Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 326 results
highperson_alertThreat ActorLaundry Bear exploits Zimbra XSS zero-day for email theft
Laundry Bear (also tracked as Void Blizzard by Microsoft) is a Russian state-sponsored APT group first publicly attributed by Dutch intelligence agencies in May 2025 following their 2024 compromise of the Dutch National Police.
highbug_reportVulnerabilityUAC-0099 abuses Notepad++ plugin loading to deploy LunchPoke malware
Organizations in Ukraine using Notepad++ 8.8.3. The attack does not exploit a vulnerability in Notepad++; it abuses legitimate plugin-loading functionality to deploy LunchPoke, BurnyBear, and MatchBoil V2 malware loaders via social engineering (malic…
criticalbug_reportVulnerabilityProgress Telerik UI for AJAX RCE vulnerability requires immediate patching
Progress Telerik UI for AJAX - specific affected versions not disclosed in available information. Vulnerability enables remote code execution.
highpublicGeopoliticalMicrosoft 365 outage disrupts cloud services across North America
The incident represents a technical service disruption affecting critical cloud infrastructure rather than a geopolitical cyber event. Microsoft 365's position as backbone infrastructure for government, defense, and commercial operations in North Ame…
criticalbug_reportVulnerabilityCheck Point privilege escalation flaws under active exploitation
Check Point products (specific versions not disclosed in available data). Three privilege escalation vulnerabilities identified, including one actively exploited flaw enabling full admin authentication bypass.
highperson_alertThreat ActorRussian cyberespionage campaign targets Zimbra via JavaScript injection
This campaign is attributed by Unit 42 to Russian cyberespionage interests. The actor's motivation centers on intelligence gathering through compromise of email infrastructure.
highperson_alertThreat ActorJadeProx Deploys TriBack Loader Against Asian, Latin American Targets
JadeProx is a China-nexus threat actor tracked by Group-IB, discovered through an exposed Alibaba Cloud server in Singapore in mid-April 2026. The actor targets government, healthcare, and education organizations across Asia and Latin America.
highperson_alertThreat ActorLaundry Bear: Russian APT deploys zero-click phishing via Zimbra exploit
Laundry Bear is an advanced persistent threat (APT) group attributed to Russian state support, specializing in covert email data acquisition. The group conducts espionage operations targeting Western organizations and NATO members.
highbug_reportVulnerabilityFortiBleed campaign targets Fortinet globally; Finland unaffected
Fortinet products (specific models and versions not disclosed). Campaign active globally as of June 2026, Finland not impacted to date.
criticalbug_reportVulnerabilityCheck Point SmartConsole auth bypass zero-day exploited in the wild
Check Point SmartConsole (GUI admin panel for Security Management Server and Multi-Domain Security Management Server). CVE-2026-16232. Vulnerable configurations: Management Server IP exposed to Internet without Trusted Client IP restrictions.
highpublicGeopoliticalSouth Korea discloses 10-month breach of diplomatic training platform
The compromise of South Korea's National Diplomatic Academy represents a significant intelligence collection operation targeting a key U.S. ally in Northeast Asia.
highperson_alertThreat ActorEverest Gang Demands $12.3M from Stadler Rail After Supplier Breach
Everest is a ransomware operation that emerged in 2020, initially deploying file encryption but later pivoted to pure data theft extortion tactics. The group threatens to leak stolen data unless ransom demands are met.
criticalbug_reportVulnerabilityWordPress Core RCE flaws CVE-2026-63030, CVE-2026-60137 under active exploit
WordPress Core (specific versions not disclosed in advisory). Two remote code execution vulnerabilities (CVE-2026-63030, CVE-2026-60137) affecting the core platform.
criticalbug_reportVulnerabilityCISA orders urgent patching of exploited Langflow RCE (CVE-2026-0770)
Langflow visual framework for building AI agents. All unpatched versions vulnerable. Affects unauthenticated remote attackers who can reach the /api/v1/validate/code endpoint. Federal agencies must patch by July 25, 2026.
