Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-21 · 02:09 UTC
articleTotal: 606 reports
Cyber Threat Daily Brief — July 21, 2026satellite_altDaily Brief
Threat Intel Brief·Daily Summary

Cyber Threat Daily Brief — July 21, 2026

Today's briefing: 3 critical and 16 high-severity threats. A total of 23 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.

3 Critical16 High23 analyses
schedule02:09 UTC
Read briefarrow_forward

Latest Reports

26 / 606 results
WhatsApp malware campaign uses fake business docs to deploy VBScript RATshighbug_reportVulnerability
bug_reportVulnerability

WhatsApp malware campaign uses fake business docs to deploy VBScript RATs

WhatsApp users across multiple countries. Attack vector: social engineering via WhatsApp messages containing malicious VBScript files disguised as business documents. Enables remote access to Windows PCs.

BleepingComputer20:42 UTC
Cloud bucket hijacking flaw exploits global namespace across AWS, Azure, GCPhighbug_reportVulnerability
bug_reportVulnerability

Cloud bucket hijacking flaw exploits global namespace across AWS, Azure, GCP

AWS S3, Azure Blob Storage, and Google Cloud Storage bucket naming systems. Affects organizations using cloud storage services across all three major cloud providers.

Amazon Web Services20:00 UTC
FFmpeg 'PixelSmash' flaw enables RCE on Jellyfin, DoS on multiple appshighbug_reportVulnerability
bug_reportVulnerability

FFmpeg 'PixelSmash' flaw enables RCE on Jellyfin, DoS on multiple apps

FFmpeg (version details not specified). Downstream impact: Jellyfin (remote code execution), Kodi, Emby, Nextcloud, PhotoPrism, OBS Studio (denial-of-service). Affects media processing and streaming applications using vulnerable FFmpeg libraries.

FFmpeg19:05 UTC
FortiBleed Campaign Targets FortiGate Devices with Credential Sniffershighperson_alertThreat Actor
person_alertThreat Actor

FortiBleed Campaign Targets FortiGate Devices with Credential Sniffers

FortiBleed is a campaign-level designation for coordinated activity targeting Fortinet FortiGate network security appliances. The campaign's primary objective is credential harvesting through the deployment of custom sniffers on compromised firewalls…

Fortinet18:01 UTC
ShapedPlugin WordPress Pro plugins backdoored via compromised update channelhighbug_reportVulnerability
bug_reportVulnerability

ShapedPlugin WordPress Pro plugins backdoored via compromised update channel

Multiple ShapedPlugin Pro WordPress plugins distributed through official licensed update channels. Exact plugin names and affected versions not specified.

ShapedPlugin16:00 UTC
Microsoft patches AutoJack vulnerability chain in AutoGen Studiohighbug_reportVulnerability
bug_reportVulnerability

Microsoft patches AutoJack vulnerability chain in AutoGen Studio

Microsoft AutoGen Studio - all versions prior to the patched release. AutoGen Studio is a low-code interface for building and managing AI agents. The vulnerability chain affects users who interact with untrusted web content while AutoGen Studio is ru…

Microsoft15:28 UTC
DifyTap flaws enable cross-tenant AI conversation theft in Dify platformhighbug_reportVulnerability
bug_reportVulnerability

DifyTap flaws enable cross-tenant AI conversation theft in Dify platform

Dify open-source agentic workflow platform. Specific affected versions not disclosed. Vulnerability enables cross-tenant data access, affecting multi-tenant deployments and cloud-hosted instances.

Dify14:13 UTC
Dual ransomware actors operate simultaneously in Microsoft environmentshighbug_reportVulnerability
bug_reportVulnerability

Dual ransomware actors operate simultaneously in Microsoft environments

Organizations using Microsoft environments, particularly those with insufficient network segmentation and endpoint visibility. No specific product vulnerability; threat involves operational security gaps enabling parallel intrusions.

Microsoft14:00 UTC
Critical RCE and XSS flaws in pgAdmin 4 enable credential theftcriticalbug_reportVulnerability
bug_reportVulnerability

Critical RCE and XSS flaws in pgAdmin 4 enable credential theft

pgAdmin 4 (specific vulnerable versions not provided in alert). pgAdmin is a web-based administration tool for PostgreSQL databases, commonly deployed in enterprise environments for database management.

pgAdmin13:02 UTC
ProxySQL ACL bypass and heap corruption flaws threaten database securitycriticalbug_reportVulnerability
bug_reportVulnerability

ProxySQL ACL bypass and heap corruption flaws threaten database security

ProxySQL (specific versions not provided). Vulnerabilities include ACL bypass allowing unauthorized access and heap memory corruption potentially enabling remote code execution. Database proxy infrastructure is at risk.

ProxySQL12:48 UTC
29-year-old Squid heap over-read leaks HTTP credentials in default confighighbug_reportVulnerability
bug_reportVulnerability

29-year-old Squid heap over-read leaks HTTP credentials in default config

Squid web proxy, all versions containing FTP parsing code from 1997 onward. Vulnerability present in default configuration. Affects organizations using Squid as forward or reverse proxy.

Squid12:29 UTC
Russian-speaking actor deploys OXLOADER to distribute CastleStealerhighperson_alertThreat Actor
person_alertThreat Actor

Russian-speaking actor deploys OXLOADER to distribute CastleStealer

The threat actor is a Russian-speaking, financially motivated cybercrime operator leveraging malicious advertising infrastructure for initial access. The actor demonstrates capability in developing or acquiring custom malware tooling, including the p…

Google11:20 UTC
AryStinger Malware Infects 4,300+ Routers for Recon Operationshighperson_alertThreat Actor
person_alertThreat Actor

AryStinger Malware Infects 4,300+ Routers for Recon Operations

AryStinger is a newly discovered malware family identified by QiAnXin's XLab threat research team. Unlike traditional DDoS botnets, AryStinger is purpose-built for pre-attack reconnaissance and distributed proxy operations.

