Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
satellite_altDaily BriefCyber Threat Daily Brief — July 20, 2026
Today's briefing: 3 critical and 4 high-severity threats. A total of 10 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.
Latest Reports
28 / 584 results
highperson_alertThreat ActorScattered Spider Member Extradited to U.S. on Federal Hacking Charges
Scattered Spider (also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944) is a financially motivated threat actor group known for sophisticated social engineering and identity-based attacks.
highperson_alertThreat ActorMassive SEO-Poisoned Campaign Distributes AsyncRAT via ScreenConnect
The threat actor behind this campaign remains unattributed. Motivation appears to be financially driven, consistent with commodity RAT deployment for access brokering, credential theft, or follow-on ransomware operations.
highpublicGeopoliticalDHS Confirms Breach of Homeland Security Information Network
The compromise of the Homeland Security Information Network (HSIN) represents a significant breach of a critical federal information-sharing infrastructure.
highperson_alertThreat ActorVEIL#DROP campaign delivers PureLogs stealer via Blogger pages
VEIL#DROP is a multi-stage malware delivery campaign identified by Securonix researchers. The campaign employs social engineering tactics and abuses legitimate Blogger platform infrastructure to distribute PureLogs, an information-stealing malware.
highbug_reportVulnerabilityPassword-spray campaign hits Microsoft 365 with 81M login attempts
Microsoft 365 environments (Exchange Online, Azure AD/Entra ID, SharePoint, Teams). All organizations using M365 cloud services are potential targets. Attack focuses on user authentication endpoints.
highbug_reportVulnerabilityOusaban banking trojan targets Spain and Portugal via phishing
Windows users in Spain and Portugal. Ousaban banking trojan campaign using fake PDF lures with geolocation filtering and steganography techniques. No specific product vulnerability; threat actor campaign identified by Fortinet FortiGuard Labs in May…
criticalbug_reportVulnerabilityAdobe patches CVSS 10.0 flaws in ColdFusion and Campaign Classic
Adobe ColdFusion and Adobe Campaign Classic (specific versions not provided). Vulnerabilities include arbitrary code execution, privilege escalation, arbitrary file system read, and security feature bypass.
criticalbug_reportVulnerabilityCursor AI editor vulnerable to sandbox escape via prompt injection
Cursor AI code editor, all versions prior to patch. Both CVE-2026-50548 (CVSS 9.8) and CVE-2026-50549 (CVSS 9.3) enable sandbox escape and arbitrary command execution via prompt injection without user interaction.
criticalbug_reportVulnerabilityProgress Kemp LoadMaster RCE under active exploitation (CVE-2026-8037)
Progress Kemp LoadMaster load balancers. Specific affected versions not disclosed. Pre-authentication vulnerability allows unauthenticated remote attackers to execute OS commands.
highperson_alertThreat ActorDeepSeek AI Used to Generate Novel Browser-Based Ransomware
DeepSeek refers to the AI model leveraged by unknown threat actors to generate functional browser-based ransomware code. This marks the first documented instance of a frontier AI model being weaponized to create a novel ransomware technique.
criticalbug_reportVulnerability900+ Oracle E-Business Suite instances exposed, under active attack
Oracle E-Business Suite instances exposed to the internet (900+ confirmed). Specific vulnerable versions not disclosed; critical severity vulnerability being exploited.
highbug_reportVulnerabilityLLM hallucinations exploited for supply chain attacks via phantom domains
Organizations using LLMs for development assistance, code generation, or package recommendations. Developers relying on AI-generated domain/package suggestions without verification.
highbug_reportVulnerabilityTrojanized Pyrogram forks on PyPI target Telegram bot developers
Python developers using PyPI packages for Telegram bot development. Malicious forks of Pyrogram library active since November 2024. Affects developers who may have installed compromised packages instead of legitimate Pyrogram.
highbug_reportVulnerabilityAI agents using Model Context Protocol vulnerable to tool poisoning attacks
AI agents implementing Microsoft's Model Context Protocol (MCP). Specific products and versions not disclosed. Affects organizations deploying MCP-based AI agents with access to sensitive internal data and external tool integrations.
