Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 390 results
highbug_reportVulnerabilityAdblock for YouTube extension with 10M+ installs contains code injection risk
Chrome extension "Adblock for YouTube" (10+ million active installations). All users with the extension installed are potentially affected. Extension currently holds Featured badge status in Chrome Web Store.
highperson_alertThreat ActorKongTuke Deploys Mistic Backdoor in Multi-Sector Financial Attacks
KongTuke is an initial access broker (IAB) conducting financially motivated operations targeting organizations across insurance, education, IT, and professional services sectors.
highbug_reportVulnerabilityCisco Catalyst SD-WAN zero-day exploited in wild for two months
Cisco Catalyst SD-WAN Manager. Specific affected versions not disclosed. Requires authenticated local access for exploitation.
highperson_alertThreat ActorSnoopy Sentenced to 18 Months for DraftKings Account Compromise
Snoopy is a 21-year-old individual arrested and sentenced for unauthorized access to customer accounts on the DraftKings sports betting platform in November 2022.
highperson_alertThreat ActorEdgecution: Malicious Edge Extension Enables Sandbox Escape
Edgecution is a malicious browser extension targeting Microsoft Edge, not a threat actor group. It functions as a tool deployed during ransomware operations to facilitate sandbox escape and establish persistence.
highperson_alertThreat ActorEuropol disrupts Amadey and StealC infrastructure, recovers 27M credentials
This report describes a law enforcement disruption operation led by Europol in partnership with private sector entities including Bitdefender, Bitsight, ESET, and Microsoft.
highperson_alertThreat ActorEuropol-led Operation Endgame disrupts Amadey and StealC infrastructure
Europol is a law enforcement agency coordinating international cybercrime investigations. In this context, Europol led Operation Endgame, a coordinated law enforcement action involving Microsoft and international partners targeting cybercriminal infr…
highbug_reportVulnerabilityMicrosoft DCU disrupts StealC and Amadey infostealer infrastructure
Organizations globally using Windows systems targeted by StealC and Amadey infostealer malware-as-a-service operations. Infrastructure takedown executed June 24, 2026.
highperson_alertThreat ActorKongTuke Deploys Mistic Backdoor in Multi-Sector Intrusions
KongTuke is a financially motivated threat actor operating as a ransomware access broker. The group specializes in gaining initial access to corporate networks and establishing persistent backdoor access, which is then sold or provided to ransomware…
highperson_alertThreat ActorU.S. seizes HuiOne Group assets, sanctions Prince Group entities
HuiOne Group and Prince Group are entities linked to cyber scam money laundering operations with infrastructure in Cambodia. HuiOne Group subsidiaries allegedly operated cloud computing infrastructure used to facilitate financial transactions related…
highbug_reportVulnerabilityMalicious AI skills in ClawHub marketplace evade scanners, deploy infostealers
ClawHub marketplace users consuming third-party AI skills. Specific affected products: OpenClaw and ClawHub platforms. Scope includes organizations deploying AI agents with marketplace-sourced skills that may contain evasive malware delivering infost…
highbug_reportVulnerabilityCisco Unified Communications Manager SSRF under active exploitation
Cisco Unified Communications Manager (CUCM). Specific affected versions not disclosed. SSRF vulnerability (CVE-2026-20230) allows attackers to force the server to make unauthorized requests to internal or external resources.
highpublicGeopoliticalTata Electronics confirms cyberattack and data leak on IT infrastructure
Tata Electronics, a subsidiary of India's Tata Group conglomerate, has confirmed a cyberattack that compromised portions of its IT infrastructure and resulted in data exfiltration.
highperson_alertThreat ActorClickFix Targets macOS with Terminal-Based Infostealer Campaign
ClickFix is a threat actor conducting social engineering campaigns that trick users into executing malicious commands. The actor leverages deceptive techniques to convince victims to manually run Terminal commands on macOS systems, facilitating the d…
highperson_alertThreat ActorScattered Spider Members Plead Guilty to Transport for London Attack
Scattered Spider (also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944 by various vendors) is a financially motivated cybercrime group known for sophisticated social engineering and identity-based attacks.
