Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 547 results
Active filter:tag: #vulnerability✕ clear
Chrome Password Manager passkey bypass allows malware to hijack accountshighbug_reportVulnerability
bug_reportVulnerability

Chrome Password Manager passkey bypass allows malware to hijack accounts

Google Chrome Password Manager on Windows systems with TPM. All three attack paths require malware already running as an ordinary user. Specific affected Chrome versions not disclosed.

Google3 Aug · 14:24 UTC
BTMOB Android RAT ecosystem fragments into resellers and source-code saleshighbug_reportVulnerability
bug_reportVulnerability

BTMOB Android RAT ecosystem fragments into resellers and source-code sales

Organizations and individuals targeted by BTMOB Android RAT malware-as-a-service (MaaS). BTMOB is an Android remote access trojan distributed through multiple channels including official operators, resellers, and source-code buyers.

BleepingComputer3 Aug · 12:45 UTC
N-Central actively exploited vulnerability requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

N-Central actively exploited vulnerability requires immediate patching

N-Central remote monitoring and management (RMM) platform. Specific affected versions not disclosed in available advisory. CVE identifier not yet assigned or published.

N-Central3 Aug · 11:45 UTC
Passkey auth bypass via User Verified flag validation gap in relying partieshighbug_reportVulnerability
bug_reportVulnerability

Passkey auth bypass via User Verified flag validation gap in relying parties

Relying parties (websites/services) implementing passkey authentication that fail to validate the User Verified (UV) flag in WebAuthn assertions. Affects passwordless authentication systems across multiple platforms.

Palo Alto Networks3 Aug · 08:00 UTC
Thermo Fisher patches DNA analysis file tampering flaw in forensic softwarehighbug_reportVulnerability
bug_reportVulnerability

Thermo Fisher patches DNA analysis file tampering flaw in forensic software

Thermo Fisher Applied Biosystems human identification software: 3500/3500xL Series Data Collection ≤4.0.2, 3730/3730xL Series ≤5.0.2, SeqStudio Genetic Analyzer ≤1.2.5, SeqStudio Flex ≤1.2.0, GeneMapper ID-X ≤v1.7.3.

CVE-2026-175833 Aug · 06:05 UTC
N-able N-central auth bypass exploited; incomplete patch requires upgradecriticalbug_reportVulnerability
bug_reportVulnerability

N-able N-central auth bypass exploited; incomplete patch requires upgrade

N-able N-central builds prior to 2026.3.1.7. All versions before the August 2 emergency hotfix are vulnerable. Affects MSPs and IT teams using N-central for remote monitoring and management of customer endpoints.

CVE-2026-185773 Aug · 04:41 UTC
Hugging Face Diffusers RCE flaws bypass trust_remote_code safeguardhighbug_reportVulnerability
bug_reportVulnerability

Hugging Face Diffusers RCE flaws bypass trust_remote_code safeguard

Hugging Face Diffusers library versions prior to 0.38.0. Affects any user invoking DiffusionPipeline.from_pretrained with custom pipelines. The library has over 8.1 million downloads monthly and is widely embedded in enterprise AI production pipeline…

Hugging Face3 Aug · 04:40 UTC
COLDCARD wallet RNG flaw exploited to steal $88.6M in Bitcoincriticalbug_reportVulnerability
bug_reportVulnerability

COLDCARD wallet RNG flaw exploited to steal $88.6M in Bitcoin

COLDCARD hardware wallets: Mk2/Mk3 firmware 4.0.1-4.1.9, Mk4/Mk5 before 5.6.0 (standard) or 6.6.0X (Edge), Q devices before 1.5.0Q (standard) or 6.6.0QX (Edge). Seeds generated using the flawed RNG are compromised.

COLDCARD2 Aug · 19:14 UTC
Coldcard wallet PRNG flaw enabled $70M Bitcoin theft in 41 minutescriticalbug_reportVulnerability
bug_reportVulnerability

Coldcard wallet PRNG flaw enabled $70M Bitcoin theft in 41 minutes

Coldcard hardware wallets (Coinkite): Mk2 and Mk3 firmware 4.0.0–4.1.9 (fixed in 4.2.0); Mk4 and Mk5 before 5.6.0; Q model before 1.5.0Q; Edge builds before 6.6.0X (Mk4/Mk5) and 6.6.0QX (Q).

Coinkite1 Aug · 15:17 UTC
Rails Active Storage flaw enables file read and RCE by unauthenticated userscriticalbug_reportVulnerability
bug_reportVulnerability

Rails Active Storage flaw enables file read and RCE by unauthenticated users

Ruby on Rails applications using the Active Storage framework. Specific vulnerable versions not provided in available data. Patched versions released by Rails team.

