Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 702 results
Active filter:✕ clear
NLnet Labs patches DoS vulnerabilities in Unbound DNS resolverhighbug_reportVulnerability
bug_reportVulnerability

NLnet Labs patches DoS vulnerabilities in Unbound DNS resolver

Unbound DNS resolver by NLnet Labs. Specific vulnerable versions not provided in advisory; patched versions available. Affects organizations running Unbound for DNS resolution services.

NLnet Labs21 May · 14:21 UTC
Cisco Secure Workload max-severity flaw grants Site Admin privilegescriticalbug_reportVulnerability
bug_reportVulnerability

Cisco Secure Workload max-severity flaw grants Site Admin privileges

Cisco Secure Workload platform. Specific affected versions not provided in summary. Vulnerability allows privilege escalation to Site Admin level, affecting administrative access controls.

Cisco21 May · 11:58 UTC
Microsoft Defender privilege escalation CVE-2026-41091 under active exploithighbug_reportVulnerability
bug_reportVulnerability

Microsoft Defender privilege escalation CVE-2026-41091 under active exploit

Microsoft Defender on Windows systems. Specific product versions not disclosed. Vulnerability allows local attackers to escalate privileges to SYSTEM level through improper link resolution handling.

CVE-2026-4109121 May · 08:55 UTC
Critical flaws in Sparx Pro Cloud Server actively exploited in the wildcriticalbug_reportVulnerability
bug_reportVulnerability

Critical flaws in Sparx Pro Cloud Server actively exploited in the wild

Sparx Systems Pro Cloud Server and Enterprise Architect products. Specific vulnerable versions not disclosed in summary; CERT.BE advisory should be consulted for version details.

Sparx Systems21 May · 06:49 UTC
SonicWall Gen6 SSL-VPN exploited for credential brute-force and MFA bypasscriticalbug_reportVulnerability
bug_reportVulnerability

SonicWall Gen6 SSL-VPN exploited for credential brute-force and MFA bypass

SonicWall Gen6 SSL-VPN appliances with incomplete patching. Specific firmware versions not disclosed. Affects organizations using SonicWall SSL-VPN for remote access.

SonicWall20 May · 19:19 UTC
Compromised @antv npm packages deploy credential-stealing malwarecriticalbug_reportVulnerability
bug_reportVulnerability

Compromised @antv npm packages deploy credential-stealing malware

Multiple @antv npm packages compromised with Mini Shai-Hulud malware. Affects Linux-based CI/CD pipelines using npm install. Targets credentials from GitHub, AWS, Kubernetes, HashiCorp Vault, npm, and 1Password.

npm20 May · 15:48 UTC
Grafana breach via unrotated GitHub token after TanStack npm compromisehighbug_reportVulnerability
bug_reportVulnerability

Grafana breach via unrotated GitHub token after TanStack npm compromise

Grafana Labs infrastructure. Organizations using Grafana products are not directly affected by the breach itself, but should monitor for potential secondary impacts.

Grafana20 May · 13:46 UTC
PgBouncer integer overflow under active exploitation, patch immediatelycriticalbug_reportVulnerability
bug_reportVulnerability

PgBouncer integer overflow under active exploitation, patch immediately

PgBouncer (PostgreSQL connection pooler) - specific affected versions not disclosed by CERT.BE. All unpatched instances should be considered at risk.

PgBouncer20 May · 12:50 UTC
Drupal critical core vulnerability with imminent exploit riskcriticalbug_reportVulnerability
bug_reportVulnerability

Drupal critical core vulnerability with imminent exploit risk

Drupal core (specific versions not disclosed). All Drupal installations should be considered at risk until patched.

Drupal20 May · 10:52 UTC
PinTheft Linux privilege escalation PoC released for Arch Linuxhighbug_reportVulnerability
bug_reportVulnerability

PinTheft Linux privilege escalation PoC released for Arch Linux

Arch Linux systems. Specific affected package versions not disclosed; vulnerability has been patched in recent updates. Other Linux distributions may be affected depending on package configurations.

