Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 547 results
criticalbug_reportVulnerabilityMicrosoft SharePoint RCE (CVE-2026-50522) actively exploited after PoC
Microsoft SharePoint Server (all versions prior to July 2026 patches). Vulnerability involves deserialization of untrusted data leading to unauthenticated remote code execution. CVSS 9.8 (Critical).
criticalbug_reportVulnerabilityZimbra 10.1.20 patches critical SNMP command injection and 4 XSS flaws
Zimbra Collaboration Suite versions prior to 10.1.20. Critical impact: SNMP monitoring component when SNMP notifications are enabled. Additional impact: four XSS vulnerabilities affecting the web interface.
highbug_reportVulnerabilityMobile AI agent frameworks vulnerable to instruction injection attacks
Five open-source mobile AI agent frameworks including AppAgent and AppAgentX. Attack requires malicious Android apps with overlay and storage permissions to inject invisible instructions, leading to command execution on connected host PCs.
criticalbug_reportVulnerabilityWordPress wp2shell flaws enable unauthenticated RCE, active exploitation
WordPress core (specific versions not disclosed). CVE-2026-63030 and CVE-2026-60137 must be chained for unauthenticated remote code execution. All unpatched WordPress installations are potentially vulnerable.
highbug_reportVulnerabilityWindows LegacyHive zero-day enables privilege escalation, unofficial patches available
Microsoft Windows systems (all current versions). Specific affected versions not disclosed. Impacts up-to-date Windows installations. No CVE assigned yet.
criticalbug_reportVulnerabilitySonicWall SMA1000 VPN appliances exploited via two zero-day flaws
SonicWall SMA1000 series VPN appliances. Specific vulnerable versions not disclosed. Affects enterprise VPN infrastructure using these devices.
highbug_reportVulnerabilitySandbox escape flaws in Cursor, Codex, Gemini CLI, Antigravity AI tools
Multiple AI development tools: Cursor IDE, OpenAI Codex, Google Gemini CLI, and Antigravity. Vulnerability affects AI agent sandbox implementations where agents write files executed by host tools, allowing escape from restricted environments.
highbug_reportVulnerabilityHollowGraph malware abuses Microsoft 365 calendar for C2 and exfiltration
Microsoft 365 environments with compromised mailboxes. Threat actors leverage Microsoft Graph API and calendar features to establish covert command-and-control channels.
highbug_reportVulnerabilityAI-assisted phishing toolkit targets Windows users in Mexico via fake gov site
Windows users in Mexico targeted via fake government ID-lookup website. Delivery mechanism uses WebDAV to distribute infostealer malware. Toolkit contains 1,048 files including phishing templates, droppers, and builder documentation.
highbug_reportVulnerability7-Zip heap overflow in XZ handling allows code execution via crafted archives
7-Zip versions prior to 26.02. Affects all platforms where 7-Zip is deployed (Windows, Linux). Vulnerability triggered when opening malicious XZ archives.
highbug_reportVulnerabilityMalicious RubyGems packages deliver payloads to developer workstations
RubyGems ecosystem: three malicious packages (git_credential_manager, Dendreo, and one unnamed) published to the official RubyGems repository. Affects Ruby developers who installed these packages.
criticalbug_reportVulnerabilityCritical NGINX heap overflow enables RCE via crafted HTTP requests
NGINX open source versions prior to 1.30.4 and 1.31.3, and NGINX Plus versions prior to 37.0.3.1. All deployments accepting HTTP requests from untrusted networks are at risk.
highbug_reportVulnerabilityViPNet update mechanism compromised to target Russian government agencies
ViPNet private networking software users, primarily Russian government agencies and organizations. All versions using the compromised update delivery mechanism are potentially affected. Specific version range not disclosed.
criticalbug_reportVulnerabilitySonicWall SMA 1000 VPN zero-days exploited by UTA0533 for root access
SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. Specific vulnerable versions not disclosed. All SMA 1000 deployments should be considered at risk until vendor guidance is available.
highbug_reportVulnerability7-Zip 26.02 patches RCE flaw via malicious compressed files
7-Zip versions prior to 26.02. All platforms (Windows, Linux, macOS) where 7-Zip is installed and users handle compressed archives from untrusted sources.