Ruby on Rails1 Aug · 12:20 UTC
Adform supply chain attack injected crypto wallet swapper into customer siteshighbug_reportVulnerability
bug_reportVulnerability

Adform supply chain attack injected crypto wallet swapper into customer sites

Adform advertising platform customers; specifically the trackpoint-async.js file served from s2.adform[.]net. Sites embedding this tracking script were affected on July 27, 2026 (confirmed date), with reports suggesting possible exposure up to one we…

Adform1 Aug · 07:03 UTC
Adobe Campaign Classic CVSS 10.0 flaw allows code execution without interactioncriticalbug_reportVulnerability
bug_reportVulnerability

Adobe Campaign Classic CVSS 10.0 flaw allows code execution without interaction

Adobe Campaign Classic (ACC) v7 versions prior to 7.4.3 build 9398 on Windows and Linux. The vulnerability affects the enterprise marketing automation platform used for customer campaign management.

CVE-2026-484491 Aug · 05:12 UTC
Arch Linux disables AUR package adoption after malicious takeovershighbug_reportVulnerability
bug_reportVulnerability

Arch Linux disables AUR package adoption after malicious takeovers

Arch Linux Arch User Repository (AUR) - all community-maintained packages. Users who installed or updated AUR packages during the compromise window are potentially affected. Scope limited to AUR; official Arch repositories unaffected.

Arch Linux31 Jul · 19:38 UTC
Adform ad platform compromised to inject crypto-stealing clipboard scriptshighbug_reportVulnerability
bug_reportVulnerability

Adform ad platform compromised to inject crypto-stealing clipboard scripts

Adform ad platform and all websites embedding Adform advertising scripts. Any site visitor copying cryptocurrency wallet addresses during the compromise window was at risk of clipboard hijacking.

Adform31 Jul · 19:09 UTC
CISA warns of rising attacks on internet-exposed PLCs in water systemshighbug_reportVulnerability
bug_reportVulnerability

CISA warns of rising attacks on internet-exposed PLCs in water systems

Internet-exposed programmable logic controllers (PLCs) in U.S. water and wastewater systems. Specific vendors and models not disclosed in available information.

BleepingComputer31 Jul · 14:49 UTC
Adobe Campaign Classic critical RCE and file read flaws require patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Adobe Campaign Classic critical RCE and file read flaws require patching

Adobe Campaign Classic (specific versions not disclosed in advisory). Two vulnerabilities: one critical severity enabling arbitrary code execution, one high severity allowing file system read access.

Adobe31 Jul · 13:59 UTC
Critical vCenter vulnerabilities require immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical vCenter vulnerabilities require immediate patching

VMware vCenter Server component across multiple VMware product deployments. Specific affected versions not provided in advisory. Widespread impact expected given vCenter's role in VMware infrastructure management.

VMware31 Jul · 13:45 UTC
Chrome 149–151 fix 1,442 flaws as AI-driven bug discovery outpaces patchinghighbug_reportVulnerability
bug_reportVulnerability

Chrome 149–151 fix 1,442 flaws as AI-driven bug discovery outpaces patching

Google Chrome versions 149, 150, and 151 (released June–July 2026). All prior Chrome versions are affected by the resolved vulnerabilities. One critical flaw (CVE-2026-3545, CVSS 9.6) is a 13-year-old sandbox escape in Navigation component, patched i…

Google31 Jul · 10:51 UTC
84 flaws in 4G/5G core networks enable DoS and session hijackinghighbug_reportVulnerability
bug_reportVulnerability

84 flaws in 4G/5G core networks enable DoS and session hijacking

4G and 5G core network implementations: Open5GS (LTE/5G), free5GC, OpenAirInterface (LTE/5G), SD-Core, and eUPF. Vulnerabilities affect GTP-C and PFCP signaling protocols. 83 of 84 flaws confirmed, 81 assigned CVE identifiers.

The Hacker News31 Jul · 09:55 UTC
Cisco Secure Firewall Management Center under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Cisco Secure Firewall Management Center under active exploitation

Cisco Secure Firewall Management Center (formerly Firepower Management Center). Specific affected versions not disclosed in available data. Vulnerability details including CVE identifier not yet published.

