Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-20 · 02:03 UTC
articleTotal: 593 reports

Filtered Reports

30 / 346 results
Active filter:✕ clear
AI browsers leak credentials via BioShocking social engineering attackhighbug_reportVulnerability
bug_reportVulnerability

AI browsers leak credentials via BioShocking social engineering attack

Six AI browsers and assistants including OpenAI ChatGPT Atlas, Perplexity Comet, and Anthropic Claude browser extension. Attack exploits AI reasoning vulnerabilities to extract user credentials through game-based social engineering.

OpenAI06:37 UTC
Dell Wyse RCE flaw exploitable by low-privileged attackerscriticalbug_reportVulnerability
bug_reportVulnerability

Dell Wyse RCE flaw exploitable by low-privileged attackers

Dell Wyse thin client products. Specific affected models and firmware versions not disclosed in summary. Vulnerability enables remote code execution with low privilege requirements.

Dell13:04 UTC
SimpleHelp CVE-2026-48558 exploited to deploy Djinn Stealer malwarecriticalbug_reportVulnerability
bug_reportVulnerability

SimpleHelp CVE-2026-48558 exploited to deploy Djinn Stealer malware

SimpleHelp remote support software (specific versions not disclosed). Affects organizations using SimpleHelp for remote access and support operations across Windows, macOS, and Linux environments.

CVE-2026-4855812:00 UTC
Oracle E-Business Suite under active exploit via CVE-2026-46817criticalbug_reportVulnerability
bug_reportVulnerability

Oracle E-Business Suite under active exploit via CVE-2026-46817

Oracle E-Business Suite (EBS) financial application. Specific affected versions not disclosed in available intelligence.

CVE-2026-4681711:46 UTC
Stack buffer overflow in libxml2 enables code execution via malformed inputhighbug_reportVulnerability
bug_reportVulnerability

Stack buffer overflow in libxml2 enables code execution via malformed input

libxml2 library, all versions not yet patched. Affects systems and applications that parse XML using libxml2, including numerous Linux distributions, Python, PHP, and other software that depends on this widely-deployed XML parsing library.

CVE-2026-1197911:20 UTC
236K+ malicious sites use DCloud Uni-App templates for crypto scamshighbug_reportVulnerability
bug_reportVulnerability

236K+ malicious sites use DCloud Uni-App templates for crypto scams

Organizations and users interacting with websites built using DCloud Uni-App framework templates. Over 236,000 malicious sites identified conducting cryptocurrency scams, phishing, wallet draining, pig-butchering schemes, and fake gambling platforms.

DCloud09:57 UTC
Critical RCE flaw in PTC Windchill and FlexPLM requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical RCE flaw in PTC Windchill and FlexPLM requires immediate patching

PTC Windchill and FlexPLM products. Specific affected versions not disclosed in available data. Both products are enterprise Product Lifecycle Management (PLM) platforms widely used in manufacturing and engineering environments.

PTC07:52 UTC
Microsoft removes 119 malicious Edge extensions hiding malware via steganographyhighbug_reportVulnerability
bug_reportVulnerability

Microsoft removes 119 malicious Edge extensions hiding malware via steganography

Microsoft Edge browser users who installed any of 119 malicious extensions from the official Microsoft Edge Add-ons store. Campaign active since at least 2021, affecting unknown number of users globally.

Microsoft06:32 UTC
Microsoft Exchange privilege escalation flaw requires immediate patchinghighbug_reportVulnerability
bug_reportVulnerability

Microsoft Exchange privilege escalation flaw requires immediate patching

Microsoft Exchange Server 2016, 2019, and Subscription Edition. All on-premises deployments of these versions are potentially affected.

Microsoft06:06 UTC
libssh2 RCE via malicious SSH server (CVE-2026-55200), PoC publiccriticalbug_reportVulnerability
bug_reportVulnerability

libssh2 RCE via malicious SSH server (CVE-2026-55200), PoC public

libssh2 library versions up to and including 1.11.1. Affects any application or system using libssh2 for SSH client connections, including Git, curl, rsync wrappers, and custom SSH clients.

