Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
satellite_altDaily BriefCyber Threat Daily Brief — July 21, 2026
Today's briefing: 3 critical and 16 high-severity threats. A total of 23 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.
Latest Reports
28 / 606 results
criticalbug_reportVulnerabilityGogs Git service vulnerable to remote code execution, patch immediately
Gogs Git service (specific versions not disclosed in advisory). All internet-facing Gogs instances should be considered at risk until patched.
highbug_reportVulnerabilityAdblock for YouTube extension with 10M+ installs contains code injection risk
Chrome extension "Adblock for YouTube" (10+ million active installations). All users with the extension installed are potentially affected. Extension currently holds Featured badge status in Chrome Web Store.
highperson_alertThreat ActorKongTuke Deploys Mistic Backdoor in Multi-Sector Financial Attacks
KongTuke is an initial access broker (IAB) conducting financially motivated operations targeting organizations across insurance, education, IT, and professional services sectors.
highbug_reportVulnerabilityCisco Catalyst SD-WAN zero-day exploited in wild for two months
Cisco Catalyst SD-WAN Manager. Specific affected versions not disclosed. Requires authenticated local access for exploitation.
highperson_alertThreat ActorSnoopy Sentenced to 18 Months for DraftKings Account Compromise
Snoopy is a 21-year-old individual arrested and sentenced for unauthorized access to customer accounts on the DraftKings sports betting platform in November 2022.
criticalbug_reportVulnerabilityCisco Catalyst SD-WAN zero-day exploited for root access (CVE-2026-20245)
Cisco Catalyst SD-WAN devices. Specific affected versions not disclosed in available information. Attackers gain root-level access and can create persistent rogue accounts.
highperson_alertThreat ActorEdgecution: Malicious Edge Extension Enables Sandbox Escape
Edgecution is a malicious browser extension targeting Microsoft Edge, not a threat actor group. It functions as a tool deployed during ransomware operations to facilitate sandbox escape and establish persistence.
criticalbug_reportVulnerabilityCISA warns: Lantronix EDS5000 code injection under active exploit
Lantronix EDS5000 Series devices. Specific vulnerable firmware versions not disclosed in provided data. Critical code injection vulnerability (CVE-2025-67038, CVSS 9.8).
highperson_alertThreat ActorEuropol disrupts Amadey and StealC infrastructure, recovers 27M credentials
This report describes a law enforcement disruption operation led by Europol in partnership with private sector entities including Bitdefender, Bitsight, ESET, and Microsoft.
criticalbug_reportVulnerabilityCISA warns: Critical flaws in Ubiquiti UniFi OS and Lantronix exploited
Ubiquiti UniFi OS and Lantronix serial-to-ethernet servers. Specific affected versions not disclosed in summary. Both products commonly deployed in enterprise network infrastructure and IoT/OT environments.
highperson_alertThreat ActorEuropol-led Operation Endgame disrupts Amadey and StealC infrastructure
Europol is a law enforcement agency coordinating international cybercrime investigations. In this context, Europol led Operation Endgame, a coordinated law enforcement action involving Microsoft and international partners targeting cybercriminal infr…
criticalbug_reportVulnerabilityCI/CD flaw "Cordyceps" exposes 300+ GitHub repos to supply-chain takeover
300+ GitHub repositories across major organizations including Microsoft, Google, and Apache. Vulnerability affects GitHub Actions CI/CD workflows. Specific products and versions not disclosed in available data.
highbug_reportVulnerabilityMicrosoft DCU disrupts StealC and Amadey infostealer infrastructure
Organizations globally using Windows systems targeted by StealC and Amadey infostealer malware-as-a-service operations. Infrastructure takedown executed June 24, 2026.
