Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 547 results
highbug_reportVulnerabilityChrome Password Manager passkey bypass allows malware to hijack accounts
Google Chrome Password Manager on Windows systems with TPM. All three attack paths require malware already running as an ordinary user. Specific affected Chrome versions not disclosed.
highbug_reportVulnerabilityBTMOB Android RAT ecosystem fragments into resellers and source-code sales
Organizations and individuals targeted by BTMOB Android RAT malware-as-a-service (MaaS). BTMOB is an Android remote access trojan distributed through multiple channels including official operators, resellers, and source-code buyers.
criticalbug_reportVulnerabilityN-Central actively exploited vulnerability requires immediate patching
N-Central remote monitoring and management (RMM) platform. Specific affected versions not disclosed in available advisory. CVE identifier not yet assigned or published.
highbug_reportVulnerabilityPasskey auth bypass via User Verified flag validation gap in relying parties
Relying parties (websites/services) implementing passkey authentication that fail to validate the User Verified (UV) flag in WebAuthn assertions. Affects passwordless authentication systems across multiple platforms.
highbug_reportVulnerabilityThermo Fisher patches DNA analysis file tampering flaw in forensic software
Thermo Fisher Applied Biosystems human identification software: 3500/3500xL Series Data Collection ≤4.0.2, 3730/3730xL Series ≤5.0.2, SeqStudio Genetic Analyzer ≤1.2.5, SeqStudio Flex ≤1.2.0, GeneMapper ID-X ≤v1.7.3.
criticalbug_reportVulnerabilityN-able N-central auth bypass exploited; incomplete patch requires upgrade
N-able N-central builds prior to 2026.3.1.7. All versions before the August 2 emergency hotfix are vulnerable. Affects MSPs and IT teams using N-central for remote monitoring and management of customer endpoints.
highbug_reportVulnerabilityHugging Face Diffusers RCE flaws bypass trust_remote_code safeguard
Hugging Face Diffusers library versions prior to 0.38.0. Affects any user invoking DiffusionPipeline.from_pretrained with custom pipelines. The library has over 8.1 million downloads monthly and is widely embedded in enterprise AI production pipeline…
criticalbug_reportVulnerabilityCOLDCARD wallet RNG flaw exploited to steal $88.6M in Bitcoin
COLDCARD hardware wallets: Mk2/Mk3 firmware 4.0.1-4.1.9, Mk4/Mk5 before 5.6.0 (standard) or 6.6.0X (Edge), Q devices before 1.5.0Q (standard) or 6.6.0QX (Edge). Seeds generated using the flawed RNG are compromised.
criticalbug_reportVulnerabilityColdcard wallet PRNG flaw enabled $70M Bitcoin theft in 41 minutes
Coldcard hardware wallets (Coinkite): Mk2 and Mk3 firmware 4.0.0–4.1.9 (fixed in 4.2.0); Mk4 and Mk5 before 5.6.0; Q model before 1.5.0Q; Edge builds before 6.6.0X (Mk4/Mk5) and 6.6.0QX (Q).
criticalbug_reportVulnerabilityRails Active Storage flaw enables file read and RCE by unauthenticated users
Ruby on Rails applications using the Active Storage framework. Specific vulnerable versions not provided in available data. Patched versions released by Rails team.
highbug_reportVulnerabilityAdform supply chain attack injected crypto wallet swapper into customer sites
Adform advertising platform customers; specifically the trackpoint-async.js file served from s2.adform[.]net. Sites embedding this tracking script were affected on July 27, 2026 (confirmed date), with reports suggesting possible exposure up to one we…
criticalbug_reportVulnerabilityAdobe Campaign Classic CVSS 10.0 flaw allows code execution without interaction
Adobe Campaign Classic (ACC) v7 versions prior to 7.4.3 build 9398 on Windows and Linux. The vulnerability affects the enterprise marketing automation platform used for customer campaign management.
highbug_reportVulnerabilityArch Linux disables AUR package adoption after malicious takeovers
Arch Linux Arch User Repository (AUR) - all community-maintained packages. Users who installed or updated AUR packages during the compromise window are potentially affected. Scope limited to AUR; official Arch repositories unaffected.
highbug_reportVulnerabilityAdform ad platform compromised to inject crypto-stealing clipboard scripts
Adform ad platform and all websites embedding Adform advertising scripts. Any site visitor copying cryptocurrency wallet addresses during the compromise window was at risk of clipboard hijacking.
highbug_reportVulnerabilityCISA warns of rising attacks on internet-exposed PLCs in water systems
Internet-exposed programmable logic controllers (PLCs) in U.S. water and wastewater systems. Specific vendors and models not disclosed in available information.
criticalbug_reportVulnerabilityAdobe Campaign Classic critical RCE and file read flaws require patching
Adobe Campaign Classic (specific versions not disclosed in advisory). Two vulnerabilities: one critical severity enabling arbitrary code execution, one high severity allowing file system read access.
