Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-21 · 02:09 UTC
articleTotal: 606 reports
Cyber Threat Daily Brief — July 21, 2026satellite_altDaily Brief
Threat Intel Brief·Daily Summary

Cyber Threat Daily Brief — July 21, 2026

Today's briefing: 3 critical and 16 high-severity threats. A total of 23 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.

3 Critical16 High23 analyses
schedule02:09 UTC
Read briefarrow_forward

Latest Reports

28 / 606 results
Gogs Git service vulnerable to remote code execution, patch immediatelycriticalbug_reportVulnerability
bug_reportVulnerability

Gogs Git service vulnerable to remote code execution, patch immediately

Gogs Git service (specific versions not disclosed in advisory). All internet-facing Gogs instances should be considered at risk until patched.

Gogs12:55 UTC
Adblock for YouTube extension with 10M+ installs contains code injection riskhighbug_reportVulnerability
bug_reportVulnerability

Adblock for YouTube extension with 10M+ installs contains code injection risk

Chrome extension "Adblock for YouTube" (10+ million active installations). All users with the extension installed are potentially affected. Extension currently holds Featured badge status in Chrome Web Store.

Google12:12 UTC
KongTuke Deploys Mistic Backdoor in Multi-Sector Financial Attackshighperson_alertThreat Actor
person_alertThreat Actor

KongTuke Deploys Mistic Backdoor in Multi-Sector Financial Attacks

KongTuke is an initial access broker (IAB) conducting financially motivated operations targeting organizations across insurance, education, IT, and professional services sectors.

The Hacker News06:54 UTC
Cisco Catalyst SD-WAN zero-day exploited in wild for two monthshighbug_reportVulnerability
bug_reportVulnerability

Cisco Catalyst SD-WAN zero-day exploited in wild for two months

Cisco Catalyst SD-WAN Manager. Specific affected versions not disclosed. Requires authenticated local access for exploitation.

CVE-2026-2024503:46 UTC
Snoopy Sentenced to 18 Months for DraftKings Account Compromisehighperson_alertThreat Actor
person_alertThreat Actor

Snoopy Sentenced to 18 Months for DraftKings Account Compromise

Snoopy is a 21-year-old individual arrested and sentenced for unauthorized access to customer accounts on the DraftKings sports betting platform in November 2022.

DraftKings19:55 UTC
Cisco Catalyst SD-WAN zero-day exploited for root access (CVE-2026-20245)criticalbug_reportVulnerability
bug_reportVulnerability

Cisco Catalyst SD-WAN zero-day exploited for root access (CVE-2026-20245)

Cisco Catalyst SD-WAN devices. Specific affected versions not disclosed in available information. Attackers gain root-level access and can create persistent rogue accounts.

CVE-2026-2024519:29 UTC
Edgecution: Malicious Edge Extension Enables Sandbox Escapehighperson_alertThreat Actor
person_alertThreat Actor

Edgecution: Malicious Edge Extension Enables Sandbox Escape

Edgecution is a malicious browser extension targeting Microsoft Edge, not a threat actor group. It functions as a tool deployed during ransomware operations to facilitate sandbox escape and establish persistence.

Microsoft18:58 UTC
CISA warns: Lantronix EDS5000 code injection under active exploitcriticalbug_reportVulnerability
bug_reportVulnerability

CISA warns: Lantronix EDS5000 code injection under active exploit

Lantronix EDS5000 Series devices. Specific vulnerable firmware versions not disclosed in provided data. Critical code injection vulnerability (CVE-2025-67038, CVSS 9.8).

CVE-2025-6703815:19 UTC
Europol disrupts Amadey and StealC infrastructure, recovers 27M credentialshighperson_alertThreat Actor
person_alertThreat Actor

Europol disrupts Amadey and StealC infrastructure, recovers 27M credentials

This report describes a law enforcement disruption operation led by Europol in partnership with private sector entities including Bitdefender, Bitsight, ESET, and Microsoft.

