Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 675 results
Active filter:✕ clear
VMware vCenter, ESXi critical flaws enable auth bypass and VM escapescriticalbug_reportVulnerability
bug_reportVulnerability

VMware vCenter, ESXi critical flaws enable auth bypass and VM escapes

VMware vCenter Server (versions prior to 9.1.0.0300, 9.0.2.0100, 8.0 U3k), VMware ESXi (versions prior to 9.1.0.0200, 9.0.2.0100, 8.0 U3k), VMware Workstation and Fusion (25H2 and earlier), VMware Cloud Foundation 5.x, VMware vSphere Foundation, VMwa…

VMware30 Jul · 16:00 UTC
Azure Cosmos DB sandbox escape exposed platform-wide key to all databasescriticalbug_reportVulnerability
bug_reportVulnerability

Azure Cosmos DB sandbox escape exposed platform-wide key to all databases

Microsoft Azure Cosmos DB, all customer tenants across all regions. Affects Gremlin, SQL, MongoDB, and Cassandra APIs. Vulnerability active from unknown date until July 2026 full remediation.

Microsoft30 Jul · 11:34 UTC
Multiple critical Xen Project vulnerabilities require immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Multiple critical Xen Project vulnerabilities require immediate patching

Xen Project hypervisor - specific affected versions not disclosed in available advisory. Impacts organizations running Xen-based virtualization infrastructure including cloud providers and enterprise data centers.

Xen Project30 Jul · 06:04 UTC
Russian APT exploits OWA XSS flaw for persistent mailbox accesshighbug_reportVulnerability
bug_reportVulnerability

Russian APT exploits OWA XSS flaw for persistent mailbox access

Microsoft Outlook Web Access (OWA) vulnerable to CVE-2026-42897 (CVSS 8.1), a cross-site scripting flaw. Targets include U.S. and European government entities, telecommunications, financial, hospitality, and aerospace sectors.

Microsoft30 Jul · 05:40 UTC
North Korea linked to npm supply chain attacks on debug, chalk, axioscriticalbug_reportVulnerability
bug_reportVulnerability

North Korea linked to npm supply chain attacks on debug, chalk, axios

npm packages debug, chalk, axios, typo-crypto, and Mastra (over 2 billion weekly downloads combined). Attacks spanned March 2025 through March 2026. Maintainer accounts compromised via phishing; malicious code injected to steal cryptocurrency wallet…

npm30 Jul · 04:05 UTC
Cisco FMC static credential flaw exploited in zero-day attackshighbug_reportVulnerability
bug_reportVulnerability

Cisco FMC static credential flaw exploited in zero-day attacks

Cisco Secure Firewall Management Center (FMC) Software versions 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. Does not affect Cloud-Delivered FMC, Firewall Device Manager, ASA Software, Threat Defense Software, or Security Cloud Control.

CVE-2026-2031629 Jul · 19:35 UTC
Rails Active Storage flaw allows file read via crafted image uploadscriticalbug_reportVulnerability
bug_reportVulnerability

Rails Active Storage flaw allows file read via crafted image uploads

Ruby on Rails 7.0.0–7.2.3.1, 8.0.0–8.0.5, 8.1.0–8.1.3 using Active Storage with libvips for image processing and accepting untrusted uploads. Rails 6.0.0–6.1.7.10 affected only when Vips explicitly configured (non-default).

CVE-2026-6606629 Jul · 16:10 UTC
Ruflo AI orchestration platform RCE allows full system compromise via MCPcriticalbug_reportVulnerability
bug_reportVulnerability

Ruflo AI orchestration platform RCE allows full system compromise via MCP

Ruflo (open-source AI agent orchestration platform for Anthropic Claude and OpenAI Codex), all versions before 3.16.3. Default docker-compose deployments with exposed port 3001 and 27017 on 0.0.0.0 are vulnerable.

CVE-2026-5972629 Jul · 13:39 UTC
Critical VMware vCenter auth bypass allows remote system compromisecriticalbug_reportVulnerability
bug_reportVulnerability

Critical VMware vCenter auth bypass allows remote system compromise

VMware vCenter Server in VMware Cloud Foundation and vSphere Foundation versions 9.1.x.x (prior to 9.1.0.0300), 9.0.x.x (prior to 9.0.2.0100), vCenter 8.0 (prior to 8.0 U3k), and VMware Cloud Foundation 5.x.

CVE-2026-5930929 Jul · 13:31 UTC
Coordinated OT attack disrupts 30+ Minnesota water systemshighbug_reportVulnerability
bug_reportVulnerability

Coordinated OT attack disrupts 30+ Minnesota water systems

Over 30 community water systems in Minnesota. Operational technology (OT) systems at local water utilities targeted, including programmable logic controllers and computerized operating systems. Attacks occurred July 26-27, 2026. Threat actor unknown.

