Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 675 results
highbug_reportVulnerabilityLarge-scale DDoS campaign disrupts Threema encrypted messaging service
Threema secure messaging service (cloud-hosted instances). Users in Switzerland, India, and China reported outages. Threema On-Prem customers unaffected as they use independent infrastructure. Colocation partner Nine also targeted.
highbug_reportVulnerabilityAmnesiaStealer malware hijacks macOS browser sessions via live remote control
macOS users targeted via ClickFix campaigns using fake GitHub pages. Affects 16 Chromium-based browsers including Chrome, Edge, Brave, Opera, Vivaldi, Arc, and Chromium.
highbug_reportVulnerabilityEvooo1Bot: Mirai-based botnet targets Linux gateways as SOCKS5 proxies
Internet-facing Linux gateway devices (routers, firewalls, edge appliances). Specific vendors and models not disclosed. Mirai-based malware with modular architecture targeting devices with weak credentials or known vulnerabilities.
criticalbug_reportVulnerabilitySAP Commerce Cloud CVE-2026-58231 under active exploit, 3 days post-patch
SAP Commerce Cloud, all versions prior to patched release levels. Vulnerability affects default authentication clients and endpoints lacking input validation. Unauthenticated remote exploitation possible.
highbug_reportVulnerabilitymacOS Screen Sharing auth bypass exploited to deploy Monero miners
macOS Screen Sharing feature on systems with TCP port 5900 exposed to the internet. Fixed in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. CVE-2026-65400 affects earlier versions of these releases.
criticalbug_reportVulnerabilitySAP Commerce Cloud RCE flaw (CVE-2026-58231) exploited 3 days post-patch
SAP Commerce Cloud (formerly Hybris), specifically the core Data Hub Adapter extension. All unpatched instances are vulnerable. Shadowserver tracks 4,200+ internet-exposed instances, primarily in Europe and North America.
highbug_reportVulnerabilityMicrosoft patches LegacyHive Windows zero-day granting admin privileges
Windows User Profile Service in Windows 10 version 2004 and later, Windows Server 2022 and later. Tracked as CVE-2026-62832. All Windows systems running affected versions are vulnerable.
criticalbug_reportVulnerabilityVMware vCenter RCE (CVE-2026-59310) exploited for reverse SSH access
VMware vCenter Server versions prior to 9.1.0.0300 (9.1 branch), 9.0.2.0100 (9.0 branch), and 8.0 U3k/U2f (8.0 branch). The vulnerability affects the vCenter Syslog Server component and is exploitable by unauthenticated attackers with network access.
criticalbug_reportVulnerabilitySonicWall GMS unauthenticated RCE flaws require immediate patching
SonicWall Global Management System (GMS). Specific affected versions not disclosed in available data. Both CVE-2026-66145 and CVE-2026-66147 enable unauthenticated remote code execution.
highbug_reportVulnerabilityPlesk privilege escalation flaw requires immediate patching
Plesk web hosting control panel - specific affected versions not disclosed in advisory. Privilege escalation vulnerability allows attackers to gain elevated access.
criticalbug_reportVulnerabilityCisco Secure Firewall DoS flaw under active exploitation
Cisco Secure Firewall products (specific versions not disclosed in available data). Organizations using Cisco ASA, FTD, or Firepower appliances should assume exposure until vendor advisory is reviewed.
criticalbug_reportVulnerabilityMetabase SQL injection under active exploitation, patch immediately
Metabase open-source business intelligence platform. Specific affected versions not disclosed in advisory. SQL injection vulnerability allows unauthorized database access.
criticalbug_reportVulnerabilitySharePoint CVE-2026-55040 exploited in wild after PoC release
Microsoft SharePoint servers not patched with July 2026 Patch Tuesday updates. All unpatched SharePoint instances are vulnerable to authentication bypass allowing unauthenticated remote attackers to impersonate any site user or administrator.
highbug_reportVulnerabilityWindRelay NFC relay malware + SpyNote RAT steal cards, take loans
Android devices in Czechia, Slovakia, and Slovenia. WindRelay NFC relay malware deployed alongside SpyNote RAT (and variants SpyMax, CypherRAT). 24 WindRelay samples identified on VirusTotal from November 2025 to July 2026.
criticalbug_reportVulnerabilityAdobe Commerce/Magento flaw CVE-2026-71362 exploited to hijack accounts
Adobe Commerce and Magento Open Source e-commerce platforms, all currently supported release lines. The vulnerability affects customer account session handling and requires no authentication to exploit.
highbug_reportVulnerability737 fake Chrome VPN extensions route traffic through attacker SOCKS5 proxies
Google Chrome Web Store users who installed any of 737 malicious extensions impersonating VPN/proxy services (Proton VPN, NordVPN, Surfshark, ExpressVPN, Cloudflare 1.1.1.1). Approximately 75,000 downloads recorded, primarily Russian users.
