Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 358 results
criticalbug_reportVulnerabilitySupply chain attack compromises 144 Mastra npm packages via hijacked account
144 npm packages in the @mastra/* namespace (Mastra AI framework for JavaScript/TypeScript). Attack vector: compromised npm contributor account (ehindero). All downstream projects using affected Mastra packages are potentially impacted.
criticalbug_reportVulnerabilityCISA: Widget Factory Joomla JCE flaw exploited in the wild (CVSS 10.0)
Widget Factory Joomla Content Editor (JCE). Specific affected versions not disclosed. Impacts Joomla CMS installations using the JCE component.
highbug_reportVulnerabilityMalicious JetBrains IDE plugins steal AI API keys from developers
JetBrains Marketplace users who installed any of the 15+ malicious plugins. Affects developers using JetBrains IDEs (IntelliJ IDEA, PyCharm, WebStorm, etc.) with AI API keys configured. Specific plugin names and versions not provided in summary.
highbug_reportVulnerabilityRokarolla Android banking trojan targets 217 banking and crypto apps
Android devices with 217 targeted banking and cryptocurrency applications. Malware features 137 commands for comprehensive device control and data exfiltration. Specific app list and Android version scope not disclosed.
highbug_reportVulnerabilityGoogle Cloud Vertex AI SDK flaw enables ML model hijacking via pickle attack
Google Cloud Vertex AI SDK for Python. Specific affected versions not disclosed. Impacts organizations using the SDK to upload and deploy machine learning models to Google Cloud's serving infrastructure.
highbug_reportVulnerabilityMalware campaign abuses Steam Workshop via Wallpaper Engine packages
Valve Steam Workshop users, specifically those using Wallpaper Engine application. All versions of Wallpaper Engine that integrate with Steam Workshop are potentially affected. Scope includes users downloading community-created wallpaper content.
highbug_reportVulnerabilityClickFix campaigns deploy three malware loaders via fake updates
Education and financial sector organizations targeted by ClickFix social engineering campaigns delivering BabaDeda Loader, Lorem Ipsum Loader, and Potemkin malware loaders through fake software update lures.
criticalbug_reportVulnerabilityCisco SD-WAN vulnerability under active exploitation, patches released
Cisco SD-WAN products. Specific affected versions not provided in available data. Organizations running Cisco SD-WAN infrastructure are potentially at risk.
highbug_reportVulnerabilityHeap buffer overflow in jansi library enables code execution
jansi library (all versions not specified). The jansi library is a Java library for ANSI escape sequences, commonly used in console applications and logging frameworks across Java ecosystems.
criticalbug_reportVulnerabilityCISA orders patch for exploited LiteSpeed cPanel plugin flaw (3-day deadline)
LiteSpeed cPanel user-end plugin (specific versions not disclosed). Affects web hosting environments using cPanel with LiteSpeed integration. U.S. federal agencies explicitly targeted by CISA directive.
criticalbug_reportVulnerabilityFortinet FortiSandbox under active exploit for 3 CVEs including critical 9.1
Fortinet FortiSandbox - specific affected versions not disclosed. Three CVEs: CVE-2026-39813 (CVSS 9.1 critical), CVE-2026-39808, CVE-2026-25089. At least one vulnerability recently patched; patch status of others unclear.
highbug_reportVulnerabilityVertex AI Python SDK vulnerable to RCE via bucket squatting attacks
Google Vertex AI Python SDK. Affects users uploading models to Vertex AI. Vulnerability exploits bucket squatting during model upload process combined with pickle deserialization to achieve cross-tenant remote code execution.
criticalbug_reportVulnerabilityActive exploitation of critical FortiSandbox vulnerabilities
Fortinet FortiSandbox cyber threat detection platform. Specific versions not disclosed. No CVE assigned yet.
highbug_reportVulnerabilitySprySOCKS malware expands to Windows in government-targeted attacks
Government organizations in at least four countries. Windows systems now targeted alongside previously known Linux variants. Specific Windows versions and attack vector not disclosed.
highbug_reportVulnerabilityCisco Catalyst SD-WAN Manager under active exploit (CVE-2026-20262)
Cisco Catalyst SD-WAN Manager. Specific vulnerable versions not provided in summary. Affects web UI component accessible to authenticated remote users.