highperson_alertThreat ActorRustDuck Botnet Targets IoT Devices for DDoS Operations
RustDuck is a two-stage malware family written in Rust, designed to compromise Internet of Things (IoT) devices including home routers, IP cameras, Android set-top boxes, and inadequately secured servers.
criticalbug_reportVulnerabilityLangflow RCE (CVE-2026-33017) actively exploited for cryptomining
Langflow AI application framework, all exposed endpoints vulnerable to unauthenticated remote code execution. Specific affected versions not disclosed; assume all unpatched instances at risk.
highbug_reportVulnerabilityFake Perplexity AI Chrome extension hijacks search traffic on Web Store
Google Chrome users who installed the malicious Perplexity AI impersonator extension from the Chrome Web Store. Affects organizations and individuals using Chrome browser seeking AI productivity tools.
highperson_alertThreat ActorSilent Swap Campaign Targets Cryptocurrency via Malicious Browser Extensions
Silent Swap is an active cybercrime campaign leveraging malicious browser extensions to conduct cryptocurrency theft. The operation distributes unsigned installers written in both .NET and Golang variants, masquerading as a legitimate Google Notes br…
highbug_reportVulnerabilityGuardFall shell injection bypasses safety checks in 10 of 11 AI coding agents
10 out of 11 tested open-source AI coding and computer-use agents are vulnerable to GuardFall shell injection bypass. Only "Continue" agent demonstrated resistance.
highbug_reportVulnerability63% of iOS AI chatbot apps leak API keys via unencrypted network traffic
282 out of 444 iOS AI chatbot applications expose paid AI service credentials (API keys, tokens, backend endpoints) in plaintext network traffic. Affects apps integrating third-party AI services (OpenAI, Anthropic, Google, etc.).
highperson_alertThreat ActorPre-Planned Fraud Campaign Targets FIFA World Cup 2026 Across Sectors
The threat actor behind this campaign remains unattributed. Motivation appears financially driven, leveraging the global interest in FIFA World Cup 2026 to conduct fraud operations.
criticalbug_reportVulnerabilitySimpleHelp OpenID auth bypass (CVE-2026-48558) exploited in wild
SimpleHelp remote support software, all versions using OpenID Connect authentication. CVE-2026-48558 is a critical authentication bypass (CVSS 10.0) in the OpenID Connect flow.
highpublicGeopoliticalAflac Japan breach exposes personal and financial data
The breach at Aflac's Japan subsidiary underscores the persistent targeting of financial services firms operating in major economies. Japan represents a high-value target environment due to its advanced digital economy, aging population with signific…
highbug_reportVulnerabilityAirDrop and Quick Share flaws enable wireless DoS and security bypass
Apple AirDrop and Google Quick Share wireless file transfer features on iOS, macOS, and Android devices. Specific affected versions not disclosed. Attack requires physical proximity (wireless range).
highbug_reportVulnerabilityAI browsers leak credentials via BioShocking social engineering attack
Six AI browsers and assistants including OpenAI ChatGPT Atlas, Perplexity Comet, and Anthropic Claude browser extension. Attack exploits AI reasoning vulnerabilities to extract user credentials through game-based social engineering.
highperson_alertThreat ActorShinyHunters Exploits Oracle PeopleSoft Zero-Day in Nissan Breach
ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has established a pattern of exploiting vulnerabilities in enterprise applications to exfiltrate sensitive data, which is th…
highperson_alertThreat ActorShinyHunters Exploits Oracle PeopleSoft Zero-Day at NAIC
ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has historically targeted organizations to exfiltrate sensitive data, which is then leveraged for extortion or sold on under…
highperson_alertThreat ActorMalicious Chrome Extension Impersonates Perplexity AI to Intercept Searches
The threat actor behind this campaign remains unattributed. The operation demonstrates a financially or espionage-motivated adversary leveraging social engineering through brand impersonation of Perplexity AI, a popular search technology.