Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-21 · 02:09 UTC
articleTotal: 606 reports

Filtered Reports

30 / 264 results
Active filter:tag: #vulnerability✕ clear
Microsoft June 2026 Patch Tuesday: 200 flaws, 3 disclosed zero-dayshighbug_reportVulnerability
bug_reportVulnerability

Microsoft June 2026 Patch Tuesday: 200 flaws, 3 disclosed zero-days

Microsoft products across the ecosystem. 200 vulnerabilities patched, including 3 publicly disclosed zero-day vulnerabilities. Specific affected products and CVE identifiers not yet detailed in available information.

Microsoft15:57 UTC
Veeam Backup & Replication RCE flaw (CVE-2026-44963) patched, CVSS 9.4criticalbug_reportVulnerability
bug_reportVulnerability

Veeam Backup & Replication RCE flaw (CVE-2026-44963) patched, CVSS 9.4

Veeam Backup & Replication software. Specific affected versions not disclosed in available data. Requires authenticated domain user access to exploit.

CVE-2026-4496314:39 UTC
Microsoft GitHub repos compromised, 73 disabled for distributing malwarehighbug_reportVulnerability
bug_reportVulnerability

Microsoft GitHub repos compromised, 73 disabled for distributing malware

73 repositories across Microsoft's official GitHub organizations (Azure, microsoft, Azure-Samples, MicrosoftDocs). Organizations using Microsoft sample code, Azure templates, or CI/CD pipelines referencing these repositories are potentially affected.

Microsoft13:42 UTC
SAP releases critical patches for multiple productscriticalbug_reportVulnerability
bug_reportVulnerability

SAP releases critical patches for multiple products

Multiple SAP products affected. Specific product names and versions not disclosed in available information. Patches released by SAP to address critical-severity vulnerabilities.

SAP12:23 UTC
WinRAR CVE-2025-8088 path traversal exploited by Russian APTs vs Ukrainehighbug_reportVulnerability
bug_reportVulnerability

WinRAR CVE-2025-8088 path traversal exploited by Russian APTs vs Ukraine

WinRAR versions prior to patched release (approximately one year old). Primary targets: Ukrainian organizations. Threat actors: Earth Dahu (Gamaredon) and SHADOW-EARTH-066 (UAC-0226), Russia-aligned APT groups.

CVE-2025-808810:26 UTC
Check Point VPN authentication flaw under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Check Point VPN authentication flaw under active exploitation

Check Point VPN products with user authentication functionality. Specific affected versions not disclosed. CVE identifier not yet assigned.

Check Point10:15 UTC
Chrome V8 zero-day CVE-2026-11645 exploited in wild, patch immediatelycriticalbug_reportVulnerability
bug_reportVulnerability

Chrome V8 zero-day CVE-2026-11645 exploited in wild, patch immediately

Google Chrome versions prior to 149.0.7827.103 on all platforms. The vulnerability resides in the V8 JavaScript engine, affecting out-of-bounds memory access.

CVE-2026-1164509:58 UTC
FROST attack enables website-based user tracking via SSD timing analysishighbug_reportVulnerability
bug_reportVulnerability

FROST attack enables website-based user tracking via SSD timing analysis

All systems with SSDs accessed via web browsers supporting high-resolution JavaScript timers. Attack affects users across Windows, Linux, and macOS platforms. No specific browser, SSD model, or OS version is immune.

The Hacker News07:50 UTC
PyPI supply chain attack: 19 packages with auto-executing credential stealerhighbug_reportVulnerability
bug_reportVulnerability

PyPI supply chain attack: 19 packages with auto-executing credential stealer

PyPI repository: 19 compromised packages containing 37 malicious wheel artifacts. Affects Python developers who installed these packages. Attack uses .pth files for automatic execution during pip install, targeting credential theft via Bun-based stea…

PyPI07:13 UTC
BerriAI LiteLLM command injection under active exploitation (CISA KEV)highbug_reportVulnerability
bug_reportVulnerability

BerriAI LiteLLM command injection under active exploitation (CISA KEV)

BerriAI LiteLLM - specific vulnerable versions not disclosed in summary. Command injection vulnerability (CVE-2026-42271) affects authenticated users with access to the system.

