Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports
Cyber Threat Daily Brief — September 4, 2026satellite_altDaily Brief
Threat Intel Brief·Daily Summary

Cyber Threat Daily Brief — September 4, 2026

Today's briefing: 14 critical and 22 high-severity threats. A total of 47 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.

14 Critical22 High47 analyses
schedule02:17 UTC
Read briefarrow_forward

Latest Reports

26 / 1172 results
Aurora Ransomware Operators Leverage Cursor AI for Network Intrusionhighperson_alertThreat Actor
person_alertThreat Actor

Aurora Ransomware Operators Leverage Cursor AI for Network Intrusion

Aurora (aka Aur0ra) ransomware operators are a Russian-speaking cybercrime group operating a ransomware-as-a-service (RaaS) model with affiliates. The group has been active since at least April 2026, targeting organizations across nine countries with…

SpaceX31 Aug · 09:47 UTC
Spring Ring Campaign Weaponizes Microsoft Teams for Vishing Attackshighperson_alertThreat Actor
person_alertThreat Actor

Spring Ring Campaign Weaponizes Microsoft Teams for Vishing Attacks

Spring Ring is a coordinated social engineering campaign identified between January and April 2026 that leverages external Microsoft Teams accounts to impersonate IT help desk personnel.

Microsoft31 Aug · 08:00 UTC
Nigerian Sextortion Operators Extradited to US for Crimes Resulting in Deathshighperson_alertThreat Actor
person_alertThreat Actor

Nigerian Sextortion Operators Extradited to US for Crimes Resulting in Deaths

Two Nigerian nationals, 26-year-old Adebola Festus Adekunle and 24-year-old Mudasiru Afeez Olawale, are cybercriminals involved in sextortion schemes targeting minors.

BleepingComputer31 Aug · 07:22 UTC
Fire Ant Expands Espionage to Cisco Routers and TACACS Servershighperson_alertThreat Actor
person_alertThreat Actor

Fire Ant Expands Espionage to Cisco Routers and TACACS Servers

Fire Ant is a China-linked cyber espionage actor that has conducted long-running campaigns targeting network infrastructure and virtualization platforms.

Cisco31 Aug · 07:04 UTC
Chinese QTFY Group Targeted U.S. Federal Agencies via IoT Botnethighperson_alertThreat Actor
person_alertThreat Actor

Chinese QTFY Group Targeted U.S. Federal Agencies via IoT Botnet

QTFY (also known as QT AND QTCYBER) is a Chinese state-sponsored threat actor active since 2018, operating on behalf of Nanjing Xinjiuwei Network Technology Co.

NASA31 Aug · 05:56 UTC
FulcrumSec claims 86 GB data theft from Manchester Airports Grouphighperson_alertThreat Actor
person_alertThreat Actor

FulcrumSec claims 86 GB data theft from Manchester Airports Group

FulcrumSec is a financially motivated data-extortion group active since 2025. The group specializes in stealing sensitive corporate data and threatening to publish it, operating without deploying ransomware or encrypting victim systems.

Manchester Airports Group30 Aug · 13:00 UTC
19 malicious Chrome/Edge extensions steal crypto and credentialshighbug_reportVulnerability
bug_reportVulnerability

19 malicious Chrome/Edge extensions steal crypto and credentials

Google Chrome and Microsoft Edge users who installed any of 19 malicious extensions, including "Enable Right Click & Copy" (70,000+ Chrome users, 10,000+ Edge users). Campaign active since early 2024.

Google30 Aug · 12:17 UTC
TerminalFix campaign uses fake CAPTCHAs to deploy reverse-tunnel backdoorhighbug_reportVulnerability
bug_reportVulnerability

TerminalFix campaign uses fake CAPTCHAs to deploy reverse-tunnel backdoor

Organizations across multiple sectors using Windows environments with PowerShell and Windows Terminal. Attack leverages compromised websites serving fake Cloudflare CAPTCHA pages to social engineer users into executing malicious PowerShell commands.

