Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 675 results
Active filter:✕ clear
Large-scale DDoS campaign disrupts Threema encrypted messaging servicehighbug_reportVulnerability
bug_reportVulnerability

Large-scale DDoS campaign disrupts Threema encrypted messaging service

Threema secure messaging service (cloud-hosted instances). Users in Switzerland, India, and China reported outages. Threema On-Prem customers unaffected as they use independent infrastructure. Colocation partner Nine also targeted.

Threema16 Aug · 15:29 UTC
AmnesiaStealer malware hijacks macOS browser sessions via live remote controlhighbug_reportVulnerability
bug_reportVulnerability

AmnesiaStealer malware hijacks macOS browser sessions via live remote control

macOS users targeted via ClickFix campaigns using fake GitHub pages. Affects 16 Chromium-based browsers including Chrome, Edge, Brave, Opera, Vivaldi, Arc, and Chromium.

BleepingComputer16 Aug · 13:07 UTC
Evooo1Bot: Mirai-based botnet targets Linux gateways as SOCKS5 proxieshighbug_reportVulnerability
bug_reportVulnerability

Evooo1Bot: Mirai-based botnet targets Linux gateways as SOCKS5 proxies

Internet-facing Linux gateway devices (routers, firewalls, edge appliances). Specific vendors and models not disclosed. Mirai-based malware with modular architecture targeting devices with weak credentials or known vulnerabilities.

BleepingComputer15 Aug · 12:14 UTC
SAP Commerce Cloud CVE-2026-58231 under active exploit, 3 days post-patchcriticalbug_reportVulnerability
bug_reportVulnerability

SAP Commerce Cloud CVE-2026-58231 under active exploit, 3 days post-patch

SAP Commerce Cloud, all versions prior to patched release levels. Vulnerability affects default authentication clients and endpoints lacking input validation. Unauthenticated remote exploitation possible.

CVE-2026-5823115 Aug · 06:38 UTC
macOS Screen Sharing auth bypass exploited to deploy Monero minershighbug_reportVulnerability
bug_reportVulnerability

macOS Screen Sharing auth bypass exploited to deploy Monero miners

macOS Screen Sharing feature on systems with TCP port 5900 exposed to the internet. Fixed in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. CVE-2026-65400 affects earlier versions of these releases.

Apple14 Aug · 12:59 UTC
SAP Commerce Cloud RCE flaw (CVE-2026-58231) exploited 3 days post-patchcriticalbug_reportVulnerability
bug_reportVulnerability

SAP Commerce Cloud RCE flaw (CVE-2026-58231) exploited 3 days post-patch

SAP Commerce Cloud (formerly Hybris), specifically the core Data Hub Adapter extension. All unpatched instances are vulnerable. Shadowserver tracks 4,200+ internet-exposed instances, primarily in Europe and North America.

SAP14 Aug · 11:45 UTC
Microsoft patches LegacyHive Windows zero-day granting admin privilegeshighbug_reportVulnerability
bug_reportVulnerability

Microsoft patches LegacyHive Windows zero-day granting admin privileges

Windows User Profile Service in Windows 10 version 2004 and later, Windows Server 2022 and later. Tracked as CVE-2026-62832. All Windows systems running affected versions are vulnerable.

Microsoft13 Aug · 15:46 UTC
VMware vCenter RCE (CVE-2026-59310) exploited for reverse SSH accesscriticalbug_reportVulnerability
bug_reportVulnerability

VMware vCenter RCE (CVE-2026-59310) exploited for reverse SSH access

VMware vCenter Server versions prior to 9.1.0.0300 (9.1 branch), 9.0.2.0100 (9.0 branch), and 8.0 U3k/U2f (8.0 branch). The vulnerability affects the vCenter Syslog Server component and is exploitable by unauthenticated attackers with network access.

CVE-2026-5931013 Aug · 14:40 UTC
SonicWall GMS unauthenticated RCE flaws require immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

SonicWall GMS unauthenticated RCE flaws require immediate patching

SonicWall Global Management System (GMS). Specific affected versions not disclosed in available data. Both CVE-2026-66145 and CVE-2026-66147 enable unauthenticated remote code execution.

CVE-2026-6614513 Aug · 13:36 UTC
Plesk privilege escalation flaw requires immediate patchinghighbug_reportVulnerability
bug_reportVulnerability

Plesk privilege escalation flaw requires immediate patching

Plesk web hosting control panel - specific affected versions not disclosed in advisory. Privilege escalation vulnerability allows attackers to gain elevated access.

Plesk13 Aug · 13:01 UTC
Cisco Secure Firewall DoS flaw under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Cisco Secure Firewall DoS flaw under active exploitation

Cisco Secure Firewall products (specific versions not disclosed in available data). Organizations using Cisco ASA, FTD, or Firepower appliances should assume exposure until vendor advisory is reviewed.

