Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 692 results
highbug_reportVulnerabilityZimbra SNMP flaw CVE-2026-73570 under active exploitation for RCE
Zimbra Collaboration Server (ZCS) versions before 10.1.20, only when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Unauthenticated remote attackers can exploit this command injection flaw.
highbug_reportVulnerabilityCitrix urges immediate patching of NetScaler auth bypass and DoS flaws
Citrix NetScaler ADC and NetScaler Gateway appliances (all supported versions prior to 14.1-73.32 and 13.1-63.21). CVE-2026-19490 affects appliances configured as AAA virtual server or Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) with SAML authentic…
highbug_reportVulnerabilityZombie Card attack revives expired Visa contactless cards via NFC relay
Visa contactless credit cards using Kernel 3 specification. Attack requires physical card access or sustained NFC proximity, plus relay device between card and terminal. Five major US banks tested; three confirmed vulnerable with varying policies.
highbug_reportVulnerabilityManic Android malware exfiltrates data via nearby infected devices
Android users in Central and Western Europe (including UK), Russia, and primarily Ukraine. Targets 169 banking, government/eID, payment, crypto wallet, messaging, and 2FA apps. Active since at least February 2026.
highperson_alertThreat ActorRansom Busters: Rogue Affiliate Impersonates Recovery Firm
Ransom Busters is a suspected ransomware affiliate operating across multiple Ransomware-as-a-Service (RaaS) platforms, including DragonForce, Settra, and Anubis.
highpublicGeopoliticalSakura Internet breach exposes 1.36M accounts at Japan Gov Cloud provider
The breach of Sakura Internet carries strategic significance beyond typical commercial cloud incidents due to the company's designation as a domestic provider for Japan's Government Cloud program.
highpublicGeopoliticalCareCloud breach exposes 3.7M patient records in AWS environment
The CareCloud incident reflects the persistent vulnerability of U.S. healthcare infrastructure to cyber intrusions, particularly cloud-hosted environments containing sensitive medical data.
highbug_reportVulnerabilitySpectre attack on Cloudflare Workers leaks JWT at 12 bits/sec
Cloudflare Workers running on AMD EPYC Zen 2 and Zen 3 processors (Linux). Attack targets V8 isolates within shared Worker processes. Affects multi-tenant serverless environments relying on language-level isolation.
highbug_reportVulnerability14,500 Dahua IP cameras compromised via brute-force and known CVEs
Dahua IP cameras globally, with concentration in Ukraine and Russia. Devices vulnerable to CVE-2021-33044 and CVE-2021-33045, those exposed on TCP port 37777, and cloud-registered cameras accessible via serial number recovery codes.
highperson_alertThreat ActorAI-Generated Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure
No specific threat actor or group has been attributed to this campaign. The advisory describes ongoing activity by unidentified threat actors targeting Siemens S7 Series programmable logic controllers in U.S. critical infrastructure.
highperson_alertThreat ActorU.S. charges 17 Mabna Institute members for $3.4B IP theft campaign
Mabna Institute is an Iranian hacking-for-hire organization linked to cyber operations conducted on behalf of Iran's Islamic Revolutionary Guard Corps (IRGC), other Iranian government bodies, universities, and private paying customers.
highperson_alertThreat Actor155x surge in password spraying exploits MFA gaps and legacy OAuth flows
The threat actor behind the LSHIY campaign remains unattributed. Motivation appears financially driven, likely focused on credential validation for resale on dark web markets rather than immediate post-compromise exploitation.
highperson_alertThreat ActorSilkParasite Targets Central Asian Governments with Five New RATs
SilkParasite is a previously unreported cyber espionage operation first discovered in late 2025, assessed with medium confidence to be a China-nexus threat cluster.
highbug_reportVulnerabilityCERT.BE warns of critical Oracle vulnerabilities requiring urgent patching
Multiple Oracle products affected. Specific product names, versions, and CVE identifiers not provided in advisory. Scope appears broad across Oracle product portfolio based on CERT.BE warning classification.
highperson_alertThreat ActorOperation CameraSwarm compromises 14,530+ Dahua IoT devices
Operation CameraSwarm is a campaign disclosed by Hunt.io that compromised over 14,530 Dahua surveillance devices between June 17 and July 22, 2026. The campaign was reconstructed from a 407 MB exposed working directory containing 2,616 files across 2…
highperson_alertThreat ActorStopAndProtect Exploits 2,000 Hacked WordPress Sites for Malware Delivery
StopAndProtect is a global cybercrime operation tracked by Check Point Research since mid-May 2026. The operation is named after a ransomware family discovered during initial investigation.
