Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 321 results
Active filter:tag: #critical✕ clear
CISA orders federal agencies to patch exploited Splunk Enterprise flawcriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders federal agencies to patch exploited Splunk Enterprise flaw

Splunk Enterprise (specific versions not disclosed in summary). CISA directive targets U.S. federal agencies, but vulnerability affects all Splunk Enterprise deployments.

Splunk19 Jun · 08:39 UTC
Critical auth bypass in SimpleHelp remote support software (CVE-2026-48558)criticalbug_reportVulnerability
bug_reportVulnerability

Critical auth bypass in SimpleHelp remote support software (CVE-2026-48558)

SimpleHelp remote support software, specific versions not disclosed. Vendor patch available. Authentication bypass vulnerability allows unauthorized access.

CVE-2026-4855819 Jun · 06:46 UTC
AutoJack exploit chain enables RCE on AI agent hosts via malicious webpagecriticalbug_reportVulnerability
bug_reportVulnerability

AutoJack exploit chain enables RCE on AI agent hosts via malicious webpage

Microsoft AutoGen Studio users running AI browsing agents. Affects deployments where AutoGen Studio's MCP WebSocket is accessible to localhost without authentication. Specific version range not disclosed.

Microsoft18 Jun · 22:17 UTC
NGINX Open Source RCE via HTTP/3 use-after-free (CVE-2026-42530)criticalbug_reportVulnerability
bug_reportVulnerability

NGINX Open Source RCE via HTTP/3 use-after-free (CVE-2026-42530)

NGINX Open Source versions with ngx_http_v3_module enabled. Specific vulnerable versions not provided in summary. F5 NGINX products potentially affected.

CVE-2026-4253018 Jun · 15:32 UTC
Jenkins RCE vulnerability requires immediate patching per CERT.BEcriticalbug_reportVulnerability
bug_reportVulnerability

Jenkins RCE vulnerability requires immediate patching per CERT.BE

Jenkins (specific versions not disclosed in alert). Vulnerability enables arbitrary remote code execution. CVE identifier not yet assigned or published.

Jenkins17 Jun · 12:42 UTC
Critical vulnerability in Joomla Content Editor (JCE) requires urgent patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical vulnerability in Joomla Content Editor (JCE) requires urgent patching

Joomla Content Editor (JCE) extension for Joomla CMS. Specific affected versions not disclosed in advisory. All Joomla sites using the JCE extension should be considered at risk pending vendor confirmation.

Joomla17 Jun · 12:39 UTC
CISA orders patching of actively exploited Joomla JCE plugin flawcriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders patching of actively exploited Joomla JCE plugin flaw

Widget Factory Joomla Content Editor (JCE) plugin for Joomla CMS. Specific vulnerable versions not disclosed in provided data. Maximum severity rating indicates critical impact.

Widget Factory17 Jun · 08:09 UTC
Supply chain attack compromises 144 Mastra npm packages via hijacked accountcriticalbug_reportVulnerability
bug_reportVulnerability

Supply chain attack compromises 144 Mastra npm packages via hijacked account

144 npm packages in the @mastra/* namespace (Mastra AI framework for JavaScript/TypeScript). Attack vector: compromised npm contributor account (ehindero). All downstream projects using affected Mastra packages are potentially impacted.

Mastra17 Jun · 05:38 UTC
CISA: Widget Factory Joomla JCE flaw exploited in the wild (CVSS 10.0)criticalbug_reportVulnerability
bug_reportVulnerability

CISA: Widget Factory Joomla JCE flaw exploited in the wild (CVSS 10.0)

Widget Factory Joomla Content Editor (JCE). Specific affected versions not disclosed. Impacts Joomla CMS installations using the JCE component.

CVE-2026-4890717 Jun · 03:50 UTC
Cisco SD-WAN vulnerability under active exploitation, patches releasedcriticalbug_reportVulnerability
bug_reportVulnerability

Cisco SD-WAN vulnerability under active exploitation, patches released

Cisco SD-WAN products. Specific affected versions not provided in available data. Organizations running Cisco SD-WAN infrastructure are potentially at risk.

