Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports
Cyber Threat Daily Brief — September 4, 2026satellite_altDaily Brief
Threat Intel Brief·Daily Summary

Cyber Threat Daily Brief — September 4, 2026

Today's briefing: 14 critical and 22 high-severity threats. A total of 47 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.

14 Critical22 High47 analyses
schedule02:17 UTC
Read briefarrow_forward

Latest Reports

28 / 1107 results
Cisco Unified CM vulnerability under active exploitation post-patchhighbug_reportVulnerability
bug_reportVulnerability

Cisco Unified CM vulnerability under active exploitation post-patch

Cisco Unified Communications Manager (Unified CM). Specific vulnerable versions not disclosed; patched versions available since early June 2024. Affects organizations running unpatched Unified CM deployments.

Cisco2 Jul · 09:35 UTC
CISA: Active exploitation of RCE flaw in Microsoft SharePointhighbug_reportVulnerability
bug_reportVulnerability

CISA: Active exploitation of RCE flaw in Microsoft SharePoint

Microsoft SharePoint servers vulnerable prior to May 2024 security updates. Affects on-premises SharePoint deployments; unauthenticated remote code execution possible on unpatched systems.

Microsoft2 Jul · 08:52 UTC
JADEPUFFER: First AI-Agent-Orchestrated Ransomware Attackcriticalperson_alertThreat Actor
person_alertThreat Actor

JADEPUFFER: First AI-Agent-Orchestrated Ransomware Attack

JADEPUFFER is a threat actor identified by Sysdig as the operator behind what is claimed to be the first fully AI-agent-orchestrated ransomware attack. The actor leveraged artificial intelligence agents to automate the entire attack lifecycle, repres…

Langflow2 Jul · 07:13 UTC
Scattered Spider Member Extradited to U.S. from Estoniahighperson_alertThreat Actor
person_alertThreat Actor

Scattered Spider Member Extradited to U.S. from Estonia

Scattered Spider (G1015), also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944, is a financially motivated threat actor collective known for sophisticated social engineering and identity-based attacks.

BleepingComputer2 Jul · 06:58 UTC
FortiBleed Campaign Linked to INC and Lynx Ransomware Operationshighperson_alertThreat Actor
person_alertThreat Actor

FortiBleed Campaign Linked to INC and Lynx Ransomware Operations

The FortiBleed campaign is a financially-motivated credential theft operation attributed to actors associated with the INC and Lynx ransomware groups. The campaign focuses on exploiting FortiGate devices to harvest credentials, which are subsequently…

Fortinet2 Jul · 06:00 UTC
Fake GitHub PoC repos deliver ChocoPoC trojan to security researchershighbug_reportVulnerability
bug_reportVulnerability

Fake GitHub PoC repos deliver ChocoPoC trojan to security researchers

Vulnerability researchers and security professionals using GitHub to access proof-of-concept exploit code. The ChocoPoC malware targets Windows systems, stealing credentials, browser data, and files while establishing remote shell access.

GitHub2 Jul · 05:24 UTC
Microsoft SharePoint RCE flaw under active exploitation (CVE-2026-45659)criticalbug_reportVulnerability
bug_reportVulnerability

Microsoft SharePoint RCE flaw under active exploitation (CVE-2026-45659)

Microsoft SharePoint Server, all versions vulnerable to deserialization attacks. Specific affected versions not yet disclosed.

CVE-2026-456592 Jul · 03:46 UTC
ShinyHunters Breaches Medtronic Healthcare Device Manufacturerhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Breaches Medtronic Healthcare Device Manufacturer

ShinyHunters is a financially-motivated cybercrime group known for large-scale data breaches and database exfiltration operations. The group has been active since at least 2020, targeting organizations across multiple sectors to steal sensitive data…

Medtronic2 Jul · 02:25 UTC
INC and Lynx Ransomware Groups Exploit FortiBleed for Credential Thefthighperson_alertThreat Actor
person_alertThreat Actor

INC and Lynx Ransomware Groups Exploit FortiBleed for Credential Theft

INC and Lynx are ransomware threat actors linked to the FortiBleed credential theft campaign. These groups operate with the primary motivation of financial gain through ransomware deployment.

