Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports
Cyber Threat Daily Brief — September 4, 2026satellite_altDaily Brief
Threat Intel Brief·Daily Summary

Cyber Threat Daily Brief — September 4, 2026

Today's briefing: 14 critical and 22 high-severity threats. A total of 47 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.

14 Critical22 High47 analyses
schedule02:17 UTC
Read briefarrow_forward

Latest Reports

26 / 1172 results
Operation QUICSILVER: China-nexus campaign targets Myanmar with QUICAgenthighperson_alertThreat Actor
person_alertThreat Actor

Operation QUICSILVER: China-nexus campaign targets Myanmar with QUICAgent

Operation QUICSILVER is attributed with moderate confidence to a China-nexus threat actor conducting cyber espionage operations against Myanmar. The actor demonstrates sophisticated tradecraft, leveraging social engineering lures themed around govern…

The Hacker News24 Aug · 09:51 UTC
CISA orders 3-day patch for exploited Zimbra RCE (CVE-2026-73570)criticalbug_reportVulnerability
bug_reportVulnerability

CISA orders 3-day patch for exploited Zimbra RCE (CVE-2026-73570)

Zimbra Collaboration Suite (ZCS) versions prior to 10.1.20. Exploitation requires SNMP notifications to be enabled. Over 12,000 Zimbra servers exposed online; 270+ confirmed compromised instances detected by Shadowserver.

Zimbra24 Aug · 08:45 UTC
UAT-10147 Deploys AI-Assisted Attacks and SPECTRE Malware Globallyhighperson_alertThreat Actor
person_alertThreat Actor

UAT-10147 Deploys AI-Assisted Attacks and SPECTRE Malware Globally

UAT-10147 is a Chinese-speaking cybercrime group conducting large-scale attacks against Windows and Linux web servers globally. The actor's primary motivation appears to be SEO fraud and data theft.

The Hacker News24 Aug · 06:08 UTC
ToxicPanda 2.0 abuses VPN and ADB to evade Google Play Protecthighbug_reportVulnerability
bug_reportVulnerability

ToxicPanda 2.0 abuses VPN and ADB to evade Google Play Protect

Android devices running Android 11 or later (Wireless ADB support). Targets 349 banking, financial, cryptocurrency, and e-wallet apps across 16 countries. Specific OEM persistence mechanisms for Xiaomi, OPPO, Vivo, Samsung, and Huawei devices.

BleepingComputer23 Aug · 12:23 UTC
Supply-chain attack targets Android car head units via update apphighbug_reportVulnerability
bug_reportVulnerability

Supply-chain attack targets Android car head units via update app

Android-based automotive head units receiving updates through a compromised legitimate device-update application. Specific vendors, models, and geographic distribution not disclosed.

BleepingComputer22 Aug · 12:14 UTC
Attackers shift focus to CI/CD pipelines and developer tools in SDLChighbug_reportVulnerability
bug_reportVulnerability

Attackers shift focus to CI/CD pipelines and developer tools in SDLC

All organizations using modern software development practices with CI/CD pipelines, open-source dependencies, and developer tools. Specific recent attacks include ChainDrop npm worm (400+ packages including keyv and cacheable-request), XZ Utils (CVE-…

Unit 42 (Palo Alto)21 Aug · 21:00 UTC
14 trojanized npm packages deliver AI-powered RedC2 4.0 Linux backdoorhighbug_reportVulnerability
bug_reportVulnerability

14 trojanized npm packages deliver AI-powered RedC2 4.0 Linux backdoor

14 npm packages (streak-metrics-math, kit-map-vim, streak-map-cache, streak-map-kit, map-streak-kit, streak-cache-map, streak-calc-metrics, streak-calc-math, streak-math-abz, streak-metricsaz, streak-math-metrics, streak-metricazbd, streak-metricsazb…

npm21 Aug · 16:53 UTC
SynkLoader malware spreads via Microsoft Teams phishing campaignshighbug_reportVulnerability
bug_reportVulnerability

SynkLoader malware spreads via Microsoft Teams phishing campaigns

Microsoft Teams users across all organizations. SynkLoader is a new credential-stealing malware family delivered through phishing messages on the Teams platform. No specific product versions or CVEs identified.

