Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 358 results
criticalbug_reportVulnerabilityMicrosoft Defender zero-day 'RoguePlanet' enables SYSTEM privilege escalation
Microsoft Defender on Windows systems. Specific affected versions not disclosed. Given Defender's deployment, scope includes enterprise endpoints, servers running Defender, and consumer Windows installations with default security configuration.
criticalbug_reportVulnerabilityMicrosoft June 2026 Patch Tuesday: ~200 patches, 36 critical, 3 with PoCs
Microsoft products across the portfolio. Approximately 200 vulnerabilities patched, including ~36 critical-severity issues. At least 3 vulnerabilities have public proof-of-concept exploit code available.
highbug_reportVulnerabilityOpenClaw AI email agent vulnerable to phishing attacks
OpenClaw AI email agent (all versions). Scope: AI-powered email processing systems that handle user communications and may access sensitive user data.
criticalbug_reportVulnerabilitySAP June 2026 patches fix 4 critical flaws in NetWeaver, Commerce Cloud
SAP NetWeaver and SAP Commerce Cloud products. Total of 15 vulnerabilities patched, including 4 critical-severity issues. Specific affected versions not disclosed in summary.
highbug_reportVulnerabilityMicrosoft June 2026 Patch Tuesday: 200 flaws, 3 disclosed zero-days
Microsoft products across the ecosystem. 200 vulnerabilities patched, including 3 publicly disclosed zero-day vulnerabilities. Specific affected products and CVE identifiers not yet detailed in available information.
criticalbug_reportVulnerabilityVeeam Backup & Replication RCE flaw (CVE-2026-44963) patched, CVSS 9.4
Veeam Backup & Replication software. Specific affected versions not disclosed in available data. Requires authenticated domain user access to exploit.
highbug_reportVulnerabilityMicrosoft GitHub repos compromised, 73 disabled for distributing malware
73 repositories across Microsoft's official GitHub organizations (Azure, microsoft, Azure-Samples, MicrosoftDocs). Organizations using Microsoft sample code, Azure templates, or CI/CD pipelines referencing these repositories are potentially affected.
criticalbug_reportVulnerabilitySAP releases critical patches for multiple products
Multiple SAP products affected. Specific product names and versions not disclosed in available information. Patches released by SAP to address critical-severity vulnerabilities.
highbug_reportVulnerabilityWinRAR CVE-2025-8088 path traversal exploited by Russian APTs vs Ukraine
WinRAR versions prior to patched release (approximately one year old). Primary targets: Ukrainian organizations. Threat actors: Earth Dahu (Gamaredon) and SHADOW-EARTH-066 (UAC-0226), Russia-aligned APT groups.
criticalbug_reportVulnerabilityCheck Point VPN authentication flaw under active exploitation
Check Point VPN products with user authentication functionality. Specific affected versions not disclosed. CVE identifier not yet assigned.
criticalbug_reportVulnerabilityChrome V8 zero-day CVE-2026-11645 exploited in wild, patch immediately
Google Chrome versions prior to 149.0.7827.103 on all platforms. The vulnerability resides in the V8 JavaScript engine, affecting out-of-bounds memory access.
FROST attack enables website-based user tracking via SSD timing analysis
All systems with SSDs accessed via web browsers supporting high-resolution JavaScript timers. Attack affects users across Windows, Linux, and macOS platforms. No specific browser, SSD model, or OS version is immune.
highbug_reportVulnerabilityPyPI supply chain attack: 19 packages with auto-executing credential stealer
PyPI repository: 19 compromised packages containing 37 malicious wheel artifacts. Affects Python developers who installed these packages. Attack uses .pth files for automatic execution during pip install, targeting credential theft via Bun-based stea…
highbug_reportVulnerabilityBerriAI LiteLLM command injection under active exploitation (CISA KEV)
BerriAI LiteLLM - specific vulnerable versions not disclosed in summary. Command injection vulnerability (CVE-2026-42271) affects authenticated users with access to the system.
highbug_reportVulnerabilityNFCShare Android malware distributed via GitHub as fake banking app updates
Android mobile users, particularly customers of targeted banking applications. Malware distributed through GitHub repositories posing as legitimate banking app updates.
