Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-21 · 02:09 UTC
articleTotal: 606 reports

Filtered Reports

30 / 244 results
Active filter:tag: #geopolitical✕ clear
Kidsview authentication bypass allows unauthorized access (CVE-2026-8990)highbug_reportVulnerability
bug_reportVulnerability

Kidsview authentication bypass allows unauthorized access (CVE-2026-8990)

Kidsview application (specific versions not disclosed). Authentication mechanisms can be bypassed, potentially affecting all deployments until patched versions are confirmed.

CVE-2026-899011:55 UTC
Romanian National Sentenced for Hacking Oregon Government Networkhighperson_alertThreat Actor
person_alertThreat Actor

Romanian National Sentenced for Hacking Oregon Government Network

A Romanian national individual actor who conducted unauthorized access operations targeting U.S. government and private sector networks. The actor's motivation appears to be financially driven cybercrime, operating from Romania to compromise Oregon s…

BleepingComputer10:43 UTC
Out-of-bounds write in bzip2 enables code execution or DoShighbug_reportVulnerability
bug_reportVulnerability

Out-of-bounds write in bzip2 enables code execution or DoS

bzip2 compression software, all versions not yet patched. Affects systems using bzip2 for file compression/decompression, including Linux distributions, BSD variants, and applications embedding libbz2.

CVE-2026-4225010:15 UTC
Apache ActiveMQ NMS AMQP Client deserialization flaw enables RCEcriticalbug_reportVulnerability
bug_reportVulnerability

Apache ActiveMQ NMS AMQP Client deserialization flaw enables RCE

Apache ActiveMQ NMS AMQP Client - specific vulnerable versions not provided. Affects .NET/C# applications using the NMS AMQP client library for message queue operations.

Apache14:59 UTC
Microsoft SharePoint RCE vulnerability requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft SharePoint RCE vulnerability requires immediate patching

Microsoft SharePoint Server (specific versions not disclosed in advisory). Organizations running on-premises SharePoint deployments are affected. SharePoint Online managed by Microsoft likely already patched.

Microsoft14:23 UTC
Banking trojans Grandoreiro and BTMOB target LATAM and Europehighbug_reportVulnerability
bug_reportVulnerability

Banking trojans Grandoreiro and BTMOB target LATAM and Europe

Windows and Android devices in Latin America (Brazil, Mexico) and Europe (Spain, Portugal). Grandoreiro targets Windows systems at companies; BTMOB RAT targets Android mobile users in Brazil.

Windows14:10 UTC
Silent Ransom Group Shifts to Physical Data Theft at U.S. Law Firmshighperson_alertThreat Actor
person_alertThreat Actor

Silent Ransom Group Shifts to Physical Data Theft at U.S. Law Firms

Silent Ransom Group (SRG) is an extortion-focused threat actor that has evolved from traditional ransomware operations to conducting physical, in-person data theft attacks.

BleepingComputer09:51 UTC
CISA orders federal agencies to patch LiteSpeed cPanel plugin in 4 dayscriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders federal agencies to patch LiteSpeed cPanel plugin in 4 days

LiteSpeed cPanel user-end plugin. Specific vulnerable versions not disclosed. Affects organizations using cPanel with LiteSpeed integration.

LiteSpeed08:06 UTC
ShinyHunters Extorts Charter Communications After Data Breachhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Extorts Charter Communications After Data Breach

ShinyHunters is a financially motivated cybercrime group known for large-scale data breaches and extortion operations targeting organizations across multiple sectors.

Charter Communications17:46 UTC
LiteSpeed cPanel/WHM plugin under active exploit (CVE-2026-48172)criticalbug_reportVulnerability
bug_reportVulnerability

LiteSpeed cPanel/WHM plugin under active exploit (CVE-2026-48172)

LiteSpeed plugin for cPanel/WHM. Specific vulnerable versions not disclosed in provided data. Affects web hosting environments using LiteSpeed with cPanel/WHM integration.

