Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-21 · 02:09 UTC
articleTotal: 606 reports

Filtered Reports

30 / 358 results
Active filter:✕ clear
29-year-old Squid heap over-read leaks HTTP credentials in default confighighbug_reportVulnerability
bug_reportVulnerability

29-year-old Squid heap over-read leaks HTTP credentials in default config

Squid web proxy, all versions containing FTP parsing code from 1997 onward. Vulnerability present in default configuration. Affects organizations using Squid as forward or reverse proxy.

Squid12:29 UTC
AryStinger botnet compromises 4,000+ legacy D-Link routers as proxieshighbug_reportVulnerability
bug_reportVulnerability

AryStinger botnet compromises 4,000+ legacy D-Link routers as proxies

Over 4,000 outdated D-Link routers worldwide, specifically legacy models no longer receiving security updates. Exact models not specified in available data.

D-Link12:14 UTC
North Korean APT compromised 140+ npm packages via Mastra AI frameworkhighbug_reportVulnerability
bug_reportVulnerability

North Korean APT compromised 140+ npm packages via Mastra AI framework

Mastra AI framework and over 140 dependent npm packages. Organizations using Mastra AI or downstream dependencies in Node.js/JavaScript applications are affected.

Mastra AI12:09 UTC
Unit 42 issues guidance on large-scale credential attack campaignshighbug_reportVulnerability
bug_reportVulnerability

Unit 42 issues guidance on large-scale credential attack campaigns

Organizations using security vendor devices targeted in recent credential-based attack campaigns. No specific CVE; threat involves coordinated credential compromise attempts across multiple vendors' products.

Unit 42 (Palo Alto)00:05 UTC
Gravity SMTP WordPress plugin under active exploit for info disclosurehighbug_reportVulnerability
bug_reportVulnerability

Gravity SMTP WordPress plugin under active exploit for info disclosure

Gravity SMTP WordPress plugin, affecting approximately 100,000 websites. Specific vulnerable versions not disclosed in available data.

Gravity SMTP18:25 UTC
Unpatchable SecureROM exploit for Apple A12/A13 chips publishedcriticalbug_reportVulnerability
bug_reportVulnerability

Unpatchable SecureROM exploit for Apple A12/A13 chips published

Apple devices with A12 and A13 chips (iPhone XS/XR/11 series, iPad Air 3rd gen, iPad mini 5th gen, iPad 8th gen). SecureROM vulnerability is permanent and cannot be patched via software updates.

Apple16:37 UTC
Critical RCE in Splunk Enterprise under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Critical RCE in Splunk Enterprise under active exploitation

Splunk Enterprise (specific versions not disclosed in alert). The vulnerability enables remote code execution. CVE identifier not yet assigned or published.

Splunk13:33 UTC
AutoJack exploit chain enables RCE on AI browsing agents via malicious pageshighbug_reportVulnerability
bug_reportVulnerability

AutoJack exploit chain enables RCE on AI browsing agents via malicious pages

AI browsing agents (autonomous web browsers with AI capabilities) that interact with privileged local services via JavaScript. Specific products and versions not disclosed in Microsoft's research disclosure.

Microsoft13:30 UTC
CISA orders federal agencies to patch exploited Splunk Enterprise flawcriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders federal agencies to patch exploited Splunk Enterprise flaw

Splunk Enterprise (specific versions not disclosed in summary). CISA directive targets U.S. federal agencies, but vulnerability affects all Splunk Enterprise deployments.

Splunk08:39 UTC
Salesforce disables Klue integration after OAuth token abuse exposes datahighbug_reportVulnerability
bug_reportVulnerability

Salesforce disables Klue integration after OAuth token abuse exposes data

Salesforce customers using the Klue Battlecards app integration. OAuth tokens were abused to access customer data. Integration disabled as of June 11, 2026.

Salesforce07:03 UTC
Critical auth bypass in SimpleHelp remote support software (CVE-2026-48558)criticalbug_reportVulnerability
bug_reportVulnerability

Critical auth bypass in SimpleHelp remote support software (CVE-2026-48558)

SimpleHelp remote support software, specific versions not disclosed. Vendor patch available. Authentication bypass vulnerability allows unauthorized access.

