Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 675 results
criticalbug_reportVulnerabilityZoom annotation tool flaws enabled zero-click client hijacking
Zoom Workplace (all platforms) before 7.1.5 and 7.0.6; Zoom Workplace VDI Client for Windows before 7.0.11 and 6.6.16; Zoom Rooms and Zoom Meeting SDK (all platforms) before 7.1.0 and 7.1.5. Affects both screen sharers and meeting viewers.
criticalbug_reportVulnerabilityMicrosoft patches 400 flaws including 3 zero-days, one exploited by Lazarus
All supported Windows versions (Windows 10, Windows 11). Three zero-day vulnerabilities: CVE-2026-68820 (Windows AFD.sys driver, actively exploited by Lazarus APT), CVE-2026-62832 (Windows User Profile Service, publicly disclosed as "LegacyHive"), an…
criticalbug_reportVulnerabilitySharePoint Server auth bypass chained to RCE, no credentials required
Microsoft SharePoint Server Subscription Edition, 2019, and 2016 (CVE-2026-55040, CVSS 9.1). Chained RCE flaw CVE-2026-63520 (CVSS 8.1) also affects Project Server 2013 SP1 and Office Web Apps 2013 SP1. SharePoint Online is not affected.
highbug_reportVulnerabilityMalicious SIM cards can execute code on IoT cellular modules via RUN AT
Cellular IoT modules (6 of 8 tested, primarily Quectel parts with Qualcomm processors) in EV chargers, industrial routers, car telematics units. Limited phone impact: OPPO Find X5, OPPO Reno 14 F 5G, ASUS Zenfone 9.
highbug_reportVulnerabilityMozilla revokes Firefox/Thunderbird Linux signing key after repo exposure
Mozilla Firefox and Thunderbird Linux downloads (all versions signed with subkey 09BE ED63 F346 2A2D FFAB 3B87 5ECB 6497 C1A2 0256 from April 2025 to August 2026).
highbug_reportVulnerabilityKimwolf v7 botnet targets Android IoT with HTTP/2 DDoS, ENS C2 resolution
Android TV boxes and set-top boxes with unauthenticated Android Debug Bridge (ADB) exposed on port 5555. Primarily affects devices accessible via residential proxy services. ARM-based Android IoT devices running vulnerable configurations.
highbug_reportVulnerabilityAeternum botnet uses Polygon blockchain for decentralized C2 infrastructure
Windows systems infected with Aeternum C++ botnet loader (Build.exe). The malware targets Windows environments and uses Polygon blockchain smart contracts for command and control, making traditional domain/IP-based blocking ineffective.
highbug_reportVulnerabilityBdThemes WordPress plugins compromised to create rogue admin accounts
BdThemes WordPress plugins including Element Pack (100,000+ active installs), Prime Slider, Ultimate Post Kit, Pixel Gallery, and Ultimate Store Kit. All versions using the vulnerable Biggop Library introduced in March 2026.
criticalbug_reportVulnerabilityCritical SQL injection in Metabase requires immediate patching
Metabase (specific affected versions not disclosed in advisory). SQL injection vulnerability impacts database query functionality.
highbug_reportVulnerabilityPasskey bypass attacks target Windows, Chrome, and Entra ID implementations
Microsoft Windows 10, Windows 11, Windows Server (CVE-2026-34348); Microsoft Entra ID passkey validation; Google Password Manager synced passkeys in Chrome on Windows; Windows Hello for Business.
highbug_reportVulnerabilityLexisNexis shuts down services after suspicious third-party vendor breach
LexisNexis Diligence, Metabase API, and Newsdesk services. Incident stems from compromise of unnamed third-party vendor's servers hosting these platforms.
highbug_reportVulnerabilityHeap overflow in entr file watcher allows local DoS via argument overflow
eradman entr versions through 5.8. entr is a command-line utility that runs arbitrary commands when files change. All versions up to and including 5.8 are vulnerable.
criticalbug_reportVulnerabilityProgress Kemp LoadMaster command injection flaw exploited in the wild
Progress Kemp LoadMaster GA v7.2.63.1 and older, LTSF v7.2.54.17 and older; MOVEit WAF all versions before GA v7.2.63.2. Approximately 300 instances exposed online. Used by Fortune 500 companies and government agencies including Amazon and U.S.
highbug_reportVulnerabilityMalicious VS Code extensions steal crypto wallets and credentials from devs
Microsoft Visual Studio Code users who installed "Solidity Pro" extensions (helper-beeps.solidity-pro or web3devtoolsx.solidity-pro) from Open VSX marketplace. Extensions targeted Ethereum/Web3 developers.
criticalbug_reportVulnerabilityHead Mare hacktivists backdoor TrueConf installers via server compromise
TrueConf video conferencing servers (unpatched versions) and client installers distributed from compromised servers. Specific vulnerable versions not disclosed. Affects organizations using TrueConf for video conferencing.
