Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-21 · 02:09 UTC
articleTotal: 606 reports

Filtered Reports

30 / 163 results
Active filter:tag: #critical✕ clear
Critical RCE vulnerability in LiquidJS requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical RCE vulnerability in LiquidJS requires immediate patching

LiquidJS templating engine, all versions prior to patched release. Specific vulnerable version range not provided in available data.

LiquidJS12:20 UTC
Dell Container Storage Modules info disclosure enables data exfiltrationcriticalbug_reportVulnerability
bug_reportVulnerability

Dell Container Storage Modules info disclosure enables data exfiltration

Dell Container Storage Modules (specific versions not disclosed in summary). Vulnerability allows information disclosure that can lead to data exfiltration and lateral movement within containerized environments.

Dell11:55 UTC
Apache ActiveMQ NMS AMQP Client deserialization flaw enables RCEcriticalbug_reportVulnerability
bug_reportVulnerability

Apache ActiveMQ NMS AMQP Client deserialization flaw enables RCE

Apache ActiveMQ NMS AMQP Client - specific vulnerable versions not provided. Affects .NET/C# applications using the NMS AMQP client library for message queue operations.

Apache14:59 UTC
Microsoft SharePoint RCE vulnerability requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft SharePoint RCE vulnerability requires immediate patching

Microsoft SharePoint Server (specific versions not disclosed in advisory). Organizations running on-premises SharePoint deployments are affected. SharePoint Online managed by Microsoft likely already patched.

Microsoft14:23 UTC
CISA orders federal agencies to patch LiteSpeed cPanel plugin in 4 dayscriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders federal agencies to patch LiteSpeed cPanel plugin in 4 days

LiteSpeed cPanel user-end plugin. Specific vulnerable versions not disclosed. Affects organizations using cPanel with LiteSpeed integration.

LiteSpeed08:06 UTC
Zero-day in KnowledgeDeliver LMS exploited to deploy Godzilla web shellcriticalbug_reportVulnerability
bug_reportVulnerability

Zero-day in KnowledgeDeliver LMS exploited to deploy Godzilla web shell

KnowledgeDeliver learning management system (specific versions unknown). Exploitation results in web shell deployment enabling persistent remote access to affected servers.

KnowledgeDeliver18:07 UTC
LiteSpeed cPanel/WHM plugin under active exploit (CVE-2026-48172)criticalbug_reportVulnerability
bug_reportVulnerability

LiteSpeed cPanel/WHM plugin under active exploit (CVE-2026-48172)

LiteSpeed plugin for cPanel/WHM. Specific vulnerable versions not disclosed in provided data. Affects web hosting environments using LiteSpeed with cPanel/WHM integration.

CVE-2026-4817214:28 UTC
Ubiquiti patches critical UniFi OS vulnerabilitiescriticalbug_reportVulnerability
bug_reportVulnerability

Ubiquiti patches critical UniFi OS vulnerabilities

Ubiquiti UniFi OS (specific versions not disclosed). Affects UniFi network management appliances including Dream Machine, Cloud Key, and similar devices running UniFi OS.

Ubiquiti14:13 UTC
Trend Micro Apex One & Vision One SEP flaws under active exploitcriticalbug_reportVulnerability
bug_reportVulnerability

Trend Micro Apex One & Vision One SEP flaws under active exploit

Trend Micro Apex One and Trend Micro Vision One Endpoint Security (SEP). Specific vulnerable versions not disclosed in summary; multiple vulnerabilities confirmed under active exploitation.

Trend Micro08:17 UTC
Critical vulnerability in Cisco Secure Workload requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical vulnerability in Cisco Secure Workload requires immediate patching

Cisco Secure Workload (specific versions not disclosed in advisory). CVE identifier not yet assigned or published.