Legacy Router Manufacturers04:57 UTC
AryStinger botnet compromises 4,000+ legacy D-Link routers as proxieshighbug_reportVulnerability
bug_reportVulnerability

AryStinger botnet compromises 4,000+ legacy D-Link routers as proxies

Over 4,000 outdated D-Link routers worldwide, specifically legacy models no longer receiving security updates. Exact models not specified in available data.

D-Link12:14 UTC
Prinz Eugen ransomware targets recently modified files, omits ransom notehighperson_alertThreat Actor
person_alertThreat Actor

Prinz Eugen ransomware targets recently modified files, omits ransom note

Prinz Eugen is a newly identified ransomware family characterized by unconventional operational tactics. Unlike traditional ransomware operations that encrypt files indiscriminately and leave detailed ransom notes, Prinz Eugen employs a selective enc…

BleepingComputer13:23 UTC
North Korean APT compromised 140+ npm packages via Mastra AI frameworkhighbug_reportVulnerability
bug_reportVulnerability

North Korean APT compromised 140+ npm packages via Mastra AI framework

Mastra AI framework and over 140 dependent npm packages. Organizations using Mastra AI or downstream dependencies in Node.js/JavaScript applications are affected.

Mastra AI12:09 UTC
Unit 42 issues guidance on large-scale credential attack campaignshighbug_reportVulnerability
bug_reportVulnerability

Unit 42 issues guidance on large-scale credential attack campaigns

Organizations using security vendor devices targeted in recent credential-based attack campaigns. No specific CVE; threat involves coordinated credential compromise attempts across multiple vendors' products.

Unit 42 (Palo Alto)00:05 UTC
Icarus Extortion Group Breaches Klue, Steals Salesforce OAuth Tokenshighperson_alertThreat Actor
person_alertThreat Actor

Icarus Extortion Group Breaches Klue, Steals Salesforce OAuth Tokens

Icarus is an extortion-focused threat actor that has publicly claimed responsibility for breaching the market intelligence platform Klue. The group's motivation appears to be financially driven, targeting SaaS and market intelligence platforms to ste…

Klue20:31 UTC
Gravity SMTP WordPress plugin under active exploit for info disclosurehighbug_reportVulnerability
bug_reportVulnerability

Gravity SMTP WordPress plugin under active exploit for info disclosure

Gravity SMTP WordPress plugin, affecting approximately 100,000 websites. Specific vulnerable versions not disclosed in available data.

Gravity SMTP18:25 UTC
Unpatchable SecureROM exploit for Apple A12/A13 chips publishedcriticalbug_reportVulnerability
bug_reportVulnerability

Unpatchable SecureROM exploit for Apple A12/A13 chips published

Apple devices with A12 and A13 chips (iPhone XS/XR/11 series, iPad Air 3rd gen, iPad mini 5th gen, iPad 8th gen). SecureROM vulnerability is permanent and cannot be patched via software updates.

Apple16:37 UTC
Gentlemen RaaS Deploys GentleKiller EDR Evasion Frameworkhighperson_alertThreat Actor
person_alertThreat Actor

Gentlemen RaaS Deploys GentleKiller EDR Evasion Framework

Gentlemen is a ransomware-as-a-service (RaaS) operation that provides infrastructure, tooling, and support to affiliate threat actors. The group actively develops and distributes specialized frameworks to enhance affiliate success rates, including th…

The Hacker News16:33 UTC
Texas Parks and Wildlife vendor breach exposes 3M+ recordshighpublicGeopolitical
publicGeopolitical

Texas Parks and Wildlife vendor breach exposes 3M+ records

The breach at a Texas state agency vendor underscores persistent vulnerabilities in third-party supply chains supporting U.S. public administration. While no attribution has been disclosed, the exposure of driver's license data and personally identif…

BleepingComputer14:12 UTC
Critical RCE in Splunk Enterprise under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Critical RCE in Splunk Enterprise under active exploitation

Splunk Enterprise (specific versions not disclosed in alert). The vulnerability enables remote code execution. CVE identifier not yet assigned or published.

Splunk13:33 UTC
AutoJack exploit chain enables RCE on AI browsing agents via malicious pageshighbug_reportVulnerability
bug_reportVulnerability

AutoJack exploit chain enables RCE on AI browsing agents via malicious pages

AI browsing agents (autonomous web browsers with AI capabilities) that interact with privileged local services via JavaScript. Specific products and versions not disclosed in Microsoft's research disclosure.

Microsoft13:30 UTC
SocGholish Infrastructure Disrupted in Operation Endgame Takedownhighperson_alertThreat Actor
person_alertThreat Actor

SocGholish Infrastructure Disrupted in Operation Endgame Takedown

SocGholish is a threat actor known for compromising web infrastructure, particularly WordPress-based content management systems, to facilitate malware distribution and drive-by download attacks.

WordPress13:07 UTC
Russian-speaking actors compromise 86,644 FortiGate devices via FortiBleedhighperson_alertThreat Actor
person_alertThreat Actor

Russian-speaking actors compromise 86,644 FortiGate devices via FortiBleed

Russian-speaking threat actors are conducting the FortiBleed campaign, targeting internet-accessible FortiGate appliances at scale. The actors' specific motivation remains unclear from available data, though the mass compromise of 86,644 devices sugg…

Fortinet12:00 UTC