Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
satellite_altDaily BriefCyber Threat Daily Brief — September 4, 2026
Today's briefing: 14 critical and 22 high-severity threats. A total of 47 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.
Latest Reports
26 / 1172 results
highbug_reportVulnerabilityEvooo1Bot: Mirai-based botnet targets Linux gateways as SOCKS5 proxies
Internet-facing Linux gateway devices (routers, firewalls, edge appliances). Specific vendors and models not disclosed. Mirai-based malware with modular architecture targeting devices with weak credentials or known vulnerabilities.
criticalbug_reportVulnerabilitySAP Commerce Cloud CVE-2026-58231 under active exploit, 3 days post-patch
SAP Commerce Cloud, all versions prior to patched release levels. Vulnerability affects default authentication clients and endpoints lacking input validation. Unauthenticated remote exploitation possible.
highperson_alertThreat Actor€30M Bank Fraud via Service Provider Exploit Targets Commerzbank
An unknown cybercriminal group, financially motivated, conducted a coordinated bank fraud operation targeting Commerzbank customers. The group operated across multiple jurisdictions, with four members arrested in Brazil and three charged in Europe.
highbug_reportVulnerabilitymacOS Screen Sharing auth bypass exploited to deploy Monero miners
macOS Screen Sharing feature on systems with TCP port 5900 exposed to the internet. Fixed in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. CVE-2026-65400 affects earlier versions of these releases.
criticalbug_reportVulnerabilitySAP Commerce Cloud RCE flaw (CVE-2026-58231) exploited 3 days post-patch
SAP Commerce Cloud (formerly Hybris), specifically the core Data Hub Adapter extension. All unpatched instances are vulnerable. Shadowserver tracks 4,200+ internet-exposed instances, primarily in Europe and North America.
highperson_alertThreat ActorClop Ransomware Gang Exploits CVE-2026-12569 in PTC Windchill Attacks
Clop is a financially motivated ransomware gang known for mass exploitation campaigns targeting zero-day and n-day vulnerabilities in enterprise software.
highperson_alertThreat ActorShinyHunters Breaches RingCentral, Leaks 1.6M Account Records
ShinyHunters is a financially motivated extortion group that operates a "pay or leak" model, demanding ransom payments from breached organizations and publishing stolen data on dark web leak sites when victims refuse to pay.
highperson_alertThreat ActorFormer Brightly Software Contractor Sentenced for $2.5M Extortion
Cameron Curry (alias "Loot"), a 27-year-old North Carolina resident, was a former data analyst contractor for Brightly Software (formerly SchoolDude, acquired by Siemens in 2022).
highperson_alertThreat ActorAkira Ransomware Affiliate Uses Safe Mode to Evade EDR, Fails Encryption
Akira (also tracked as GOLD SAHARA, PUNK SPIDER, and Howling Scorpius) is a ransomware operation that emerged as a significant threat actor conducting double extortion attacks.
highperson_alertThreat ActorJewelbug APT Conducts Dual-Track Espionage and Crypto Fraud
Jewelbug (also tracked as Earth Alux and REF7707) is a China-based threat actor conducting parallel espionage and financially-motivated operations. The group targets government and military entities across the Middle East, Southeast Asia, and South A…
highbug_reportVulnerabilityMicrosoft patches LegacyHive Windows zero-day granting admin privileges
Windows User Profile Service in Windows 10 version 2004 and later, Windows Server 2022 and later. Tracked as CVE-2026-62832. All Windows systems running affected versions are vulnerable.
criticalbug_reportVulnerabilityVMware vCenter RCE (CVE-2026-59310) exploited for reverse SSH access
VMware vCenter Server versions prior to 9.1.0.0300 (9.1 branch), 9.0.2.0100 (9.0 branch), and 8.0 U3k/U2f (8.0 branch). The vulnerability affects the vCenter Syslog Server component and is exploitable by unauthenticated attackers with network access.
criticalbug_reportVulnerabilitySonicWall GMS unauthenticated RCE flaws require immediate patching
SonicWall Global Management System (GMS). Specific affected versions not disclosed in available data. Both CVE-2026-66145 and CVE-2026-66147 enable unauthenticated remote code execution.