Bitdefender13:59 UTC
CISA warns: Critical flaws in Ubiquiti UniFi OS and Lantronix exploitedcriticalbug_reportVulnerability
bug_reportVulnerability

CISA warns: Critical flaws in Ubiquiti UniFi OS and Lantronix exploited

Ubiquiti UniFi OS and Lantronix serial-to-ethernet servers. Specific affected versions not disclosed in summary. Both products commonly deployed in enterprise network infrastructure and IoT/OT environments.

Ubiquiti12:35 UTC
Europol-led Operation Endgame disrupts Amadey and StealC infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

Europol-led Operation Endgame disrupts Amadey and StealC infrastructure

Europol is a law enforcement agency coordinating international cybercrime investigations. In this context, Europol led Operation Endgame, a coordinated law enforcement action involving Microsoft and international partners targeting cybercriminal infr…

Microsoft12:35 UTC
CI/CD flaw "Cordyceps" exposes 300+ GitHub repos to supply-chain takeovercriticalbug_reportVulnerability
bug_reportVulnerability

CI/CD flaw "Cordyceps" exposes 300+ GitHub repos to supply-chain takeover

300+ GitHub repositories across major organizations including Microsoft, Google, and Apache. Vulnerability affects GitHub Actions CI/CD workflows. Specific products and versions not disclosed in available data.

Microsoft10:48 UTC
Microsoft DCU disrupts StealC and Amadey infostealer infrastructurehighbug_reportVulnerability
bug_reportVulnerability

Microsoft DCU disrupts StealC and Amadey infostealer infrastructure

Organizations globally using Windows systems targeted by StealC and Amadey infostealer malware-as-a-service operations. Infrastructure takedown executed June 24, 2026.

Microsoft10:30 UTC
KongTuke Deploys Mistic Backdoor in Multi-Sector Intrusionshighperson_alertThreat Actor
person_alertThreat Actor

KongTuke Deploys Mistic Backdoor in Multi-Sector Intrusions

KongTuke is a financially motivated threat actor operating as a ransomware access broker. The group specializes in gaining initial access to corporate networks and establishing persistent backdoor access, which is then sold or provided to ransomware…

BleepingComputer08:41 UTC
U.S. seizes HuiOne Group assets, sanctions Prince Group entitieshighperson_alertThreat Actor
person_alertThreat Actor

U.S. seizes HuiOne Group assets, sanctions Prince Group entities

HuiOne Group and Prince Group are entities linked to cyber scam money laundering operations with infrastructure in Cambodia. HuiOne Group subsidiaries allegedly operated cloud computing infrastructure used to facilitate financial transactions related…

Huione Cloud06:55 UTC
Cisco Unified CM critical flaw under active exploitation, root access riskcriticalbug_reportVulnerability
bug_reportVulnerability

Cisco Unified CM critical flaw under active exploitation, root access risk

Cisco Unified Communications Manager (CUCM) and Unified CM SME. Specific affected versions not provided in available data. Vulnerability affects HTTP request handling with unauthenticated remote attack vector.

CVE-2026-2023004:50 UTC
Malicious AI skills in ClawHub marketplace evade scanners, deploy infostealershighbug_reportVulnerability
bug_reportVulnerability

Malicious AI skills in ClawHub marketplace evade scanners, deploy infostealers

ClawHub marketplace users consuming third-party AI skills. Specific affected products: OpenClaw and ClawHub platforms. Scope includes organizations deploying AI agents with marketplace-sourced skills that may contain evasive malware delivering infost…

OpenClaw, ClawHub20:00 UTC
Cisco Unified Communications Manager SSRF under active exploitationhighbug_reportVulnerability
bug_reportVulnerability

Cisco Unified Communications Manager SSRF under active exploitation

Cisco Unified Communications Manager (CUCM). Specific affected versions not disclosed. SSRF vulnerability (CVE-2026-20230) allows attackers to force the server to make unauthorized requests to internal or external resources.

