Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 675 results
Active filter:✕ clear
Zoom annotation tool flaws enabled zero-click client hijackingcriticalbug_reportVulnerability
bug_reportVulnerability

Zoom annotation tool flaws enabled zero-click client hijacking

Zoom Workplace (all platforms) before 7.1.5 and 7.0.6; Zoom Workplace VDI Client for Windows before 7.0.11 and 6.6.16; Zoom Rooms and Zoom Meeting SDK (all platforms) before 7.1.0 and 7.1.5. Affects both screen sharers and meeting viewers.

Zoom11 Aug · 17:08 UTC
Microsoft patches 400 flaws including 3 zero-days, one exploited by Lazaruscriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft patches 400 flaws including 3 zero-days, one exploited by Lazarus

All supported Windows versions (Windows 10, Windows 11). Three zero-day vulnerabilities: CVE-2026-68820 (Windows AFD.sys driver, actively exploited by Lazarus APT), CVE-2026-62832 (Windows User Profile Service, publicly disclosed as "LegacyHive"), an…

Microsoft11 Aug · 16:08 UTC
SharePoint Server auth bypass chained to RCE, no credentials requiredcriticalbug_reportVulnerability
bug_reportVulnerability

SharePoint Server auth bypass chained to RCE, no credentials required

Microsoft SharePoint Server Subscription Edition, 2019, and 2016 (CVE-2026-55040, CVSS 9.1). Chained RCE flaw CVE-2026-63520 (CVSS 8.1) also affects Project Server 2013 SP1 and Office Web Apps 2013 SP1. SharePoint Online is not affected.

CVE-2026-5504011 Aug · 14:47 UTC
Malicious SIM cards can execute code on IoT cellular modules via RUN AThighbug_reportVulnerability
bug_reportVulnerability

Malicious SIM cards can execute code on IoT cellular modules via RUN AT

Cellular IoT modules (6 of 8 tested, primarily Quectel parts with Qualcomm processors) in EV chargers, industrial routers, car telematics units. Limited phone impact: OPPO Find X5, OPPO Reno 14 F 5G, ASUS Zenfone 9.

The Hacker News11 Aug · 10:05 UTC
Mozilla revokes Firefox/Thunderbird Linux signing key after repo exposurehighbug_reportVulnerability
bug_reportVulnerability

Mozilla revokes Firefox/Thunderbird Linux signing key after repo exposure

Mozilla Firefox and Thunderbird Linux downloads (all versions signed with subkey 09BE ED63 F346 2A2D FFAB 3B87 5ECB 6497 C1A2 0256 from April 2025 to August 2026).

Mozilla11 Aug · 10:04 UTC
Kimwolf v7 botnet targets Android IoT with HTTP/2 DDoS, ENS C2 resolutionhighbug_reportVulnerability
bug_reportVulnerability

Kimwolf v7 botnet targets Android IoT with HTTP/2 DDoS, ENS C2 resolution

Android TV boxes and set-top boxes with unauthenticated Android Debug Bridge (ADB) exposed on port 5555. Primarily affects devices accessible via residential proxy services. ARM-based Android IoT devices running vulnerable configurations.

Unit 42 (Palo Alto)11 Aug · 08:00 UTC
Aeternum botnet uses Polygon blockchain for decentralized C2 infrastructurehighbug_reportVulnerability
bug_reportVulnerability

Aeternum botnet uses Polygon blockchain for decentralized C2 infrastructure

Windows systems infected with Aeternum C++ botnet loader (Build.exe). The malware targets Windows environments and uses Polygon blockchain smart contracts for command and control, making traditional domain/IP-based blocking ineffective.

Unit 42 (Palo Alto)10 Aug · 20:00 UTC
BdThemes WordPress plugins compromised to create rogue admin accountshighbug_reportVulnerability
bug_reportVulnerability

BdThemes WordPress plugins compromised to create rogue admin accounts

BdThemes WordPress plugins including Element Pack (100,000+ active installs), Prime Slider, Ultimate Post Kit, Pixel Gallery, and Ultimate Store Kit. All versions using the vulnerable Biggop Library introduced in March 2026.

BdThemes10 Aug · 19:12 UTC
Critical SQL injection in Metabase requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical SQL injection in Metabase requires immediate patching

Metabase (specific affected versions not disclosed in advisory). SQL injection vulnerability impacts database query functionality.

Metabase10 Aug · 12:40 UTC
Passkey bypass attacks target Windows, Chrome, and Entra ID implementationshighbug_reportVulnerability
bug_reportVulnerability

Passkey bypass attacks target Windows, Chrome, and Entra ID implementations

Microsoft Windows 10, Windows 11, Windows Server (CVE-2026-34348); Microsoft Entra ID passkey validation; Google Password Manager synced passkeys in Chrome on Windows; Windows Hello for Business.

