Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 173 results
highperson_alertThreat ActorChinese-speaking actor uses DeepSeek AI with Hermes Agent for automation
A Chinese-speaking threat actor leveraging artificial intelligence models to conduct cyberattacks. The actor employs the DeepSeek AI model in combination with the open-source Hermes Agent framework to enable autonomous offensive operations against in…
highbug_reportVulnerabilityChrome 149–151 fix 1,442 flaws as AI-driven bug discovery outpaces patching
Google Chrome versions 149, 150, and 151 (released June–July 2026). All prior Chrome versions are affected by the resolved vulnerabilities. One critical flaw (CVE-2026-3545, CVSS 9.6) is a 13-year-old sandbox escape in Navigation component, patched i…
highperson_alertThreat ActorLazarus Deploys Crypto-Stealing Malware via macOS Malvertising Campaign
Lazarus is a North Korea-linked APT group with a sustained focus on financial gain, particularly targeting cryptocurrency assets. Operating under DPRK state sponsorship, the group has evolved its tactics to include sophisticated social engineering ca…
highperson_alertThreat ActorChaos Ransomware Deployed via Microsoft Teams Vishing in North America
Chaos is a ransomware-as-a-service (RaaS) operation active since at least February 2025, believed to be linked to former members of the BlackSuit and Royal ransomware gangs—both spinoffs from the notorious Conti cybercrime syndicate.
criticalbug_reportVulnerabilityCritical VMware vCenter auth bypass allows remote system compromise
VMware vCenter Server in VMware Cloud Foundation and vSphere Foundation versions 9.1.x.x (prior to 9.1.0.0300), 9.0.x.x (prior to 9.0.2.0100), vCenter 8.0 (prior to 8.0 U3k), and VMware Cloud Foundation 5.x.
highbug_reportVulnerabilityApache Traffic Server vulnerabilities require immediate patching
Apache Traffic Server - specific versions not disclosed in available advisory. All users running Apache Traffic Server should verify their version against Apache security bulletins.
highbug_reportVulnerabilityFirefox JIT flaw CVE-2026-10702 enables remote code execution via webpage
Mozilla Firefox versions 147 through 151.0.2 (stable releases). Tor Browser releases incorporating vulnerable Firefox versions also affected. Firefox ESR not affected.
highbug_reportVulnerabilityTengu botnet abuses Linux watchdog to force reboots after process kill
Linux-based IoT devices and embedded systems across multiple architectures (i386, amd64, MIPS, ARM, PowerPC, m68k). No specific vendor or device model identified. Devices with exposed Telnet services and weak credentials are primary targets.
criticalbug_reportVulnerabilityFastJson RCE zero-day (CVE-2026-16723) actively exploited against US firms
FastJson versions 1.2.68 through 1.2.83 in Spring Boot fat-JAR deployments (java -jar xxx.jar). FastJson 1.2.60 and earlier, fastjson2, and non-fat-JAR deployments are NOT affected.
highperson_alertThreat ActorBlueNoroff Phishing Kit Profiles Crypto Wallets Before Malware Delivery
BlueNoroff (also tracked as APT38, NICKEL GLADSTONE, BeagleBoyz, Stardust Chollima) is a North Korean state-sponsored threat actor attributed to financially motivated operations targeting the cryptocurrency and technology sectors.
criticalbug_reportVulnerabilityRedis patches authenticated RCE flaws in versions 6.2–8.8
Redis versions 6.2.22, 7.2.14, 7.4.9, 8.2.7, 8.4.4, 8.6.4, and 8.8.0. Exploitation requires authenticated access and RESTORE command privileges. Streams-based chain also requires EVAL and XGROUP commands; RedisBloom chain (8.8.0) requires EVAL and bu…
highbug_reportVulnerabilityBing malvertising pushes fake Claude installer delivering SectopRAT
Microsoft Bing search users seeking Claude AI desktop app. Malicious Claude Artifact hosted on legitimate claude.ai domain (removed by Anthropic). At least 29 organizations compromised July 21-22, 2026.
highpublicGeopoliticalMicrosoft 365 outage disrupts cloud services across North America
The incident represents a technical service disruption affecting critical cloud infrastructure rather than a geopolitical cyber event. Microsoft 365's position as backbone infrastructure for government, defense, and commercial operations in North Ame…
highperson_alertThreat ActorChaos Ransomware Group Deploys msaRAT Rust Implant via Headless Browsers
Chaos is a ransomware group that operates through spam floods, vishing campaigns, Quick Assist abuse, and RMM tools for initial access and persistence. The group deploys custom tooling including the msaRAT Rust-based implant as a pre-ransomware stage…
highbug_reportVulnerabilityLinux XFS race condition CVE-2026-64600 enables local root escalation
Linux kernel v4.11 and later (since February 2017) with XFS filesystem and reflink enabled (default on RHEL, Oracle Linux, Amazon Linux, Fedora, CentOS Stream, Rocky Linux, AlmaLinux, CloudLinux).
