Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports
Cyber Threat Daily Brief — September 4, 2026satellite_altDaily Brief
Threat Intel Brief·Daily Summary

Cyber Threat Daily Brief — September 4, 2026

Today's briefing: 14 critical and 22 high-severity threats. A total of 47 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.

14 Critical22 High47 analyses
schedule02:17 UTC
Read briefarrow_forward

Latest Reports

26 / 1136 results
City Forum campaign scrapes Salesforce and ServiceNow portalshighperson_alertThreat Actor
person_alertThreat Actor

City Forum campaign scrapes Salesforce and ServiceNow portals

City Forum is a campaign name assigned by Reco to a coordinated data harvesting operation targeting enterprise SaaS platforms. The activity is attributed to a single attacker infrastructure operating from IP address 158.220.87.79, hosted on a Contabo…

Salesforce18 Aug · 09:30 UTC
StubMaker Campaign Deploys 16 Typosquatted RubyGems to Steal Credentialshighperson_alertThreat Actor
person_alertThreat Actor

StubMaker Campaign Deploys 16 Typosquatted RubyGems to Steal Credentials

StubMaker is a typosquatting campaign tracked by OpenSourceMalware researchers, discovered on August 15, 2026. The campaign operators published 16 malicious RubyGems packages under user accounts "mod8rz41mje" (Riley Miller) and "rbq95bwt6q" (Alex Dav…

RubyGems18 Aug · 09:20 UTC
CVE-2025-60710: Windows Task Host Flaw Exploited by Ransomware Gangshighperson_alertThreat Actor
person_alertThreat Actor

CVE-2025-60710: Windows Task Host Flaw Exploited by Ransomware Gangs

No specific threat actor or ransomware gang has been publicly attributed to the exploitation of CVE-2025-60710. CISA confirmed that multiple ransomware operators are actively exploiting this vulnerability in the wild as of August 2026.

Microsoft18 Aug · 08:32 UTC
Ray framework CVE-2025-62593 exploited via DNS rebinding for browser RCEcriticalbug_reportVulnerability
bug_reportVulnerability

Ray framework CVE-2025-62593 exploited via DNS rebinding for browser RCE

Ray open-source Python distributed computing framework, versions prior to 2.52.0. Primarily affects developers running development/testing environments. Over 43,500 GitHub stars indicate wide adoption in AI/ML workflows.

Ray18 Aug · 04:34 UTC
Critical GitLab GraphQL flaw allows unauthenticated project deletioncriticalbug_reportVulnerability
bug_reportVulnerability

Critical GitLab GraphQL flaw allows unauthenticated project deletion

GitLab Community Edition (CE) and Enterprise Edition (EE) self-managed installations: all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4.

CVE-2026-1947817 Aug · 19:03 UTC
CEVA Logistics breach exposes Pokémon Center customer data in EUhighpublicGeopolitical
publicGeopolitical

CEVA Logistics breach exposes Pokémon Center customer data in EU

This incident exemplifies the systemic vulnerabilities inherent in globalized supply chain networks, where third-party logistics providers serve as critical nodes connecting consumer-facing platforms with physical distribution infrastructure.

Pokémon Center17 Aug · 17:12 UTC
Snowflake GitHub Actions workflow injection exposed Jira credentialshighbug_reportVulnerability
bug_reportVulnerability

Snowflake GitHub Actions workflow injection exposed Jira credentials

Snowflake's snowflakedb/snowflake-connector-net GitHub repository, specifically the .github/workflows/jira_issue.yml workflow. Vulnerable code was present on the default branch from June 18–23, 2026 (5-day window).

Snowflake17 Aug · 16:44 UTC
Forminator WordPress plugin RCE affects 600K+ sites via file upload bypasscriticalbug_reportVulnerability
bug_reportVulnerability

Forminator WordPress plugin RCE affects 600K+ sites via file upload bypass

Forminator Forms WordPress plugin versions ≤1.56.1. Affects 600,000+ active installations. Exploitation requires a form with both File Upload and Select fields. Sites using custom file upload storage paths are at higher risk.

