Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 415 results
Active filter:tag: #geopolitical✕ clear
Totolink EX1200L router vulnerable to stack buffer overflow (RCE)highbug_reportVulnerability
bug_reportVulnerability

Totolink EX1200L router vulnerable to stack buffer overflow (RCE)

Totolink EX1200L router software. Specific affected firmware versions not disclosed. Vulnerability is a stack-based buffer overflow enabling potential remote code execution.

CVE-2026-4408923 Jun · 08:55 UTC
WhatsApp VBScript Campaign Deploys ManageEngine RMM Across 9 Countrieshighperson_alertThreat Actor
person_alertThreat Actor

WhatsApp VBScript Campaign Deploys ManageEngine RMM Across 9 Countries

This campaign represents an unattributed threat activity leveraging WhatsApp as an initial access vector. The actor's motivation appears to be establishing persistent remote access to victim systems through legitimate remote monitoring and management…

WhatsApp23 Jun · 03:38 UTC
WhatsApp malware campaign uses fake business docs to deploy VBScript RATshighbug_reportVulnerability
bug_reportVulnerability

WhatsApp malware campaign uses fake business docs to deploy VBScript RATs

WhatsApp users across multiple countries. Attack vector: social engineering via WhatsApp messages containing malicious VBScript files disguised as business documents. Enables remote access to Windows PCs.

BleepingComputer22 Jun · 20:42 UTC
Critical RCE and XSS flaws in pgAdmin 4 enable credential theftcriticalbug_reportVulnerability
bug_reportVulnerability

Critical RCE and XSS flaws in pgAdmin 4 enable credential theft

pgAdmin 4 (specific vulnerable versions not provided in alert). pgAdmin is a web-based administration tool for PostgreSQL databases, commonly deployed in enterprise environments for database management.

pgAdmin22 Jun · 13:02 UTC
ProxySQL ACL bypass and heap corruption flaws threaten database securitycriticalbug_reportVulnerability
bug_reportVulnerability

ProxySQL ACL bypass and heap corruption flaws threaten database security

ProxySQL (specific versions not provided). Vulnerabilities include ACL bypass allowing unauthorized access and heap memory corruption potentially enabling remote code execution. Database proxy infrastructure is at risk.

ProxySQL22 Jun · 12:48 UTC
29-year-old Squid heap over-read leaks HTTP credentials in default confighighbug_reportVulnerability
bug_reportVulnerability

29-year-old Squid heap over-read leaks HTTP credentials in default config

Squid web proxy, all versions containing FTP parsing code from 1997 onward. Vulnerability present in default configuration. Affects organizations using Squid as forward or reverse proxy.

Squid22 Jun · 12:29 UTC
Russian-speaking actor deploys OXLOADER to distribute CastleStealerhighperson_alertThreat Actor
person_alertThreat Actor

Russian-speaking actor deploys OXLOADER to distribute CastleStealer

The threat actor is a Russian-speaking, financially motivated cybercrime operator leveraging malicious advertising infrastructure for initial access. The actor demonstrates capability in developing or acquiring custom malware tooling, including the p…

Google22 Jun · 11:20 UTC
North Korean APT compromised 140+ npm packages via Mastra AI frameworkhighbug_reportVulnerability
bug_reportVulnerability

North Korean APT compromised 140+ npm packages via Mastra AI framework

Mastra AI framework and over 140 dependent npm packages. Organizations using Mastra AI or downstream dependencies in Node.js/JavaScript applications are affected.

Mastra AI20 Jun · 12:09 UTC
Texas Parks and Wildlife vendor breach exposes 3M+ recordshighpublicGeopolitical
publicGeopolitical

Texas Parks and Wildlife vendor breach exposes 3M+ records

The breach at a Texas state agency vendor underscores persistent vulnerabilities in third-party supply chains supporting U.S. public administration. While no attribution has been disclosed, the exposure of driver's license data and personally identif…

BleepingComputer19 Jun · 14:12 UTC
Critical RCE in Splunk Enterprise under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Critical RCE in Splunk Enterprise under active exploitation

Splunk Enterprise (specific versions not disclosed in alert). The vulnerability enables remote code execution. CVE identifier not yet assigned or published.