Cisco13 Aug · 06:31 UTC
Metabase SQL injection under active exploitation, patch immediatelycriticalbug_reportVulnerability
bug_reportVulnerability

Metabase SQL injection under active exploitation, patch immediately

Metabase open-source business intelligence platform. Specific affected versions not disclosed in advisory. SQL injection vulnerability allows unauthorized database access.

Metabase13 Aug · 06:16 UTC
SharePoint CVE-2026-55040 exploited in wild after PoC releasecriticalbug_reportVulnerability
bug_reportVulnerability

SharePoint CVE-2026-55040 exploited in wild after PoC release

Microsoft SharePoint servers not patched with July 2026 Patch Tuesday updates. All unpatched SharePoint instances are vulnerable to authentication bypass allowing unauthenticated remote attackers to impersonate any site user or administrator.

CVE-2026-5504013 Aug · 04:09 UTC
WindRelay NFC relay malware + SpyNote RAT steal cards, take loanshighbug_reportVulnerability
bug_reportVulnerability

WindRelay NFC relay malware + SpyNote RAT steal cards, take loans

Android devices in Czechia, Slovakia, and Slovenia. WindRelay NFC relay malware deployed alongside SpyNote RAT (and variants SpyMax, CypherRAT). 24 WindRelay samples identified on VirusTotal from November 2025 to July 2026.

BleepingComputer12 Aug · 20:22 UTC
Adobe Commerce/Magento flaw CVE-2026-71362 exploited to hijack accountscriticalbug_reportVulnerability
bug_reportVulnerability

Adobe Commerce/Magento flaw CVE-2026-71362 exploited to hijack accounts

Adobe Commerce and Magento Open Source e-commerce platforms, all currently supported release lines. The vulnerability affects customer account session handling and requires no authentication to exploit.

CVE-2026-7136212 Aug · 18:54 UTC
737 fake Chrome VPN extensions route traffic through attacker SOCKS5 proxieshighbug_reportVulnerability
bug_reportVulnerability

737 fake Chrome VPN extensions route traffic through attacker SOCKS5 proxies

Google Chrome Web Store users who installed any of 737 malicious extensions impersonating VPN/proxy services (Proton VPN, NordVPN, Surfshark, ExpressVPN, Cloudflare 1.1.1.1). Approximately 75,000 downloads recorded, primarily Russian users.

Google12 Aug · 16:54 UTC
Plug and Pwn attacks exploit Windows Plug and Play for SYSTEM accesshighbug_reportVulnerability
bug_reportVulnerability

Plug and Pwn attacks exploit Windows Plug and Play for SYSTEM access

All Windows systems (including fully patched Windows 11) that support Plug and Play device installation. Specific vulnerable vendor packages include Sierra Wireless and Sony FeliCa software.

Microsoft12 Aug · 14:05 UTC
737 malicious Chrome VPN extensions route traffic through attacker proxieshighbug_reportVulnerability
bug_reportVulnerability

737 malicious Chrome VPN extensions route traffic through attacker proxies

Google Chrome users who installed any of 737 malicious VPN/proxy extensions from Chrome Web Store, primarily targeting Russian-speaking users. 274 extensions impersonated 66 legitimate VPN brands (Proton VPN, NordVPN, Surfshark, AdGuard VPN, Browsec,…

Google12 Aug · 12:09 UTC
Microsoft SharePoint JWT auth bypass exploited in wild after PoC releasecriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft SharePoint JWT auth bypass exploited in wild after PoC release

Microsoft SharePoint Enterprise Server 2016 and SharePoint Server 2019. CVE-2026-55040 is a critical authentication bypass in JWT token validation allowing unauthenticated attackers to impersonate SharePoint users or administrators.

Microsoft12 Aug · 10:25 UTC
Microsoft August 2026 Patch Tuesday: 398 vulnerabilities, 42 criticalcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft August 2026 Patch Tuesday: 398 vulnerabilities, 42 critical

Microsoft products and services across the ecosystem. Specific affected products, versions, and CVE identifiers not disclosed in available information. 398 total vulnerabilities addressed, including 42 rated critical severity.

Microsoft12 Aug · 10:11 UTC
OpenAI, Anthropic, Google reasoning APIs leaked secrets via session replayhighbug_reportVulnerability
bug_reportVulnerability

OpenAI, Anthropic, Google reasoning APIs leaked secrets via session replay

OpenAI, Anthropic, and Google reasoning APIs (GPT-5.6 Luna, Claude Haiku 4.5, Gemini Robotics ER-1.6). Affects developers who published raw agent logs containing encrypted reasoning objects.

