Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 326 results
Active filter:tag: #geopolitical✕ clear
Laundry Bear exploits Zimbra XSS zero-day for email thefthighperson_alertThreat Actor
person_alertThreat Actor

Laundry Bear exploits Zimbra XSS zero-day for email theft

Laundry Bear (also tracked as Void Blizzard by Microsoft) is a Russian state-sponsored APT group first publicly attributed by Dutch intelligence agencies in May 2025 following their 2024 compromise of the Dutch National Police.

Zimbra23 Jul · 14:49 UTC
UAC-0099 abuses Notepad++ plugin loading to deploy LunchPoke malwarehighbug_reportVulnerability
bug_reportVulnerability

UAC-0099 abuses Notepad++ plugin loading to deploy LunchPoke malware

Organizations in Ukraine using Notepad++ 8.8.3. The attack does not exploit a vulnerability in Notepad++; it abuses legitimate plugin-loading functionality to deploy LunchPoke, BurnyBear, and MatchBoil V2 malware loaders via social engineering (malic…

Notepad++23 Jul · 14:32 UTC
Progress Telerik UI for AJAX RCE vulnerability requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Progress Telerik UI for AJAX RCE vulnerability requires immediate patching

Progress Telerik UI for AJAX - specific affected versions not disclosed in available information. Vulnerability enables remote code execution.

Progress23 Jul · 13:51 UTC
Microsoft 365 outage disrupts cloud services across North AmericahighpublicGeopolitical
publicGeopolitical

Microsoft 365 outage disrupts cloud services across North America

The incident represents a technical service disruption affecting critical cloud infrastructure rather than a geopolitical cyber event. Microsoft 365's position as backbone infrastructure for government, defense, and commercial operations in North Ame…

Microsoft23 Jul · 13:34 UTC
Check Point privilege escalation flaws under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Check Point privilege escalation flaws under active exploitation

Check Point products (specific versions not disclosed in available data). Three privilege escalation vulnerabilities identified, including one actively exploited flaw enabling full admin authentication bypass.

Check Point23 Jul · 13:19 UTC
Russian cyberespionage campaign targets Zimbra via JavaScript injectionhighperson_alertThreat Actor
person_alertThreat Actor

Russian cyberespionage campaign targets Zimbra via JavaScript injection

This campaign is attributed by Unit 42 to Russian cyberespionage interests. The actor's motivation centers on intelligence gathering through compromise of email infrastructure.

Zimbra23 Jul · 12:10 UTC
JadeProx Deploys TriBack Loader Against Asian, Latin American Targetshighperson_alertThreat Actor
person_alertThreat Actor

JadeProx Deploys TriBack Loader Against Asian, Latin American Targets

JadeProx is a China-nexus threat actor tracked by Group-IB, discovered through an exposed Alibaba Cloud server in Singapore in mid-April 2026. The actor targets government, healthcare, and education organizations across Asia and Latin America.

Alibaba Cloud23 Jul · 10:20 UTC
Laundry Bear: Russian APT deploys zero-click phishing via Zimbra exploithighperson_alertThreat Actor
person_alertThreat Actor

Laundry Bear: Russian APT deploys zero-click phishing via Zimbra exploit

Laundry Bear is an advanced persistent threat (APT) group attributed to Russian state support, specializing in covert email data acquisition. The group conducts espionage operations targeting Western organizations and NATO members.

NCSC UK23 Jul · 10:00 UTC
FortiBleed campaign targets Fortinet globally; Finland unaffectedhighbug_reportVulnerability
bug_reportVulnerability

FortiBleed campaign targets Fortinet globally; Finland unaffected

Fortinet products (specific models and versions not disclosed). Campaign active globally as of June 2026, Finland not impacted to date.

Fortinet23 Jul · 06:15 UTC
Check Point SmartConsole auth bypass zero-day exploited in the wildcriticalbug_reportVulnerability
bug_reportVulnerability

Check Point SmartConsole auth bypass zero-day exploited in the wild

Check Point SmartConsole (GUI admin panel for Security Management Server and Multi-Domain Security Management Server). CVE-2026-16232. Vulnerable configurations: Management Server IP exposed to Internet without Trusted Client IP restrictions.

