Curated Cyber Threat Intelligence
Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
scheduleUpdated 2026-07-21 · 02:09 UTC
articleTotal: 606 reports
Filtered Reports
2 / 2 results
criticalbug_reportVulnerabilitybug_reportVulnerability
Argo CD repo-server RCE enables cluster takeover, no patch available
Argo CD repo-server component, all versions (specific affected versions not disclosed). Exploitation requires access to internal network port where repo-server listens.
Argo CD17:40 UTC
criticalbug_reportVulnerabilitybug_reportVulnerability
Compromised @antv npm packages deploy credential-stealing malware
Multiple @antv npm packages compromised with Mini Shai-Hulud malware. Affects Linux-based CI/CD pipelines using npm install. Targets credentials from GitHub, AWS, Kubernetes, HashiCorp Vault, npm, and 1Password.
npm15:48 UTC