Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 692 results
Active filter:tag: #high✕ clear
Zimbra SNMP flaw CVE-2026-73570 under active exploitation for RCEhighbug_reportVulnerability
bug_reportVulnerability

Zimbra SNMP flaw CVE-2026-73570 under active exploitation for RCE

Zimbra Collaboration Server (ZCS) versions before 10.1.20, only when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Unauthenticated remote attackers can exploit this command injection flaw.

CVE-2026-7357020 Aug · 11:24 UTC
Citrix urges immediate patching of NetScaler auth bypass and DoS flawshighbug_reportVulnerability
bug_reportVulnerability

Citrix urges immediate patching of NetScaler auth bypass and DoS flaws

Citrix NetScaler ADC and NetScaler Gateway appliances (all supported versions prior to 14.1-73.32 and 13.1-63.21). CVE-2026-19490 affects appliances configured as AAA virtual server or Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) with SAML authentic…

Citrix20 Aug · 10:14 UTC
Zombie Card attack revives expired Visa contactless cards via NFC relayhighbug_reportVulnerability
bug_reportVulnerability

Zombie Card attack revives expired Visa contactless cards via NFC relay

Visa contactless credit cards using Kernel 3 specification. Attack requires physical card access or sustained NFC proximity, plus relay device between card and terminal. Five major US banks tested; three confirmed vulnerable with varying policies.

Visa20 Aug · 10:01 UTC
Manic Android malware exfiltrates data via nearby infected deviceshighbug_reportVulnerability
bug_reportVulnerability

Manic Android malware exfiltrates data via nearby infected devices

Android users in Central and Western Europe (including UK), Russia, and primarily Ukraine. Targets 169 banking, government/eID, payment, crypto wallet, messaging, and 2FA apps. Active since at least February 2026.

BleepingComputer20 Aug · 08:02 UTC
Ransom Busters: Rogue Affiliate Impersonates Recovery Firmhighperson_alertThreat Actor
person_alertThreat Actor

Ransom Busters: Rogue Affiliate Impersonates Recovery Firm

Ransom Busters is a suspected ransomware affiliate operating across multiple Ransomware-as-a-Service (RaaS) platforms, including DragonForce, Settra, and Anubis.

BleepingComputer19 Aug · 18:59 UTC
Sakura Internet breach exposes 1.36M accounts at Japan Gov Cloud providerhighpublicGeopolitical
publicGeopolitical

Sakura Internet breach exposes 1.36M accounts at Japan Gov Cloud provider

The breach of Sakura Internet carries strategic significance beyond typical commercial cloud incidents due to the company's designation as a domestic provider for Japan's Government Cloud program.

Sakura Internet19 Aug · 18:53 UTC
CareCloud breach exposes 3.7M patient records in AWS environmenthighpublicGeopolitical
publicGeopolitical

CareCloud breach exposes 3.7M patient records in AWS environment

The CareCloud incident reflects the persistent vulnerability of U.S. healthcare infrastructure to cyber intrusions, particularly cloud-hosted environments containing sensitive medical data.

CareCloud19 Aug · 18:07 UTC
Spectre attack on Cloudflare Workers leaks JWT at 12 bits/sechighbug_reportVulnerability
bug_reportVulnerability

Spectre attack on Cloudflare Workers leaks JWT at 12 bits/sec

Cloudflare Workers running on AMD EPYC Zen 2 and Zen 3 processors (Linux). Attack targets V8 isolates within shared Worker processes. Affects multi-tenant serverless environments relying on language-level isolation.

Cloudflare19 Aug · 17:02 UTC
14,500 Dahua IP cameras compromised via brute-force and known CVEshighbug_reportVulnerability
bug_reportVulnerability

14,500 Dahua IP cameras compromised via brute-force and known CVEs

Dahua IP cameras globally, with concentration in Ukraine and Russia. Devices vulnerable to CVE-2021-33044 and CVE-2021-33045, those exposed on TCP port 37777, and cloud-registered cameras accessible via serial number recovery codes.

Dahua19 Aug · 16:09 UTC
AI-Generated Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

AI-Generated Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure

No specific threat actor or group has been attributed to this campaign. The advisory describes ongoing activity by unidentified threat actors targeting Siemens S7 Series programmable logic controllers in U.S. critical infrastructure.

