Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 173 results
Active filter:tag: #technology✕ clear
DifyTap flaws enable cross-tenant AI conversation theft in Dify platformhighbug_reportVulnerability
bug_reportVulnerability

DifyTap flaws enable cross-tenant AI conversation theft in Dify platform

Dify open-source agentic workflow platform. Specific affected versions not disclosed. Vulnerability enables cross-tenant data access, affecting multi-tenant deployments and cloud-hosted instances.

Dify22 Jun · 14:13 UTC
29-year-old Squid heap over-read leaks HTTP credentials in default confighighbug_reportVulnerability
bug_reportVulnerability

29-year-old Squid heap over-read leaks HTTP credentials in default config

Squid web proxy, all versions containing FTP parsing code from 1997 onward. Vulnerability present in default configuration. Affects organizations using Squid as forward or reverse proxy.

Squid22 Jun · 12:29 UTC
AutoJack exploit chain enables RCE on AI browsing agents via malicious pageshighbug_reportVulnerability
bug_reportVulnerability

AutoJack exploit chain enables RCE on AI browsing agents via malicious pages

AI browsing agents (autonomous web browsers with AI capabilities) that interact with privileged local services via JavaScript. Specific products and versions not disclosed in Microsoft's research disclosure.

Microsoft19 Jun · 13:30 UTC
F5 patches high-severity flaws in NGINX Open Source and Gateway Fabrichighbug_reportVulnerability
bug_reportVulnerability

F5 patches high-severity flaws in NGINX Open Source and Gateway Fabric

NGINX Open Source and NGINX Gateway Fabric (specific versions not provided). Four CVEs: CVE-2026-11311, CVE-2026-42055, CVE-2026-42530, CVE-2026-50107. Affects organizations running NGINX web servers, reverse proxies, API gateways, and Kubernetes ing…

CVE-2026-1131119 Jun · 06:24 UTC
NGINX Open Source RCE via HTTP/3 use-after-free (CVE-2026-42530)criticalbug_reportVulnerability
bug_reportVulnerability

NGINX Open Source RCE via HTTP/3 use-after-free (CVE-2026-42530)

NGINX Open Source versions with ngx_http_v3_module enabled. Specific vulnerable versions not provided in summary. F5 NGINX products potentially affected.

CVE-2026-4253018 Jun · 15:32 UTC
Weekly threat roundup: Claude abuse, npm poisoning, phishing campaignshighbug_reportVulnerability
bug_reportVulnerability

Weekly threat roundup: Claude abuse, npm poisoning, phishing campaigns

Multiple platforms and products: Claude AI chat interface, npm package ecosystem (NastyC2), OAuth device-code flows, browser extensions (unspecified), macOS systems, cloud management agents, and internet-exposed edge devices.

Claude18 Jun · 13:27 UTC
Icarus Threat Actor Exploits OAuth to Steal Salesforce Data via Kluehighperson_alertThreat Actor
person_alertThreat Actor

Icarus Threat Actor Exploits OAuth to Steal Salesforce Data via Klue

Icarus is a threat actor conducting an ongoing extortion campaign targeting organizations through supply chain compromise. The actor exploited OAuth authentication mechanisms to breach Klue, a market intelligence platform, gaining unauthorized access…

Klue18 Jun · 12:19 UTC
Microsoft Defender zero-day CVE-2026-50656 enables privilege escalationhighbug_reportVulnerability
bug_reportVulnerability

Microsoft Defender zero-day CVE-2026-50656 enables privilege escalation

Microsoft Defender Malware Protection Engine across all Windows versions. Specific affected engine versions not disclosed. Impacts enterprise and consumer deployments relying on Microsoft Defender for endpoint protection.

CVE-2026-5065617 Jun · 15:36 UTC
Malicious AI plugins on JetBrains Marketplace exfiltrate developer API keyshighbug_reportVulnerability
bug_reportVulnerability

Malicious AI plugins on JetBrains Marketplace exfiltrate developer API keys

JetBrains Marketplace users who installed any of 15+ malicious plugins impersonating AI coding assistants (DeepSeek and other LLM-based tools). Affects developers using JetBrains IDEs (IntelliJ IDEA, PyCharm, WebStorm, etc.).

JetBrains17 Jun · 11:51 UTC
Microsoft Defender zero-day "RoguePlanet" awaits patch after disclosurehighbug_reportVulnerability
bug_reportVulnerability

Microsoft Defender zero-day "RoguePlanet" awaits patch after disclosure

Microsoft Defender (all versions currently deployed). Specific affected versions not disclosed. Impacts organizations relying on Defender for endpoint protection.

