Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
satellite_altDaily BriefCyber Threat Daily Brief — September 4, 2026
Today's briefing: 14 critical and 22 high-severity threats. A total of 47 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.
Latest Reports
26 / 1136 results
highperson_alertThreat ActorCity Forum campaign scrapes Salesforce and ServiceNow portals
City Forum is a campaign name assigned by Reco to a coordinated data harvesting operation targeting enterprise SaaS platforms. The activity is attributed to a single attacker infrastructure operating from IP address 158.220.87.79, hosted on a Contabo…
highperson_alertThreat ActorStubMaker Campaign Deploys 16 Typosquatted RubyGems to Steal Credentials
StubMaker is a typosquatting campaign tracked by OpenSourceMalware researchers, discovered on August 15, 2026. The campaign operators published 16 malicious RubyGems packages under user accounts "mod8rz41mje" (Riley Miller) and "rbq95bwt6q" (Alex Dav…
highperson_alertThreat ActorCVE-2025-60710: Windows Task Host Flaw Exploited by Ransomware Gangs
No specific threat actor or ransomware gang has been publicly attributed to the exploitation of CVE-2025-60710. CISA confirmed that multiple ransomware operators are actively exploiting this vulnerability in the wild as of August 2026.
criticalbug_reportVulnerabilityRay framework CVE-2025-62593 exploited via DNS rebinding for browser RCE
Ray open-source Python distributed computing framework, versions prior to 2.52.0. Primarily affects developers running development/testing environments. Over 43,500 GitHub stars indicate wide adoption in AI/ML workflows.
criticalbug_reportVulnerabilityCritical GitLab GraphQL flaw allows unauthenticated project deletion
GitLab Community Edition (CE) and Enterprise Edition (EE) self-managed installations: all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4.
highpublicGeopoliticalCEVA Logistics breach exposes Pokémon Center customer data in EU
This incident exemplifies the systemic vulnerabilities inherent in globalized supply chain networks, where third-party logistics providers serve as critical nodes connecting consumer-facing platforms with physical distribution infrastructure.
highbug_reportVulnerabilitySnowflake GitHub Actions workflow injection exposed Jira credentials
Snowflake's snowflakedb/snowflake-connector-net GitHub repository, specifically the .github/workflows/jira_issue.yml workflow. Vulnerable code was present on the default branch from June 18–23, 2026 (5-day window).
criticalbug_reportVulnerabilityForminator WordPress plugin RCE affects 600K+ sites via file upload bypass
Forminator Forms WordPress plugin versions ≤1.56.1. Affects 600,000+ active installations. Exploitation requires a form with both File Upload and Select fields. Sites using custom file upload storage paths are at higher risk.
highperson_alertThreat ActorIranian Cavern C2 Framework Evolves with DNS and Google Apps Script Relay
Cavern (aka Cav3rn) is a command-and-control framework attributed to Iranian nation-state threat actors, specifically linked to Cavern Manticore, a hacking group affiliated with Iran's Ministry of Intelligence and Security (MOIS).
criticalbug_reportVulnerabilityGeoServer zero-day SQL injection under active exploitation
GeoServer (specific versions not disclosed in advisory). All unpatched instances potentially vulnerable to SQL injection attacks.
criticalbug_reportVulnerabilityCertighost (CVE-2026-54121): Domain user can escalate to DC via CA
Microsoft Active Directory Certificate Services (AD CS) in Enterprise CA configurations. All versions prior to July 14, 2026 patch. Affects organizations with default AD settings including MachineAccountQuota allowing machine account creation by stan…
highbug_reportVulnerabilityIvanti EPM high severity flaws require immediate patching
Ivanti Endpoint Manager (EPM). Specific affected versions not disclosed in available advisory. CVE identifiers not yet assigned or published.