Siemens19 Aug · 15:50 UTC
U.S. charges 17 Mabna Institute members for $3.4B IP theft campaignhighperson_alertThreat Actor
person_alertThreat Actor

U.S. charges 17 Mabna Institute members for $3.4B IP theft campaign

Mabna Institute is an Iranian hacking-for-hire organization linked to cyber operations conducted on behalf of Iran's Islamic Revolutionary Guard Corps (IRGC), other Iranian government bodies, universities, and private paying customers.

BleepingComputer19 Aug · 13:56 UTC
155x surge in password spraying exploits MFA gaps and legacy OAuth flowshighperson_alertThreat Actor
person_alertThreat Actor

155x surge in password spraying exploits MFA gaps and legacy OAuth flows

The threat actor behind the LSHIY campaign remains unattributed. Motivation appears financially driven, likely focused on credential validation for resale on dark web markets rather than immediate post-compromise exploitation.

BleepingComputer19 Aug · 12:00 UTC
SilkParasite Targets Central Asian Governments with Five New RATshighperson_alertThreat Actor
person_alertThreat Actor

SilkParasite Targets Central Asian Governments with Five New RATs

SilkParasite is a previously unreported cyber espionage operation first discovered in late 2025, assessed with medium confidence to be a China-nexus threat cluster.

The Hacker News19 Aug · 11:12 UTC
CERT.BE warns of critical Oracle vulnerabilities requiring urgent patchinghighbug_reportVulnerability
bug_reportVulnerability

CERT.BE warns of critical Oracle vulnerabilities requiring urgent patching

Multiple Oracle products affected. Specific product names, versions, and CVE identifiers not provided in advisory. Scope appears broad across Oracle product portfolio based on CERT.BE warning classification.

Oracle19 Aug · 11:01 UTC
Operation CameraSwarm compromises 14,530+ Dahua IoT deviceshighperson_alertThreat Actor
person_alertThreat Actor

Operation CameraSwarm compromises 14,530+ Dahua IoT devices

Operation CameraSwarm is a campaign disclosed by Hunt.io that compromised over 14,530 Dahua surveillance devices between June 17 and July 22, 2026. The campaign was reconstructed from a 407 MB exposed working directory containing 2,616 files across 2…

Dahua19 Aug · 09:34 UTC
StopAndProtect Exploits 2,000 Hacked WordPress Sites for Malware Deliveryhighperson_alertThreat Actor
person_alertThreat Actor

StopAndProtect Exploits 2,000 Hacked WordPress Sites for Malware Delivery

StopAndProtect is a global cybercrime operation tracked by Check Point Research since mid-May 2026. The operation is named after a ransomware family discovered during initial investigation.

WordPress19 Aug · 09:25 UTC
MacSync Stealer campaign uses 30+ rotating domains to target macOS usershighbug_reportVulnerability
bug_reportVulnerability

MacSync Stealer campaign uses 30+ rotating domains to target macOS users

macOS systems, all versions. Primary targets: users with AWS credentials, SSH keys, Kubernetes configs, browser credentials, and Keychain data. Organizations with macOS endpoints in development, DevOps, and cloud administration roles face elevated ri…

Microsoft19 Aug · 04:01 UTC
Microsoft Copilot Personal flaws enable one-click data exfiltration via URLhighbug_reportVulnerability
bug_reportVulnerability

Microsoft Copilot Personal flaws enable one-click data exfiltration via URL

Microsoft Copilot Personal (consumer assistant at copilot.microsoft.com). Research does not indicate Microsoft 365 Copilot is affected. Vulnerability tracked as CVE-2026-24301. Patched August 18, 2026.

Microsoft18 Aug · 15:47 UTC
Clop Gang Deploys Custom Java Web Shell for Windchill Data Thefthighperson_alertThreat Actor
person_alertThreat Actor

Clop Gang Deploys Custom Java Web Shell for Windchill Data Theft

Clop is a financially motivated ransomware and extortion gang known for mass-exploitation campaigns targeting enterprise file-sharing and collaboration platforms.

PTC18 Aug · 15:29 UTC
MacSync Stealer targets macOS via ClickFix, rotates 30+ domainshighbug_reportVulnerability
bug_reportVulnerability

MacSync Stealer targets macOS via ClickFix, rotates 30+ domains

macOS devices. No specific version restrictions identified. Targets Keychain, browser data, credentials, SSH keys, and sensitive user files. Delivered via ClickFix social engineering (malicious Terminal commands).