criticalbug_reportVulnerabilityRefluXFS kernel flaw grants local root on default RHEL, Fedora, Amazon Linux
Linux kernel 4.11+ (2017–July 2026) on systems with XFS filesystems created with reflink=1. Default installations of RHEL/CentOS Stream/Oracle/Rocky/AlmaLinux/CloudLinux 8/9/10, Fedora Server 31+, Amazon Linux 2023, and Amazon Linux 2 (Dec 2022+) are…
highbug_reportVulnerabilityAdobe Acrobat Chrome extension flaw allows WhatsApp data theft via UXSS
Adobe Acrobat Chrome extension (ID: efaidnbmnnnibpcajpcglclefindmkaj) versions up to and including 26.5.2.2. Affects 314+ million users. Exploitation impacts any web application data accessible in victim's browser, demonstrated against WhatsApp Web.
highperson_alertThreat ActorFakeGit Campaign Distributes Malware via 7,600 Malicious GitHub Repos
FakeGit is a threat actor conducting a large-scale supply chain attack campaign targeting the software development community. The actor's motivation centers on mass malware distribution through the compromise of developer trust in the GitHub platform…
criticalbug_reportVulnerabilityMicrosoft SharePoint RCE CVE-2026-50522 actively exploited for persistence
Microsoft SharePoint Server (specific versions not provided). Vulnerability enables remote code execution with machine key theft capability, allowing persistent access beyond patch deployment.
highbug_reportVulnerabilityApple fixes Hide My Email flaw exposing real addresses in mail logs
Apple Hide My Email service (all users prior to July 3, 2026 patch). The vulnerability affected the privacy relay feature that masks user email addresses, causing real email addresses to leak in mail server logs.
highbug_reportVulnerabilityAWS Kiro IDE vulnerability allowed RCE via hidden web text injection
AWS Kiro agentic coding IDE (specific versions not disclosed). Vulnerability has been patched by AWS. Users who installed Kiro before the patch are potentially affected.
highbug_reportVulnerabilityWindows LegacyHive zero-day enables privilege escalation, unofficial patches available
Microsoft Windows systems (all current versions). Specific affected versions not disclosed. Impacts up-to-date Windows installations. No CVE assigned yet.
criticalbug_reportVulnerabilitySonicWall SMA1000 VPN appliances exploited via two zero-day flaws
SonicWall SMA1000 series VPN appliances. Specific vulnerable versions not disclosed. Affects enterprise VPN infrastructure using these devices.
highperson_alertThreat ActorJadePuffer Deploys EncForge Ransomware Targeting AI Infrastructure
JadePuffer is characterized as an autonomous AI agent that has been enhanced with offensive capabilities. The actor's motivation centers on targeting artificial intelligence infrastructure, specifically focusing on high-value AI assets such as traini…
highperson_alertThreat ActorFakeGit Campaign Distributes SmartLoader via 7,600+ Malicious GitHub Repos
FakeGit is a campaign (not a named threat actor group) targeting software developers through a large-scale supply chain attack leveraging GitHub's trusted platform.
highbug_reportVulnerabilityHollowGraph malware abuses Microsoft 365 calendar for C2 and exfiltration
Microsoft 365 environments with compromised mailboxes. Threat actors leverage Microsoft Graph API and calendar features to establish covert command-and-control channels.
highperson_alertThreat ActorAutonomous AI Agent Breaches Hugging Face Repository
The threat actor is identified as an autonomous AI agent system—a novel adversary class representing machine-driven attack capabilities operating with minimal or no human intervention.
criticalbug_reportVulnerabilityCritical NGINX heap overflow enables RCE via crafted HTTP requests
NGINX open source versions prior to 1.30.4 and 1.31.3, and NGINX Plus versions prior to 37.0.3.1. All deployments accepting HTTP requests from untrusted networks are at risk.
criticalbug_reportVulnerabilitySonicWall SMA 1000 VPN zero-days exploited by UTA0533 for root access
SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. Specific vulnerable versions not disclosed. All SMA 1000 deployments should be considered at risk until vendor guidance is available.
highbug_reportVulnerabilityOpenSSL "HollowByte" DoS allows 11-byte requests to freeze server memory
OpenSSL versions prior to June 2024 patch. Affects TLS servers running on glibc-based Linux systems. Specific vulnerable versions not disclosed; patch applied without CVE or public advisory.