Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 253 results
Active filter:tag: #geopolitical✕ clear
Salesforce disables Klue integration after OAuth token abuse exposes datahighbug_reportVulnerability
bug_reportVulnerability

Salesforce disables Klue integration after OAuth token abuse exposes data

Salesforce customers using the Klue Battlecards app integration. OAuth tokens were abused to access customer data. Integration disabled as of June 11, 2026.

Salesforce19 Jun · 07:03 UTC
Critical auth bypass in SimpleHelp remote support software (CVE-2026-48558)criticalbug_reportVulnerability
bug_reportVulnerability

Critical auth bypass in SimpleHelp remote support software (CVE-2026-48558)

SimpleHelp remote support software, specific versions not disclosed. Vendor patch available. Authentication bypass vulnerability allows unauthorized access.

CVE-2026-4855819 Jun · 06:46 UTC
F5 patches high-severity flaws in NGINX Open Source and Gateway Fabrichighbug_reportVulnerability
bug_reportVulnerability

F5 patches high-severity flaws in NGINX Open Source and Gateway Fabric

NGINX Open Source and NGINX Gateway Fabric (specific versions not provided). Four CVEs: CVE-2026-11311, CVE-2026-42055, CVE-2026-42530, CVE-2026-50107. Affects organizations running NGINX web servers, reverse proxies, API gateways, and Kubernetes ing…

CVE-2026-1131119 Jun · 06:24 UTC
CISA warns of 74,000 Fortinet credentials exposed in FortiBleed leakhighpublicGeopolitical
publicGeopolitical

CISA warns of 74,000 Fortinet credentials exposed in FortiBleed leak

The exposure of approximately 74,000 Fortinet firewall and VPN credentials represents a significant supply-side vulnerability affecting critical infrastructure globally.

Fortinet19 Jun · 04:47 UTC
NetNut Linked to Popa Android Botnet Enabling Proxy Fraudhighperson_alertThreat Actor
person_alertThreat Actor

NetNut Linked to Popa Android Botnet Enabling Proxy Fraud

NetNut is a residential proxy service operated by Alarum Technologies Ltd (NASDAQ: ALAR), a publicly-traded Israeli firm. Multiple security researchers have linked NetNut to the Popa Android botnet, which has compromised millions of consumer TV boxes…

Alarum Technologies Ltd18 Jun · 15:37 UTC
DragonForce Deploys Backdoor.Turn RAT via Microsoft Teams Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

DragonForce Deploys Backdoor.Turn RAT via Microsoft Teams Infrastructure

DragonForce is a threat actor associated with ransomware operations. The group has demonstrated advanced capabilities in developing custom tooling and leveraging legitimate cloud infrastructure for command-and-control communications.

Microsoft18 Jun · 11:30 UTC
Evil Corp SocGholish botnet dismantled: 15,000 sites, 100+ servershighperson_alertThreat Actor
person_alertThreat Actor

Evil Corp SocGholish botnet dismantled: 15,000 sites, 100+ servers

Evil Corp (also tracked as Indrik Spider, Manatee Tempest, DEV-0243, UNC2165) is a financially motivated cybercrime group linked to Russia. The group has operated since at least 2014 and is known for deploying banking trojans and ransomware variants…

WordPress18 Jun · 11:25 UTC
NCSC warns of active global campaign targeting Fortinet firewalls and VPNshighbug_reportVulnerability
bug_reportVulnerability

NCSC warns of active global campaign targeting Fortinet firewalls and VPNs

Fortinet firewalls and VPN gateways globally. Specific product lines and versions not disclosed in alert. Organizations using FortiGate, FortiOS, or FortiClient VPN services should assume potential exposure.

Fortinet18 Jun · 10:00 UTC
Junior Hacker targets French automotive sector with credential thefthighperson_alertThreat Actor
person_alertThreat Actor

Junior Hacker targets French automotive sector with credential theft

Junior Hacker is a French-speaking threat actor targeting small businesses in the French automotive sector. The actor demonstrates financially motivated objectives, focusing on credential theft for banking and email access.

The Hacker News17 Jun · 14:00 UTC
Jenkins RCE vulnerability requires immediate patching per CERT.BEcriticalbug_reportVulnerability
bug_reportVulnerability

Jenkins RCE vulnerability requires immediate patching per CERT.BE

Jenkins (specific versions not disclosed in alert). Vulnerability enables arbitrary remote code execution. CVE identifier not yet assigned or published.