CVE-2026-5520005:06 UTC
Hijacked npm and Go packages deploy cross-platform stealer via VS Codehighbug_reportVulnerability
bug_reportVulnerability

Hijacked npm and Go packages deploy cross-platform stealer via VS Code

Compromised npm and Go packages targeting developers using Microsoft Visual Studio Code on Windows, Linux, and macOS. Attack bypasses npm v12 lifecycle script protections by abusing VS Code task execution.

npm03:36 UTC
Agentic coding tools vulnerable to hidden malicious payloads in reposhighbug_reportVulnerability
bug_reportVulnerability

Agentic coding tools vulnerable to hidden malicious payloads in repos

Agentic coding tools and AI-assisted development platforms that automatically fetch and execute code from GitHub repositories. Specific products not disclosed.

BleepingComputer12:22 UTC
CISA orders federal patch for exploited Cisco Unified Comms flawcriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders federal patch for exploited Cisco Unified Comms flaw

Cisco Unified Communications Manager Server. Specific versions not disclosed. Federal agencies mandated to patch; all organizations running this product should consider affected.

Cisco17:43 UTC
SharkLoader malware deploys Cobalt Strike in attacks on Asian governmentshighbug_reportVulnerability
bug_reportVulnerability

SharkLoader malware deploys Cobalt Strike in attacks on Asian governments

Diplomatic and government organizations in Indonesia and Taiwan. SharkLoader is a newly identified malware family used to deliver Cobalt Strike Beacon payloads in the StrikeShark campaign.

The Hacker News16:17 UTC
Polymarket frontend compromised via third-party vendor; $3M stolenhighbug_reportVulnerability
bug_reportVulnerability

Polymarket frontend compromised via third-party vendor; $3M stolen

Polymarket platform users. Attack vector: malicious JavaScript injected into frontend via compromised third-party vendor. Approximately $3 million in customer funds stolen. No CVE assigned.

Polymarket16:04 UTC
Linux kernel traffic-control flaw grants local root via public exploitcriticalbug_reportVulnerability
bug_reportVulnerability

Linux kernel traffic-control flaw grants local root via public exploit

Linux kernel traffic-control subsystem (act_pedit module). All distributions running vulnerable kernel versions are affected. Specific patched versions not provided; assume unpatched kernels prior to June 16, 2026 vendor advisories are vulnerable.

CVE-2026-4633111:57 UTC
Amazon Q Developer flaw allows credential theft via malicious reposhighbug_reportVulnerability
bug_reportVulnerability

Amazon Q Developer flaw allows credential theft via malicious repos

Amazon Q Developer (all versions prior to patch). Affects developers using the IDE plugin who clone or open malicious repositories containing crafted Model Context Protocol (MCP) server configurations.

CVE-2026-1295711:53 UTC
PTC Windchill and FlexPLM RCE actively exploited in web shell attackscriticalbug_reportVulnerability
bug_reportVulnerability

PTC Windchill and FlexPLM RCE actively exploited in web shell attacks

PTC Windchill PDMlink and PTC FlexPLM Product Lifecycle Management systems. Specific affected versions not disclosed in summary; consult CISA KEV catalog and PTC security advisories for version details.

PTC10:31 UTC
DirtyClone Linux kernel flaw enables local privilege escalation to roothighbug_reportVulnerability
bug_reportVulnerability

DirtyClone Linux kernel flaw enables local privilege escalation to root

Linux kernel (specific vulnerable versions not disclosed). Affects systems where local users can trigger network packet cloning operations. Part of the DirtyFrag vulnerability family.

CVE-2026-4350309:51 UTC
Miasma malware compromises npm packages LeoPlatform and RStreamshighbug_reportVulnerability
bug_reportVulnerability

Miasma malware compromises npm packages LeoPlatform and RStreams

npm packages LeoPlatform and RStreams compromised by Miasma malware family. Attack extends to GitHub Actions workflows and Go ecosystem. Organizations using these packages or dependent projects are affected.

npm09:05 UTC
Phishing campaign targets hotel front desks with Node.js implanthighbug_reportVulnerability
bug_reportVulnerability

Phishing campaign targets hotel front desks with Node.js implant

Hotel and hospitality organizations in Europe and Asia. Front-desk systems targeted via photo-themed ZIP file attachments containing Node.js-based malware. Campaign active since April 2026.

