Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
20 / 96 results
criticalbug_reportVulnerabilityMicrosoft Defender zero-day "RoguePlanet" exploited for SYSTEM access
Microsoft Defender on all updated Windows systems. No CVE assigned yet. Vulnerability is a race condition enabling local privilege escalation to SYSTEM.
criticalbug_reportVulnerabilityMicrosoft Defender zero-day 'RoguePlanet' enables SYSTEM privilege escalation
Microsoft Defender on Windows systems. Specific affected versions not disclosed. Given Defender's deployment, scope includes enterprise endpoints, servers running Defender, and consumer Windows installations with default security configuration.
criticalbug_reportVulnerabilityMicrosoft June 2026 Patch Tuesday: ~200 patches, 36 critical, 3 with PoCs
Microsoft products across the portfolio. Approximately 200 vulnerabilities patched, including ~36 critical-severity issues. At least 3 vulnerabilities have public proof-of-concept exploit code available.
highbug_reportVulnerabilityMicrosoft June 2026 Patch Tuesday: 200 flaws, 3 disclosed zero-days
Microsoft products across the ecosystem. 200 vulnerabilities patched, including 3 publicly disclosed zero-day vulnerabilities. Specific affected products and CVE identifiers not yet detailed in available information.
highbug_reportVulnerabilityMicrosoft GitHub repos compromised, 73 disabled for distributing malware
73 repositories across Microsoft's official GitHub organizations (Azure, microsoft, Azure-Samples, MicrosoftDocs). Organizations using Microsoft sample code, Azure templates, or CI/CD pipelines referencing these repositories are potentially affected.
highbug_reportVulnerabilityMiasma worm compromises 73 Microsoft GitHub repos in supply chain attack
73 Microsoft GitHub repositories across four organizations: Azure, Azure-Samples, Microsoft, and MicrosoftDocs. GitHub has disabled access to affected repositories.
highperson_alertThreat ActorUNC5221 Deploys Brickstorm, Plenet, AgentPSD in M365 Espionage Campaign
UNC5221 is a Chinese APT group attributed to conducting cyber espionage operations. The group demonstrates advanced capabilities in targeting cloud environments, specifically Microsoft 365 infrastructure.
highperson_alertThreat ActorOP-512 Targets IIS Servers with Custom Web Shell Framework
OP-512 is a previously unreported threat cluster assessed by ReliaQuest with moderate to high confidence to be linked to China. The actor demonstrates espionage-focused objectives, leveraging custom web shell frameworks to compromise Microsoft Intern…
criticalbug_reportVulnerabilityWindows Netlogon RCE under active exploitation after patch release
Microsoft Windows Netlogon service, all versions prior to recent patch. Affects domain controllers and systems with Netlogon service enabled. Specific CVE and affected version details not provided in alert.
criticalbug_reportVulnerabilityMicrosoft May 2026 Patch Tuesday: 118 vulnerabilities, 16 critical
Microsoft products and services across the ecosystem. 118 total vulnerabilities: 16 critical severity, 102 important severity. Specific affected products and CVE identifiers not yet detailed in available information.
highperson_alertThreat ActorStorm-2697 Deploys The Gentlemen Go-Based Ransomware with Worm Capabilities
Storm-2697 is a threat actor tracked by Microsoft Threat Intelligence that operates as a ransomware affiliate group. The actor deploys The Gentlemen ransomware, a sophisticated Go-based encryption tool, suggesting technical proficiency in modern prog…
criticalbug_reportVulnerabilityMicrosoft SharePoint RCE vulnerability requires immediate patching
Microsoft SharePoint Server (specific versions not disclosed in advisory). Organizations running on-premises SharePoint deployments are affected. SharePoint Online managed by Microsoft likely already patched.
highbug_reportVulnerabilityAI chatbot abuse delivers cryptojacking malware via social engineering
Users of AI chatbots (platform-agnostic); Windows systems targeted for cryptojacking payload deployment. Campaign actively observed by Microsoft; no specific product vulnerability, relies on social engineering.
highbug_reportVulnerabilityCryptojacking campaign uses SEO poisoning and ScreenConnect for GPU mining
Organizations using ScreenConnect remote access software; high-performance PCs with GPUs; users searching for compromised topics via search engines and AI chatbots. Campaign leverages Microsoft .NET utilities for execution.
highbug_reportVulnerabilityMicrosoft patches SharePoint RCE flaw via unsafe deserialization
Microsoft SharePoint Server (specific versions not disclosed). Vulnerability involves deserialization of untrusted data leading to remote code execution with CVSS 8.8.
highbug_reportVulnerabilityWindows Server 2016 domain controller lookups fail after KB5087537 update
Windows Server 2016 domain controllers running KB5087537 (May 2026 security update). Impacts Active Directory domain controller lookup functionality and domain connectivity.
highperson_alertThreat ActorFBI warns of Kali365 phishing-as-a-service targeting Microsoft 365
Kali365 is a phishing-as-a-service (PhaaS) platform that enables threat actors to conduct credential harvesting and account takeover operations against Microsoft 365 users.
highperson_alertThreat ActorF5 BIG-IP Exploitation Leads to Confluence Compromise and Lateral Movement
The threat actor behind this campaign remains unattributed. Motivation appears to be credential theft and network persistence within enterprise environments.
highbug_reportVulnerabilityMicrosoft Defender privilege escalation CVE-2026-41091 under active exploit
Microsoft Defender on Windows systems. Specific product versions not disclosed. Vulnerability allows local attackers to escalate privileges to SYSTEM level through improper link resolution handling.
criticalperson_alertThreat ActorMicrosoft Disrupts Fox Tempest Malware-Signing-as-a-Service Operation
Fox Tempest is a threat actor attributed by Microsoft as operating a malware-signing-as-a-service (MSaaS) business model. The actor exploited Microsoft's Artifact Signing system to provide malicious code signing services to other cybercriminals, enab…