Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 675 results
Active filter:✕ clear
CISA: Critical MLflow SSRF flaw (CVE-2026-64849) exploited in the wildcriticalbug_reportVulnerability
bug_reportVulnerability

CISA: Critical MLflow SSRF flaw (CVE-2026-64849) exploited in the wild

MLflow open-source AI engineering platform, all versions prior to 3.15.0. Default MLflow Tracking Server deployments without authentication are vulnerable.

MLflow20 Aug · 09:06 UTC
Manic Android malware exfiltrates data via nearby infected deviceshighbug_reportVulnerability
bug_reportVulnerability

Manic Android malware exfiltrates data via nearby infected devices

Android users in Central and Western Europe (including UK), Russia, and primarily Ukraine. Targets 169 banking, government/eID, payment, crypto wallet, messaging, and 2FA apps. Active since at least February 2026.

BleepingComputer20 Aug · 08:02 UTC
Zimbra RCE flaw CVE-2026-73570 actively exploited in the wildcriticalbug_reportVulnerability
bug_reportVulnerability

Zimbra RCE flaw CVE-2026-73570 actively exploited in the wild

Zimbra Collaboration Suite (ZCS) versions prior to 10.1.20. Affects servers with SNMP notifications enabled. Over 12,100 Zimbra servers exposed online, primarily in Europe (4,382) and Asia (4,492). Impacts businesses and government agencies globally.

Zimbra20 Aug · 07:46 UTC
Spectre attack on Cloudflare Workers leaks JWT at 12 bits/sechighbug_reportVulnerability
bug_reportVulnerability

Spectre attack on Cloudflare Workers leaks JWT at 12 bits/sec

Cloudflare Workers running on AMD EPYC Zen 2 and Zen 3 processors (Linux). Attack targets V8 isolates within shared Worker processes. Affects multi-tenant serverless environments relying on language-level isolation.

Cloudflare19 Aug · 17:02 UTC
Critical auth bypass and DoS flaws in Citrix NetScaler ADC/Gatewaycriticalbug_reportVulnerability
bug_reportVulnerability

Critical auth bypass and DoS flaws in Citrix NetScaler ADC/Gateway

Citrix NetScaler ADC and NetScaler Gateway versions 14.1 before 14.1-73.32, 13.1 before 13.1-63.21, NetScaler ADC FIPS before 14.1-73.32 FIPS, and FIPS/NDcPP before 13.1-37.277. CVE-2026-19489 affects devices with SIP ALG enabled on LSN groups.

Citrix19 Aug · 16:13 UTC
14,500 Dahua IP cameras compromised via brute-force and known CVEshighbug_reportVulnerability
bug_reportVulnerability

14,500 Dahua IP cameras compromised via brute-force and known CVEs

Dahua IP cameras globally, with concentration in Ukraine and Russia. Devices vulnerable to CVE-2021-33044 and CVE-2021-33045, those exposed on TCP port 37777, and cloud-registered cameras accessible via serial number recovery codes.

Dahua19 Aug · 16:09 UTC
Microsoft April 2026 Patch Tuesday: 163 vulnerabilities, 8 criticalcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft April 2026 Patch Tuesday: 163 vulnerabilities, 8 critical

Microsoft products and services across the ecosystem. 163 total vulnerabilities patched, including 8 critical severity issues. Specific affected products, CVE identifiers, and version details not provided in source material.

Microsoft19 Aug · 11:46 UTC
Zimbra Collaboration RCE under active exploitation, patch immediatelycriticalbug_reportVulnerability
bug_reportVulnerability

Zimbra Collaboration RCE under active exploitation, patch immediately

Zimbra Collaboration Suite - specific vulnerable versions not disclosed in advisory. Remote code execution vulnerability affecting internet-facing Zimbra instances.

Zimbra19 Aug · 11:28 UTC
CERT.BE warns of critical Oracle vulnerabilities requiring urgent patchinghighbug_reportVulnerability
bug_reportVulnerability

CERT.BE warns of critical Oracle vulnerabilities requiring urgent patching

Multiple Oracle products affected. Specific product names, versions, and CVE identifiers not provided in advisory. Scope appears broad across Oracle product portfolio based on CERT.BE warning classification.