CVE-2026-2023019:48 UTC
Tata Electronics confirms cyberattack and data leak on IT infrastructurehighpublicGeopolitical
publicGeopolitical

Tata Electronics confirms cyberattack and data leak on IT infrastructure

Tata Electronics, a subsidiary of India's Tata Group conglomerate, has confirmed a cyberattack that compromised portions of its IT infrastructure and resulted in data exfiltration.

Tata Electronics19:06 UTC
ClickFix Targets macOS with Terminal-Based Infostealer Campaignhighperson_alertThreat Actor
person_alertThreat Actor

ClickFix Targets macOS with Terminal-Based Infostealer Campaign

ClickFix is a threat actor conducting social engineering campaigns that trick users into executing malicious commands. The actor leverages deceptive techniques to convince victims to manually run Terminal commands on macOS systems, facilitating the d…

Apple16:30 UTC
FortiBleed: Russian IAB harvests 110M credentials from FortiGate devicescriticalperson_alertThreat Actor
person_alertThreat Actor

FortiBleed: Russian IAB harvests 110M credentials from FortiGate devices

FortiBleed is attributed to a Russian-speaking initial access broker (IAB) conducting large-scale credential harvesting operations since February 2026. The actor demonstrates advanced operational capabilities through systematic targeting of over 430,…

Fortinet16:20 UTC
Scattered Spider Members Plead Guilty to Transport for London Attackhighperson_alertThreat Actor
person_alertThreat Actor

Scattered Spider Members Plead Guilty to Transport for London Attack

Scattered Spider (also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944 by various vendors) is a financially motivated cybercrime group known for sophisticated social engineering and identity-based attacks.

Transport for London14:12 UTC
Scattered Spider Members Plead Guilty to Transport for London Breachhighperson_alertThreat Actor
person_alertThreat Actor

Scattered Spider Members Plead Guilty to Transport for London Breach

Scattered Spider (G1015), also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944, is a financially motivated cybercrime group known for sophisticated social engineering and identity-based attacks.

Transport for London13:31 UTC
GitHub blocks pwn request attacks in actions/checkout starting June 2026highbug_reportVulnerability
bug_reportVulnerability

GitHub blocks pwn request attacks in actions/checkout starting June 2026

GitHub Actions workflows using actions/checkout with pull_request_target trigger. Organizations using GitHub Actions for CI/CD pipelines are affected. The security update applies to all repositories using the actions/checkout action after June 18, 20…

GitHub12:22 UTC
LastPass breached via Klue supply chain attack; OAuth tokens stolenhighbug_reportVulnerability
bug_reportVulnerability

LastPass breached via Klue supply chain attack; OAuth tokens stolen

LastPass customers. Attack vector: compromised Klue third-party service leading to OAuth token theft and unauthorized access to LastPass Salesforce environment containing customer data.

LastPass11:58 UTC
Totolink EX1200L router vulnerable to stack buffer overflow (RCE)highbug_reportVulnerability
bug_reportVulnerability

Totolink EX1200L router vulnerable to stack buffer overflow (RCE)

Totolink EX1200L router software. Specific affected firmware versions not disclosed. Vulnerability is a stack-based buffer overflow enabling potential remote code execution.

CVE-2026-4408908:55 UTC
Malicious npm packages deliver Windows RAT to JavaScript developershighbug_reportVulnerability
bug_reportVulnerability

Malicious npm packages deliver Windows RAT to JavaScript developers

Three npm packages (aes-decode-runner-pro, postcss-minify-selector, postcss-minify-selector-parser) published within the past month. Total downloads: 145-615 per package. Affects Windows-based development environments using npm package manager.

npm06:54 UTC
WhatsApp VBScript Campaign Deploys ManageEngine RMM Across 9 Countrieshighperson_alertThreat Actor
person_alertThreat Actor

WhatsApp VBScript Campaign Deploys ManageEngine RMM Across 9 Countries

This campaign represents an unattributed threat activity leveraging WhatsApp as an initial access vector. The actor's motivation appears to be establishing persistent remote access to victim systems through legitimate remote monitoring and management…

WhatsApp03:38 UTC