highperson_alertThreat ActorScattered Spider Members Plead Guilty to Transport for London Breach
Scattered Spider (G1015), also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944, is a financially motivated cybercrime group known for sophisticated social engineering and identity-based attacks.
highbug_reportVulnerabilityGitHub blocks pwn request attacks in actions/checkout starting June 2026
GitHub Actions workflows using actions/checkout with pull_request_target trigger. Organizations using GitHub Actions for CI/CD pipelines are affected. The security update applies to all repositories using the actions/checkout action after June 18, 20…
highbug_reportVulnerabilityLastPass breached via Klue supply chain attack; OAuth tokens stolen
LastPass customers. Attack vector: compromised Klue third-party service leading to OAuth token theft and unauthorized access to LastPass Salesforce environment containing customer data.
highbug_reportVulnerabilityTotolink EX1200L router vulnerable to stack buffer overflow (RCE)
Totolink EX1200L router software. Specific affected firmware versions not disclosed. Vulnerability is a stack-based buffer overflow enabling potential remote code execution.
highbug_reportVulnerabilityMalicious npm packages deliver Windows RAT to JavaScript developers
Three npm packages (aes-decode-runner-pro, postcss-minify-selector, postcss-minify-selector-parser) published within the past month. Total downloads: 145-615 per package. Affects Windows-based development environments using npm package manager.
highperson_alertThreat ActorWhatsApp VBScript Campaign Deploys ManageEngine RMM Across 9 Countries
This campaign represents an unattributed threat activity leveraging WhatsApp as an initial access vector. The actor's motivation appears to be establishing persistent remote access to victim systems through legitimate remote monitoring and management…
highbug_reportVulnerabilityWhatsApp malware campaign uses fake business docs to deploy VBScript RATs
WhatsApp users across multiple countries. Attack vector: social engineering via WhatsApp messages containing malicious VBScript files disguised as business documents. Enables remote access to Windows PCs.
highbug_reportVulnerabilityCloud bucket hijacking flaw exploits global namespace across AWS, Azure, GCP
AWS S3, Azure Blob Storage, and Google Cloud Storage bucket naming systems. Affects organizations using cloud storage services across all three major cloud providers.
FFmpeg 'PixelSmash' flaw enables RCE on Jellyfin, DoS on multiple apps
FFmpeg (version details not specified). Downstream impact: Jellyfin (remote code execution), Kodi, Emby, Nextcloud, PhotoPrism, OBS Studio (denial-of-service). Affects media processing and streaming applications using vulnerable FFmpeg libraries.
highperson_alertThreat ActorFortiBleed Campaign Targets FortiGate Devices with Credential Sniffers
FortiBleed is a campaign-level designation for coordinated activity targeting Fortinet FortiGate network security appliances. The campaign's primary objective is credential harvesting through the deployment of custom sniffers on compromised firewalls…
highbug_reportVulnerabilityShapedPlugin WordPress Pro plugins backdoored via compromised update channel
Multiple ShapedPlugin Pro WordPress plugins distributed through official licensed update channels. Exact plugin names and affected versions not specified.
highbug_reportVulnerabilityMicrosoft patches AutoJack vulnerability chain in AutoGen Studio
Microsoft AutoGen Studio - all versions prior to the patched release. AutoGen Studio is a low-code interface for building and managing AI agents. The vulnerability chain affects users who interact with untrusted web content while AutoGen Studio is ru…
highbug_reportVulnerabilityDifyTap flaws enable cross-tenant AI conversation theft in Dify platform
Dify open-source agentic workflow platform. Specific affected versions not disclosed. Vulnerability enables cross-tenant data access, affecting multi-tenant deployments and cloud-hosted instances.
highbug_reportVulnerabilityDual ransomware actors operate simultaneously in Microsoft environments
Organizations using Microsoft environments, particularly those with insufficient network segmentation and endpoint visibility. No specific product vulnerability; threat involves operational security gaps enabling parallel intrusions.
highbug_reportVulnerability29-year-old Squid heap over-read leaks HTTP credentials in default config
Squid web proxy, all versions containing FTP parsing code from 1997 onward. Vulnerability present in default configuration. Affects organizations using Squid as forward or reverse proxy.