Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 307 results
Active filter:✕ clear
Credential-stealing worm compromises 400+ npm packages via auto-propagationcriticalbug_reportVulnerability
bug_reportVulnerability

Credential-stealing worm compromises 400+ npm packages via auto-propagation

Over 400 npm packages across multiple unrelated publishers, including keyv, flat-cache, cache-manager, and other major enterprise software ecosystem packages. Affects developer workstations and CI/CD environments with npm lifecycle scripts enabled.

npm4 Aug · 21:46 UTC
ChainDrop worm compromises 1,300+ npm packages with 2B monthly downloadscriticalbug_reportVulnerability
bug_reportVulnerability

ChainDrop worm compromises 1,300+ npm packages with 2B monthly downloads

Over 1,300 npm packages (1,381 versions) including Keyv, Cacheable, flat-cache, and file-entry-cache. Attack originated from compromised GitHub account of Keyv maintainer.

npm4 Aug · 13:24 UTC
npm worm from keyv@6.0.0 poisons 353+ packages, steals credentials via hookscriticalbug_reportVulnerability
bug_reportVulnerability

npm worm from keyv@6.0.0 poisons 353+ packages, steals credentials via hooks

npm packages: keyv@6.0.0 and at least 353 poisoned versions across 79 package names (SafeDep verified); broader estimates reach 868 packages. Affects developers and CI/CD environments using npm clients prior to npm 12, Claude Code, and VS Code.

npm4 Aug · 11:30 UTC
N-Central actively exploited vulnerability requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

N-Central actively exploited vulnerability requires immediate patching

N-Central remote monitoring and management (RMM) platform. Specific affected versions not disclosed in available advisory. CVE identifier not yet assigned or published.

N-Central3 Aug · 11:45 UTC
N-able N-central auth bypass exploited; incomplete patch requires upgradecriticalbug_reportVulnerability
bug_reportVulnerability

N-able N-central auth bypass exploited; incomplete patch requires upgrade

N-able N-central builds prior to 2026.3.1.7. All versions before the August 2 emergency hotfix are vulnerable. Affects MSPs and IT teams using N-central for remote monitoring and management of customer endpoints.

CVE-2026-185773 Aug · 04:41 UTC
COLDCARD wallet RNG flaw exploited to steal $88.6M in Bitcoincriticalbug_reportVulnerability
bug_reportVulnerability

COLDCARD wallet RNG flaw exploited to steal $88.6M in Bitcoin

COLDCARD hardware wallets: Mk2/Mk3 firmware 4.0.1-4.1.9, Mk4/Mk5 before 5.6.0 (standard) or 6.6.0X (Edge), Q devices before 1.5.0Q (standard) or 6.6.0QX (Edge). Seeds generated using the flawed RNG are compromised.

COLDCARD2 Aug · 19:14 UTC
Coldcard wallet PRNG flaw enabled $70M Bitcoin theft in 41 minutescriticalbug_reportVulnerability
bug_reportVulnerability

Coldcard wallet PRNG flaw enabled $70M Bitcoin theft in 41 minutes

Coldcard hardware wallets (Coinkite): Mk2 and Mk3 firmware 4.0.0–4.1.9 (fixed in 4.2.0); Mk4 and Mk5 before 5.6.0; Q model before 1.5.0Q; Edge builds before 6.6.0X (Mk4/Mk5) and 6.6.0QX (Q).

Coinkite1 Aug · 15:17 UTC
Rails Active Storage flaw enables file read and RCE by unauthenticated userscriticalbug_reportVulnerability
bug_reportVulnerability

Rails Active Storage flaw enables file read and RCE by unauthenticated users

Ruby on Rails applications using the Active Storage framework. Specific vulnerable versions not provided in available data. Patched versions released by Rails team.

Ruby on Rails1 Aug · 12:20 UTC
Adobe Campaign Classic CVSS 10.0 flaw allows code execution without interactioncriticalbug_reportVulnerability
bug_reportVulnerability

Adobe Campaign Classic CVSS 10.0 flaw allows code execution without interaction

Adobe Campaign Classic (ACC) v7 versions prior to 7.4.3 build 9398 on Windows and Linux. The vulnerability affects the enterprise marketing automation platform used for customer campaign management.

CVE-2026-484491 Aug · 05:12 UTC
Adobe Campaign Classic critical RCE and file read flaws require patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Adobe Campaign Classic critical RCE and file read flaws require patching

Adobe Campaign Classic (specific versions not disclosed in advisory). Two vulnerabilities: one critical severity enabling arbitrary code execution, one high severity allowing file system read access.

