Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports
Cyber Threat Daily Brief — September 4, 2026satellite_altDaily Brief
Threat Intel Brief·Daily Summary

Cyber Threat Daily Brief — September 4, 2026

Today's briefing: 14 critical and 22 high-severity threats. A total of 47 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.

14 Critical22 High47 analyses
schedule02:17 UTC
Read briefarrow_forward

Latest Reports

26 / 1172 results
Evooo1Bot: Mirai-based botnet targets Linux gateways as SOCKS5 proxieshighbug_reportVulnerability
bug_reportVulnerability

Evooo1Bot: Mirai-based botnet targets Linux gateways as SOCKS5 proxies

Internet-facing Linux gateway devices (routers, firewalls, edge appliances). Specific vendors and models not disclosed. Mirai-based malware with modular architecture targeting devices with weak credentials or known vulnerabilities.

BleepingComputer15 Aug · 12:14 UTC
SAP Commerce Cloud CVE-2026-58231 under active exploit, 3 days post-patchcriticalbug_reportVulnerability
bug_reportVulnerability

SAP Commerce Cloud CVE-2026-58231 under active exploit, 3 days post-patch

SAP Commerce Cloud, all versions prior to patched release levels. Vulnerability affects default authentication clients and endpoints lacking input validation. Unauthenticated remote exploitation possible.

CVE-2026-5823115 Aug · 06:38 UTC
€30M Bank Fraud via Service Provider Exploit Targets Commerzbankhighperson_alertThreat Actor
person_alertThreat Actor

€30M Bank Fraud via Service Provider Exploit Targets Commerzbank

An unknown cybercriminal group, financially motivated, conducted a coordinated bank fraud operation targeting Commerzbank customers. The group operated across multiple jurisdictions, with four members arrested in Brazil and three charged in Europe.

Commerzbank14 Aug · 16:04 UTC
macOS Screen Sharing auth bypass exploited to deploy Monero minershighbug_reportVulnerability
bug_reportVulnerability

macOS Screen Sharing auth bypass exploited to deploy Monero miners

macOS Screen Sharing feature on systems with TCP port 5900 exposed to the internet. Fixed in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. CVE-2026-65400 affects earlier versions of these releases.

Apple14 Aug · 12:59 UTC
SAP Commerce Cloud RCE flaw (CVE-2026-58231) exploited 3 days post-patchcriticalbug_reportVulnerability
bug_reportVulnerability

SAP Commerce Cloud RCE flaw (CVE-2026-58231) exploited 3 days post-patch

SAP Commerce Cloud (formerly Hybris), specifically the core Data Hub Adapter extension. All unpatched instances are vulnerable. Shadowserver tracks 4,200+ internet-exposed instances, primarily in Europe and North America.

SAP14 Aug · 11:45 UTC
Clop Ransomware Gang Exploits CVE-2026-12569 in PTC Windchill Attackshighperson_alertThreat Actor
person_alertThreat Actor

Clop Ransomware Gang Exploits CVE-2026-12569 in PTC Windchill Attacks

Clop is a financially motivated ransomware gang known for mass exploitation campaigns targeting zero-day and n-day vulnerabilities in enterprise software.

Shell14 Aug · 09:55 UTC
ShinyHunters Breaches RingCentral, Leaks 1.6M Account Recordshighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Breaches RingCentral, Leaks 1.6M Account Records

ShinyHunters is a financially motivated extortion group that operates a "pay or leak" model, demanding ransom payments from breached organizations and publishing stolen data on dark web leak sites when victims refuse to pay.

RingCentral14 Aug · 08:52 UTC
Former Brightly Software Contractor Sentenced for $2.5M Extortionhighperson_alertThreat Actor
person_alertThreat Actor

Former Brightly Software Contractor Sentenced for $2.5M Extortion

Cameron Curry (alias "Loot"), a 27-year-old North Carolina resident, was a former data analyst contractor for Brightly Software (formerly SchoolDude, acquired by Siemens in 2022).

