Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-21 · 02:09 UTC
articleTotal: 606 reports

Filtered Reports

13 / 13 results
Active filter:tag: #cloud-services✕ clear
Google Dialogflow CX flaw lets attackers hijack agents in same GCP projectcriticalbug_reportVulnerability
bug_reportVulnerability

Google Dialogflow CX flaw lets attackers hijack agents in same GCP project

Google Dialogflow CX agents with Code Block feature enabled, within shared Google Cloud projects. Requires attacker to have edit rights on at least one agent in the project.

Google14:37 UTC
DEBULL Campaign Exploits Microsoft Device Code Flow for M365 Phishinghighperson_alertThreat Actor
person_alertThreat Actor

DEBULL Campaign Exploits Microsoft Device Code Flow for M365 Phishing

DEBULL is a phishing campaign active from late June through early July 2026, targeting Microsoft 365 accounts through abuse of Microsoft's legitimate device-code flow authentication mechanism.

Microsoft13:14 UTC
ConsentFix and ClickFix campaigns hijack M365 accounts via OAuth token thefthighbug_reportVulnerability
bug_reportVulnerability

ConsentFix and ClickFix campaigns hijack M365 accounts via OAuth token theft

Microsoft 365 accounts across all organizations using OAuth authentication. Campaigns target users through social engineering to approve malicious OAuth consent prompts, bypassing MFA protections by stealing valid authentication tokens.

Microsoft12:00 UTC
Password-spray campaign hits Microsoft 365 with 81M login attemptshighbug_reportVulnerability
bug_reportVulnerability

Password-spray campaign hits Microsoft 365 with 81M login attempts

Microsoft 365 environments (Exchange Online, Azure AD/Entra ID, SharePoint, Teams). All organizations using M365 cloud services are potential targets. Attack focuses on user authentication endpoints.

Microsoft14:38 UTC
Weekly threat roundup: Claude abuse, npm poisoning, phishing campaignshighbug_reportVulnerability
bug_reportVulnerability

Weekly threat roundup: Claude abuse, npm poisoning, phishing campaigns

Multiple platforms and products: Claude AI chat interface, npm package ecosystem (NastyC2), OAuth device-code flows, browser extensions (unspecified), macOS systems, cloud management agents, and internet-exposed edge devices.

Claude13:27 UTC
Microsoft 365 Copilot SearchLeak allows data exfiltration via trusted linkhighbug_reportVulnerability
bug_reportVulnerability

Microsoft 365 Copilot SearchLeak allows data exfiltration via trusted link

Microsoft 365 Copilot Enterprise Search. All organizations using M365 Copilot with Enterprise Search enabled are potentially affected. Specific version details not disclosed.

Microsoft13:09 UTC
SearchLeak in Microsoft 365 Copilot enables data theft via crafted URLscriticalbug_reportVulnerability
bug_reportVulnerability

SearchLeak in Microsoft 365 Copilot enables data theft via crafted URLs

Microsoft 365 Copilot Enterprise. All organizations using Copilot with access to mailbox, OneDrive, or SharePoint data are potentially affected. Specific vulnerable versions not disclosed.

Microsoft11:00 UTC
Cisco Catalyst SD-WAN Manager CVE-2026-20245 exploited in wild, no patchhighbug_reportVulnerability
bug_reportVulnerability

Cisco Catalyst SD-WAN Manager CVE-2026-20245 exploited in wild, no patch

Cisco Catalyst SD-WAN Manager across all deployment types: On-Prem, Cloud-Pro, Cloud (Cisco Managed), and Government (FedRAMP). Specific affected versions not disclosed. CVSS 7.8 (High).

CVE-2026-2024502:19 UTC
PCPJack Hijacks 230+ Cloud Servers for Covert SMTP Relay Networkhighperson_alertThreat Actor
person_alertThreat Actor

PCPJack Hijacks 230+ Cloud Servers for Covert SMTP Relay Network

PCPJack is a threat actor focused on compromising cloud infrastructure to establish illicit email relay networks. The actor has demonstrated capability to breach business servers across major cloud service providers (AWS, Google Cloud, Microsoft Azur…

Amazon Web Services03:34 UTC
Miasma supply chain attack compromises Red Hat npm packagescriticalbug_reportVulnerability
bug_reportVulnerability

Miasma supply chain attack compromises Red Hat npm packages

Red Hat Cloud Services npm packages (@redhat-cloud-services scope). Affects developers and CI/CD pipelines using these packages. Scope includes any environment where compromised packages were installed.

Red Hat15:40 UTC
Malicious npm package codexui-android steals OpenAI tokens, 29K downloadshighbug_reportVulnerability
bug_reportVulnerability

Malicious npm package codexui-android steals OpenAI tokens, 29K downloads

npm package codexui-android (all versions). Targets developers using OpenAI Codex APIs. Affects organizations with Node.js/npm development environments where this package was installed.

OpenAI07:31 UTC
Mini Shai-Hulud: Typosquatted npm Packages Target Developer Credentialshighperson_alertThreat Actor
person_alertThreat Actor

Mini Shai-Hulud: Typosquatted npm Packages Target Developer Credentials

Mini Shai-Hulud is a threat actor campaign focused on compromising software development environments through supply chain attacks. The actor leverages typosquatting techniques against the npm package ecosystem to distribute malicious packages that ma…

npm01:04 UTC
ROADtools Framework Misused in Nation-State Cloud Intrusionshighperson_alertThreat Actor
person_alertThreat Actor

ROADtools Framework Misused in Nation-State Cloud Intrusions

Multiple threat actors, including nation-state groups, are misusing the open-source ROADtools framework for cloud intrusions. ROADtools is a legitimate Azure AD reconnaissance toolkit designed for security assessments, but has been co-opted by advers…

Unit 42 (Palo Alto)08:00 UTC