Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 666 results
highbug_reportVulnerabilityCryptojacking campaign uses SEO poisoning and ScreenConnect for GPU mining
Organizations using ScreenConnect remote access software; high-performance PCs with GPUs; users searching for compromised topics via search engines and AI chatbots. Campaign leverages Microsoft .NET utilities for execution.
criticalbug_reportVulnerabilityZero-day in KnowledgeDeliver LMS exploited to deploy Godzilla web shell
KnowledgeDeliver learning management system (specific versions unknown). Exploitation results in web shell deployment enabling persistent remote access to affected servers.
criticalbug_reportVulnerabilityLiteSpeed cPanel/WHM plugin under active exploit (CVE-2026-48172)
LiteSpeed plugin for cPanel/WHM. Specific vulnerable versions not disclosed in provided data. Affects web hosting environments using LiteSpeed with cPanel/WHM integration.
criticalbug_reportVulnerabilityUbiquiti patches critical UniFi OS vulnerabilities
Ubiquiti UniFi OS (specific versions not disclosed). Affects UniFi network management appliances including Dream Machine, Cloud Key, and similar devices running UniFi OS.
highbug_reportVulnerabilityMicrosoft patches SharePoint RCE flaw via unsafe deserialization
Microsoft SharePoint Server (specific versions not disclosed). Vulnerability involves deserialization of untrusted data leading to remote code execution with CVSS 8.8.
criticalbug_reportVulnerabilityTrend Micro Apex One & Vision One SEP flaws under active exploit
Trend Micro Apex One and Trend Micro Vision One Endpoint Security (SEP). Specific vulnerable versions not disclosed in summary; multiple vulnerabilities confirmed under active exploitation.
criticalbug_reportVulnerabilityCritical vulnerability in Cisco Secure Workload requires immediate patching
Cisco Secure Workload (specific versions not disclosed in advisory). CVE identifier not yet assigned or published.
criticalbug_reportVulnerabilityCISA orders emergency patching of exploited Drupal SQL injection flaw
Drupal CMS (specific versions not provided in alert). Affects U.S. government agencies and all organizations running vulnerable Drupal instances.
highbug_reportVulnerabilityWindows Server 2016 domain controller lookups fail after KB5087537 update
Windows Server 2016 domain controllers running KB5087537 (May 2026 security update). Impacts Active Directory domain controller lookup functionality and domain connectivity.
highbug_reportVulnerabilityDigital Knowledge LMS exploited via hardcoded ASP.NET keys (CVE-2026-5426)
Digital Knowledge KnowledgeDeliver LMS (specific versions not disclosed). Vulnerability stems from hard-coded ASP.NET machine keys enabling authentication bypass and remote code execution.
criticalbug_reportVulnerabilityGhost CMS SQL injection (CVE-2026-26980) exploited in ClickFix campaign
Ghost CMS Content API, all versions prior to patch. Over 700 sites confirmed compromised. Unauthenticated attackers can exploit the SQL injection vulnerability remotely.
highbug_reportVulnerabilityOutSystems Lifetime authorization bypass via user-controlled key
OutSystems Lifetime software. Specific affected versions not disclosed. Vulnerability allows authorization bypass through improper handling of user-controlled keys.
criticalbug_reportVulnerabilityTrapDoor campaign deploys credential stealers across npm, PyPI, Crates.io
34+ malicious packages (384+ versions) distributed across npm (Node.js), PyPI (Python), and Crates.io (Rust) repositories. Campaign active since May 2026. Affects developers and CI/CD pipelines consuming packages from these ecosystems.
highbug_reportVulnerabilityLaravel Lang packages compromised to deliver credential-stealing malware
Laravel Lang localization packages distributed via Composer. Affects developers who installed or updated compromised packages during the attack window. Specific package names and versions not yet publicly disclosed.
highbug_reportVulnerabilitySupply chain attack compromises 8 Packagist packages with malicious binary
Eight Composer packages on Packagist containing JavaScript components. Malicious code injected into package.json files executes a Linux binary from GitHub Releases. Downstream projects using these packages are affected.
