Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 154 results
Active filter:tag: #software-development✕ clear
FastJson RCE zero-day (CVE-2026-16723) actively exploited against US firmscriticalbug_reportVulnerability
bug_reportVulnerability

FastJson RCE zero-day (CVE-2026-16723) actively exploited against US firms

FastJson versions 1.2.68 through 1.2.83 in Spring Boot fat-JAR deployments (java -jar xxx.jar). FastJson 1.2.60 and earlier, fastjson2, and non-fat-JAR deployments are NOT affected.

Alibaba27 Jul · 21:49 UTC
Fastjson 1.x RCE under active attack; no patch availablecriticalbug_reportVulnerability
bug_reportVulnerability

Fastjson 1.x RCE under active attack; no patch available

Alibaba Fastjson versions 1.2.68 through 1.2.83 in Spring Boot executable fat-JAR deployments. Requires network-reachable JSON parsing endpoint and default SafeMode disabled. Plain JARs, generic uber-JARs, and WAR deployments are not affected.

CVE-2026-1672325 Jul · 10:52 UTC
NodeBB forum software patches 8 high-severity flaws with public exploitshighbug_reportVulnerability
bug_reportVulnerability

NodeBB forum software patches 8 high-severity flaws with public exploits

NodeBB forum software, all versions before 4.14.0. Fixes available in version 4.14.2 and later. Five of eight flaws affect only forums with ActivityPub federation enabled (default in v4 fresh installs, disabled in v3 upgrades).

NodeBB24 Jul · 05:41 UTC
Redis patches authenticated RCE flaws in versions 6.2–8.8criticalbug_reportVulnerability
bug_reportVulnerability

Redis patches authenticated RCE flaws in versions 6.2–8.8

Redis versions 6.2.22, 7.2.14, 7.4.9, 8.2.7, 8.4.4, 8.6.4, and 8.8.0. Exploitation requires authenticated access and RESTORE command privileges. Streams-based chain also requires EVAL and XGROUP commands; RedisBloom chain (8.8.0) requires EVAL and bu…

Redis24 Jul · 04:58 UTC
GitHub Actions Abused to Scan and Exploit cPanel/WHM Servershighperson_alertThreat Actor
person_alertThreat Actor

GitHub Actions Abused to Scan and Exploit cPanel/WHM Servers

The threat actor behind this campaign remains unattributed. The operation demonstrates sophisticated understanding of GitHub Actions infrastructure and supply chain attack vectors.

GitHub23 Jul · 09:28 UTC
Windmill path traversal flaw exploited to read server files unauthenticatedhighbug_reportVulnerability
bug_reportVulnerability

Windmill path traversal flaw exploited to read server files unauthenticated

Windmill open-source developer platform versions prior to 1.603.3. The vulnerability affects the "get_log_file" endpoint (/api/w/{workspace}/jobs_u/get_log_file/{filename}). Approximately 170 vulnerable systems identified across 24 countries.

CVE-2026-2905922 Jul · 10:36 UTC
Trojanized NuGet package targets Digitain betting platform via typosquattinghighbug_reportVulnerability
bug_reportVulnerability

Trojanized NuGet package targets Digitain betting platform via typosquatting

NuGet package "Newtonsoftt.Json.Net" versions 11.0.4, 11.0.5, 11.0.7, 11.0.8, 11.0.9, 11.0.10, and 11.0.11 (typosquat of Newtonsoft.Json). Primary target: Digitain FG-Crash betting game backend. Downloaded ~1,200 times.

Newtonsoft22 Jul · 04:00 UTC
Azure DevOps MCP server flaw lets hidden PR comments hijack AI agentshighbug_reportVulnerability
bug_reportVulnerability

Azure DevOps MCP server flaw lets hidden PR comments hijack AI agents

Microsoft Azure DevOps MCP server versions up to and including v2.8.0 (released June 24, 2026). The flaw affects the repo_get_pull_request_by_id tool, which returns pull request descriptions without prompt-injection guardrails.

Microsoft22 Jul · 02:57 UTC
FakeGit Campaign Distributes Malware via 7,600 Malicious GitHub Reposhighperson_alertThreat Actor
person_alertThreat Actor

FakeGit Campaign Distributes Malware via 7,600 Malicious GitHub Repos

FakeGit is a threat actor conducting a large-scale supply chain attack campaign targeting the software development community. The actor's motivation centers on mass malware distribution through the compromise of developer trust in the GitHub platform…

GitHub21 Jul · 20:34 UTC
AWS Kiro IDE vulnerability allowed RCE via hidden web text injectionhighbug_reportVulnerability
bug_reportVulnerability

AWS Kiro IDE vulnerability allowed RCE via hidden web text injection

AWS Kiro agentic coding IDE (specific versions not disclosed). Vulnerability has been patched by AWS. Users who installed Kiro before the patch are potentially affected.