criticalbug_reportVulnerabilityWordPress Core RCE "wp2shell" exploits now public, patch immediately
WordPress Core (specific versions not disclosed in provided data). Vulnerability enables remote code execution. Public exploits available under the name "wp2shell".
highbug_reportVulnerabilityACR Stealer campaign targets Microsoft enterprise customers
Microsoft enterprise customers; targets browser-stored credentials, authentication tokens, and sensitive documents across enterprise environments
criticalbug_reportVulnerabilityWordPress 6.9–7.0 unauthenticated RCE patched, forced auto-update active
WordPress core versions 6.9.0–6.9.4 and 7.0.0–7.0.1. All sites running these versions are vulnerable to unauthenticated remote code execution via anonymous HTTP requests. Patched in 6.9.5 and 7.0.2.
highbug_reportVulnerabilityOpenSSL "HollowByte" DoS allows 11-byte requests to freeze server memory
OpenSSL versions prior to June 2024 patch. Affects TLS servers running on glibc-based Linux systems. Specific vulnerable versions not disclosed; patch applied without CVE or public advisory.
highbug_reportVulnerabilitySeven malicious npm packages target Vite ecosystem with blockchain C2 RAT
npm package ecosystem, specifically projects using Vite frontend tooling. Seven malicious packages identified in the ViteVenom campaign. Any JavaScript/Node.js development environments that installed these packages are compromised.
highbug_reportVulnerabilityHollowByte flaw enables DoS on OpenSSL servers via 11-byte payload
OpenSSL servers (specific versions not disclosed). Unauthenticated remote attackers can exploit the vulnerability. Scope includes any internet-facing OpenSSL server implementations susceptible to the malicious payload.
criticalbug_reportVulnerabilityDigiCert breach linked to Chinese APT; code-signing certs stolen
DigiCert certificate authority infrastructure compromised in April 2026. Code-signing certificates stolen by CylindricalCanine (GoldenEyeDog/APT-Q-27 subgroup).
criticalbug_reportVulnerabilityFortinet FortiSandbox critical RCE and privilege escalation flaw
Fortinet FortiSandbox - specific affected versions not disclosed in available advisory. Product used for malware analysis and threat detection in enterprise environments.
highbug_reportVulnerabilitySpring Authorization Server authentication bypass requires immediate patch
Spring Authorization Server (part of Spring Security framework by VMware/Pivotal). Specific affected versions not disclosed in available information. Authentication mechanism is impacted.
criticalbug_reportVulnerabilityWindows zero-day LegacyHive enables privilege escalation on patched systems
All up-to-date Windows systems. Specific affected versions not disclosed. Exploit enables local privilege escalation from standard user to administrator level. No CVE assigned yet.
criticalbug_reportVulnerabilitySiemens ROX II OT switches vulnerable to chained zero-day privilege escalation
Siemens ROX II industrial switches used in operational technology (OT) environments. Specific affected firmware versions not disclosed in summary. Vulnerability chain enables privilege escalation to persistent root access.
highbug_reportVulnerabilityACR Stealer campaign uses ClickFix social engineering to steal M365 data
Microsoft 365 enterprise users and organizations. ACR Stealer targets browser credentials, session tokens, and M365 documents. Active since 2024 with two documented delivery chains using ClickFix social engineering lures.
criticalbug_reportVulnerabilityCISA orders patching of actively exploited Fortinet FortiSandbox flaws
Fortinet FortiSandbox threat detection platform. Specific versions not provided in available data. Two vulnerabilities confirmed, CVE identifiers not yet disclosed.
criticalbug_reportVulnerabilityCISA: Microsoft SharePoint RCE CVE-2026-58644 actively exploited
Microsoft SharePoint Server (specific versions not disclosed). CVSS 9.8 critical remote code execution vulnerability.
criticalbug_reportVulnerabilityCISA adds CVE-2023-4346 KNX Protocol flaw to KEV catalog
KNX Protocol implementations used in building automation and smart home systems. Specific affected products and versions not disclosed in available information.