Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
satellite_altDaily BriefCyber Threat Daily Brief — September 4, 2026
Today's briefing: 14 critical and 22 high-severity threats. A total of 47 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.
Latest Reports
30 / 1172 results
highbug_reportVulnerabilityPoC released for DirtyDecrypt LPE in Linux kernel (CVE-2026-31635)
Linux kernel - specific vulnerable versions not provided. Local privilege escalation vulnerability affecting systems running vulnerable kernel versions.
highbug_reportVulnerabilityOver 600 malicious npm packages published in Shai-Hulud campaign
npm ecosystem: 600+ malicious packages published by threat actors. Affects organizations using npm for JavaScript/Node.js dependency management. Specific package names not provided in summary.
highbug_reportVulnerabilitySonicWall releases patches for multiple high-severity vulnerabilities
SonicWall products (specific models and versions not disclosed in summary). CERT.BE advisory indicates multiple vulnerabilities requiring immediate patching across SonicWall product line.
highperson_alertThreat ActorShinyHunters Claims 7-Eleven Data Breach
ShinyHunters is a financially motivated cybercrime group known for large-scale data breaches and database theft. The group emerged around 2020 and has been linked to numerous high-profile data exfiltration incidents targeting organizations across var…
highbug_reportVulnerabilityMicrosoft sees rise in privilege escalation and identity abuse flaws
Microsoft products and services experiencing increased critical vulnerabilities focused on privilege escalation and identity abuse. Specific affected products and versions not detailed in available data.
highbug_reportVulnerabilityABB CoreSense path traversal flaw allows unauthenticated system access
ABB CoreSense HM (versions prior to v2.3.4) and CoreSense M10 (versions prior to v1.4.1.31). Path traversal vulnerability affects unauthenticated remote attackers.
criticalbug_reportVulnerabilityScadaBR 1.2.0 critical flaws enable unauthenticated remote code execution
ScadaBR version 1.2.0, a SCADA system used in critical infrastructure sectors including energy, water, and manufacturing worldwide. All four CVEs affect the same version.
criticalbug_reportVulnerabilityZKTeco CCTV cameras expose credentials via unauthenticated config port
ZKTeco CCTV cameras, specifically model SSC335-GC2063-Face-0b77, running firmware versions prior to V5.0.1.2.20260421. Vulnerability affects an undocumented configuration export port that allows unauthenticated access to camera credentials and config…
highbug_reportVulnerabilityKieback & Peter DDC controllers vulnerable to XSS attacks
Kieback & Peter DDC (Direct Digital Control) Building Controllers. Specific affected versions not disclosed in available data.
highbug_reportVulnerabilityBuffer overflow in PAN-OS User-ID portal enables unauthenticated RCE
Palo Alto Networks PAN-OS on PA-Series and VM-Series firewalls; Siemens RUGGEDCOM APE1808 devices. Specific affected PAN-OS versions not provided in summary.
criticalbug_reportVulnerabilityMicrosoft Exchange Server XSS flaw actively exploited for session hijacking
Microsoft Exchange Server (specific versions not disclosed). Cross-Site Scripting vulnerability enabling spoofing and session hijacking. No CVE assigned yet.
criticalbug_reportVulnerabilityCritical PAN-OS vulnerabilities enable auth bypass and code execution
Palo Alto Networks PAN-OS (specific versions not provided in summary). Affects authentication controls, code execution surface, and availability.
criticalbug_reportVulnerabilityCisco Catalyst SD-WAN auth bypass grants admin access to attackers
Cisco Catalyst SD-WAN platform. Specific affected versions not disclosed. Vulnerability allows authentication bypass leading to administrative access on SD-WAN infrastructure components.
highbug_reportVulnerabilityIvanti releases security updates for multiple products
Multiple Ivanti products affected. Specific product names, versions, and CVE identifiers not disclosed in available information. High severity rating indicates significant security risk.
criticalbug_reportVulnerabilityMultiple critical vulnerabilities in Fortinet products require patching
Fortinet products: FortiSandbox, FortiOS, FortiAP, FortiAnalyzer, and FortiManager. Specific affected versions not provided in advisory. Multiple vulnerabilities ranging from critical to medium severity.