Brightly Software14 Aug · 06:27 UTC
Akira Ransomware Affiliate Uses Safe Mode to Evade EDR, Fails Encryptionhighperson_alertThreat Actor
person_alertThreat Actor

Akira Ransomware Affiliate Uses Safe Mode to Evade EDR, Fails Encryption

Akira (also tracked as GOLD SAHARA, PUNK SPIDER, and Howling Scorpius) is a ransomware operation that emerged as a significant threat actor conducting double extortion attacks.

BleepingComputer13 Aug · 18:47 UTC
Jewelbug APT Conducts Dual-Track Espionage and Crypto Fraudhighperson_alertThreat Actor
person_alertThreat Actor

Jewelbug APT Conducts Dual-Track Espionage and Crypto Fraud

Jewelbug (also tracked as Earth Alux and REF7707) is a China-based threat actor conducting parallel espionage and financially-motivated operations. The group targets government and military entities across the Middle East, Southeast Asia, and South A…

BleepingComputer13 Aug · 16:15 UTC
Microsoft patches LegacyHive Windows zero-day granting admin privilegeshighbug_reportVulnerability
bug_reportVulnerability

Microsoft patches LegacyHive Windows zero-day granting admin privileges

Windows User Profile Service in Windows 10 version 2004 and later, Windows Server 2022 and later. Tracked as CVE-2026-62832. All Windows systems running affected versions are vulnerable.

Microsoft13 Aug · 15:46 UTC
VMware vCenter RCE (CVE-2026-59310) exploited for reverse SSH accesscriticalbug_reportVulnerability
bug_reportVulnerability

VMware vCenter RCE (CVE-2026-59310) exploited for reverse SSH access

VMware vCenter Server versions prior to 9.1.0.0300 (9.1 branch), 9.0.2.0100 (9.0 branch), and 8.0 U3k/U2f (8.0 branch). The vulnerability affects the vCenter Syslog Server component and is exploitable by unauthenticated attackers with network access.

CVE-2026-5931013 Aug · 14:40 UTC
SonicWall GMS unauthenticated RCE flaws require immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

SonicWall GMS unauthenticated RCE flaws require immediate patching

SonicWall Global Management System (GMS). Specific affected versions not disclosed in available data. Both CVE-2026-66145 and CVE-2026-66147 enable unauthenticated remote code execution.

CVE-2026-6614513 Aug · 13:36 UTC
Plesk privilege escalation flaw requires immediate patchinghighbug_reportVulnerability
bug_reportVulnerability

Plesk privilege escalation flaw requires immediate patching

Plesk web hosting control panel - specific affected versions not disclosed in advisory. Privilege escalation vulnerability allows attackers to gain elevated access.

Plesk13 Aug · 13:01 UTC
Cisco Secure Firewall DoS flaw under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Cisco Secure Firewall DoS flaw under active exploitation

Cisco Secure Firewall products (specific versions not disclosed in available data). Organizations using Cisco ASA, FTD, or Firepower appliances should assume exposure until vendor advisory is reviewed.

Cisco13 Aug · 06:31 UTC
Metabase SQL injection under active exploitation, patch immediatelycriticalbug_reportVulnerability
bug_reportVulnerability

Metabase SQL injection under active exploitation, patch immediately

Metabase open-source business intelligence platform. Specific affected versions not disclosed in advisory. SQL injection vulnerability allows unauthorized database access.

Metabase13 Aug · 06:16 UTC
SharePoint CVE-2026-55040 exploited in wild after PoC releasecriticalbug_reportVulnerability
bug_reportVulnerability

SharePoint CVE-2026-55040 exploited in wild after PoC release

Microsoft SharePoint servers not patched with July 2026 Patch Tuesday updates. All unpatched SharePoint instances are vulnerable to authentication bypass allowing unauthenticated remote attackers to impersonate any site user or administrator.