Microsoft10 Aug · 10:25 UTC
LexisNexis shuts down services after suspicious third-party vendor breachhighbug_reportVulnerability
bug_reportVulnerability

LexisNexis shuts down services after suspicious third-party vendor breach

LexisNexis Diligence, Metabase API, and Newsdesk services. Incident stems from compromise of unnamed third-party vendor's servers hosting these platforms.

LexisNexis10 Aug · 10:11 UTC
Heap overflow in entr file watcher allows local DoS via argument overflowhighbug_reportVulnerability
bug_reportVulnerability

Heap overflow in entr file watcher allows local DoS via argument overflow

eradman entr versions through 5.8. entr is a command-line utility that runs arbitrary commands when files change. All versions up to and including 5.8 are vulnerable.

CVE-2026-1837010 Aug · 09:55 UTC
Progress Kemp LoadMaster command injection flaw exploited in the wildcriticalbug_reportVulnerability
bug_reportVulnerability

Progress Kemp LoadMaster command injection flaw exploited in the wild

Progress Kemp LoadMaster GA v7.2.63.1 and older, LTSF v7.2.54.17 and older; MOVEit WAF all versions before GA v7.2.63.2. Approximately 300 instances exposed online. Used by Fortune 500 companies and government agencies including Amazon and U.S.

Progress10 Aug · 07:49 UTC
Malicious VS Code extensions steal crypto wallets and credentials from devshighbug_reportVulnerability
bug_reportVulnerability

Malicious VS Code extensions steal crypto wallets and credentials from devs

Microsoft Visual Studio Code users who installed "Solidity Pro" extensions (helper-beeps.solidity-pro or web3devtoolsx.solidity-pro) from Open VSX marketplace. Extensions targeted Ethereum/Web3 developers.

Microsoft10 Aug · 05:38 UTC
Head Mare hacktivists backdoor TrueConf installers via server compromisecriticalbug_reportVulnerability
bug_reportVulnerability

Head Mare hacktivists backdoor TrueConf installers via server compromise

TrueConf video conferencing servers (unpatched versions) and client installers distributed from compromised servers. Specific vulnerable versions not disclosed. Affects organizations using TrueConf for video conferencing.

TrueConf8 Aug · 12:16 UTC
Atlassian Rovo prompt injection enables data exfiltration from Jira/Confluencehighbug_reportVulnerability
bug_reportVulnerability

Atlassian Rovo prompt injection enables data exfiltration from Jira/Confluence

Atlassian Rovo assistant on Standard, Premium, and Enterprise plans. Affects organizations with Rovo enabled (default setting). Exploitable by authenticated users who interact with attacker-controlled content (documents) or links (rovoChatPrompt para…

Atlassian8 Aug · 06:54 UTC
CSS attacks bypass webmail sanitizers to steal passwords and tokenshighbug_reportVulnerability
bug_reportVulnerability

CSS attacks bypass webmail sanitizers to steal passwords and tokens

Microsoft Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail webmail interfaces. Attacks exploit CSS and HTML parsing discrepancies to escape message boundaries.

Microsoft8 Aug · 06:03 UTC
Metabase zero-day (CVSS 10.0) exploited for unauthenticated admin accesscriticalbug_reportVulnerability
bug_reportVulnerability

Metabase zero-day (CVSS 10.0) exploited for unauthenticated admin access

Metabase versions 1.58.0 through 1.63.2 (all self-hosted and cloud instances). Specifically: 1.58.0–1.58.23, 1.59.0–1.59.20, 1.60.0–1.60.16, 1.61.0–1.61.10, 1.62.0–1.62.8, and 1.63.0–1.63.2. Metabase Cloud instances already patched.

Metabase8 Aug · 04:58 UTC
N-able N-central exploited; attackers persist via Cloudflare tunnelscriticalbug_reportVulnerability
bug_reportVulnerability

N-able N-central exploited; attackers persist via Cloudflare tunnels

N-able N-central RMM product, all versions prior to 2026.3.1.7. CVE-2026-18577 (CVSS 8.2) is an incomplete fix for CVE-2026-18556 (CVSS 8.2), both enabling authentication bypass and account takeover. On-premise deployments are affected.

N-able8 Aug · 04:57 UTC
Progress Kemp LoadMaster command injection (CVE-2026-8037) exploitedcriticalbug_reportVulnerability
bug_reportVulnerability

Progress Kemp LoadMaster command injection (CVE-2026-8037) exploited

Progress Kemp LoadMaster appliances. All versions with vulnerable escape_quotes() function. Unauthenticated remote attack vector.