Microsoft21 Aug · 16:01 UTC
Microsoft Defender BTR.sys driver weaponized for kernel-level sabotagehighbug_reportVulnerability
bug_reportVulnerability

Microsoft Defender BTR.sys driver weaponized for kernel-level sabotage

Microsoft Defender BTR.sys driver on all Windows versions from Windows 7 through Windows 11 25H2. The driver is a required component shipped with every Windows installation and cannot be blocked without breaking Defender functionality.

Microsoft21 Aug · 13:52 UTC
CISA orders patching of two actively exploited TrueConf Server flawscriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders patching of two actively exploited TrueConf Server flaws

TrueConf Server, a self-hosted corporate messaging and video conferencing platform. CVE-2026-72529 (critical missing authentication allowing remote script execution via TCP port 4307) and CVE-2026-72530 (critical sandbox escape enabling arbitrary OS…

TrueConf21 Aug · 10:25 UTC
Microsoft Entra ID deserialization flaw exploited; already patchedcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft Entra ID deserialization flaw exploited; already patched

Microsoft Entra ID (formerly Azure Active Directory) cloud-based identity and access management platform. All versions prior to Microsoft's server-side patch.

Microsoft21 Aug · 09:04 UTC
Threat actors abuse FTP banners to deliver E4del and PINHOLE RATshighbug_reportVulnerability
bug_reportVulnerability

Threat actors abuse FTP banners to deliver E4del and PINHOLE RATs

Windows systems targeted via phishing campaigns delivering LNK files. Two RATs deployed: E4del (Node.js/Electron-based, masquerading as Discord) and PINHOLE (memory-resident, using Pinterest/SurveyMonkey for C2).

BleepingComputer21 Aug · 09:00 UTC
Cisco patches nine flaws in Crosswork and Secure Workload; five rated 10.0criticalbug_reportVulnerability
bug_reportVulnerability

Cisco patches nine flaws in Crosswork and Secure Workload; five rated 10.0

Cisco Crosswork Data Gateway, Crosswork Network Controller, Crosswork Planning (Release 7.2.1 and earlier); Cisco Secure Workload SaaS and on-premises (Release 3.10 and earlier, Release 4.0).

Cisco21 Aug · 08:03 UTC
GitLab CVE-2026-19478 code injection under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

GitLab CVE-2026-19478 code injection under active exploitation

GitLab Community Edition (CE) and Enterprise Edition (EE): versions 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. Affects self-hosted instances with publicly accessible projects.

CVE-2026-1947821 Aug · 05:04 UTC
Microsoft patches critical Entra ID RCE flaw (CVE-2026-69836, CVSS 10.0)criticalbug_reportVulnerability
bug_reportVulnerability

Microsoft patches critical Entra ID RCE flaw (CVE-2026-69836, CVSS 10.0)

Microsoft Entra ID (formerly Azure Active Directory), all versions. Cloud-based identity and access management service. Microsoft has already deployed server-side mitigations; no customer action required.

Microsoft21 Aug · 04:06 UTC
Rust crates compromised via account takeover; build-time malware deployedcriticalbug_reportVulnerability
bug_reportVulnerability

Rust crates compromised via account takeover; build-time malware deployed

Three Rust crates (arrayref 0.3.10, internment 0.8.7, append-only-vec 0.1.9) with 245 million combined downloads. Malicious versions were live for 86-107 minutes on August 20, 2026.