highbug_reportVulnerabilityPyPI supply-chain attack: 19 science packages compromised with malware
19 science-focused Python packages on PyPI, collectively downloaded hundreds of thousands of times. Specific package names and versions not disclosed in summary. Affects Python developers using PyPI packages in scientific/research workflows.
criticalbug_reportVulnerabilityLinux kernel nf_tables use-after-free enables root escalation (CVE-2026-23111)
Linux kernel nf_tables subsystem. All distributions using vulnerable kernel versions prior to the February 5, 2026 patch. Affects systems where unprivileged users have local access or container environments.
criticalbug_reportVulnerabilityGogs patches critical RCE zero-day affecting Internet-facing instances
Gogs Git service, Internet-facing instances (specific vulnerable versions not disclosed). All repositories including private repos accessible post-exploitation.
criticalbug_reportVulnerabilityUbiquiti UniFi OS vulnerable to RCE via chained patched vulnerabilities
Ubiquiti UniFi OS server (specific versions not provided). Vulnerability chain affects systems running outdated UniFi OS versions containing three previously patched flaws.
highbug_reportVulnerabilityThree high-severity XSS flaws in VMware Telco Cloud and Aria Operations
VMware Telco Cloud/vSphere Foundation and VMware Aria Operations. Specific affected versions not provided in advisory; consult VMware security bulletin for version details.
criticalbug_reportVulnerabilitySolarWinds Serv-U actively exploited for resource exhaustion attacks
SolarWinds Serv-U file transfer software, unpatched versions. Specific vulnerable version range not disclosed in summary. CVE identifier not yet assigned.
criticalbug_reportVulnerabilityCheck Point VPN auth bypass under active exploit via IKEv1 flaw
Check Point Remote Access VPN and Mobile Access deployments using deprecated IKEv1 protocol. Specific product versions not disclosed. Does not affect IKEv2 configurations.
criticalbug_reportVulnerabilityCheck Point patches zero-day in VPN/Mobile Access exploited by Qilin
Check Point Remote Access VPN and Mobile Access deployments. Specific product versions not disclosed in summary; refer to vendor advisory for affected releases and patched versions.
criticalbug_reportVulnerabilityCritical vulnerability in MISP requires immediate patching
MISP (Malware Information Sharing Platform) - specific versions not disclosed in advisory. All unpatched instances potentially affected.
highbug_reportVulnerabilityGafgyt C0XMO botnet exploits DD-WRT router flaw, kills rival malware
DD-WRT router firmware (specific versions not disclosed). Affects devices across multiple CPU architectures. No CVE assigned yet.
criticalbug_reportVulnerabilityEverest Forms Pro WordPress plugin under active exploit for site takeover
Everest Forms Pro plugin for WordPress. Specific affected versions not disclosed. All WordPress sites running this premium plugin are potentially at risk.
highbug_reportVulnerabilitySolarWinds Serv-U DoS flaw actively exploited, added to CISA KEV
SolarWinds Serv-U multi-protocol file server. Specific affected versions not disclosed in provided data. The vulnerability causes service crashes via denial-of-service attacks.
highbug_reportVulnerabilityAI finds 21 zero-days in FFmpeg; Chrome 149 patches 429 bugs
FFmpeg media library (all versions prior to upcoming patch release); Google Chrome versions prior to 149 (all platforms). FFmpeg is embedded in countless applications, browsers, media players, and server-side processing pipelines.
highbug_reportVulnerabilityMiasma worm compromises 73 Microsoft GitHub repos in supply chain attack
73 Microsoft GitHub repositories across four organizations: Azure, Azure-Samples, Microsoft, and MicrosoftDocs. GitHub has disabled access to affected repositories.
highbug_reportVulnerabilityCisco Catalyst SD-WAN Manager CVE-2026-20245 exploited in wild, no patch
Cisco Catalyst SD-WAN Manager across all deployment types: On-Prem, Cloud-Pro, Cloud (Cisco Managed), and Government (FedRAMP). Specific affected versions not disclosed. CVSS 7.8 (High).