Cisco16 Jun · 11:40 UTC
CISA orders patch for exploited LiteSpeed cPanel plugin flaw (3-day deadline)criticalbug_reportVulnerability
bug_reportVulnerability

CISA orders patch for exploited LiteSpeed cPanel plugin flaw (3-day deadline)

LiteSpeed cPanel user-end plugin (specific versions not disclosed). Affects web hosting environments using cPanel with LiteSpeed integration. U.S. federal agencies explicitly targeted by CISA directive.

CVE-2026-5442016 Jun · 08:47 UTC
Fortinet FortiSandbox under active exploit for 3 CVEs including critical 9.1criticalbug_reportVulnerability
bug_reportVulnerability

Fortinet FortiSandbox under active exploit for 3 CVEs including critical 9.1

Fortinet FortiSandbox - specific affected versions not disclosed. Three CVEs: CVE-2026-39813 (CVSS 9.1 critical), CVE-2026-39808, CVE-2026-25089. At least one vulnerability recently patched; patch status of others unclear.

CVE-2026-2508916 Jun · 08:30 UTC
Active exploitation of critical FortiSandbox vulnerabilitiescriticalbug_reportVulnerability
bug_reportVulnerability

Active exploitation of critical FortiSandbox vulnerabilities

Fortinet FortiSandbox cyber threat detection platform. Specific versions not disclosed. No CVE assigned yet.

Fortinet16 Jun · 07:19 UTC
China-linked espionage group targets North American research networkscriticalperson_alertThreat Actor
person_alertThreat Actor

China-linked espionage group targets North American research networks

A China-linked espionage group conducted a sustained intrusion campaign lasting over one year against North American institutions. The actor's motivation appears to be intelligence collection focused on medical research, academic intellectual propert…

Google Workspace15 Jun · 17:44 UTC
Cisco Catalyst SD-WAN Manager root privilege escalation under attackcriticalbug_reportVulnerability
bug_reportVulnerability

Cisco Catalyst SD-WAN Manager root privilege escalation under attack

Cisco Catalyst SD-WAN Manager (specific versions not provided). Vulnerability allows privilege escalation to root level on affected systems.

CVE-2026-2026215 Jun · 15:12 UTC
LiteLLM AI gateway vulnerable to privilege escalation and RCEcriticalbug_reportVulnerability
bug_reportVulnerability

LiteLLM AI gateway vulnerable to privilege escalation and RCE

LiteLLM open-source AI gateway. Specific affected versions not disclosed. Impacts organizations using LiteLLM to manage API keys and route requests to AI providers (OpenAI, Anthropic, etc.).

LiteLLM15 Jun · 14:39 UTC
SearchLeak in Microsoft 365 Copilot enables data theft via crafted URLscriticalbug_reportVulnerability
bug_reportVulnerability

SearchLeak in Microsoft 365 Copilot enables data theft via crafted URLs

Microsoft 365 Copilot Enterprise. All organizations using Copilot with access to mailbox, OneDrive, or SharePoint data are potentially affected. Specific vulnerable versions not disclosed.

Microsoft15 Jun · 11:00 UTC
Supply chain attack hits PushEngage, OptinMonster, TrustPulse pluginscriticalbug_reportVulnerability
bug_reportVulnerability

Supply chain attack hits PushEngage, OptinMonster, TrustPulse plugins

WordPress sites using PushEngage, OptinMonster, and TrustPulse plugins. All versions loading compromised JavaScript files from vendor infrastructure are affected.

PushEngage15 Jun · 07:59 UTC
Chinese state-sponsored hackers maintain 10-year persistent accesscriticalperson_alertThreat Actor
person_alertThreat Actor

Chinese state-sponsored hackers maintain 10-year persistent access

Chinese state-sponsored hackers, likely an advanced persistent threat (APT) group operating on behalf of the People's Republic of China. The actor demonstrated exceptional operational security and patience, maintaining covert access to a target organ…

BleepingComputer13 Jun · 12:06 UTC
Splunk Enterprise RCE flaw allows unauthenticated remote code executioncriticalbug_reportVulnerability
bug_reportVulnerability

Splunk Enterprise RCE flaw allows unauthenticated remote code execution

Splunk Enterprise versions below 10.2.4 and 10.0.7. The vulnerability enables unauthenticated attackers to perform arbitrary file operations and achieve remote code execution. CVSS score 9.8 (Critical).

