Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-20 · 02:03 UTC
articleTotal: 593 reports
Cyber Threat Daily Brief — July 20, 2026satellite_altDaily Brief
Threat Intel Brief·Daily Summary

Cyber Threat Daily Brief — July 20, 2026

Today's briefing: 3 critical and 4 high-severity threats. A total of 10 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.

3 Critical4 High10 analyses
schedule02:03 UTC
Read briefarrow_forward

Latest Reports

28 / 584 results
Scattered Spider Member Extradited to U.S. on Federal Hacking Chargeshighperson_alertThreat Actor
person_alertThreat Actor

Scattered Spider Member Extradited to U.S. on Federal Hacking Charges

Scattered Spider (also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944) is a financially motivated threat actor group known for sophisticated social engineering and identity-based attacks.

The Hacker News17:28 UTC
Massive SEO-Poisoned Campaign Distributes AsyncRAT via ScreenConnecthighperson_alertThreat Actor
person_alertThreat Actor

Massive SEO-Poisoned Campaign Distributes AsyncRAT via ScreenConnect

The threat actor behind this campaign remains unattributed. Motivation appears to be financially driven, consistent with commodity RAT deployment for access brokering, credential theft, or follow-on ransomware operations.

OBS Studio15:53 UTC
DHS Confirms Breach of Homeland Security Information NetworkhighpublicGeopolitical
publicGeopolitical

DHS Confirms Breach of Homeland Security Information Network

The compromise of the Homeland Security Information Network (HSIN) represents a significant breach of a critical federal information-sharing infrastructure.

Department of Homeland Security15:32 UTC
VEIL#DROP campaign delivers PureLogs stealer via Blogger pageshighperson_alertThreat Actor
person_alertThreat Actor

VEIL#DROP campaign delivers PureLogs stealer via Blogger pages

VEIL#DROP is a multi-stage malware delivery campaign identified by Securonix researchers. The campaign employs social engineering tactics and abuses legitimate Blogger platform infrastructure to distribute PureLogs, an information-stealing malware.

Google Blogger15:18 UTC
Password-spray campaign hits Microsoft 365 with 81M login attemptshighbug_reportVulnerability
bug_reportVulnerability

Password-spray campaign hits Microsoft 365 with 81M login attempts

Microsoft 365 environments (Exchange Online, Azure AD/Entra ID, SharePoint, Teams). All organizations using M365 cloud services are potential targets. Attack focuses on user authentication endpoints.

Microsoft14:38 UTC
Ousaban banking trojan targets Spain and Portugal via phishinghighbug_reportVulnerability
bug_reportVulnerability

Ousaban banking trojan targets Spain and Portugal via phishing

Windows users in Spain and Portugal. Ousaban banking trojan campaign using fake PDF lures with geolocation filtering and steganography techniques. No specific product vulnerability; threat actor campaign identified by Fortinet FortiGuard Labs in May…

Fortinet13:26 UTC
Adobe patches CVSS 10.0 flaws in ColdFusion and Campaign Classiccriticalbug_reportVulnerability
bug_reportVulnerability

Adobe patches CVSS 10.0 flaws in ColdFusion and Campaign Classic

Adobe ColdFusion and Adobe Campaign Classic (specific versions not provided). Vulnerabilities include arbitrary code execution, privilege escalation, arbitrary file system read, and security feature bypass.

Adobe13:25 UTC
Cursor AI editor vulnerable to sandbox escape via prompt injectioncriticalbug_reportVulnerability
bug_reportVulnerability

Cursor AI editor vulnerable to sandbox escape via prompt injection

Cursor AI code editor, all versions prior to patch. Both CVE-2026-50548 (CVSS 9.8) and CVE-2026-50549 (CVSS 9.3) enable sandbox escape and arbitrary command execution via prompt injection without user interaction.

