Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
satellite_altDaily BriefCyber Threat Daily Brief — September 4, 2026
Today's briefing: 14 critical and 22 high-severity threats. A total of 47 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.
Latest Reports
26 / 1172 results
highperson_alertThreat ActorOperation QUICSILVER: China-nexus campaign targets Myanmar with QUICAgent
Operation QUICSILVER is attributed with moderate confidence to a China-nexus threat actor conducting cyber espionage operations against Myanmar. The actor demonstrates sophisticated tradecraft, leveraging social engineering lures themed around govern…
criticalbug_reportVulnerabilityCISA orders 3-day patch for exploited Zimbra RCE (CVE-2026-73570)
Zimbra Collaboration Suite (ZCS) versions prior to 10.1.20. Exploitation requires SNMP notifications to be enabled. Over 12,000 Zimbra servers exposed online; 270+ confirmed compromised instances detected by Shadowserver.
highperson_alertThreat ActorUAT-10147 Deploys AI-Assisted Attacks and SPECTRE Malware Globally
UAT-10147 is a Chinese-speaking cybercrime group conducting large-scale attacks against Windows and Linux web servers globally. The actor's primary motivation appears to be SEO fraud and data theft.
highbug_reportVulnerabilityToxicPanda 2.0 abuses VPN and ADB to evade Google Play Protect
Android devices running Android 11 or later (Wireless ADB support). Targets 349 banking, financial, cryptocurrency, and e-wallet apps across 16 countries. Specific OEM persistence mechanisms for Xiaomi, OPPO, Vivo, Samsung, and Huawei devices.
highbug_reportVulnerabilitySupply-chain attack targets Android car head units via update app
Android-based automotive head units receiving updates through a compromised legitimate device-update application. Specific vendors, models, and geographic distribution not disclosed.
highbug_reportVulnerabilityAttackers shift focus to CI/CD pipelines and developer tools in SDLC
All organizations using modern software development practices with CI/CD pipelines, open-source dependencies, and developer tools. Specific recent attacks include ChainDrop npm worm (400+ packages including keyv and cacheable-request), XZ Utils (CVE-…
highbug_reportVulnerability14 trojanized npm packages deliver AI-powered RedC2 4.0 Linux backdoor
14 npm packages (streak-metrics-math, kit-map-vim, streak-map-cache, streak-map-kit, map-streak-kit, streak-cache-map, streak-calc-metrics, streak-calc-math, streak-math-abz, streak-metricsaz, streak-math-metrics, streak-metricazbd, streak-metricsazb…
highbug_reportVulnerabilitySynkLoader malware spreads via Microsoft Teams phishing campaigns
Microsoft Teams users across all organizations. SynkLoader is a new credential-stealing malware family delivered through phishing messages on the Teams platform. No specific product versions or CVEs identified.
highbug_reportVulnerabilityMicrosoft Defender BTR.sys driver weaponized for kernel-level sabotage
Microsoft Defender BTR.sys driver on all Windows versions from Windows 7 through Windows 11 25H2. The driver is a required component shipped with every Windows installation and cannot be blocked without breaking Defender functionality.
criticalbug_reportVulnerabilityCISA orders patching of two actively exploited TrueConf Server flaws
TrueConf Server, a self-hosted corporate messaging and video conferencing platform. CVE-2026-72529 (critical missing authentication allowing remote script execution via TCP port 4307) and CVE-2026-72530 (critical sandbox escape enabling arbitrary OS…
criticalbug_reportVulnerabilityMicrosoft Entra ID deserialization flaw exploited; already patched
Microsoft Entra ID (formerly Azure Active Directory) cloud-based identity and access management platform. All versions prior to Microsoft's server-side patch.
highbug_reportVulnerabilityThreat actors abuse FTP banners to deliver E4del and PINHOLE RATs
Windows systems targeted via phishing campaigns delivering LNK files. Two RATs deployed: E4del (Node.js/Electron-based, masquerading as Discord) and PINHOLE (memory-resident, using Pinterest/SurveyMonkey for C2).