highbug_reportVulnerabilityPlug and Pwn attacks exploit Windows Plug and Play for SYSTEM access
All Windows systems (including fully patched Windows 11) that support Plug and Play device installation. Specific vulnerable vendor packages include Sierra Wireless and Sony FeliCa software.
highbug_reportVulnerability737 malicious Chrome VPN extensions route traffic through attacker proxies
Google Chrome users who installed any of 737 malicious VPN/proxy extensions from Chrome Web Store, primarily targeting Russian-speaking users. 274 extensions impersonated 66 legitimate VPN brands (Proton VPN, NordVPN, Surfshark, AdGuard VPN, Browsec,…
criticalbug_reportVulnerabilityMicrosoft SharePoint JWT auth bypass exploited in wild after PoC release
Microsoft SharePoint Enterprise Server 2016 and SharePoint Server 2019. CVE-2026-55040 is a critical authentication bypass in JWT token validation allowing unauthenticated attackers to impersonate SharePoint users or administrators.
criticalbug_reportVulnerabilityMicrosoft August 2026 Patch Tuesday: 398 vulnerabilities, 42 critical
Microsoft products and services across the ecosystem. Specific affected products, versions, and CVE identifiers not disclosed in available information. 398 total vulnerabilities addressed, including 42 rated critical severity.
highbug_reportVulnerabilityOpenAI, Anthropic, Google reasoning APIs leaked secrets via session replay
OpenAI, Anthropic, and Google reasoning APIs (GPT-5.6 Luna, Claude Haiku 4.5, Gemini Robotics ER-1.6). Affects developers who published raw agent logs containing encrypted reasoning objects.
criticalbug_reportVulnerabilityAdobe patches three CVSS 10.0 flaws in ColdFusion and Campaign Classic
Adobe ColdFusion 2025.0.x (prior to 2025.0.12) and 2023.0.x (prior to 2023.0.23); Adobe Campaign Classic v7 (prior to 7.4.4 build 9400) on-premise and hybrid deployments; Adobe Commerce (version not specified).
criticalbug_reportVulnerabilityVMware vCenter CVE-2026-59310 exploited in wild for RCE and persistence
Broadcom VMware vCenter Server (all unpatched versions prior to late July 2026 patch release). Affects 361+ confirmed victim IPs across 47 countries, primarily Germany, US, Turkey, Iran, and France.
criticalbug_reportVulnerabilityMalicious LiteLLM PyPI packages stole credentials from 2,100+ orgs
LiteLLM versions 1.82.7 and 1.82.8 published on PyPI on March 24, 2026 (10:39-11:19 UTC, treat installs through 16:00 UTC as suspect). Any system that installed these versions or pulled them as transitive dependencies via agent frameworks or orchestr…
criticalbug_reportVulnerabilitySAP Commerce Cloud critical flaw allows unauthenticated RCE (CVSS 10.0)
SAP Commerce Cloud (Data Hub Adapter). All unpatched versions are affected. The vulnerability impacts the default authentication client and certain functions lacking input validation.
highbug_reportVulnerabilityShieldBreak zero-day bypasses Microsoft Defender patch, grants SYSTEM access
Microsoft Defender for Windows on Windows 11 25H2, Windows Server 2025, and Windows 10 (all editions). The vulnerability bypasses the patch for CVE-2026-50656 (RoguePlanet) in the Microsoft Malware Protection Engine (mpengine.dll).
highbug_reportVulnerabilityCisco ASA/FTD remote DoS flaw exploited in wild, CISA orders patch by Aug 14
Cisco Secure Firewall ASA Software (versions 9.16.1, 9.18.1, 9.20, 9.22, 9.23, 9.24) and FTD Software (versions 7.0, 7.2, 7.4, 7.6, 7.7, 10.0) with IKEv2 Remote Access VPN, SSL-VPN, or Zero Trust Network Access enabled.
highbug_reportVulnerabilityMicrosoft patches 398 flaws including one actively exploited zero-day
Microsoft Windows operating systems and supported software. All Windows endpoints are affected. Critical focus: CVE-2026-68820 (afd.sys driver privilege escalation, actively exploited), CVE-2026-62832 (Windows User Profile Service privilege escalatio…
criticalbug_reportVulnerabilityWindows kernel driver zero-day CVE-2026-68820 exploited by Lazarus APT
Windows kernel driver afd.sys (Ancillary Function Driver for WinSock) across all supported Windows versions. CVE-2026-68820 is a use-after-free vulnerability enabling local privilege escalation to SYSTEM level. CVSS 7.0.
highbug_reportVulnerabilityCisco ASA/FTD VPN flaw CVE-2026-20349 actively exploited for DoS
Cisco Secure Firewall ASA (versions 9.16, 9.18, 9.20, 9.22, 9.23, 9.24) and Threat Defense FTD (versions 7.0, 7.2, 7.4, 7.6, 7.7, 10.0) with Remote Access SSL VPN, IKEv2 Remote Access VPN with client services, or Zero Trust Network Access enabled.