Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 173 results
Active filter:tag: #technology✕ clear
Chinese-speaking actor uses DeepSeek AI with Hermes Agent for automationhighperson_alertThreat Actor
person_alertThreat Actor

Chinese-speaking actor uses DeepSeek AI with Hermes Agent for automation

A Chinese-speaking threat actor leveraging artificial intelligence models to conduct cyberattacks. The actor employs the DeepSeek AI model in combination with the open-source Hermes Agent framework to enable autonomous offensive operations against in…

BleepingComputer31 Jul · 15:35 UTC
Chrome 149–151 fix 1,442 flaws as AI-driven bug discovery outpaces patchinghighbug_reportVulnerability
bug_reportVulnerability

Chrome 149–151 fix 1,442 flaws as AI-driven bug discovery outpaces patching

Google Chrome versions 149, 150, and 151 (released June–July 2026). All prior Chrome versions are affected by the resolved vulnerabilities. One critical flaw (CVE-2026-3545, CVSS 9.6) is a 13-year-old sandbox escape in Navigation component, patched i…

Google31 Jul · 10:51 UTC
Lazarus Deploys Crypto-Stealing Malware via macOS Malvertising Campaignhighperson_alertThreat Actor
person_alertThreat Actor

Lazarus Deploys Crypto-Stealing Malware via macOS Malvertising Campaign

Lazarus is a North Korea-linked APT group with a sustained focus on financial gain, particularly targeting cryptocurrency assets. Operating under DPRK state sponsorship, the group has evolved its tactics to include sophisticated social engineering ca…

Apple30 Jul · 16:18 UTC
Chaos Ransomware Deployed via Microsoft Teams Vishing in North Americahighperson_alertThreat Actor
person_alertThreat Actor

Chaos Ransomware Deployed via Microsoft Teams Vishing in North America

Chaos is a ransomware-as-a-service (RaaS) operation active since at least February 2025, believed to be linked to former members of the BlackSuit and Royal ransomware gangs—both spinoffs from the notorious Conti cybercrime syndicate.

BleepingComputer30 Jul · 13:56 UTC
Critical VMware vCenter auth bypass allows remote system compromisecriticalbug_reportVulnerability
bug_reportVulnerability

Critical VMware vCenter auth bypass allows remote system compromise

VMware vCenter Server in VMware Cloud Foundation and vSphere Foundation versions 9.1.x.x (prior to 9.1.0.0300), 9.0.x.x (prior to 9.0.2.0100), vCenter 8.0 (prior to 8.0 U3k), and VMware Cloud Foundation 5.x.

CVE-2026-5930929 Jul · 13:31 UTC
Apache Traffic Server vulnerabilities require immediate patchinghighbug_reportVulnerability
bug_reportVulnerability

Apache Traffic Server vulnerabilities require immediate patching

Apache Traffic Server - specific versions not disclosed in available advisory. All users running Apache Traffic Server should verify their version against Apache security bulletins.

Apache29 Jul · 11:59 UTC
Firefox JIT flaw CVE-2026-10702 enables remote code execution via webpagehighbug_reportVulnerability
bug_reportVulnerability

Firefox JIT flaw CVE-2026-10702 enables remote code execution via webpage

Mozilla Firefox versions 147 through 151.0.2 (stable releases). Tor Browser releases incorporating vulnerable Firefox versions also affected. Firefox ESR not affected.

CVE-2026-1070229 Jul · 09:57 UTC
Tengu botnet abuses Linux watchdog to force reboots after process killhighbug_reportVulnerability
bug_reportVulnerability

Tengu botnet abuses Linux watchdog to force reboots after process kill

Linux-based IoT devices and embedded systems across multiple architectures (i386, amd64, MIPS, ARM, PowerPC, m68k). No specific vendor or device model identified. Devices with exposed Telnet services and weak credentials are primary targets.

Linux28 Jul · 13:01 UTC
FastJson RCE zero-day (CVE-2026-16723) actively exploited against US firmscriticalbug_reportVulnerability
bug_reportVulnerability

FastJson RCE zero-day (CVE-2026-16723) actively exploited against US firms

FastJson versions 1.2.68 through 1.2.83 in Spring Boot fat-JAR deployments (java -jar xxx.jar). FastJson 1.2.60 and earlier, fastjson2, and non-fat-JAR deployments are NOT affected.

Alibaba27 Jul · 21:49 UTC
BlueNoroff Phishing Kit Profiles Crypto Wallets Before Malware Deliveryhighperson_alertThreat Actor
person_alertThreat Actor

BlueNoroff Phishing Kit Profiles Crypto Wallets Before Malware Delivery

BlueNoroff (also tracked as APT38, NICKEL GLADSTONE, BeagleBoyz, Stardust Chollima) is a North Korean state-sponsored threat actor attributed to financially motivated operations targeting the cryptocurrency and technology sectors.