highbug_reportVulnerabilityAtlassian Rovo prompt injection enables data exfiltration from Jira/Confluence
Atlassian Rovo assistant on Standard, Premium, and Enterprise plans. Affects organizations with Rovo enabled (default setting). Exploitable by authenticated users who interact with attacker-controlled content (documents) or links (rovoChatPrompt para…
highbug_reportVulnerabilityCSS attacks bypass webmail sanitizers to steal passwords and tokens
Microsoft Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail webmail interfaces. Attacks exploit CSS and HTML parsing discrepancies to escape message boundaries.
criticalbug_reportVulnerabilityMetabase zero-day (CVSS 10.0) exploited for unauthenticated admin access
Metabase versions 1.58.0 through 1.63.2 (all self-hosted and cloud instances). Specifically: 1.58.0–1.58.23, 1.59.0–1.59.20, 1.60.0–1.60.16, 1.61.0–1.61.10, 1.62.0–1.62.8, and 1.63.0–1.63.2. Metabase Cloud instances already patched.
criticalbug_reportVulnerabilityN-able N-central exploited; attackers persist via Cloudflare tunnels
N-able N-central RMM product, all versions prior to 2026.3.1.7. CVE-2026-18577 (CVSS 8.2) is an incomplete fix for CVE-2026-18556 (CVSS 8.2), both enabling authentication bypass and account takeover. On-premise deployments are affected.
criticalbug_reportVulnerabilityProgress Kemp LoadMaster command injection (CVE-2026-8037) exploited
Progress Kemp LoadMaster appliances. All versions with vulnerable escape_quotes() function. Unauthenticated remote attack vector.
criticalbug_reportVulnerabilityMetabase SQL injection zero-day exploited to steal customer data
Metabase (specific versions not disclosed). Confirmed victims include Framework and Tally customer instances. All unpatched Metabase deployments potentially at risk.
criticalbug_reportVulnerabilityNearly 800 malicious npm packages deliver cross-platform RAT via typosquatting
npm registry: ~800 packages using typosquatting and AI-generated names. Targets all Node.js developers on Windows, macOS (x64/ARM64), and Linux (x64/ARM64). Delivers WEL1DROPPER leading to Sliver C2 framework and platform-specific infostealers.
highbug_reportVulnerabilityClickFix attacks deliver macOS stealer targeting crypto wallets and Keychain
macOS systems (all CPU architectures). Users tricked into pasting malicious commands into Terminal. Targets cryptocurrency wallets (Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, XRP), browser passwords, Apple iCloud Keychain, and cached credentials.
criticalbug_reportVulnerabilityKVM VM escape vulnerabilities require immediate patching
KVM (Kernel-based Virtual Machine) hypervisor. Specific affected versions not disclosed in advisory. Impacts organizations running KVM-based virtualization infrastructure on Linux hosts.
highbug_reportVulnerabilityTwo H1 2026 campaigns use compromised email and clipboard hijacking
Campaign 1: Users in Czechia, Slovakia, Poland, and Lithuania targeted by GepyS banking malware via compromised corporate email accounts. Campaign 2: Cryptocurrency users globally affected by Rust-based clipboard hijacker monitoring 21 blockchain typ…
highbug_reportVulnerabilityWordPress pre-auth XSS on login page enables RCE via admin interaction
WordPress CMS all versions prior to 7.0.3. Patches backported to 4.7 branch and newer. Versions older than 4.7 remain vulnerable and unpatched. Default installations affected; no special hosting configuration required.
criticalbug_reportVulnerability18-year-old Linux SCTP flaw enables local root and container escape
Linux kernel versions since 2.6.25 (2008) through 7.1.5, 6.18.41, 6.12.100, and 6.6.147. Affects systems with SCTP networking enabled. Confirmed vulnerable: Debian 13, Ubuntu 24.04, Rocky Linux 9, RHEL 9, OpenCloudOS.
highbug_reportVulnerabilityNatJack attacks hijack TCP sessions via NAT manipulation; Windows & Linux CVEs
Windows NAT (Hyper-V): Windows 11 24H2 <26100.8875, 25H2 <26200.8875, 26H1 <28000.2525, Server 2025 <26100.33158 (CVE-2026-56181, CVSS 8.3). Linux Netfilter conntrack: kernel <5.10.259, <5.15.210, <6.1.176, <6.6.143, <6.12.93, <6.18.35, <7.0.12, <7.1…
highbug_reportVulnerabilityAitM phishing campaign targets Microsoft 365 for payroll email theft
Microsoft 365 accounts across healthcare, education, manufacturing, government, and professional services sectors in the U.S., Canada, and Europe. Hundreds of organizations targeted in July 2026, with focus on payroll, HR, and finance personnel.
highbug_reportVulnerabilityAI system finds HTTP desync techniques; Apache Traffic Server zero-day patched
Apache Traffic Server (CVE-2026-63078, specific versions unknown); 700+ websites vulnerable to HTTP desynchronization including banks, government infrastructure, security products, and airports.