Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
satellite_altDaily BriefCyber Threat Daily Brief — September 4, 2026
Today's briefing: 14 critical and 22 high-severity threats. A total of 47 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.
Latest Reports
26 / 1172 results
highperson_alertThreat ActorAurora Ransomware Operators Leverage Cursor AI for Network Intrusion
Aurora (aka Aur0ra) ransomware operators are a Russian-speaking cybercrime group operating a ransomware-as-a-service (RaaS) model with affiliates. The group has been active since at least April 2026, targeting organizations across nine countries with…
highperson_alertThreat ActorSpring Ring Campaign Weaponizes Microsoft Teams for Vishing Attacks
Spring Ring is a coordinated social engineering campaign identified between January and April 2026 that leverages external Microsoft Teams accounts to impersonate IT help desk personnel.
highperson_alertThreat ActorNigerian Sextortion Operators Extradited to US for Crimes Resulting in Deaths
Two Nigerian nationals, 26-year-old Adebola Festus Adekunle and 24-year-old Mudasiru Afeez Olawale, are cybercriminals involved in sextortion schemes targeting minors.
highperson_alertThreat ActorFire Ant Expands Espionage to Cisco Routers and TACACS Servers
Fire Ant is a China-linked cyber espionage actor that has conducted long-running campaigns targeting network infrastructure and virtualization platforms.
highperson_alertThreat ActorChinese QTFY Group Targeted U.S. Federal Agencies via IoT Botnet
QTFY (also known as QT AND QTCYBER) is a Chinese state-sponsored threat actor active since 2018, operating on behalf of Nanjing Xinjiuwei Network Technology Co.
highperson_alertThreat ActorFulcrumSec claims 86 GB data theft from Manchester Airports Group
FulcrumSec is a financially motivated data-extortion group active since 2025. The group specializes in stealing sensitive corporate data and threatening to publish it, operating without deploying ransomware or encrypting victim systems.
highbug_reportVulnerability19 malicious Chrome/Edge extensions steal crypto and credentials
Google Chrome and Microsoft Edge users who installed any of 19 malicious extensions, including "Enable Right Click & Copy" (70,000+ Chrome users, 10,000+ Edge users). Campaign active since early 2024.
highbug_reportVulnerabilityTerminalFix campaign uses fake CAPTCHAs to deploy reverse-tunnel backdoor
Organizations across multiple sectors using Windows environments with PowerShell and Windows Terminal. Attack leverages compromised websites serving fake Cloudflare CAPTCHA pages to social engineer users into executing malicious PowerShell commands.
criticalbug_reportVulnerabilityCritical WordPress plugin flaws enable auth bypass and RCE on popular sites
WPMU DEV Dashboard plugin ≤5.0.1 (CVE-2026-76581), Avada theme ≤7.16 with Fusion Builder ≤3.16 (CVE-2026-18431), TranslatePress ≤3.3.1 with specific config (CVE-2026-19632), Pods plugin ≤3.3.9 (CVE-2026-19598), GiveWP plugin ≤4.16.7.1 (CVE-2026-82222…
highperson_alertThreat ActorTerminalFix Campaign Deploys Multi-Stage Attacks via Fake CAPTCHAs
TerminalFix is a coordinated campaign activity (variant of ClickFix social engineering technique) disclosed by Microsoft Threat Intelligence. The campaign targets organizations across multiple industries using compromised websites to deliver sophisti…
criticalperson_alertThreat ActorShinyHunters Claims 284M Patient Records from McKesson Breach
ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations targeting organizations with valuable databases.
highpublicGeopoliticalBerlin refuses ransom demand after Rhysida-linked breach of state network
The August 2026 compromise of Berlin's state administrative network represents a significant escalation in ransomware targeting of European critical infrastructure and government services.
criticalbug_reportVulnerabilityCosmos EVM balance flaw exploited on six chains after delayed patch
Cosmos EVM module versions < 0.6.2 and >= 0.7.0 < 0.7.2. All blockchains running Cosmos EVM with permissionless vesting account creation are vulnerable. Six chains were exploited August 20–25, 2026. Fixed in v0.6.2 and v0.7.2 (released August 19).