criticalbug_reportVulnerabilityMicrosoft SharePoint RCE flaws actively exploited; immediate patching required
Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. Five critical vulnerabilities: CVE-2026-50522 (CVSS 9.8, deserialization RCE), CVE-2026-58644 (CVSS 9.8, unauthenticated RCE), CVE-2026-5…
highperson_alertThreat ActorKratos Phishing Kit Dismantled After Stealing Microsoft 365 Sessions
The Kratos operator is an Indonesian individual arrested by local authorities for allegedly developing and operating the Kratos phishing-as-a-service (PhaaS) platform.
highperson_alertThreat ActorKratos PhaaS Platform Dismantled in Joint Law Enforcement Operation
Kratos is a phishing-as-a-service (PhaaS) platform operator that provided cybercriminal infrastructure enabling third-party threat actors to conduct phishing campaigns at scale.
highperson_alertThreat ActorAnubis Ransomware Gang Targets Coca-Cola's Fairlife Subsidiary
Anubis is a ransomware threat actor employing double extortion tactics, claiming responsibility for attacks against the food and beverage sector. The group operates by encrypting victim systems and exfiltrating sensitive corporate data, threatening p…
highbug_reportVulnerabilityAI-assisted phishing toolkit targets Windows users in Mexico via fake gov site
Windows users in Mexico targeted via fake government ID-lookup website. Delivery mechanism uses WebDAV to distribute infostealer malware. Toolkit contains 1,048 files including phishing templates, droppers, and builder documentation.
highperson_alertThreat ActorRussian Intelligence Services Exploit Security Cameras for Military Surveillance
Russian intelligence services are conducting a systematic cyber-espionage campaign targeting internet-connected security cameras across Europe and Ukraine.
highperson_alertThreat Actorbandcampro leverages Google Gemini CLI to control dental clinic botnet
bandcampro is a Russian-speaking threat actor that has demonstrated novel tradecraft by weaponizing Google's Gemini CLI tool to orchestrate botnet operations.
highbug_reportVulnerabilityViPNet update mechanism compromised to target Russian government agencies
ViPNet private networking software users, primarily Russian government agencies and organizations. All versions using the compromised update delivery mechanism are potentially affected. Specific version range not disclosed.
highperson_alertThreat ActorUAC-0145 (Sandworm sub-cluster) deploys ClickFix lures vs Ukraine
UAC-0145 is a sub-cluster of Sandworm, a Russian state-sponsored APT group attributed to the GRU (Main Intelligence Directorate of the General Staff of the Armed Forces of the Russian Federation).
criticalbug_reportVulnerabilityDigiCert breach linked to Chinese APT; code-signing certs stolen
DigiCert certificate authority infrastructure compromised in April 2026. Code-signing certificates stolen by CylindricalCanine (GoldenEyeDog/APT-Q-27 subgroup).
criticalbug_reportVulnerabilityFortinet FortiSandbox critical RCE and privilege escalation flaw
Fortinet FortiSandbox - specific affected versions not disclosed in available advisory. Product used for malware analysis and threat detection in enterprise environments.
highbug_reportVulnerabilitySpring Authorization Server authentication bypass requires immediate patch
Spring Authorization Server (part of Spring Security framework by VMware/Pivotal). Specific affected versions not disclosed in available information. Authentication mechanism is impacted.
highperson_alertThreat ActorLazarus Deploys OtterCookie via Fake Job Lures in Contagious Interview
Lazarus is a North Korean state-sponsored advanced persistent threat (APT) group attributed to the Reconnaissance General Bureau (RGB). The group is financially motivated, conducting operations to generate revenue for the DPRK regime through cryptocu…
highperson_alertThreat ActorArmenia Detains Russian National on U.S. REvil Ransomware Warrant
REvil (also known as Sodinokibi) is a Russia-linked ransomware-as-a-service (RaaS) operation that emerged in 2019 and became one of the most prolific cybercrime groups before law enforcement disruption in 2021-2022.
highperson_alertThreat ActorGoSerpent Malware Targets Southeast Asian Government and Diplomacy
GoSerpent is a previously undocumented malware family discovered by Kaspersky researchers in late 2025. The malware is designed for long-term persistent access and intelligence gathering operations.
criticalbug_reportVulnerabilityCISA orders patching of actively exploited Fortinet FortiSandbox flaws
Fortinet FortiSandbox threat detection platform. Specific versions not provided in available data. Two vulnerabilities confirmed, CVE identifiers not yet disclosed.