CVE-2026-4855806:46 UTC
F5 patches high-severity flaws in NGINX Open Source and Gateway Fabrichighbug_reportVulnerability
bug_reportVulnerability

F5 patches high-severity flaws in NGINX Open Source and Gateway Fabric

NGINX Open Source and NGINX Gateway Fabric (specific versions not provided). Four CVEs: CVE-2026-11311, CVE-2026-42055, CVE-2026-42530, CVE-2026-50107. Affects organizations running NGINX web servers, reverse proxies, API gateways, and Kubernetes ing…

CVE-2026-1131106:24 UTC
Apple Beats Studio Buds Bluetooth flaw allows unauthorized pairinghighbug_reportVulnerability
bug_reportVulnerability

Apple Beats Studio Buds Bluetooth flaw allows unauthorized pairing

Apple Beats Studio Buds using Airoha Bluetooth audio SDK. Vulnerability affects devices prior to firmware update released by Apple. Attackers must be within Bluetooth range (typically <10 meters).

CVE-2025-2070104:36 UTC
AutoJack exploit chain enables RCE on AI agent hosts via malicious webpagecriticalbug_reportVulnerability
bug_reportVulnerability

AutoJack exploit chain enables RCE on AI agent hosts via malicious webpage

Microsoft AutoGen Studio users running AI browsing agents. Affects deployments where AutoGen Studio's MCP WebSocket is accessible to localhost without authentication. Specific version range not disclosed.

Microsoft22:17 UTC
NGINX Open Source RCE via HTTP/3 use-after-free (CVE-2026-42530)criticalbug_reportVulnerability
bug_reportVulnerability

NGINX Open Source RCE via HTTP/3 use-after-free (CVE-2026-42530)

NGINX Open Source versions with ngx_http_v3_module enabled. Specific vulnerable versions not provided in summary. F5 NGINX products potentially affected.

CVE-2026-4253015:32 UTC
Clipboard-stealing malware spreads via USB, targets crypto walletshighbug_reportVulnerability
bug_reportVulnerability

Clipboard-stealing malware spreads via USB, targets crypto wallets

Windows systems with USB connectivity. Targets cryptocurrency wallet users. No specific vendor or product vulnerability; relies on user interaction with malicious Windows shortcut (.lnk) files on removable media.

BleepingComputer14:20 UTC
Weekly threat roundup: Claude abuse, npm poisoning, phishing campaignshighbug_reportVulnerability
bug_reportVulnerability

Weekly threat roundup: Claude abuse, npm poisoning, phishing campaigns

Multiple platforms and products: Claude AI chat interface, npm package ecosystem (NastyC2), OAuth device-code flows, browser extensions (unspecified), macOS systems, cloud management agents, and internet-exposed edge devices.

Claude13:27 UTC
Windows cryptocurrency clipper campaign uses USB worms and Tor C2highbug_reportVulnerability
bug_reportVulnerability

Windows cryptocurrency clipper campaign uses USB worms and Tor C2

Windows systems with Windows Script Host and ActiveX enabled. Campaign active since February 2026 targeting cryptocurrency users via USB-based LNK worm propagation.

Microsoft12:30 UTC
ShapedPlugin WordPress plugins compromised in supply chain attackhighbug_reportVulnerability
bug_reportVulnerability

ShapedPlugin WordPress plugins compromised in supply chain attack

Multiple WordPress plugins from ShapedPlugin vendor. Infected releases distributed to paying customers via official update mechanism. Specific plugin names and version numbers not disclosed in provided data.

ShapedPlugin10:55 UTC
Apple patches Bluetooth eavesdropping flaw in Beats Studio Budshighbug_reportVulnerability
bug_reportVulnerability

Apple patches Bluetooth eavesdropping flaw in Beats Studio Buds

Apple Beats Studio Buds wireless earbuds. Specific firmware versions not disclosed. Vulnerability requires attacker to be within Bluetooth range (typically 10-30 meters).