Fortinet1 Jul · 19:37 UTC
Kubota North America reports month-long network intrusion in 2024highpublicGeopolitical
publicGeopolitical

Kubota North America reports month-long network intrusion in 2024

The extended unauthorized access to Kubota North America's network systems highlights vulnerabilities in critical infrastructure sectors, particularly manufacturing and agriculture.

Kubota1 Jul · 19:09 UTC
Trojanized GitHub PoC exploits deliver ChocoPoC RAT to researchershighbug_reportVulnerability
bug_reportVulnerability

Trojanized GitHub PoC exploits deliver ChocoPoC RAT to researchers

Cybersecurity researchers and security teams downloading proof-of-concept exploit code from GitHub repositories. ChocoPoC is a Python-based remote access trojan with command execution and data exfiltration capabilities.

BleepingComputer1 Jul · 18:08 UTC
Argo CD repo-server RCE enables cluster takeover, no patch availablecriticalbug_reportVulnerability
bug_reportVulnerability

Argo CD repo-server RCE enables cluster takeover, no patch available

Argo CD repo-server component, all versions (specific affected versions not disclosed). Exploitation requires access to internal network port where repo-server listens.

Argo CD1 Jul · 17:40 UTC
Scattered Spider Member Extradited to U.S. on Federal Hacking Chargeshighperson_alertThreat Actor
person_alertThreat Actor

Scattered Spider Member Extradited to U.S. on Federal Hacking Charges

Scattered Spider (also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944) is a financially motivated threat actor group known for sophisticated social engineering and identity-based attacks.

The Hacker News1 Jul · 17:28 UTC
Massive SEO-Poisoned Campaign Distributes AsyncRAT via ScreenConnecthighperson_alertThreat Actor
person_alertThreat Actor

Massive SEO-Poisoned Campaign Distributes AsyncRAT via ScreenConnect

The threat actor behind this campaign remains unattributed. Motivation appears to be financially driven, consistent with commodity RAT deployment for access brokering, credential theft, or follow-on ransomware operations.

OBS Studio1 Jul · 15:53 UTC
DHS Confirms Breach of Homeland Security Information NetworkhighpublicGeopolitical
publicGeopolitical

DHS Confirms Breach of Homeland Security Information Network

The compromise of the Homeland Security Information Network (HSIN) represents a significant breach of a critical federal information-sharing infrastructure.

Department of Homeland Security1 Jul · 15:32 UTC
VEIL#DROP campaign delivers PureLogs stealer via Blogger pageshighperson_alertThreat Actor
person_alertThreat Actor

VEIL#DROP campaign delivers PureLogs stealer via Blogger pages

VEIL#DROP is a multi-stage malware delivery campaign identified by Securonix researchers. The campaign employs social engineering tactics and abuses legitimate Blogger platform infrastructure to distribute PureLogs, an information-stealing malware.

Google Blogger1 Jul · 15:18 UTC
Password-spray campaign hits Microsoft 365 with 81M login attemptshighbug_reportVulnerability
bug_reportVulnerability

Password-spray campaign hits Microsoft 365 with 81M login attempts

Microsoft 365 environments (Exchange Online, Azure AD/Entra ID, SharePoint, Teams). All organizations using M365 cloud services are potential targets. Attack focuses on user authentication endpoints.

Microsoft1 Jul · 14:38 UTC
Ousaban banking trojan targets Spain and Portugal via phishinghighbug_reportVulnerability
bug_reportVulnerability

Ousaban banking trojan targets Spain and Portugal via phishing

Windows users in Spain and Portugal. Ousaban banking trojan campaign using fake PDF lures with geolocation filtering and steganography techniques. No specific product vulnerability; threat actor campaign identified by Fortinet FortiGuard Labs in May…

Fortinet1 Jul · 13:26 UTC
Adobe patches CVSS 10.0 flaws in ColdFusion and Campaign Classiccriticalbug_reportVulnerability
bug_reportVulnerability

Adobe patches CVSS 10.0 flaws in ColdFusion and Campaign Classic

Adobe ColdFusion and Adobe Campaign Classic (specific versions not provided). Vulnerabilities include arbitrary code execution, privilege escalation, arbitrary file system read, and security feature bypass.

