Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-21 · 02:09 UTC
articleTotal: 606 reports

Filtered Reports

30 / 244 results
Active filter:tag: #geopolitical✕ clear
Jenkins RCE vulnerability requires immediate patching per CERT.BEcriticalbug_reportVulnerability
bug_reportVulnerability

Jenkins RCE vulnerability requires immediate patching per CERT.BE

Jenkins (specific versions not disclosed in alert). Vulnerability enables arbitrary remote code execution. CVE identifier not yet assigned or published.

Jenkins12:42 UTC
Critical vulnerability in Joomla Content Editor (JCE) requires urgent patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical vulnerability in Joomla Content Editor (JCE) requires urgent patching

Joomla Content Editor (JCE) extension for Joomla CMS. Specific affected versions not disclosed in advisory. All Joomla sites using the JCE extension should be considered at risk pending vendor confirmation.

Joomla12:39 UTC
UK NCSC: Hostile states linked to 75% of critical infrastructure attackshighpublicGeopolitical
publicGeopolitical

UK NCSC: Hostile states linked to 75% of critical infrastructure attacks

The NCSC assessment underscores the strategic shift in cyber threat landscape from predominantly criminal actors to state-aligned operations targeting national critical infrastructure.

NCSC UK10:00 UTC
CISA orders patching of actively exploited Joomla JCE plugin flawcriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders patching of actively exploited Joomla JCE plugin flaw

Widget Factory Joomla Content Editor (JCE) plugin for Joomla CMS. Specific vulnerable versions not disclosed in provided data. Maximum severity rating indicates critical impact.

Widget Factory08:09 UTC
CISA: Widget Factory Joomla JCE flaw exploited in the wild (CVSS 10.0)criticalbug_reportVulnerability
bug_reportVulnerability

CISA: Widget Factory Joomla JCE flaw exploited in the wild (CVSS 10.0)

Widget Factory Joomla Content Editor (JCE). Specific affected versions not disclosed. Impacts Joomla CMS installations using the JCE component.

CVE-2026-4890703:50 UTC
Cisco SD-WAN vulnerability under active exploitation, patches releasedcriticalbug_reportVulnerability
bug_reportVulnerability

Cisco SD-WAN vulnerability under active exploitation, patches released

Cisco SD-WAN products. Specific affected versions not provided in available data. Organizations running Cisco SD-WAN infrastructure are potentially at risk.

Cisco11:40 UTC
Heap buffer overflow in jansi library enables code executionhighbug_reportVulnerability
bug_reportVulnerability

Heap buffer overflow in jansi library enables code execution

jansi library (all versions not specified). The jansi library is a Java library for ANSI escape sequences, commonly used in console applications and logging frameworks across Java ecosystems.

CVE-2026-848408:55 UTC
CISA orders patch for exploited LiteSpeed cPanel plugin flaw (3-day deadline)criticalbug_reportVulnerability
bug_reportVulnerability

CISA orders patch for exploited LiteSpeed cPanel plugin flaw (3-day deadline)

LiteSpeed cPanel user-end plugin (specific versions not disclosed). Affects web hosting environments using cPanel with LiteSpeed integration. U.S. federal agencies explicitly targeted by CISA directive.

CVE-2026-5442008:47 UTC
SprySOCKS malware expands to Windows in government-targeted attackshighbug_reportVulnerability
bug_reportVulnerability

SprySOCKS malware expands to Windows in government-targeted attacks

Government organizations in at least four countries. Windows systems now targeted alongside previously known Linux variants. Specific Windows versions and attack vector not disclosed.

