Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 675 results
criticalbug_reportVulnerabilityCISA: Critical MLflow SSRF flaw (CVE-2026-64849) exploited in the wild
MLflow open-source AI engineering platform, all versions prior to 3.15.0. Default MLflow Tracking Server deployments without authentication are vulnerable.
highbug_reportVulnerabilityManic Android malware exfiltrates data via nearby infected devices
Android users in Central and Western Europe (including UK), Russia, and primarily Ukraine. Targets 169 banking, government/eID, payment, crypto wallet, messaging, and 2FA apps. Active since at least February 2026.
criticalbug_reportVulnerabilityZimbra RCE flaw CVE-2026-73570 actively exploited in the wild
Zimbra Collaboration Suite (ZCS) versions prior to 10.1.20. Affects servers with SNMP notifications enabled. Over 12,100 Zimbra servers exposed online, primarily in Europe (4,382) and Asia (4,492). Impacts businesses and government agencies globally.
highbug_reportVulnerabilitySpectre attack on Cloudflare Workers leaks JWT at 12 bits/sec
Cloudflare Workers running on AMD EPYC Zen 2 and Zen 3 processors (Linux). Attack targets V8 isolates within shared Worker processes. Affects multi-tenant serverless environments relying on language-level isolation.
criticalbug_reportVulnerabilityCritical auth bypass and DoS flaws in Citrix NetScaler ADC/Gateway
Citrix NetScaler ADC and NetScaler Gateway versions 14.1 before 14.1-73.32, 13.1 before 13.1-63.21, NetScaler ADC FIPS before 14.1-73.32 FIPS, and FIPS/NDcPP before 13.1-37.277. CVE-2026-19489 affects devices with SIP ALG enabled on LSN groups.
highbug_reportVulnerability14,500 Dahua IP cameras compromised via brute-force and known CVEs
Dahua IP cameras globally, with concentration in Ukraine and Russia. Devices vulnerable to CVE-2021-33044 and CVE-2021-33045, those exposed on TCP port 37777, and cloud-registered cameras accessible via serial number recovery codes.
criticalbug_reportVulnerabilityMicrosoft April 2026 Patch Tuesday: 163 vulnerabilities, 8 critical
Microsoft products and services across the ecosystem. 163 total vulnerabilities patched, including 8 critical severity issues. Specific affected products, CVE identifiers, and version details not provided in source material.
criticalbug_reportVulnerabilityZimbra Collaboration RCE under active exploitation, patch immediately
Zimbra Collaboration Suite - specific vulnerable versions not disclosed in advisory. Remote code execution vulnerability affecting internet-facing Zimbra instances.
highbug_reportVulnerabilityCERT.BE warns of critical Oracle vulnerabilities requiring urgent patching
Multiple Oracle products affected. Specific product names, versions, and CVE identifiers not provided in advisory. Scope appears broad across Oracle product portfolio based on CERT.BE warning classification.
criticalbug_reportVulnerabilityCISA flags 4 critical flaws in macOS, SharePoint, vCenter, IKE under attack
Apple macOS (CVE-2026-65400, Screen Sharing authentication bypass), Microsoft SharePoint (CVE-2026-55040, weak authentication), Broadcom VMware vCenter (CVE-2026-59310, path traversal RCE), Microsoft IKE Service Extensions (CVE-2026-33824, double fre…
criticalbug_reportVulnerabilityWindows IKE Extension RCE (CVE-2026-33824) actively exploited
All supported Windows 10, Windows 11, and Windows Server versions. The vulnerability affects the Windows Internet Key Exchange (IKE) Service Extensions (MS-IKEE) component accessible via UDP ports 500 and 4500.
highbug_reportVulnerabilityMacSync Stealer campaign uses 30+ rotating domains to target macOS users
macOS systems, all versions. Primary targets: users with AWS credentials, SSH keys, Kubernetes configs, browser credentials, and Keychain data. Organizations with macOS endpoints in development, DevOps, and cloud administration roles face elevated ri…
criticalbug_reportVulnerabilityClop deploys custom JSP web shell targeting PTC Windchill and FlexPLM
PTC Windchill and FlexPLM servers vulnerable to CVE-2026-12569 (CVSS 9.3). All unpatched instances are at risk. These enterprise Product Lifecycle Management (PLM) systems store engineering data, product designs, and administrative credentials.
highbug_reportVulnerabilityMicrosoft Copilot Personal flaws enable one-click data exfiltration via URL
Microsoft Copilot Personal (consumer assistant at copilot.microsoft.com). Research does not indicate Microsoft 365 Copilot is affected. Vulnerability tracked as CVE-2026-24301. Patched August 18, 2026.