highperson_alertThreat ActorClop Ransomware Gang Exploits PTC Windchill Flaw to Breach GE, Philips
Clop is a financially motivated ransomware and extortion gang with a well-established history of exploiting zero-day and n-day vulnerabilities in enterprise file-sharing and product lifecycle management (PLM) platforms to conduct mass data theft camp…
criticalbug_reportVulnerabilityUnisoc modem flaw enables Android kernel takeover via VoLTE video call
Unisoc chipsets T606, T612, and T7250 used in Motorola E13, Realme C33, and Xiaomi Redmi A5. Devices with these chipsets sold across 140+ countries. Confirmed vulnerable on Motorola E13 (February 2025 patch) and Xiaomi Redmi A5 (January 2026 patch).
highpublicGeopoliticalFrench tax authority breach exposes 678,000 records amid rising attacks
The breach of France's General Directorate of Public Finances (DGFiP) represents the latest in a sustained pattern of cyberattacks targeting French government infrastructure throughout 2026.
criticalbug_reportVulnerabilityIBM i systems face critical vulnerabilities requiring immediate patching
IBM i systems (formerly AS/400). Specific versions and CVE identifiers not disclosed in advisory. Scope appears to be multiple severe vulnerabilities across the platform.
highbug_reportVulnerabilityEvooo1Bot botnet exploits 18 CVEs to turn edge devices into SOCKS5 proxies
Internet-facing Linux-based edge devices including routers (NETGEAR, Tenda, D-Link, TP-Link, Zyxel), IP cameras (Hikvision), enterprise appliances (Alcatel OmniPCX, Mitsubishi ME-RTU, Telesquare SDT-CW3B1/TLR-2005KSH), and servers running vulnerable…
criticalbug_reportVulnerabilityAdobe Commerce critical vulnerability under active exploitation
Adobe Commerce (formerly Magento). Specific affected versions not disclosed in advisory. All unpatched instances should be considered at risk.
highbug_reportVulnerabilityMicrosoft Defender ShieldBreak zero-day grants SYSTEM privileges on Windows
Microsoft Defender on Windows 10, Windows 11 (including 25H2 and Canary), and Windows Server 2025. All fully patched systems with Defender enabled are vulnerable.
criticalperson_alertThreat ActorChina-Nexus APT Exploits VMware vCenter Flaws, Deploys Babuk Ransomware
A suspected China-nexus advanced persistent threat actor, assessed with moderate confidence by QUIRSO to be Chinese-speaking and operating in the UTC+08:00 time zone.
highbug_reportVulnerabilityLarge-scale DDoS campaign disrupts Threema encrypted messaging service
Threema secure messaging service (cloud-hosted instances). Users in Switzerland, India, and China reported outages. Threema On-Prem customers unaffected as they use independent infrastructure. Colocation partner Nine also targeted.
highbug_reportVulnerabilityAmnesiaStealer malware hijacks macOS browser sessions via live remote control
macOS users targeted via ClickFix campaigns using fake GitHub pages. Affects 16 Chromium-based browsers including Chrome, Edge, Brave, Opera, Vivaldi, Arc, and Chromium.
highbug_reportVulnerabilityEvooo1Bot: Mirai-based botnet targets Linux gateways as SOCKS5 proxies
Internet-facing Linux gateway devices (routers, firewalls, edge appliances). Specific vendors and models not disclosed. Mirai-based malware with modular architecture targeting devices with weak credentials or known vulnerabilities.
criticalbug_reportVulnerabilitySAP Commerce Cloud CVE-2026-58231 under active exploit, 3 days post-patch
SAP Commerce Cloud, all versions prior to patched release levels. Vulnerability affects default authentication clients and endpoints lacking input validation. Unauthenticated remote exploitation possible.
highperson_alertThreat Actor€30M Bank Fraud via Service Provider Exploit Targets Commerzbank
An unknown cybercriminal group, financially motivated, conducted a coordinated bank fraud operation targeting Commerzbank customers. The group operated across multiple jurisdictions, with four members arrested in Brazil and three charged in Europe.
highbug_reportVulnerabilitymacOS Screen Sharing auth bypass exploited to deploy Monero miners
macOS Screen Sharing feature on systems with TCP port 5900 exposed to the internet. Fixed in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. CVE-2026-65400 affects earlier versions of these releases.