Jenkins17 Jun · 12:42 UTC
Critical vulnerability in Joomla Content Editor (JCE) requires urgent patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical vulnerability in Joomla Content Editor (JCE) requires urgent patching

Joomla Content Editor (JCE) extension for Joomla CMS. Specific affected versions not disclosed in advisory. All Joomla sites using the JCE extension should be considered at risk pending vendor confirmation.

Joomla17 Jun · 12:39 UTC
UK NCSC: Hostile states linked to 75% of critical infrastructure attackshighpublicGeopolitical
publicGeopolitical

UK NCSC: Hostile states linked to 75% of critical infrastructure attacks

The NCSC assessment underscores the strategic shift in cyber threat landscape from predominantly criminal actors to state-aligned operations targeting national critical infrastructure.

NCSC UK17 Jun · 10:00 UTC
CISA orders patching of actively exploited Joomla JCE plugin flawcriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders patching of actively exploited Joomla JCE plugin flaw

Widget Factory Joomla Content Editor (JCE) plugin for Joomla CMS. Specific vulnerable versions not disclosed in provided data. Maximum severity rating indicates critical impact.

Widget Factory17 Jun · 08:09 UTC
CISA: Widget Factory Joomla JCE flaw exploited in the wild (CVSS 10.0)criticalbug_reportVulnerability
bug_reportVulnerability

CISA: Widget Factory Joomla JCE flaw exploited in the wild (CVSS 10.0)

Widget Factory Joomla Content Editor (JCE). Specific affected versions not disclosed. Impacts Joomla CMS installations using the JCE component.

CVE-2026-4890717 Jun · 03:50 UTC
Cisco SD-WAN vulnerability under active exploitation, patches releasedcriticalbug_reportVulnerability
bug_reportVulnerability

Cisco SD-WAN vulnerability under active exploitation, patches released

Cisco SD-WAN products. Specific affected versions not provided in available data. Organizations running Cisco SD-WAN infrastructure are potentially at risk.

Cisco16 Jun · 11:40 UTC
Heap buffer overflow in jansi library enables code executionhighbug_reportVulnerability
bug_reportVulnerability

Heap buffer overflow in jansi library enables code execution

jansi library (all versions not specified). The jansi library is a Java library for ANSI escape sequences, commonly used in console applications and logging frameworks across Java ecosystems.

CVE-2026-848416 Jun · 08:55 UTC
CISA orders patch for exploited LiteSpeed cPanel plugin flaw (3-day deadline)criticalbug_reportVulnerability
bug_reportVulnerability

CISA orders patch for exploited LiteSpeed cPanel plugin flaw (3-day deadline)

LiteSpeed cPanel user-end plugin (specific versions not disclosed). Affects web hosting environments using cPanel with LiteSpeed integration. U.S. federal agencies explicitly targeted by CISA directive.

CVE-2026-5442016 Jun · 08:47 UTC
SprySOCKS malware expands to Windows in government-targeted attackshighbug_reportVulnerability
bug_reportVulnerability

SprySOCKS malware expands to Windows in government-targeted attacks

Government organizations in at least four countries. Windows systems now targeted alongside previously known Linux variants. Specific Windows versions and attack vector not disclosed.

BleepingComputer16 Jun · 07:00 UTC
ScarCruft Deploys NarwhalRAT via Microsoft Account Phishing Lureshighperson_alertThreat Actor
person_alertThreat Actor

ScarCruft Deploys NarwhalRAT via Microsoft Account Phishing Lures

ScarCruft (also tracked as APT37, InkySquid, Reaper, and Group123) is a North Korean state-sponsored advanced persistent threat group. The actor is attributed to North Korea's intelligence apparatus and conducts espionage operations aligned with Pyon…

Microsoft16 Jun · 06:14 UTC
CISA adds LiteSpeed cPanel Plugin privilege escalation to KEV cataloghighbug_reportVulnerability
bug_reportVulnerability

CISA adds LiteSpeed cPanel Plugin privilege escalation to KEV catalog

LiteSpeed cPanel Plugin (specific versions not disclosed). Affects web hosting environments using cPanel with LiteSpeed integration. Federal agencies and hosting providers running this plugin are in scope.

