Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 675 results
highbug_reportVulnerabilityMalware can abuse Windows Hello for Business keys for persistent Entra ID access
Windows Hello for Business on all Windows versions with Entra ID integration. Affects organizations using Windows Hello for Business as phishing-resistant authentication. TPM-backed and non-TPM deployments both vulnerable.
highbug_reportVulnerabilityClickFix campaign delivers Go-based macOS stealer targeting crypto wallets
macOS users across all versions; targets cryptocurrency wallets (Bitcoin, Ethereum, Litecoin, Dogecoin, Monero, XRP), browser password databases, Apple Keychain, and cached browser credentials.
highbug_reportVulnerabilityChainDrop npm worm infects 400+ packages, steals secrets via blockchain C2
Over 400 npm packages including widely used packages like keyv and cacheable-request. Affects developer workstations, CI/CD pipelines (especially GitHub Actions), cloud environments, and downstream software users.
highbug_reportVulnerabilityTONTOU attack bypasses Spectre v2 mitigations on Intel and AMD CPUs
Intel and AMD processors with Spectre v2 mitigations (eIBRS on Intel, Safe RET on AMD). Confirmed exploitable on AMD Zen 2 systems running Linux kernel 6.14.0-37-generic. Intel systems also vulnerable but require additional software prerequisites.
highbug_reportVulnerabilityZapscape KVM flaw allows L1 guest escape to host with nested virtualization
Linux kernel KVM/x86 shadow MMU in versions 5.9 through 7.1.5. Fixed in stable releases 6.6.148, 6.12.101, 6.18.42, 7.1.6, and 7.2-rc5. Affects systems running KVM hosts with nested virtualization exposed to untrusted guests.
criticalbug_reportVulnerabilityCisco patches 12 critical SD-WAN and IOS XE flaws, three rated 9.8+
Cisco Catalyst SD-WAN Software (all versions prior to 20.9, versions 20.9–26.1); Cisco IOS XE Software versions 17.9–26.1 running in autonomous or controller mode; Cisco Integrated Management Controller (IMC) web interface.
criticalbug_reportVulnerabilityCritical Cisco Catalyst SD-WAN flaws require immediate patching
Cisco Catalyst SD-WAN Software (specific versions not disclosed in advisory). Scope: SD-WAN infrastructure components used for enterprise WAN connectivity and management.
highbug_reportVulnerabilityInterrupt injection bypasses Spectre v2 defenses on Intel, AMD CPUs
Intel CPUs (Cascade Lake Refresh, Arrow Lake) and AMD Zen 1-4 processors running Linux. AMD Safe-RET mitigation vulnerable; Intel eIBRS/BHI defenses also affected. Requires local code execution on shared Linux systems.
highbug_reportVulnerabilityCisco IOS/IOS XE vulnerabilities require immediate patching per CERT.BE
Cisco IOS and IOS XE platforms. Specific affected versions not provided in advisory. Multiple vulnerabilities of high severity impact network infrastructure devices including routers and switches running these operating systems.
highbug_reportVulnerability4,407 Rockwell PLCs exposed online; 22 in cities hit by water attacks
Rockwell Automation programmable logic controllers (PLCs) globally: 4,407 exposed devices (2,844 in US). Primary models: MicroLogix 1400 (50%) and MicroLogix 1100 (8%).
criticalbug_reportVulnerabilityCryptoJS weak RNG drained $5.7M from five crypto wallets over 12 years
CryptoJS versions below 4.0.0 (except 3.2.0 and 3.2.1). Five confirmed affected wallet apps: RRWallet (discontinued), Bexo Wallet (fixed in 20.1.0, builds pending), NanChat (fixed in 1.3.0), Bitcoin Libre (fixed in v4, July 2024), and Milo (discontin…
highbug_reportVulnerabilityApple iCloud Private Relay leaks real IP via WebKit proxy bypasses
Apple iCloud Private Relay on iOS 15+, macOS, and iPadOS. Affects Safari and all WebKit-based browsers (Chrome, Edge, Firefox, Brave) on Apple platforms. Impacts users with iCloud+ subscriptions using Private Relay for privacy protection.
highbug_reportVulnerabilityAWS, Google, Vercel agent flaws allow tool execution without model checks
Amazon Bedrock AgentCore InvokeHarness API (fixed July 31, 2026; CVE-2026-18830, CVSS 8.6), open-source Strands Python library (unpatched resume path remains), Google Agent Development Kit (ADK) for Python <2.5.0 (CVE-2026-18236, CVSS 9.3), Vercel AI…
highbug_reportVulnerabilityOracle SQL injection exploited to deploy khunt toolkit inside database
Oracle databases with Java Virtual Machine enabled, particularly those connected to public-facing Java applications (Apache Tomcat observed). Specific Oracle versions not disclosed.
highbug_reportVulnerabilityPhishing campaign exploits COLDCARD wallet fears to deploy ScreenConnect RAT
COLDCARD hardware wallet users targeted via phishing emails. Attack delivers ConnectWise ScreenConnect remote access tool via malicious batch file (Coldcard_Diagnostic_Tool.bat) hosted on GitHub.
