Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-21 · 02:09 UTC
articleTotal: 606 reports

Filtered Reports

30 / 244 results
Active filter:tag: #geopolitical✕ clear
Jacob Butler Arrested for Operating Kimwolf DDoS Botnethighperson_alertThreat Actor
person_alertThreat Actor

Jacob Butler Arrested for Operating Kimwolf DDoS Botnet

Jacob Butler, also known as "Dort," is a 23-year-old Canadian national from Ottawa arrested by the U.S. Department of Justice for developing and operating the Kimwolf DDoS botnet.

The Hacker News06:50 UTC
CISA: Langflow and Trend Micro Apex One flaws actively exploitedcriticalbug_reportVulnerability
bug_reportVulnerability

CISA: Langflow and Trend Micro Apex One flaws actively exploited

Langflow (CVE-2025-34291, CVSS 9.4, origin validation error) and Trend Micro Apex One (CVE unspecified). Both products confirmed under active exploitation. Specific affected versions not disclosed in summary.

CVE-2025-3429103:47 UTC
Dort Arrested for Operating Kimwolf IoT Botnet in Multi-Million Device DDoS Campaignhighperson_alertThreat Actor
person_alertThreat Actor

Dort Arrested for Operating Kimwolf IoT Botnet in Multi-Million Device DDoS Campaign

Dort is a 23-year-old cybercriminal based in Ottawa, Canada, suspected of developing and operating the Kimwolf IoT botnet. Motivated by launching large-scale DDoS attacks, doxing, and swatting campaigns, Dort leveraged compromised IoT devices to buil…

Krebs on Security19:50 UTC
Critical SQL injection in Drupal Core requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical SQL injection in Drupal Core requires immediate patching

Drupal Core, all versions (specific affected versions not disclosed in alert). Impacts all Drupal installations until patched.

Drupal14:42 UTC
NLnet Labs patches DoS vulnerabilities in Unbound DNS resolverhighbug_reportVulnerability
bug_reportVulnerability

NLnet Labs patches DoS vulnerabilities in Unbound DNS resolver

Unbound DNS resolver by NLnet Labs. Specific vulnerable versions not provided in advisory; patched versions available. Affects organizations running Unbound for DNS resolution services.

NLnet Labs14:21 UTC
Showboat Linux Malware Targets Middle East Telecom Since Mid-2022highperson_alertThreat Actor
person_alertThreat Actor

Showboat Linux Malware Targets Middle East Telecom Since Mid-2022

The threat actor behind Showboat remains unattributed. The campaign demonstrates sophisticated targeting of telecommunications infrastructure in the Middle East, suggesting a motivated adversary with strategic intelligence collection objectives.

The Hacker News12:17 UTC
Chinese APT Deploys Showboat and JFMBackdoor Against Telecom Sectorhighperson_alertThreat Actor
person_alertThreat Actor

Chinese APT Deploys Showboat and JFMBackdoor Against Telecom Sector

Chinese state-sponsored threat actors conducting cyber-espionage operations against telecommunications infrastructure. The actors demonstrate cross-platform capabilities with custom Linux and Windows malware tooling.

BleepingComputer12:00 UTC
Critical flaws in Sparx Pro Cloud Server actively exploited in the wildcriticalbug_reportVulnerability
bug_reportVulnerability

Critical flaws in Sparx Pro Cloud Server actively exploited in the wild

Sparx Systems Pro Cloud Server and Enterprise Architect products. Specific vulnerable versions not disclosed in summary; CERT.BE advisory should be consulted for version details.

Sparx Systems06:49 UTC
18-Year-Old Infostealer Operator Arrested for Compromising 28K Accountshighperson_alertThreat Actor
person_alertThreat Actor

18-Year-Old Infostealer Operator Arrested for Compromising 28K Accounts

An 18-year-old individual from Odesa, Ukraine, identified by Ukrainian cyberpolice in coordination with U.S. law enforcement. The operator is suspected of deploying infostealer malware to harvest credentials and compromise user accounts.