highbug_reportVulnerabilityPlesk privilege escalation flaw requires immediate patching
Plesk web hosting control panel - specific affected versions not disclosed in advisory. Privilege escalation vulnerability allows attackers to gain elevated access.
criticalbug_reportVulnerabilityCisco Secure Firewall DoS flaw under active exploitation
Cisco Secure Firewall products (specific versions not disclosed in available data). Organizations using Cisco ASA, FTD, or Firepower appliances should assume exposure until vendor advisory is reviewed.
criticalbug_reportVulnerabilityMetabase SQL injection under active exploitation, patch immediately
Metabase open-source business intelligence platform. Specific affected versions not disclosed in advisory. SQL injection vulnerability allows unauthorized database access.
criticalbug_reportVulnerabilitySharePoint CVE-2026-55040 exploited in wild after PoC release
Microsoft SharePoint servers not patched with July 2026 Patch Tuesday updates. All unpatched SharePoint instances are vulnerable to authentication bypass allowing unauthenticated remote attackers to impersonate any site user or administrator.
highperson_alertThreat ActorCity-Forum Campaign Targets Salesforce and ServiceNow Portals
City-Forum is an ongoing data theft campaign, not a formally attributed threat actor group. The campaign has been active since at least March 2025 and is characterized by consistent infrastructure use—a single IP address (158.220.87.79) hosted by Ger…
highbug_reportVulnerabilityWindRelay NFC relay malware + SpyNote RAT steal cards, take loans
Android devices in Czechia, Slovakia, and Slovenia. WindRelay NFC relay malware deployed alongside SpyNote RAT (and variants SpyMax, CypherRAT). 24 WindRelay samples identified on VirusTotal from November 2025 to July 2026.
criticalbug_reportVulnerabilityAdobe Commerce/Magento flaw CVE-2026-71362 exploited to hijack accounts
Adobe Commerce and Magento Open Source e-commerce platforms, all currently supported release lines. The vulnerability affects customer account session handling and requires no authentication to exploit.
highbug_reportVulnerability737 fake Chrome VPN extensions route traffic through attacker SOCKS5 proxies
Google Chrome Web Store users who installed any of 737 malicious extensions impersonating VPN/proxy services (Proton VPN, NordVPN, Surfshark, ExpressVPN, Cloudflare 1.1.1.1). Approximately 75,000 downloads recorded, primarily Russian users.
criticalperson_alertThreat ActorLazarus Exploits Windows Zero-Day in Operation Dream Job Campaign
Lazarus Group is a North Korean state-sponsored advanced persistent threat (APT) actor attributed to Pyongyang-backed cyber operations. The group conducts cyber espionage and financially motivated campaigns targeting organizations worldwide.
highbug_reportVulnerabilityPlug and Pwn attacks exploit Windows Plug and Play for SYSTEM access
All Windows systems (including fully patched Windows 11) that support Plug and Play device installation. Specific vulnerable vendor packages include Sierra Wireless and Sony FeliCa software.
criticalperson_alertThreat ActorLazarus Exploits Windows Zero-Day in Operation Dream Job Campaign
Lazarus is a North Korean state-sponsored advanced persistent threat (APT) group linked to the Reconnaissance General Bureau. The group is financially and strategically motivated, conducting espionage operations targeting defense and critical infrast…
highperson_alertThreat ActorCybercriminals Target Social Media Accounts for Sexual Exploitation
Unattributed cybercriminals conducting coordinated account compromise campaigns targeting social media and online service accounts belonging to adults, children, and student-athletes in the United States.
highbug_reportVulnerability737 malicious Chrome VPN extensions route traffic through attacker proxies
Google Chrome users who installed any of 737 malicious VPN/proxy extensions from Chrome Web Store, primarily targeting Russian-speaking users. 274 extensions impersonated 66 legitimate VPN brands (Proton VPN, NordVPN, Surfshark, AdGuard VPN, Browsec,…