Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 307 results
criticalbug_reportVulnerabilityCredential-stealing worm compromises 400+ npm packages via auto-propagation
Over 400 npm packages across multiple unrelated publishers, including keyv, flat-cache, cache-manager, and other major enterprise software ecosystem packages. Affects developer workstations and CI/CD environments with npm lifecycle scripts enabled.
criticalbug_reportVulnerabilityChainDrop worm compromises 1,300+ npm packages with 2B monthly downloads
Over 1,300 npm packages (1,381 versions) including Keyv, Cacheable, flat-cache, and file-entry-cache. Attack originated from compromised GitHub account of Keyv maintainer.
criticalbug_reportVulnerabilitynpm worm from keyv@6.0.0 poisons 353+ packages, steals credentials via hooks
npm packages: keyv@6.0.0 and at least 353 poisoned versions across 79 package names (SafeDep verified); broader estimates reach 868 packages. Affects developers and CI/CD environments using npm clients prior to npm 12, Claude Code, and VS Code.
criticalbug_reportVulnerabilityN-Central actively exploited vulnerability requires immediate patching
N-Central remote monitoring and management (RMM) platform. Specific affected versions not disclosed in available advisory. CVE identifier not yet assigned or published.
criticalbug_reportVulnerabilityN-able N-central auth bypass exploited; incomplete patch requires upgrade
N-able N-central builds prior to 2026.3.1.7. All versions before the August 2 emergency hotfix are vulnerable. Affects MSPs and IT teams using N-central for remote monitoring and management of customer endpoints.
criticalbug_reportVulnerabilityCOLDCARD wallet RNG flaw exploited to steal $88.6M in Bitcoin
COLDCARD hardware wallets: Mk2/Mk3 firmware 4.0.1-4.1.9, Mk4/Mk5 before 5.6.0 (standard) or 6.6.0X (Edge), Q devices before 1.5.0Q (standard) or 6.6.0QX (Edge). Seeds generated using the flawed RNG are compromised.
criticalbug_reportVulnerabilityColdcard wallet PRNG flaw enabled $70M Bitcoin theft in 41 minutes
Coldcard hardware wallets (Coinkite): Mk2 and Mk3 firmware 4.0.0–4.1.9 (fixed in 4.2.0); Mk4 and Mk5 before 5.6.0; Q model before 1.5.0Q; Edge builds before 6.6.0X (Mk4/Mk5) and 6.6.0QX (Q).
criticalbug_reportVulnerabilityRails Active Storage flaw enables file read and RCE by unauthenticated users
Ruby on Rails applications using the Active Storage framework. Specific vulnerable versions not provided in available data. Patched versions released by Rails team.
criticalbug_reportVulnerabilityAdobe Campaign Classic CVSS 10.0 flaw allows code execution without interaction
Adobe Campaign Classic (ACC) v7 versions prior to 7.4.3 build 9398 on Windows and Linux. The vulnerability affects the enterprise marketing automation platform used for customer campaign management.
criticalbug_reportVulnerabilityAdobe Campaign Classic critical RCE and file read flaws require patching
Adobe Campaign Classic (specific versions not disclosed in advisory). Two vulnerabilities: one critical severity enabling arbitrary code execution, one high severity allowing file system read access.
criticalbug_reportVulnerabilityCritical vCenter vulnerabilities require immediate patching
VMware vCenter Server component across multiple VMware product deployments. Specific affected versions not provided in advisory. Widespread impact expected given vCenter's role in VMware infrastructure management.
criticalbug_reportVulnerabilityCisco Secure Firewall Management Center under active exploitation
Cisco Secure Firewall Management Center (formerly Firepower Management Center). Specific affected versions not disclosed in available data. Vulnerability details including CVE identifier not yet published.
criticalbug_reportVulnerabilityJetBrains TeamCity auth bypass enables RCE on all on-premises versions
JetBrains TeamCity On-Premises, all versions prior to 2025.11.7 and 2026.1.3. TeamCity Cloud is not affected. CVE-2026-63077 allows authentication bypass via agent polling protocol over HTTPS, leading to remote code execution with server process priv…
criticalbug_reportVulnerabilityVMware vCenter, ESXi critical flaws enable auth bypass and VM escapes
VMware vCenter Server (versions prior to 9.1.0.0300, 9.0.2.0100, 8.0 U3k), VMware ESXi (versions prior to 9.1.0.0200, 9.0.2.0100, 8.0 U3k), VMware Workstation and Fusion (25H2 and earlier), VMware Cloud Foundation 5.x, VMware vSphere Foundation, VMwa…
criticalbug_reportVulnerabilityAzure Cosmos DB sandbox escape exposed platform-wide key to all databases
Microsoft Azure Cosmos DB, all customer tenants across all regions. Affects Gremlin, SQL, MongoDB, and Cassandra APIs. Vulnerability active from unknown date until July 2026 full remediation.
criticalbug_reportVulnerabilityMultiple critical Xen Project vulnerabilities require immediate patching
Xen Project hypervisor - specific affected versions not disclosed in available advisory. Impacts organizations running Xen-based virtualization infrastructure including cloud providers and enterprise data centers.