Check Point Software23 Jul · 06:13 UTC
South Korea discloses 10-month breach of diplomatic training platformhighpublicGeopolitical
publicGeopolitical

South Korea discloses 10-month breach of diplomatic training platform

The compromise of South Korea's National Diplomatic Academy represents a significant intelligence collection operation targeting a key U.S. ally in Northeast Asia.

BleepingComputer22 Jul · 18:06 UTC
Everest Gang Demands $12.3M from Stadler Rail After Supplier Breachhighperson_alertThreat Actor
person_alertThreat Actor

Everest Gang Demands $12.3M from Stadler Rail After Supplier Breach

Everest is a ransomware operation that emerged in 2020, initially deploying file encryption but later pivoted to pure data theft extortion tactics. The group threatens to leak stolen data unless ransom demands are met.

Stadler Rail22 Jul · 14:59 UTC
WordPress Core RCE flaws CVE-2026-63030, CVE-2026-60137 under active exploitcriticalbug_reportVulnerability
bug_reportVulnerability

WordPress Core RCE flaws CVE-2026-63030, CVE-2026-60137 under active exploit

WordPress Core (specific versions not disclosed in advisory). Two remote code execution vulnerabilities (CVE-2026-63030, CVE-2026-60137) affecting the core platform.

CVE-2026-6013722 Jul · 14:09 UTC
CISA orders urgent patching of exploited Langflow RCE (CVE-2026-0770)criticalbug_reportVulnerability
bug_reportVulnerability

CISA orders urgent patching of exploited Langflow RCE (CVE-2026-0770)

Langflow visual framework for building AI agents. All unpatched versions vulnerable. Affects unauthenticated remote attackers who can reach the /api/v1/validate/code endpoint. Federal agencies must patch by July 25, 2026.

Langflow22 Jul · 09:43 UTC
Microsoft SharePoint RCE flaws actively exploited; immediate patching requiredcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft SharePoint RCE flaws actively exploited; immediate patching required

Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. Five critical vulnerabilities: CVE-2026-50522 (CVSS 9.8, deserialization RCE), CVE-2026-58644 (CVSS 9.8, unauthenticated RCE), CVE-2026-5…

Microsoft22 Jul · 08:39 UTC
Kratos Phishing Kit Dismantled After Stealing Microsoft 365 Sessionshighperson_alertThreat Actor
person_alertThreat Actor

Kratos Phishing Kit Dismantled After Stealing Microsoft 365 Sessions

The Kratos operator is an Indonesian individual arrested by local authorities for allegedly developing and operating the Kratos phishing-as-a-service (PhaaS) platform.

Microsoft22 Jul · 04:38 UTC
Kratos PhaaS Platform Dismantled in Joint Law Enforcement Operationhighperson_alertThreat Actor
person_alertThreat Actor

Kratos PhaaS Platform Dismantled in Joint Law Enforcement Operation

Kratos is a phishing-as-a-service (PhaaS) platform operator that provided cybercriminal infrastructure enabling third-party threat actors to conduct phishing campaigns at scale.

BleepingComputer21 Jul · 21:07 UTC
Anubis Ransomware Gang Targets Coca-Cola's Fairlife Subsidiaryhighperson_alertThreat Actor
person_alertThreat Actor

Anubis Ransomware Gang Targets Coca-Cola's Fairlife Subsidiary

Anubis is a ransomware threat actor employing double extortion tactics, claiming responsibility for attacks against the food and beverage sector. The group operates by encrypting victim systems and exfiltrating sensitive corporate data, threatening p…

Coca-Cola21 Jul · 16:50 UTC
AI-assisted phishing toolkit targets Windows users in Mexico via fake gov sitehighbug_reportVulnerability
bug_reportVulnerability

AI-assisted phishing toolkit targets Windows users in Mexico via fake gov site

Windows users in Mexico targeted via fake government ID-lookup website. Delivery mechanism uses WebDAV to distribute infostealer malware. Toolkit contains 1,048 files including phishing templates, droppers, and builder documentation.

Microsoft20 Jul · 15:29 UTC
Russian Intelligence Services Exploit Security Cameras for Military Surveillancehighperson_alertThreat Actor
person_alertThreat Actor

Russian Intelligence Services Exploit Security Cameras for Military Surveillance

Russian intelligence services are conducting a systematic cyber-espionage campaign targeting internet-connected security cameras across Europe and Ukraine.