CVE-2026-5054812:42 UTC
Progress Kemp LoadMaster RCE under active exploitation (CVE-2026-8037)criticalbug_reportVulnerability
bug_reportVulnerability

Progress Kemp LoadMaster RCE under active exploitation (CVE-2026-8037)

Progress Kemp LoadMaster load balancers. Specific affected versions not disclosed. Pre-authentication vulnerability allows unauthenticated remote attackers to execute OS commands.

CVE-2026-803711:56 UTC
DeepSeek AI Used to Generate Novel Browser-Based Ransomwarehighperson_alertThreat Actor
person_alertThreat Actor

DeepSeek AI Used to Generate Novel Browser-Based Ransomware

DeepSeek refers to the AI model leveraged by unknown threat actors to generate functional browser-based ransomware code. This marks the first documented instance of a frontier AI model being weaponized to create a novel ransomware technique.

Chromium10:59 UTC
900+ Oracle E-Business Suite instances exposed, under active attackcriticalbug_reportVulnerability
bug_reportVulnerability

900+ Oracle E-Business Suite instances exposed, under active attack

Oracle E-Business Suite instances exposed to the internet (900+ confirmed). Specific vulnerable versions not disclosed; critical severity vulnerability being exploited.

Oracle10:30 UTC
LLM hallucinations exploited for supply chain attacks via phantom domainshighbug_reportVulnerability
bug_reportVulnerability

LLM hallucinations exploited for supply chain attacks via phantom domains

Organizations using LLMs for development assistance, code generation, or package recommendations. Developers relying on AI-generated domain/package suggestions without verification.

Unit 42 (Palo Alto)23:00 UTC
Trojanized Pyrogram forks on PyPI target Telegram bot developershighbug_reportVulnerability
bug_reportVulnerability

Trojanized Pyrogram forks on PyPI target Telegram bot developers

Python developers using PyPI packages for Telegram bot development. Malicious forks of Pyrogram library active since November 2024. Affects developers who may have installed compromised packages instead of legitimate Pyrogram.

PyPI19:02 UTC
AI agents using Model Context Protocol vulnerable to tool poisoning attackshighbug_reportVulnerability
bug_reportVulnerability

AI agents using Model Context Protocol vulnerable to tool poisoning attacks

AI agents implementing Microsoft's Model Context Protocol (MCP). Specific products and versions not disclosed. Affects organizations deploying MCP-based AI agents with access to sensitive internal data and external tool integrations.

Microsoft15:46 UTC
RustDuck Botnet Targets IoT Devices for DDoS Operationshighperson_alertThreat Actor
person_alertThreat Actor

RustDuck Botnet Targets IoT Devices for DDoS Operations

RustDuck is a two-stage malware family written in Rust, designed to compromise Internet of Things (IoT) devices including home routers, IP cameras, Android set-top boxes, and inadequately secured servers.

Generic routers15:45 UTC
Langflow RCE (CVE-2026-33017) actively exploited for cryptominingcriticalbug_reportVulnerability
bug_reportVulnerability

Langflow RCE (CVE-2026-33017) actively exploited for cryptomining

Langflow AI application framework, all exposed endpoints vulnerable to unauthenticated remote code execution. Specific affected versions not disclosed; assume all unpatched instances at risk.

CVE-2026-3301713:47 UTC
Fake Perplexity AI Chrome extension hijacks search traffic on Web Storehighbug_reportVulnerability
bug_reportVulnerability

Fake Perplexity AI Chrome extension hijacks search traffic on Web Store

Google Chrome users who installed the malicious Perplexity AI impersonator extension from the Chrome Web Store. Affects organizations and individuals using Chrome browser seeking AI productivity tools.

Google13:46 UTC
Silent Swap Campaign Targets Cryptocurrency via Malicious Browser Extensionshighperson_alertThreat Actor
person_alertThreat Actor

Silent Swap Campaign Targets Cryptocurrency via Malicious Browser Extensions

Silent Swap is an active cybercrime campaign leveraging malicious browser extensions to conduct cryptocurrency theft. The operation distributes unsigned installers written in both .NET and Golang variants, masquerading as a legitimate Google Notes br…

Google13:40 UTC
GuardFall shell injection bypasses safety checks in 10 of 11 AI coding agentshighbug_reportVulnerability
bug_reportVulnerability

GuardFall shell injection bypasses safety checks in 10 of 11 AI coding agents

10 out of 11 tested open-source AI coding and computer-use agents are vulnerable to GuardFall shell injection bypass. Only "Continue" agent demonstrated resistance.