CVE-2026-80378 Aug · 04:52 UTC
Metabase SQL injection zero-day exploited to steal customer datacriticalbug_reportVulnerability
bug_reportVulnerability

Metabase SQL injection zero-day exploited to steal customer data

Metabase (specific versions not disclosed). Confirmed victims include Framework and Tally customer instances. All unpatched Metabase deployments potentially at risk.

Metabase7 Aug · 18:14 UTC
Nearly 800 malicious npm packages deliver cross-platform RAT via typosquattingcriticalbug_reportVulnerability
bug_reportVulnerability

Nearly 800 malicious npm packages deliver cross-platform RAT via typosquatting

npm registry: ~800 packages using typosquatting and AI-generated names. Targets all Node.js developers on Windows, macOS (x64/ARM64), and Linux (x64/ARM64). Delivers WEL1DROPPER leading to Sliver C2 framework and platform-specific infostealers.

npm7 Aug · 16:48 UTC
ClickFix attacks deliver macOS stealer targeting crypto wallets and Keychainhighbug_reportVulnerability
bug_reportVulnerability

ClickFix attacks deliver macOS stealer targeting crypto wallets and Keychain

macOS systems (all CPU architectures). Users tricked into pasting malicious commands into Terminal. Targets cryptocurrency wallets (Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, XRP), browser passwords, Apple iCloud Keychain, and cached credentials.

Apple7 Aug · 16:29 UTC
KVM VM escape vulnerabilities require immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

KVM VM escape vulnerabilities require immediate patching

KVM (Kernel-based Virtual Machine) hypervisor. Specific affected versions not disclosed in advisory. Impacts organizations running KVM-based virtualization infrastructure on Linux hosts.

KVM7 Aug · 12:02 UTC
Two H1 2026 campaigns use compromised email and clipboard hijackinghighbug_reportVulnerability
bug_reportVulnerability

Two H1 2026 campaigns use compromised email and clipboard hijacking

Campaign 1: Users in Czechia, Slovakia, Poland, and Lithuania targeted by GepyS banking malware via compromised corporate email accounts. Campaign 2: Cryptocurrency users globally affected by Rust-based clipboard hijacker monitoring 21 blockchain typ…

BleepingComputer7 Aug · 12:00 UTC
WordPress pre-auth XSS on login page enables RCE via admin interactionhighbug_reportVulnerability
bug_reportVulnerability

WordPress pre-auth XSS on login page enables RCE via admin interaction

WordPress CMS all versions prior to 7.0.3. Patches backported to 4.7 branch and newer. Versions older than 4.7 remain vulnerable and unpatched. Default installations affected; no special hosting configuration required.

CVE-2026-646387 Aug · 10:56 UTC
18-year-old Linux SCTP flaw enables local root and container escapecriticalbug_reportVulnerability
bug_reportVulnerability

18-year-old Linux SCTP flaw enables local root and container escape

Linux kernel versions since 2.6.25 (2008) through 7.1.5, 6.18.41, 6.12.100, and 6.6.147. Affects systems with SCTP networking enabled. Confirmed vulnerable: Debian 13, Ubuntu 24.04, Rocky Linux 9, RHEL 9, OpenCloudOS.

Linux7 Aug · 09:10 UTC
NatJack attacks hijack TCP sessions via NAT manipulation; Windows & Linux CVEshighbug_reportVulnerability
bug_reportVulnerability

NatJack attacks hijack TCP sessions via NAT manipulation; Windows & Linux CVEs

Windows NAT (Hyper-V): Windows 11 24H2 <26100.8875, 25H2 <26200.8875, 26H1 <28000.2525, Server 2025 <26100.33158 (CVE-2026-56181, CVSS 8.3). Linux Netfilter conntrack: kernel <5.10.259, <5.15.210, <6.1.176, <6.6.143, <6.12.93, <6.18.35, <7.0.12, <7.1…

Microsoft7 Aug · 08:58 UTC
AitM phishing campaign targets Microsoft 365 for payroll email thefthighbug_reportVulnerability
bug_reportVulnerability

AitM phishing campaign targets Microsoft 365 for payroll email theft

Microsoft 365 accounts across healthcare, education, manufacturing, government, and professional services sectors in the U.S., Canada, and Europe. Hundreds of organizations targeted in July 2026, with focus on payroll, HR, and finance personnel.

Microsoft7 Aug · 08:38 UTC
AI system finds HTTP desync techniques; Apache Traffic Server zero-day patchedhighbug_reportVulnerability
bug_reportVulnerability

AI system finds HTTP desync techniques; Apache Traffic Server zero-day patched

Apache Traffic Server (CVE-2026-63078, specific versions unknown); 700+ websites vulnerable to HTTP desynchronization including banks, government infrastructure, security products, and airports.

Apache7 Aug · 08:09 UTC