AWS21 Jul · 14:06 UTC
Mobile AI agent frameworks vulnerable to instruction injection attackshighbug_reportVulnerability
bug_reportVulnerability

Mobile AI agent frameworks vulnerable to instruction injection attacks

Five open-source mobile AI agent frameworks including AppAgent and AppAgentX. Attack requires malicious Android apps with overlay and storage permissions to inject invisible instructions, leading to command execution on connected host PCs.

AppAgent21 Jul · 09:58 UTC
Sandbox escape flaws in Cursor, Codex, Gemini CLI, Antigravity AI toolshighbug_reportVulnerability
bug_reportVulnerability

Sandbox escape flaws in Cursor, Codex, Gemini CLI, Antigravity AI tools

Multiple AI development tools: Cursor IDE, OpenAI Codex, Google Gemini CLI, and Antigravity. Vulnerability affects AI agent sandbox implementations where agents write files executed by host tools, allowing escape from restricted environments.

Cursor20 Jul · 19:14 UTC
FakeGit Campaign Distributes SmartLoader via 7,600+ Malicious GitHub Reposhighperson_alertThreat Actor
person_alertThreat Actor

FakeGit Campaign Distributes SmartLoader via 7,600+ Malicious GitHub Repos

FakeGit is a campaign (not a named threat actor group) targeting software developers through a large-scale supply chain attack leveraging GitHub's trusted platform.

GitHub20 Jul · 16:23 UTC
7-Zip heap overflow in XZ handling allows code execution via crafted archiveshighbug_reportVulnerability
bug_reportVulnerability

7-Zip heap overflow in XZ handling allows code execution via crafted archives

7-Zip versions prior to 26.02. Affects all platforms where 7-Zip is deployed (Windows, Linux). Vulnerability triggered when opening malicious XZ archives.

CVE-2026-1426620 Jul · 07:10 UTC
Malicious RubyGems packages deliver payloads to developer workstationshighbug_reportVulnerability
bug_reportVulnerability

Malicious RubyGems packages deliver payloads to developer workstations

RubyGems ecosystem: three malicious packages (git_credential_manager, Dendreo, and one unnamed) published to the official RubyGems repository. Affects Ruby developers who installed these packages.

RubyGems20 Jul · 03:15 UTC
Seven malicious npm packages target Vite ecosystem with blockchain C2 RAThighbug_reportVulnerability
bug_reportVulnerability

Seven malicious npm packages target Vite ecosystem with blockchain C2 RAT

npm package ecosystem, specifically projects using Vite frontend tooling. Seven malicious packages identified in the ViteVenom campaign. Any JavaScript/Node.js development environments that installed these packages are compromised.

npm17 Jul · 16:54 UTC
NadMesh Botnet Targets AI Services for AWS and Kubernetes Credential Thefthighperson_alertThreat Actor
person_alertThreat Actor

NadMesh Botnet Targets AI Services for AWS and Kubernetes Credential Theft

NadMesh is a Go-based botnet operation discovered in early July that specializes in compromising cloud infrastructure credentials through exploitation of exposed AI and automation services.

AWS17 Jul · 15:12 UTC
Spring Authorization Server authentication bypass requires immediate patchhighbug_reportVulnerability
bug_reportVulnerability

Spring Authorization Server authentication bypass requires immediate patch

Spring Authorization Server (part of Spring Security framework by VMware/Pivotal). Specific affected versions not disclosed in available information. Authentication mechanism is impacted.

Spring (Pivotal/VMware)17 Jul · 13:32 UTC
Malicious npm and PyPI packages impersonate Paysafe payment SDKshighbug_reportVulnerability
bug_reportVulnerability

Malicious npm and PyPI packages impersonate Paysafe payment SDKs

Developers using npm and PyPI repositories who may have installed counterfeit packages impersonating Paysafe, Skrill, and Neteller payment SDKs. Affects development environments and potentially downstream applications integrating these malicious pack…

Paysafe8 Jul · 17:54 UTC
HalluSquatting attack exploits AI coding assistants to distribute malwarehighbug_reportVulnerability
bug_reportVulnerability

HalluSquatting attack exploits AI coding assistants to distribute malware

AI coding assistants (GitHub Copilot, ChatGPT, Claude, etc.) and developers using AI-generated package recommendations. All package ecosystems (npm, PyPI, Maven, etc.) are potential targets.

