Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-21 · 02:09 UTC
articleTotal: 606 reports

Filtered Reports

30 / 91 results
Active filter:tag: #technology✕ clear
Microsoft Defender zero-day 'RoguePlanet' enables SYSTEM privilege escalationcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft Defender zero-day 'RoguePlanet' enables SYSTEM privilege escalation

Microsoft Defender on Windows systems. Specific affected versions not disclosed. Given Defender's deployment, scope includes enterprise endpoints, servers running Defender, and consumer Windows installations with default security configuration.

Microsoft21:11 UTC
Microsoft June 2026 Patch Tuesday: ~200 patches, 36 critical, 3 with PoCscriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft June 2026 Patch Tuesday: ~200 patches, 36 critical, 3 with PoCs

Microsoft products across the portfolio. Approximately 200 vulnerabilities patched, including ~36 critical-severity issues. At least 3 vulnerabilities have public proof-of-concept exploit code available.

Microsoft20:07 UTC
Chrome V8 zero-day CVE-2026-11645 exploited in wild, patch immediatelycriticalbug_reportVulnerability
bug_reportVulnerability

Chrome V8 zero-day CVE-2026-11645 exploited in wild, patch immediately

Google Chrome versions prior to 149.0.7827.103 on all platforms. The vulnerability resides in the V8 JavaScript engine, affecting out-of-bounds memory access.

CVE-2026-1164509:58 UTC
BerriAI LiteLLM command injection under active exploitation (CISA KEV)highbug_reportVulnerability
bug_reportVulnerability

BerriAI LiteLLM command injection under active exploitation (CISA KEV)

BerriAI LiteLLM - specific vulnerable versions not disclosed in summary. Command injection vulnerability (CVE-2026-42271) affects authenticated users with access to the system.

CVE-2026-4227104:26 UTC
Linux kernel nf_tables use-after-free enables root escalation (CVE-2026-23111)criticalbug_reportVulnerability
bug_reportVulnerability

Linux kernel nf_tables use-after-free enables root escalation (CVE-2026-23111)

Linux kernel nf_tables subsystem. All distributions using vulnerable kernel versions prior to the February 5, 2026 patch. Affects systems where unprivileged users have local access or container environments.

CVE-2026-2311118:17 UTC
Toshiba, Muji sites show credential-stealing prompts via polyfill supply chainhighbug_reportVulnerability
bug_reportVulnerability

Toshiba, Muji sites show credential-stealing prompts via polyfill supply chain

Toshiba and Muji public websites, potentially other sites using the compromised third-party polyfill library. Scope of affected sites and specific polyfill service not yet confirmed.

Toshiba19:54 UTC
PCPJack Hijacks 230+ Cloud Servers for Covert SMTP Relay Networkhighperson_alertThreat Actor
person_alertThreat Actor

PCPJack Hijacks 230+ Cloud Servers for Covert SMTP Relay Network

PCPJack is a threat actor focused on compromising cloud infrastructure to establish illicit email relay networks. The actor has demonstrated capability to breach business servers across major cloud service providers (AWS, Google Cloud, Microsoft Azur…

Amazon Web Services03:34 UTC
Dutch authorities dismantle botnet controlling 17M infected deviceshighbug_reportVulnerability
bug_reportVulnerability

Dutch authorities dismantle botnet controlling 17M infected devices

At least 17 million infected devices globally including computers, tablets, smartphones, and IoT devices. Over 200 command-and-control servers located in the Netherlands were seized.

The Hacker News10:22 UTC
CIFSwitch: Linux kernel CIFS flaw enables local privilege escalationhighbug_reportVulnerability
bug_reportVulnerability

CIFSwitch: Linux kernel CIFS flaw enables local privilege escalation

Linux kernel CIFS implementation across multiple distributions. Specific affected kernel versions not yet disclosed. Requires local access to exploit.

Linux12:16 UTC
Palo Alto PAN-OS auth bypass (CVE-2026-0257) exploited in the wildhighbug_reportVulnerability
bug_reportVulnerability

Palo Alto PAN-OS auth bypass (CVE-2026-0257) exploited in the wild

Palo Alto Networks PAN-OS and Prisma Access. Specific affected versions not disclosed in provided data. Vulnerability impacts VPN authentication mechanisms.

