Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
satellite_altDaily BriefCyber Threat Daily Brief — September 4, 2026
Today's briefing: 14 critical and 22 high-severity threats. A total of 47 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.
Latest Reports
28 / 1136 results
highbug_reportVulnerabilitySupply-chain attack targets Android car head units via update app
Android-based automotive head units receiving updates through a compromised legitimate device-update application. Specific vendors, models, and geographic distribution not disclosed.
highbug_reportVulnerabilityAttackers shift focus to CI/CD pipelines and developer tools in SDLC
All organizations using modern software development practices with CI/CD pipelines, open-source dependencies, and developer tools. Specific recent attacks include ChainDrop npm worm (400+ packages including keyv and cacheable-request), XZ Utils (CVE-…
highbug_reportVulnerability14 trojanized npm packages deliver AI-powered RedC2 4.0 Linux backdoor
14 npm packages (streak-metrics-math, kit-map-vim, streak-map-cache, streak-map-kit, map-streak-kit, streak-cache-map, streak-calc-metrics, streak-calc-math, streak-math-abz, streak-metricsaz, streak-math-metrics, streak-metricazbd, streak-metricsazb…
highbug_reportVulnerabilitySynkLoader malware spreads via Microsoft Teams phishing campaigns
Microsoft Teams users across all organizations. SynkLoader is a new credential-stealing malware family delivered through phishing messages on the Teams platform. No specific product versions or CVEs identified.
highbug_reportVulnerabilityMicrosoft Defender BTR.sys driver weaponized for kernel-level sabotage
Microsoft Defender BTR.sys driver on all Windows versions from Windows 7 through Windows 11 25H2. The driver is a required component shipped with every Windows installation and cannot be blocked without breaking Defender functionality.
criticalbug_reportVulnerabilityCISA orders patching of two actively exploited TrueConf Server flaws
TrueConf Server, a self-hosted corporate messaging and video conferencing platform. CVE-2026-72529 (critical missing authentication allowing remote script execution via TCP port 4307) and CVE-2026-72530 (critical sandbox escape enabling arbitrary OS…
criticalbug_reportVulnerabilityMicrosoft Entra ID deserialization flaw exploited; already patched
Microsoft Entra ID (formerly Azure Active Directory) cloud-based identity and access management platform. All versions prior to Microsoft's server-side patch.
highbug_reportVulnerabilityThreat actors abuse FTP banners to deliver E4del and PINHOLE RATs
Windows systems targeted via phishing campaigns delivering LNK files. Two RATs deployed: E4del (Node.js/Electron-based, masquerading as Discord) and PINHOLE (memory-resident, using Pinterest/SurveyMonkey for C2).
criticalbug_reportVulnerabilityCisco patches nine flaws in Crosswork and Secure Workload; five rated 10.0
Cisco Crosswork Data Gateway, Crosswork Network Controller, Crosswork Planning (Release 7.2.1 and earlier); Cisco Secure Workload SaaS and on-premises (Release 3.10 and earlier, Release 4.0).
criticalbug_reportVulnerabilityGitLab CVE-2026-19478 code injection under active exploitation
GitLab Community Edition (CE) and Enterprise Edition (EE): versions 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. Affects self-hosted instances with publicly accessible projects.
criticalbug_reportVulnerabilityMicrosoft patches critical Entra ID RCE flaw (CVE-2026-69836, CVSS 10.0)
Microsoft Entra ID (formerly Azure Active Directory), all versions. Cloud-based identity and access management service. Microsoft has already deployed server-side mitigations; no customer action required.
criticalbug_reportVulnerabilityRust crates compromised via account takeover; build-time malware deployed
Three Rust crates (arrayref 0.3.10, internment 0.8.7, append-only-vec 0.1.9) with 245 million combined downloads. Malicious versions were live for 86-107 minutes on August 20, 2026.
highperson_alertThreat ActorUNC6293, UNC7005, UNC5976 Abuse OAuth and WhatsApp Linking for Espionage
UNC6293, UNC7005, and UNC5976 are three distinct suspected Russian cyber espionage threat clusters conducting persistent account compromise operations. UNC6293 is assessed to be a sub-cluster of Ice Relic (formerly APT29, also tracked as Cozy Bear an…
criticalbug_reportVulnerabilityZero-click RCE in Zoom clients requires immediate patching
Zoom clients (specific versions not disclosed in available data). Zero-click remote code execution vulnerability affects users without interaction required.
