Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 390 results
Active filter:tag: #high✕ clear
China-Nexus Actors Expand JDY Botnet to 1,500+ IoT/SOHO Deviceshighperson_alertThreat Actor
person_alertThreat Actor

China-Nexus Actors Expand JDY Botnet to 1,500+ IoT/SOHO Devices

China-nexus state-sponsored threat actors operating the JDY botnet infrastructure. The actors leverage compromised small office/home office (SOHO) routers and IoT devices to build a distributed scanning platform for cyber reconnaissance operations.

The Hacker News10 Jun · 14:08 UTC
Volt Typhoon Expands JDY Botnet Operations Against U.S. Militaryhighperson_alertThreat Actor
person_alertThreat Actor

Volt Typhoon Expands JDY Botnet Operations Against U.S. Military

Volt Typhoon (also tracked as BRONZE SILHOUETTE, Vanguard Panda, DEV-0391, and UNC3236) is a Chinese state-sponsored APT group attributed to conducting cyber espionage operations targeting critical infrastructure.

BleepingComputer10 Jun · 13:00 UTC
Cisco Catalyst SD-WAN Manager actively exploited (CVE-2026-20245)highbug_reportVulnerability
bug_reportVulnerability

Cisco Catalyst SD-WAN Manager actively exploited (CVE-2026-20245)

Cisco Catalyst SD-WAN Manager. Specific affected versions not disclosed. Vulnerability involves improper encoding or escaping of output (CVSS 7.8). Also affects products from Google and Arista (details not provided).

CVE-2026-2024510 Jun · 12:44 UTC
The Gentlemen Ransomware: Aggressive Affiliate Model Drives Rapid Growthhighperson_alertThreat Actor
person_alertThreat Actor

The Gentlemen Ransomware: Aggressive Affiliate Model Drives Rapid Growth

The Gentlemen is a ransomware-as-a-service (RaaS) operation that has rapidly ascended to become the second most active ransomware group by victim count.

Krebs on Security10 Jun · 12:03 UTC
Microsoft patches actively exploited XSS zero-day in Exchange Server OWAhighbug_reportVulnerability
bug_reportVulnerability

Microsoft patches actively exploited XSS zero-day in Exchange Server OWA

Microsoft Exchange Server (all versions with Outlook Web Access enabled). Specific patched versions not provided. Affects organizations exposing OWA to users.

Microsoft10 Jun · 11:44 UTC
Aix-DB missing authentication flaw allows unauthorized critical accesshighbug_reportVulnerability
bug_reportVulnerability

Aix-DB missing authentication flaw allows unauthorized critical access

Aix-DB software (vendor: Aix-DB). Specific affected versions not disclosed. Vulnerability allows unauthenticated access to critical functions (CWE-306).

CVE-2026-833510 Jun · 08:55 UTC
ServiceNow patches actively exploited auth bypass on hosted instanceshighbug_reportVulnerability
bug_reportVulnerability

ServiceNow patches actively exploited auth bypass on hosted instances

ServiceNow hosted customer instances (specific versions not disclosed). On-premise deployments may also be affected pending vendor guidance.

ServiceNow10 Jun · 05:02 UTC
Six RCE and DoS flaws found in protobuf.js for Node.js applicationshighbug_reportVulnerability
bug_reportVulnerability

Six RCE and DoS flaws found in protobuf.js for Node.js applications

protobuf.js library (JavaScript/TypeScript implementation of Protocol Buffers) used in Node.js applications. Specific vulnerable versions not provided in summary.

protobuf.js10 Jun · 03:08 UTC
OpenClaw AI email agent vulnerable to phishing attackshighbug_reportVulnerability
bug_reportVulnerability

OpenClaw AI email agent vulnerable to phishing attacks

OpenClaw AI email agent (all versions). Scope: AI-powered email processing systems that handle user communications and may access sensitive user data.

OpenClaw9 Jun · 19:20 UTC
Microsoft June 2026 Patch Tuesday: 200 flaws, 3 disclosed zero-dayshighbug_reportVulnerability
bug_reportVulnerability

Microsoft June 2026 Patch Tuesday: 200 flaws, 3 disclosed zero-days

Microsoft products across the ecosystem. 200 vulnerabilities patched, including 3 publicly disclosed zero-day vulnerabilities. Specific affected products and CVE identifiers not yet detailed in available information.