criticalbug_reportVulnerabilityCisco patches nine flaws in Crosswork and Secure Workload; five rated 10.0
Cisco Crosswork Data Gateway, Crosswork Network Controller, Crosswork Planning (Release 7.2.1 and earlier); Cisco Secure Workload SaaS and on-premises (Release 3.10 and earlier, Release 4.0).
criticalbug_reportVulnerabilityGitLab CVE-2026-19478 code injection under active exploitation
GitLab Community Edition (CE) and Enterprise Edition (EE): versions 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. Affects self-hosted instances with publicly accessible projects.
criticalbug_reportVulnerabilityMicrosoft patches critical Entra ID RCE flaw (CVE-2026-69836, CVSS 10.0)
Microsoft Entra ID (formerly Azure Active Directory), all versions. Cloud-based identity and access management service. Microsoft has already deployed server-side mitigations; no customer action required.
criticalbug_reportVulnerabilityRust crates compromised via account takeover; build-time malware deployed
Three Rust crates (arrayref 0.3.10, internment 0.8.7, append-only-vec 0.1.9) with 245 million combined downloads. Malicious versions were live for 86-107 minutes on August 20, 2026.
highperson_alertThreat ActorUNC6293, UNC7005, UNC5976 Abuse OAuth and WhatsApp Linking for Espionage
UNC6293, UNC7005, and UNC5976 are three distinct suspected Russian cyber espionage threat clusters conducting persistent account compromise operations. UNC6293 is assessed to be a sub-cluster of Ice Relic (formerly APT29, also tracked as Cozy Bear an…
criticalbug_reportVulnerabilityZero-click RCE in Zoom clients requires immediate patching
Zoom clients (specific versions not disclosed in available data). Zero-click remote code execution vulnerability affects users without interaction required.
criticalbug_reportVulnerabilityRust crate arrayref compromised via maintainer account takeover
Rust crate arrayref (vendor: arrayref). Specific malicious versions not detailed in source. Affects developers using this dependency during compilation. Scope: Rust ecosystem supply chain.
highbug_reportVulnerabilityGogs 10.0 RCE and n8n workflow-to-RCE vulnerabilities disclosed
Gogs version 10.0 (Git service) and n8n (workflow automation platform) - specific n8n versions not provided. Multiple attack vectors disclosed including signed driver abuse (Microsoft Defender BTR.sys), DLL sideloading via Grandoreiro, and ErrTraffic…
highperson_alertThreat ActorAI-Generated Exploits Target Siemens S7 PLCs in U.S. Critical Infrastructure
This campaign involves unattributed threat actors leveraging artificial intelligence to generate exploitation scripts targeting industrial control systems.
criticalbug_reportVulnerabilityElementor Pro WordPress plugin allows arbitrary file upload and RCE
Elementor Pro WordPress plugin. Specific vulnerable versions not disclosed in available data. Affects WordPress sites with Elementor Pro installed.
highbug_reportVulnerabilityGrok chatbot vulnerable to data exfiltration via encrypted prompt injection
xAI Grok 4.5 Fast (web chat at grok.com). Google Gemini 3 Flash (Web) in Deep Thinking mode also demonstrated vulnerable in March 2026. Affects users requesting web page summaries through the chatbot interface.
criticalbug_reportVulnerabilityRed Hat Keycloak password-reset flaw enables account takeover
Red Hat build of Keycloak, specific versions not disclosed in source. Vulnerability exists in the password-reset flow mechanism.
criticalbug_reportVulnerabilityCitrix NetScaler ADC/Gateway auth bypass requires immediate patching
Citrix NetScaler ADC and NetScaler Gateway products. Specific affected versions not disclosed in available information. Authentication bypass vulnerability allows unauthorized access.
criticalbug_reportVulnerabilityCritical sandbox escape in isolated-vm ≤7.0.0 enables RCE on host
isolated-vm library versions ≤7.0.0. Patched in versions 6.2.0 and 7.0.1. Affects Node.js environments using isolated-vm for sandboxing untrusted JavaScript. Package has ~1 million weekly npm downloads.