highbug_reportVulnerabilityMacSync Stealer campaign uses 30+ rotating domains to target macOS users
macOS systems, all versions. Primary targets: users with AWS credentials, SSH keys, Kubernetes configs, browser credentials, and Keychain data. Organizations with macOS endpoints in development, DevOps, and cloud administration roles face elevated ri…
highbug_reportVulnerabilityMicrosoft Copilot Personal flaws enable one-click data exfiltration via URL
Microsoft Copilot Personal (consumer assistant at copilot.microsoft.com). Research does not indicate Microsoft 365 Copilot is affected. Vulnerability tracked as CVE-2026-24301. Patched August 18, 2026.
highperson_alertThreat ActorClop Gang Deploys Custom Java Web Shell for Windchill Data Theft
Clop is a financially motivated ransomware and extortion gang known for mass-exploitation campaigns targeting enterprise file-sharing and collaboration platforms.
highbug_reportVulnerabilityMacSync Stealer targets macOS via ClickFix, rotates 30+ domains
macOS devices. No specific version restrictions identified. Targets Keychain, browser data, credentials, SSH keys, and sensitive user files. Delivered via ClickFix social engineering (malicious Terminal commands).
highperson_alertThreat ActorTWINLOOT Implant Abuses Microsoft 365 Services for C2 and Lateral Movement
No specific threat actor has been attributed to TWINLOOT operations. The malware was discovered by Ontinue's Cyber Defense Center during investigation of an ongoing campaign in July 2026.
highperson_alertThreat ActorCity Forum campaign scrapes Salesforce and ServiceNow portals
City Forum is a campaign name assigned by Reco to a coordinated data harvesting operation targeting enterprise SaaS platforms. The activity is attributed to a single attacker infrastructure operating from IP address 158.220.87.79, hosted on a Contabo…
highperson_alertThreat ActorStubMaker Campaign Deploys 16 Typosquatted RubyGems to Steal Credentials
StubMaker is a typosquatting campaign tracked by OpenSourceMalware researchers, discovered on August 15, 2026. The campaign operators published 16 malicious RubyGems packages under user accounts "mod8rz41mje" (Riley Miller) and "rbq95bwt6q" (Alex Dav…
highperson_alertThreat ActorCVE-2025-60710: Windows Task Host Flaw Exploited by Ransomware Gangs
No specific threat actor or ransomware gang has been publicly attributed to the exploitation of CVE-2025-60710. CISA confirmed that multiple ransomware operators are actively exploiting this vulnerability in the wild as of August 2026.
highpublicGeopoliticalCEVA Logistics breach exposes Pokémon Center customer data in EU
This incident exemplifies the systemic vulnerabilities inherent in globalized supply chain networks, where third-party logistics providers serve as critical nodes connecting consumer-facing platforms with physical distribution infrastructure.
highbug_reportVulnerabilitySnowflake GitHub Actions workflow injection exposed Jira credentials
Snowflake's snowflakedb/snowflake-connector-net GitHub repository, specifically the .github/workflows/jira_issue.yml workflow. Vulnerable code was present on the default branch from June 18–23, 2026 (5-day window).
highperson_alertThreat ActorIranian Cavern C2 Framework Evolves with DNS and Google Apps Script Relay
Cavern (aka Cav3rn) is a command-and-control framework attributed to Iranian nation-state threat actors, specifically linked to Cavern Manticore, a hacking group affiliated with Iran's Ministry of Intelligence and Security (MOIS).
highbug_reportVulnerabilityIvanti EPM high severity flaws require immediate patching
Ivanti Endpoint Manager (EPM). Specific affected versions not disclosed in available advisory. CVE identifiers not yet assigned or published.
highperson_alertThreat ActorClop Ransomware Gang Exploits PTC Windchill Flaw to Breach GE, Philips
Clop is a financially motivated ransomware and extortion gang with a well-established history of exploiting zero-day and n-day vulnerabilities in enterprise file-sharing and product lifecycle management (PLM) platforms to conduct mass data theft camp…
highpublicGeopoliticalFrench tax authority breach exposes 678,000 records amid rising attacks
The breach of France's General Directorate of Public Finances (DGFiP) represents the latest in a sustained pattern of cyberattacks targeting French government infrastructure throughout 2026.