Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
16 / 16 results
highbug_reportVulnerabilityAttackers abuse Microsoft Teams external chat to impersonate IT support
Microsoft Teams users in enterprise environments with external collaboration enabled. All organizations using Teams for business communication are at risk if users accept external contact requests and grant remote access via RMM tools or Quick Assist…
highperson_alertThreat ActorSpring Ring Campaign Weaponizes Microsoft Teams for Vishing Attacks
Spring Ring is a coordinated social engineering campaign identified between January and April 2026 that leverages external Microsoft Teams accounts to impersonate IT help desk personnel.
highbug_reportVulnerabilityMicrosoft SharePoint RCE chain (CVE-2026-55040 + CVE-2026-63520) exploited
Microsoft SharePoint Server (on-premises). CVE-2026-55040: JWT authentication bypass. CVE-2026-63520: Business Connectivity Services RCE. Over 8,700 SharePoint servers exposed online. Specific vulnerable versions not disclosed in article.
criticalbug_reportVulnerabilityCisco Secure Firewall DoS flaw under active exploitation
Cisco Secure Firewall products (specific versions not disclosed in available data). Organizations using Cisco ASA, FTD, or Firepower appliances should assume exposure until vendor advisory is reviewed.
highperson_alertThreat ActorKali365 Campaign Weaponizes Microsoft Device Code Flow Against US Firms
Kali365 is a device code phishing campaign targeting US organizations through abuse of legitimate Microsoft authentication mechanisms. The campaign leverages a phishing kit designed to trick victims into approving attacker-controlled device codes on…
highperson_alertThreat ActorGreatness PhaaS Expands to AiTM and Device-Code Phishing via RingCentral
Greatness is a phishing-as-a-service (PhaaS) platform active since at least mid-2022, operated by cybercriminals who sell access for $289/month via a Telegram channel with thousands of subscribers.
highbug_reportVulnerabilityACR Stealer campaign uses ClickFix social engineering to steal M365 data
Microsoft 365 enterprise users and organizations. ACR Stealer targets browser credentials, session tokens, and M365 documents. Active since 2024 with two documented delivery chains using ClickFix social engineering lures.
highperson_alertThreat ActorDEBULL Campaign Exploits Microsoft Device Code Flow for M365 Phishing
DEBULL is a phishing campaign active from late June through early July 2026, targeting Microsoft 365 accounts through abuse of Microsoft's legitimate device-code flow authentication mechanism.
highbug_reportVulnerabilityConsentFix and ClickFix campaigns hijack M365 accounts via OAuth token theft
Microsoft 365 accounts across all organizations using OAuth authentication. Campaigns target users through social engineering to approve malicious OAuth consent prompts, bypassing MFA protections by stealing valid authentication tokens.
criticalbug_reportVulnerabilityOracle PeopleSoft RCE actively exploited, immediate patching required
Oracle PeopleSoft (specific versions not disclosed in alert). Remote code execution vulnerability affecting internet-facing PeopleSoft instances.
criticalbug_reportVulnerabilityOracle PeopleSoft zero-day CVE-2026-35273 exploited by ShinyHunters
Oracle PeopleSoft (all versions prior to June 10 patch). Confirmed exploitation targeting enterprise systems and universities. Vulnerability was unpatched during active exploitation window (May 27 - June 9).
criticalbug_reportVulnerabilityWindows Server domain controllers under active RCE attack
Windows Server domain controllers (all supported versions). Specific version details not yet published by Microsoft. Unauthenticated remote code execution vulnerability.
criticalbug_reportVulnerabilityMicrosoft SharePoint RCE vulnerability requires immediate patching
Microsoft SharePoint Server (specific versions not disclosed in advisory). Organizations running on-premises SharePoint deployments are affected. SharePoint Online managed by Microsoft likely already patched.
highperson_alertThreat ActorF5 BIG-IP Exploitation Leads to Confluence Compromise and Lateral Movement
The threat actor behind this campaign remains unattributed. Motivation appears to be credential theft and network persistence within enterprise environments.
criticalbug_reportVulnerabilityMicrosoft Exchange Server XSS flaw actively exploited for session hijacking
Microsoft Exchange Server (specific versions not disclosed). Cross-Site Scripting vulnerability enabling spoofing and session hijacking. No CVE assigned yet.
criticalbug_reportVulnerabilityCisco Catalyst SD-WAN auth bypass grants admin access to attackers
Cisco Catalyst SD-WAN platform. Specific affected versions not disclosed. Vulnerability allows authentication bypass leading to administrative access on SD-WAN infrastructure components.