Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports
Cyber Threat Daily Brief — September 4, 2026satellite_altDaily Brief
Threat Intel Brief·Daily Summary

Cyber Threat Daily Brief — September 4, 2026

Today's briefing: 14 critical and 22 high-severity threats. A total of 47 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.

14 Critical22 High47 analyses
schedule02:17 UTC
Read briefarrow_forward

Latest Reports

27 / 1107 results
Agentic coding tools vulnerable to hidden malicious payloads in reposhighbug_reportVulnerability
bug_reportVulnerability

Agentic coding tools vulnerable to hidden malicious payloads in repos

Agentic coding tools and AI-assisted development platforms that automatically fetch and execute code from GitHub repositories. Specific products not disclosed.

BleepingComputer27 Jun · 12:22 UTC
Russian Intelligence Services Target Signal Users in Phishing Campaignhighperson_alertThreat Actor
person_alertThreat Actor

Russian Intelligence Services Target Signal Users in Phishing Campaign

Russian intelligence services are conducting a phishing campaign targeting Signal messaging application users. The operation is attributed by the FBI and CISA, indicating state-sponsored activity aimed at compromising secure communications.

Signal26 Jun · 20:06 UTC
CISA orders federal patch for exploited Cisco Unified Comms flawcriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders federal patch for exploited Cisco Unified Comms flaw

Cisco Unified Communications Manager Server. Specific versions not disclosed. Federal agencies mandated to patch; all organizations running this product should consider affected.

Cisco26 Jun · 17:43 UTC
Russian Intelligence Escalates Signal Phishing for Backup Recovery Keyshighperson_alertThreat Actor
person_alertThreat Actor

Russian Intelligence Escalates Signal Phishing for Backup Recovery Keys

Russian intelligence actors, as identified by FBI and CISA joint reporting, are conducting targeted phishing operations against Signal messaging platform users.

Signal26 Jun · 17:38 UTC
SharkLoader malware deploys Cobalt Strike in attacks on Asian governmentshighbug_reportVulnerability
bug_reportVulnerability

SharkLoader malware deploys Cobalt Strike in attacks on Asian governments

Diplomatic and government organizations in Indonesia and Taiwan. SharkLoader is a newly identified malware family used to deliver Cobalt Strike Beacon payloads in the StrikeShark campaign.

The Hacker News26 Jun · 16:17 UTC
Polymarket frontend compromised via third-party vendor; $3M stolenhighbug_reportVulnerability
bug_reportVulnerability

Polymarket frontend compromised via third-party vendor; $3M stolen

Polymarket platform users. Attack vector: malicious JavaScript injected into frontend via compromised third-party vendor. Approximately $3 million in customer funds stolen. No CVE assigned.

Polymarket26 Jun · 16:04 UTC
Unknown Actors Exploit OpenAI Tenants to Phish Cybersecurity Firmshighperson_alertThreat Actor
person_alertThreat Actor

Unknown Actors Exploit OpenAI Tenants to Phish Cybersecurity Firms

The threat actors behind this campaign remain unattributed. Their motivation appears to be intelligence gathering and corporate espionage, leveraging the trust associated with OpenAI's platform to deceive employees of cybersecurity companies.

BleepingComputer26 Jun · 15:49 UTC
CL-STA-1062 deploys TinyRCT backdoor against Southeast Asian governmenthighperson_alertThreat Actor
person_alertThreat Actor

CL-STA-1062 deploys TinyRCT backdoor against Southeast Asian government

CL-STA-1062 is a Chinese-speaking APT actor conducting targeted cyber espionage operations against government entities and critical infrastructure in Southeast Asia.

Palo Alto Networks26 Jun · 14:21 UTC
Linux kernel traffic-control flaw grants local root via public exploitcriticalbug_reportVulnerability
bug_reportVulnerability

Linux kernel traffic-control flaw grants local root via public exploit

Linux kernel traffic-control subsystem (act_pedit module). All distributions running vulnerable kernel versions are affected. Specific patched versions not provided; assume unpatched kernels prior to June 16, 2026 vendor advisories are vulnerable.