Cisco31 Jul · 06:58 UTC
JetBrains TeamCity auth bypass enables RCE on all on-premises versionscriticalbug_reportVulnerability
bug_reportVulnerability

JetBrains TeamCity auth bypass enables RCE on all on-premises versions

JetBrains TeamCity On-Premises, all versions prior to 2025.11.7 and 2026.1.3. TeamCity Cloud is not affected. CVE-2026-63077 allows authentication bypass via agent polling protocol over HTTPS, leading to remote code execution with server process priv…

JetBrains30 Jul · 20:01 UTC
North Korea-linked actors compromise npm packages debug, chalk, axioshighbug_reportVulnerability
bug_reportVulnerability

North Korea-linked actors compromise npm packages debug, chalk, axios

Node Package Manager (npm) ecosystem: typo-crypto (March 2025), debug and chalk (September 2025, ~10% of cloud environments affected within 2 hours), axios (March 2026, 100M+ weekly downloads).

npm30 Jul · 16:13 UTC
VMware vCenter, ESXi critical flaws enable auth bypass and VM escapescriticalbug_reportVulnerability
bug_reportVulnerability

VMware vCenter, ESXi critical flaws enable auth bypass and VM escapes

VMware vCenter Server (versions prior to 9.1.0.0300, 9.0.2.0100, 8.0 U3k), VMware ESXi (versions prior to 9.1.0.0200, 9.0.2.0100, 8.0 U3k), VMware Workstation and Fusion (25H2 and earlier), VMware Cloud Foundation 5.x, VMware vSphere Foundation, VMwa…

VMware30 Jul · 16:00 UTC
Azure Cosmos DB sandbox escape exposed platform-wide key to all databasescriticalbug_reportVulnerability
bug_reportVulnerability

Azure Cosmos DB sandbox escape exposed platform-wide key to all databases

Microsoft Azure Cosmos DB, all customer tenants across all regions. Affects Gremlin, SQL, MongoDB, and Cassandra APIs. Vulnerability active from unknown date until July 2026 full remediation.

Microsoft30 Jul · 11:34 UTC
Multiple critical Xen Project vulnerabilities require immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Multiple critical Xen Project vulnerabilities require immediate patching

Xen Project hypervisor - specific affected versions not disclosed in available advisory. Impacts organizations running Xen-based virtualization infrastructure including cloud providers and enterprise data centers.

Xen Project30 Jul · 06:04 UTC
Russian APT exploits OWA XSS flaw for persistent mailbox accesshighbug_reportVulnerability
bug_reportVulnerability

Russian APT exploits OWA XSS flaw for persistent mailbox access

Microsoft Outlook Web Access (OWA) vulnerable to CVE-2026-42897 (CVSS 8.1), a cross-site scripting flaw. Targets include U.S. and European government entities, telecommunications, financial, hospitality, and aerospace sectors.

Microsoft30 Jul · 05:40 UTC
North Korea linked to npm supply chain attacks on debug, chalk, axioscriticalbug_reportVulnerability
bug_reportVulnerability

North Korea linked to npm supply chain attacks on debug, chalk, axios

npm packages debug, chalk, axios, typo-crypto, and Mastra (over 2 billion weekly downloads combined). Attacks spanned March 2025 through March 2026. Maintainer accounts compromised via phishing; malicious code injected to steal cryptocurrency wallet…

npm30 Jul · 04:05 UTC
Cisco FMC static credential flaw exploited in zero-day attackshighbug_reportVulnerability
bug_reportVulnerability

Cisco FMC static credential flaw exploited in zero-day attacks

Cisco Secure Firewall Management Center (FMC) Software versions 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. Does not affect Cloud-Delivered FMC, Firewall Device Manager, ASA Software, Threat Defense Software, or Security Cloud Control.

CVE-2026-2031629 Jul · 19:35 UTC
Rails Active Storage flaw allows file read via crafted image uploadscriticalbug_reportVulnerability
bug_reportVulnerability

Rails Active Storage flaw allows file read via crafted image uploads

Ruby on Rails 7.0.0–7.2.3.1, 8.0.0–8.0.5, 8.1.0–8.1.3 using Active Storage with libvips for image processing and accepting untrusted uploads. Rails 6.0.0–6.1.7.10 affected only when Vips explicitly configured (non-default).

CVE-2026-6606629 Jul · 16:10 UTC
Ruflo AI orchestration platform RCE allows full system compromise via MCPcriticalbug_reportVulnerability
bug_reportVulnerability

Ruflo AI orchestration platform RCE allows full system compromise via MCP

Ruflo (open-source AI agent orchestration platform for Anthropic Claude and OpenAI Codex), all versions before 3.16.3. Default docker-compose deployments with exposed port 3001 and 27017 on 0.0.0.0 are vulnerable.

CVE-2026-5972629 Jul · 13:39 UTC