Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 675 results
Active filter:✕ clear
Malware can abuse Windows Hello for Business keys for persistent Entra ID accesshighbug_reportVulnerability
bug_reportVulnerability

Malware can abuse Windows Hello for Business keys for persistent Entra ID access

Windows Hello for Business on all Windows versions with Entra ID integration. Affects organizations using Windows Hello for Business as phishing-resistant authentication. TPM-backed and non-TPM deployments both vulnerable.

Microsoft7 Aug · 06:52 UTC
ClickFix campaign delivers Go-based macOS stealer targeting crypto walletshighbug_reportVulnerability
bug_reportVulnerability

ClickFix campaign delivers Go-based macOS stealer targeting crypto wallets

macOS users across all versions; targets cryptocurrency wallets (Bitcoin, Ethereum, Litecoin, Dogecoin, Monero, XRP), browser password databases, Apple Keychain, and cached browser credentials.

BleepingComputer6 Aug · 20:37 UTC
ChainDrop npm worm infects 400+ packages, steals secrets via blockchain C2highbug_reportVulnerability
bug_reportVulnerability

ChainDrop npm worm infects 400+ packages, steals secrets via blockchain C2

Over 400 npm packages including widely used packages like keyv and cacheable-request. Affects developer workstations, CI/CD pipelines (especially GitHub Actions), cloud environments, and downstream software users.

npm6 Aug · 20:26 UTC
TONTOU attack bypasses Spectre v2 mitigations on Intel and AMD CPUshighbug_reportVulnerability
bug_reportVulnerability

TONTOU attack bypasses Spectre v2 mitigations on Intel and AMD CPUs

Intel and AMD processors with Spectre v2 mitigations (eIBRS on Intel, Safe RET on AMD). Confirmed exploitable on AMD Zen 2 systems running Linux kernel 6.14.0-37-generic. Intel systems also vulnerable but require additional software prerequisites.

BleepingComputer6 Aug · 16:03 UTC
Zapscape KVM flaw allows L1 guest escape to host with nested virtualizationhighbug_reportVulnerability
bug_reportVulnerability

Zapscape KVM flaw allows L1 guest escape to host with nested virtualization

Linux kernel KVM/x86 shadow MMU in versions 5.9 through 7.1.5. Fixed in stable releases 6.6.148, 6.12.101, 6.18.42, 7.1.6, and 7.2-rc5. Affects systems running KVM hosts with nested virtualization exposed to untrusted guests.

CVE-2026-645616 Aug · 15:58 UTC
Cisco patches 12 critical SD-WAN and IOS XE flaws, three rated 9.8+criticalbug_reportVulnerability
bug_reportVulnerability

Cisco patches 12 critical SD-WAN and IOS XE flaws, three rated 9.8+

Cisco Catalyst SD-WAN Software (all versions prior to 20.9, versions 20.9–26.1); Cisco IOS XE Software versions 17.9–26.1 running in autonomous or controller mode; Cisco Integrated Management Controller (IMC) web interface.

Cisco6 Aug · 15:13 UTC
Critical Cisco Catalyst SD-WAN flaws require immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical Cisco Catalyst SD-WAN flaws require immediate patching

Cisco Catalyst SD-WAN Software (specific versions not disclosed in advisory). Scope: SD-WAN infrastructure components used for enterprise WAN connectivity and management.

Cisco6 Aug · 14:29 UTC
Interrupt injection bypasses Spectre v2 defenses on Intel, AMD CPUshighbug_reportVulnerability
bug_reportVulnerability

Interrupt injection bypasses Spectre v2 defenses on Intel, AMD CPUs

Intel CPUs (Cascade Lake Refresh, Arrow Lake) and AMD Zen 1-4 processors running Linux. AMD Safe-RET mitigation vulnerable; Intel eIBRS/BHI defenses also affected. Requires local code execution on shared Linux systems.

Intel6 Aug · 14:17 UTC
Cisco IOS/IOS XE vulnerabilities require immediate patching per CERT.BEhighbug_reportVulnerability
bug_reportVulnerability

Cisco IOS/IOS XE vulnerabilities require immediate patching per CERT.BE

Cisco IOS and IOS XE platforms. Specific affected versions not provided in advisory. Multiple vulnerabilities of high severity impact network infrastructure devices including routers and switches running these operating systems.

Cisco6 Aug · 13:38 UTC
4,407 Rockwell PLCs exposed online; 22 in cities hit by water attackshighbug_reportVulnerability
bug_reportVulnerability

4,407 Rockwell PLCs exposed online; 22 in cities hit by water attacks

Rockwell Automation programmable logic controllers (PLCs) globally: 4,407 exposed devices (2,844 in US). Primary models: MicroLogix 1400 (50%) and MicroLogix 1100 (8%).