criticalbug_reportVulnerabilityRust crate arrayref compromised via maintainer account takeover
Rust crate arrayref (vendor: arrayref). Specific malicious versions not detailed in source. Affects developers using this dependency during compilation. Scope: Rust ecosystem supply chain.
highbug_reportVulnerabilityGogs 10.0 RCE and n8n workflow-to-RCE vulnerabilities disclosed
Gogs version 10.0 (Git service) and n8n (workflow automation platform) - specific n8n versions not provided. Multiple attack vectors disclosed including signed driver abuse (Microsoft Defender BTR.sys), DLL sideloading via Grandoreiro, and ErrTraffic…
highperson_alertThreat ActorAI-Generated Exploits Target Siemens S7 PLCs in U.S. Critical Infrastructure
This campaign involves unattributed threat actors leveraging artificial intelligence to generate exploitation scripts targeting industrial control systems.
criticalbug_reportVulnerabilityElementor Pro WordPress plugin allows arbitrary file upload and RCE
Elementor Pro WordPress plugin. Specific vulnerable versions not disclosed in available data. Affects WordPress sites with Elementor Pro installed.
highbug_reportVulnerabilityGrok chatbot vulnerable to data exfiltration via encrypted prompt injection
xAI Grok 4.5 Fast (web chat at grok.com). Google Gemini 3 Flash (Web) in Deep Thinking mode also demonstrated vulnerable in March 2026. Affects users requesting web page summaries through the chatbot interface.
criticalbug_reportVulnerabilityRed Hat Keycloak password-reset flaw enables account takeover
Red Hat build of Keycloak, specific versions not disclosed in source. Vulnerability exists in the password-reset flow mechanism.
criticalbug_reportVulnerabilityCitrix NetScaler ADC/Gateway auth bypass requires immediate patching
Citrix NetScaler ADC and NetScaler Gateway products. Specific affected versions not disclosed in available information. Authentication bypass vulnerability allows unauthorized access.
criticalbug_reportVulnerabilityCritical sandbox escape in isolated-vm ≤7.0.0 enables RCE on host
isolated-vm library versions ≤7.0.0. Patched in versions 6.2.0 and 7.0.1. Affects Node.js environments using isolated-vm for sandboxing untrusted JavaScript. Package has ~1 million weekly npm downloads.
criticalbug_reportVulnerabilityCritical auth bypass in NetScaler Gateway/AAA servers (CVE-2026-19490)
Citrix NetScaler ADC and NetScaler Gateway customer-managed instances: versions 14.1 before 14.1-73.32, 13.1 before 13.1-63.21, FIPS builds before 14.1-73.32 FIPS and 13.1-37.277.
highbug_reportVulnerabilityZimbra SNMP flaw CVE-2026-73570 under active exploitation for RCE
Zimbra Collaboration Server (ZCS) versions before 10.1.20, only when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Unauthenticated remote attackers can exploit this command injection flaw.
highbug_reportVulnerabilityCitrix urges immediate patching of NetScaler auth bypass and DoS flaws
Citrix NetScaler ADC and NetScaler Gateway appliances (all supported versions prior to 14.1-73.32 and 13.1-63.21). CVE-2026-19490 affects appliances configured as AAA virtual server or Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) with SAML authentic…
highbug_reportVulnerabilityZombie Card attack revives expired Visa contactless cards via NFC relay
Visa contactless credit cards using Kernel 3 specification. Attack requires physical card access or sustained NFC proximity, plus relay device between card and terminal. Five major US banks tested; three confirmed vulnerable with varying policies.
criticalbug_reportVulnerabilityCISA: Critical MLflow SSRF flaw (CVE-2026-64849) exploited in the wild
MLflow open-source AI engineering platform, all versions prior to 3.15.0. Default MLflow Tracking Server deployments without authentication are vulnerable.
highbug_reportVulnerabilityManic Android malware exfiltrates data via nearby infected devices
Android users in Central and Western Europe (including UK), Russia, and primarily Ukraine. Targets 169 banking, government/eID, payment, crypto wallet, messaging, and 2FA apps. Active since at least February 2026.