CVE-2026-4817214:28 UTC
Ubiquiti patches critical UniFi OS vulnerabilitiescriticalbug_reportVulnerability
bug_reportVulnerability

Ubiquiti patches critical UniFi OS vulnerabilities

Ubiquiti UniFi OS (specific versions not disclosed). Affects UniFi network management appliances including Dream Machine, Cloud Key, and similar devices running UniFi OS.

Ubiquiti14:13 UTC
MuddyWater Q1 2026 espionage campaign hits nine countries via DLL side-loadinghighperson_alertThreat Actor
person_alertThreat Actor

MuddyWater Q1 2026 espionage campaign hits nine countries via DLL side-loading

MuddyWater (also tracked as Earth Vetala, MERCURY, Static Kitten, and Seedworm) is an Iranian state-sponsored APT group attributed to Iran's Ministry of Intelligence and Security (MOIS).

The Hacker News13:48 UTC
Trend Micro Apex One & Vision One SEP flaws under active exploitcriticalbug_reportVulnerability
bug_reportVulnerability

Trend Micro Apex One & Vision One SEP flaws under active exploit

Trend Micro Apex One and Trend Micro Vision One Endpoint Security (SEP). Specific vulnerable versions not disclosed in summary; multiple vulnerabilities confirmed under active exploitation.

Trend Micro08:17 UTC
India mandates 12-hour patching for critical vulnerabilitieshighpublicGeopolitical
publicGeopolitical

India mandates 12-hour patching for critical vulnerabilities

India's Computer Emergency Response Team (CERT-In) has introduced stringent vulnerability management requirements, mandating that organizations patch critical security flaws in internet-facing systems within 12 hours of notification.

The Hacker News07:13 UTC
Critical vulnerability in Cisco Secure Workload requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical vulnerability in Cisco Secure Workload requires immediate patching

Cisco Secure Workload (specific versions not disclosed in advisory). CVE identifier not yet assigned or published.

Cisco06:50 UTC
CISA orders emergency patching of exploited Drupal SQL injection flawcriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders emergency patching of exploited Drupal SQL injection flaw

Drupal CMS (specific versions not provided in alert). Affects U.S. government agencies and all organizations running vulnerable Drupal instances.

Drupal06:46 UTC
Nimbus Manticore deploys MiniFast and MiniJunk V2 via phishing and SEO poisoninghighperson_alertThreat Actor
person_alertThreat Actor

Nimbus Manticore deploys MiniFast and MiniJunk V2 via phishing and SEO poisoning

Nimbus Manticore (also tracked as Screening Serpens and UNC1549) is an Iranian state-sponsored threat actor attributed to Iran's intelligence apparatus.

The Hacker News05:13 UTC
ShinyHunters Breaches 7-Eleven, Exfiltrates 183K Recordshighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Breaches 7-Eleven, Exfiltrates 183K Records

ShinyHunters is a financially motivated cybercrime group known for large-scale data breaches and extortion operations targeting organizations across multiple sectors.

7-Eleven05:01 UTC
Digital Knowledge LMS exploited via hardcoded ASP.NET keys (CVE-2026-5426)highbug_reportVulnerability
bug_reportVulnerability

Digital Knowledge LMS exploited via hardcoded ASP.NET keys (CVE-2026-5426)

Digital Knowledge KnowledgeDeliver LMS (specific versions not disclosed). Vulnerability stems from hard-coded ASP.NET machine keys enabling authentication bypass and remote code execution.

CVE-2026-542603:19 UTC
Dutch Authorities Disrupt Hosting Infrastructure Linked to Russian Opshighperson_alertThreat Actor
person_alertThreat Actor

Dutch Authorities Disrupt Hosting Infrastructure Linked to Russian Ops

This operation involves Russian state-sponsored cyber activity facilitated through compromised Internet hosting infrastructure in the Netherlands. The arrested co-owners operated hosting companies that assumed control of Stark Industries Solutions' t…

Stark Industries Solutions11:21 UTC
OutSystems Lifetime authorization bypass via user-controlled keyhighbug_reportVulnerability
bug_reportVulnerability

OutSystems Lifetime authorization bypass via user-controlled key

OutSystems Lifetime software. Specific affected versions not disclosed. Vulnerability allows authorization bypass through improper handling of user-controlled keys.

