Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
13 / 13 results
criticalbug_reportVulnerabilityGoogle Dialogflow CX flaw lets attackers hijack agents in same GCP project
Google Dialogflow CX agents with Code Block feature enabled, within shared Google Cloud projects. Requires attacker to have edit rights on at least one agent in the project.
highperson_alertThreat ActorDEBULL Campaign Exploits Microsoft Device Code Flow for M365 Phishing
DEBULL is a phishing campaign active from late June through early July 2026, targeting Microsoft 365 accounts through abuse of Microsoft's legitimate device-code flow authentication mechanism.
highbug_reportVulnerabilityConsentFix and ClickFix campaigns hijack M365 accounts via OAuth token theft
Microsoft 365 accounts across all organizations using OAuth authentication. Campaigns target users through social engineering to approve malicious OAuth consent prompts, bypassing MFA protections by stealing valid authentication tokens.
highbug_reportVulnerabilityPassword-spray campaign hits Microsoft 365 with 81M login attempts
Microsoft 365 environments (Exchange Online, Azure AD/Entra ID, SharePoint, Teams). All organizations using M365 cloud services are potential targets. Attack focuses on user authentication endpoints.
highbug_reportVulnerabilityWeekly threat roundup: Claude abuse, npm poisoning, phishing campaigns
Multiple platforms and products: Claude AI chat interface, npm package ecosystem (NastyC2), OAuth device-code flows, browser extensions (unspecified), macOS systems, cloud management agents, and internet-exposed edge devices.
highbug_reportVulnerabilityMicrosoft 365 Copilot SearchLeak allows data exfiltration via trusted link
Microsoft 365 Copilot Enterprise Search. All organizations using M365 Copilot with Enterprise Search enabled are potentially affected. Specific version details not disclosed.
criticalbug_reportVulnerabilitySearchLeak in Microsoft 365 Copilot enables data theft via crafted URLs
Microsoft 365 Copilot Enterprise. All organizations using Copilot with access to mailbox, OneDrive, or SharePoint data are potentially affected. Specific vulnerable versions not disclosed.
highbug_reportVulnerabilityCisco Catalyst SD-WAN Manager CVE-2026-20245 exploited in wild, no patch
Cisco Catalyst SD-WAN Manager across all deployment types: On-Prem, Cloud-Pro, Cloud (Cisco Managed), and Government (FedRAMP). Specific affected versions not disclosed. CVSS 7.8 (High).
highperson_alertThreat ActorPCPJack Hijacks 230+ Cloud Servers for Covert SMTP Relay Network
PCPJack is a threat actor focused on compromising cloud infrastructure to establish illicit email relay networks. The actor has demonstrated capability to breach business servers across major cloud service providers (AWS, Google Cloud, Microsoft Azur…
criticalbug_reportVulnerabilityMiasma supply chain attack compromises Red Hat npm packages
Red Hat Cloud Services npm packages (@redhat-cloud-services scope). Affects developers and CI/CD pipelines using these packages. Scope includes any environment where compromised packages were installed.
highbug_reportVulnerabilityMalicious npm package codexui-android steals OpenAI tokens, 29K downloads
npm package codexui-android (all versions). Targets developers using OpenAI Codex APIs. Affects organizations with Node.js/npm development environments where this package was installed.
highperson_alertThreat ActorMini Shai-Hulud: Typosquatted npm Packages Target Developer Credentials
Mini Shai-Hulud is a threat actor campaign focused on compromising software development environments through supply chain attacks. The actor leverages typosquatting techniques against the npm package ecosystem to distribute malicious packages that ma…
highperson_alertThreat ActorROADtools Framework Misused in Nation-State Cloud Intrusions
Multiple threat actors, including nation-state groups, are misusing the open-source ROADtools framework for cloud intrusions. ROADtools is a legitimate Azure AD reconnaissance toolkit designed for security assessments, but has been co-opted by advers…