highbug_reportVulnerabilityCode Runner MCP Server missing authentication flaw allows unauthorized access
Code Runner MCP Server (all versions not specified). The vulnerability affects critical functions within the server, allowing unauthenticated access to protected operations. Specific version ranges have not been disclosed by CERT.PL.
highbug_reportVulnerability3onedata GW1101 Modbus gateway vulnerable to OS command injection
3onedata GW1101-1D(RS-485)-TB-P Modbus gateways. Specific affected firmware versions not disclosed. These are industrial IoT devices used for Modbus protocol conversion in OT/ICS environments.
highperson_alertThreat ActorNCSC UK Issues Guidance on China-Nexus Covert Device Networks
China-nexus threat actors are state-sponsored groups linked to the People's Republic of China. These actors are motivated by strategic intelligence collection, espionage, and maintaining persistent access to foreign networks.
highperson_alertThreat ActorNCSC UK Issues Advisory on China-Linked Covert Network Tactics
China-linked threat actors employing covert network tactics to conceal malicious cyber activity. These actors are characterized by their use of sophisticated techniques to maintain persistent, stealthy access to compromised networks.
highpublicGeopoliticalUK NCSC Issues Guidance on China-Linked Covert Device Networks
The UK National Cyber Security Centre's release of defensive guidance targeting China-nexus covert networks reflects ongoing strategic competition between Western democracies and Beijing in cyberspace.
highbug_reportVulnerabilityOrca heat pumps lack authentication, transmit cleartext data to servers
Orca heat pumps (specific models and versions not disclosed). Vulnerability affects device-to-server communication and server-side data processing.
highbug_reportVulnerabilityMikroTik RouterOS auth bypass via certificate validation flaw
MikroTik RouterOS - versions not specified. Affects OpenVPN, CAPsMAN (wireless management), and 802.1X (Dot1x) services that rely on certificate-based authentication.
criticalbug_reportVulnerabilityCisco SD-WAN Manager auth bypass exploited in wild since 2023
Cisco Catalyst SD-WAN controllers and Cisco SD-WAN Manager. Specific affected versions not provided in advisory summary. CVE-2026-20127 allows administrative access compromise.
highpublicGeopoliticalLatvia faces elevated cyber threats amid geopolitical tensions in Q4 2025
Latvia's position as a NATO and EU member state on the eastern flank of the Alliance places it at the intersection of Western institutional security architecture and persistent regional tensions.
criticalbug_reportVulnerabilityIvanti EPMM critical RCE flaws under limited exploitation
Ivanti Endpoint Manager Mobile (EPMM) products. Specific affected versions not provided in advisory summary. Two critical vulnerabilities enabling unauthenticated remote code execution.
highbug_reportVulnerabilityFortinet FortiCloud SSO bypass exploited to extract LDAP passwords
Fortinet FortiGate appliances with FortiCloud SSO enabled. CVE-2025-59718 and CVE-2025-59719 allow authentication bypass. All FortiGate instances share a default static encryption key that enables decryption of LDAP credentials and private keys from…
criticalbug_reportVulnerabilityFortinet FortiCloud SSO auth bypass under active exploitation
Fortinet FortiCloud SSO SAML authentication processing (CVE-2025-59718, CVE-2025-59719). Affects management interfaces of FortiGate and potentially other Fortinet products using FortiCloud SSO.
criticalbug_reportVulnerabilityCisco Secure Email Gateway critical flaw unpatched, check for compromise
Cisco Secure Email Gateway and Cisco Secure Email and Web Manager. Specific affected versions not provided in advisory summary. No patch available as of December 17, 2025.
criticalbug_reportVulnerabilityReact Server Components RCE flaw enables unauthenticated remote execution
React Server Components and integrating frameworks (e.g., Next.js, Remix). All versions using React Server Components are potentially affected until patched.
criticalbug_reportVulnerabilityMicrosoft patches critical WSUS RCE flaw with public PoC exploit
Windows Server Update Service (WSUS) on Windows Server. Specific versions not disclosed in out-of-band update. Affects organizations running WSUS infrastructure for Windows update management.