Microsoft9 Jun · 15:57 UTC
Microsoft GitHub repos compromised, 73 disabled for distributing malwarehighbug_reportVulnerability
bug_reportVulnerability

Microsoft GitHub repos compromised, 73 disabled for distributing malware

73 repositories across Microsoft's official GitHub organizations (Azure, microsoft, Azure-Samples, MicrosoftDocs). Organizations using Microsoft sample code, Azure templates, or CI/CD pipelines referencing these repositories are potentially affected.

Microsoft9 Jun · 13:42 UTC
WinRAR CVE-2025-8088 path traversal exploited by Russian APTs vs Ukrainehighbug_reportVulnerability
bug_reportVulnerability

WinRAR CVE-2025-8088 path traversal exploited by Russian APTs vs Ukraine

WinRAR versions prior to patched release (approximately one year old). Primary targets: Ukrainian organizations. Threat actors: Earth Dahu (Gamaredon) and SHADOW-EARTH-066 (UAC-0226), Russia-aligned APT groups.

CVE-2025-80889 Jun · 10:26 UTC
FROST attack enables website-based user tracking via SSD timing analysishighbug_reportVulnerability
bug_reportVulnerability

FROST attack enables website-based user tracking via SSD timing analysis

All systems with SSDs accessed via web browsers supporting high-resolution JavaScript timers. Attack affects users across Windows, Linux, and macOS platforms. No specific browser, SSD model, or OS version is immune.

The Hacker News9 Jun · 07:50 UTC
PyPI supply chain attack: 19 packages with auto-executing credential stealerhighbug_reportVulnerability
bug_reportVulnerability

PyPI supply chain attack: 19 packages with auto-executing credential stealer

PyPI repository: 19 compromised packages containing 37 malicious wheel artifacts. Affects Python developers who installed these packages. Attack uses .pth files for automatic execution during pip install, targeting credential theft via Bun-based stea…

PyPI9 Jun · 07:13 UTC
BerriAI LiteLLM command injection under active exploitation (CISA KEV)highbug_reportVulnerability
bug_reportVulnerability

BerriAI LiteLLM command injection under active exploitation (CISA KEV)

BerriAI LiteLLM - specific vulnerable versions not disclosed in summary. Command injection vulnerability (CVE-2026-42271) affects authenticated users with access to the system.

CVE-2026-422719 Jun · 04:26 UTC
NFCShare Android malware distributed via GitHub as fake banking app updateshighbug_reportVulnerability
bug_reportVulnerability

NFCShare Android malware distributed via GitHub as fake banking app updates

Android mobile users, particularly customers of targeted banking applications. Malware distributed through GitHub repositories posing as legitimate banking app updates.

BleepingComputer8 Jun · 20:11 UTC
SoFi Hong Kong reports third-party vendor breach exposing customer datahighpublicGeopolitical
publicGeopolitical

SoFi Hong Kong reports third-party vendor breach exposing customer data

The incident reflects the persistent vulnerability of financial services supply chains in Hong Kong, a major international financial hub operating under the "One Country, Two Systems" framework.

SoFi8 Jun · 19:55 UTC
PyPI supply-chain attack: 19 science packages compromised with malwarehighbug_reportVulnerability
bug_reportVulnerability

PyPI supply-chain attack: 19 science packages compromised with malware

19 science-focused Python packages on PyPI, collectively downloaded hundreds of thousands of times. Specific package names and versions not disclosed in summary. Affects Python developers using PyPI packages in scientific/research workflows.

BleepingComputer8 Jun · 18:41 UTC
NSO Group linked to WhatsApp spear-phishing campaignshighperson_alertThreat Actor
person_alertThreat Actor

NSO Group linked to WhatsApp spear-phishing campaigns

NSO Group is an Israeli cyber intelligence firm that develops and sells commercial surveillance technology, primarily the Pegasus spyware platform. The company markets its tools to government clients for lawful interception and intelligence gathering…

WhatsApp8 Jun · 16:40 UTC
Meta blocks NSO Group spear-phishing targeting WhatsApp usershighperson_alertThreat Actor
person_alertThreat Actor

Meta blocks NSO Group spear-phishing targeting WhatsApp users

NSO Group is an Israeli commercial surveillance vendor that develops and sells offensive cyber capabilities, primarily the Pegasus spyware platform, to government clients.

