Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 675 results
highbug_reportVulnerabilityPalo Alto NOVA AI system discovers 14,090 unreported OSS vulnerabilities
3,915 open-source software projects across six ecosystems (Go, JavaScript/TypeScript, PHP, C/C++, Java/JVM, Ruby/Python/Lua/Perl). 99.4% of 14,090 vulnerabilities were previously unreported; 40% rated high or critical severity.
highbug_reportVulnerabilityGoogle removes ADK workflows after prompt injection exposed CI credentials
Google Agent Development Kit (ADK) Python repository on GitHub. Three workflows removed: issue-analyze.yml, issue-fix.yml, and pr-analyze.yml. Affected repository automation infrastructure, not the distributed ADK Python package itself.
highbug_reportVulnerabilitycPanel SQL privilege escalation lets hosting customers run commands as root
cPanel & WHM all supported versions prior to 11.110.0.137, 11.118.0.71, 11.126.0.78, 11.134.0.48, 11.136.0.32, and WP Squared prior to 138.1.6. Requires authenticated cPanel account with MySQL/MariaDB feature access.
highbug_reportVulnerabilityN-able N-central auth bypass exploited; CISA orders patch by Aug 6
N-able N-central versions prior to 2026.3 HF1. CVE-2026-18577 (CVSS 8.2) is an incomplete patch for CVE-2026-18556. Affects on-premises N-central servers with remote management capabilities.
highbug_reportVulnerabilityMalware can hijack Google Password Manager passkeys on Windows via TPM abuse
Google Password Manager synced passkeys on Chrome for Windows with TPM. All three attacks require pre-existing malware on the victim's Windows device. Services that do not properly validate user verification flags (e.g., eBay, now patched) are vulner…
highbug_reportVulnerabilityFake Xeno Executor installers infect Roblox players with RAT malware
Roblox players downloading fake Xeno Executor script launcher installers from gaming forums, Discord communities, and compromised accounts. Campaign active since January 2026 with sharp increase in March.
highbug_reportVulnerability18 malicious npm packages deliver cross-platform RAT to Alibaba developers
18 npm packages targeting Alibaba developer tool users, primarily Chinese-speaking environments. Key packages: lib-mtop (v1.0.1-1.0.3), aone-kit, aone-kit-cli, aone-sandbox, local-config-parser, smart-config-manager, and 12 others.
highbug_reportVulnerabilityN-able N-central auth bypass exploited; affects all pre-2026.3 versions
N-able N-central RMM platform, all versions prior to 2026.3. Affects both hosted and on-premises deployments. Hosted instances patched automatically; on-premises require manual hotfix 2026.3.1.7 installation.
highbug_reportVulnerabilityChrome Password Manager passkey bypass allows malware to hijack accounts
Google Chrome Password Manager on Windows systems with TPM. All three attack paths require malware already running as an ordinary user. Specific affected Chrome versions not disclosed.
highbug_reportVulnerabilityBTMOB Android RAT ecosystem fragments into resellers and source-code sales
Organizations and individuals targeted by BTMOB Android RAT malware-as-a-service (MaaS). BTMOB is an Android remote access trojan distributed through multiple channels including official operators, resellers, and source-code buyers.
criticalbug_reportVulnerabilityN-Central actively exploited vulnerability requires immediate patching
N-Central remote monitoring and management (RMM) platform. Specific affected versions not disclosed in available advisory. CVE identifier not yet assigned or published.
highbug_reportVulnerabilityPasskey auth bypass via User Verified flag validation gap in relying parties
Relying parties (websites/services) implementing passkey authentication that fail to validate the User Verified (UV) flag in WebAuthn assertions. Affects passwordless authentication systems across multiple platforms.
highbug_reportVulnerabilityThermo Fisher patches DNA analysis file tampering flaw in forensic software
Thermo Fisher Applied Biosystems human identification software: 3500/3500xL Series Data Collection ≤4.0.2, 3730/3730xL Series ≤5.0.2, SeqStudio Genetic Analyzer ≤1.2.5, SeqStudio Flex ≤1.2.0, GeneMapper ID-X ≤v1.7.3.
criticalbug_reportVulnerabilityN-able N-central auth bypass exploited; incomplete patch requires upgrade
N-able N-central builds prior to 2026.3.1.7. All versions before the August 2 emergency hotfix are vulnerable. Affects MSPs and IT teams using N-central for remote monitoring and management of customer endpoints.
