Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 415 results
highbug_reportVulnerabilityTotolink EX1200L router vulnerable to stack buffer overflow (RCE)
Totolink EX1200L router software. Specific affected firmware versions not disclosed. Vulnerability is a stack-based buffer overflow enabling potential remote code execution.
highperson_alertThreat ActorWhatsApp VBScript Campaign Deploys ManageEngine RMM Across 9 Countries
This campaign represents an unattributed threat activity leveraging WhatsApp as an initial access vector. The actor's motivation appears to be establishing persistent remote access to victim systems through legitimate remote monitoring and management…
highbug_reportVulnerabilityWhatsApp malware campaign uses fake business docs to deploy VBScript RATs
WhatsApp users across multiple countries. Attack vector: social engineering via WhatsApp messages containing malicious VBScript files disguised as business documents. Enables remote access to Windows PCs.
criticalbug_reportVulnerabilityCritical RCE and XSS flaws in pgAdmin 4 enable credential theft
pgAdmin 4 (specific vulnerable versions not provided in alert). pgAdmin is a web-based administration tool for PostgreSQL databases, commonly deployed in enterprise environments for database management.
criticalbug_reportVulnerabilityProxySQL ACL bypass and heap corruption flaws threaten database security
ProxySQL (specific versions not provided). Vulnerabilities include ACL bypass allowing unauthorized access and heap memory corruption potentially enabling remote code execution. Database proxy infrastructure is at risk.
highbug_reportVulnerability29-year-old Squid heap over-read leaks HTTP credentials in default config
Squid web proxy, all versions containing FTP parsing code from 1997 onward. Vulnerability present in default configuration. Affects organizations using Squid as forward or reverse proxy.
highperson_alertThreat ActorRussian-speaking actor deploys OXLOADER to distribute CastleStealer
The threat actor is a Russian-speaking, financially motivated cybercrime operator leveraging malicious advertising infrastructure for initial access. The actor demonstrates capability in developing or acquiring custom malware tooling, including the p…
highbug_reportVulnerabilityNorth Korean APT compromised 140+ npm packages via Mastra AI framework
Mastra AI framework and over 140 dependent npm packages. Organizations using Mastra AI or downstream dependencies in Node.js/JavaScript applications are affected.
highpublicGeopoliticalTexas Parks and Wildlife vendor breach exposes 3M+ records
The breach at a Texas state agency vendor underscores persistent vulnerabilities in third-party supply chains supporting U.S. public administration. While no attribution has been disclosed, the exposure of driver's license data and personally identif…
criticalbug_reportVulnerabilityCritical RCE in Splunk Enterprise under active exploitation
Splunk Enterprise (specific versions not disclosed in alert). The vulnerability enables remote code execution. CVE identifier not yet assigned or published.
highperson_alertThreat ActorSocGholish Infrastructure Disrupted in Operation Endgame Takedown
SocGholish is a threat actor known for compromising web infrastructure, particularly WordPress-based content management systems, to facilitate malware distribution and drive-by download attacks.
highperson_alertThreat ActorRussian-speaking actors compromise 86,644 FortiGate devices via FortiBleed
Russian-speaking threat actors are conducting the FortiBleed campaign, targeting internet-accessible FortiGate appliances at scale. The actors' specific motivation remains unclear from available data, though the mass compromise of 86,644 devices sugg…
highbug_reportVulnerabilitySalesforce disables Klue integration after OAuth token abuse exposes data
Salesforce customers using the Klue Battlecards app integration. OAuth tokens were abused to access customer data. Integration disabled as of June 11, 2026.
criticalbug_reportVulnerabilityCritical auth bypass in SimpleHelp remote support software (CVE-2026-48558)
SimpleHelp remote support software, specific versions not disclosed. Vendor patch available. Authentication bypass vulnerability allows unauthorized access.
highbug_reportVulnerabilityF5 patches high-severity flaws in NGINX Open Source and Gateway Fabric
NGINX Open Source and NGINX Gateway Fabric (specific versions not provided). Four CVEs: CVE-2026-11311, CVE-2026-42055, CVE-2026-42530, CVE-2026-50107. Affects organizations running NGINX web servers, reverse proxies, API gateways, and Kubernetes ing…
highpublicGeopoliticalCISA warns of 74,000 Fortinet credentials exposed in FortiBleed leak
The exposure of approximately 74,000 Fortinet firewall and VPN credentials represents a significant supply-side vulnerability affecting critical infrastructure globally.
