Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports
Cyber Threat Daily Brief — September 4, 2026satellite_altDaily Brief
Threat Intel Brief·Daily Summary

Cyber Threat Daily Brief — September 4, 2026

Today's briefing: 14 critical and 22 high-severity threats. A total of 47 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.

14 Critical22 High47 analyses
schedule02:17 UTC
Read briefarrow_forward

Latest Reports

27 / 1172 results
Microsoft 365 Copilot SearchLeak allows data exfiltration via trusted linkhighbug_reportVulnerability
bug_reportVulnerability

Microsoft 365 Copilot SearchLeak allows data exfiltration via trusted link

Microsoft 365 Copilot Enterprise Search. All organizations using M365 Copilot with Enterprise Search enabled are potentially affected. Specific version details not disclosed.

Microsoft15 Jun · 13:09 UTC
China-Linked Espionage Group Deploys InfiniteRed via REDCap Servershighperson_alertThreat Actor
person_alertThreat Actor

China-Linked Espionage Group Deploys InfiniteRed via REDCap Servers

This activity is attributed to a China-linked espionage group targeting healthcare and medical research sectors. The actor's motivation appears to be intelligence collection focused on sensitive medical research data, consistent with strategic intere…

REDCap15 Jun · 12:00 UTC
SearchLeak in Microsoft 365 Copilot enables data theft via crafted URLscriticalbug_reportVulnerability
bug_reportVulnerability

SearchLeak in Microsoft 365 Copilot enables data theft via crafted URLs

Microsoft 365 Copilot Enterprise. All organizations using Copilot with access to mailbox, OneDrive, or SharePoint data are potentially affected. Specific vulnerable versions not disclosed.

Microsoft15 Jun · 11:00 UTC
ShinyHunters Breaches 137K+ School Staff via Salesforce Attackhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Breaches 137K+ School Staff via Salesforce Attack

ShinyHunters is a financially motivated cybercrime actor specializing in large-scale data theft and extortion operations. The group has established a reputation for targeting cloud-based platforms and third-party service providers to compromise downs…

Salesforce15 Jun · 10:38 UTC
Responsive FileManager RCE via unrestricted file upload (CVE-2026-5482)highbug_reportVulnerability
bug_reportVulnerability

Responsive FileManager RCE via unrestricted file upload (CVE-2026-5482)

Responsive FileManager (versions not specified). The vulnerability affects file upload mechanisms allowing unrestricted file uploads leading to remote code execution.

CVE-2026-548215 Jun · 09:55 UTC
Quick.CMS deserialization flaw enables potential remote code executionhighbug_reportVulnerability
bug_reportVulnerability

Quick.CMS deserialization flaw enables potential remote code execution

Quick.CMS software (specific versions not disclosed). Affects systems where untrusted data is deserialized without proper validation.

CVE-2026-1186015 Jun · 08:55 UTC
Supply chain attack hits PushEngage, OptinMonster, TrustPulse pluginscriticalbug_reportVulnerability
bug_reportVulnerability

Supply chain attack hits PushEngage, OptinMonster, TrustPulse plugins

WordPress sites using PushEngage, OptinMonster, and TrustPulse plugins. All versions loading compromised JavaScript files from vendor infrastructure are affected.

PushEngage15 Jun · 07:59 UTC
Multiple high-severity vulnerabilities in GitLab CE and EE require patchinghighbug_reportVulnerability
bug_reportVulnerability

Multiple high-severity vulnerabilities in GitLab CE and EE require patching

GitLab Community Edition (CE) and Enterprise Edition (EE). Specific affected versions not provided in advisory; typically affects versions prior to latest security release.

GitLab15 Jun · 06:25 UTC
Palo Alto PAN-OS GlobalProtect auth bypass under active exploitationhighbug_reportVulnerability
bug_reportVulnerability

Palo Alto PAN-OS GlobalProtect auth bypass under active exploitation

Palo Alto Networks PAN-OS GlobalProtect VPN portal and gateway components. Specific affected versions not disclosed in provided data. CVE-2026-0257, CVSS 7.8 (High).