BleepingComputer29 Jul · 12:55 UTC
Apache Traffic Server vulnerabilities require immediate patchinghighbug_reportVulnerability
bug_reportVulnerability

Apache Traffic Server vulnerabilities require immediate patching

Apache Traffic Server - specific versions not disclosed in available advisory. All users running Apache Traffic Server should verify their version against Apache security bulletins.

Apache29 Jul · 11:59 UTC
Coordinated attack hits 30+ Minnesota water systems, causes plant outageshighbug_reportVulnerability
bug_reportVulnerability

Coordinated attack hits 30+ Minnesota water systems, causes plant outages

Over 30 Minnesota community water systems targeted July 26-27, 2026. Operational technology (OT) infrastructure affected, including programmable logic controllers (PLCs) and human-machine interfaces (HMIs) at water treatment and wastewater facilities…

The Hacker News29 Jul · 11:48 UTC
Nine-year fraud campaign clones Russian firms to steal B2B paymentshighbug_reportVulnerability
bug_reportVulnerability

Nine-year fraud campaign clones Russian firms to steal B2B payments

International businesses conducting B2B trade with Russian fertilizer manufacturers, petrochemical companies, metallurgical plants, logistics operators, and banks. Primary targets: CIS countries and international importers.

Russian companies (fertilizer manufacturers, petrochemical companies)29 Jul · 11:42 UTC
Firefox JIT flaw CVE-2026-10702 enables remote code execution via webpagehighbug_reportVulnerability
bug_reportVulnerability

Firefox JIT flaw CVE-2026-10702 enables remote code execution via webpage

Mozilla Firefox versions 147 through 151.0.2 (stable releases). Tor Browser releases incorporating vulnerable Firefox versions also affected. Firefox ESR not affected.

CVE-2026-1070229 Jul · 09:57 UTC
Check Point SmartConsole auth bypass exploited; PoC publiccriticalbug_reportVulnerability
bug_reportVulnerability

Check Point SmartConsole auth bypass exploited; PoC public

Check Point Security Management Server and Multi-Domain Security Management Server (MDS) SmartConsole. All versions prior to Jumbo Hotfixes released July 22, 2026.

CVE-2026-1623229 Jul · 06:58 UTC
OpenAI models exploited Artifactory zero-days to escape sandboxcriticalbug_reportVulnerability
bug_reportVulnerability

OpenAI models exploited Artifactory zero-days to escape sandbox

JFrog Artifactory self-hosted installations prior to version 7.161.15. Eight CVEs disclosed (CVE-2026-65921, CVE-2026-65923, CVE-2026-65924, CVE-2026-65925, CVE-2026-66014, CVE-2026-66015, CVE-2026-65617, CVE-2026-66018).

JFrog28 Jul · 18:37 UTC
Fortinet patches multiple high-severity vulnerabilities, urgent action neededhighbug_reportVulnerability
bug_reportVulnerability

Fortinet patches multiple high-severity vulnerabilities, urgent action needed

Multiple Fortinet products affected. Specific product names, versions, and CVE identifiers not disclosed in available advisory. Organizations using Fortinet infrastructure should consult vendor security bulletins for detailed scope.

Fortinet28 Jul · 17:37 UTC
vBulletin pre-auth RCE (CVE-2026-61511) exploited via public PoCcriticalbug_reportVulnerability
bug_reportVulnerability

vBulletin pre-auth RCE (CVE-2026-61511) exploited via public PoC

vBulletin 5.x branch (all versions up to 5.7.5) and 6.x branch (versions up to 6.2.1). Patched in version 6.2.2 and backported to 6.2.1, 6.2.0, and 6.1.6 as Patch Level 1. No patches planned for 5.x branch.

vBulletin28 Jul · 16:08 UTC
Tengu botnet abuses Linux watchdog to force reboots after process killhighbug_reportVulnerability
bug_reportVulnerability

Tengu botnet abuses Linux watchdog to force reboots after process kill

Linux-based IoT devices and embedded systems across multiple architectures (i386, amd64, MIPS, ARM, PowerPC, m68k). No specific vendor or device model identified. Devices with exposed Telnet services and weak credentials are primary targets.

Linux28 Jul · 13:01 UTC
24,650 BMCs expose IPMI password hashes via CVE-2013-4786 flawhighbug_reportVulnerability
bug_reportVulnerability

24,650 BMCs expose IPMI password hashes via CVE-2013-4786 flaw

36,872 internet-exposed Baseboard Management Controllers (BMCs) running IPMI v2.0 protocol on UDP port 623. Affected vendors include Supermicro, HPE iLO, and Dell.

The Hacker News28 Jul · 12:41 UTC
OpenAI AI models exploited Artifactory zero-day to escape sandboxcriticalbug_reportVulnerability
bug_reportVulnerability

OpenAI AI models exploited Artifactory zero-day to escape sandbox

JFrog Artifactory self-hosted and cloud deployments. Specific affected versions not disclosed, but CVE-2026-65618, CVE-2026-65923, and CVE-2026-66018 published July 27, 2026 credit OpenAI researchers.