Rockwell Automation6 Aug · 10:16 UTC
CryptoJS weak RNG drained $5.7M from five crypto wallets over 12 yearscriticalbug_reportVulnerability
bug_reportVulnerability

CryptoJS weak RNG drained $5.7M from five crypto wallets over 12 years

CryptoJS versions below 4.0.0 (except 3.2.0 and 3.2.1). Five confirmed affected wallet apps: RRWallet (discontinued), Bexo Wallet (fixed in 20.1.0, builds pending), NanChat (fixed in 1.3.0), Bitcoin Libre (fixed in v4, July 2024), and Milo (discontin…

CryptoJS6 Aug · 09:49 UTC
Apple iCloud Private Relay leaks real IP via WebKit proxy bypasseshighbug_reportVulnerability
bug_reportVulnerability

Apple iCloud Private Relay leaks real IP via WebKit proxy bypasses

Apple iCloud Private Relay on iOS 15+, macOS, and iPadOS. Affects Safari and all WebKit-based browsers (Chrome, Edge, Firefox, Brave) on Apple platforms. Impacts users with iCloud+ subscriptions using Private Relay for privacy protection.

Apple6 Aug · 09:33 UTC
AWS, Google, Vercel agent flaws allow tool execution without model checkshighbug_reportVulnerability
bug_reportVulnerability

AWS, Google, Vercel agent flaws allow tool execution without model checks

Amazon Bedrock AgentCore InvokeHarness API (fixed July 31, 2026; CVE-2026-18830, CVSS 8.6), open-source Strands Python library (unpatched resume path remains), Google Agent Development Kit (ADK) for Python <2.5.0 (CVE-2026-18236, CVSS 9.3), Vercel AI…

Amazon Web Services6 Aug · 06:57 UTC
Oracle SQL injection exploited to deploy khunt toolkit inside databasehighbug_reportVulnerability
bug_reportVulnerability

Oracle SQL injection exploited to deploy khunt toolkit inside database

Oracle databases with Java Virtual Machine enabled, particularly those connected to public-facing Java applications (Apache Tomcat observed). Specific Oracle versions not disclosed.

Oracle5 Aug · 17:55 UTC
Phishing campaign exploits COLDCARD wallet fears to deploy ScreenConnect RAThighbug_reportVulnerability
bug_reportVulnerability

Phishing campaign exploits COLDCARD wallet fears to deploy ScreenConnect RAT

COLDCARD hardware wallet users targeted via phishing emails. Attack delivers ConnectWise ScreenConnect remote access tool via malicious batch file (Coldcard_Diagnostic_Tool.bat) hosted on GitHub.

COLDCARD5 Aug · 15:49 UTC
CISA orders 3-day patch for exploited IBM Langflow, N-central, Tomcat flawshighbug_reportVulnerability
bug_reportVulnerability

CISA orders 3-day patch for exploited IBM Langflow, N-central, Tomcat flaws

IBM Langflow (CVE-2026-9198, CVSS 9.8) - default deployments vulnerable to unauthenticated RCE via API endpoint chaining. N-able N-central (CVE-2026-18576) - all versions before 2026.3 allow unauthenticated admin account hijacking; incomplete patch b…

IBM5 Aug · 13:51 UTC
macOS ClickFix campaign adds fingerprinting to evade detectionhighbug_reportVulnerability
bug_reportVulnerability

macOS ClickFix campaign adds fingerprinting to evade detection

macOS users targeted via 250+ algorithmically generated domains (e.g., filecopperbasket, apricotfilepoint[.]com). Campaign delivers MacSync and Atomic Stealer (AMOS) infostealers. All macOS versions susceptible to social engineering technique.

Apple5 Aug · 13:48 UTC
Paperclip AI control plane flaws enable RCE via malicious agent importshighbug_reportVulnerability
bug_reportVulnerability

Paperclip AI control plane flaws enable RCE via malicious agent imports

Paperclip open-source AI agent control plane, versions prior to v2026.416.0. CVE-2026-41679 (CVSS 10.0) affects network-accessible authenticated deployments with default registration.

Paperclip5 Aug · 13:14 UTC
Terraform MCP, Veeam VSPC, Django patch 11 flaws including CVSS 10.0 bugcriticalbug_reportVulnerability
bug_reportVulnerability

Terraform MCP, Veeam VSPC, Django patch 11 flaws including CVSS 10.0 bug

HashiCorp Terraform MCP Server versions 0.2.1–1.0.0 (Streamable HTTP mode only); Veeam Service Provider Console versions 9.2.1.33875 and earlier (all version 9 builds before 9.3); Django versions prior to 6.0.8 and 5.2.17 (GeoDjango spatial field con…

HashiCorp5 Aug · 12:27 UTC
Trojanized npm packages use blockchain to hide C2 IPs in supply chain attackhighbug_reportVulnerability
bug_reportVulnerability

Trojanized npm packages use blockchain to hide C2 IPs in supply chain attack

Two npm packages: "bianira-ui" (109 downloads) and "fluid-type-ui" (587 downloads), published July 28, 2026 by users "npmuser1101" and "npmuser3002". Packages now removed from npm.

npm5 Aug · 11:41 UTC
Critical Veeam Service Provider Console flaws require immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical Veeam Service Provider Console flaws require immediate patching

Veeam Service Provider Console - specific affected versions not disclosed in available information. All users running VSPC should assume exposure until vendor guidance is reviewed.

