Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
25 / 85 results
criticalbug_reportVulnerabilityPgBouncer integer overflow under active exploitation, patch immediately
PgBouncer (PostgreSQL connection pooler) - specific affected versions not disclosed by CERT.BE. All unpatched instances should be considered at risk.
highperson_alertThreat ActorWebworm Deploys EchoCreep and GraphWorm Backdoors via Discord and Graph API
Webworm is a China-aligned advanced persistent threat (APT) actor first documented by Symantec in September 2022, with activity traced back to at least 2022.
highbug_reportVulnerabilityPostgreSQL patches multiple high-severity flaws; version 14 EOL announced
PostgreSQL database server, multiple versions affected by security vulnerabilities. Version 14 reaching end-of-life, no longer receiving security updates after EOL date.
criticalbug_reportVulnerabilityCritical Portainer vulnerabilities enable full host takeover
Portainer container management platform. Specific affected versions not disclosed in summary; CERT.BE advisory should be consulted for version details. Impacts organizations using Portainer for Docker/Kubernetes management.
criticalbug_reportVulnerabilityCritical nginx vulnerabilities enable RCE and rate-limit bypass
nginx web server (specific versions not provided by CERT.BE advisory). Affects organizations running vulnerable nginx instances, particularly those exposed to the internet or untrusted networks.
highbug_reportVulnerabilityABB CoreSense path traversal flaw allows unauthenticated system access
ABB CoreSense HM (versions prior to v2.3.4) and CoreSense M10 (versions prior to v1.4.1.31). Path traversal vulnerability affects unauthenticated remote attackers.
criticalbug_reportVulnerabilityScadaBR 1.2.0 critical flaws enable unauthenticated remote code execution
ScadaBR version 1.2.0, a SCADA system used in critical infrastructure sectors including energy, water, and manufacturing worldwide. All four CVEs affect the same version.
criticalbug_reportVulnerabilityZKTeco CCTV cameras expose credentials via unauthenticated config port
ZKTeco CCTV cameras, specifically model SSC335-GC2063-Face-0b77, running firmware versions prior to V5.0.1.2.20260421. Vulnerability affects an undocumented configuration export port that allows unauthenticated access to camera credentials and config…
highbug_reportVulnerabilityBuffer overflow in PAN-OS User-ID portal enables unauthenticated RCE
Palo Alto Networks PAN-OS on PA-Series and VM-Series firewalls; Siemens RUGGEDCOM APE1808 devices. Specific affected PAN-OS versions not provided in summary.
criticalbug_reportVulnerabilityMicrosoft Exchange Server XSS flaw actively exploited for session hijacking
Microsoft Exchange Server (specific versions not disclosed). Cross-Site Scripting vulnerability enabling spoofing and session hijacking. No CVE assigned yet.
criticalbug_reportVulnerabilityCritical PAN-OS vulnerabilities enable auth bypass and code execution
Palo Alto Networks PAN-OS (specific versions not provided in summary). Affects authentication controls, code execution surface, and availability.
criticalbug_reportVulnerabilityCisco Catalyst SD-WAN auth bypass grants admin access to attackers
Cisco Catalyst SD-WAN platform. Specific affected versions not disclosed. Vulnerability allows authentication bypass leading to administrative access on SD-WAN infrastructure components.
highbug_reportVulnerabilityIvanti releases security updates for multiple products
Multiple Ivanti products affected. Specific product names, versions, and CVE identifiers not disclosed in available information. High severity rating indicates significant security risk.
criticalbug_reportVulnerabilityMultiple critical vulnerabilities in Fortinet products require patching
Fortinet products: FortiSandbox, FortiOS, FortiAP, FortiAnalyzer, and FortiManager. Specific affected versions not provided in advisory. Multiple vulnerabilities ranging from critical to medium severity.
highbug_reportVulnerabilityCode Runner MCP Server missing authentication flaw allows unauthorized access
Code Runner MCP Server (all versions not specified). The vulnerability affects critical functions within the server, allowing unauthenticated access to protected operations. Specific version ranges have not been disclosed by CERT.PL.
highbug_reportVulnerability3onedata GW1101 Modbus gateway vulnerable to OS command injection
3onedata GW1101-1D(RS-485)-TB-P Modbus gateways. Specific affected firmware versions not disclosed. These are industrial IoT devices used for Modbus protocol conversion in OT/ICS environments.
highperson_alertThreat ActorNCSC UK Issues Guidance on China-Nexus Covert Device Networks
China-nexus threat actors are state-sponsored groups linked to the People's Republic of China. These actors are motivated by strategic intelligence collection, espionage, and maintaining persistent access to foreign networks.
highperson_alertThreat ActorNCSC UK Issues Advisory on China-Linked Covert Network Tactics
China-linked threat actors employing covert network tactics to conceal malicious cyber activity. These actors are characterized by their use of sophisticated techniques to maintain persistent, stealthy access to compromised networks.
highpublicGeopoliticalUK NCSC Issues Guidance on China-Linked Covert Device Networks
The UK National Cyber Security Centre's release of defensive guidance targeting China-nexus covert networks reflects ongoing strategic competition between Western democracies and Beijing in cyberspace.
highbug_reportVulnerabilityOrca heat pumps lack authentication, transmit cleartext data to servers
Orca heat pumps (specific models and versions not disclosed). Vulnerability affects device-to-server communication and server-side data processing.
highbug_reportVulnerabilityMikroTik RouterOS auth bypass via certificate validation flaw
MikroTik RouterOS - versions not specified. Affects OpenVPN, CAPsMAN (wireless management), and 802.1X (Dot1x) services that rely on certificate-based authentication.
highpublicGeopoliticalLatvia faces elevated cyber threats amid geopolitical tensions in Q4 2025
Latvia's position as a NATO and EU member state on the eastern flank of the Alliance places it at the intersection of Western institutional security architecture and persistent regional tensions.
highbug_reportVulnerabilityFortinet FortiCloud SSO bypass exploited to extract LDAP passwords
Fortinet FortiGate appliances with FortiCloud SSO enabled. CVE-2025-59718 and CVE-2025-59719 allow authentication bypass. All FortiGate instances share a default static encryption key that enables decryption of LDAP credentials and private keys from…
criticalbug_reportVulnerabilityFortinet FortiCloud SSO auth bypass under active exploitation
Fortinet FortiCloud SSO SAML authentication processing (CVE-2025-59718, CVE-2025-59719). Affects management interfaces of FortiGate and potentially other Fortinet products using FortiCloud SSO.
highperson_alertThreat ActorRansomware Campaigns Target Slovenia via Email, RDP, and Exploits
Unattributed ransomware operators targeting Slovenia. Motivation appears financially driven, consistent with commodity ransomware campaigns. No specific actor attribution available; likely represents multiple threat groups employing common ransomware…