Zoom24 Jul · 13:12 UTC
Redis patches authenticated RCE flaws in versions 6.2–8.8criticalbug_reportVulnerability
bug_reportVulnerability

Redis patches authenticated RCE flaws in versions 6.2–8.8

Redis versions 6.2.22, 7.2.14, 7.4.9, 8.2.7, 8.4.4, 8.6.4, and 8.8.0. Exploitation requires authenticated access and RESTORE command privileges. Streams-based chain also requires EVAL and XGROUP commands; RedisBloom chain (8.8.0) requires EVAL and bu…

Redis24 Jul · 04:58 UTC
Bing malvertising pushes fake Claude installer delivering SectopRAThighbug_reportVulnerability
bug_reportVulnerability

Bing malvertising pushes fake Claude installer delivering SectopRAT

Microsoft Bing search users seeking Claude AI desktop app. Malicious Claude Artifact hosted on legitimate claude.ai domain (removed by Anthropic). At least 29 organizations compromised July 21-22, 2026.

Microsoft23 Jul · 17:48 UTC
Microsoft 365 outage disrupts cloud services across North AmericahighpublicGeopolitical
publicGeopolitical

Microsoft 365 outage disrupts cloud services across North America

The incident represents a technical service disruption affecting critical cloud infrastructure rather than a geopolitical cyber event. Microsoft 365's position as backbone infrastructure for government, defense, and commercial operations in North Ame…

Microsoft23 Jul · 13:34 UTC
Chaos Ransomware Group Deploys msaRAT Rust Implant via Headless Browsershighperson_alertThreat Actor
person_alertThreat Actor

Chaos Ransomware Group Deploys msaRAT Rust Implant via Headless Browsers

Chaos is a ransomware group that operates through spam floods, vishing campaigns, Quick Assist abuse, and RMM tools for initial access and persistence. The group deploys custom tooling including the msaRAT Rust-based implant as a pre-ransomware stage…

Microsoft23 Jul · 11:11 UTC
Linux XFS race condition CVE-2026-64600 enables local root escalationhighbug_reportVulnerability
bug_reportVulnerability

Linux XFS race condition CVE-2026-64600 enables local root escalation

Linux kernel v4.11 and later (since February 2017) with XFS filesystem and reflink enabled (default on RHEL, Oracle Linux, Amazon Linux, Fedora, CentOS Stream, Rocky Linux, AlmaLinux, CloudLinux).

CVE-2026-6460023 Jul · 09:40 UTC
RefluXFS kernel flaw grants local root on default RHEL, Fedora, Amazon Linuxcriticalbug_reportVulnerability
bug_reportVulnerability

RefluXFS kernel flaw grants local root on default RHEL, Fedora, Amazon Linux

Linux kernel 4.11+ (2017–July 2026) on systems with XFS filesystems created with reflink=1. Default installations of RHEL/CentOS Stream/Oracle/Rocky/AlmaLinux/CloudLinux 8/9/10, Fedora Server 31+, Amazon Linux 2023, and Amazon Linux 2 (Dec 2022+) are…

CVE-2026-6460023 Jul · 06:04 UTC
Adobe Acrobat Chrome extension flaw allows WhatsApp data theft via UXSShighbug_reportVulnerability
bug_reportVulnerability

Adobe Acrobat Chrome extension flaw allows WhatsApp data theft via UXSS

Adobe Acrobat Chrome extension (ID: efaidnbmnnnibpcajpcglclefindmkaj) versions up to and including 26.5.2.2. Affects 314+ million users. Exploitation impacts any web application data accessible in victim's browser, demonstrated against WhatsApp Web.

CVE-2026-4829422 Jul · 13:01 UTC
FakeGit Campaign Distributes Malware via 7,600 Malicious GitHub Reposhighperson_alertThreat Actor
person_alertThreat Actor

FakeGit Campaign Distributes Malware via 7,600 Malicious GitHub Repos

FakeGit is a threat actor conducting a large-scale supply chain attack campaign targeting the software development community. The actor's motivation centers on mass malware distribution through the compromise of developer trust in the GitHub platform…

GitHub21 Jul · 20:34 UTC
Microsoft SharePoint RCE CVE-2026-50522 actively exploited for persistencecriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft SharePoint RCE CVE-2026-50522 actively exploited for persistence

Microsoft SharePoint Server (specific versions not provided). Vulnerability enables remote code execution with machine key theft capability, allowing persistent access beyond patch deployment.