CVE-2026-1574817 Aug · 16:22 UTC
Iranian Cavern C2 Framework Evolves with DNS and Google Apps Script Relayhighperson_alertThreat Actor
person_alertThreat Actor

Iranian Cavern C2 Framework Evolves with DNS and Google Apps Script Relay

Cavern (aka Cav3rn) is a command-and-control framework attributed to Iranian nation-state threat actors, specifically linked to Cavern Manticore, a hacking group affiliated with Iran's Ministry of Intelligence and Security (MOIS).

The Hacker News17 Aug · 15:41 UTC
GeoServer zero-day SQL injection under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

GeoServer zero-day SQL injection under active exploitation

GeoServer (specific versions not disclosed in advisory). All unpatched instances potentially vulnerable to SQL injection attacks.

GeoServer17 Aug · 12:17 UTC
Certighost (CVE-2026-54121): Domain user can escalate to DC via CAcriticalbug_reportVulnerability
bug_reportVulnerability

Certighost (CVE-2026-54121): Domain user can escalate to DC via CA

Microsoft Active Directory Certificate Services (AD CS) in Enterprise CA configurations. All versions prior to July 14, 2026 patch. Affects organizations with default AD settings including MachineAccountQuota allowing machine account creation by stan…

CVE-2026-5412117 Aug · 12:00 UTC
Ivanti EPM high severity flaws require immediate patchinghighbug_reportVulnerability
bug_reportVulnerability

Ivanti EPM high severity flaws require immediate patching

Ivanti Endpoint Manager (EPM). Specific affected versions not disclosed in available advisory. CVE identifiers not yet assigned or published.

Ivanti17 Aug · 11:57 UTC
Clop Ransomware Gang Exploits PTC Windchill Flaw to Breach GE, Philipshighperson_alertThreat Actor
person_alertThreat Actor

Clop Ransomware Gang Exploits PTC Windchill Flaw to Breach GE, Philips

Clop is a financially motivated ransomware and extortion gang with a well-established history of exploiting zero-day and n-day vulnerabilities in enterprise file-sharing and product lifecycle management (PLM) platforms to conduct mass data theft camp…

General Electric17 Aug · 09:25 UTC
Unisoc modem flaw enables Android kernel takeover via VoLTE video callcriticalbug_reportVulnerability
bug_reportVulnerability

Unisoc modem flaw enables Android kernel takeover via VoLTE video call

Unisoc chipsets T606, T612, and T7250 used in Motorola E13, Realme C33, and Xiaomi Redmi A5. Devices with these chipsets sold across 140+ countries. Confirmed vulnerable on Motorola E13 (February 2025 patch) and Xiaomi Redmi A5 (January 2026 patch).

Unisoc17 Aug · 08:52 UTC
French tax authority breach exposes 678,000 records amid rising attackshighpublicGeopolitical
publicGeopolitical

French tax authority breach exposes 678,000 records amid rising attacks

The breach of France's General Directorate of Public Finances (DGFiP) represents the latest in a sustained pattern of cyberattacks targeting French government infrastructure throughout 2026.

French Ministry of the Economy and Finance17 Aug · 08:09 UTC
IBM i systems face critical vulnerabilities requiring immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

IBM i systems face critical vulnerabilities requiring immediate patching

IBM i systems (formerly AS/400). Specific versions and CVE identifiers not disclosed in advisory. Scope appears to be multiple severe vulnerabilities across the platform.

IBM17 Aug · 07:37 UTC
Evooo1Bot botnet exploits 18 CVEs to turn edge devices into SOCKS5 proxieshighbug_reportVulnerability
bug_reportVulnerability

Evooo1Bot botnet exploits 18 CVEs to turn edge devices into SOCKS5 proxies

Internet-facing Linux-based edge devices including routers (NETGEAR, Tenda, D-Link, TP-Link, Zyxel), IP cameras (Hikvision), enterprise appliances (Alcatel OmniPCX, Mitsubishi ME-RTU, Telesquare SDT-CW3B1/TLR-2005KSH), and servers running vulnerable…

The Hacker News17 Aug · 07:29 UTC
Adobe Commerce critical vulnerability under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Adobe Commerce critical vulnerability under active exploitation

Adobe Commerce (formerly Magento). Specific affected versions not disclosed in advisory. All unpatched instances should be considered at risk.

