bug_reportVulnerability

Malware campaign infects 2,000 WordPress sites using Steam profiles for C2

Nearly 2,000 WordPress websites compromised. All WordPress versions potentially affected depending on initial infection vector (likely vulnerable plugins, themes, or weak credentials).

WordPress1 Jun · 15:04 UTC
Hard-coded credentials in KS-SOMED software enable unauthorized accesshighbug_reportVulnerability
bug_reportVulnerability

Hard-coded credentials in KS-SOMED software enable unauthorized access

KS-SOMED software (specific versions not disclosed). Hard-coded credentials embedded in application code allow unauthorized access to affected systems.

CVE-2026-422511 Jun · 10:55 UTC
Windows Netlogon RCE under active exploitation after patch releasecriticalbug_reportVulnerability
bug_reportVulnerability

Windows Netlogon RCE under active exploitation after patch release

Microsoft Windows Netlogon service, all versions prior to recent patch. Affects domain controllers and systems with Netlogon service enabled. Specific CVE and affected version details not provided in alert.

Microsoft1 Jun · 10:30 UTC
Malicious npm package codexui-android steals OpenAI tokens, 29K downloadshighbug_reportVulnerability
bug_reportVulnerability

Malicious npm package codexui-android steals OpenAI tokens, 29K downloads

npm package codexui-android (all versions). Targets developers using OpenAI Codex APIs. Affects organizations with Node.js/npm development environments where this package was installed.

OpenAI1 Jun · 07:31 UTC
WP Maps Pro plugin exploited to create rogue admin accounts on WordPresscriticalbug_reportVulnerability
bug_reportVulnerability

WP Maps Pro plugin exploited to create rogue admin accounts on WordPress

WP Maps Pro WordPress plugin (all versions prior to patch). Over 15,000 installations via Envato Market. Affects WordPress sites using this plugin for Google Maps integration.

WP Maps Pro1 Jun · 06:45 UTC
WP Maps Pro plugin under active attack via admin account creation flawhighbug_reportVulnerability
bug_reportVulnerability

WP Maps Pro plugin under active attack via admin account creation flaw

WP Maps Pro WordPress plugin (version details not specified). Affects WordPress sites with the plugin installed. Vulnerability allows unauthenticated attackers to create administrator accounts.

WP Maps Pro31 May · 12:06 UTC
Dutch authorities dismantle botnet controlling 17M infected deviceshighbug_reportVulnerability
bug_reportVulnerability

Dutch authorities dismantle botnet controlling 17M infected devices

At least 17 million infected devices globally including computers, tablets, smartphones, and IoT devices. Over 200 command-and-control servers located in the Netherlands were seized.

The Hacker News31 May · 10:22 UTC
PAN-OS GlobalProtect auth bypass CVE-2026-0257 under active exploitcriticalbug_reportVulnerability
bug_reportVulnerability

PAN-OS GlobalProtect auth bypass CVE-2026-0257 under active exploit

Palo Alto Networks PAN-OS GlobalProtect VPN. Specific affected versions not disclosed in provided data. Impacts corporate networks using GlobalProtect for remote access.

CVE-2026-025730 May · 16:02 UTC
CIFSwitch: Linux kernel CIFS flaw enables local privilege escalationhighbug_reportVulnerability
bug_reportVulnerability

CIFSwitch: Linux kernel CIFS flaw enables local privilege escalation

Linux kernel CIFS implementation across multiple distributions. Specific affected kernel versions not yet disclosed. Requires local access to exploit.

Linux30 May · 12:16 UTC
Palo Alto PAN-OS auth bypass (CVE-2026-0257) exploited in the wildhighbug_reportVulnerability
bug_reportVulnerability

Palo Alto PAN-OS auth bypass (CVE-2026-0257) exploited in the wild

Palo Alto Networks PAN-OS and Prisma Access. Specific affected versions not disclosed in provided data. Vulnerability impacts VPN authentication mechanisms.