Microsoft30 Aug · 05:36 UTC
Critical WordPress plugin flaws enable auth bypass and RCE on popular sitescriticalbug_reportVulnerability
bug_reportVulnerability

Critical WordPress plugin flaws enable auth bypass and RCE on popular sites

WPMU DEV Dashboard plugin ≤5.0.1 (CVE-2026-76581), Avada theme ≤7.16 with Fusion Builder ≤3.16 (CVE-2026-18431), TranslatePress ≤3.3.1 with specific config (CVE-2026-19632), Pods plugin ≤3.3.9 (CVE-2026-19598), GiveWP plugin ≤4.16.7.1 (CVE-2026-82222…

CVE-2026-7658129 Aug · 14:25 UTC
TerminalFix Campaign Deploys Multi-Stage Attacks via Fake CAPTCHAshighperson_alertThreat Actor
person_alertThreat Actor

TerminalFix Campaign Deploys Multi-Stage Attacks via Fake CAPTCHAs

TerminalFix is a coordinated campaign activity (variant of ClickFix social engineering technique) disclosed by Microsoft Threat Intelligence. The campaign targets organizations across multiple industries using compromised websites to deliver sophisti…

Microsoft29 Aug · 01:43 UTC
ShinyHunters Claims 284M Patient Records from McKesson Breachcriticalperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Claims 284M Patient Records from McKesson Breach

ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations targeting organizations with valuable databases.

McKesson28 Aug · 20:40 UTC
Berlin refuses ransom demand after Rhysida-linked breach of state networkhighpublicGeopolitical
publicGeopolitical

Berlin refuses ransom demand after Rhysida-linked breach of state network

The August 2026 compromise of Berlin's state administrative network represents a significant escalation in ransomware targeting of European critical infrastructure and government services.

The Hacker News28 Aug · 19:30 UTC
Cosmos EVM balance flaw exploited on six chains after delayed patchcriticalbug_reportVulnerability
bug_reportVulnerability

Cosmos EVM balance flaw exploited on six chains after delayed patch

Cosmos EVM module versions < 0.6.2 and >= 0.7.0 < 0.7.2. All blockchains running Cosmos EVM with permissionless vesting account creation are vulnerable. Six chains were exploited August 20–25, 2026. Fixed in v0.6.2 and v0.7.2 (released August 19).

Cosmos Labs28 Aug · 18:38 UTC
PaperCut NG/MF actively exploited; second emergency patch releasedcriticalbug_reportVulnerability
bug_reportVulnerability

PaperCut NG/MF actively exploited; second emergency patch released

PaperCut NG and MF print management software versions 24, 25, and 26 on Windows, Linux, and macOS. CVE-2026-81578 (CVSS 8.8) authentication bypass and CVE-2026-82078 (CVSS 9.4) unsafe class-loading vulnerability can be chained for pre-auth RCE.

PaperCut28 Aug · 17:08 UTC
GiveWP WordPress plugin RCE allows unauthenticated server takeovercriticalbug_reportVulnerability
bug_reportVulnerability

GiveWP WordPress plugin RCE allows unauthenticated server takeover

GiveWP WordPress donation plugin versions 4.16.6 through 4.16.7.1. Over 100,000 active installations. Exploitation requires legacy donation forms without 'formBuilderSettings' (common in upgraded sites or when using option-based form editor).

GiveWP28 Aug · 16:18 UTC
PaperCut NG/MF flaws chained for unauthenticated RCE, active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

PaperCut NG/MF flaws chained for unauthenticated RCE, active exploitation

PaperCut NG and PaperCut MF (all unpatched versions). CVE-2026-81578 (CVSS 8.8, improper access control) and CVE-2026-82078 (CVSS 9.4, unsafe dynamic class loading) are chained to bypass authentication and execute arbitrary Java code.

PaperCut28 Aug · 15:12 UTC
ownCloud CVE-2023-49105 exploited to steal nuclear records from Philippinescriticalbug_reportVulnerability
bug_reportVulnerability

ownCloud CVE-2023-49105 exploited to steal nuclear records from Philippines

ownCloud core versions 10.6.0 through 10.13.0. The vulnerability is a WebDAV API authentication bypass allowing unauthenticated file access when usernames are known and no signing-key is configured (default state). Fixed in version 10.13.1.