Adobe17 Aug · 07:14 UTC
Microsoft Defender ShieldBreak zero-day grants SYSTEM privileges on Windowshighbug_reportVulnerability
bug_reportVulnerability

Microsoft Defender ShieldBreak zero-day grants SYSTEM privileges on Windows

Microsoft Defender on Windows 10, Windows 11 (including 25H2 and Canary), and Windows Server 2025. All fully patched systems with Defender enabled are vulnerable.

CVE-2026-6941417 Aug · 07:05 UTC
China-Nexus APT Exploits VMware vCenter Flaws, Deploys Babuk Ransomwarecriticalperson_alertThreat Actor
person_alertThreat Actor

China-Nexus APT Exploits VMware vCenter Flaws, Deploys Babuk Ransomware

A suspected China-nexus advanced persistent threat actor, assessed with moderate confidence by QUIRSO to be Chinese-speaking and operating in the UTC+08:00 time zone.

CVE-2026-5931017 Aug · 05:36 UTC
Large-scale DDoS campaign disrupts Threema encrypted messaging servicehighbug_reportVulnerability
bug_reportVulnerability

Large-scale DDoS campaign disrupts Threema encrypted messaging service

Threema secure messaging service (cloud-hosted instances). Users in Switzerland, India, and China reported outages. Threema On-Prem customers unaffected as they use independent infrastructure. Colocation partner Nine also targeted.

Threema16 Aug · 15:29 UTC
AmnesiaStealer malware hijacks macOS browser sessions via live remote controlhighbug_reportVulnerability
bug_reportVulnerability

AmnesiaStealer malware hijacks macOS browser sessions via live remote control

macOS users targeted via ClickFix campaigns using fake GitHub pages. Affects 16 Chromium-based browsers including Chrome, Edge, Brave, Opera, Vivaldi, Arc, and Chromium.

BleepingComputer16 Aug · 13:07 UTC
Evooo1Bot: Mirai-based botnet targets Linux gateways as SOCKS5 proxieshighbug_reportVulnerability
bug_reportVulnerability

Evooo1Bot: Mirai-based botnet targets Linux gateways as SOCKS5 proxies

Internet-facing Linux gateway devices (routers, firewalls, edge appliances). Specific vendors and models not disclosed. Mirai-based malware with modular architecture targeting devices with weak credentials or known vulnerabilities.

BleepingComputer15 Aug · 12:14 UTC
SAP Commerce Cloud CVE-2026-58231 under active exploit, 3 days post-patchcriticalbug_reportVulnerability
bug_reportVulnerability

SAP Commerce Cloud CVE-2026-58231 under active exploit, 3 days post-patch

SAP Commerce Cloud, all versions prior to patched release levels. Vulnerability affects default authentication clients and endpoints lacking input validation. Unauthenticated remote exploitation possible.

CVE-2026-5823115 Aug · 06:38 UTC
€30M Bank Fraud via Service Provider Exploit Targets Commerzbankhighperson_alertThreat Actor
person_alertThreat Actor

€30M Bank Fraud via Service Provider Exploit Targets Commerzbank

An unknown cybercriminal group, financially motivated, conducted a coordinated bank fraud operation targeting Commerzbank customers. The group operated across multiple jurisdictions, with four members arrested in Brazil and three charged in Europe.

Commerzbank14 Aug · 16:04 UTC
macOS Screen Sharing auth bypass exploited to deploy Monero minershighbug_reportVulnerability
bug_reportVulnerability

macOS Screen Sharing auth bypass exploited to deploy Monero miners

macOS Screen Sharing feature on systems with TCP port 5900 exposed to the internet. Fixed in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. CVE-2026-65400 affects earlier versions of these releases.

Apple14 Aug · 12:59 UTC