CVE-2026-025730 May · 04:41 UTC
33 malicious npm packages deployed in dependency confusion recon campaignhighbug_reportVulnerability
bug_reportVulnerability

33 malicious npm packages deployed in dependency confusion recon campaign

npm ecosystem; organizations using private npm packages with names vulnerable to dependency confusion attacks. Affects developer workstations, CI/CD pipelines, and build environments that may inadvertently install public packages instead of intended…

npm29 May · 22:06 UTC
Threat actors abuse ChatGPT sharing to host fake OpenAI outage pageshighbug_reportVulnerability
bug_reportVulnerability

Threat actors abuse ChatGPT sharing to host fake OpenAI outage pages

OpenAI ChatGPT users globally. Threat actors exploit ChatGPT's legitimate content-sharing feature (chatgpt.com shared links) to host convincing phishing pages that impersonate OpenAI outage notifications and distribute malware posing as the ChatGPT d…

OpenAI29 May · 16:21 UTC
ChatGPT Markdown renderer vulnerable to prompt injection and phishinghighbug_reportVulnerability
bug_reportVulnerability

ChatGPT Markdown renderer vulnerable to prompt injection and phishing

OpenAI ChatGPT web summary response renderer. All users interacting with ChatGPT's web interface that processes Markdown links and images are potentially affected. Specific version details not disclosed.

OpenAI29 May · 16:07 UTC
Microsoft May 2026 Patch Tuesday: 118 vulnerabilities, 16 criticalcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft May 2026 Patch Tuesday: 118 vulnerabilities, 16 critical

Microsoft products and services across the ecosystem. 118 total vulnerabilities: 16 critical severity, 102 important severity. Specific affected products and CVE identifiers not yet detailed in available information.

Microsoft29 May · 14:06 UTC
Oracle releases critical security patches for multiple productshighbug_reportVulnerability
bug_reportVulnerability

Oracle releases critical security patches for multiple products

Multiple Oracle products affected by high-severity vulnerabilities. Specific product names, versions, and CVE identifiers not provided in CERT.BE advisory. Likely part of Oracle's quarterly Critical Patch Update (CPU).

Oracle29 May · 12:43 UTC
CVE-2026-39987 in Marimo actively exploited for cloud credential thefthighbug_reportVulnerability
bug_reportVulnerability

CVE-2026-39987 in Marimo actively exploited for cloud credential theft

Marimo notebook platform (specific versions not disclosed). Affects internet-exposed Marimo notebook instances vulnerable to CVE-2026-39987.

CVE-2026-3998729 May · 12:39 UTC
Dutch authorities disrupt 17M-device botnet, seize 200+ servershighbug_reportVulnerability
bug_reportVulnerability

Dutch authorities disrupt 17M-device botnet, seize 200+ servers

Approximately 17 million infected devices globally; over 200 servers seized from a Dutch hosting provider. Specific botnet malware family and affected device types not disclosed.

BleepingComputer29 May · 12:26 UTC
Malicious NuGet package "Sicoob.Sdk" steals banking credentialshighbug_reportVulnerability
bug_reportVulnerability

Malicious NuGet package "Sicoob.Sdk" steals banking credentials

NuGet package "Sicoob.Sdk" versions 2.0.0 through 2.0.4. Targets developers integrating with Sicoob (Brazilian cooperative banking system). Affects .NET development environments where the malicious package was installed.

Sicoob29 May · 07:11 UTC
Hard-coded secret in Trac PDBM enables unauthorized accesshighbug_reportVulnerability
bug_reportVulnerability

Hard-coded secret in Trac PDBM enables unauthorized access

Trac d.o.o. Process Database Manager (PDBM) - specific affected versions not disclosed. Vulnerability involves hard-coded cryptographic secret embedded in executable binary.