CVE-2026-4227104:26 UTC
NFCShare Android malware distributed via GitHub as fake banking app updateshighbug_reportVulnerability
bug_reportVulnerability

NFCShare Android malware distributed via GitHub as fake banking app updates

Android mobile users, particularly customers of targeted banking applications. Malware distributed through GitHub repositories posing as legitimate banking app updates.

BleepingComputer20:11 UTC
PyPI supply-chain attack: 19 science packages compromised with malwarehighbug_reportVulnerability
bug_reportVulnerability

PyPI supply-chain attack: 19 science packages compromised with malware

19 science-focused Python packages on PyPI, collectively downloaded hundreds of thousands of times. Specific package names and versions not disclosed in summary. Affects Python developers using PyPI packages in scientific/research workflows.

BleepingComputer18:41 UTC
Linux kernel nf_tables use-after-free enables root escalation (CVE-2026-23111)criticalbug_reportVulnerability
bug_reportVulnerability

Linux kernel nf_tables use-after-free enables root escalation (CVE-2026-23111)

Linux kernel nf_tables subsystem. All distributions using vulnerable kernel versions prior to the February 5, 2026 patch. Affects systems where unprivileged users have local access or container environments.

CVE-2026-2311118:17 UTC
Gogs patches critical RCE zero-day affecting Internet-facing instancescriticalbug_reportVulnerability
bug_reportVulnerability

Gogs patches critical RCE zero-day affecting Internet-facing instances

Gogs Git service, Internet-facing instances (specific vulnerable versions not disclosed). All repositories including private repos accessible post-exploitation.

Gogs14:18 UTC
Ubiquiti UniFi OS vulnerable to RCE via chained patched vulnerabilitiescriticalbug_reportVulnerability
bug_reportVulnerability

Ubiquiti UniFi OS vulnerable to RCE via chained patched vulnerabilities

Ubiquiti UniFi OS server (specific versions not provided). Vulnerability chain affects systems running outdated UniFi OS versions containing three previously patched flaws.

Ubiquiti13:51 UTC
Three high-severity XSS flaws in VMware Telco Cloud and Aria Operationshighbug_reportVulnerability
bug_reportVulnerability

Three high-severity XSS flaws in VMware Telco Cloud and Aria Operations

VMware Telco Cloud/vSphere Foundation and VMware Aria Operations. Specific affected versions not provided in advisory; consult VMware security bulletin for version details.

VMware13:05 UTC
SolarWinds Serv-U actively exploited for resource exhaustion attackscriticalbug_reportVulnerability
bug_reportVulnerability

SolarWinds Serv-U actively exploited for resource exhaustion attacks

SolarWinds Serv-U file transfer software, unpatched versions. Specific vulnerable version range not disclosed in summary. CVE identifier not yet assigned.

SolarWinds13:04 UTC
Check Point VPN auth bypass under active exploit via IKEv1 flawcriticalbug_reportVulnerability
bug_reportVulnerability

Check Point VPN auth bypass under active exploit via IKEv1 flaw

Check Point Remote Access VPN and Mobile Access deployments using deprecated IKEv1 protocol. Specific product versions not disclosed. Does not affect IKEv2 configurations.

CVE-2026-5075112:17 UTC
Check Point patches zero-day in VPN/Mobile Access exploited by Qilincriticalbug_reportVulnerability
bug_reportVulnerability

Check Point patches zero-day in VPN/Mobile Access exploited by Qilin

Check Point Remote Access VPN and Mobile Access deployments. Specific product versions not disclosed in summary; refer to vendor advisory for affected releases and patched versions.

Check Point11:05 UTC
Critical vulnerability in MISP requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical vulnerability in MISP requires immediate patching

MISP (Malware Information Sharing Platform) - specific versions not disclosed in advisory. All unpatched instances potentially affected.