Microsoft17 Jun · 06:32 UTC
Malicious JetBrains IDE plugins steal AI API keys from developershighbug_reportVulnerability
bug_reportVulnerability

Malicious JetBrains IDE plugins steal AI API keys from developers

JetBrains Marketplace users who installed any of the 15+ malicious plugins. Affects developers using JetBrains IDEs (IntelliJ IDEA, PyCharm, WebStorm, etc.) with AI API keys configured. Specific plugin names and versions not provided in summary.

JetBrains16 Jun · 19:54 UTC
Contagious Interview targets developers via recruitment-themed phishinghighperson_alertThreat Actor
person_alertThreat Actor

Contagious Interview targets developers via recruitment-themed phishing

Contagious Interview (also tracked as DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, and DEV#POPPER) is a North Korean-aligned threat actor cluster that specializes in social engineering attacks against software developers and technology secto…

The Hacker News15 Jun · 17:32 UTC
LiteLLM AI gateway vulnerable to privilege escalation and RCEcriticalbug_reportVulnerability
bug_reportVulnerability

LiteLLM AI gateway vulnerable to privilege escalation and RCE

LiteLLM open-source AI gateway. Specific affected versions not disclosed. Impacts organizations using LiteLLM to manage API keys and route requests to AI providers (OpenAI, Anthropic, etc.).

LiteLLM15 Jun · 14:39 UTC
Chinese Cybercrime Network Weaponizes Google Gemini AI for SMS Phishinghighperson_alertThreat Actor
person_alertThreat Actor

Chinese Cybercrime Network Weaponizes Google Gemini AI for SMS Phishing

A Chinese cybercrime network operating a phishing-as-a-service (PhaaS) platform called Outsider. The group weaponizes Google's Gemini AI to craft and conduct SMS-based phishing attacks (smishing) targeting American victims.

Google12 Jun · 16:59 UTC
OpenClaw AI agent vulnerable to prompt injection via vCards and location pinshighbug_reportVulnerability
bug_reportVulnerability

OpenClaw AI agent vulnerable to prompt injection via vCards and location pins

OpenClaw self-hosted AI agent platform, all versions. Vulnerability affects input processing mechanisms for vCards, location pins, and potentially other structured data formats.

OpenClaw11 Jun · 15:46 UTC
BitLocker bypass via recovery partition XML files (GreatXML)highbug_reportVulnerability
bug_reportVulnerability

BitLocker bypass via recovery partition XML files (GreatXML)

Windows BitLocker encryption on systems with recovery partitions. All Windows versions with BitLocker enabled are potentially affected. Specific version scope not yet published.

Microsoft11 Jun · 15:43 UTC
Fortinet FortiSandbox command injection flaw enables remote code executioncriticalbug_reportVulnerability
bug_reportVulnerability

Fortinet FortiSandbox command injection flaw enables remote code execution

Fortinet FortiSandbox products affected by CVE-2026-25089 (CVSS 9.1). Specific vulnerable versions not disclosed in provided data. Ivanti and SAP also released patches for separate critical vulnerabilities.

CVE-2026-2508910 Jun · 13:10 UTC
Langflow path traversal flaw (CVE-2026-5027) exploited for RCEcriticalbug_reportVulnerability
bug_reportVulnerability

Langflow path traversal flaw (CVE-2026-5027) exploited for RCE

Langflow open-source low-code AI platform, all unpatched versions. Vulnerability allows unauthenticated path traversal leading to arbitrary file write and remote code execution.

CVE-2026-502710 Jun · 13:00 UTC
Cisco Catalyst SD-WAN Manager actively exploited (CVE-2026-20245)highbug_reportVulnerability
bug_reportVulnerability

Cisco Catalyst SD-WAN Manager actively exploited (CVE-2026-20245)

Cisco Catalyst SD-WAN Manager. Specific affected versions not disclosed. Vulnerability involves improper encoding or escaping of output (CVSS 7.8). Also affects products from Google and Arista (details not provided).

CVE-2026-2024510 Jun · 12:44 UTC
Microsoft patches 3 zero-days: YellowKey, GreenPlasma, MiniPlasmacriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft patches 3 zero-days: YellowKey, GreenPlasma, MiniPlasma

All fully patched Windows systems prior to latest patch release. YellowKey and GreenPlasma enable SYSTEM privilege escalation; MiniPlasma bypasses BitLocker encryption on protected drives.