Microsoft07:27 UTC
Active campaign targets hospitality in Europe/Asia via ZIP archiveshighbug_reportVulnerability
bug_reportVulnerability

Active campaign targets hospitality in Europe/Asia via ZIP archives

Hospitality organizations in Europe and Asia. Attack vector: photo-themed ZIP archives containing malicious shortcut files that deploy a Node.js implant.

Microsoft20:30 UTC
Shopify Shop app abused for callback phishing via fake order receiptshighbug_reportVulnerability
bug_reportVulnerability

Shopify Shop app abused for callback phishing via fake order receipts

Shopify Shop order-tracking app users. Threat actors inject fraudulent purchase receipts into legitimate user order histories, leveraging Shopify's trusted platform to deliver phishing lures.

Shopify17:45 UTC
Bluekit PhaaS expands with 70 new domains, adds browser-in-the-middlehighbug_reportVulnerability
bug_reportVulnerability

Bluekit PhaaS expands with 70 new domains, adds browser-in-the-middle

Organizations using cloud services and SaaS platforms targeted by Bluekit phishing-as-a-service infrastructure. Approximately 70 new phishing hostnames deployed in the past week.

BleepingComputer13:00 UTC
Gogs Git service vulnerable to remote code execution, patch immediatelycriticalbug_reportVulnerability
bug_reportVulnerability

Gogs Git service vulnerable to remote code execution, patch immediately

Gogs Git service (specific versions not disclosed in advisory). All internet-facing Gogs instances should be considered at risk until patched.

Gogs12:55 UTC
Adblock for YouTube extension with 10M+ installs contains code injection riskhighbug_reportVulnerability
bug_reportVulnerability

Adblock for YouTube extension with 10M+ installs contains code injection risk

Chrome extension "Adblock for YouTube" (10+ million active installations). All users with the extension installed are potentially affected. Extension currently holds Featured badge status in Chrome Web Store.

Google12:12 UTC
Cisco Catalyst SD-WAN zero-day exploited in wild for two monthshighbug_reportVulnerability
bug_reportVulnerability

Cisco Catalyst SD-WAN zero-day exploited in wild for two months

Cisco Catalyst SD-WAN Manager. Specific affected versions not disclosed. Requires authenticated local access for exploitation.

CVE-2026-2024503:46 UTC
Cisco Catalyst SD-WAN zero-day exploited for root access (CVE-2026-20245)criticalbug_reportVulnerability
bug_reportVulnerability

Cisco Catalyst SD-WAN zero-day exploited for root access (CVE-2026-20245)

Cisco Catalyst SD-WAN devices. Specific affected versions not disclosed in available information. Attackers gain root-level access and can create persistent rogue accounts.

CVE-2026-2024519:29 UTC
CISA warns: Lantronix EDS5000 code injection under active exploitcriticalbug_reportVulnerability
bug_reportVulnerability

CISA warns: Lantronix EDS5000 code injection under active exploit

Lantronix EDS5000 Series devices. Specific vulnerable firmware versions not disclosed in provided data. Critical code injection vulnerability (CVE-2025-67038, CVSS 9.8).

CVE-2025-6703815:19 UTC
CISA warns: Critical flaws in Ubiquiti UniFi OS and Lantronix exploitedcriticalbug_reportVulnerability
bug_reportVulnerability

CISA warns: Critical flaws in Ubiquiti UniFi OS and Lantronix exploited

Ubiquiti UniFi OS and Lantronix serial-to-ethernet servers. Specific affected versions not disclosed in summary. Both products commonly deployed in enterprise network infrastructure and IoT/OT environments.

Ubiquiti12:35 UTC