Splunk19 Jun · 13:33 UTC
SocGholish Infrastructure Disrupted in Operation Endgame Takedownhighperson_alertThreat Actor
person_alertThreat Actor

SocGholish Infrastructure Disrupted in Operation Endgame Takedown

SocGholish is a threat actor known for compromising web infrastructure, particularly WordPress-based content management systems, to facilitate malware distribution and drive-by download attacks.

WordPress19 Jun · 13:07 UTC
Russian-speaking actors compromise 86,644 FortiGate devices via FortiBleedhighperson_alertThreat Actor
person_alertThreat Actor

Russian-speaking actors compromise 86,644 FortiGate devices via FortiBleed

Russian-speaking threat actors are conducting the FortiBleed campaign, targeting internet-accessible FortiGate appliances at scale. The actors' specific motivation remains unclear from available data, though the mass compromise of 86,644 devices sugg…

Fortinet19 Jun · 12:00 UTC
Salesforce disables Klue integration after OAuth token abuse exposes datahighbug_reportVulnerability
bug_reportVulnerability

Salesforce disables Klue integration after OAuth token abuse exposes data

Salesforce customers using the Klue Battlecards app integration. OAuth tokens were abused to access customer data. Integration disabled as of June 11, 2026.

Salesforce19 Jun · 07:03 UTC
Critical auth bypass in SimpleHelp remote support software (CVE-2026-48558)criticalbug_reportVulnerability
bug_reportVulnerability

Critical auth bypass in SimpleHelp remote support software (CVE-2026-48558)

SimpleHelp remote support software, specific versions not disclosed. Vendor patch available. Authentication bypass vulnerability allows unauthorized access.

CVE-2026-4855819 Jun · 06:46 UTC
F5 patches high-severity flaws in NGINX Open Source and Gateway Fabrichighbug_reportVulnerability
bug_reportVulnerability

F5 patches high-severity flaws in NGINX Open Source and Gateway Fabric

NGINX Open Source and NGINX Gateway Fabric (specific versions not provided). Four CVEs: CVE-2026-11311, CVE-2026-42055, CVE-2026-42530, CVE-2026-50107. Affects organizations running NGINX web servers, reverse proxies, API gateways, and Kubernetes ing…

CVE-2026-1131119 Jun · 06:24 UTC
CISA warns of 74,000 Fortinet credentials exposed in FortiBleed leakhighpublicGeopolitical
publicGeopolitical

CISA warns of 74,000 Fortinet credentials exposed in FortiBleed leak

The exposure of approximately 74,000 Fortinet firewall and VPN credentials represents a significant supply-side vulnerability affecting critical infrastructure globally.

Fortinet19 Jun · 04:47 UTC
NetNut Linked to Popa Android Botnet Enabling Proxy Fraudhighperson_alertThreat Actor
person_alertThreat Actor

NetNut Linked to Popa Android Botnet Enabling Proxy Fraud

NetNut is a residential proxy service operated by Alarum Technologies Ltd (NASDAQ: ALAR), a publicly-traded Israeli firm. Multiple security researchers have linked NetNut to the Popa Android botnet, which has compromised millions of consumer TV boxes…

Alarum Technologies Ltd18 Jun · 15:37 UTC
DragonForce Deploys Backdoor.Turn RAT via Microsoft Teams Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

DragonForce Deploys Backdoor.Turn RAT via Microsoft Teams Infrastructure

DragonForce is a threat actor associated with ransomware operations. The group has demonstrated advanced capabilities in developing custom tooling and leveraging legitimate cloud infrastructure for command-and-control communications.

Microsoft18 Jun · 11:30 UTC
Evil Corp SocGholish botnet dismantled: 15,000 sites, 100+ servershighperson_alertThreat Actor
person_alertThreat Actor

Evil Corp SocGholish botnet dismantled: 15,000 sites, 100+ servers

Evil Corp (also tracked as Indrik Spider, Manatee Tempest, DEV-0243, UNC2165) is a financially motivated cybercrime group linked to Russia. The group has operated since at least 2014 and is known for deploying banking trojans and ransomware variants…

WordPress18 Jun · 11:25 UTC
NCSC warns of active global campaign targeting Fortinet firewalls and VPNshighbug_reportVulnerability
bug_reportVulnerability

NCSC warns of active global campaign targeting Fortinet firewalls and VPNs

Fortinet firewalls and VPN gateways globally. Specific product lines and versions not disclosed in alert. Organizations using FortiGate, FortiOS, or FortiClient VPN services should assume potential exposure.