criticalbug_reportVulnerabilityCritical vCenter vulnerabilities require immediate patching
VMware vCenter Server component across multiple VMware product deployments. Specific affected versions not provided in advisory. Widespread impact expected given vCenter's role in VMware infrastructure management.
highbug_reportVulnerabilityChrome 149–151 fix 1,442 flaws as AI-driven bug discovery outpaces patching
Google Chrome versions 149, 150, and 151 (released June–July 2026). All prior Chrome versions are affected by the resolved vulnerabilities. One critical flaw (CVE-2026-3545, CVSS 9.6) is a 13-year-old sandbox escape in Navigation component, patched i…
highbug_reportVulnerability84 flaws in 4G/5G core networks enable DoS and session hijacking
4G and 5G core network implementations: Open5GS (LTE/5G), free5GC, OpenAirInterface (LTE/5G), SD-Core, and eUPF. Vulnerabilities affect GTP-C and PFCP signaling protocols. 83 of 84 flaws confirmed, 81 assigned CVE identifiers.
criticalbug_reportVulnerabilityCisco Secure Firewall Management Center under active exploitation
Cisco Secure Firewall Management Center (formerly Firepower Management Center). Specific affected versions not disclosed in available data. Vulnerability details including CVE identifier not yet published.
criticalbug_reportVulnerabilityJetBrains TeamCity auth bypass enables RCE on all on-premises versions
JetBrains TeamCity On-Premises, all versions prior to 2025.11.7 and 2026.1.3. TeamCity Cloud is not affected. CVE-2026-63077 allows authentication bypass via agent polling protocol over HTTPS, leading to remote code execution with server process priv…
highbug_reportVulnerabilityNorth Korea-linked actors compromise npm packages debug, chalk, axios
Node Package Manager (npm) ecosystem: typo-crypto (March 2025), debug and chalk (September 2025, ~10% of cloud environments affected within 2 hours), axios (March 2026, 100M+ weekly downloads).
criticalbug_reportVulnerabilityVMware vCenter, ESXi critical flaws enable auth bypass and VM escapes
VMware vCenter Server (versions prior to 9.1.0.0300, 9.0.2.0100, 8.0 U3k), VMware ESXi (versions prior to 9.1.0.0200, 9.0.2.0100, 8.0 U3k), VMware Workstation and Fusion (25H2 and earlier), VMware Cloud Foundation 5.x, VMware vSphere Foundation, VMwa…
criticalbug_reportVulnerabilityAzure Cosmos DB sandbox escape exposed platform-wide key to all databases
Microsoft Azure Cosmos DB, all customer tenants across all regions. Affects Gremlin, SQL, MongoDB, and Cassandra APIs. Vulnerability active from unknown date until July 2026 full remediation.
criticalbug_reportVulnerabilityMultiple critical Xen Project vulnerabilities require immediate patching
Xen Project hypervisor - specific affected versions not disclosed in available advisory. Impacts organizations running Xen-based virtualization infrastructure including cloud providers and enterprise data centers.
highbug_reportVulnerabilityRussian APT exploits OWA XSS flaw for persistent mailbox access
Microsoft Outlook Web Access (OWA) vulnerable to CVE-2026-42897 (CVSS 8.1), a cross-site scripting flaw. Targets include U.S. and European government entities, telecommunications, financial, hospitality, and aerospace sectors.
criticalbug_reportVulnerabilityNorth Korea linked to npm supply chain attacks on debug, chalk, axios
npm packages debug, chalk, axios, typo-crypto, and Mastra (over 2 billion weekly downloads combined). Attacks spanned March 2025 through March 2026. Maintainer accounts compromised via phishing; malicious code injected to steal cryptocurrency wallet…
highbug_reportVulnerabilityCisco FMC static credential flaw exploited in zero-day attacks
Cisco Secure Firewall Management Center (FMC) Software versions 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. Does not affect Cloud-Delivered FMC, Firewall Device Manager, ASA Software, Threat Defense Software, or Security Cloud Control.
criticalbug_reportVulnerabilityRails Active Storage flaw allows file read via crafted image uploads
Ruby on Rails 7.0.0–7.2.3.1, 8.0.0–8.0.5, 8.1.0–8.1.3 using Active Storage with libvips for image processing and accepting untrusted uploads. Rails 6.0.0–6.1.7.10 affected only when Vips explicitly configured (non-default).
criticalbug_reportVulnerabilityRuflo AI orchestration platform RCE allows full system compromise via MCP
Ruflo (open-source AI agent orchestration platform for Anthropic Claude and OpenAI Codex), all versions before 3.16.3. Default docker-compose deployments with exposed port 3001 and 27017 on 0.0.0.0 are vulnerable.