criticalbug_reportVulnerabilityPaperCut NG/MF actively exploited; second emergency patch released
PaperCut NG and MF print management software versions 24, 25, and 26 on Windows, Linux, and macOS. CVE-2026-81578 (CVSS 8.8) authentication bypass and CVE-2026-82078 (CVSS 9.4) unsafe class-loading vulnerability can be chained for pre-auth RCE.
criticalbug_reportVulnerabilityGiveWP WordPress plugin RCE allows unauthenticated server takeover
GiveWP WordPress donation plugin versions 4.16.6 through 4.16.7.1. Over 100,000 active installations. Exploitation requires legacy donation forms without 'formBuilderSettings' (common in upgraded sites or when using option-based form editor).
criticalbug_reportVulnerabilityPaperCut NG/MF flaws chained for unauthenticated RCE, active exploitation
PaperCut NG and PaperCut MF (all unpatched versions). CVE-2026-81578 (CVSS 8.8, improper access control) and CVE-2026-82078 (CVSS 9.4, unsafe dynamic class loading) are chained to bypass authentication and execute arbitrary Java code.
criticalbug_reportVulnerabilityownCloud CVE-2023-49105 exploited to steal nuclear records from Philippines
ownCloud core versions 10.6.0 through 10.13.0. The vulnerability is a WebDAV API authentication bypass allowing unauthenticated file access when usernames are known and no signing-key is configured (default state). Fixed in version 10.13.1.
highbug_reportVulnerability19 malicious Chrome/Edge extensions drain crypto wallets via auto-updates
19 browser extensions (18 Chrome, 1 Edge) published since February 2024, with "Enable Right Click & Copy — Smart Unlock + OCR" having 80,000 installs. Extensions either created by threat actor or purchased from legitimate owners.
highbug_reportVulnerabilityWatchGuard Fireware OS vulnerabilities require immediate patching
WatchGuard Fireware OS - specific versions not provided in advisory. Affects WatchGuard firewall appliances running vulnerable Fireware OS versions.
criticalbug_reportVulnerabilityCritical vulnerabilities in PaperCut software require immediate patching
PaperCut software (specific versions not disclosed in advisory). Affects organizations using PaperCut print management solutions.
criticalbug_reportVulnerabilityServiceNow platforms face critical vulnerabilities requiring urgent patching
ServiceNow platforms (specific versions not disclosed in advisory). Scope and affected components not detailed in available information.
criticalbug_reportVulnerability8,300+ Gitea servers unpatched against exploited RCE flaw CVE-2026-60004
Gitea versions prior to 1.27.1. Over 8,300 Internet-exposed instances remain vulnerable. Affects self-hosted Gitea installations with default open registration enabled.
criticalbug_reportVulnerabilityUnitree G1 EDU robot vulnerable to dual root RCE via network and BLE
Unitree G1 EDU humanoid robot. Firmware versions not definitively confirmed; researcher tested V1.5.2. G1 (non-EDU) and other Unitree robot models have unconfirmed applicability. Both vulnerabilities grant root access on the Locomotion PC.
criticalbug_reportVulnerabilityServiceNow AI Platform: Three CVSS 10.0 flaws enable unauthenticated RCE
ServiceNow AI Platform versions: Xanadu (before Patch 11 HF 7a), Yokohama (before Patch 12 HF 3b / Patch 13 HF 4), Zurich (before Patch 7b HF 3 through Patch 12 depending on branch), Australia (before Patch 2 HF 3 through Patch 5).
criticalbug_reportVulnerabilityZBT routers ship with factory implants granting root access via network
ZBT (Shenzhen Zhibotong Electronics) routers and white-labeled variants. CVE-2026-74233 (DARKLANTERN) affects 16+ models including WE1326, WE826-T2, WE5926, WG3526 on firmware builds from 2019-2020.
criticalbug_reportVulnerabilityServiceNow AI Platform: 3 critical unauthenticated flaws patched
ServiceNow AI Platform (formerly Now Platform): Xanadu Patch 11, Yokohama Patch 12-13, Zurich Patch 7-12, Australia Patch 2-5. Affects cloud (auto-patched) and self-hosted instances.