Cisco06:50 UTC
CISA orders emergency patching of exploited Drupal SQL injection flawcriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders emergency patching of exploited Drupal SQL injection flaw

Drupal CMS (specific versions not provided in alert). Affects U.S. government agencies and all organizations running vulnerable Drupal instances.

Drupal06:46 UTC
Ghost CMS SQL injection (CVE-2026-26980) exploited in ClickFix campaigncriticalbug_reportVulnerability
bug_reportVulnerability

Ghost CMS SQL injection (CVE-2026-26980) exploited in ClickFix campaign

Ghost CMS Content API, all versions prior to patch. Over 700 sites confirmed compromised. Unauthenticated attackers can exploit the SQL injection vulnerability remotely.

CVE-2026-2698010:02 UTC
TrapDoor campaign deploys credential stealers across npm, PyPI, Crates.iocriticalbug_reportVulnerability
bug_reportVulnerability

TrapDoor campaign deploys credential stealers across npm, PyPI, Crates.io

34+ malicious packages (384+ versions) distributed across npm (Node.js), PyPI (Python), and Crates.io (Rust) repositories. Campaign active since May 2026. Affects developers and CI/CD pipelines consuming packages from these ecosystems.

npm03:59 UTC
ClickFix Campaign Exploits Ghost CMS SQLi to Inject Malicious JavaScriptcriticalperson_alertThreat Actor
person_alertThreat Actor

ClickFix Campaign Exploits Ghost CMS SQLi to Inject Malicious JavaScript

The threat actor behind this campaign remains unattributed. Motivation appears to be financially driven, leveraging ClickFix social engineering tactics to deliver malware or steal credentials.

CVE-2026-2698012:12 UTC
CISA Contractor Leaks AWS GovCloud Keys on Public GitHub Repositorycriticalperson_alertThreat Actor
person_alertThreat Actor

CISA Contractor Leaks AWS GovCloud Keys on Public GitHub Repository

The threat actor is an insider—a contractor working for the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The individual intentionally published sensitive AWS GovCloud credentials and agency secrets to a public GitHub repository.

Amazon Web Services14:34 UTC
Trend Micro Apex One zero-day actively exploited in the wildcriticalbug_reportVulnerability
bug_reportVulnerability

Trend Micro Apex One zero-day actively exploited in the wild

Trend Micro Apex One on Windows systems. Specific affected versions not disclosed. Zero-day vulnerability with no CVE assigned yet.

Trend Micro11:39 UTC
Drupal SQL injection under active exploitation, patch immediatelycriticalbug_reportVulnerability
bug_reportVulnerability

Drupal SQL injection under active exploitation, patch immediately

Drupal CMS installations. Specific affected versions not provided in available data. Critical SQL injection vulnerability announced this week, now actively exploited.

Drupal11:14 UTC
Ubiquiti patches three critical unauthenticated RCE flaws in UniFi OScriticalbug_reportVulnerability
bug_reportVulnerability

Ubiquiti patches three critical unauthenticated RCE flaws in UniFi OS

Ubiquiti UniFi OS (specific versions not disclosed). Affects UniFi network management appliances including Dream Machine, Cloud Key, and other UniFi OS-based devices.

Ubiquiti10:00 UTC
CISA: Langflow and Trend Micro Apex One flaws actively exploitedcriticalbug_reportVulnerability
bug_reportVulnerability

CISA: Langflow and Trend Micro Apex One flaws actively exploited

Langflow (CVE-2025-34291, CVSS 9.4, origin validation error) and Trend Micro Apex One (CVE unspecified). Both products confirmed under active exploitation. Specific affected versions not disclosed in summary.

CVE-2025-3429103:47 UTC
Cisco Secure Workload REST API flaw allows unauthenticated data accesscriticalbug_reportVulnerability
bug_reportVulnerability

Cisco Secure Workload REST API flaw allows unauthenticated data access

Cisco Secure Workload (formerly Tetration). Specific affected versions not provided in available data. Vulnerability impacts REST API endpoints with insufficient authentication controls.

