Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 244 results
criticalbug_reportVulnerabilityCISA orders federal agencies to patch exploited Ivanti Sentry flaw
Ivanti Sentry (specific versions not disclosed in summary). U.S. federal agencies under BOD 26-04 mandate, but all Ivanti Sentry deployments at risk given active exploitation.
highpublicGeopoliticalFrench Government Messaging Platform Tchap Breached, 73,000 Accounts Affected
The compromise of Tchap, France's sovereign encrypted messaging solution developed as an alternative to foreign platforms, represents a significant breach of government communications infrastructure.
highperson_alertThreat ActorEuropol Disrupts AudiA6 Cryptocurrency Laundering Service
AudiA6 was a cryptocurrency laundering service utilized by ransomware gangs and cybercriminal networks to obfuscate and legitimize illicit proceeds. The service facilitated the conversion and movement of cryptocurrency obtained through ransomware ope…
highpublicGeopoliticalJapanese utility loses drive with 10.9M customer records
The incident at Kyushu Electric Power Co., Inc. represents a physical security failure rather than a cyber intrusion, but underscores the vulnerability of critical infrastructure operators to data exposure.
criticalbug_reportVulnerabilityCritical command injection flaw in Fortinet FortiSandbox requires patching
Fortinet FortiSandbox (specific versions not disclosed in available data). Command injection vulnerability allows unauthorized command execution.
highpublicGeopoliticalSouth Korea issues record $409M fine to Coupang for 37M-user breach
The unprecedented fine against Coupang reflects South Korea's increasingly assertive regulatory posture on data protection, aligning Seoul with global trends toward stringent enforcement of privacy frameworks.
highpublicGeopoliticalCISA mandates 3-day patching for exploited flaws in federal agencies
The directive represents a significant tightening of federal cybersecurity posture in response to persistent exploitation of known vulnerabilities by both state-sponsored and criminal actors.
highperson_alertThreat ActorOceanLotus Targets Vietnamese Infrastructure with SPECTRALVIPER Backdoor
OceanLotus (also tracked as APT32, SeaLotus, APT-C-00, and Canvas Cyclone) is a Vietnam-aligned advanced persistent threat group attributed by multiple vendors to conducting cyber espionage operations.
highpublicGeopoliticalUniversity of Nottingham breach exposes 450,000+ student records
The breach at the University of Nottingham represents a significant compromise of a major UK higher education institution, affecting a substantial population of current and former students.
criticalbug_reportVulnerabilityCritical RCE in Veeam Backup & Replication requires immediate patching
Veeam Backup & Replication (specific versions not disclosed in summary). Remote code execution vulnerability allows attackers to execute arbitrary code on affected systems.
highperson_alertThreat ActorChina-Nexus Actors Expand JDY Botnet to 1,500+ IoT/SOHO Devices
China-nexus state-sponsored threat actors operating the JDY botnet infrastructure. The actors leverage compromised small office/home office (SOHO) routers and IoT devices to build a distributed scanning platform for cyber reconnaissance operations.
criticalbug_reportVulnerabilityMicrosoft June 2025 Patch Tuesday: 206 vulnerabilities, 33 critical
Microsoft products across the ecosystem. 206 total vulnerabilities: 33 critical, 173 important severity. Specific affected products and CVE identifiers not yet detailed in available information.
highperson_alertThreat ActorVolt Typhoon Expands JDY Botnet Operations Against U.S. Military
Volt Typhoon (also tracked as BRONZE SILHOUETTE, Vanguard Panda, DEV-0391, and UNC3236) is a Chinese state-sponsored APT group attributed to conducting cyber espionage operations targeting critical infrastructure.
highbug_reportVulnerabilityCisco Catalyst SD-WAN Manager actively exploited (CVE-2026-20245)
Cisco Catalyst SD-WAN Manager. Specific affected versions not disclosed. Vulnerability involves improper encoding or escaping of output (CVSS 7.8). Also affects products from Google and Arista (details not provided).