CVE-2026-2560029 May · 05:16 UTC
BTMOB Android RAT offered as MaaS with custom phishing builderhighbug_reportVulnerability
bug_reportVulnerability

BTMOB Android RAT offered as MaaS with custom phishing builder

Android devices targeted by BTMOB remote access trojan. No specific vendor or version restrictions; affects users who install malicious APKs distributed through phishing campaigns.

BleepingComputer28 May · 19:10 UTC
Fortinet FortiClient EMS auth bypass exploited to deploy EKZ malwarehighbug_reportVulnerability
bug_reportVulnerability

Fortinet FortiClient EMS auth bypass exploited to deploy EKZ malware

Fortinet FortiClient Enterprise Management Server (EMS). Specific vulnerable versions not provided in available data. Authentication bypass vulnerability CVE-2026-35616 allows unauthorized access.

CVE-2026-3561628 May · 15:25 UTC
Critical RCE in Gogs Git service allows authenticated users to execute codecriticalbug_reportVulnerability
bug_reportVulnerability

Critical RCE in Gogs Git service allows authenticated users to execute code

Gogs self-hosted Git service. Specific affected versions not disclosed. All authenticated users can exploit the vulnerability.

Gogs28 May · 15:24 UTC
Starlette and FastAPI authentication bypass flaw affects millions of serverscriticalbug_reportVulnerability
bug_reportVulnerability

Starlette and FastAPI authentication bypass flaw affects millions of servers

Starlette web framework and dependent frameworks including FastAPI. Specific vulnerable versions not provided in source data. Affects authentication mechanisms in applications built with these frameworks.

Starlette28 May · 12:32 UTC
Unpatched RCE zero-day in Gogs Git service actively threatens exposed instancescriticalbug_reportVulnerability
bug_reportVulnerability

Unpatched RCE zero-day in Gogs Git service actively threatens exposed instances

Gogs self-hosted Git service, all Internet-facing instances. Specific affected versions not disclosed. No patch currently available.

Gogs28 May · 12:25 UTC
Critical RCE vulnerability in LiquidJS requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical RCE vulnerability in LiquidJS requires immediate patching

LiquidJS templating engine, all versions prior to patched release. Specific vulnerable version range not provided in available data.

LiquidJS28 May · 12:20 UTC
Dell Container Storage Modules info disclosure enables data exfiltrationcriticalbug_reportVulnerability
bug_reportVulnerability

Dell Container Storage Modules info disclosure enables data exfiltration

Dell Container Storage Modules (specific versions not disclosed in summary). Vulnerability allows information disclosure that can lead to data exfiltration and lateral movement within containerized environments.

Dell28 May · 11:55 UTC
Kidsview authentication bypass allows unauthorized access (CVE-2026-8990)highbug_reportVulnerability
bug_reportVulnerability

Kidsview authentication bypass allows unauthorized access (CVE-2026-8990)

Kidsview application (specific versions not disclosed). Authentication mechanisms can be bypassed, potentially affecting all deployments until patched versions are confirmed.

CVE-2026-899028 May · 11:55 UTC
Out-of-bounds write in bzip2 enables code execution or DoShighbug_reportVulnerability
bug_reportVulnerability

Out-of-bounds write in bzip2 enables code execution or DoS

bzip2 compression software, all versions not yet patched. Affects systems using bzip2 for file compression/decompression, including Linux distributions, BSD variants, and applications embedding libbz2.

CVE-2026-4225028 May · 10:15 UTC
Cryptojacking campaign uses SEO poisoning and AI chatbots for GPU malwarehighbug_reportVulnerability
bug_reportVulnerability

Cryptojacking campaign uses SEO poisoning and AI chatbots for GPU malware

High-performance systems with GPUs accessed via search engines and AI chatbot platforms. No specific vendor or product vulnerability; targets users searching for legitimate software or information through poisoned search results and manipulated chatb…

BleepingComputer27 May · 19:31 UTC