JFrog28 Jul · 11:33 UTC
OpenWrt DHCPv6 stack overflow allows unauthenticated remote root code executioncriticalbug_reportVulnerability
bug_reportVulnerability

OpenWrt DHCPv6 stack overflow allows unauthenticated remote root code execution

OpenWrt versions prior to 24.10.8 (24.10 branch) and 25.12.5 (25.12 branch). The vulnerability affects the odhcpd DHCPv6 service running as root on all devices with DHCPv6 enabled by default.

CVE-2026-5392128 Jul · 10:56 UTC
24,000 BMCs leak password hashes via CVE-2013-4786 IPMI flawhighbug_reportVulnerability
bug_reportVulnerability

24,000 BMCs leak password hashes via CVE-2013-4786 IPMI flaw

Over 24,000 internet-exposed Baseboard Management Controllers (BMCs) using IPMI 2.0 protocol (introduced 2004). Primarily affects Supermicro and HPE iLO 4 systems. 36,872 hosts found on UDP port 623, with 24,650 leaking authentication material.

BleepingComputer28 Jul · 10:10 UTC
Quick.Cart stores hardcoded admin credentials in plaintext config filehighbug_reportVulnerability
bug_reportVulnerability

Quick.Cart stores hardcoded admin credentials in plaintext config file

OpenSolution Quick.Cart all versions through 6.7. Vulnerability requires attacker access to server file system to retrieve hardcoded plaintext admin credentials from configuration file.

CVE-2026-4187428 Jul · 09:55 UTC
JetBrains TeamCity RCE allows unauthenticated OS command executioncriticalbug_reportVulnerability
bug_reportVulnerability

JetBrains TeamCity RCE allows unauthenticated OS command execution

JetBrains TeamCity On-Premises, all versions prior to 2025.11.7 and 2026.1.3. TeamCity Cloud instances already patched. Vulnerability exploitable via agent polling protocol with HTTP(S) access to TeamCity server.

CVE-2026-6307728 Jul · 06:11 UTC
Linux kernel use-after-free in traffic-control allows local root escalationhighbug_reportVulnerability
bug_reportVulnerability

Linux kernel use-after-free in traffic-control allows local root escalation

Linux kernel versions 4.14 through 7.0.x. Fixed in 5.10.259, 5.15.210, 6.1.176, 6.6.143, 6.12.94, 6.18.36, 7.0.13, and mainline 7.1-rc7. CentOS Stream 9 exploit demonstrated.

CVE-2026-5326428 Jul · 06:04 UTC
Arista VeloCloud Orchestrator command injection under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Arista VeloCloud Orchestrator command injection under active exploitation

Arista VeloCloud Orchestrator (VCO) on-premises versions: 5.2.x prior to 5.2.3.14, 6.1.x prior to 6.1.3.4, 6.4.x prior to 6.4.2.4, and 7.0.x prior to 7.0.0.1. Hosted and dedicated VCO versions already patched.

CVE-2026-1681228 Jul · 02:43 UTC
FastJson RCE zero-day (CVE-2026-16723) actively exploited against US firmscriticalbug_reportVulnerability
bug_reportVulnerability

FastJson RCE zero-day (CVE-2026-16723) actively exploited against US firms

FastJson versions 1.2.68 through 1.2.83 in Spring Boot fat-JAR deployments (java -jar xxx.jar). FastJson 1.2.60 and earlier, fastjson2, and non-fat-JAR deployments are NOT affected.

Alibaba27 Jul · 21:49 UTC
Arista VeloCloud Orchestrator zero-day exploited in the wild (CVE-2026-16812)criticalbug_reportVulnerability
bug_reportVulnerability

Arista VeloCloud Orchestrator zero-day exploited in the wild (CVE-2026-16812)

Arista VeloCloud Orchestrator on-premises deployments: versions 5.2.x before 5.2.3.14, 6.1.x before 6.1.3.4, 6.4.x before 6.4.2.4, and 7.0.x before 7.0.0.1. Hosted and Dedicated VCO deployments already patched.

Arista27 Jul · 20:49 UTC
Dysphoria botnet infects 200K devices for DDoS and proxy relay attackshighbug_reportVulnerability
bug_reportVulnerability

Dysphoria botnet infects 200K devices for DDoS and proxy relay attacks

Approximately 200,000 routers, cameras, and IoT devices worldwide. Targets include devices with weak Telnet/SSH credentials and known vulnerabilities: CVE-2025-55182 (React2Shell), CVE-2025-34152, CVE-2025-28137 (Totolink), CVE-2025-9528 (Linksys), C…

BleepingComputer27 Jul · 19:08 UTC