Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 159 results
criticalbug_reportVulnerabilityActive exploitation of critical FortiSandbox vulnerabilities
Fortinet FortiSandbox cyber threat detection platform. Specific versions not disclosed. No CVE assigned yet.
criticalperson_alertThreat ActorChina-linked espionage group targets North American research networks
A China-linked espionage group conducted a sustained intrusion campaign lasting over one year against North American institutions. The actor's motivation appears to be intelligence collection focused on medical research, academic intellectual propert…
criticalbug_reportVulnerabilityCisco Catalyst SD-WAN Manager root privilege escalation under attack
Cisco Catalyst SD-WAN Manager (specific versions not provided). Vulnerability allows privilege escalation to root level on affected systems.
criticalbug_reportVulnerabilityLiteLLM AI gateway vulnerable to privilege escalation and RCE
LiteLLM open-source AI gateway. Specific affected versions not disclosed. Impacts organizations using LiteLLM to manage API keys and route requests to AI providers (OpenAI, Anthropic, etc.).
criticalbug_reportVulnerabilitySearchLeak in Microsoft 365 Copilot enables data theft via crafted URLs
Microsoft 365 Copilot Enterprise. All organizations using Copilot with access to mailbox, OneDrive, or SharePoint data are potentially affected. Specific vulnerable versions not disclosed.
criticalbug_reportVulnerabilitySupply chain attack hits PushEngage, OptinMonster, TrustPulse plugins
WordPress sites using PushEngage, OptinMonster, and TrustPulse plugins. All versions loading compromised JavaScript files from vendor infrastructure are affected.
criticalperson_alertThreat ActorChinese state-sponsored hackers maintain 10-year persistent access
Chinese state-sponsored hackers, likely an advanced persistent threat (APT) group operating on behalf of the People's Republic of China. The actor demonstrated exceptional operational security and patience, maintaining covert access to a target organ…
criticalbug_reportVulnerabilitySplunk Enterprise RCE flaw allows unauthenticated remote code execution
Splunk Enterprise versions below 10.2.4 and 10.0.7. The vulnerability enables unauthenticated attackers to perform arbitrary file operations and achieve remote code execution. CVSS score 9.8 (Critical).
criticalbug_reportVulnerabilityArch User Repository supply chain attack: 400+ packages backdoored
Arch Linux users who installed or updated packages from the Arch User Repository (AUR) during the compromise window. Over 400 AUR packages contained malicious build scripts deploying a Rust-based infostealer.
criticalperson_alertThreat ActorVelvet Ant: China-linked APT backdoors Linux auth for decade-long access
Velvet Ant (G1047) is a China-linked advanced persistent threat actor characterized by exceptional operational security and long-term persistence capabilities.
criticalbug_reportVulnerability400+ Arch User Repository packages compromised with rootkit and infostealer
Arch Linux users who installed or updated packages from the Arch User Repository (AUR). Over 400 AUR packages confirmed compromised. Specific package names and versions not yet disclosed.
criticalbug_reportVulnerabilityOracle PeopleSoft RCE actively exploited, immediate patching required
Oracle PeopleSoft (specific versions not disclosed in alert). Remote code execution vulnerability affecting internet-facing PeopleSoft instances.
criticalbug_reportVulnerabilityLangGraph AI framework patched for critical RCE via SQL injection chain
LangGraph (LangChain's open-source AI agent framework). Specific vulnerable versions not disclosed; patches available. Affects deployments using LangGraph for AI agent orchestration.
criticalbug_reportVulnerabilityCISA orders federal agencies to patch exploited Ivanti Sentry flaw
Ivanti Sentry (specific versions not disclosed in summary). U.S. federal agencies under BOD 26-04 mandate, but all Ivanti Sentry deployments at risk given active exploitation.
criticalbug_reportVulnerabilityOracle PeopleSoft zero-day CVE-2026-35273 exploited by ShinyHunters
Oracle PeopleSoft (all versions prior to June 10 patch). Confirmed exploitation targeting enterprise systems and universities. Vulnerability was unpatched during active exploitation window (May 27 - June 9).