Microsoft18 Aug · 15:08 UTC
TWINLOOT Implant Abuses Microsoft 365 Services for C2 and Lateral Movementhighperson_alertThreat Actor
person_alertThreat Actor

TWINLOOT Implant Abuses Microsoft 365 Services for C2 and Lateral Movement

No specific threat actor has been attributed to TWINLOOT operations. The malware was discovered by Ontinue's Cyber Defense Center during investigation of an ongoing campaign in July 2026.

Microsoft18 Aug · 10:38 UTC
City Forum campaign scrapes Salesforce and ServiceNow portalshighperson_alertThreat Actor
person_alertThreat Actor

City Forum campaign scrapes Salesforce and ServiceNow portals

City Forum is a campaign name assigned by Reco to a coordinated data harvesting operation targeting enterprise SaaS platforms. The activity is attributed to a single attacker infrastructure operating from IP address 158.220.87.79, hosted on a Contabo…

Salesforce18 Aug · 09:30 UTC
StubMaker Campaign Deploys 16 Typosquatted RubyGems to Steal Credentialshighperson_alertThreat Actor
person_alertThreat Actor

StubMaker Campaign Deploys 16 Typosquatted RubyGems to Steal Credentials

StubMaker is a typosquatting campaign tracked by OpenSourceMalware researchers, discovered on August 15, 2026. The campaign operators published 16 malicious RubyGems packages under user accounts "mod8rz41mje" (Riley Miller) and "rbq95bwt6q" (Alex Dav…

RubyGems18 Aug · 09:20 UTC
CVE-2025-60710: Windows Task Host Flaw Exploited by Ransomware Gangshighperson_alertThreat Actor
person_alertThreat Actor

CVE-2025-60710: Windows Task Host Flaw Exploited by Ransomware Gangs

No specific threat actor or ransomware gang has been publicly attributed to the exploitation of CVE-2025-60710. CISA confirmed that multiple ransomware operators are actively exploiting this vulnerability in the wild as of August 2026.

Microsoft18 Aug · 08:32 UTC
CEVA Logistics breach exposes Pokémon Center customer data in EUhighpublicGeopolitical
publicGeopolitical

CEVA Logistics breach exposes Pokémon Center customer data in EU

This incident exemplifies the systemic vulnerabilities inherent in globalized supply chain networks, where third-party logistics providers serve as critical nodes connecting consumer-facing platforms with physical distribution infrastructure.

Pokémon Center17 Aug · 17:12 UTC
Snowflake GitHub Actions workflow injection exposed Jira credentialshighbug_reportVulnerability
bug_reportVulnerability

Snowflake GitHub Actions workflow injection exposed Jira credentials

Snowflake's snowflakedb/snowflake-connector-net GitHub repository, specifically the .github/workflows/jira_issue.yml workflow. Vulnerable code was present on the default branch from June 18–23, 2026 (5-day window).

Snowflake17 Aug · 16:44 UTC
Iranian Cavern C2 Framework Evolves with DNS and Google Apps Script Relayhighperson_alertThreat Actor
person_alertThreat Actor

Iranian Cavern C2 Framework Evolves with DNS and Google Apps Script Relay

Cavern (aka Cav3rn) is a command-and-control framework attributed to Iranian nation-state threat actors, specifically linked to Cavern Manticore, a hacking group affiliated with Iran's Ministry of Intelligence and Security (MOIS).

The Hacker News17 Aug · 15:41 UTC
Ivanti EPM high severity flaws require immediate patchinghighbug_reportVulnerability
bug_reportVulnerability

Ivanti EPM high severity flaws require immediate patching

Ivanti Endpoint Manager (EPM). Specific affected versions not disclosed in available advisory. CVE identifiers not yet assigned or published.

Ivanti17 Aug · 11:57 UTC
Clop Ransomware Gang Exploits PTC Windchill Flaw to Breach GE, Philipshighperson_alertThreat Actor
person_alertThreat Actor

Clop Ransomware Gang Exploits PTC Windchill Flaw to Breach GE, Philips

Clop is a financially motivated ransomware and extortion gang with a well-established history of exploiting zero-day and n-day vulnerabilities in enterprise file-sharing and product lifecycle management (PLM) platforms to conduct mass data theft camp…

General Electric17 Aug · 09:25 UTC
French tax authority breach exposes 678,000 records amid rising attackshighpublicGeopolitical
publicGeopolitical

French tax authority breach exposes 678,000 records amid rising attacks

The breach of France's General Directorate of Public Finances (DGFiP) represents the latest in a sustained pattern of cyberattacks targeting French government infrastructure throughout 2026.

French Ministry of the Economy and Finance17 Aug · 08:09 UTC