highperson_alertThreat ActorNetNut Linked to Popa Android Botnet Enabling Proxy Fraud
NetNut is a residential proxy service operated by Alarum Technologies Ltd (NASDAQ: ALAR), a publicly-traded Israeli firm. Multiple security researchers have linked NetNut to the Popa Android botnet, which has compromised millions of consumer TV boxes…
highperson_alertThreat ActorDragonForce Deploys Backdoor.Turn RAT via Microsoft Teams Infrastructure
DragonForce is a threat actor associated with ransomware operations. The group has demonstrated advanced capabilities in developing custom tooling and leveraging legitimate cloud infrastructure for command-and-control communications.
highperson_alertThreat ActorEvil Corp SocGholish botnet dismantled: 15,000 sites, 100+ servers
Evil Corp (also tracked as Indrik Spider, Manatee Tempest, DEV-0243, UNC2165) is a financially motivated cybercrime group linked to Russia. The group has operated since at least 2014 and is known for deploying banking trojans and ransomware variants…
highbug_reportVulnerabilityNCSC warns of active global campaign targeting Fortinet firewalls and VPNs
Fortinet firewalls and VPN gateways globally. Specific product lines and versions not disclosed in alert. Organizations using FortiGate, FortiOS, or FortiClient VPN services should assume potential exposure.
highperson_alertThreat ActorJunior Hacker targets French automotive sector with credential theft
Junior Hacker is a French-speaking threat actor targeting small businesses in the French automotive sector. The actor demonstrates financially motivated objectives, focusing on credential theft for banking and email access.
criticalbug_reportVulnerabilityJenkins RCE vulnerability requires immediate patching per CERT.BE
Jenkins (specific versions not disclosed in alert). Vulnerability enables arbitrary remote code execution. CVE identifier not yet assigned or published.
criticalbug_reportVulnerabilityCritical vulnerability in Joomla Content Editor (JCE) requires urgent patching
Joomla Content Editor (JCE) extension for Joomla CMS. Specific affected versions not disclosed in advisory. All Joomla sites using the JCE extension should be considered at risk pending vendor confirmation.
highpublicGeopoliticalUK NCSC: Hostile states linked to 75% of critical infrastructure attacks
The NCSC assessment underscores the strategic shift in cyber threat landscape from predominantly criminal actors to state-aligned operations targeting national critical infrastructure.
criticalbug_reportVulnerabilityCISA orders patching of actively exploited Joomla JCE plugin flaw
Widget Factory Joomla Content Editor (JCE) plugin for Joomla CMS. Specific vulnerable versions not disclosed in provided data. Maximum severity rating indicates critical impact.
criticalbug_reportVulnerabilityCISA: Widget Factory Joomla JCE flaw exploited in the wild (CVSS 10.0)
Widget Factory Joomla Content Editor (JCE). Specific affected versions not disclosed. Impacts Joomla CMS installations using the JCE component.
criticalbug_reportVulnerabilityCisco SD-WAN vulnerability under active exploitation, patches released
Cisco SD-WAN products. Specific affected versions not provided in available data. Organizations running Cisco SD-WAN infrastructure are potentially at risk.
highbug_reportVulnerabilityHeap buffer overflow in jansi library enables code execution
jansi library (all versions not specified). The jansi library is a Java library for ANSI escape sequences, commonly used in console applications and logging frameworks across Java ecosystems.
criticalbug_reportVulnerabilityCISA orders patch for exploited LiteSpeed cPanel plugin flaw (3-day deadline)
LiteSpeed cPanel user-end plugin (specific versions not disclosed). Affects web hosting environments using cPanel with LiteSpeed integration. U.S. federal agencies explicitly targeted by CISA directive.
highbug_reportVulnerabilitySprySOCKS malware expands to Windows in government-targeted attacks
Government organizations in at least four countries. Windows systems now targeted alongside previously known Linux variants. Specific Windows versions and attack vector not disclosed.