Microsoft10 Jun · 07:57 UTC
Microsoft Defender zero-day "RoguePlanet" exploited for SYSTEM accesscriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft Defender zero-day "RoguePlanet" exploited for SYSTEM access

Microsoft Defender on all updated Windows systems. No CVE assigned yet. Vulnerability is a race condition enabling local privilege escalation to SYSTEM.

Microsoft10 Jun · 03:22 UTC
Six RCE and DoS flaws found in protobuf.js for Node.js applicationshighbug_reportVulnerability
bug_reportVulnerability

Six RCE and DoS flaws found in protobuf.js for Node.js applications

protobuf.js library (JavaScript/TypeScript implementation of Protocol Buffers) used in Node.js applications. Specific vulnerable versions not provided in summary.

protobuf.js10 Jun · 03:08 UTC
Microsoft Defender zero-day 'RoguePlanet' enables SYSTEM privilege escalationcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft Defender zero-day 'RoguePlanet' enables SYSTEM privilege escalation

Microsoft Defender on Windows systems. Specific affected versions not disclosed. Given Defender's deployment, scope includes enterprise endpoints, servers running Defender, and consumer Windows installations with default security configuration.

Microsoft9 Jun · 21:11 UTC
Microsoft June 2026 Patch Tuesday: ~200 patches, 36 critical, 3 with PoCscriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft June 2026 Patch Tuesday: ~200 patches, 36 critical, 3 with PoCs

Microsoft products across the portfolio. Approximately 200 vulnerabilities patched, including ~36 critical-severity issues. At least 3 vulnerabilities have public proof-of-concept exploit code available.

Microsoft9 Jun · 20:07 UTC
Chrome V8 zero-day CVE-2026-11645 exploited in wild, patch immediatelycriticalbug_reportVulnerability
bug_reportVulnerability

Chrome V8 zero-day CVE-2026-11645 exploited in wild, patch immediately

Google Chrome versions prior to 149.0.7827.103 on all platforms. The vulnerability resides in the V8 JavaScript engine, affecting out-of-bounds memory access.

CVE-2026-116459 Jun · 09:58 UTC
BerriAI LiteLLM command injection under active exploitation (CISA KEV)highbug_reportVulnerability
bug_reportVulnerability

BerriAI LiteLLM command injection under active exploitation (CISA KEV)

BerriAI LiteLLM - specific vulnerable versions not disclosed in summary. Command injection vulnerability (CVE-2026-42271) affects authenticated users with access to the system.

CVE-2026-422719 Jun · 04:26 UTC
Linux kernel nf_tables use-after-free enables root escalation (CVE-2026-23111)criticalbug_reportVulnerability
bug_reportVulnerability

Linux kernel nf_tables use-after-free enables root escalation (CVE-2026-23111)

Linux kernel nf_tables subsystem. All distributions using vulnerable kernel versions prior to the February 5, 2026 patch. Affects systems where unprivileged users have local access or container environments.

CVE-2026-231118 Jun · 18:17 UTC
Toshiba, Muji sites show credential-stealing prompts via polyfill supply chainhighbug_reportVulnerability
bug_reportVulnerability

Toshiba, Muji sites show credential-stealing prompts via polyfill supply chain

Toshiba and Muji public websites, potentially other sites using the compromised third-party polyfill library. Scope of affected sites and specific polyfill service not yet confirmed.

Toshiba5 Jun · 19:54 UTC
PCPJack Hijacks 230+ Cloud Servers for Covert SMTP Relay Networkhighperson_alertThreat Actor
person_alertThreat Actor

PCPJack Hijacks 230+ Cloud Servers for Covert SMTP Relay Network

PCPJack is a threat actor focused on compromising cloud infrastructure to establish illicit email relay networks. The actor has demonstrated capability to breach business servers across major cloud service providers (AWS, Google Cloud, Microsoft Azur…

Amazon Web Services5 Jun · 03:34 UTC
Dutch authorities dismantle botnet controlling 17M infected deviceshighbug_reportVulnerability
bug_reportVulnerability

Dutch authorities dismantle botnet controlling 17M infected devices

At least 17 million infected devices globally including computers, tablets, smartphones, and IoT devices. Over 200 command-and-control servers located in the Netherlands were seized.

The Hacker News31 May · 10:22 UTC