MISP06:28 UTC
Gafgyt C0XMO botnet exploits DD-WRT router flaw, kills rival malwarehighbug_reportVulnerability
bug_reportVulnerability

Gafgyt C0XMO botnet exploits DD-WRT router flaw, kills rival malware

DD-WRT router firmware (specific versions not disclosed). Affects devices across multiple CPU architectures. No CVE assigned yet.

DD-WRT12:17 UTC
Everest Forms Pro WordPress plugin under active exploit for site takeovercriticalbug_reportVulnerability
bug_reportVulnerability

Everest Forms Pro WordPress plugin under active exploit for site takeover

Everest Forms Pro plugin for WordPress. Specific affected versions not disclosed. All WordPress sites running this premium plugin are potentially at risk.

CVE-2026-330012:09 UTC
SolarWinds Serv-U DoS flaw actively exploited, added to CISA KEVhighbug_reportVulnerability
bug_reportVulnerability

SolarWinds Serv-U DoS flaw actively exploited, added to CISA KEV

SolarWinds Serv-U multi-protocol file server. Specific affected versions not disclosed in provided data. The vulnerability causes service crashes via denial-of-service attacks.

CVE-2026-2831806:14 UTC
AI finds 21 zero-days in FFmpeg; Chrome 149 patches 429 bugshighbug_reportVulnerability
bug_reportVulnerability

AI finds 21 zero-days in FFmpeg; Chrome 149 patches 429 bugs

FFmpeg media library (all versions prior to upcoming patch release); Google Chrome versions prior to 149 (all platforms). FFmpeg is embedded in countless applications, browsers, media players, and server-side processing pipelines.

FFmpeg05:28 UTC
Miasma worm compromises 73 Microsoft GitHub repos in supply chain attackhighbug_reportVulnerability
bug_reportVulnerability

Miasma worm compromises 73 Microsoft GitHub repos in supply chain attack

73 Microsoft GitHub repositories across four organizations: Azure, Azure-Samples, Microsoft, and MicrosoftDocs. GitHub has disabled access to affected repositories.

Microsoft04:58 UTC
Cisco Catalyst SD-WAN Manager CVE-2026-20245 exploited in wild, no patchhighbug_reportVulnerability
bug_reportVulnerability

Cisco Catalyst SD-WAN Manager CVE-2026-20245 exploited in wild, no patch

Cisco Catalyst SD-WAN Manager across all deployment types: On-Prem, Cloud-Pro, Cloud (Cisco Managed), and Government (FedRAMP). Specific affected versions not disclosed. CVSS 7.8 (High).

CVE-2026-2024502:19 UTC
Toshiba, Muji sites show credential-stealing prompts via polyfill supply chainhighbug_reportVulnerability
bug_reportVulnerability

Toshiba, Muji sites show credential-stealing prompts via polyfill supply chain

Toshiba and Muji public websites, potentially other sites using the compromised third-party polyfill library. Scope of affected sites and specific polyfill service not yet confirmed.

Toshiba19:54 UTC
CISA warns of active exploitation of SolarWinds Serv-U vulnerabilityhighbug_reportVulnerability
bug_reportVulnerability

CISA warns of active exploitation of SolarWinds Serv-U vulnerability

SolarWinds Serv-U managed file transfer software. Specific vulnerable versions not provided in summary; patch recently released by vendor.

SolarWinds17:15 UTC
npm supply chain attack: 50+ packages deliver IronWorm stealer and rootkitcriticalbug_reportVulnerability
bug_reportVulnerability

npm supply chain attack: 50+ packages deliver IronWorm stealer and rootkit

npm ecosystem: over 50 compromised legitimate packages. Affects developers using npm for JavaScript/Node.js projects. IronWorm targets developer credentials and source code with eBPF kernel-level persistence.

npm16:05 UTC
Prompt injection in Claude Code GitHub Action exposes workflow secretshighbug_reportVulnerability
bug_reportVulnerability

Prompt injection in Claude Code GitHub Action exposes workflow secrets

Anthropic's Claude Code GitHub Action (prior to mitigation). Affects GitHub workflows using the action with access to repository secrets. Vulnerability exploitable when action processes untrusted input from pull requests or external sources.

Anthropic14:46 UTC