Arch Linux20 May · 08:52 UTC
Microsoft mitigates YellowKey BitLocker bypass (CVE-2026-45585)highbug_reportVulnerability
bug_reportVulnerability

Microsoft mitigates YellowKey BitLocker bypass (CVE-2026-45585)

Microsoft BitLocker on Windows systems. Specific affected versions not disclosed. Vulnerability allows bypass of BitLocker disk encryption protections.

CVE-2026-4558520 May · 06:28 UTC
Microsoft mitigates YellowKey BitLocker zero-day bypass vulnerabilityhighbug_reportVulnerability
bug_reportVulnerability

Microsoft mitigates YellowKey BitLocker zero-day bypass vulnerability

Windows BitLocker across all supported Windows versions. The vulnerability allows unauthorized access to BitLocker-protected drives. No CVE assigned yet.

Microsoft20 May · 05:31 UTC
PostgreSQL patches multiple high-severity flaws; version 14 EOL announcedhighbug_reportVulnerability
bug_reportVulnerability

PostgreSQL patches multiple high-severity flaws; version 14 EOL announced

PostgreSQL database server, multiple versions affected by security vulnerabilities. Version 14 reaching end-of-life, no longer receiving security updates after EOL date.

PostgreSQL20 May · 04:05 UTC
Critical Portainer vulnerabilities enable full host takeovercriticalbug_reportVulnerability
bug_reportVulnerability

Critical Portainer vulnerabilities enable full host takeover

Portainer container management platform. Specific affected versions not disclosed in summary; CERT.BE advisory should be consulted for version details. Impacts organizations using Portainer for Docker/Kubernetes management.

Portainer20 May · 03:56 UTC
ChromaDB FastAPI RCE allows unauthenticated arbitrary code executioncriticalbug_reportVulnerability
bug_reportVulnerability

ChromaDB FastAPI RCE allows unauthenticated arbitrary code execution

ChromaDB latest Python FastAPI version. Affects exposed ChromaDB servers accessible over the network. No CVE assigned yet.

ChromaDB19 May · 20:25 UTC
Critical nginx vulnerabilities enable RCE and rate-limit bypasscriticalbug_reportVulnerability
bug_reportVulnerability

Critical nginx vulnerabilities enable RCE and rate-limit bypass

nginx web server (specific versions not provided by CERT.BE advisory). Affects organizations running vulnerable nginx instances, particularly those exposed to the internet or untrusted networks.

nginx19 May · 13:05 UTC
PoC released for DirtyDecrypt LPE in Linux kernel (CVE-2026-31635)highbug_reportVulnerability
bug_reportVulnerability

PoC released for DirtyDecrypt LPE in Linux kernel (CVE-2026-31635)

Linux kernel - specific vulnerable versions not provided. Local privilege escalation vulnerability affecting systems running vulnerable kernel versions.

CVE-2026-3163519 May · 12:56 UTC
Over 600 malicious npm packages published in Shai-Hulud campaignhighbug_reportVulnerability
bug_reportVulnerability

Over 600 malicious npm packages published in Shai-Hulud campaign

npm ecosystem: 600+ malicious packages published by threat actors. Affects organizations using npm for JavaScript/Node.js dependency management. Specific package names not provided in summary.

npm19 May · 12:30 UTC
SonicWall releases patches for multiple high-severity vulnerabilitieshighbug_reportVulnerability
bug_reportVulnerability

SonicWall releases patches for multiple high-severity vulnerabilities

SonicWall products (specific models and versions not disclosed in summary). CERT.BE advisory indicates multiple vulnerabilities requiring immediate patching across SonicWall product line.

SonicWall19 May · 12:27 UTC
Microsoft sees rise in privilege escalation and identity abuse flawshighbug_reportVulnerability
bug_reportVulnerability

Microsoft sees rise in privilege escalation and identity abuse flaws

Microsoft products and services experiencing increased critical vulnerabilities focused on privilege escalation and identity abuse. Specific affected products and versions not detailed in available data.