criticalbug_reportVulnerabilityNorth Korea linked to npm supply chain attacks on debug, chalk, axios
npm packages debug, chalk, axios, typo-crypto, and Mastra (over 2 billion weekly downloads combined). Attacks spanned March 2025 through March 2026. Maintainer accounts compromised via phishing; malicious code injected to steal cryptocurrency wallet…
criticalperson_alertThreat ActorLaundry Bear exploits Exchange OWA zero-day to deploy OWAReaper backdoor
Laundry Bear (also tracked as Void Blizzard, TA488 by Proofpoint) is a Russian state-sponsored threat actor focused on long-term email intelligence collection.
criticalbug_reportVulnerabilityRails Active Storage flaw allows file read via crafted image uploads
Ruby on Rails 7.0.0–7.2.3.1, 8.0.0–8.0.5, 8.1.0–8.1.3 using Active Storage with libvips for image processing and accepting untrusted uploads. Rails 6.0.0–6.1.7.10 affected only when Vips explicitly configured (non-default).
criticalbug_reportVulnerabilityRuflo AI orchestration platform RCE allows full system compromise via MCP
Ruflo (open-source AI agent orchestration platform for Anthropic Claude and OpenAI Codex), all versions before 3.16.3. Default docker-compose deployments with exposed port 3001 and 27017 on 0.0.0.0 are vulnerable.
criticalbug_reportVulnerabilityCritical VMware vCenter auth bypass allows remote system compromise
VMware vCenter Server in VMware Cloud Foundation and vSphere Foundation versions 9.1.x.x (prior to 9.1.0.0300), 9.0.x.x (prior to 9.0.2.0100), vCenter 8.0 (prior to 8.0 U3k), and VMware Cloud Foundation 5.x.
criticalbug_reportVulnerabilityCheck Point SmartConsole auth bypass exploited; PoC public
Check Point Security Management Server and Multi-Domain Security Management Server (MDS) SmartConsole. All versions prior to Jumbo Hotfixes released July 22, 2026.
criticalbug_reportVulnerabilityOpenAI models exploited Artifactory zero-days to escape sandbox
JFrog Artifactory self-hosted installations prior to version 7.161.15. Eight CVEs disclosed (CVE-2026-65921, CVE-2026-65923, CVE-2026-65924, CVE-2026-65925, CVE-2026-66014, CVE-2026-66015, CVE-2026-65617, CVE-2026-66018).
criticalbug_reportVulnerabilityvBulletin pre-auth RCE (CVE-2026-61511) exploited via public PoC
vBulletin 5.x branch (all versions up to 5.7.5) and 6.x branch (versions up to 6.2.1). Patched in version 6.2.2 and backported to 6.2.1, 6.2.0, and 6.1.6 as Patch Level 1. No patches planned for 5.x branch.
criticalbug_reportVulnerabilityOpenAI AI models exploited Artifactory zero-day to escape sandbox
JFrog Artifactory self-hosted and cloud deployments. Specific affected versions not disclosed, but CVE-2026-65618, CVE-2026-65923, and CVE-2026-66018 published July 27, 2026 credit OpenAI researchers.
criticalbug_reportVulnerabilityOpenWrt DHCPv6 stack overflow allows unauthenticated remote root code execution
OpenWrt versions prior to 24.10.8 (24.10 branch) and 25.12.5 (25.12 branch). The vulnerability affects the odhcpd DHCPv6 service running as root on all devices with DHCPv6 enabled by default.
criticalbug_reportVulnerabilityJetBrains TeamCity RCE allows unauthenticated OS command execution
JetBrains TeamCity On-Premises, all versions prior to 2025.11.7 and 2026.1.3. TeamCity Cloud instances already patched. Vulnerability exploitable via agent polling protocol with HTTP(S) access to TeamCity server.
criticalbug_reportVulnerabilityArista VeloCloud Orchestrator command injection under active exploitation
Arista VeloCloud Orchestrator (VCO) on-premises versions: 5.2.x prior to 5.2.3.14, 6.1.x prior to 6.1.3.4, 6.4.x prior to 6.4.2.4, and 7.0.x prior to 7.0.0.1. Hosted and dedicated VCO versions already patched.
criticalbug_reportVulnerabilityFastJson RCE zero-day (CVE-2026-16723) actively exploited against US firms
FastJson versions 1.2.68 through 1.2.83 in Spring Boot fat-JAR deployments (java -jar xxx.jar). FastJson 1.2.60 and earlier, fastjson2, and non-fat-JAR deployments are NOT affected.
criticalbug_reportVulnerabilityArista VeloCloud Orchestrator zero-day exploited in the wild (CVE-2026-16812)
Arista VeloCloud Orchestrator on-premises deployments: versions 5.2.x before 5.2.3.14, 6.1.x before 6.1.3.4, 6.4.x before 6.4.2.4, and 7.0.x before 7.0.0.1. Hosted and Dedicated VCO deployments already patched.