criticalbug_reportVulnerabilityOracle PeopleSoft zero-day CVE-2026-35273 exploited for RCE by ShinyHunter
Oracle PeopleSoft Suite, all versions (specific affected versions not disclosed). Unauthenticated remote code execution vulnerability affecting internet-facing PeopleSoft instances.
criticalbug_reportVulnerabilityCritical command injection flaw in Fortinet FortiSandbox requires patching
Fortinet FortiSandbox (specific versions not disclosed in available data). Command injection vulnerability allows unauthorized command execution.
criticalbug_reportVulnerabilityIvanti Sentry RCE flaw under active exploitation, root access possible
Ivanti Sentry (formerly MobileIron Sentry) - Internet-exposed secure mobile gateways. Specific vulnerable versions not provided in summary, but patch recently released.
criticalbug_reportVulnerabilityCritical RCE in Veeam Backup & Replication requires immediate patching
Veeam Backup & Replication (specific versions not disclosed in summary). Remote code execution vulnerability allows attackers to execute arbitrary code on affected systems.
criticalbug_reportVulnerabilityMicrosoft June 2025 Patch Tuesday: 206 vulnerabilities, 33 critical
Microsoft products across the ecosystem. 206 total vulnerabilities: 33 critical, 173 important severity. Specific affected products and CVE identifiers not yet detailed in available information.
criticalbug_reportVulnerabilityIvanti Sentry critical RCE and auth bypass require immediate patching
Ivanti Sentry (specific versions not disclosed in summary). Vulnerabilities enable root-level remote code execution and authentication bypass. CVE identifiers not yet assigned or published.
criticalbug_reportVulnerabilityFortinet FortiSandbox command injection flaw enables remote code execution
Fortinet FortiSandbox products affected by CVE-2026-25089 (CVSS 9.1). Specific vulnerable versions not disclosed in provided data. Ivanti and SAP also released patches for separate critical vulnerabilities.
criticalbug_reportVulnerabilityLangflow path traversal flaw (CVE-2026-5027) exploited for RCE
Langflow open-source low-code AI platform, all unpatched versions. Vulnerability allows unauthenticated path traversal leading to arbitrary file write and remote code execution.
criticalbug_reportVulnerabilityIvanti Sentry critical RCE flaws allow unauthenticated remote attacks
Ivanti Sentry products (specific versions not provided). Two critical vulnerabilities enable unauthenticated remote code execution on exposed devices.
criticalbug_reportVulnerabilityMicrosoft patches 3 zero-days: YellowKey, GreenPlasma, MiniPlasma
All fully patched Windows systems prior to latest patch release. YellowKey and GreenPlasma enable SYSTEM privilege escalation; MiniPlasma bypasses BitLocker encryption on protected drives.
criticalbug_reportVulnerabilityMicrosoft patches 206 vulnerabilities including 3 zero-days, 39 critical
Microsoft software portfolio: 206 vulnerabilities patched including 56 remote code execution (RCE) flaws, 63 privilege escalation issues, 39 critical-severity vulnerabilities, and 3 actively exploited zero-day flaws.
criticalbug_reportVulnerabilityWindows Server domain controllers under active RCE attack
Windows Server domain controllers (all supported versions). Specific version details not yet published by Microsoft. Unauthenticated remote code execution vulnerability.
criticalbug_reportVulnerabilityIvanti Sentry critical RCE allows unauthenticated root code execution
Ivanti Sentry secure mobile gateway solution. Specific affected versions not disclosed. Two critical vulnerabilities patched, including one maximum-severity (likely CVSS 10.0) remote code execution flaw enabling unauthenticated attackers to execute a…
criticalbug_reportVulnerabilityMicrosoft Defender zero-day "RoguePlanet" exploited for SYSTEM access
Microsoft Defender on all updated Windows systems. No CVE assigned yet. Vulnerability is a race condition enabling local privilege escalation to SYSTEM.
criticalbug_reportVulnerabilityMicrosoft Defender zero-day 'RoguePlanet' enables SYSTEM privilege escalation
Microsoft Defender on Windows systems. Specific affected versions not disclosed. Given Defender's deployment, scope includes enterprise endpoints, servers running Defender, and consumer Windows installations with default security configuration.