highbug_reportVulnerabilityCISA orders 3-day patch for exploited IBM Langflow, N-central, Tomcat flaws
IBM Langflow (CVE-2026-9198, CVSS 9.8) - default deployments vulnerable to unauthenticated RCE via API endpoint chaining. N-able N-central (CVE-2026-18576) - all versions before 2026.3 allow unauthenticated admin account hijacking; incomplete patch b…
highbug_reportVulnerabilitymacOS ClickFix campaign adds fingerprinting to evade detection
macOS users targeted via 250+ algorithmically generated domains (e.g., filecopperbasket, apricotfilepoint[.]com). Campaign delivers MacSync and Atomic Stealer (AMOS) infostealers. All macOS versions susceptible to social engineering technique.
highbug_reportVulnerabilityPaperclip AI control plane flaws enable RCE via malicious agent imports
Paperclip open-source AI agent control plane, versions prior to v2026.416.0. CVE-2026-41679 (CVSS 10.0) affects network-accessible authenticated deployments with default registration.
criticalbug_reportVulnerabilityTerraform MCP, Veeam VSPC, Django patch 11 flaws including CVSS 10.0 bug
HashiCorp Terraform MCP Server versions 0.2.1–1.0.0 (Streamable HTTP mode only); Veeam Service Provider Console versions 9.2.1.33875 and earlier (all version 9 builds before 9.3); Django versions prior to 6.0.8 and 5.2.17 (GeoDjango spatial field con…
highbug_reportVulnerabilityTrojanized npm packages use blockchain to hide C2 IPs in supply chain attack
Two npm packages: "bianira-ui" (109 downloads) and "fluid-type-ui" (587 downloads), published July 28, 2026 by users "npmuser1101" and "npmuser3002". Packages now removed from npm.
criticalbug_reportVulnerabilityCritical Veeam Service Provider Console flaws require immediate patching
Veeam Service Provider Console - specific affected versions not disclosed in available information. All users running VSPC should assume exposure until vendor guidance is reviewed.
highbug_reportVulnerabilityLinux kernel Open vSwitch flaw grants local root; public exploit available
Linux kernel Open vSwitch datapath. Fixed in stable kernels 5.15.212, 6.1.178, 6.6.145, 6.12.97, 6.18.40, and 7.1.5. Affects default configurations of AlmaLinux 9/10, Alpine 3.22-3.24, Amazon Linux 2023, Arch, CentOS Stream 9/10, Debian 12/13, Fedora…
criticalbug_reportVulnerabilityGitea CVE-2026-59774: Unauthenticated file read via Org-mode markup
Gitea versions 1.22.1 through 1.27.0. Self-hosted instances with public repositories and Org-mode rendering enabled are vulnerable. Gitea Cloud instances upgraded automatically. Fixed in version 1.27.1.
criticalbug_reportVulnerabilityCredential-stealing worm compromises 400+ npm packages via auto-propagation
Over 400 npm packages across multiple unrelated publishers, including keyv, flat-cache, cache-manager, and other major enterprise software ecosystem packages. Affects developer workstations and CI/CD environments with npm lifecycle scripts enabled.
highbug_reportVulnerabilityTP-Link patches 15 Omada ZTP flaws enabling network infiltration via RCE
TP-Link Omada network devices including Controllers, Gateways, Switches, Access Points, OLT platforms, Cloud services, and mobile applications (Omada, Omada Guard, TP-Link apps). Over 1,800 internet-accessible Omada controllers identified.
highbug_reportVulnerabilityXCSSET v40 malware targets macOS developers via poisoned Xcode projects
macOS developers using Xcode and downloading projects from compromised Git/GitHub repositories. XCSSET v40 observed in attacks mid-April and early May 2026. All macOS versions with Xcode are at risk; specific version details not provided.
highbug_reportVulnerability77 malicious Open VSX extensions harvested developer environment metadata
Open VSX marketplace users who installed any of 77 counterfeit "evil twin" extensions between July 26 and August 1, 2026. Extensions impersonated legitimate tools from AMD, Azure, Salesforce, Hyperledger, LEGO Education, IOTA, and a U.S.
highbug_reportVulnerabilityGreatness PhaaS adds device code phishing to bypass MFA via OAuth abuse
Organizations using Microsoft 365, Google Workspace, iCloud, and Yahoo with OAuth 2.0 authentication. Particularly at risk: RingCentral customers targeted via spoofed voicemail lures exploiting safe sender trust configurations.
criticalbug_reportVulnerabilityChainDrop worm compromises 1,300+ npm packages with 2B monthly downloads
Over 1,300 npm packages (1,381 versions) including Keyv, Cacheable, flat-cache, and file-entry-cache. Attack originated from compromised GitHub account of Keyv maintainer.
criticalbug_reportVulnerabilitynpm worm from keyv@6.0.0 poisons 353+ packages, steals credentials via hooks
npm packages: keyv@6.0.0 and at least 353 poisoned versions across 79 package names (SafeDep verified); broader estimates reach 868 packages. Affects developers and CI/CD environments using npm clients prior to npm 12, Claude Code, and VS Code.