AI coding assistants8 Jul · 13:07 UTC
GitHub commit verification flaw allows signature reuse on rewritten commitshighbug_reportVulnerability
bug_reportVulnerability

GitHub commit verification flaw allows signature reuse on rewritten commits

GitHub's commit verification system for GPG/SSH-signed commits. All repositories using signed commits with GitHub's "Verified" badge are potentially affected. The flaw is in GitHub's verification logic, not Git itself.

GitHub8 Jul · 09:51 UTC
GitHub Agentic Workflows leak private repo data via public issueshighbug_reportVulnerability
bug_reportVulnerability

GitHub Agentic Workflows leak private repo data via public issues

GitHub Agentic Workflows with cross-repository read access. Organizations using GitHub agents that can access both public and private repositories are vulnerable. No CVE assigned yet.

GitHub7 Jul · 12:04 UTC
Gitea Docker auth bypass under active probing (CVE-2026-20896)criticalbug_reportVulnerability
bug_reportVulnerability

Gitea Docker auth bypass under active probing (CVE-2026-20896)

Gitea Docker images with improper X-WEBAUTH-USER header validation. Specific vulnerable versions not provided; affects deployments trusting reverse proxy authentication headers without IP restrictions.

CVE-2026-208966 Jul · 14:28 UTC
Adobe ColdFusion CVE-2026-48282 under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Adobe ColdFusion CVE-2026-48282 under active exploitation

Adobe ColdFusion (specific versions not disclosed). Maximum severity vulnerability actively exploited in the wild.

CVE-2026-482826 Jul · 11:18 UTC
North Korean actors deploy 108 malicious packages in PolinRider campaignhighbug_reportVulnerability
bug_reportVulnerability

North Korean actors deploy 108 malicious packages in PolinRider campaign

npm, Packagist (PHP), Go modules, and Google Chrome Web Store. 108 malicious packages and extensions published. Maintainer accounts actively compromised. Campaign linked to North Korean Contagious Interview threat group.

The Hacker News4 Jul · 09:17 UTC
North Korean actors deploy malicious npm packages to steal developer secretshighbug_reportVulnerability
bug_reportVulnerability

North Korean actors deploy malicious npm packages to steal developer secrets

npm ecosystem: malicious packages "rollup-packages-polyfill-core" and "rollup-runtime-polyfill-core" impersonating legitimate "rollup-plugin-polyfill-node".

npm3 Jul · 14:07 UTC
Argo CD repo-server RCE enables cluster takeover, no patch availablecriticalbug_reportVulnerability
bug_reportVulnerability

Argo CD repo-server RCE enables cluster takeover, no patch available

Argo CD repo-server component, all versions (specific affected versions not disclosed). Exploitation requires access to internal network port where repo-server listens.

Argo CD1 Jul · 17:40 UTC
Adobe patches CVSS 10.0 flaws in ColdFusion and Campaign Classiccriticalbug_reportVulnerability
bug_reportVulnerability

Adobe patches CVSS 10.0 flaws in ColdFusion and Campaign Classic

Adobe ColdFusion and Adobe Campaign Classic (specific versions not provided). Vulnerabilities include arbitrary code execution, privilege escalation, arbitrary file system read, and security feature bypass.

Adobe1 Jul · 13:25 UTC
LLM hallucinations exploited for supply chain attacks via phantom domainshighbug_reportVulnerability
bug_reportVulnerability

LLM hallucinations exploited for supply chain attacks via phantom domains

Organizations using LLMs for development assistance, code generation, or package recommendations. Developers relying on AI-generated domain/package suggestions without verification.

Unit 42 (Palo Alto)30 Jun · 23:00 UTC
Trojanized Pyrogram forks on PyPI target Telegram bot developershighbug_reportVulnerability
bug_reportVulnerability

Trojanized Pyrogram forks on PyPI target Telegram bot developers

Python developers using PyPI packages for Telegram bot development. Malicious forks of Pyrogram library active since November 2024. Affects developers who may have installed compromised packages instead of legitimate Pyrogram.

PyPI30 Jun · 19:02 UTC