CVE-2026-5442016 Jun · 03:41 UTC
DOJ seizes AI deepfake sites under new TAKE IT DOWN Act authorityhighpublicGeopolitical
publicGeopolitical

DOJ seizes AI deepfake sites under new TAKE IT DOWN Act authority

The seizure of CFAKE.com and SOCFAKE.com represents the first public enforcement action under the TAKE IT DOWN Act, signaling a U.S. policy shift toward proactive domain-level intervention against AI-enabled image-based sexual abuse.

BleepingComputer15 Jun · 19:56 UTC
China-linked espionage group targets North American research networkscriticalperson_alertThreat Actor
person_alertThreat Actor

China-linked espionage group targets North American research networks

A China-linked espionage group conducted a sustained intrusion campaign lasting over one year against North American institutions. The actor's motivation appears to be intelligence collection focused on medical research, academic intellectual propert…

Google Workspace15 Jun · 17:44 UTC
Contagious Interview targets developers via recruitment-themed phishinghighperson_alertThreat Actor
person_alertThreat Actor

Contagious Interview targets developers via recruitment-themed phishing

Contagious Interview (also tracked as DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, and DEV#POPPER) is a North Korean-aligned threat actor cluster that specializes in social engineering attacks against software developers and technology secto…

The Hacker News15 Jun · 17:32 UTC
ShinyHunters Claims Council of Europe Data Breachhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Claims Council of Europe Data Breach

ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has been active since at least 2020, targeting organizations across multiple sectors to steal sensitive databases and person…

Council of Europe15 Jun · 14:37 UTC
China-Linked Espionage Group Deploys InfiniteRed via REDCap Servershighperson_alertThreat Actor
person_alertThreat Actor

China-Linked Espionage Group Deploys InfiniteRed via REDCap Servers

This activity is attributed to a China-linked espionage group targeting healthcare and medical research sectors. The actor's motivation appears to be intelligence collection focused on sensitive medical research data, consistent with strategic intere…

REDCap15 Jun · 12:00 UTC
Responsive FileManager RCE via unrestricted file upload (CVE-2026-5482)highbug_reportVulnerability
bug_reportVulnerability

Responsive FileManager RCE via unrestricted file upload (CVE-2026-5482)

Responsive FileManager (versions not specified). The vulnerability affects file upload mechanisms allowing unrestricted file uploads leading to remote code execution.

CVE-2026-548215 Jun · 09:55 UTC
Quick.CMS deserialization flaw enables potential remote code executionhighbug_reportVulnerability
bug_reportVulnerability

Quick.CMS deserialization flaw enables potential remote code execution

Quick.CMS software (specific versions not disclosed). Affects systems where untrusted data is deserialized without proper validation.

CVE-2026-1186015 Jun · 08:55 UTC
FBI disrupts Outsider Enterprise Chinese phishing-as-a-service platformhighperson_alertThreat Actor
person_alertThreat Actor

FBI disrupts Outsider Enterprise Chinese phishing-as-a-service platform

Outsider Enterprise is a Chinese phishing-as-a-service (PhaaS) operation disrupted by the FBI in coordination with Google and Black Lotus Labs. The actor operated thousands of phishing websites designed to harvest credit card data and passwords from…

BleepingComputer14 Jun · 12:36 UTC
Former Iowa school IT employee sentenced for insider cyberattackhighpublicGeopolitical
publicGeopolitical

Former Iowa school IT employee sentenced for insider cyberattack

This incident represents a domestic insider threat case within the United States education sector, rather than a state-sponsored or geopolitically motivated cyberattack. The prosecution and sentencing reflect U.S.

BleepingComputer13 Jun · 18:53 UTC
Chinese state-sponsored hackers maintain 10-year persistent accesscriticalperson_alertThreat Actor
person_alertThreat Actor

Chinese state-sponsored hackers maintain 10-year persistent access

Chinese state-sponsored hackers, likely an advanced persistent threat (APT) group operating on behalf of the People's Republic of China. The actor demonstrated exceptional operational security and patience, maintaining covert access to a target organ…

BleepingComputer13 Jun · 12:06 UTC