criticalbug_reportVulnerabilityMLflow SSRF and FUXA path traversal flaws under active exploitation
MLflow versions < 3.15.0 (CVE-2026-64849, CVSS 9.3) and FUXA versions <= 1.2.9 (CVE-2026-25895, CVSS 9.5). MLflow is an open-source AI platform; FUXA is open-source SCADA/HMI software for industrial automation.
highbug_reportVulnerabilityMacSync Stealer targets macOS via ClickFix, rotates 30+ domains
macOS devices. No specific version restrictions identified. Targets Keychain, browser data, credentials, SSH keys, and sensitive user files. Delivered via ClickFix social engineering (malicious Terminal commands).
criticalbug_reportVulnerabilityGitLab CE/EE critical code injection flaw with public PoC exploit
GitLab Community Edition (CE) and Enterprise Edition (EE). Specific affected versions not provided in source material. CVE identifier not yet assigned or disclosed.
criticalbug_reportVulnerabilitySAP Commerce Cloud, NetWeaver, MII: 4 critical flaws, 1 exploited
SAP Commerce Cloud, SAP NetWeaver, and SAP Manufacturing Integration and Intelligence (MII). Specific versions not disclosed in available data. At least 4 critical vulnerabilities confirmed.
criticalbug_reportVulnerabilityRay framework CVE-2025-62593 exploited via DNS rebinding for browser RCE
Ray open-source Python distributed computing framework, versions prior to 2.52.0. Primarily affects developers running development/testing environments. Over 43,500 GitHub stars indicate wide adoption in AI/ML workflows.
criticalbug_reportVulnerabilityCritical GitLab GraphQL flaw allows unauthenticated project deletion
GitLab Community Edition (CE) and Enterprise Edition (EE) self-managed installations: all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4.
highbug_reportVulnerabilitySnowflake GitHub Actions workflow injection exposed Jira credentials
Snowflake's snowflakedb/snowflake-connector-net GitHub repository, specifically the .github/workflows/jira_issue.yml workflow. Vulnerable code was present on the default branch from June 18–23, 2026 (5-day window).
criticalbug_reportVulnerabilityForminator WordPress plugin RCE affects 600K+ sites via file upload bypass
Forminator Forms WordPress plugin versions ≤1.56.1. Affects 600,000+ active installations. Exploitation requires a form with both File Upload and Select fields. Sites using custom file upload storage paths are at higher risk.
criticalbug_reportVulnerabilityGeoServer zero-day SQL injection under active exploitation
GeoServer (specific versions not disclosed in advisory). All unpatched instances potentially vulnerable to SQL injection attacks.
criticalbug_reportVulnerabilityCertighost (CVE-2026-54121): Domain user can escalate to DC via CA
Microsoft Active Directory Certificate Services (AD CS) in Enterprise CA configurations. All versions prior to July 14, 2026 patch. Affects organizations with default AD settings including MachineAccountQuota allowing machine account creation by stan…
highbug_reportVulnerabilityIvanti EPM high severity flaws require immediate patching
Ivanti Endpoint Manager (EPM). Specific affected versions not disclosed in available advisory. CVE identifiers not yet assigned or published.
criticalbug_reportVulnerabilityUnisoc modem flaw enables Android kernel takeover via VoLTE video call
Unisoc chipsets T606, T612, and T7250 used in Motorola E13, Realme C33, and Xiaomi Redmi A5. Devices with these chipsets sold across 140+ countries. Confirmed vulnerable on Motorola E13 (February 2025 patch) and Xiaomi Redmi A5 (January 2026 patch).
criticalbug_reportVulnerabilityIBM i systems face critical vulnerabilities requiring immediate patching
IBM i systems (formerly AS/400). Specific versions and CVE identifiers not disclosed in advisory. Scope appears to be multiple severe vulnerabilities across the platform.
highbug_reportVulnerabilityEvooo1Bot botnet exploits 18 CVEs to turn edge devices into SOCKS5 proxies
Internet-facing Linux-based edge devices including routers (NETGEAR, Tenda, D-Link, TP-Link, Zyxel), IP cameras (Hikvision), enterprise appliances (Alcatel OmniPCX, Mitsubishi ME-RTU, Telesquare SDT-CW3B1/TLR-2005KSH), and servers running vulnerable…
criticalbug_reportVulnerabilityAdobe Commerce critical vulnerability under active exploitation
Adobe Commerce (formerly Magento). Specific affected versions not disclosed in advisory. All unpatched instances should be considered at risk.
highbug_reportVulnerabilityMicrosoft Defender ShieldBreak zero-day grants SYSTEM privileges on Windows
Microsoft Defender on Windows 10, Windows 11 (including 25H2 and Canary), and Windows Server 2025. All fully patched systems with Defender enabled are vulnerable.