CVE-2026-5052221 Jul · 18:06 UTC
Apple fixes Hide My Email flaw exposing real addresses in mail logshighbug_reportVulnerability
bug_reportVulnerability

Apple fixes Hide My Email flaw exposing real addresses in mail logs

Apple Hide My Email service (all users prior to July 3, 2026 patch). The vulnerability affected the privacy relay feature that masks user email addresses, causing real email addresses to leak in mail server logs.

Apple21 Jul · 16:46 UTC
AWS Kiro IDE vulnerability allowed RCE via hidden web text injectionhighbug_reportVulnerability
bug_reportVulnerability

AWS Kiro IDE vulnerability allowed RCE via hidden web text injection

AWS Kiro agentic coding IDE (specific versions not disclosed). Vulnerability has been patched by AWS. Users who installed Kiro before the patch are potentially affected.

AWS21 Jul · 14:06 UTC
Windows LegacyHive zero-day enables privilege escalation, unofficial patches availablehighbug_reportVulnerability
bug_reportVulnerability

Windows LegacyHive zero-day enables privilege escalation, unofficial patches available

Microsoft Windows systems (all current versions). Specific affected versions not disclosed. Impacts up-to-date Windows installations. No CVE assigned yet.

Microsoft21 Jul · 06:06 UTC
SonicWall SMA1000 VPN appliances exploited via two zero-day flawscriticalbug_reportVulnerability
bug_reportVulnerability

SonicWall SMA1000 VPN appliances exploited via two zero-day flaws

SonicWall SMA1000 series VPN appliances. Specific vulnerable versions not disclosed. Affects enterprise VPN infrastructure using these devices.

SonicWall20 Jul · 20:23 UTC
JadePuffer Deploys EncForge Ransomware Targeting AI Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

JadePuffer Deploys EncForge Ransomware Targeting AI Infrastructure

JadePuffer is characterized as an autonomous AI agent that has been enhanced with offensive capabilities. The actor's motivation centers on targeting artificial intelligence infrastructure, specifically focusing on high-value AI assets such as traini…

BleepingComputer20 Jul · 19:08 UTC
FakeGit Campaign Distributes SmartLoader via 7,600+ Malicious GitHub Reposhighperson_alertThreat Actor
person_alertThreat Actor

FakeGit Campaign Distributes SmartLoader via 7,600+ Malicious GitHub Repos

FakeGit is a campaign (not a named threat actor group) targeting software developers through a large-scale supply chain attack leveraging GitHub's trusted platform.

GitHub20 Jul · 16:23 UTC
HollowGraph malware abuses Microsoft 365 calendar for C2 and exfiltrationhighbug_reportVulnerability
bug_reportVulnerability

HollowGraph malware abuses Microsoft 365 calendar for C2 and exfiltration

Microsoft 365 environments with compromised mailboxes. Threat actors leverage Microsoft Graph API and calendar features to establish covert command-and-control channels.

Microsoft20 Jul · 15:43 UTC
Autonomous AI Agent Breaches Hugging Face Repositoryhighperson_alertThreat Actor
person_alertThreat Actor

Autonomous AI Agent Breaches Hugging Face Repository

The threat actor is identified as an autonomous AI agent system—a novel adversary class representing machine-driven attack capabilities operating with minimal or no human intervention.

Hugging Face20 Jul · 03:27 UTC
Critical NGINX heap overflow enables RCE via crafted HTTP requestscriticalbug_reportVulnerability
bug_reportVulnerability

Critical NGINX heap overflow enables RCE via crafted HTTP requests

NGINX open source versions prior to 1.30.4 and 1.31.3, and NGINX Plus versions prior to 37.0.3.1. All deployments accepting HTTP requests from untrusted networks are at risk.

CVE-2026-4253319 Jul · 18:42 UTC
SonicWall SMA 1000 VPN zero-days exploited by UTA0533 for root accesscriticalbug_reportVulnerability
bug_reportVulnerability

SonicWall SMA 1000 VPN zero-days exploited by UTA0533 for root access

SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. Specific vulnerable versions not disclosed. All SMA 1000 deployments should be considered at risk until vendor guidance is available.

SonicWall19 Jul · 11:18 UTC
OpenSSL "HollowByte" DoS allows 11-byte requests to freeze server memoryhighbug_reportVulnerability
bug_reportVulnerability

OpenSSL "HollowByte" DoS allows 11-byte requests to freeze server memory

OpenSSL versions prior to June 2024 patch. Affects TLS servers running on glibc-based Linux systems. Specific vulnerable versions not disclosed; patch applied without CVE or public advisory.

OpenSSL17 Jul · 18:20 UTC