Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
satellite_altDaily BriefCyber Threat Daily Brief — July 21, 2026
Today's briefing: 3 critical and 16 high-severity threats. A total of 23 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.
Latest Reports
26 / 606 results
highbug_reportVulnerabilityWhatsApp malware campaign uses fake business docs to deploy VBScript RATs
WhatsApp users across multiple countries. Attack vector: social engineering via WhatsApp messages containing malicious VBScript files disguised as business documents. Enables remote access to Windows PCs.
highbug_reportVulnerabilityCloud bucket hijacking flaw exploits global namespace across AWS, Azure, GCP
AWS S3, Azure Blob Storage, and Google Cloud Storage bucket naming systems. Affects organizations using cloud storage services across all three major cloud providers.
FFmpeg 'PixelSmash' flaw enables RCE on Jellyfin, DoS on multiple apps
FFmpeg (version details not specified). Downstream impact: Jellyfin (remote code execution), Kodi, Emby, Nextcloud, PhotoPrism, OBS Studio (denial-of-service). Affects media processing and streaming applications using vulnerable FFmpeg libraries.
highperson_alertThreat ActorFortiBleed Campaign Targets FortiGate Devices with Credential Sniffers
FortiBleed is a campaign-level designation for coordinated activity targeting Fortinet FortiGate network security appliances. The campaign's primary objective is credential harvesting through the deployment of custom sniffers on compromised firewalls…
highbug_reportVulnerabilityShapedPlugin WordPress Pro plugins backdoored via compromised update channel
Multiple ShapedPlugin Pro WordPress plugins distributed through official licensed update channels. Exact plugin names and affected versions not specified.
highbug_reportVulnerabilityMicrosoft patches AutoJack vulnerability chain in AutoGen Studio
Microsoft AutoGen Studio - all versions prior to the patched release. AutoGen Studio is a low-code interface for building and managing AI agents. The vulnerability chain affects users who interact with untrusted web content while AutoGen Studio is ru…
highbug_reportVulnerabilityDifyTap flaws enable cross-tenant AI conversation theft in Dify platform
Dify open-source agentic workflow platform. Specific affected versions not disclosed. Vulnerability enables cross-tenant data access, affecting multi-tenant deployments and cloud-hosted instances.
highbug_reportVulnerabilityDual ransomware actors operate simultaneously in Microsoft environments
Organizations using Microsoft environments, particularly those with insufficient network segmentation and endpoint visibility. No specific product vulnerability; threat involves operational security gaps enabling parallel intrusions.
criticalbug_reportVulnerabilityCritical RCE and XSS flaws in pgAdmin 4 enable credential theft
pgAdmin 4 (specific vulnerable versions not provided in alert). pgAdmin is a web-based administration tool for PostgreSQL databases, commonly deployed in enterprise environments for database management.
criticalbug_reportVulnerabilityProxySQL ACL bypass and heap corruption flaws threaten database security
ProxySQL (specific versions not provided). Vulnerabilities include ACL bypass allowing unauthorized access and heap memory corruption potentially enabling remote code execution. Database proxy infrastructure is at risk.
highbug_reportVulnerability29-year-old Squid heap over-read leaks HTTP credentials in default config
Squid web proxy, all versions containing FTP parsing code from 1997 onward. Vulnerability present in default configuration. Affects organizations using Squid as forward or reverse proxy.
highperson_alertThreat ActorRussian-speaking actor deploys OXLOADER to distribute CastleStealer
The threat actor is a Russian-speaking, financially motivated cybercrime operator leveraging malicious advertising infrastructure for initial access. The actor demonstrates capability in developing or acquiring custom malware tooling, including the p…
highperson_alertThreat ActorAryStinger Malware Infects 4,300+ Routers for Recon Operations
AryStinger is a newly discovered malware family identified by QiAnXin's XLab threat research team. Unlike traditional DDoS botnets, AryStinger is purpose-built for pre-attack reconnaissance and distributed proxy operations.
highbug_reportVulnerabilityAryStinger botnet compromises 4,000+ legacy D-Link routers as proxies
Over 4,000 outdated D-Link routers worldwide, specifically legacy models no longer receiving security updates. Exact models not specified in available data.
highperson_alertThreat ActorPrinz Eugen ransomware targets recently modified files, omits ransom note
Prinz Eugen is a newly identified ransomware family characterized by unconventional operational tactics. Unlike traditional ransomware operations that encrypt files indiscriminately and leave detailed ransom notes, Prinz Eugen employs a selective enc…
highbug_reportVulnerabilityNorth Korean APT compromised 140+ npm packages via Mastra AI framework
Mastra AI framework and over 140 dependent npm packages. Organizations using Mastra AI or downstream dependencies in Node.js/JavaScript applications are affected.
highbug_reportVulnerabilityUnit 42 issues guidance on large-scale credential attack campaigns
Organizations using security vendor devices targeted in recent credential-based attack campaigns. No specific CVE; threat involves coordinated credential compromise attempts across multiple vendors' products.
highperson_alertThreat ActorIcarus Extortion Group Breaches Klue, Steals Salesforce OAuth Tokens
Icarus is an extortion-focused threat actor that has publicly claimed responsibility for breaching the market intelligence platform Klue. The group's motivation appears to be financially driven, targeting SaaS and market intelligence platforms to ste…
highbug_reportVulnerabilityGravity SMTP WordPress plugin under active exploit for info disclosure
Gravity SMTP WordPress plugin, affecting approximately 100,000 websites. Specific vulnerable versions not disclosed in available data.
criticalbug_reportVulnerabilityUnpatchable SecureROM exploit for Apple A12/A13 chips published
Apple devices with A12 and A13 chips (iPhone XS/XR/11 series, iPad Air 3rd gen, iPad mini 5th gen, iPad 8th gen). SecureROM vulnerability is permanent and cannot be patched via software updates.
highperson_alertThreat ActorGentlemen RaaS Deploys GentleKiller EDR Evasion Framework
Gentlemen is a ransomware-as-a-service (RaaS) operation that provides infrastructure, tooling, and support to affiliate threat actors. The group actively develops and distributes specialized frameworks to enhance affiliate success rates, including th…
highpublicGeopoliticalTexas Parks and Wildlife vendor breach exposes 3M+ records
The breach at a Texas state agency vendor underscores persistent vulnerabilities in third-party supply chains supporting U.S. public administration. While no attribution has been disclosed, the exposure of driver's license data and personally identif…
criticalbug_reportVulnerabilityCritical RCE in Splunk Enterprise under active exploitation
Splunk Enterprise (specific versions not disclosed in alert). The vulnerability enables remote code execution. CVE identifier not yet assigned or published.
highbug_reportVulnerabilityAutoJack exploit chain enables RCE on AI browsing agents via malicious pages
AI browsing agents (autonomous web browsers with AI capabilities) that interact with privileged local services via JavaScript. Specific products and versions not disclosed in Microsoft's research disclosure.
highperson_alertThreat ActorSocGholish Infrastructure Disrupted in Operation Endgame Takedown
SocGholish is a threat actor known for compromising web infrastructure, particularly WordPress-based content management systems, to facilitate malware distribution and drive-by download attacks.
highperson_alertThreat ActorRussian-speaking actors compromise 86,644 FortiGate devices via FortiBleed
Russian-speaking threat actors are conducting the FortiBleed campaign, targeting internet-accessible FortiGate appliances at scale. The actors' specific motivation remains unclear from available data, though the mass compromise of 86,644 devices sugg…