Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
23 / 173 results
highbug_reportVulnerabilityCIFSwitch: Linux kernel CIFS flaw enables local privilege escalation
Linux kernel CIFS implementation across multiple distributions. Specific affected kernel versions not yet disclosed. Requires local access to exploit.
highbug_reportVulnerabilityPalo Alto PAN-OS auth bypass (CVE-2026-0257) exploited in the wild
Palo Alto Networks PAN-OS and Prisma Access. Specific affected versions not disclosed in provided data. Vulnerability impacts VPN authentication mechanisms.
highbug_reportVulnerability33 malicious npm packages deployed in dependency confusion recon campaign
npm ecosystem; organizations using private npm packages with names vulnerable to dependency confusion attacks. Affects developer workstations, CI/CD pipelines, and build environments that may inadvertently install public packages instead of intended…
highbug_reportVulnerabilityThreat actors abuse ChatGPT sharing to host fake OpenAI outage pages
OpenAI ChatGPT users globally. Threat actors exploit ChatGPT's legitimate content-sharing feature (chatgpt.com shared links) to host convincing phishing pages that impersonate OpenAI outage notifications and distribute malware posing as the ChatGPT d…
highbug_reportVulnerabilityChatGPT Markdown renderer vulnerable to prompt injection and phishing
OpenAI ChatGPT web summary response renderer. All users interacting with ChatGPT's web interface that processes Markdown links and images are potentially affected. Specific version details not disclosed.
criticalbug_reportVulnerabilityStarlette and FastAPI authentication bypass flaw affects millions of servers
Starlette web framework and dependent frameworks including FastAPI. Specific vulnerable versions not provided in source data. Affects authentication mechanisms in applications built with these frameworks.
highbug_reportVulnerabilityCryptojacking campaign uses SEO poisoning and AI chatbots for GPU malware
High-performance systems with GPUs accessed via search engines and AI chatbot platforms. No specific vendor or product vulnerability; targets users searching for legitimate software or information through poisoned search results and manipulated chatb…
criticalbug_reportVulnerabilityMicrosoft SharePoint RCE vulnerability requires immediate patching
Microsoft SharePoint Server (specific versions not disclosed in advisory). Organizations running on-premises SharePoint deployments are affected. SharePoint Online managed by Microsoft likely already patched.
highbug_reportVulnerabilityCrowdStrike, Google disrupt GlassWorm C2 targeting software developers
Software developers using third-party packages and browser extensions. GlassWorm campaign active since early 2025, distributing malware through supply chain vectors including malicious packages and extensions.
highbug_reportVulnerabilityCryptojacking campaign uses SEO poisoning and ScreenConnect for GPU mining
Organizations using ScreenConnect remote access software; high-performance PCs with GPUs; users searching for compromised topics via search engines and AI chatbots. Campaign leverages Microsoft .NET utilities for execution.
highperson_alertThreat ActorF5 BIG-IP Exploitation Leads to Confluence Compromise and Lateral Movement
The threat actor behind this campaign remains unattributed. Motivation appears to be credential theft and network persistence within enterprise environments.
highperson_alertThreat ActorScreening Serpens: Iranian APT Targets Tech and Defense with RAT Malware
Screening Serpens is an Iranian APT group attributed by Unit 42, conducting cyber espionage operations. The group is motivated by intelligence collection targeting technology and defense sectors, consistent with Iranian state interests in acquiring s…
highperson_alertThreat ActorMegalodon campaign injects 5,718 malicious commits into GitHub repos
Megalodon is an automated supply chain attack campaign targeting GitHub repositories. The actor's motivation appears to be exfiltration of CI/CD environment data, including secrets, tokens, and credentials stored in GitHub Actions workflows.
criticalbug_reportVulnerabilityCisco Secure Workload REST API flaw allows unauthenticated data access
Cisco Secure Workload (formerly Tetration). Specific affected versions not provided in available data. Vulnerability impacts REST API endpoints with insufficient authentication controls.
highperson_alertThreat ActorDort Arrested for Operating Kimwolf IoT Botnet in Multi-Million Device DDoS Campaign
Dort is a 23-year-old cybercriminal based in Ottawa, Canada, suspected of developing and operating the Kimwolf IoT botnet. Motivated by launching large-scale DDoS attacks, doxing, and swatting campaigns, Dort leveraged compromised IoT devices to buil…
highbug_reportVulnerabilityChromium zero-day disclosed: JavaScript persists after browser close
Chromium-based browsers (Google Chrome, Microsoft Edge, Brave, Opera, Vivaldi) - specific affected versions not disclosed. Vulnerability remains unpatched at time of disclosure.
criticalbug_reportVulnerabilityCisco Secure Workload max-severity flaw grants Site Admin privileges
Cisco Secure Workload platform. Specific affected versions not provided in summary. Vulnerability allows privilege escalation to Site Admin level, affecting administrative access controls.
highbug_reportVulnerabilityMicrosoft Defender privilege escalation CVE-2026-41091 under active exploit
Microsoft Defender on Windows systems. Specific product versions not disclosed. Vulnerability allows local attackers to escalate privileges to SYSTEM level through improper link resolution handling.
criticalbug_reportVulnerabilitySonicWall Gen6 SSL-VPN exploited for credential brute-force and MFA bypass
SonicWall Gen6 SSL-VPN appliances with incomplete patching. Specific firmware versions not disclosed. Affects organizations using SonicWall SSL-VPN for remote access.
criticalbug_reportVulnerabilityPgBouncer integer overflow under active exploitation, patch immediately
PgBouncer (PostgreSQL connection pooler) - specific affected versions not disclosed by CERT.BE. All unpatched instances should be considered at risk.
highperson_alertThreat ActorTeamPCP Lists GitHub Source Code for Sale After Repository Breach
TeamPCP is a threat actor that has emerged in the cybercrime ecosystem, demonstrating capability to compromise high-value technology platforms. The actor's motivation appears financially driven, as evidenced by their decision to monetize stolen GitHu…
highbug_reportVulnerabilityFortinet FortiCloud SSO bypass exploited to extract LDAP passwords
Fortinet FortiGate appliances with FortiCloud SSO enabled. CVE-2025-59718 and CVE-2025-59719 allow authentication bypass. All FortiGate instances share a default static encryption key that enables decryption of LDAP credentials and private keys from…
criticalbug_reportVulnerabilityFortinet FortiCloud SSO auth bypass under active exploitation
Fortinet FortiCloud SSO SAML authentication processing (CVE-2025-59718, CVE-2025-59719). Affects management interfaces of FortiGate and potentially other Fortinet products using FortiCloud SSO.