Rust Project20 Aug · 18:22 UTC
UNC6293, UNC7005, UNC5976 Abuse OAuth and WhatsApp Linking for Espionagehighperson_alertThreat Actor
person_alertThreat Actor

UNC6293, UNC7005, UNC5976 Abuse OAuth and WhatsApp Linking for Espionage

UNC6293, UNC7005, and UNC5976 are three distinct suspected Russian cyber espionage threat clusters conducting persistent account compromise operations. UNC6293 is assessed to be a sub-cluster of Ice Relic (formerly APT29, also tracked as Cozy Bear an…

Google20 Aug · 17:59 UTC
Zero-click RCE in Zoom clients requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Zero-click RCE in Zoom clients requires immediate patching

Zoom clients (specific versions not disclosed in available data). Zero-click remote code execution vulnerability affects users without interaction required.

Zoom20 Aug · 16:29 UTC
Rust crate arrayref compromised via maintainer account takeovercriticalbug_reportVulnerability
bug_reportVulnerability

Rust crate arrayref compromised via maintainer account takeover

Rust crate arrayref (vendor: arrayref). Specific malicious versions not detailed in source. Affects developers using this dependency during compilation. Scope: Rust ecosystem supply chain.

arrayref20 Aug · 15:53 UTC
Gogs 10.0 RCE and n8n workflow-to-RCE vulnerabilities disclosedhighbug_reportVulnerability
bug_reportVulnerability

Gogs 10.0 RCE and n8n workflow-to-RCE vulnerabilities disclosed

Gogs version 10.0 (Git service) and n8n (workflow automation platform) - specific n8n versions not provided. Multiple attack vectors disclosed including signed driver abuse (Microsoft Defender BTR.sys), DLL sideloading via Grandoreiro, and ErrTraffic…

Gogs20 Aug · 15:23 UTC
AI-Generated Exploits Target Siemens S7 PLCs in U.S. Critical Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

AI-Generated Exploits Target Siemens S7 PLCs in U.S. Critical Infrastructure

This campaign involves unattributed threat actors leveraging artificial intelligence to generate exploitation scripts targeting industrial control systems.

Siemens20 Aug · 14:59 UTC
Elementor Pro WordPress plugin allows arbitrary file upload and RCEcriticalbug_reportVulnerability
bug_reportVulnerability

Elementor Pro WordPress plugin allows arbitrary file upload and RCE

Elementor Pro WordPress plugin. Specific vulnerable versions not disclosed in available data. Affects WordPress sites with Elementor Pro installed.

Elementor20 Aug · 12:39 UTC
Grok chatbot vulnerable to data exfiltration via encrypted prompt injectionhighbug_reportVulnerability
bug_reportVulnerability

Grok chatbot vulnerable to data exfiltration via encrypted prompt injection

xAI Grok 4.5 Fast (web chat at grok.com). Google Gemini 3 Flash (Web) in Deep Thinking mode also demonstrated vulnerable in March 2026. Affects users requesting web page summaries through the chatbot interface.

xAI20 Aug · 12:36 UTC
Red Hat Keycloak password-reset flaw enables account takeovercriticalbug_reportVulnerability
bug_reportVulnerability

Red Hat Keycloak password-reset flaw enables account takeover

Red Hat build of Keycloak, specific versions not disclosed in source. Vulnerability exists in the password-reset flow mechanism.

Red Hat20 Aug · 12:36 UTC
Citrix NetScaler ADC/Gateway auth bypass requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Citrix NetScaler ADC/Gateway auth bypass requires immediate patching

Citrix NetScaler ADC and NetScaler Gateway products. Specific affected versions not disclosed in available information. Authentication bypass vulnerability allows unauthorized access.

Citrix20 Aug · 12:25 UTC
Critical sandbox escape in isolated-vm ≤7.0.0 enables RCE on hostcriticalbug_reportVulnerability
bug_reportVulnerability

Critical sandbox escape in isolated-vm ≤7.0.0 enables RCE on host

isolated-vm library versions ≤7.0.0. Patched in versions 6.2.0 and 7.0.1. Affects Node.js environments using isolated-vm for sandboxing untrusted JavaScript. Package has ~1 million weekly npm downloads.

isolated-vm20 Aug · 11:48 UTC