Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

18 / 18 results
Active filter:tag: #devops✕ clear
Shai-Hulud infostealer now targets 469 credential locations in dev toolshighbug_reportVulnerability
bug_reportVulnerability

Shai-Hulud infostealer now targets 469 credential locations in dev tools

Developer workstations, CI/CD pipelines, cloud configurations, AI tool configs, package registries (npm, GitHub, Docker), and any environment storing long-lived credentials or tokens.

The Hacker News3 Sep · 08:36 UTC
JFrog Artifactory auth bypass exploited to forge admin tokenscriticalbug_reportVulnerability
bug_reportVulnerability

JFrog Artifactory auth bypass exploited to forge admin tokens

JFrog Artifactory self-managed instances in default configuration. Patched in versions 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, and 7.161.20 (released August 28, 2026). JFrog Cloud environments already protected.

CVE-2026-823292 Sep · 13:47 UTC
JFrog Artifactory auth bypass CVE-2026-82329 under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

JFrog Artifactory auth bypass CVE-2026-82329 under active exploitation

JFrog Artifactory versions 7.161.0-7.161.19, 7.146.0-7.146.36, 7.133.0-7.133.28, 7.125.0-7.125.19, 7.117.0-7.117.27, and 7.111.4-7.111.21. Affects default configurations of self-managed instances. JFrog Access component specifically vulnerable.

CVE-2026-823291 Sep · 15:53 UTC
Critical GitLab GraphQL flaw allows unauthenticated project deletioncriticalbug_reportVulnerability
bug_reportVulnerability

Critical GitLab GraphQL flaw allows unauthenticated project deletion

GitLab Community Edition (CE) and Enterprise Edition (EE) self-managed installations: all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4.

CVE-2026-1947817 Aug · 19:03 UTC
ChainDrop npm worm infects 400+ packages, steals secrets via blockchain C2highbug_reportVulnerability
bug_reportVulnerability

ChainDrop npm worm infects 400+ packages, steals secrets via blockchain C2

Over 400 npm packages including widely used packages like keyv and cacheable-request. Affects developer workstations, CI/CD pipelines (especially GitHub Actions), cloud environments, and downstream software users.

npm6 Aug · 20:26 UTC
Gitea CVE-2026-59774: Unauthenticated file read via Org-mode markupcriticalbug_reportVulnerability
bug_reportVulnerability

Gitea CVE-2026-59774: Unauthenticated file read via Org-mode markup

Gitea versions 1.22.1 through 1.27.0. Self-hosted instances with public repositories and Org-mode rendering enabled are vulnerable. Gitea Cloud instances upgraded automatically. Fixed in version 1.27.1.

CVE-2026-597745 Aug · 09:04 UTC
JetBrains TeamCity auth bypass enables RCE on all on-premises versionscriticalbug_reportVulnerability
bug_reportVulnerability

JetBrains TeamCity auth bypass enables RCE on all on-premises versions

JetBrains TeamCity On-Premises, all versions prior to 2025.11.7 and 2026.1.3. TeamCity Cloud is not affected. CVE-2026-63077 allows authentication bypass via agent polling protocol over HTTPS, leading to remote code execution with server process priv…

JetBrains30 Jul · 20:01 UTC
JetBrains TeamCity RCE allows unauthenticated OS command executioncriticalbug_reportVulnerability
bug_reportVulnerability

JetBrains TeamCity RCE allows unauthenticated OS command execution

JetBrains TeamCity On-Premises, all versions prior to 2025.11.7 and 2026.1.3. TeamCity Cloud instances already patched. Vulnerability exploitable via agent polling protocol with HTTP(S) access to TeamCity server.

CVE-2026-6307728 Jul · 06:11 UTC
GitHub Actions Abused to Scan and Exploit cPanel/WHM Servershighperson_alertThreat Actor
person_alertThreat Actor

GitHub Actions Abused to Scan and Exploit cPanel/WHM Servers

The threat actor behind this campaign remains unattributed. The operation demonstrates sophisticated understanding of GitHub Actions infrastructure and supply chain attack vectors.

