Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
satellite_altDaily BriefCyber Threat Daily Brief — July 20, 2026
Today's briefing: 3 critical and 4 high-severity threats. A total of 10 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.
Latest Reports
27 / 584 results
highperson_alertThreat ActorU.S. offers $10M reward for intel on UNC5792 and UNC4221 APT groups
UNC5792 and UNC4221 are threat actor groups attributed to Russian intelligence and military services. Both groups have been designated as high-priority targets by the U.S.
criticalbug_reportVulnerabilityDell Wyse RCE flaw exploitable by low-privileged attackers
Dell Wyse thin client products. Specific affected models and firmware versions not disclosed in summary. Vulnerability enables remote code execution with low privilege requirements.
highperson_alertThreat ActorMustang Panda Targets Indian Government and Hydropower Infrastructure
Mustang Panda (also tracked as TA416, RedDelta, BRONZE PRESIDENT, and STATELY TAURUS) is a China-aligned advanced persistent threat group focused on espionage operations.
criticalbug_reportVulnerabilitySimpleHelp CVE-2026-48558 exploited to deploy Djinn Stealer malware
SimpleHelp remote support software (specific versions not disclosed). Affects organizations using SimpleHelp for remote access and support operations across Windows, macOS, and Linux environments.
criticalbug_reportVulnerabilityOracle E-Business Suite under active exploit via CVE-2026-46817
Oracle E-Business Suite (EBS) financial application. Specific affected versions not disclosed in available intelligence.
highbug_reportVulnerabilityStack buffer overflow in libxml2 enables code execution via malformed input
libxml2 library, all versions not yet patched. Affects systems and applications that parse XML using libxml2, including numerous Linux distributions, Python, PHP, and other software that depends on this widely-deployed XML parsing library.
highbug_reportVulnerability236K+ malicious sites use DCloud Uni-App templates for crypto scams
Organizations and users interacting with websites built using DCloud Uni-App framework templates. Over 236,000 malicious sites identified conducting cryptocurrency scams, phishing, wallet draining, pig-butchering schemes, and fake gambling platforms.
highperson_alertThreat ActorGamaredon APT Expands Ukraine Operations with 35 Spear-Phishing Campaigns
Gamaredon (also tracked as Armageddon, Shuckworm, Primitive Bear, and UAC-0010) is a Russian state-sponsored APT group attributed by multiple vendors to Russia's Federal Security Service (FSB).
criticalbug_reportVulnerabilityCritical RCE flaw in PTC Windchill and FlexPLM requires immediate patching
PTC Windchill and FlexPLM products. Specific affected versions not disclosed in available data. Both products are enterprise Product Lifecycle Management (PLM) platforms widely used in manufacturing and engineering environments.
highbug_reportVulnerabilityMicrosoft removes 119 malicious Edge extensions hiding malware via steganography
Microsoft Edge browser users who installed any of 119 malicious extensions from the official Microsoft Edge Add-ons store. Campaign active since at least 2021, affecting unknown number of users globally.
highbug_reportVulnerabilityMicrosoft Exchange privilege escalation flaw requires immediate patching
Microsoft Exchange Server 2016, 2019, and Subscription Edition. All on-premises deployments of these versions are potentially affected.
criticalbug_reportVulnerabilitylibssh2 RCE via malicious SSH server (CVE-2026-55200), PoC public
libssh2 library versions up to and including 1.11.1. Affects any application or system using libssh2 for SSH client connections, including Git, curl, rsync wrappers, and custom SSH clients.
highbug_reportVulnerabilityHijacked npm and Go packages deploy cross-platform stealer via VS Code
Compromised npm and Go packages targeting developers using Microsoft Visual Studio Code on Windows, Linux, and macOS. Attack bypasses npm v12 lifecycle script protections by abusing VS Code task execution.
highpublicGeopoliticalKDDI breach exposes 14.2M email accounts across Japanese ISP ecosystem
The breach at KDDI Corporation, one of Japan's largest telecommunications operators, highlights systemic vulnerabilities in shared infrastructure models within critical communications sectors.
highperson_alertThreat ActorRussian Intelligence Services Target Messaging Accounts via Phishing
Russian intelligence services conducted a long-running credential harvesting campaign targeting messaging platforms. The operation, uncovered jointly by Ukraine's Security Service (SSU) and the FBI, focused on stealing authentication credentials from…
highbug_reportVulnerabilityAgentic coding tools vulnerable to hidden malicious payloads in repos
Agentic coding tools and AI-assisted development platforms that automatically fetch and execute code from GitHub repositories. Specific products not disclosed.
highperson_alertThreat ActorRussian Intelligence Services Target Signal Users in Phishing Campaign
Russian intelligence services are conducting a phishing campaign targeting Signal messaging application users. The operation is attributed by the FBI and CISA, indicating state-sponsored activity aimed at compromising secure communications.
criticalbug_reportVulnerabilityCISA orders federal patch for exploited Cisco Unified Comms flaw
Cisco Unified Communications Manager Server. Specific versions not disclosed. Federal agencies mandated to patch; all organizations running this product should consider affected.
highperson_alertThreat ActorRussian Intelligence Escalates Signal Phishing for Backup Recovery Keys
Russian intelligence actors, as identified by FBI and CISA joint reporting, are conducting targeted phishing operations against Signal messaging platform users.
highbug_reportVulnerabilitySharkLoader malware deploys Cobalt Strike in attacks on Asian governments
Diplomatic and government organizations in Indonesia and Taiwan. SharkLoader is a newly identified malware family used to deliver Cobalt Strike Beacon payloads in the StrikeShark campaign.
highbug_reportVulnerabilityPolymarket frontend compromised via third-party vendor; $3M stolen
Polymarket platform users. Attack vector: malicious JavaScript injected into frontend via compromised third-party vendor. Approximately $3 million in customer funds stolen. No CVE assigned.
highperson_alertThreat ActorUnknown Actors Exploit OpenAI Tenants to Phish Cybersecurity Firms
The threat actors behind this campaign remain unattributed. Their motivation appears to be intelligence gathering and corporate espionage, leveraging the trust associated with OpenAI's platform to deceive employees of cybersecurity companies.
highperson_alertThreat ActorCL-STA-1062 deploys TinyRCT backdoor against Southeast Asian government
CL-STA-1062 is a Chinese-speaking APT actor conducting targeted cyber espionage operations against government entities and critical infrastructure in Southeast Asia.
criticalbug_reportVulnerabilityLinux kernel traffic-control flaw grants local root via public exploit
Linux kernel traffic-control subsystem (act_pedit module). All distributions running vulnerable kernel versions are affected. Specific patched versions not provided; assume unpatched kernels prior to June 16, 2026 vendor advisories are vulnerable.
highbug_reportVulnerabilityAmazon Q Developer flaw allows credential theft via malicious repos
Amazon Q Developer (all versions prior to patch). Affects developers using the IDE plugin who clone or open malicious repositories containing crafted Model Context Protocol (MCP) server configurations.
criticalbug_reportVulnerabilityPTC Windchill and FlexPLM RCE actively exploited in web shell attacks
PTC Windchill PDMlink and PTC FlexPLM Product Lifecycle Management systems. Specific affected versions not disclosed in summary; consult CISA KEV catalog and PTC security advisories for version details.
highbug_reportVulnerabilityDirtyClone Linux kernel flaw enables local privilege escalation to root
Linux kernel (specific vulnerable versions not disclosed). Affects systems where local users can trigger network packet cloning operations. Part of the DirtyFrag vulnerability family.