Fortinet18 Jun · 10:00 UTC
Junior Hacker targets French automotive sector with credential thefthighperson_alertThreat Actor
person_alertThreat Actor

Junior Hacker targets French automotive sector with credential theft

Junior Hacker is a French-speaking threat actor targeting small businesses in the French automotive sector. The actor demonstrates financially motivated objectives, focusing on credential theft for banking and email access.

The Hacker News17 Jun · 14:00 UTC
Jenkins RCE vulnerability requires immediate patching per CERT.BEcriticalbug_reportVulnerability
bug_reportVulnerability

Jenkins RCE vulnerability requires immediate patching per CERT.BE

Jenkins (specific versions not disclosed in alert). Vulnerability enables arbitrary remote code execution. CVE identifier not yet assigned or published.

Jenkins17 Jun · 12:42 UTC
Critical vulnerability in Joomla Content Editor (JCE) requires urgent patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical vulnerability in Joomla Content Editor (JCE) requires urgent patching

Joomla Content Editor (JCE) extension for Joomla CMS. Specific affected versions not disclosed in advisory. All Joomla sites using the JCE extension should be considered at risk pending vendor confirmation.

Joomla17 Jun · 12:39 UTC
UK NCSC: Hostile states linked to 75% of critical infrastructure attackshighpublicGeopolitical
publicGeopolitical

UK NCSC: Hostile states linked to 75% of critical infrastructure attacks

The NCSC assessment underscores the strategic shift in cyber threat landscape from predominantly criminal actors to state-aligned operations targeting national critical infrastructure.

NCSC UK17 Jun · 10:00 UTC
CISA orders patching of actively exploited Joomla JCE plugin flawcriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders patching of actively exploited Joomla JCE plugin flaw

Widget Factory Joomla Content Editor (JCE) plugin for Joomla CMS. Specific vulnerable versions not disclosed in provided data. Maximum severity rating indicates critical impact.

Widget Factory17 Jun · 08:09 UTC
CISA: Widget Factory Joomla JCE flaw exploited in the wild (CVSS 10.0)criticalbug_reportVulnerability
bug_reportVulnerability

CISA: Widget Factory Joomla JCE flaw exploited in the wild (CVSS 10.0)

Widget Factory Joomla Content Editor (JCE). Specific affected versions not disclosed. Impacts Joomla CMS installations using the JCE component.

CVE-2026-4890717 Jun · 03:50 UTC
Cisco SD-WAN vulnerability under active exploitation, patches releasedcriticalbug_reportVulnerability
bug_reportVulnerability

Cisco SD-WAN vulnerability under active exploitation, patches released

Cisco SD-WAN products. Specific affected versions not provided in available data. Organizations running Cisco SD-WAN infrastructure are potentially at risk.

Cisco16 Jun · 11:40 UTC
Heap buffer overflow in jansi library enables code executionhighbug_reportVulnerability
bug_reportVulnerability

Heap buffer overflow in jansi library enables code execution

jansi library (all versions not specified). The jansi library is a Java library for ANSI escape sequences, commonly used in console applications and logging frameworks across Java ecosystems.

CVE-2026-848416 Jun · 08:55 UTC
CISA orders patch for exploited LiteSpeed cPanel plugin flaw (3-day deadline)criticalbug_reportVulnerability
bug_reportVulnerability

CISA orders patch for exploited LiteSpeed cPanel plugin flaw (3-day deadline)

LiteSpeed cPanel user-end plugin (specific versions not disclosed). Affects web hosting environments using cPanel with LiteSpeed integration. U.S. federal agencies explicitly targeted by CISA directive.

CVE-2026-5442016 Jun · 08:47 UTC
SprySOCKS malware expands to Windows in government-targeted attackshighbug_reportVulnerability
bug_reportVulnerability

SprySOCKS malware expands to Windows in government-targeted attacks

Government organizations in at least four countries. Windows systems now targeted alongside previously known Linux variants. Specific Windows versions and attack vector not disclosed.

BleepingComputer16 Jun · 07:00 UTC