GitHub23 Jul · 09:28 UTC
GitHub commit verification flaw allows signature reuse on rewritten commitshighbug_reportVulnerability
bug_reportVulnerability

GitHub commit verification flaw allows signature reuse on rewritten commits

GitHub's commit verification system for GPG/SSH-signed commits. All repositories using signed commits with GitHub's "Verified" badge are potentially affected. The flaw is in GitHub's verification logic, not Git itself.

GitHub8 Jul · 09:51 UTC
Gitea Docker auth bypass under active probing (CVE-2026-20896)criticalbug_reportVulnerability
bug_reportVulnerability

Gitea Docker auth bypass under active probing (CVE-2026-20896)

Gitea Docker images with improper X-WEBAUTH-USER header validation. Specific vulnerable versions not provided; affects deployments trusting reverse proxy authentication headers without IP restrictions.

CVE-2026-208966 Jul · 14:28 UTC
Argo CD repo-server RCE enables cluster takeover, no patch availablecriticalbug_reportVulnerability
bug_reportVulnerability

Argo CD repo-server RCE enables cluster takeover, no patch available

Argo CD repo-server component, all versions (specific affected versions not disclosed). Exploitation requires access to internal network port where repo-server listens.

Argo CD1 Jul · 17:40 UTC
Agentic coding tools vulnerable to hidden malicious payloads in reposhighbug_reportVulnerability
bug_reportVulnerability

Agentic coding tools vulnerable to hidden malicious payloads in repos

Agentic coding tools and AI-assisted development platforms that automatically fetch and execute code from GitHub repositories. Specific products not disclosed.

BleepingComputer27 Jun · 12:22 UTC
GitHub blocks pwn request attacks in actions/checkout starting June 2026highbug_reportVulnerability
bug_reportVulnerability

GitHub blocks pwn request attacks in actions/checkout starting June 2026

GitHub Actions workflows using actions/checkout with pull_request_target trigger. Organizations using GitHub Actions for CI/CD pipelines are affected. The security update applies to all repositories using the actions/checkout action after June 18, 20…

GitHub23 Jun · 12:22 UTC
Jenkins RCE vulnerability requires immediate patching per CERT.BEcriticalbug_reportVulnerability
bug_reportVulnerability

Jenkins RCE vulnerability requires immediate patching per CERT.BE

Jenkins (specific versions not disclosed in alert). Vulnerability enables arbitrary remote code execution. CVE identifier not yet assigned or published.

Jenkins17 Jun · 12:42 UTC
Prompt injection in Claude Code GitHub Action exposes workflow secretshighbug_reportVulnerability
bug_reportVulnerability

Prompt injection in Claude Code GitHub Action exposes workflow secrets

Anthropic's Claude Code GitHub Action (prior to mitigation). Affects GitHub workflows using the action with access to repository secrets. Vulnerability exploitable when action processes untrusted input from pull requests or external sources.

Anthropic5 Jun · 14:46 UTC
Gitea auth bypass exposes private container images to unauthenticated usershighbug_reportVulnerability
bug_reportVulnerability

Gitea auth bypass exposes private container images to unauthenticated users

Gitea versions prior to 1.26.2. All deployments using Gitea's container registry feature are affected. Unauthenticated remote attackers can pull private container images without credentials.

CVE-2026-2777127 May · 08:06 UTC
Compromised @antv npm packages deploy credential-stealing malwarecriticalbug_reportVulnerability
bug_reportVulnerability

Compromised @antv npm packages deploy credential-stealing malware

Multiple @antv npm packages compromised with Mini Shai-Hulud malware. Affects Linux-based CI/CD pipelines using npm install. Targets credentials from GitHub, AWS, Kubernetes, HashiCorp Vault, npm, and 1Password.

npm20 May · 15:48 UTC