Meta8 Jun · 15:08 UTC
Three high-severity XSS flaws in VMware Telco Cloud and Aria Operationshighbug_reportVulnerability
bug_reportVulnerability

Three high-severity XSS flaws in VMware Telco Cloud and Aria Operations

VMware Telco Cloud/vSphere Foundation and VMware Aria Operations. Specific affected versions not provided in advisory; consult VMware security bulletin for version details.

VMware8 Jun · 13:05 UTC
Oxford University CareerConnect platform breached via third-party providerhighpublicGeopolitical
publicGeopolitical

Oxford University CareerConnect platform breached via third-party provider

The breach of Oxford University's CareerConnect platform represents a supply chain compromise affecting a high-value target within the United Kingdom's higher education sector.

Group GTI8 Jun · 09:14 UTC
VerdantBamboo deploys BSD BRICKSTORM variant with Linux malwarehighperson_alertThreat Actor
person_alertThreat Actor

VerdantBamboo deploys BSD BRICKSTORM variant with Linux malware

VerdantBamboo is a China-nexus cyber espionage group attributed by Volexity, with operational overlap with the threat cluster known as Clay Typhoon. The actor focuses on intelligence collection operations and has demonstrated cross-platform capabilit…

The Hacker News8 Jun · 08:27 UTC
UNC3753 Conducts Data Theft Extortion via Vishing and Physical Intrusionhighperson_alertThreat Actor
person_alertThreat Actor

UNC3753 Conducts Data Theft Extortion via Vishing and Physical Intrusion

UNC3753 is a financially motivated threat actor attributed by Mandiant. The group conducted a data theft extortion campaign targeting dozens of organizations in the United States between January and May 2026.

The Hacker News8 Jun · 05:39 UTC
Gafgyt C0XMO botnet exploits DD-WRT router flaw, kills rival malwarehighbug_reportVulnerability
bug_reportVulnerability

Gafgyt C0XMO botnet exploits DD-WRT router flaw, kills rival malware

DD-WRT router firmware (specific versions not disclosed). Affects devices across multiple CPU architectures. No CVE assigned yet.

DD-WRT7 Jun · 12:17 UTC
Silent Ransom Group targets U.S. legal sector via fake IT supporthighperson_alertThreat Actor
person_alertThreat Actor

Silent Ransom Group targets U.S. legal sector via fake IT support

Silent Ransom Group is a threat actor conducting social engineering-driven intrusions against U.S. legal services and professional services organizations.

BleepingComputer7 Jun · 12:09 UTC
SolarWinds Serv-U DoS flaw actively exploited, added to CISA KEVhighbug_reportVulnerability
bug_reportVulnerability

SolarWinds Serv-U DoS flaw actively exploited, added to CISA KEV

SolarWinds Serv-U multi-protocol file server. Specific affected versions not disclosed in provided data. The vulnerability causes service crashes via denial-of-service attacks.

CVE-2026-283186 Jun · 06:14 UTC
AI finds 21 zero-days in FFmpeg; Chrome 149 patches 429 bugshighbug_reportVulnerability
bug_reportVulnerability

AI finds 21 zero-days in FFmpeg; Chrome 149 patches 429 bugs

FFmpeg media library (all versions prior to upcoming patch release); Google Chrome versions prior to 149 (all platforms). FFmpeg is embedded in countless applications, browsers, media players, and server-side processing pipelines.

FFmpeg6 Jun · 05:28 UTC
Miasma worm compromises 73 Microsoft GitHub repos in supply chain attackhighbug_reportVulnerability
bug_reportVulnerability

Miasma worm compromises 73 Microsoft GitHub repos in supply chain attack

73 Microsoft GitHub repositories across four organizations: Azure, Azure-Samples, Microsoft, and MicrosoftDocs. GitHub has disabled access to affected repositories.

Microsoft6 Jun · 04:58 UTC
Cisco Catalyst SD-WAN Manager CVE-2026-20245 exploited in wild, no patchhighbug_reportVulnerability
bug_reportVulnerability

Cisco Catalyst SD-WAN Manager CVE-2026-20245 exploited in wild, no patch

Cisco Catalyst SD-WAN Manager across all deployment types: On-Prem, Cloud-Pro, Cloud (Cisco Managed), and Government (FedRAMP). Specific affected versions not disclosed. CVSS 7.8 (High).

CVE-2026-202456 Jun · 02:19 UTC