CVE-2026-025715 Jun · 04:17 UTC
FBI disrupts Outsider Enterprise Chinese phishing-as-a-service platformhighperson_alertThreat Actor
person_alertThreat Actor

FBI disrupts Outsider Enterprise Chinese phishing-as-a-service platform

Outsider Enterprise is a Chinese phishing-as-a-service (PhaaS) operation disrupted by the FBI in coordination with Google and Black Lotus Labs. The actor operated thousands of phishing websites designed to harvest credit card data and passwords from…

BleepingComputer14 Jun · 12:36 UTC
Former Iowa school IT employee sentenced for insider cyberattackhighpublicGeopolitical
publicGeopolitical

Former Iowa school IT employee sentenced for insider cyberattack

This incident represents a domestic insider threat case within the United States education sector, rather than a state-sponsored or geopolitically motivated cyberattack. The prosecution and sentencing reflect U.S.

BleepingComputer13 Jun · 18:53 UTC
Chinese state-sponsored hackers maintain 10-year persistent accesscriticalperson_alertThreat Actor
person_alertThreat Actor

Chinese state-sponsored hackers maintain 10-year persistent access

Chinese state-sponsored hackers, likely an advanced persistent threat (APT) group operating on behalf of the People's Republic of China. The actor demonstrated exceptional operational security and patience, maintaining covert access to a target organ…

BleepingComputer13 Jun · 12:06 UTC
Splunk Enterprise RCE flaw allows unauthenticated remote code executioncriticalbug_reportVulnerability
bug_reportVulnerability

Splunk Enterprise RCE flaw allows unauthenticated remote code execution

Splunk Enterprise versions below 10.2.4 and 10.0.7. The vulnerability enables unauthenticated attackers to perform arbitrary file operations and achieve remote code execution. CVSS score 9.8 (Critical).

CVE-2026-2025313 Jun · 11:23 UTC
US orders Anthropic to restrict foreign access to advanced AI modelshighpublicGeopolitical
publicGeopolitical

US orders Anthropic to restrict foreign access to advanced AI models

The directive appears to represent an expansion of US export control philosophy into the AI domain, treating advanced language models as dual-use technologies with national security implications.

Anthropic13 Jun · 08:01 UTC
U.S. orders Anthropic to suspend foreign access to advanced AI modelshighpublicGeopolitical
publicGeopolitical

U.S. orders Anthropic to suspend foreign access to advanced AI models

The directive represents an escalation in U.S. efforts to control the diffusion of advanced artificial intelligence capabilities, treating frontier AI models as dual-use technologies with strategic implications.

Anthropic13 Jun · 03:42 UTC
Arch User Repository supply chain attack: 400+ packages backdooredcriticalbug_reportVulnerability
bug_reportVulnerability

Arch User Repository supply chain attack: 400+ packages backdoored

Arch Linux users who installed or updated packages from the Arch User Repository (AUR) during the compromise window. Over 400 AUR packages contained malicious build scripts deploying a Rust-based infostealer.

Arch Linux12 Jun · 17:33 UTC
Chinese Cybercrime Network Weaponizes Google Gemini AI for SMS Phishinghighperson_alertThreat Actor
person_alertThreat Actor

Chinese Cybercrime Network Weaponizes Google Gemini AI for SMS Phishing

A Chinese cybercrime network operating a phishing-as-a-service (PhaaS) platform called Outsider. The group weaponizes Google's Gemini AI to craft and conduct SMS-based phishing attacks (smishing) targeting American victims.

