Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
18 / 18 results
highbug_reportVulnerabilityShai-Hulud infostealer now targets 469 credential locations in dev tools
Developer workstations, CI/CD pipelines, cloud configurations, AI tool configs, package registries (npm, GitHub, Docker), and any environment storing long-lived credentials or tokens.
criticalbug_reportVulnerabilityJFrog Artifactory auth bypass exploited to forge admin tokens
JFrog Artifactory self-managed instances in default configuration. Patched in versions 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, and 7.161.20 (released August 28, 2026). JFrog Cloud environments already protected.
criticalbug_reportVulnerabilityJFrog Artifactory auth bypass CVE-2026-82329 under active exploitation
JFrog Artifactory versions 7.161.0-7.161.19, 7.146.0-7.146.36, 7.133.0-7.133.28, 7.125.0-7.125.19, 7.117.0-7.117.27, and 7.111.4-7.111.21. Affects default configurations of self-managed instances. JFrog Access component specifically vulnerable.
criticalbug_reportVulnerabilityCritical GitLab GraphQL flaw allows unauthenticated project deletion
GitLab Community Edition (CE) and Enterprise Edition (EE) self-managed installations: all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4.
highbug_reportVulnerabilityChainDrop npm worm infects 400+ packages, steals secrets via blockchain C2
Over 400 npm packages including widely used packages like keyv and cacheable-request. Affects developer workstations, CI/CD pipelines (especially GitHub Actions), cloud environments, and downstream software users.
criticalbug_reportVulnerabilityGitea CVE-2026-59774: Unauthenticated file read via Org-mode markup
Gitea versions 1.22.1 through 1.27.0. Self-hosted instances with public repositories and Org-mode rendering enabled are vulnerable. Gitea Cloud instances upgraded automatically. Fixed in version 1.27.1.
criticalbug_reportVulnerabilityJetBrains TeamCity auth bypass enables RCE on all on-premises versions
JetBrains TeamCity On-Premises, all versions prior to 2025.11.7 and 2026.1.3. TeamCity Cloud is not affected. CVE-2026-63077 allows authentication bypass via agent polling protocol over HTTPS, leading to remote code execution with server process priv…
criticalbug_reportVulnerabilityJetBrains TeamCity RCE allows unauthenticated OS command execution
JetBrains TeamCity On-Premises, all versions prior to 2025.11.7 and 2026.1.3. TeamCity Cloud instances already patched. Vulnerability exploitable via agent polling protocol with HTTP(S) access to TeamCity server.
highperson_alertThreat ActorGitHub Actions Abused to Scan and Exploit cPanel/WHM Servers
The threat actor behind this campaign remains unattributed. The operation demonstrates sophisticated understanding of GitHub Actions infrastructure and supply chain attack vectors.
highbug_reportVulnerabilityGitHub commit verification flaw allows signature reuse on rewritten commits
GitHub's commit verification system for GPG/SSH-signed commits. All repositories using signed commits with GitHub's "Verified" badge are potentially affected. The flaw is in GitHub's verification logic, not Git itself.
criticalbug_reportVulnerabilityGitea Docker auth bypass under active probing (CVE-2026-20896)
Gitea Docker images with improper X-WEBAUTH-USER header validation. Specific vulnerable versions not provided; affects deployments trusting reverse proxy authentication headers without IP restrictions.
criticalbug_reportVulnerabilityArgo CD repo-server RCE enables cluster takeover, no patch available
Argo CD repo-server component, all versions (specific affected versions not disclosed). Exploitation requires access to internal network port where repo-server listens.
highbug_reportVulnerabilityAgentic coding tools vulnerable to hidden malicious payloads in repos
Agentic coding tools and AI-assisted development platforms that automatically fetch and execute code from GitHub repositories. Specific products not disclosed.
highbug_reportVulnerabilityGitHub blocks pwn request attacks in actions/checkout starting June 2026
GitHub Actions workflows using actions/checkout with pull_request_target trigger. Organizations using GitHub Actions for CI/CD pipelines are affected. The security update applies to all repositories using the actions/checkout action after June 18, 20…
criticalbug_reportVulnerabilityJenkins RCE vulnerability requires immediate patching per CERT.BE
Jenkins (specific versions not disclosed in alert). Vulnerability enables arbitrary remote code execution. CVE identifier not yet assigned or published.
highbug_reportVulnerabilityPrompt injection in Claude Code GitHub Action exposes workflow secrets
Anthropic's Claude Code GitHub Action (prior to mitigation). Affects GitHub workflows using the action with access to repository secrets. Vulnerability exploitable when action processes untrusted input from pull requests or external sources.
highbug_reportVulnerabilityGitea auth bypass exposes private container images to unauthenticated users
Gitea versions prior to 1.26.2. All deployments using Gitea's container registry feature are affected. Unauthenticated remote attackers can pull private container images without credentials.
criticalbug_reportVulnerabilityCompromised @antv npm packages deploy credential-stealing malware
Multiple @antv npm packages compromised with Mini Shai-Hulud malware. Affects Linux-based CI/CD pipelines using npm install. Targets credentials from GitHub, AWS, Kubernetes, HashiCorp Vault, npm, and 1Password.