CVE-2023-4910528 Aug · 13:56 UTC
19 malicious Chrome/Edge extensions drain crypto wallets via auto-updateshighbug_reportVulnerability
bug_reportVulnerability

19 malicious Chrome/Edge extensions drain crypto wallets via auto-updates

19 browser extensions (18 Chrome, 1 Edge) published since February 2024, with "Enable Right Click & Copy — Smart Unlock + OCR" having 80,000 installs. Extensions either created by threat actor or purchased from legitimate owners.

Google28 Aug · 13:27 UTC
WatchGuard Fireware OS vulnerabilities require immediate patchinghighbug_reportVulnerability
bug_reportVulnerability

WatchGuard Fireware OS vulnerabilities require immediate patching

WatchGuard Fireware OS - specific versions not provided in advisory. Affects WatchGuard firewall appliances running vulnerable Fireware OS versions.

WatchGuard28 Aug · 13:08 UTC
Critical vulnerabilities in PaperCut software require immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical vulnerabilities in PaperCut software require immediate patching

PaperCut software (specific versions not disclosed in advisory). Affects organizations using PaperCut print management solutions.

PaperCut28 Aug · 13:03 UTC
ServiceNow platforms face critical vulnerabilities requiring urgent patchingcriticalbug_reportVulnerability
bug_reportVulnerability

ServiceNow platforms face critical vulnerabilities requiring urgent patching

ServiceNow platforms (specific versions not disclosed in advisory). Scope and affected components not detailed in available information.

ServiceNow28 Aug · 12:09 UTC
8,300+ Gitea servers unpatched against exploited RCE flaw CVE-2026-60004criticalbug_reportVulnerability
bug_reportVulnerability

8,300+ Gitea servers unpatched against exploited RCE flaw CVE-2026-60004

Gitea versions prior to 1.27.1. Over 8,300 Internet-exposed instances remain vulnerable. Affects self-hosted Gitea installations with default open registration enabled.

Gitea28 Aug · 10:58 UTC
Unitree G1 EDU robot vulnerable to dual root RCE via network and BLEcriticalbug_reportVulnerability
bug_reportVulnerability

Unitree G1 EDU robot vulnerable to dual root RCE via network and BLE

Unitree G1 EDU humanoid robot. Firmware versions not definitively confirmed; researcher tested V1.5.2. G1 (non-EDU) and other Unitree robot models have unconfirmed applicability. Both vulnerabilities grant root access on the Locomotion PC.

CVE-2026-7663928 Aug · 10:07 UTC
ServiceNow AI Platform: Three CVSS 10.0 flaws enable unauthenticated RCEcriticalbug_reportVulnerability
bug_reportVulnerability

ServiceNow AI Platform: Three CVSS 10.0 flaws enable unauthenticated RCE

ServiceNow AI Platform versions: Xanadu (before Patch 11 HF 7a), Yokohama (before Patch 12 HF 3b / Patch 13 HF 4), Zurich (before Patch 7b HF 3 through Patch 12 depending on branch), Australia (before Patch 2 HF 3 through Patch 5).

ServiceNow28 Aug · 09:20 UTC
ZBT routers ship with factory implants granting root access via networkcriticalbug_reportVulnerability
bug_reportVulnerability

ZBT routers ship with factory implants granting root access via network

ZBT (Shenzhen Zhibotong Electronics) routers and white-labeled variants. CVE-2026-74233 (DARKLANTERN) affects 16+ models including WE1326, WE826-T2, WE5926, WG3526 on firmware builds from 2019-2020.

CVE-2026-7423228 Aug · 08:58 UTC
ServiceNow AI Platform: 3 critical unauthenticated flaws patchedcriticalbug_reportVulnerability
bug_reportVulnerability

ServiceNow AI Platform: 3 critical unauthenticated flaws patched

ServiceNow AI Platform (formerly Now Platform): Xanadu Patch 11, Yokohama Patch 12-13, Zurich Patch 7-12, Australia Patch 2-5. Affects cloud (auto-patched) and self-hosted instances.

ServiceNow28 Aug · 08:29 UTC