Microsoft19 May · 12:00 UTC
ABB CoreSense path traversal flaw allows unauthenticated system accesshighbug_reportVulnerability
bug_reportVulnerability

ABB CoreSense path traversal flaw allows unauthenticated system access

ABB CoreSense HM (versions prior to v2.3.4) and CoreSense M10 (versions prior to v1.4.1.31). Path traversal vulnerability affects unauthenticated remote attackers.

CVE-2025-346519 May · 10:00 UTC
ScadaBR 1.2.0 critical flaws enable unauthenticated remote code executioncriticalbug_reportVulnerability
bug_reportVulnerability

ScadaBR 1.2.0 critical flaws enable unauthenticated remote code execution

ScadaBR version 1.2.0, a SCADA system used in critical infrastructure sectors including energy, water, and manufacturing worldwide. All four CVEs affect the same version.

CVE-2026-860219 May · 10:00 UTC
ZKTeco CCTV cameras expose credentials via unauthenticated config portcriticalbug_reportVulnerability
bug_reportVulnerability

ZKTeco CCTV cameras expose credentials via unauthenticated config port

ZKTeco CCTV cameras, specifically model SSC335-GC2063-Face-0b77, running firmware versions prior to V5.0.1.2.20260421. Vulnerability affects an undocumented configuration export port that allows unauthenticated access to camera credentials and config…

CVE-2026-859819 May · 10:00 UTC
Kieback & Peter DDC controllers vulnerable to XSS attackshighbug_reportVulnerability
bug_reportVulnerability

Kieback & Peter DDC controllers vulnerable to XSS attacks

Kieback & Peter DDC (Direct Digital Control) Building Controllers. Specific affected versions not disclosed in available data.

CVE-2026-429319 May · 10:00 UTC
Buffer overflow in PAN-OS User-ID portal enables unauthenticated RCEhighbug_reportVulnerability
bug_reportVulnerability

Buffer overflow in PAN-OS User-ID portal enables unauthenticated RCE

Palo Alto Networks PAN-OS on PA-Series and VM-Series firewalls; Siemens RUGGEDCOM APE1808 devices. Specific affected PAN-OS versions not provided in summary.

CVE-2026-030019 May · 10:00 UTC
Microsoft Exchange Server XSS flaw actively exploited for session hijackingcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft Exchange Server XSS flaw actively exploited for session hijacking

Microsoft Exchange Server (specific versions not disclosed). Cross-Site Scripting vulnerability enabling spoofing and session hijacking. No CVE assigned yet.

Microsoft18 May · 13:25 UTC
Critical PAN-OS vulnerabilities enable auth bypass and code executioncriticalbug_reportVulnerability
bug_reportVulnerability

Critical PAN-OS vulnerabilities enable auth bypass and code execution

Palo Alto Networks PAN-OS (specific versions not provided in summary). Affects authentication controls, code execution surface, and availability.

Palo Alto Networks18 May · 12:43 UTC
Cisco Catalyst SD-WAN auth bypass grants admin access to attackerscriticalbug_reportVulnerability
bug_reportVulnerability

Cisco Catalyst SD-WAN auth bypass grants admin access to attackers

Cisco Catalyst SD-WAN platform. Specific affected versions not disclosed. Vulnerability allows authentication bypass leading to administrative access on SD-WAN infrastructure components.

Cisco18 May · 12:16 UTC
Ivanti releases security updates for multiple productshighbug_reportVulnerability
bug_reportVulnerability

Ivanti releases security updates for multiple products

Multiple Ivanti products affected. Specific product names, versions, and CVE identifiers not disclosed in available information. High severity rating indicates significant security risk.

Ivanti14 May · 07:55 UTC
Multiple critical vulnerabilities in Fortinet products require patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Multiple critical vulnerabilities in Fortinet products require patching

Fortinet products: FortiSandbox, FortiOS, FortiAP, FortiAnalyzer, and FortiManager. Specific affected versions not provided in advisory. Multiple vulnerabilities ranging from critical to medium severity.

Fortinet14 May · 05:08 UTC