BleepingComputer07:00 UTC
ScarCruft Deploys NarwhalRAT via Microsoft Account Phishing Lureshighperson_alertThreat Actor
person_alertThreat Actor

ScarCruft Deploys NarwhalRAT via Microsoft Account Phishing Lures

ScarCruft (also tracked as APT37, InkySquid, Reaper, and Group123) is a North Korean state-sponsored advanced persistent threat group. The actor is attributed to North Korea's intelligence apparatus and conducts espionage operations aligned with Pyon…

Microsoft06:14 UTC
CISA adds LiteSpeed cPanel Plugin privilege escalation to KEV cataloghighbug_reportVulnerability
bug_reportVulnerability

CISA adds LiteSpeed cPanel Plugin privilege escalation to KEV catalog

LiteSpeed cPanel Plugin (specific versions not disclosed). Affects web hosting environments using cPanel with LiteSpeed integration. Federal agencies and hosting providers running this plugin are in scope.

CVE-2026-5442003:41 UTC
DOJ seizes AI deepfake sites under new TAKE IT DOWN Act authorityhighpublicGeopolitical
publicGeopolitical

DOJ seizes AI deepfake sites under new TAKE IT DOWN Act authority

The seizure of CFAKE.com and SOCFAKE.com represents the first public enforcement action under the TAKE IT DOWN Act, signaling a U.S. policy shift toward proactive domain-level intervention against AI-enabled image-based sexual abuse.

BleepingComputer19:56 UTC
China-linked espionage group targets North American research networkscriticalperson_alertThreat Actor
person_alertThreat Actor

China-linked espionage group targets North American research networks

A China-linked espionage group conducted a sustained intrusion campaign lasting over one year against North American institutions. The actor's motivation appears to be intelligence collection focused on medical research, academic intellectual propert…

Google Workspace17:44 UTC
Contagious Interview targets developers via recruitment-themed phishinghighperson_alertThreat Actor
person_alertThreat Actor

Contagious Interview targets developers via recruitment-themed phishing

Contagious Interview (also tracked as DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, and DEV#POPPER) is a North Korean-aligned threat actor cluster that specializes in social engineering attacks against software developers and technology secto…

The Hacker News17:32 UTC
ShinyHunters Claims Council of Europe Data Breachhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Claims Council of Europe Data Breach

ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has been active since at least 2020, targeting organizations across multiple sectors to steal sensitive databases and person…

Council of Europe14:37 UTC
China-Linked Espionage Group Deploys InfiniteRed via REDCap Servershighperson_alertThreat Actor
person_alertThreat Actor

China-Linked Espionage Group Deploys InfiniteRed via REDCap Servers

This activity is attributed to a China-linked espionage group targeting healthcare and medical research sectors. The actor's motivation appears to be intelligence collection focused on sensitive medical research data, consistent with strategic intere…

REDCap12:00 UTC
Responsive FileManager RCE via unrestricted file upload (CVE-2026-5482)highbug_reportVulnerability
bug_reportVulnerability

Responsive FileManager RCE via unrestricted file upload (CVE-2026-5482)

Responsive FileManager (versions not specified). The vulnerability affects file upload mechanisms allowing unrestricted file uploads leading to remote code execution.

CVE-2026-548209:55 UTC
Quick.CMS deserialization flaw enables potential remote code executionhighbug_reportVulnerability
bug_reportVulnerability

Quick.CMS deserialization flaw enables potential remote code execution

Quick.CMS software (specific versions not disclosed). Affects systems where untrusted data is deserialized without proper validation.

CVE-2026-1186008:55 UTC
FBI disrupts Outsider Enterprise Chinese phishing-as-a-service platformhighperson_alertThreat Actor
person_alertThreat Actor

FBI disrupts Outsider Enterprise Chinese phishing-as-a-service platform

Outsider Enterprise is a Chinese phishing-as-a-service (PhaaS) operation disrupted by the FBI in coordination with Google and Black Lotus Labs. The actor operated thousands of phishing websites designed to harvest credit card data and passwords from…

BleepingComputer12:36 UTC
Former Iowa school IT employee sentenced for insider cyberattackhighpublicGeopolitical
publicGeopolitical

Former Iowa school IT employee sentenced for insider cyberattack

This incident represents a domestic insider threat case within the United States education sector, rather than a state-sponsored or geopolitically motivated cyberattack. The prosecution and sentencing reflect U.S.