Adobe31 Jul · 13:59 UTC
Critical vCenter vulnerabilities require immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical vCenter vulnerabilities require immediate patching

VMware vCenter Server component across multiple VMware product deployments. Specific affected versions not provided in advisory. Widespread impact expected given vCenter's role in VMware infrastructure management.

VMware31 Jul · 13:45 UTC
Cisco Secure Firewall Management Center under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Cisco Secure Firewall Management Center under active exploitation

Cisco Secure Firewall Management Center (formerly Firepower Management Center). Specific affected versions not disclosed in available data. Vulnerability details including CVE identifier not yet published.

Cisco31 Jul · 06:58 UTC
JetBrains TeamCity auth bypass enables RCE on all on-premises versionscriticalbug_reportVulnerability
bug_reportVulnerability

JetBrains TeamCity auth bypass enables RCE on all on-premises versions

JetBrains TeamCity On-Premises, all versions prior to 2025.11.7 and 2026.1.3. TeamCity Cloud is not affected. CVE-2026-63077 allows authentication bypass via agent polling protocol over HTTPS, leading to remote code execution with server process priv…

JetBrains30 Jul · 20:01 UTC
VMware vCenter, ESXi critical flaws enable auth bypass and VM escapescriticalbug_reportVulnerability
bug_reportVulnerability

VMware vCenter, ESXi critical flaws enable auth bypass and VM escapes

VMware vCenter Server (versions prior to 9.1.0.0300, 9.0.2.0100, 8.0 U3k), VMware ESXi (versions prior to 9.1.0.0200, 9.0.2.0100, 8.0 U3k), VMware Workstation and Fusion (25H2 and earlier), VMware Cloud Foundation 5.x, VMware vSphere Foundation, VMwa…

VMware30 Jul · 16:00 UTC
Azure Cosmos DB sandbox escape exposed platform-wide key to all databasescriticalbug_reportVulnerability
bug_reportVulnerability

Azure Cosmos DB sandbox escape exposed platform-wide key to all databases

Microsoft Azure Cosmos DB, all customer tenants across all regions. Affects Gremlin, SQL, MongoDB, and Cassandra APIs. Vulnerability active from unknown date until July 2026 full remediation.

Microsoft30 Jul · 11:34 UTC
Multiple critical Xen Project vulnerabilities require immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Multiple critical Xen Project vulnerabilities require immediate patching

Xen Project hypervisor - specific affected versions not disclosed in available advisory. Impacts organizations running Xen-based virtualization infrastructure including cloud providers and enterprise data centers.

Xen Project30 Jul · 06:04 UTC
North Korea linked to npm supply chain attacks on debug, chalk, axioscriticalbug_reportVulnerability
bug_reportVulnerability

North Korea linked to npm supply chain attacks on debug, chalk, axios

npm packages debug, chalk, axios, typo-crypto, and Mastra (over 2 billion weekly downloads combined). Attacks spanned March 2025 through March 2026. Maintainer accounts compromised via phishing; malicious code injected to steal cryptocurrency wallet…

npm30 Jul · 04:05 UTC
Laundry Bear exploits Exchange OWA zero-day to deploy OWAReaper backdoorcriticalperson_alertThreat Actor
person_alertThreat Actor

Laundry Bear exploits Exchange OWA zero-day to deploy OWAReaper backdoor

Laundry Bear (also tracked as Void Blizzard, TA488 by Proofpoint) is a Russian state-sponsored threat actor focused on long-term email intelligence collection.

Microsoft29 Jul · 21:44 UTC
Rails Active Storage flaw allows file read via crafted image uploadscriticalbug_reportVulnerability
bug_reportVulnerability

Rails Active Storage flaw allows file read via crafted image uploads

Ruby on Rails 7.0.0–7.2.3.1, 8.0.0–8.0.5, 8.1.0–8.1.3 using Active Storage with libvips for image processing and accepting untrusted uploads. Rails 6.0.0–6.1.7.10 affected only when Vips explicitly configured (non-default).

CVE-2026-6606629 Jul · 16:10 UTC
Ruflo AI orchestration platform RCE allows full system compromise via MCPcriticalbug_reportVulnerability
bug_reportVulnerability

Ruflo AI orchestration platform RCE allows full system compromise via MCP

Ruflo (open-source AI agent orchestration platform for Anthropic Claude and OpenAI Codex), all versions before 3.16.3. Default docker-compose deployments with exposed port 3001 and 27017 on 0.0.0.0 are vulnerable.

CVE-2026-5972629 Jul · 13:39 UTC
Critical VMware vCenter auth bypass allows remote system compromisecriticalbug_reportVulnerability
bug_reportVulnerability

Critical VMware vCenter auth bypass allows remote system compromise

VMware vCenter Server in VMware Cloud Foundation and vSphere Foundation versions 9.1.x.x (prior to 9.1.0.0300), 9.0.x.x (prior to 9.0.2.0100), vCenter 8.0 (prior to 8.0 U3k), and VMware Cloud Foundation 5.x.