highbug_reportVulnerabilityAnthropic Glasswing project finds 10,000+ critical flaws in key software
Widely used, systemically important software (specific products not disclosed). Over 10,000 high- or critical-severity vulnerabilities identified since project launch last month.
highbug_reportVulnerabilityLaravel-Lang packages compromised to deliver credential-stealing malware
Multiple Laravel-Lang PHP packages compromised: laravel-lang/lang, laravel-lang/http-statuses, laravel-lang/attributes, and laravel-lang/actions. Affects Laravel PHP applications using these localization packages.
criticalbug_reportVulnerabilityTrend Micro Apex One zero-day actively exploited in the wild
Trend Micro Apex One on Windows systems. Specific affected versions not disclosed. Zero-day vulnerability with no CVE assigned yet.
criticalbug_reportVulnerabilityDrupal SQL injection under active exploitation, patch immediately
Drupal CMS installations. Specific affected versions not provided in available data. Critical SQL injection vulnerability announced this week, now actively exploited.
criticalbug_reportVulnerabilityUbiquiti patches three critical unauthenticated RCE flaws in UniFi OS
Ubiquiti UniFi OS (specific versions not disclosed). Affects UniFi network management appliances including Dream Machine, Cloud Key, and other UniFi OS-based devices.
criticalbug_reportVulnerabilityCISA: Langflow and Trend Micro Apex One flaws actively exploited
Langflow (CVE-2025-34291, CVSS 9.4, origin validation error) and Trend Micro Apex One (CVE unspecified). Both products confirmed under active exploitation. Specific affected versions not disclosed in summary.
criticalbug_reportVulnerabilityCisco Secure Workload REST API flaw allows unauthenticated data access
Cisco Secure Workload (formerly Tetration). Specific affected versions not provided in available data. Vulnerability impacts REST API endpoints with insufficient authentication controls.
highbug_reportVulnerabilityChromium zero-day disclosed: JavaScript persists after browser close
Chromium-based browsers (Google Chrome, Microsoft Edge, Brave, Opera, Vivaldi) - specific affected versions not disclosed. Vulnerability remains unpatched at time of disclosure.
criticalbug_reportVulnerabilityCritical SQL injection in Drupal Core requires immediate patching
Drupal Core, all versions (specific affected versions not disclosed in alert). Impacts all Drupal installations until patched.
highbug_reportVulnerabilityNLnet Labs patches DoS vulnerabilities in Unbound DNS resolver
Unbound DNS resolver by NLnet Labs. Specific vulnerable versions not provided in advisory; patched versions available. Affects organizations running Unbound for DNS resolution services.
criticalbug_reportVulnerabilityCisco Secure Workload max-severity flaw grants Site Admin privileges
Cisco Secure Workload platform. Specific affected versions not provided in summary. Vulnerability allows privilege escalation to Site Admin level, affecting administrative access controls.
highbug_reportVulnerabilityMicrosoft Defender privilege escalation CVE-2026-41091 under active exploit
Microsoft Defender on Windows systems. Specific product versions not disclosed. Vulnerability allows local attackers to escalate privileges to SYSTEM level through improper link resolution handling.
criticalbug_reportVulnerabilityCritical flaws in Sparx Pro Cloud Server actively exploited in the wild
Sparx Systems Pro Cloud Server and Enterprise Architect products. Specific vulnerable versions not disclosed in summary; CERT.BE advisory should be consulted for version details.
criticalbug_reportVulnerabilitySonicWall Gen6 SSL-VPN exploited for credential brute-force and MFA bypass
SonicWall Gen6 SSL-VPN appliances with incomplete patching. Specific firmware versions not disclosed. Affects organizations using SonicWall SSL-VPN for remote access.
criticalbug_reportVulnerabilityCompromised @antv npm packages deploy credential-stealing malware
Multiple @antv npm packages compromised with Mini Shai-Hulud malware. Affects Linux-based CI/CD pipelines using npm install. Targets credentials from GitHub, AWS, Kubernetes, HashiCorp Vault, npm, and 1Password.