Oracle19 Aug · 11:01 UTC
CISA flags 4 critical flaws in macOS, SharePoint, vCenter, IKE under attackcriticalbug_reportVulnerability
bug_reportVulnerability

CISA flags 4 critical flaws in macOS, SharePoint, vCenter, IKE under attack

Apple macOS (CVE-2026-65400, Screen Sharing authentication bypass), Microsoft SharePoint (CVE-2026-55040, weak authentication), Broadcom VMware vCenter (CVE-2026-59310, path traversal RCE), Microsoft IKE Service Extensions (CVE-2026-33824, double fre…

CVE-2026-6540019 Aug · 09:01 UTC
Windows IKE Extension RCE (CVE-2026-33824) actively exploitedcriticalbug_reportVulnerability
bug_reportVulnerability

Windows IKE Extension RCE (CVE-2026-33824) actively exploited

All supported Windows 10, Windows 11, and Windows Server versions. The vulnerability affects the Windows Internet Key Exchange (IKE) Service Extensions (MS-IKEE) component accessible via UDP ports 500 and 4500.

Microsoft19 Aug · 08:12 UTC
MacSync Stealer campaign uses 30+ rotating domains to target macOS usershighbug_reportVulnerability
bug_reportVulnerability

MacSync Stealer campaign uses 30+ rotating domains to target macOS users

macOS systems, all versions. Primary targets: users with AWS credentials, SSH keys, Kubernetes configs, browser credentials, and Keychain data. Organizations with macOS endpoints in development, DevOps, and cloud administration roles face elevated ri…

Microsoft19 Aug · 04:01 UTC
Clop deploys custom JSP web shell targeting PTC Windchill and FlexPLMcriticalbug_reportVulnerability
bug_reportVulnerability

Clop deploys custom JSP web shell targeting PTC Windchill and FlexPLM

PTC Windchill and FlexPLM servers vulnerable to CVE-2026-12569 (CVSS 9.3). All unpatched instances are at risk. These enterprise Product Lifecycle Management (PLM) systems store engineering data, product designs, and administrative credentials.

PTC19 Aug · 03:39 UTC
Microsoft Copilot Personal flaws enable one-click data exfiltration via URLhighbug_reportVulnerability
bug_reportVulnerability

Microsoft Copilot Personal flaws enable one-click data exfiltration via URL

Microsoft Copilot Personal (consumer assistant at copilot.microsoft.com). Research does not indicate Microsoft 365 Copilot is affected. Vulnerability tracked as CVE-2026-24301. Patched August 18, 2026.

Microsoft18 Aug · 15:47 UTC
MLflow SSRF and FUXA path traversal flaws under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

MLflow SSRF and FUXA path traversal flaws under active exploitation

MLflow versions < 3.15.0 (CVE-2026-64849, CVSS 9.3) and FUXA versions <= 1.2.9 (CVE-2026-25895, CVSS 9.5). MLflow is an open-source AI platform; FUXA is open-source SCADA/HMI software for industrial automation.

MLflow18 Aug · 15:44 UTC
MacSync Stealer targets macOS via ClickFix, rotates 30+ domainshighbug_reportVulnerability
bug_reportVulnerability

MacSync Stealer targets macOS via ClickFix, rotates 30+ domains

macOS devices. No specific version restrictions identified. Targets Keychain, browser data, credentials, SSH keys, and sensitive user files. Delivered via ClickFix social engineering (malicious Terminal commands).

Microsoft18 Aug · 15:08 UTC
GitLab CE/EE critical code injection flaw with public PoC exploitcriticalbug_reportVulnerability
bug_reportVulnerability

GitLab CE/EE critical code injection flaw with public PoC exploit

GitLab Community Edition (CE) and Enterprise Edition (EE). Specific affected versions not provided in source material. CVE identifier not yet assigned or disclosed.

GitLab18 Aug · 13:12 UTC
SAP Commerce Cloud, NetWeaver, MII: 4 critical flaws, 1 exploitedcriticalbug_reportVulnerability
bug_reportVulnerability

SAP Commerce Cloud, NetWeaver, MII: 4 critical flaws, 1 exploited

SAP Commerce Cloud, SAP NetWeaver, and SAP Manufacturing Integration and Intelligence (MII). Specific versions not disclosed in available data. At least 4 critical vulnerabilities confirmed.

SAP18 Aug · 13:07 UTC
Ray framework CVE-2025-62593 exploited via DNS rebinding for browser RCEcriticalbug_reportVulnerability
bug_reportVulnerability

Ray framework CVE-2025-62593 exploited via DNS rebinding for browser RCE

Ray open-source Python distributed computing framework, versions prior to 2.52.0. Primarily affects developers running development/testing environments. Over 43,500 GitHub stars indicate wide adoption in AI/ML workflows.