Adversa AI12:26 UTC
63% of iOS AI chatbot apps leak API keys via unencrypted network traffichighbug_reportVulnerability
bug_reportVulnerability

63% of iOS AI chatbot apps leak API keys via unencrypted network traffic

282 out of 444 iOS AI chatbot applications expose paid AI service credentials (API keys, tokens, backend endpoints) in plaintext network traffic. Affects apps integrating third-party AI services (OpenAI, Anthropic, Google, etc.).

The Hacker News11:49 UTC
Pre-Planned Fraud Campaign Targets FIFA World Cup 2026 Across Sectorshighperson_alertThreat Actor
person_alertThreat Actor

Pre-Planned Fraud Campaign Targets FIFA World Cup 2026 Across Sectors

The threat actor behind this campaign remains unattributed. Motivation appears financially driven, leveraging the global interest in FIFA World Cup 2026 to conduct fraud operations.

The Hacker News09:30 UTC
SimpleHelp OpenID auth bypass (CVE-2026-48558) exploited in wildcriticalbug_reportVulnerability
bug_reportVulnerability

SimpleHelp OpenID auth bypass (CVE-2026-48558) exploited in wild

SimpleHelp remote support software, all versions using OpenID Connect authentication. CVE-2026-48558 is a critical authentication bypass (CVSS 10.0) in the OpenID Connect flow.

CVE-2026-4855809:18 UTC
Aflac Japan breach exposes personal and financial datahighpublicGeopolitical
publicGeopolitical

Aflac Japan breach exposes personal and financial data

The breach at Aflac's Japan subsidiary underscores the persistent targeting of financial services firms operating in major economies. Japan represents a high-value target environment due to its advanced digital economy, aging population with signific…

Aflac09:12 UTC
AirDrop and Quick Share flaws enable wireless DoS and security bypasshighbug_reportVulnerability
bug_reportVulnerability

AirDrop and Quick Share flaws enable wireless DoS and security bypass

Apple AirDrop and Google Quick Share wireless file transfer features on iOS, macOS, and Android devices. Specific affected versions not disclosed. Attack requires physical proximity (wireless range).

Apple07:27 UTC
AI browsers leak credentials via BioShocking social engineering attackhighbug_reportVulnerability
bug_reportVulnerability

AI browsers leak credentials via BioShocking social engineering attack

Six AI browsers and assistants including OpenAI ChatGPT Atlas, Perplexity Comet, and Anthropic Claude browser extension. Attack exploits AI reasoning vulnerabilities to extract user credentials through game-based social engineering.

OpenAI06:37 UTC
ShinyHunters Exploits Oracle PeopleSoft Zero-Day in Nissan Breachhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Exploits Oracle PeopleSoft Zero-Day in Nissan Breach

ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has established a pattern of exploiting vulnerabilities in enterprise applications to exfiltrate sensitive data, which is th…

Oracle18:40 UTC
ShinyHunters Exploits Oracle PeopleSoft Zero-Day at NAIChighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Exploits Oracle PeopleSoft Zero-Day at NAIC

ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has historically targeted organizations to exfiltrate sensitive data, which is then leveraged for extortion or sold on under…

Oracle18:30 UTC
Malicious Chrome Extension Impersonates Perplexity AI to Intercept Searcheshighperson_alertThreat Actor
person_alertThreat Actor

Malicious Chrome Extension Impersonates Perplexity AI to Intercept Searches

The threat actor behind this campaign remains unattributed. The operation demonstrates a financially or espionage-motivated adversary leveraging social engineering through brand impersonation of Perplexity AI, a popular search technology.

Google16:40 UTC