OpenAI12 Aug · 09:47 UTC
Adobe patches three CVSS 10.0 flaws in ColdFusion and Campaign Classiccriticalbug_reportVulnerability
bug_reportVulnerability

Adobe patches three CVSS 10.0 flaws in ColdFusion and Campaign Classic

Adobe ColdFusion 2025.0.x (prior to 2025.0.12) and 2023.0.x (prior to 2023.0.23); Adobe Campaign Classic v7 (prior to 7.4.4 build 9400) on-premise and hybrid deployments; Adobe Commerce (version not specified).

CVE-2026-4836212 Aug · 09:13 UTC
VMware vCenter CVE-2026-59310 exploited in wild for RCE and persistencecriticalbug_reportVulnerability
bug_reportVulnerability

VMware vCenter CVE-2026-59310 exploited in wild for RCE and persistence

Broadcom VMware vCenter Server (all unpatched versions prior to late July 2026 patch release). Affects 361+ confirmed victim IPs across 47 countries, primarily Germany, US, Turkey, Iran, and France.

CVE-2026-5931012 Aug · 07:01 UTC
Malicious LiteLLM PyPI packages stole credentials from 2,100+ orgscriticalbug_reportVulnerability
bug_reportVulnerability

Malicious LiteLLM PyPI packages stole credentials from 2,100+ orgs

LiteLLM versions 1.82.7 and 1.82.8 published on PyPI on March 24, 2026 (10:39-11:19 UTC, treat installs through 16:00 UTC as suspect). Any system that installed these versions or pulled them as transitive dependencies via agent frameworks or orchestr…

LiteLLM12 Aug · 06:04 UTC
SAP Commerce Cloud critical flaw allows unauthenticated RCE (CVSS 10.0)criticalbug_reportVulnerability
bug_reportVulnerability

SAP Commerce Cloud critical flaw allows unauthenticated RCE (CVSS 10.0)

SAP Commerce Cloud (Data Hub Adapter). All unpatched versions are affected. The vulnerability impacts the default authentication client and certain functions lacking input validation.

CVE-2026-5823112 Aug · 05:31 UTC
ShieldBreak zero-day bypasses Microsoft Defender patch, grants SYSTEM accesshighbug_reportVulnerability
bug_reportVulnerability

ShieldBreak zero-day bypasses Microsoft Defender patch, grants SYSTEM access

Microsoft Defender for Windows on Windows 11 25H2, Windows Server 2025, and Windows 10 (all editions). The vulnerability bypasses the patch for CVE-2026-50656 (RoguePlanet) in the Microsoft Malware Protection Engine (mpengine.dll).

CVE-2026-5065612 Aug · 04:41 UTC
Cisco ASA/FTD remote DoS flaw exploited in wild, CISA orders patch by Aug 14highbug_reportVulnerability
bug_reportVulnerability

Cisco ASA/FTD remote DoS flaw exploited in wild, CISA orders patch by Aug 14

Cisco Secure Firewall ASA Software (versions 9.16.1, 9.18.1, 9.20, 9.22, 9.23, 9.24) and FTD Software (versions 7.0, 7.2, 7.4, 7.6, 7.7, 10.0) with IKEv2 Remote Access VPN, SSL-VPN, or Zero Trust Network Access enabled.

CVE-2026-2034912 Aug · 04:15 UTC
Microsoft patches 398 flaws including one actively exploited zero-dayhighbug_reportVulnerability
bug_reportVulnerability

Microsoft patches 398 flaws including one actively exploited zero-day

Microsoft Windows operating systems and supported software. All Windows endpoints are affected. Critical focus: CVE-2026-68820 (afd.sys driver privilege escalation, actively exploited), CVE-2026-62832 (Windows User Profile Service privilege escalatio…

Microsoft11 Aug · 19:28 UTC
Windows kernel driver zero-day CVE-2026-68820 exploited by Lazarus APTcriticalbug_reportVulnerability
bug_reportVulnerability

Windows kernel driver zero-day CVE-2026-68820 exploited by Lazarus APT

Windows kernel driver afd.sys (Ancillary Function Driver for WinSock) across all supported Windows versions. CVE-2026-68820 is a use-after-free vulnerability enabling local privilege escalation to SYSTEM level. CVSS 7.0.

CVE-2026-6882011 Aug · 18:10 UTC
Cisco ASA/FTD VPN flaw CVE-2026-20349 actively exploited for DoShighbug_reportVulnerability
bug_reportVulnerability

Cisco ASA/FTD VPN flaw CVE-2026-20349 actively exploited for DoS

Cisco Secure Firewall ASA (versions 9.16, 9.18, 9.20, 9.22, 9.23, 9.24) and Threat Defense FTD (versions 7.0, 7.2, 7.4, 7.6, 7.7, 10.0) with Remote Access SSL VPN, IKEv2 Remote Access VPN with client services, or Zero Trust Network Access enabled.

Cisco11 Aug · 17:45 UTC