The Hacker News20 Jul · 10:13 UTC
bandcampro leverages Google Gemini CLI to control dental clinic botnethighperson_alertThreat Actor
person_alertThreat Actor

bandcampro leverages Google Gemini CLI to control dental clinic botnet

bandcampro is a Russian-speaking threat actor that has demonstrated novel tradecraft by weaponizing Google's Gemini CLI tool to orchestrate botnet operations.

The Hacker News20 Jul · 07:07 UTC
ViPNet update mechanism compromised to target Russian government agencieshighbug_reportVulnerability
bug_reportVulnerability

ViPNet update mechanism compromised to target Russian government agencies

ViPNet private networking software users, primarily Russian government agencies and organizations. All versions using the compromised update delivery mechanism are potentially affected. Specific version range not disclosed.

ViPNet19 Jul · 12:23 UTC
UAC-0145 (Sandworm sub-cluster) deploys ClickFix lures vs Ukrainehighperson_alertThreat Actor
person_alertThreat Actor

UAC-0145 (Sandworm sub-cluster) deploys ClickFix lures vs Ukraine

UAC-0145 is a sub-cluster of Sandworm, a Russian state-sponsored APT group attributed to the GRU (Main Intelligence Directorate of the General Staff of the Armed Forces of the Russian Federation).

The Hacker News19 Jul · 11:30 UTC
DigiCert breach linked to Chinese APT; code-signing certs stolencriticalbug_reportVulnerability
bug_reportVulnerability

DigiCert breach linked to Chinese APT; code-signing certs stolen

DigiCert certificate authority infrastructure compromised in April 2026. Code-signing certificates stolen by CylindricalCanine (GoldenEyeDog/APT-Q-27 subgroup).

DigiCert17 Jul · 14:39 UTC
Fortinet FortiSandbox critical RCE and privilege escalation flawcriticalbug_reportVulnerability
bug_reportVulnerability

Fortinet FortiSandbox critical RCE and privilege escalation flaw

Fortinet FortiSandbox - specific affected versions not disclosed in available advisory. Product used for malware analysis and threat detection in enterprise environments.

Fortinet17 Jul · 13:35 UTC
Spring Authorization Server authentication bypass requires immediate patchhighbug_reportVulnerability
bug_reportVulnerability

Spring Authorization Server authentication bypass requires immediate patch

Spring Authorization Server (part of Spring Security framework by VMware/Pivotal). Specific affected versions not disclosed in available information. Authentication mechanism is impacted.

Spring (Pivotal/VMware)17 Jul · 13:32 UTC
Lazarus Deploys OtterCookie via Fake Job Lures in Contagious Interviewhighperson_alertThreat Actor
person_alertThreat Actor

Lazarus Deploys OtterCookie via Fake Job Lures in Contagious Interview

Lazarus is a North Korean state-sponsored advanced persistent threat (APT) group attributed to the Reconnaissance General Bureau (RGB). The group is financially motivated, conducting operations to generate revenue for the DPRK regime through cryptocu…

The Hacker News17 Jul · 11:48 UTC
Armenia Detains Russian National on U.S. REvil Ransomware Warranthighperson_alertThreat Actor
person_alertThreat Actor

Armenia Detains Russian National on U.S. REvil Ransomware Warrant

REvil (also known as Sodinokibi) is a Russia-linked ransomware-as-a-service (RaaS) operation that emerged in 2019 and became one of the most prolific cybercrime groups before law enforcement disruption in 2021-2022.

The Hacker News17 Jul · 08:53 UTC
GoSerpent Malware Targets Southeast Asian Government and Diplomacyhighperson_alertThreat Actor
person_alertThreat Actor

GoSerpent Malware Targets Southeast Asian Government and Diplomacy

GoSerpent is a previously undocumented malware family discovered by Kaspersky researchers in late 2025. The malware is designed for long-term persistent access and intelligence gathering operations.

Kaspersky17 Jul · 06:46 UTC
CISA orders patching of actively exploited Fortinet FortiSandbox flawscriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders patching of actively exploited Fortinet FortiSandbox flaws

Fortinet FortiSandbox threat detection platform. Specific versions not provided in available data. Two vulnerabilities confirmed, CVE identifiers not yet disclosed.

Fortinet17 Jul · 05:03 UTC