CVE-2026-025704:41 UTC
33 malicious npm packages deployed in dependency confusion recon campaignhighbug_reportVulnerability
bug_reportVulnerability

33 malicious npm packages deployed in dependency confusion recon campaign

npm ecosystem; organizations using private npm packages with names vulnerable to dependency confusion attacks. Affects developer workstations, CI/CD pipelines, and build environments that may inadvertently install public packages instead of intended…

npm22:06 UTC
Threat actors abuse ChatGPT sharing to host fake OpenAI outage pageshighbug_reportVulnerability
bug_reportVulnerability

Threat actors abuse ChatGPT sharing to host fake OpenAI outage pages

OpenAI ChatGPT users globally. Threat actors exploit ChatGPT's legitimate content-sharing feature (chatgpt.com shared links) to host convincing phishing pages that impersonate OpenAI outage notifications and distribute malware posing as the ChatGPT d…

OpenAI16:21 UTC
ChatGPT Markdown renderer vulnerable to prompt injection and phishinghighbug_reportVulnerability
bug_reportVulnerability

ChatGPT Markdown renderer vulnerable to prompt injection and phishing

OpenAI ChatGPT web summary response renderer. All users interacting with ChatGPT's web interface that processes Markdown links and images are potentially affected. Specific version details not disclosed.

OpenAI16:07 UTC
Starlette and FastAPI authentication bypass flaw affects millions of serverscriticalbug_reportVulnerability
bug_reportVulnerability

Starlette and FastAPI authentication bypass flaw affects millions of servers

Starlette web framework and dependent frameworks including FastAPI. Specific vulnerable versions not provided in source data. Affects authentication mechanisms in applications built with these frameworks.

Starlette12:32 UTC
Cryptojacking campaign uses SEO poisoning and AI chatbots for GPU malwarehighbug_reportVulnerability
bug_reportVulnerability

Cryptojacking campaign uses SEO poisoning and AI chatbots for GPU malware

High-performance systems with GPUs accessed via search engines and AI chatbot platforms. No specific vendor or product vulnerability; targets users searching for legitimate software or information through poisoned search results and manipulated chatb…

BleepingComputer19:31 UTC
Microsoft SharePoint RCE vulnerability requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft SharePoint RCE vulnerability requires immediate patching

Microsoft SharePoint Server (specific versions not disclosed in advisory). Organizations running on-premises SharePoint deployments are affected. SharePoint Online managed by Microsoft likely already patched.

Microsoft14:23 UTC
CrowdStrike, Google disrupt GlassWorm C2 targeting software developershighbug_reportVulnerability
bug_reportVulnerability

CrowdStrike, Google disrupt GlassWorm C2 targeting software developers

Software developers using third-party packages and browser extensions. GlassWorm campaign active since early 2025, distributing malware through supply chain vectors including malicious packages and extensions.

CrowdStrike09:48 UTC
Cryptojacking campaign uses SEO poisoning and ScreenConnect for GPU mininghighbug_reportVulnerability
bug_reportVulnerability

Cryptojacking campaign uses SEO poisoning and ScreenConnect for GPU mining

Organizations using ScreenConnect remote access software; high-performance PCs with GPUs; users searching for compromised topics via search engines and AI chatbots. Campaign leverages Microsoft .NET utilities for execution.

Microsoft19:35 UTC
F5 BIG-IP Exploitation Leads to Confluence Compromise and Lateral Movementhighperson_alertThreat Actor
person_alertThreat Actor

F5 BIG-IP Exploitation Leads to Confluence Compromise and Lateral Movement

The threat actor behind this campaign remains unattributed. Motivation appears to be credential theft and network persistence within enterprise environments.

F514:53 UTC
Screening Serpens: Iranian APT Targets Tech and Defense with RAT Malwarehighperson_alertThreat Actor
person_alertThreat Actor

Screening Serpens: Iranian APT Targets Tech and Defense with RAT Malware

Screening Serpens is an Iranian APT group attributed by Unit 42, conducting cyber espionage operations. The group is motivated by intelligence collection targeting technology and defense sectors, consistent with Iranian state interests in acquiring s…

Unit 42 (Palo Alto)11:00 UTC
Megalodon campaign injects 5,718 malicious commits into GitHub reposhighperson_alertThreat Actor
person_alertThreat Actor

Megalodon campaign injects 5,718 malicious commits into GitHub repos

Megalodon is an automated supply chain attack campaign targeting GitHub repositories. The actor's motivation appears to be exfiltration of CI/CD environment data, including secrets, tokens, and credentials stored in GitHub Actions workflows.