CVE-2026-4012708:55 UTC
Lazarus Group deploys RemotePE cross-platform RAT against finance sectorhighperson_alertThreat Actor
person_alertThreat Actor

Lazarus Group deploys RemotePE cross-platform RAT against finance sector

Lazarus Group is a North Korean state-sponsored advanced persistent threat (APT) actor attributed to the Reconnaissance General Bureau (RGB). The group is financially motivated, conducting operations to generate revenue for the DPRK regime through th…

The Hacker News07:32 UTC
Italy Dismantles CINEMAGOAL Piracy Network Targeting Streaming PlatformshighpublicGeopolitical
publicGeopolitical

Italy Dismantles CINEMAGOAL Piracy Network Targeting Streaming Platforms

The disruption of the CINEMAGOAL piracy ecosystem represents a law enforcement action against organized digital piracy infrastructure rather than a state-sponsored cyber operation.

Netflix12:23 UTC
First VPN Service dismantled by European and North American authoritieshighperson_alertThreat Actor
person_alertThreat Actor

First VPN Service dismantled by European and North American authorities

First VPN Service was a criminal VPN infrastructure provider that facilitated cybercrime operations for approximately 25 ransomware groups. The service enabled threat actors to obscure their geographic origins and true IP addresses during malicious a…

The Hacker News15:35 UTC
Dutch authorities dismantle hosting infrastructure linked to cyber opshighpublicGeopolitical
publicGeopolitical

Dutch authorities dismantle hosting infrastructure linked to cyber ops

The Netherlands has emerged as a key jurisdiction for enforcement against cyber-enabling infrastructure, reflecting both its role as a European internet hub and its proactive stance on transnational cybercrime.

BleepingComputer15:24 UTC
CISA Contractor Leaks AWS GovCloud Keys on Public GitHub Repositorycriticalperson_alertThreat Actor
person_alertThreat Actor

CISA Contractor Leaks AWS GovCloud Keys on Public GitHub Repository

The threat actor is an insider—a contractor working for the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The individual intentionally published sensitive AWS GovCloud credentials and agency secrets to a public GitHub repository.

Amazon Web Services14:34 UTC
Ghostwriter Targets Ukrainian Government with Prometheus-Themed Phishinghighperson_alertThreat Actor
person_alertThreat Actor

Ghostwriter Targets Ukrainian Government with Prometheus-Themed Phishing

Ghostwriter (also tracked as UAC-0057 and UNC1151) is a Belarus-aligned threat actor known for conducting information operations and cyber espionage campaigns.

The Hacker News14:20 UTC
Trend Micro Apex One zero-day actively exploited in the wildcriticalbug_reportVulnerability
bug_reportVulnerability

Trend Micro Apex One zero-day actively exploited in the wild

Trend Micro Apex One on Windows systems. Specific affected versions not disclosed. Zero-day vulnerability with no CVE assigned yet.

Trend Micro11:39 UTC
Screening Serpens: Iranian APT Targets Tech and Defense with RAT Malwarehighperson_alertThreat Actor
person_alertThreat Actor

Screening Serpens: Iranian APT Targets Tech and Defense with RAT Malware

Screening Serpens is an Iranian APT group attributed by Unit 42, conducting cyber espionage operations. The group is motivated by intelligence collection targeting technology and defense sectors, consistent with Iranian state interests in acquiring s…

Unit 42 (Palo Alto)11:00 UTC
Canadian National Arrested for Operating KimWolf DDoS Botnethighperson_alertThreat Actor
person_alertThreat Actor

Canadian National Arrested for Operating KimWolf DDoS Botnet

A Canadian national arrested by U.S. and Canadian authorities for operating the KimWolf DDoS botnet infrastructure. The operator managed a large-scale botnet that compromised nearly two million devices globally, offering DDoS-for-hire services.

BleepingComputer07:01 UTC