CVE-2026-4633126 Jun · 11:57 UTC
Amazon Q Developer flaw allows credential theft via malicious reposhighbug_reportVulnerability
bug_reportVulnerability

Amazon Q Developer flaw allows credential theft via malicious repos

Amazon Q Developer (all versions prior to patch). Affects developers using the IDE plugin who clone or open malicious repositories containing crafted Model Context Protocol (MCP) server configurations.

CVE-2026-1295726 Jun · 11:53 UTC
PTC Windchill and FlexPLM RCE actively exploited in web shell attackscriticalbug_reportVulnerability
bug_reportVulnerability

PTC Windchill and FlexPLM RCE actively exploited in web shell attacks

PTC Windchill PDMlink and PTC FlexPLM Product Lifecycle Management systems. Specific affected versions not disclosed in summary; consult CISA KEV catalog and PTC security advisories for version details.

PTC26 Jun · 10:31 UTC
DirtyClone Linux kernel flaw enables local privilege escalation to roothighbug_reportVulnerability
bug_reportVulnerability

DirtyClone Linux kernel flaw enables local privilege escalation to root

Linux kernel (specific vulnerable versions not disclosed). Affects systems where local users can trigger network packet cloning operations. Part of the DirtyFrag vulnerability family.

CVE-2026-4350326 Jun · 09:51 UTC
Miasma malware compromises npm packages LeoPlatform and RStreamshighbug_reportVulnerability
bug_reportVulnerability

Miasma malware compromises npm packages LeoPlatform and RStreams

npm packages LeoPlatform and RStreams compromised by Miasma malware family. Attack extends to GitHub Actions workflows and Go ecosystem. Organizations using these packages or dependent projects are affected.

npm26 Jun · 09:05 UTC
Phishing campaign targets hotel front desks with Node.js implanthighbug_reportVulnerability
bug_reportVulnerability

Phishing campaign targets hotel front desks with Node.js implant

Hotel and hospitality organizations in Europe and Asia. Front-desk systems targeted via photo-themed ZIP file attachments containing Node.js-based malware. Campaign active since April 2026.

Microsoft26 Jun · 07:27 UTC
Polish Authorities Dismantle SIM-Swapping Gang Targeting Crypto Assetshighperson_alertThreat Actor
person_alertThreat Actor

Polish Authorities Dismantle SIM-Swapping Gang Targeting Crypto Assets

This organized cybercrime group operated in Poland, conducting SIM-swapping attacks with the primary motivation of financial gain through cryptocurrency theft.

BleepingComputer25 Jun · 20:37 UTC
Active campaign targets hospitality in Europe/Asia via ZIP archiveshighbug_reportVulnerability
bug_reportVulnerability

Active campaign targets hospitality in Europe/Asia via ZIP archives

Hospitality organizations in Europe and Asia. Attack vector: photo-themed ZIP archives containing malicious shortcut files that deploy a Node.js implant.

Microsoft25 Jun · 20:30 UTC
CL-STA-1062 targets Southeast Asian government with TinyRCT backdoorhighperson_alertThreat Actor
person_alertThreat Actor

CL-STA-1062 targets Southeast Asian government with TinyRCT backdoor

CL-STA-1062 is a threat actor conducting cyber espionage operations against government entities and critical infrastructure in Southeast Asia. The actor employs a hybrid toolkit centered around a custom backdoor known as TinyRCT.

Unit 42 (Palo Alto)25 Jun · 20:00 UTC
Shopify Shop app abused for callback phishing via fake order receiptshighbug_reportVulnerability
bug_reportVulnerability

Shopify Shop app abused for callback phishing via fake order receipts

Shopify Shop order-tracking app users. Threat actors inject fraudulent purchase receipts into legitimate user order histories, leveraging Shopify's trusted platform to deliver phishing lures.