BleepingComputer19:36 UTC
PgBouncer integer overflow under active exploitation, patch immediatelycriticalbug_reportVulnerability
bug_reportVulnerability

PgBouncer integer overflow under active exploitation, patch immediately

PgBouncer (PostgreSQL connection pooler) - specific affected versions not disclosed by CERT.BE. All unpatched instances should be considered at risk.

PgBouncer12:50 UTC
Webworm Deploys EchoCreep and GraphWorm Backdoors via Discord and Graph APIhighperson_alertThreat Actor
person_alertThreat Actor

Webworm Deploys EchoCreep and GraphWorm Backdoors via Discord and Graph API

Webworm is a China-aligned advanced persistent threat (APT) actor first documented by Symantec in September 2022, with activity traced back to at least 2022.

Microsoft10:51 UTC
PostgreSQL patches multiple high-severity flaws; version 14 EOL announcedhighbug_reportVulnerability
bug_reportVulnerability

PostgreSQL patches multiple high-severity flaws; version 14 EOL announced

PostgreSQL database server, multiple versions affected by security vulnerabilities. Version 14 reaching end-of-life, no longer receiving security updates after EOL date.

PostgreSQL04:05 UTC
Critical Portainer vulnerabilities enable full host takeovercriticalbug_reportVulnerability
bug_reportVulnerability

Critical Portainer vulnerabilities enable full host takeover

Portainer container management platform. Specific affected versions not disclosed in summary; CERT.BE advisory should be consulted for version details. Impacts organizations using Portainer for Docker/Kubernetes management.

Portainer03:56 UTC
Critical nginx vulnerabilities enable RCE and rate-limit bypasscriticalbug_reportVulnerability
bug_reportVulnerability

Critical nginx vulnerabilities enable RCE and rate-limit bypass

nginx web server (specific versions not provided by CERT.BE advisory). Affects organizations running vulnerable nginx instances, particularly those exposed to the internet or untrusted networks.

nginx13:05 UTC
ABB CoreSense path traversal flaw allows unauthenticated system accesshighbug_reportVulnerability
bug_reportVulnerability

ABB CoreSense path traversal flaw allows unauthenticated system access

ABB CoreSense HM (versions prior to v2.3.4) and CoreSense M10 (versions prior to v1.4.1.31). Path traversal vulnerability affects unauthenticated remote attackers.

CVE-2025-346510:00 UTC
ScadaBR 1.2.0 critical flaws enable unauthenticated remote code executioncriticalbug_reportVulnerability
bug_reportVulnerability

ScadaBR 1.2.0 critical flaws enable unauthenticated remote code execution

ScadaBR version 1.2.0, a SCADA system used in critical infrastructure sectors including energy, water, and manufacturing worldwide. All four CVEs affect the same version.

CVE-2026-860210:00 UTC
ZKTeco CCTV cameras expose credentials via unauthenticated config portcriticalbug_reportVulnerability
bug_reportVulnerability

ZKTeco CCTV cameras expose credentials via unauthenticated config port

ZKTeco CCTV cameras, specifically model SSC335-GC2063-Face-0b77, running firmware versions prior to V5.0.1.2.20260421. Vulnerability affects an undocumented configuration export port that allows unauthenticated access to camera credentials and config…

CVE-2026-859810:00 UTC
Buffer overflow in PAN-OS User-ID portal enables unauthenticated RCEhighbug_reportVulnerability
bug_reportVulnerability

Buffer overflow in PAN-OS User-ID portal enables unauthenticated RCE

Palo Alto Networks PAN-OS on PA-Series and VM-Series firewalls; Siemens RUGGEDCOM APE1808 devices. Specific affected PAN-OS versions not provided in summary.

CVE-2026-030010:00 UTC
Microsoft Exchange Server XSS flaw actively exploited for session hijackingcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft Exchange Server XSS flaw actively exploited for session hijacking

Microsoft Exchange Server (specific versions not disclosed). Cross-Site Scripting vulnerability enabling spoofing and session hijacking. No CVE assigned yet.

Microsoft13:25 UTC
Critical PAN-OS vulnerabilities enable auth bypass and code executioncriticalbug_reportVulnerability
bug_reportVulnerability

Critical PAN-OS vulnerabilities enable auth bypass and code execution

Palo Alto Networks PAN-OS (specific versions not provided in summary). Affects authentication controls, code execution surface, and availability.