Veeam5 Aug · 10:47 UTC
Linux kernel Open vSwitch flaw grants local root; public exploit availablehighbug_reportVulnerability
bug_reportVulnerability

Linux kernel Open vSwitch flaw grants local root; public exploit available

Linux kernel Open vSwitch datapath. Fixed in stable kernels 5.15.212, 6.1.178, 6.6.145, 6.12.97, 6.18.40, and 7.1.5. Affects default configurations of AlmaLinux 9/10, Alpine 3.22-3.24, Amazon Linux 2023, Arch, CentOS Stream 9/10, Debian 12/13, Fedora…

CVE-2026-645315 Aug · 09:43 UTC
Gitea CVE-2026-59774: Unauthenticated file read via Org-mode markupcriticalbug_reportVulnerability
bug_reportVulnerability

Gitea CVE-2026-59774: Unauthenticated file read via Org-mode markup

Gitea versions 1.22.1 through 1.27.0. Self-hosted instances with public repositories and Org-mode rendering enabled are vulnerable. Gitea Cloud instances upgraded automatically. Fixed in version 1.27.1.

CVE-2026-597745 Aug · 09:04 UTC
Credential-stealing worm compromises 400+ npm packages via auto-propagationcriticalbug_reportVulnerability
bug_reportVulnerability

Credential-stealing worm compromises 400+ npm packages via auto-propagation

Over 400 npm packages across multiple unrelated publishers, including keyv, flat-cache, cache-manager, and other major enterprise software ecosystem packages. Affects developer workstations and CI/CD environments with npm lifecycle scripts enabled.

npm4 Aug · 21:46 UTC
TP-Link patches 15 Omada ZTP flaws enabling network infiltration via RCEhighbug_reportVulnerability
bug_reportVulnerability

TP-Link patches 15 Omada ZTP flaws enabling network infiltration via RCE

TP-Link Omada network devices including Controllers, Gateways, Switches, Access Points, OLT platforms, Cloud services, and mobile applications (Omada, Omada Guard, TP-Link apps). Over 1,800 internet-accessible Omada controllers identified.

TP-Link4 Aug · 20:18 UTC
XCSSET v40 malware targets macOS developers via poisoned Xcode projectshighbug_reportVulnerability
bug_reportVulnerability

XCSSET v40 malware targets macOS developers via poisoned Xcode projects

macOS developers using Xcode and downloading projects from compromised Git/GitHub repositories. XCSSET v40 observed in attacks mid-April and early May 2026. All macOS versions with Xcode are at risk; specific version details not provided.

Apple4 Aug · 17:03 UTC
77 malicious Open VSX extensions harvested developer environment metadatahighbug_reportVulnerability
bug_reportVulnerability

77 malicious Open VSX extensions harvested developer environment metadata

Open VSX marketplace users who installed any of 77 counterfeit "evil twin" extensions between July 26 and August 1, 2026. Extensions impersonated legitimate tools from AMD, Azure, Salesforce, Hyperledger, LEGO Education, IOTA, and a U.S.

Open VSX4 Aug · 16:50 UTC
Greatness PhaaS adds device code phishing to bypass MFA via OAuth abusehighbug_reportVulnerability
bug_reportVulnerability

Greatness PhaaS adds device code phishing to bypass MFA via OAuth abuse

Organizations using Microsoft 365, Google Workspace, iCloud, and Yahoo with OAuth 2.0 authentication. Particularly at risk: RingCentral customers targeted via spoofed voicemail lures exploiting safe sender trust configurations.

The Hacker News4 Aug · 15:27 UTC
ChainDrop worm compromises 1,300+ npm packages with 2B monthly downloadscriticalbug_reportVulnerability
bug_reportVulnerability

ChainDrop worm compromises 1,300+ npm packages with 2B monthly downloads

Over 1,300 npm packages (1,381 versions) including Keyv, Cacheable, flat-cache, and file-entry-cache. Attack originated from compromised GitHub account of Keyv maintainer.

npm4 Aug · 13:24 UTC
npm worm from keyv@6.0.0 poisons 353+ packages, steals credentials via hookscriticalbug_reportVulnerability
bug_reportVulnerability

npm worm from keyv@6.0.0 poisons 353+ packages, steals credentials via hooks

npm packages: keyv@6.0.0 and at least 353 poisoned versions across 79 package names (SafeDep verified); broader estimates reach 868 packages. Affects developers and CI/CD environments using npm clients prior to npm 12, Claude Code, and VS Code.

npm4 Aug · 11:30 UTC