highperson_alertThreat ActorKongTuke Deploys Mistic Backdoor in Multi-Sector Intrusions
KongTuke is a financially motivated threat actor operating as a ransomware access broker. The group specializes in gaining initial access to corporate networks and establishing persistent backdoor access, which is then sold or provided to ransomware…
highperson_alertThreat ActorU.S. seizes HuiOne Group assets, sanctions Prince Group entities
HuiOne Group and Prince Group are entities linked to cyber scam money laundering operations with infrastructure in Cambodia. HuiOne Group subsidiaries allegedly operated cloud computing infrastructure used to facilitate financial transactions related…
criticalbug_reportVulnerabilityCisco Unified CM critical flaw under active exploitation, root access risk
Cisco Unified Communications Manager (CUCM) and Unified CM SME. Specific affected versions not provided in available data. Vulnerability affects HTTP request handling with unauthenticated remote attack vector.
highbug_reportVulnerabilityMalicious AI skills in ClawHub marketplace evade scanners, deploy infostealers
ClawHub marketplace users consuming third-party AI skills. Specific affected products: OpenClaw and ClawHub platforms. Scope includes organizations deploying AI agents with marketplace-sourced skills that may contain evasive malware delivering infost…
highbug_reportVulnerabilityCisco Unified Communications Manager SSRF under active exploitation
Cisco Unified Communications Manager (CUCM). Specific affected versions not disclosed. SSRF vulnerability (CVE-2026-20230) allows attackers to force the server to make unauthorized requests to internal or external resources.
highpublicGeopoliticalTata Electronics confirms cyberattack and data leak on IT infrastructure
Tata Electronics, a subsidiary of India's Tata Group conglomerate, has confirmed a cyberattack that compromised portions of its IT infrastructure and resulted in data exfiltration.
highperson_alertThreat ActorClickFix Targets macOS with Terminal-Based Infostealer Campaign
ClickFix is a threat actor conducting social engineering campaigns that trick users into executing malicious commands. The actor leverages deceptive techniques to convince victims to manually run Terminal commands on macOS systems, facilitating the d…
criticalperson_alertThreat ActorFortiBleed: Russian IAB harvests 110M credentials from FortiGate devices
FortiBleed is attributed to a Russian-speaking initial access broker (IAB) conducting large-scale credential harvesting operations since February 2026. The actor demonstrates advanced operational capabilities through systematic targeting of over 430,…
highperson_alertThreat ActorScattered Spider Members Plead Guilty to Transport for London Attack
Scattered Spider (also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944 by various vendors) is a financially motivated cybercrime group known for sophisticated social engineering and identity-based attacks.
highperson_alertThreat ActorScattered Spider Members Plead Guilty to Transport for London Breach
Scattered Spider (G1015), also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944, is a financially motivated cybercrime group known for sophisticated social engineering and identity-based attacks.
highbug_reportVulnerabilityGitHub blocks pwn request attacks in actions/checkout starting June 2026
GitHub Actions workflows using actions/checkout with pull_request_target trigger. Organizations using GitHub Actions for CI/CD pipelines are affected. The security update applies to all repositories using the actions/checkout action after June 18, 20…
highbug_reportVulnerabilityLastPass breached via Klue supply chain attack; OAuth tokens stolen
LastPass customers. Attack vector: compromised Klue third-party service leading to OAuth token theft and unauthorized access to LastPass Salesforce environment containing customer data.
highbug_reportVulnerabilityTotolink EX1200L router vulnerable to stack buffer overflow (RCE)
Totolink EX1200L router software. Specific affected firmware versions not disclosed. Vulnerability is a stack-based buffer overflow enabling potential remote code execution.
highbug_reportVulnerabilityMalicious npm packages deliver Windows RAT to JavaScript developers
Three npm packages (aes-decode-runner-pro, postcss-minify-selector, postcss-minify-selector-parser) published within the past month. Total downloads: 145-615 per package. Affects Windows-based development environments using npm package manager.
highperson_alertThreat ActorWhatsApp VBScript Campaign Deploys ManageEngine RMM Across 9 Countries
This campaign represents an unattributed threat activity leveraging WhatsApp as an initial access vector. The actor's motivation appears to be establishing persistent remote access to victim systems through legitimate remote monitoring and management…