Apple10:23 UTC
NCSC warns of active global campaign targeting Fortinet firewalls and VPNshighbug_reportVulnerability
bug_reportVulnerability

NCSC warns of active global campaign targeting Fortinet firewalls and VPNs

Fortinet firewalls and VPN gateways globally. Specific product lines and versions not disclosed in alert. Organizations using FortiGate, FortiOS, or FortiClient VPN services should assume potential exposure.

Fortinet10:00 UTC
Poisoned npm package compromises 140+ projects via postinstall payloadhighbug_reportVulnerability
bug_reportVulnerability

Poisoned npm package compromises 140+ projects via postinstall payload

140+ projects using a malicious npm package containing a hidden postinstall script. Affects Node.js/JavaScript development environments consuming npm dependencies. Specific package name not disclosed in summary.

npm01:43 UTC
Cryptocurrency clipper malware with worm propagation targets Windowshighbug_reportVulnerability
bug_reportVulnerability

Cryptocurrency clipper malware with worm propagation targets Windows

Windows systems globally. No specific product vulnerability; threat relies on social engineering, malicious downloads, or lateral movement. All cryptocurrency wallet users on Windows are potential targets.

Microsoft21:11 UTC
Microsoft Defender zero-day CVE-2026-50656 enables privilege escalationhighbug_reportVulnerability
bug_reportVulnerability

Microsoft Defender zero-day CVE-2026-50656 enables privilege escalation

Microsoft Defender Malware Protection Engine across all Windows versions. Specific affected engine versions not disclosed. Impacts enterprise and consumer deployments relying on Microsoft Defender for endpoint protection.

CVE-2026-5065615:36 UTC
Jenkins RCE vulnerability requires immediate patching per CERT.BEcriticalbug_reportVulnerability
bug_reportVulnerability

Jenkins RCE vulnerability requires immediate patching per CERT.BE

Jenkins (specific versions not disclosed in alert). Vulnerability enables arbitrary remote code execution. CVE identifier not yet assigned or published.

Jenkins12:42 UTC
Critical vulnerability in Joomla Content Editor (JCE) requires urgent patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical vulnerability in Joomla Content Editor (JCE) requires urgent patching

Joomla Content Editor (JCE) extension for Joomla CMS. Specific affected versions not disclosed in advisory. All Joomla sites using the JCE extension should be considered at risk pending vendor confirmation.

Joomla12:39 UTC
Malicious AI plugins on JetBrains Marketplace exfiltrate developer API keyshighbug_reportVulnerability
bug_reportVulnerability

Malicious AI plugins on JetBrains Marketplace exfiltrate developer API keys

JetBrains Marketplace users who installed any of 15+ malicious plugins impersonating AI coding assistants (DeepSeek and other LLM-based tools). Affects developers using JetBrains IDEs (IntelliJ IDEA, PyCharm, WebStorm, etc.).

JetBrains11:51 UTC
Windows June updates break Office launch from third-party appshighbug_reportVulnerability
bug_reportVulnerability

Windows June updates break Office launch from third-party apps

Windows systems with June 2024 updates installed. Affects third-party applications attempting to launch Microsoft Office applications or open Office documents. Specific Windows versions not yet disclosed by Microsoft.

Microsoft09:54 UTC
CISA orders patching of actively exploited Joomla JCE plugin flawcriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders patching of actively exploited Joomla JCE plugin flaw

Widget Factory Joomla Content Editor (JCE) plugin for Joomla CMS. Specific vulnerable versions not disclosed in provided data. Maximum severity rating indicates critical impact.

Widget Factory08:09 UTC
Microsoft Defender zero-day "RoguePlanet" awaits patch after disclosurehighbug_reportVulnerability
bug_reportVulnerability

Microsoft Defender zero-day "RoguePlanet" awaits patch after disclosure

Microsoft Defender (all versions currently deployed). Specific affected versions not disclosed. Impacts organizations relying on Defender for endpoint protection.

Microsoft06:32 UTC