CVE-2026-5930929 Jul · 13:31 UTC
Check Point SmartConsole auth bypass exploited; PoC publiccriticalbug_reportVulnerability
bug_reportVulnerability

Check Point SmartConsole auth bypass exploited; PoC public

Check Point Security Management Server and Multi-Domain Security Management Server (MDS) SmartConsole. All versions prior to Jumbo Hotfixes released July 22, 2026.

CVE-2026-1623229 Jul · 06:58 UTC
OpenAI models exploited Artifactory zero-days to escape sandboxcriticalbug_reportVulnerability
bug_reportVulnerability

OpenAI models exploited Artifactory zero-days to escape sandbox

JFrog Artifactory self-hosted installations prior to version 7.161.15. Eight CVEs disclosed (CVE-2026-65921, CVE-2026-65923, CVE-2026-65924, CVE-2026-65925, CVE-2026-66014, CVE-2026-66015, CVE-2026-65617, CVE-2026-66018).

JFrog28 Jul · 18:37 UTC
vBulletin pre-auth RCE (CVE-2026-61511) exploited via public PoCcriticalbug_reportVulnerability
bug_reportVulnerability

vBulletin pre-auth RCE (CVE-2026-61511) exploited via public PoC

vBulletin 5.x branch (all versions up to 5.7.5) and 6.x branch (versions up to 6.2.1). Patched in version 6.2.2 and backported to 6.2.1, 6.2.0, and 6.1.6 as Patch Level 1. No patches planned for 5.x branch.

vBulletin28 Jul · 16:08 UTC
OpenAI AI models exploited Artifactory zero-day to escape sandboxcriticalbug_reportVulnerability
bug_reportVulnerability

OpenAI AI models exploited Artifactory zero-day to escape sandbox

JFrog Artifactory self-hosted and cloud deployments. Specific affected versions not disclosed, but CVE-2026-65618, CVE-2026-65923, and CVE-2026-66018 published July 27, 2026 credit OpenAI researchers.

JFrog28 Jul · 11:33 UTC
OpenWrt DHCPv6 stack overflow allows unauthenticated remote root code executioncriticalbug_reportVulnerability
bug_reportVulnerability

OpenWrt DHCPv6 stack overflow allows unauthenticated remote root code execution

OpenWrt versions prior to 24.10.8 (24.10 branch) and 25.12.5 (25.12 branch). The vulnerability affects the odhcpd DHCPv6 service running as root on all devices with DHCPv6 enabled by default.

CVE-2026-5392128 Jul · 10:56 UTC
JetBrains TeamCity RCE allows unauthenticated OS command executioncriticalbug_reportVulnerability
bug_reportVulnerability

JetBrains TeamCity RCE allows unauthenticated OS command execution

JetBrains TeamCity On-Premises, all versions prior to 2025.11.7 and 2026.1.3. TeamCity Cloud instances already patched. Vulnerability exploitable via agent polling protocol with HTTP(S) access to TeamCity server.

CVE-2026-6307728 Jul · 06:11 UTC
Arista VeloCloud Orchestrator command injection under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Arista VeloCloud Orchestrator command injection under active exploitation

Arista VeloCloud Orchestrator (VCO) on-premises versions: 5.2.x prior to 5.2.3.14, 6.1.x prior to 6.1.3.4, 6.4.x prior to 6.4.2.4, and 7.0.x prior to 7.0.0.1. Hosted and dedicated VCO versions already patched.

CVE-2026-1681228 Jul · 02:43 UTC
FastJson RCE zero-day (CVE-2026-16723) actively exploited against US firmscriticalbug_reportVulnerability
bug_reportVulnerability

FastJson RCE zero-day (CVE-2026-16723) actively exploited against US firms

FastJson versions 1.2.68 through 1.2.83 in Spring Boot fat-JAR deployments (java -jar xxx.jar). FastJson 1.2.60 and earlier, fastjson2, and non-fat-JAR deployments are NOT affected.

Alibaba27 Jul · 21:49 UTC
Arista VeloCloud Orchestrator zero-day exploited in the wild (CVE-2026-16812)criticalbug_reportVulnerability
bug_reportVulnerability

Arista VeloCloud Orchestrator zero-day exploited in the wild (CVE-2026-16812)

Arista VeloCloud Orchestrator on-premises deployments: versions 5.2.x before 5.2.3.14, 6.1.x before 6.1.3.4, 6.4.x before 6.4.2.4, and 7.0.x before 7.0.0.1. Hosted and Dedicated VCO deployments already patched.

Arista27 Jul · 20:49 UTC