Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 358 results
highbug_reportVulnerabilityToshiba, Muji sites show credential-stealing prompts via polyfill supply chain
Toshiba and Muji public websites, potentially other sites using the compromised third-party polyfill library. Scope of affected sites and specific polyfill service not yet confirmed.
highbug_reportVulnerabilityCISA warns of active exploitation of SolarWinds Serv-U vulnerability
SolarWinds Serv-U managed file transfer software. Specific vulnerable versions not provided in summary; patch recently released by vendor.
criticalbug_reportVulnerabilitynpm supply chain attack: 50+ packages deliver IronWorm stealer and rootkit
npm ecosystem: over 50 compromised legitimate packages. Affects developers using npm for JavaScript/Node.js projects. IronWorm targets developer credentials and source code with eBPF kernel-level persistence.
highbug_reportVulnerabilityPrompt injection in Claude Code GitHub Action exposes workflow secrets
Anthropic's Claude Code GitHub Action (prior to mitigation). Affects GitHub workflows using the action with access to repository secrets. Vulnerability exploitable when action processes untrusted input from pull requests or external sources.
highbug_reportVulnerabilityAsin Android spyware targets Arabic-speaking users via fake apps
Android devices used by Arabic-speaking populations. Malware distributed through fake applications impersonating news sources, PDF utilities, and war-related content. Active campaigns identified since early 2025.
highbug_reportVulnerability900+ US fuel tank monitoring systems exposed online, vulnerable to attack
Over 900 automatic tank gauge (ATG) systems in the United States used to monitor fuel and chemical storage tanks in critical infrastructure. Specific vendors and product versions not disclosed.
highbug_reportVulnerabilityActive exploitation of PAN-OS CVE-2026-0257 reported by Unit 42
Palo Alto Networks PAN-OS (specific affected versions not provided in available data)
criticalbug_reportVulnerabilityActive exploitation of RCE flaw in Everest Forms Pro WordPress plugin
Everest Forms Pro WordPress plugin versions up to 1.9.12. Approximately 4,000 active installations at risk.
criticalbug_reportVulnerabilityCisco SD-WAN Manager zero-day CVE-2026-20245 exploited for root access
Cisco Catalyst SD-WAN Manager, all versions (specific affected versions not disclosed). Unpatched zero-day vulnerability enabling root privilege escalation.
criticalbug_reportVulnerabilityCritical vulnerabilities in Gladinet Triofox require immediate patching
Gladinet Triofox file sharing and collaboration platform. Specific affected versions not disclosed in available data. All unpatched instances should be considered at risk.
highbug_reportVulnerabilityCisco Unified Communications Manager high severity flaw with public PoC
Cisco Unified Communications Manager (CUCM). Specific affected versions not disclosed in alert. CVE identifier not yet assigned or published.
highbug_reportVulnerabilityRed Hat npm packages compromised with Miasma credential stealer
Over 30 npm packages in the '@redhat-cloud-services' namespace on npm registry. Affects developers and CI/CD pipelines consuming these packages. Specific package names and versions not yet disclosed.
criticalbug_reportVulnerabilityMiasma supply chain attack compromises Red Hat npm packages
Red Hat Cloud Services npm packages (@redhat-cloud-services scope). Affects developers and CI/CD pipelines using these packages. Scope includes any environment where compromised packages were installed.
highbug_reportVulnerabilityMeta AI bot exploited to hijack high-profile Instagram accounts
Meta Instagram platform, specifically the AI-powered customer support bot used for account recovery. High-profile accounts including Obama White House and U.S. Space Force Chief Master Sergeant were compromised.
highbug_reportVulnerabilityMalware campaign infects 2,000 WordPress sites using Steam profiles for C2
Nearly 2,000 WordPress websites compromised. All WordPress versions potentially affected depending on initial infection vector (likely vulnerable plugins, themes, or weak credentials).