highbug_reportVulnerabilityHugging Face Diffusers RCE flaws bypass trust_remote_code safeguard
Hugging Face Diffusers library versions prior to 0.38.0. Affects any user invoking DiffusionPipeline.from_pretrained with custom pipelines. The library has over 8.1 million downloads monthly and is widely embedded in enterprise AI production pipeline…
criticalbug_reportVulnerabilityCOLDCARD wallet RNG flaw exploited to steal $88.6M in Bitcoin
COLDCARD hardware wallets: Mk2/Mk3 firmware 4.0.1-4.1.9, Mk4/Mk5 before 5.6.0 (standard) or 6.6.0X (Edge), Q devices before 1.5.0Q (standard) or 6.6.0QX (Edge). Seeds generated using the flawed RNG are compromised.
criticalbug_reportVulnerabilityColdcard wallet PRNG flaw enabled $70M Bitcoin theft in 41 minutes
Coldcard hardware wallets (Coinkite): Mk2 and Mk3 firmware 4.0.0–4.1.9 (fixed in 4.2.0); Mk4 and Mk5 before 5.6.0; Q model before 1.5.0Q; Edge builds before 6.6.0X (Mk4/Mk5) and 6.6.0QX (Q).
criticalbug_reportVulnerabilityRails Active Storage flaw enables file read and RCE by unauthenticated users
Ruby on Rails applications using the Active Storage framework. Specific vulnerable versions not provided in available data. Patched versions released by Rails team.
highbug_reportVulnerabilityAdform supply chain attack injected crypto wallet swapper into customer sites
Adform advertising platform customers; specifically the trackpoint-async.js file served from s2.adform[.]net. Sites embedding this tracking script were affected on July 27, 2026 (confirmed date), with reports suggesting possible exposure up to one we…
criticalbug_reportVulnerabilityAdobe Campaign Classic CVSS 10.0 flaw allows code execution without interaction
Adobe Campaign Classic (ACC) v7 versions prior to 7.4.3 build 9398 on Windows and Linux. The vulnerability affects the enterprise marketing automation platform used for customer campaign management.
highbug_reportVulnerabilityArch Linux disables AUR package adoption after malicious takeovers
Arch Linux Arch User Repository (AUR) - all community-maintained packages. Users who installed or updated AUR packages during the compromise window are potentially affected. Scope limited to AUR; official Arch repositories unaffected.
highbug_reportVulnerabilityAdform ad platform compromised to inject crypto-stealing clipboard scripts
Adform ad platform and all websites embedding Adform advertising scripts. Any site visitor copying cryptocurrency wallet addresses during the compromise window was at risk of clipboard hijacking.
highbug_reportVulnerabilityCISA warns of rising attacks on internet-exposed PLCs in water systems
Internet-exposed programmable logic controllers (PLCs) in U.S. water and wastewater systems. Specific vendors and models not disclosed in available information.
criticalbug_reportVulnerabilityAdobe Campaign Classic critical RCE and file read flaws require patching
Adobe Campaign Classic (specific versions not disclosed in advisory). Two vulnerabilities: one critical severity enabling arbitrary code execution, one high severity allowing file system read access.
criticalbug_reportVulnerabilityCritical vCenter vulnerabilities require immediate patching
VMware vCenter Server component across multiple VMware product deployments. Specific affected versions not provided in advisory. Widespread impact expected given vCenter's role in VMware infrastructure management.
highbug_reportVulnerabilityChrome 149–151 fix 1,442 flaws as AI-driven bug discovery outpaces patching
Google Chrome versions 149, 150, and 151 (released June–July 2026). All prior Chrome versions are affected by the resolved vulnerabilities. One critical flaw (CVE-2026-3545, CVSS 9.6) is a 13-year-old sandbox escape in Navigation component, patched i…
highbug_reportVulnerability84 flaws in 4G/5G core networks enable DoS and session hijacking
4G and 5G core network implementations: Open5GS (LTE/5G), free5GC, OpenAirInterface (LTE/5G), SD-Core, and eUPF. Vulnerabilities affect GTP-C and PFCP signaling protocols. 83 of 84 flaws confirmed, 81 assigned CVE identifiers.
criticalbug_reportVulnerabilityCisco Secure Firewall Management Center under active exploitation
Cisco Secure Firewall Management Center (formerly Firepower Management Center). Specific affected versions not disclosed in available data. Vulnerability details including CVE identifier not yet published.
criticalbug_reportVulnerabilityJetBrains TeamCity auth bypass enables RCE on all on-premises versions
JetBrains TeamCity On-Premises, all versions prior to 2025.11.7 and 2026.1.3. TeamCity Cloud is not affected. CVE-2026-63077 allows authentication bypass via agent polling protocol over HTTPS, leading to remote code execution with server process priv…
highbug_reportVulnerabilityNorth Korea-linked actors compromise npm packages debug, chalk, axios
Node Package Manager (npm) ecosystem: typo-crypto (March 2025), debug and chalk (September 2025, ~10% of cloud environments affected within 2 hours), axios (March 2026, 100M+ weekly downloads).