GitHub09:55 UTC
Cisco Secure Workload REST API flaw allows unauthenticated data accesscriticalbug_reportVulnerability
bug_reportVulnerability

Cisco Secure Workload REST API flaw allows unauthenticated data access

Cisco Secure Workload (formerly Tetration). Specific affected versions not provided in available data. Vulnerability impacts REST API endpoints with insufficient authentication controls.

CVE-2026-2022303:36 UTC
Dort Arrested for Operating Kimwolf IoT Botnet in Multi-Million Device DDoS Campaignhighperson_alertThreat Actor
person_alertThreat Actor

Dort Arrested for Operating Kimwolf IoT Botnet in Multi-Million Device DDoS Campaign

Dort is a 23-year-old cybercriminal based in Ottawa, Canada, suspected of developing and operating the Kimwolf IoT botnet. Motivated by launching large-scale DDoS attacks, doxing, and swatting campaigns, Dort leveraged compromised IoT devices to buil…

Krebs on Security19:50 UTC
Chromium zero-day disclosed: JavaScript persists after browser closehighbug_reportVulnerability
bug_reportVulnerability

Chromium zero-day disclosed: JavaScript persists after browser close

Chromium-based browsers (Google Chrome, Microsoft Edge, Brave, Opera, Vivaldi) - specific affected versions not disclosed. Vulnerability remains unpatched at time of disclosure.

Google16:13 UTC
Cisco Secure Workload max-severity flaw grants Site Admin privilegescriticalbug_reportVulnerability
bug_reportVulnerability

Cisco Secure Workload max-severity flaw grants Site Admin privileges

Cisco Secure Workload platform. Specific affected versions not provided in summary. Vulnerability allows privilege escalation to Site Admin level, affecting administrative access controls.

Cisco11:58 UTC
Microsoft Defender privilege escalation CVE-2026-41091 under active exploithighbug_reportVulnerability
bug_reportVulnerability

Microsoft Defender privilege escalation CVE-2026-41091 under active exploit

Microsoft Defender on Windows systems. Specific product versions not disclosed. Vulnerability allows local attackers to escalate privileges to SYSTEM level through improper link resolution handling.

CVE-2026-4109108:55 UTC
SonicWall Gen6 SSL-VPN exploited for credential brute-force and MFA bypasscriticalbug_reportVulnerability
bug_reportVulnerability

SonicWall Gen6 SSL-VPN exploited for credential brute-force and MFA bypass

SonicWall Gen6 SSL-VPN appliances with incomplete patching. Specific firmware versions not disclosed. Affects organizations using SonicWall SSL-VPN for remote access.

SonicWall19:19 UTC
PgBouncer integer overflow under active exploitation, patch immediatelycriticalbug_reportVulnerability
bug_reportVulnerability

PgBouncer integer overflow under active exploitation, patch immediately

PgBouncer (PostgreSQL connection pooler) - specific affected versions not disclosed by CERT.BE. All unpatched instances should be considered at risk.

PgBouncer12:50 UTC
TeamPCP Lists GitHub Source Code for Sale After Repository Breachhighperson_alertThreat Actor
person_alertThreat Actor

TeamPCP Lists GitHub Source Code for Sale After Repository Breach

TeamPCP is a threat actor that has emerged in the cybercrime ecosystem, demonstrating capability to compromise high-value technology platforms. The actor's motivation appears financially driven, as evidenced by their decision to monetize stolen GitHu…

The Hacker News02:01 UTC
Fortinet FortiCloud SSO bypass exploited to extract LDAP passwordshighbug_reportVulnerability
bug_reportVulnerability

Fortinet FortiCloud SSO bypass exploited to extract LDAP passwords

Fortinet FortiGate appliances with FortiCloud SSO enabled. CVE-2025-59718 and CVE-2025-59719 allow authentication bypass. All FortiGate instances share a default static encryption key that enables decryption of LDAP credentials and private keys from…

CVE-2025-5971815:16 UTC