highbug_reportVulnerabilityHard-coded credentials in KS-SOMED software enable unauthorized access
KS-SOMED software (specific versions not disclosed). Hard-coded credentials embedded in application code allow unauthorized access to affected systems.
criticalbug_reportVulnerabilityWindows Netlogon RCE under active exploitation after patch release
Microsoft Windows Netlogon service, all versions prior to recent patch. Affects domain controllers and systems with Netlogon service enabled. Specific CVE and affected version details not provided in alert.
highbug_reportVulnerabilityMalicious npm package codexui-android steals OpenAI tokens, 29K downloads
npm package codexui-android (all versions). Targets developers using OpenAI Codex APIs. Affects organizations with Node.js/npm development environments where this package was installed.
criticalbug_reportVulnerabilityWP Maps Pro plugin exploited to create rogue admin accounts on WordPress
WP Maps Pro WordPress plugin (all versions prior to patch). Over 15,000 installations via Envato Market. Affects WordPress sites using this plugin for Google Maps integration.
highbug_reportVulnerabilityWP Maps Pro plugin under active attack via admin account creation flaw
WP Maps Pro WordPress plugin (version details not specified). Affects WordPress sites with the plugin installed. Vulnerability allows unauthenticated attackers to create administrator accounts.
highbug_reportVulnerabilityDutch authorities dismantle botnet controlling 17M infected devices
At least 17 million infected devices globally including computers, tablets, smartphones, and IoT devices. Over 200 command-and-control servers located in the Netherlands were seized.
criticalbug_reportVulnerabilityPAN-OS GlobalProtect auth bypass CVE-2026-0257 under active exploit
Palo Alto Networks PAN-OS GlobalProtect VPN. Specific affected versions not disclosed in provided data. Impacts corporate networks using GlobalProtect for remote access.
highbug_reportVulnerabilityCIFSwitch: Linux kernel CIFS flaw enables local privilege escalation
Linux kernel CIFS implementation across multiple distributions. Specific affected kernel versions not yet disclosed. Requires local access to exploit.
highbug_reportVulnerabilityPalo Alto PAN-OS auth bypass (CVE-2026-0257) exploited in the wild
Palo Alto Networks PAN-OS and Prisma Access. Specific affected versions not disclosed in provided data. Vulnerability impacts VPN authentication mechanisms.
highbug_reportVulnerability33 malicious npm packages deployed in dependency confusion recon campaign
npm ecosystem; organizations using private npm packages with names vulnerable to dependency confusion attacks. Affects developer workstations, CI/CD pipelines, and build environments that may inadvertently install public packages instead of intended…
highbug_reportVulnerabilityThreat actors abuse ChatGPT sharing to host fake OpenAI outage pages
OpenAI ChatGPT users globally. Threat actors exploit ChatGPT's legitimate content-sharing feature (chatgpt.com shared links) to host convincing phishing pages that impersonate OpenAI outage notifications and distribute malware posing as the ChatGPT d…
highbug_reportVulnerabilityChatGPT Markdown renderer vulnerable to prompt injection and phishing
OpenAI ChatGPT web summary response renderer. All users interacting with ChatGPT's web interface that processes Markdown links and images are potentially affected. Specific version details not disclosed.
criticalbug_reportVulnerabilityMicrosoft May 2026 Patch Tuesday: 118 vulnerabilities, 16 critical
Microsoft products and services across the ecosystem. 118 total vulnerabilities: 16 critical severity, 102 important severity. Specific affected products and CVE identifiers not yet detailed in available information.
highbug_reportVulnerabilityOracle releases critical security patches for multiple products
Multiple Oracle products affected by high-severity vulnerabilities. Specific product names, versions, and CVE identifiers not provided in CERT.BE advisory. Likely part of Oracle's quarterly Critical Patch Update (CPU).
highbug_reportVulnerabilityCVE-2026-39987 in Marimo actively exploited for cloud credential theft
Marimo notebook platform (specific versions not disclosed). Affects internet-exposed Marimo notebook instances vulnerable to CVE-2026-39987.