CVE-2026-5504013 Aug · 04:09 UTC
City-Forum Campaign Targets Salesforce and ServiceNow Portalshighperson_alertThreat Actor
person_alertThreat Actor

City-Forum Campaign Targets Salesforce and ServiceNow Portals

City-Forum is an ongoing data theft campaign, not a formally attributed threat actor group. The campaign has been active since at least March 2025 and is characterized by consistent infrastructure use—a single IP address (158.220.87.79) hosted by Ger…

Salesforce12 Aug · 21:07 UTC
WindRelay NFC relay malware + SpyNote RAT steal cards, take loanshighbug_reportVulnerability
bug_reportVulnerability

WindRelay NFC relay malware + SpyNote RAT steal cards, take loans

Android devices in Czechia, Slovakia, and Slovenia. WindRelay NFC relay malware deployed alongside SpyNote RAT (and variants SpyMax, CypherRAT). 24 WindRelay samples identified on VirusTotal from November 2025 to July 2026.

BleepingComputer12 Aug · 20:22 UTC
Adobe Commerce/Magento flaw CVE-2026-71362 exploited to hijack accountscriticalbug_reportVulnerability
bug_reportVulnerability

Adobe Commerce/Magento flaw CVE-2026-71362 exploited to hijack accounts

Adobe Commerce and Magento Open Source e-commerce platforms, all currently supported release lines. The vulnerability affects customer account session handling and requires no authentication to exploit.

CVE-2026-7136212 Aug · 18:54 UTC
737 fake Chrome VPN extensions route traffic through attacker SOCKS5 proxieshighbug_reportVulnerability
bug_reportVulnerability

737 fake Chrome VPN extensions route traffic through attacker SOCKS5 proxies

Google Chrome Web Store users who installed any of 737 malicious extensions impersonating VPN/proxy services (Proton VPN, NordVPN, Surfshark, ExpressVPN, Cloudflare 1.1.1.1). Approximately 75,000 downloads recorded, primarily Russian users.

Google12 Aug · 16:54 UTC
Lazarus Exploits Windows Zero-Day in Operation Dream Job Campaigncriticalperson_alertThreat Actor
person_alertThreat Actor

Lazarus Exploits Windows Zero-Day in Operation Dream Job Campaign

Lazarus Group is a North Korean state-sponsored advanced persistent threat (APT) actor attributed to Pyongyang-backed cyber operations. The group conducts cyber espionage and financially motivated campaigns targeting organizations worldwide.

Microsoft12 Aug · 15:39 UTC
Plug and Pwn attacks exploit Windows Plug and Play for SYSTEM accesshighbug_reportVulnerability
bug_reportVulnerability

Plug and Pwn attacks exploit Windows Plug and Play for SYSTEM access

All Windows systems (including fully patched Windows 11) that support Plug and Play device installation. Specific vulnerable vendor packages include Sierra Wireless and Sony FeliCa software.

Microsoft12 Aug · 14:05 UTC
Lazarus Exploits Windows Zero-Day in Operation Dream Job Campaigncriticalperson_alertThreat Actor
person_alertThreat Actor

Lazarus Exploits Windows Zero-Day in Operation Dream Job Campaign

Lazarus is a North Korean state-sponsored advanced persistent threat (APT) group linked to the Reconnaissance General Bureau. The group is financially and strategically motivated, conducting espionage operations targeting defense and critical infrast…

CVE-2026-6882012 Aug · 13:38 UTC
Cybercriminals Target Social Media Accounts for Sexual Exploitationhighperson_alertThreat Actor
person_alertThreat Actor

Cybercriminals Target Social Media Accounts for Sexual Exploitation

Unattributed cybercriminals conducting coordinated account compromise campaigns targeting social media and online service accounts belonging to adults, children, and student-athletes in the United States.

BleepingComputer12 Aug · 12:15 UTC
737 malicious Chrome VPN extensions route traffic through attacker proxieshighbug_reportVulnerability
bug_reportVulnerability

737 malicious Chrome VPN extensions route traffic through attacker proxies

Google Chrome users who installed any of 737 malicious VPN/proxy extensions from Chrome Web Store, primarily targeting Russian-speaking users. 274 extensions impersonated 66 legitimate VPN brands (Proton VPN, NordVPN, Surfshark, AdGuard VPN, Browsec,…

Google12 Aug · 12:09 UTC