CVE-2026-2022303:36 UTC
Critical SQL injection in Drupal Core requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical SQL injection in Drupal Core requires immediate patching

Drupal Core, all versions (specific affected versions not disclosed in alert). Impacts all Drupal installations until patched.

Drupal14:42 UTC
Cisco Secure Workload max-severity flaw grants Site Admin privilegescriticalbug_reportVulnerability
bug_reportVulnerability

Cisco Secure Workload max-severity flaw grants Site Admin privileges

Cisco Secure Workload platform. Specific affected versions not provided in summary. Vulnerability allows privilege escalation to Site Admin level, affecting administrative access controls.

Cisco11:58 UTC
Critical flaws in Sparx Pro Cloud Server actively exploited in the wildcriticalbug_reportVulnerability
bug_reportVulnerability

Critical flaws in Sparx Pro Cloud Server actively exploited in the wild

Sparx Systems Pro Cloud Server and Enterprise Architect products. Specific vulnerable versions not disclosed in summary; CERT.BE advisory should be consulted for version details.

Sparx Systems06:49 UTC
SonicWall Gen6 SSL-VPN exploited for credential brute-force and MFA bypasscriticalbug_reportVulnerability
bug_reportVulnerability

SonicWall Gen6 SSL-VPN exploited for credential brute-force and MFA bypass

SonicWall Gen6 SSL-VPN appliances with incomplete patching. Specific firmware versions not disclosed. Affects organizations using SonicWall SSL-VPN for remote access.

SonicWall19:19 UTC
Compromised @antv npm packages deploy credential-stealing malwarecriticalbug_reportVulnerability
bug_reportVulnerability

Compromised @antv npm packages deploy credential-stealing malware

Multiple @antv npm packages compromised with Mini Shai-Hulud malware. Affects Linux-based CI/CD pipelines using npm install. Targets credentials from GitHub, AWS, Kubernetes, HashiCorp Vault, npm, and 1Password.

npm15:48 UTC
PgBouncer integer overflow under active exploitation, patch immediatelycriticalbug_reportVulnerability
bug_reportVulnerability

PgBouncer integer overflow under active exploitation, patch immediately

PgBouncer (PostgreSQL connection pooler) - specific affected versions not disclosed by CERT.BE. All unpatched instances should be considered at risk.

PgBouncer12:50 UTC
Microsoft Disrupts Fox Tempest Malware-Signing-as-a-Service Operationcriticalperson_alertThreat Actor
person_alertThreat Actor

Microsoft Disrupts Fox Tempest Malware-Signing-as-a-Service Operation

Fox Tempest is a threat actor attributed by Microsoft as operating a malware-signing-as-a-service (MSaaS) business model. The actor exploited Microsoft's Artifact Signing system to provide malicious code signing services to other cybercriminals, enab…

Microsoft12:36 UTC
Drupal critical core vulnerability with imminent exploit riskcriticalbug_reportVulnerability
bug_reportVulnerability

Drupal critical core vulnerability with imminent exploit risk

Drupal core (specific versions not disclosed). All Drupal installations should be considered at risk until patched.

Drupal10:52 UTC
Critical Portainer vulnerabilities enable full host takeovercriticalbug_reportVulnerability
bug_reportVulnerability

Critical Portainer vulnerabilities enable full host takeover

Portainer container management platform. Specific affected versions not disclosed in summary; CERT.BE advisory should be consulted for version details. Impacts organizations using Portainer for Docker/Kubernetes management.

Portainer03:56 UTC
ChromaDB FastAPI RCE allows unauthenticated arbitrary code executioncriticalbug_reportVulnerability
bug_reportVulnerability

ChromaDB FastAPI RCE allows unauthenticated arbitrary code execution

ChromaDB latest Python FastAPI version. Affects exposed ChromaDB servers accessible over the network. No CVE assigned yet.

ChromaDB20:25 UTC