CVE-2026-2025313 Jun · 11:23 UTC
Arch User Repository supply chain attack: 400+ packages backdooredcriticalbug_reportVulnerability
bug_reportVulnerability

Arch User Repository supply chain attack: 400+ packages backdoored

Arch Linux users who installed or updated packages from the Arch User Repository (AUR) during the compromise window. Over 400 AUR packages contained malicious build scripts deploying a Rust-based infostealer.

Arch Linux12 Jun · 17:33 UTC
Velvet Ant: China-linked APT backdoors Linux auth for decade-long accesscriticalperson_alertThreat Actor
person_alertThreat Actor

Velvet Ant: China-linked APT backdoors Linux auth for decade-long access

Velvet Ant (G1047) is a China-linked advanced persistent threat actor characterized by exceptional operational security and long-term persistence capabilities.

Linux12 Jun · 16:17 UTC
400+ Arch User Repository packages compromised with rootkit and infostealercriticalbug_reportVulnerability
bug_reportVulnerability

400+ Arch User Repository packages compromised with rootkit and infostealer

Arch Linux users who installed or updated packages from the Arch User Repository (AUR). Over 400 AUR packages confirmed compromised. Specific package names and versions not yet disclosed.

Arch Linux12 Jun · 15:03 UTC
Oracle PeopleSoft RCE actively exploited, immediate patching requiredcriticalbug_reportVulnerability
bug_reportVulnerability

Oracle PeopleSoft RCE actively exploited, immediate patching required

Oracle PeopleSoft (specific versions not disclosed in alert). Remote code execution vulnerability affecting internet-facing PeopleSoft instances.

Oracle12 Jun · 12:39 UTC
LangGraph AI framework patched for critical RCE via SQL injection chaincriticalbug_reportVulnerability
bug_reportVulnerability

LangGraph AI framework patched for critical RCE via SQL injection chain

LangGraph (LangChain's open-source AI agent framework). Specific vulnerable versions not disclosed; patches available. Affects deployments using LangGraph for AI agent orchestration.

LangChain12 Jun · 07:50 UTC
CISA orders federal agencies to patch exploited Ivanti Sentry flawcriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders federal agencies to patch exploited Ivanti Sentry flaw

Ivanti Sentry (specific versions not disclosed in summary). U.S. federal agencies under BOD 26-04 mandate, but all Ivanti Sentry deployments at risk given active exploitation.

Ivanti12 Jun · 06:26 UTC
Oracle PeopleSoft zero-day CVE-2026-35273 exploited by ShinyHunterscriticalbug_reportVulnerability
bug_reportVulnerability

Oracle PeopleSoft zero-day CVE-2026-35273 exploited by ShinyHunters

Oracle PeopleSoft (all versions prior to June 10 patch). Confirmed exploitation targeting enterprise systems and universities. Vulnerability was unpatched during active exploitation window (May 27 - June 9).

CVE-2026-3527311 Jun · 18:29 UTC
Oracle PeopleSoft zero-day CVE-2026-35273 exploited for RCE by ShinyHuntercriticalbug_reportVulnerability
bug_reportVulnerability

Oracle PeopleSoft zero-day CVE-2026-35273 exploited for RCE by ShinyHunter

Oracle PeopleSoft Suite, all versions (specific affected versions not disclosed). Unauthenticated remote code execution vulnerability affecting internet-facing PeopleSoft instances.

CVE-2026-3527311 Jun · 17:39 UTC
Critical command injection flaw in Fortinet FortiSandbox requires patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical command injection flaw in Fortinet FortiSandbox requires patching

Fortinet FortiSandbox (specific versions not disclosed in available data). Command injection vulnerability allows unauthorized command execution.

Fortinet11 Jun · 12:31 UTC
Ivanti Sentry RCE flaw under active exploitation, root access possiblecriticalbug_reportVulnerability
bug_reportVulnerability

Ivanti Sentry RCE flaw under active exploitation, root access possible

Ivanti Sentry (formerly MobileIron Sentry) - Internet-exposed secure mobile gateways. Specific vulnerable versions not provided in summary, but patch recently released.

Ivanti11 Jun · 04:20 UTC