highbug_reportVulnerabilityCISA adds LiteSpeed cPanel Plugin privilege escalation to KEV catalog
LiteSpeed cPanel Plugin (specific versions not disclosed). Affects web hosting environments using cPanel with LiteSpeed integration. Federal agencies and hosting providers running this plugin are in scope.
highbug_reportVulnerabilitySimpleHelp OIDC flaw allows unauthenticated account creation
SimpleHelp remote management software servers with OpenID Connect (OIDC) authentication enabled. Specific affected versions not disclosed. All SimpleHelp deployments using OIDC for technician authentication are potentially vulnerable.
highbug_reportVulnerabilityAwesome Motive CDN breach compromises WordPress plugins in supply-chain attack
WordPress plugins OptinMonster, TrustPulse, and PushEngage distributed via Awesome Motive's CDN. All versions served through the compromised CDN infrastructure are potentially affected.
criticalbug_reportVulnerabilityCisco Catalyst SD-WAN Manager root privilege escalation under attack
Cisco Catalyst SD-WAN Manager (specific versions not provided). Vulnerability allows privilege escalation to root level on affected systems.
criticalbug_reportVulnerabilityLiteLLM AI gateway vulnerable to privilege escalation and RCE
LiteLLM open-source AI gateway. Specific affected versions not disclosed. Impacts organizations using LiteLLM to manage API keys and route requests to AI providers (OpenAI, Anthropic, etc.).
highbug_reportVulnerabilityMicrosoft 365 Copilot SearchLeak allows data exfiltration via trusted link
Microsoft 365 Copilot Enterprise Search. All organizations using M365 Copilot with Enterprise Search enabled are potentially affected. Specific version details not disclosed.
criticalbug_reportVulnerabilitySearchLeak in Microsoft 365 Copilot enables data theft via crafted URLs
Microsoft 365 Copilot Enterprise. All organizations using Copilot with access to mailbox, OneDrive, or SharePoint data are potentially affected. Specific vulnerable versions not disclosed.
highbug_reportVulnerabilityResponsive FileManager RCE via unrestricted file upload (CVE-2026-5482)
Responsive FileManager (versions not specified). The vulnerability affects file upload mechanisms allowing unrestricted file uploads leading to remote code execution.
highbug_reportVulnerabilityQuick.CMS deserialization flaw enables potential remote code execution
Quick.CMS software (specific versions not disclosed). Affects systems where untrusted data is deserialized without proper validation.
criticalbug_reportVulnerabilitySupply chain attack hits PushEngage, OptinMonster, TrustPulse plugins
WordPress sites using PushEngage, OptinMonster, and TrustPulse plugins. All versions loading compromised JavaScript files from vendor infrastructure are affected.
highbug_reportVulnerabilityMultiple high-severity vulnerabilities in GitLab CE and EE require patching
GitLab Community Edition (CE) and Enterprise Edition (EE). Specific affected versions not provided in advisory; typically affects versions prior to latest security release.
highbug_reportVulnerabilityPalo Alto PAN-OS GlobalProtect auth bypass under active exploitation
Palo Alto Networks PAN-OS GlobalProtect VPN portal and gateway components. Specific affected versions not disclosed in provided data. CVE-2026-0257, CVSS 7.8 (High).
criticalbug_reportVulnerabilitySplunk Enterprise RCE flaw allows unauthenticated remote code execution
Splunk Enterprise versions below 10.2.4 and 10.0.7. The vulnerability enables unauthenticated attackers to perform arbitrary file operations and achieve remote code execution. CVSS score 9.8 (Critical).
criticalbug_reportVulnerabilityArch User Repository supply chain attack: 400+ packages backdoored
Arch Linux users who installed or updated packages from the Arch User Repository (AUR) during the compromise window. Over 400 AUR packages contained malicious build scripts deploying a Rust-based infostealer.
highbug_reportVulnerability10-year-old phpBB auth bypass enables attacker login as any user
phpBB forum software, versions spanning approximately 10 years (specific affected versions not disclosed). All installations running unpatched versions are vulnerable.