Palo Alto Networks12:43 UTC
Cisco Catalyst SD-WAN auth bypass grants admin access to attackerscriticalbug_reportVulnerability
bug_reportVulnerability

Cisco Catalyst SD-WAN auth bypass grants admin access to attackers

Cisco Catalyst SD-WAN platform. Specific affected versions not disclosed. Vulnerability allows authentication bypass leading to administrative access on SD-WAN infrastructure components.

Cisco12:16 UTC
Ivanti releases security updates for multiple productshighbug_reportVulnerability
bug_reportVulnerability

Ivanti releases security updates for multiple products

Multiple Ivanti products affected. Specific product names, versions, and CVE identifiers not disclosed in available information. High severity rating indicates significant security risk.

Ivanti07:55 UTC
Multiple critical vulnerabilities in Fortinet products require patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Multiple critical vulnerabilities in Fortinet products require patching

Fortinet products: FortiSandbox, FortiOS, FortiAP, FortiAnalyzer, and FortiManager. Specific affected versions not provided in advisory. Multiple vulnerabilities ranging from critical to medium severity.

Fortinet05:08 UTC
Code Runner MCP Server missing authentication flaw allows unauthorized accesshighbug_reportVulnerability
bug_reportVulnerability

Code Runner MCP Server missing authentication flaw allows unauthorized access

Code Runner MCP Server (all versions not specified). The vulnerability affects critical functions within the server, allowing unauthenticated access to protected operations. Specific version ranges have not been disclosed by CERT.PL.

CVE-2026-502908:55 UTC
3onedata GW1101 Modbus gateway vulnerable to OS command injectionhighbug_reportVulnerability
bug_reportVulnerability

3onedata GW1101 Modbus gateway vulnerable to OS command injection

3onedata GW1101-1D(RS-485)-TB-P Modbus gateways. Specific affected firmware versions not disclosed. These are industrial IoT devices used for Modbus protocol conversion in OT/ICS environments.

CVE-2025-1360512:55 UTC
NCSC UK Issues Guidance on China-Nexus Covert Device Networkshighperson_alertThreat Actor
person_alertThreat Actor

NCSC UK Issues Guidance on China-Nexus Covert Device Networks

China-nexus threat actors are state-sponsored groups linked to the People's Republic of China. These actors are motivated by strategic intelligence collection, espionage, and maintaining persistent access to foreign networks.

NCSC UK10:00 UTC
NCSC UK Issues Advisory on China-Linked Covert Network Tacticshighperson_alertThreat Actor
person_alertThreat Actor

NCSC UK Issues Advisory on China-Linked Covert Network Tactics

China-linked threat actors employing covert network tactics to conceal malicious cyber activity. These actors are characterized by their use of sophisticated techniques to maintain persistent, stealthy access to compromised networks.

NCSC UK10:00 UTC
UK NCSC Issues Guidance on China-Linked Covert Device NetworkshighpublicGeopolitical
publicGeopolitical

UK NCSC Issues Guidance on China-Linked Covert Device Networks

The UK National Cyber Security Centre's release of defensive guidance targeting China-nexus covert networks reflects ongoing strategic competition between Western democracies and Beijing in cyberspace.

NCSC UK10:00 UTC
Orca heat pumps lack authentication, transmit cleartext data to servershighbug_reportVulnerability
bug_reportVulnerability

Orca heat pumps lack authentication, transmit cleartext data to servers

Orca heat pumps (specific models and versions not disclosed). Vulnerability affects device-to-server communication and server-side data processing.

CVE-2026-2559903:11 UTC
MikroTik RouterOS auth bypass via certificate validation flawhighbug_reportVulnerability
bug_reportVulnerability

MikroTik RouterOS auth bypass via certificate validation flaw

MikroTik RouterOS - versions not specified. Affects OpenVPN, CAPsMAN (wireless management), and 802.1X (Dot1x) services that rely on certificate-based authentication.

CVE-2025-4261107:08 UTC