Adobe1 Jul · 13:25 UTC
Cursor AI editor vulnerable to sandbox escape via prompt injectioncriticalbug_reportVulnerability
bug_reportVulnerability

Cursor AI editor vulnerable to sandbox escape via prompt injection

Cursor AI code editor, all versions prior to patch. Both CVE-2026-50548 (CVSS 9.8) and CVE-2026-50549 (CVSS 9.3) enable sandbox escape and arbitrary command execution via prompt injection without user interaction.

CVE-2026-505481 Jul · 12:42 UTC
Progress Kemp LoadMaster RCE under active exploitation (CVE-2026-8037)criticalbug_reportVulnerability
bug_reportVulnerability

Progress Kemp LoadMaster RCE under active exploitation (CVE-2026-8037)

Progress Kemp LoadMaster load balancers. Specific affected versions not disclosed. Pre-authentication vulnerability allows unauthenticated remote attackers to execute OS commands.

CVE-2026-80371 Jul · 11:56 UTC
DeepSeek AI Used to Generate Novel Browser-Based Ransomwarehighperson_alertThreat Actor
person_alertThreat Actor

DeepSeek AI Used to Generate Novel Browser-Based Ransomware

DeepSeek refers to the AI model leveraged by unknown threat actors to generate functional browser-based ransomware code. This marks the first documented instance of a frontier AI model being weaponized to create a novel ransomware technique.

Chromium1 Jul · 10:59 UTC
900+ Oracle E-Business Suite instances exposed, under active attackcriticalbug_reportVulnerability
bug_reportVulnerability

900+ Oracle E-Business Suite instances exposed, under active attack

Oracle E-Business Suite instances exposed to the internet (900+ confirmed). Specific vulnerable versions not disclosed; critical severity vulnerability being exploited.

Oracle1 Jul · 10:30 UTC
LLM hallucinations exploited for supply chain attacks via phantom domainshighbug_reportVulnerability
bug_reportVulnerability

LLM hallucinations exploited for supply chain attacks via phantom domains

Organizations using LLMs for development assistance, code generation, or package recommendations. Developers relying on AI-generated domain/package suggestions without verification.

Unit 42 (Palo Alto)30 Jun · 23:00 UTC
Trojanized Pyrogram forks on PyPI target Telegram bot developershighbug_reportVulnerability
bug_reportVulnerability

Trojanized Pyrogram forks on PyPI target Telegram bot developers

Python developers using PyPI packages for Telegram bot development. Malicious forks of Pyrogram library active since November 2024. Affects developers who may have installed compromised packages instead of legitimate Pyrogram.

PyPI30 Jun · 19:02 UTC
AI agents using Model Context Protocol vulnerable to tool poisoning attackshighbug_reportVulnerability
bug_reportVulnerability

AI agents using Model Context Protocol vulnerable to tool poisoning attacks

AI agents implementing Microsoft's Model Context Protocol (MCP). Specific products and versions not disclosed. Affects organizations deploying MCP-based AI agents with access to sensitive internal data and external tool integrations.

Microsoft30 Jun · 15:46 UTC
RustDuck Botnet Targets IoT Devices for DDoS Operationshighperson_alertThreat Actor
person_alertThreat Actor

RustDuck Botnet Targets IoT Devices for DDoS Operations

RustDuck is a two-stage malware family written in Rust, designed to compromise Internet of Things (IoT) devices including home routers, IP cameras, Android set-top boxes, and inadequately secured servers.

Generic routers30 Jun · 15:45 UTC
Langflow RCE (CVE-2026-33017) actively exploited for cryptominingcriticalbug_reportVulnerability
bug_reportVulnerability

Langflow RCE (CVE-2026-33017) actively exploited for cryptomining

Langflow AI application framework, all exposed endpoints vulnerable to unauthenticated remote code execution. Specific affected versions not disclosed; assume all unpatched instances at risk.

CVE-2026-3301730 Jun · 13:47 UTC