Ray18 Aug · 04:34 UTC
Critical GitLab GraphQL flaw allows unauthenticated project deletioncriticalbug_reportVulnerability
bug_reportVulnerability

Critical GitLab GraphQL flaw allows unauthenticated project deletion

GitLab Community Edition (CE) and Enterprise Edition (EE) self-managed installations: all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4.

CVE-2026-1947817 Aug · 19:03 UTC
Snowflake GitHub Actions workflow injection exposed Jira credentialshighbug_reportVulnerability
bug_reportVulnerability

Snowflake GitHub Actions workflow injection exposed Jira credentials

Snowflake's snowflakedb/snowflake-connector-net GitHub repository, specifically the .github/workflows/jira_issue.yml workflow. Vulnerable code was present on the default branch from June 18–23, 2026 (5-day window).

Snowflake17 Aug · 16:44 UTC
Forminator WordPress plugin RCE affects 600K+ sites via file upload bypasscriticalbug_reportVulnerability
bug_reportVulnerability

Forminator WordPress plugin RCE affects 600K+ sites via file upload bypass

Forminator Forms WordPress plugin versions ≤1.56.1. Affects 600,000+ active installations. Exploitation requires a form with both File Upload and Select fields. Sites using custom file upload storage paths are at higher risk.

CVE-2026-1574817 Aug · 16:22 UTC
GeoServer zero-day SQL injection under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

GeoServer zero-day SQL injection under active exploitation

GeoServer (specific versions not disclosed in advisory). All unpatched instances potentially vulnerable to SQL injection attacks.

GeoServer17 Aug · 12:17 UTC
Certighost (CVE-2026-54121): Domain user can escalate to DC via CAcriticalbug_reportVulnerability
bug_reportVulnerability

Certighost (CVE-2026-54121): Domain user can escalate to DC via CA

Microsoft Active Directory Certificate Services (AD CS) in Enterprise CA configurations. All versions prior to July 14, 2026 patch. Affects organizations with default AD settings including MachineAccountQuota allowing machine account creation by stan…

CVE-2026-5412117 Aug · 12:00 UTC
Ivanti EPM high severity flaws require immediate patchinghighbug_reportVulnerability
bug_reportVulnerability

Ivanti EPM high severity flaws require immediate patching

Ivanti Endpoint Manager (EPM). Specific affected versions not disclosed in available advisory. CVE identifiers not yet assigned or published.

Ivanti17 Aug · 11:57 UTC
Unisoc modem flaw enables Android kernel takeover via VoLTE video callcriticalbug_reportVulnerability
bug_reportVulnerability

Unisoc modem flaw enables Android kernel takeover via VoLTE video call

Unisoc chipsets T606, T612, and T7250 used in Motorola E13, Realme C33, and Xiaomi Redmi A5. Devices with these chipsets sold across 140+ countries. Confirmed vulnerable on Motorola E13 (February 2025 patch) and Xiaomi Redmi A5 (January 2026 patch).

Unisoc17 Aug · 08:52 UTC
IBM i systems face critical vulnerabilities requiring immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

IBM i systems face critical vulnerabilities requiring immediate patching

IBM i systems (formerly AS/400). Specific versions and CVE identifiers not disclosed in advisory. Scope appears to be multiple severe vulnerabilities across the platform.

IBM17 Aug · 07:37 UTC
Evooo1Bot botnet exploits 18 CVEs to turn edge devices into SOCKS5 proxieshighbug_reportVulnerability
bug_reportVulnerability

Evooo1Bot botnet exploits 18 CVEs to turn edge devices into SOCKS5 proxies

Internet-facing Linux-based edge devices including routers (NETGEAR, Tenda, D-Link, TP-Link, Zyxel), IP cameras (Hikvision), enterprise appliances (Alcatel OmniPCX, Mitsubishi ME-RTU, Telesquare SDT-CW3B1/TLR-2005KSH), and servers running vulnerable…

The Hacker News17 Aug · 07:29 UTC
Adobe Commerce critical vulnerability under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Adobe Commerce critical vulnerability under active exploitation

Adobe Commerce (formerly Magento). Specific affected versions not disclosed in advisory. All unpatched instances should be considered at risk.

Adobe17 Aug · 07:14 UTC
Microsoft Defender ShieldBreak zero-day grants SYSTEM privileges on Windowshighbug_reportVulnerability
bug_reportVulnerability

Microsoft Defender ShieldBreak zero-day grants SYSTEM privileges on Windows

Microsoft Defender on Windows 10, Windows 11 (including 25H2 and Canary), and Windows Server 2025. All fully patched systems with Defender enabled are vulnerable.

CVE-2026-6941417 Aug · 07:05 UTC