Google12 Jun · 16:59 UTC
10-year-old phpBB auth bypass enables attacker login as any userhighbug_reportVulnerability
bug_reportVulnerability

10-year-old phpBB auth bypass enables attacker login as any user

phpBB forum software, versions spanning approximately 10 years (specific affected versions not disclosed). All installations running unpatched versions are vulnerable.

phpBB12 Jun · 16:19 UTC
Velvet Ant: China-linked APT backdoors Linux auth for decade-long accesscriticalperson_alertThreat Actor
person_alertThreat Actor

Velvet Ant: China-linked APT backdoors Linux auth for decade-long access

Velvet Ant (G1047) is a China-linked advanced persistent threat actor characterized by exceptional operational security and long-term persistence capabilities.

Linux12 Jun · 16:17 UTC
Conti Operator Pleads Guilty After Extradition to United Stateshighperson_alertThreat Actor
person_alertThreat Actor

Conti Operator Pleads Guilty After Extradition to United States

Conti is a prolific ransomware-as-a-service (RaaS) operation that emerged in 2020 and became one of the most active and financially successful cybercrime groups before its infrastructure was leaked and operations fragmented in 2022.

BleepingComputer12 Jun · 15:54 UTC
400+ Arch User Repository packages compromised with rootkit and infostealercriticalbug_reportVulnerability
bug_reportVulnerability

400+ Arch User Repository packages compromised with rootkit and infostealer

Arch Linux users who installed or updated packages from the Arch User Repository (AUR). Over 400 AUR packages confirmed compromised. Specific package names and versions not yet disclosed.

Arch Linux12 Jun · 15:03 UTC
Oracle PeopleSoft RCE actively exploited, immediate patching requiredcriticalbug_reportVulnerability
bug_reportVulnerability

Oracle PeopleSoft RCE actively exploited, immediate patching required

Oracle PeopleSoft (specific versions not disclosed in alert). Remote code execution vulnerability affecting internet-facing PeopleSoft instances.

Oracle12 Jun · 12:39 UTC
AI coding agents vulnerable to code execution via crafted Sentry errorshighbug_reportVulnerability
bug_reportVulnerability

AI coding agents vulnerable to code execution via crafted Sentry errors

AI coding agents (e.g., GitHub Copilot, Cursor, Aider) integrated with Sentry error-tracking platform. Affects development environments where AI agents have code execution permissions and process Sentry error reports.

Sentry12 Jun · 10:04 UTC
UNC1151/Ghostwriter Targets Polish Gmail Accounts in Phishing Campaignhighperson_alertThreat Actor
person_alertThreat Actor

UNC1151/Ghostwriter Targets Polish Gmail Accounts in Phishing Campaign

UNC1151, also known as Ghostwriter, is a threat actor group attributed by FireEye/Mandiant that has conducted sustained information operations and cyber espionage activities.

Google12 Jun · 09:00 UTC
Novo Nordisk discloses clinical trial data breach in DenmarkhighpublicGeopolitical
publicGeopolitical

Novo Nordisk discloses clinical trial data breach in Denmark

The breach at Novo Nordisk, a Danish pharmaceutical giant controlling approximately 50% of the global insulin market, highlights the strategic vulnerability of critical healthcare infrastructure.

Novo Nordisk12 Jun · 08:13 UTC
LangGraph AI framework patched for critical RCE via SQL injection chaincriticalbug_reportVulnerability
bug_reportVulnerability

LangGraph AI framework patched for critical RCE via SQL injection chain

LangGraph (LangChain's open-source AI agent framework). Specific vulnerable versions not disclosed; patches available. Affects deployments using LangGraph for AI agent orchestration.

LangChain12 Jun · 07:50 UTC
INTERPOL arrests Guedz, admin of Sniper Dz phishing-as-a-service platformhighperson_alertThreat Actor
person_alertThreat Actor

INTERPOL arrests Guedz, admin of Sniper Dz phishing-as-a-service platform

Guedz is identified as the primary administrator of Sniper Dz, a phishing-as-a-service (PhaaS) platform that operated for approximately a decade across the Middle East and North Africa (MENA) region.

The Hacker News12 Jun · 06:52 UTC