Shopify25 Jun · 17:45 UTC
Bluekit PhaaS expands with 70 new domains, adds browser-in-the-middlehighbug_reportVulnerability
bug_reportVulnerability

Bluekit PhaaS expands with 70 new domains, adds browser-in-the-middle

Organizations using cloud services and SaaS platforms targeted by Bluekit phishing-as-a-service infrastructure. Approximately 70 new phishing hostnames deployed in the past week.

BleepingComputer25 Jun · 13:00 UTC
Gogs Git service vulnerable to remote code execution, patch immediatelycriticalbug_reportVulnerability
bug_reportVulnerability

Gogs Git service vulnerable to remote code execution, patch immediately

Gogs Git service (specific versions not disclosed in advisory). All internet-facing Gogs instances should be considered at risk until patched.

Gogs25 Jun · 12:55 UTC
Adblock for YouTube extension with 10M+ installs contains code injection riskhighbug_reportVulnerability
bug_reportVulnerability

Adblock for YouTube extension with 10M+ installs contains code injection risk

Chrome extension "Adblock for YouTube" (10+ million active installations). All users with the extension installed are potentially affected. Extension currently holds Featured badge status in Chrome Web Store.

Google25 Jun · 12:12 UTC
KongTuke Deploys Mistic Backdoor in Multi-Sector Financial Attackshighperson_alertThreat Actor
person_alertThreat Actor

KongTuke Deploys Mistic Backdoor in Multi-Sector Financial Attacks

KongTuke is an initial access broker (IAB) conducting financially motivated operations targeting organizations across insurance, education, IT, and professional services sectors.

The Hacker News25 Jun · 06:54 UTC
Cisco Catalyst SD-WAN zero-day exploited in wild for two monthshighbug_reportVulnerability
bug_reportVulnerability

Cisco Catalyst SD-WAN zero-day exploited in wild for two months

Cisco Catalyst SD-WAN Manager. Specific affected versions not disclosed. Requires authenticated local access for exploitation.

CVE-2026-2024525 Jun · 03:46 UTC
Snoopy Sentenced to 18 Months for DraftKings Account Compromisehighperson_alertThreat Actor
person_alertThreat Actor

Snoopy Sentenced to 18 Months for DraftKings Account Compromise

Snoopy is a 21-year-old individual arrested and sentenced for unauthorized access to customer accounts on the DraftKings sports betting platform in November 2022.

DraftKings24 Jun · 19:55 UTC
Cisco Catalyst SD-WAN zero-day exploited for root access (CVE-2026-20245)criticalbug_reportVulnerability
bug_reportVulnerability

Cisco Catalyst SD-WAN zero-day exploited for root access (CVE-2026-20245)

Cisco Catalyst SD-WAN devices. Specific affected versions not disclosed in available information. Attackers gain root-level access and can create persistent rogue accounts.

CVE-2026-2024524 Jun · 19:29 UTC
Edgecution: Malicious Edge Extension Enables Sandbox Escapehighperson_alertThreat Actor
person_alertThreat Actor

Edgecution: Malicious Edge Extension Enables Sandbox Escape

Edgecution is a malicious browser extension targeting Microsoft Edge, not a threat actor group. It functions as a tool deployed during ransomware operations to facilitate sandbox escape and establish persistence.

Microsoft24 Jun · 18:58 UTC
CISA warns: Lantronix EDS5000 code injection under active exploitcriticalbug_reportVulnerability
bug_reportVulnerability

CISA warns: Lantronix EDS5000 code injection under active exploit

Lantronix EDS5000 Series devices. Specific vulnerable firmware versions not disclosed in provided data. Critical code injection vulnerability (CVE-2025-67038, CVSS 9.8).

CVE-2025-6703824 Jun · 15:19 UTC