highbug_reportVulnerabilityAix-DB missing authentication flaw allows unauthorized critical access
Aix-DB software (vendor: Aix-DB). Specific affected versions not disclosed. Vulnerability allows unauthenticated access to critical functions (CWE-306).
criticalbug_reportVulnerabilityWindows Server domain controllers under active RCE attack
Windows Server domain controllers (all supported versions). Specific version details not yet published by Microsoft. Unauthenticated remote code execution vulnerability.
criticalbug_reportVulnerabilitySAP releases critical patches for multiple products
Multiple SAP products affected. Specific product names and versions not disclosed in available information. Patches released by SAP to address critical-severity vulnerabilities.
highbug_reportVulnerabilityWinRAR CVE-2025-8088 path traversal exploited by Russian APTs vs Ukraine
WinRAR versions prior to patched release (approximately one year old). Primary targets: Ukrainian organizations. Threat actors: Earth Dahu (Gamaredon) and SHADOW-EARTH-066 (UAC-0226), Russia-aligned APT groups.
criticalbug_reportVulnerabilityCheck Point VPN authentication flaw under active exploitation
Check Point VPN products with user authentication functionality. Specific affected versions not disclosed. CVE identifier not yet assigned.
FROST attack enables website-based user tracking via SSD timing analysis
All systems with SSDs accessed via web browsers supporting high-resolution JavaScript timers. Attack affects users across Windows, Linux, and macOS platforms. No specific browser, SSD model, or OS version is immune.
highbug_reportVulnerabilityBerriAI LiteLLM command injection under active exploitation (CISA KEV)
BerriAI LiteLLM - specific vulnerable versions not disclosed in summary. Command injection vulnerability (CVE-2026-42271) affects authenticated users with access to the system.
highpublicGeopoliticalSoFi Hong Kong reports third-party vendor breach exposing customer data
The incident reflects the persistent vulnerability of financial services supply chains in Hong Kong, a major international financial hub operating under the "One Country, Two Systems" framework.
highperson_alertThreat ActorMeta blocks NSO Group spear-phishing targeting WhatsApp users
NSO Group is an Israeli commercial surveillance vendor that develops and sells offensive cyber capabilities, primarily the Pegasus spyware platform, to government clients.
highbug_reportVulnerabilityThree high-severity XSS flaws in VMware Telco Cloud and Aria Operations
VMware Telco Cloud/vSphere Foundation and VMware Aria Operations. Specific affected versions not provided in advisory; consult VMware security bulletin for version details.
criticalbug_reportVulnerabilitySolarWinds Serv-U actively exploited for resource exhaustion attacks
SolarWinds Serv-U file transfer software, unpatched versions. Specific vulnerable version range not disclosed in summary. CVE identifier not yet assigned.
criticalbug_reportVulnerabilityCheck Point patches zero-day in VPN/Mobile Access exploited by Qilin
Check Point Remote Access VPN and Mobile Access deployments. Specific product versions not disclosed in summary; refer to vendor advisory for affected releases and patched versions.
highpublicGeopoliticalOxford University CareerConnect platform breached via third-party provider
The breach of Oxford University's CareerConnect platform represents a supply chain compromise affecting a high-value target within the United Kingdom's higher education sector.
highperson_alertThreat ActorVerdantBamboo deploys BSD BRICKSTORM variant with Linux malware
VerdantBamboo is a China-nexus cyber espionage group attributed by Volexity, with operational overlap with the threat cluster known as Clay Typhoon. The actor focuses on intelligence collection operations and has demonstrated cross-platform capabilit…
criticalbug_reportVulnerabilityCritical vulnerability in MISP requires immediate patching
MISP (Malware Information Sharing Platform) - specific versions not disclosed in advisory. All unpatched instances potentially affected.
highperson_alertThreat ActorUNC3753 Conducts Data Theft Extortion via Vishing and Physical Intrusion
UNC3753 is a financially motivated threat actor attributed by Mandiant. The group conducted a data theft extortion campaign targeting dozens of organizations in the United States between January and May 2026.