BleepingComputer18:53 UTC
Chinese state-sponsored hackers maintain 10-year persistent accesscriticalperson_alertThreat Actor
person_alertThreat Actor

Chinese state-sponsored hackers maintain 10-year persistent access

Chinese state-sponsored hackers, likely an advanced persistent threat (APT) group operating on behalf of the People's Republic of China. The actor demonstrated exceptional operational security and patience, maintaining covert access to a target organ…

BleepingComputer12:06 UTC
US orders Anthropic to restrict foreign access to advanced AI modelshighpublicGeopolitical
publicGeopolitical

US orders Anthropic to restrict foreign access to advanced AI models

The directive appears to represent an expansion of US export control philosophy into the AI domain, treating advanced language models as dual-use technologies with national security implications.

Anthropic08:01 UTC
U.S. orders Anthropic to suspend foreign access to advanced AI modelshighpublicGeopolitical
publicGeopolitical

U.S. orders Anthropic to suspend foreign access to advanced AI models

The directive represents an escalation in U.S. efforts to control the diffusion of advanced artificial intelligence capabilities, treating frontier AI models as dual-use technologies with strategic implications.

Anthropic03:42 UTC
Chinese Cybercrime Network Weaponizes Google Gemini AI for SMS Phishinghighperson_alertThreat Actor
person_alertThreat Actor

Chinese Cybercrime Network Weaponizes Google Gemini AI for SMS Phishing

A Chinese cybercrime network operating a phishing-as-a-service (PhaaS) platform called Outsider. The group weaponizes Google's Gemini AI to craft and conduct SMS-based phishing attacks (smishing) targeting American victims.

Google16:59 UTC
Velvet Ant: China-linked APT backdoors Linux auth for decade-long accesscriticalperson_alertThreat Actor
person_alertThreat Actor

Velvet Ant: China-linked APT backdoors Linux auth for decade-long access

Velvet Ant (G1047) is a China-linked advanced persistent threat actor characterized by exceptional operational security and long-term persistence capabilities.

Linux16:17 UTC
Conti Operator Pleads Guilty After Extradition to United Stateshighperson_alertThreat Actor
person_alertThreat Actor

Conti Operator Pleads Guilty After Extradition to United States

Conti is a prolific ransomware-as-a-service (RaaS) operation that emerged in 2020 and became one of the most active and financially successful cybercrime groups before its infrastructure was leaked and operations fragmented in 2022.

BleepingComputer15:54 UTC
Oracle PeopleSoft RCE actively exploited, immediate patching requiredcriticalbug_reportVulnerability
bug_reportVulnerability

Oracle PeopleSoft RCE actively exploited, immediate patching required

Oracle PeopleSoft (specific versions not disclosed in alert). Remote code execution vulnerability affecting internet-facing PeopleSoft instances.

Oracle12:39 UTC
UNC1151/Ghostwriter Targets Polish Gmail Accounts in Phishing Campaignhighperson_alertThreat Actor
person_alertThreat Actor

UNC1151/Ghostwriter Targets Polish Gmail Accounts in Phishing Campaign

UNC1151, also known as Ghostwriter, is a threat actor group attributed by FireEye/Mandiant that has conducted sustained information operations and cyber espionage activities.

Google09:00 UTC
Novo Nordisk discloses clinical trial data breach in DenmarkhighpublicGeopolitical
publicGeopolitical

Novo Nordisk discloses clinical trial data breach in Denmark

The breach at Novo Nordisk, a Danish pharmaceutical giant controlling approximately 50% of the global insulin market, highlights the strategic vulnerability of critical healthcare infrastructure.

Novo Nordisk08:13 UTC
INTERPOL arrests Guedz, admin of Sniper Dz phishing-as-a-service platformhighperson_alertThreat Actor
person_alertThreat Actor

INTERPOL arrests Guedz, admin of Sniper Dz phishing-as-a-service platform

Guedz is identified as the primary administrator of Sniper Dz, a phishing-as-a-service (PhaaS) platform that operated for approximately a decade across the Middle East and North Africa (MENA) region.

The Hacker News06:52 UTC