Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 420 results
highperson_alertThreat ActorFulcrumSec claims 86 GB Manchester Airports Group data theft
FulcrumSec is a financially motivated data-extortion group active since 2025. The group specializes in stealing sensitive corporate data and threatening to publish it rather than deploying ransomware or encrypting victim systems.
highpublicGeopoliticalBerlin refuses ransom demand after Rhysida-linked breach of state network
The August 2026 compromise of Berlin's state administrative network represents a significant escalation in ransomware targeting of European critical infrastructure and government services.
criticalbug_reportVulnerabilityownCloud CVE-2023-49105 exploited to steal nuclear records from Philippines
ownCloud core versions 10.6.0 through 10.13.0. The vulnerability is a WebDAV API authentication bypass allowing unauthenticated file access when usernames are known and no signing-key is configured (default state). Fixed in version 10.13.1.
highbug_reportVulnerabilityWatchGuard Fireware OS vulnerabilities require immediate patching
WatchGuard Fireware OS - specific versions not provided in advisory. Affects WatchGuard firewall appliances running vulnerable Fireware OS versions.
criticalbug_reportVulnerabilityZBT routers ship with factory implants granting root access via network
ZBT (Shenzhen Zhibotong Electronics) routers and white-labeled variants. CVE-2026-74233 (DARKLANTERN) affects 16+ models including WE1326, WE826-T2, WE5926, WG3526 on firmware builds from 2019-2020.
highpublicGeopoliticalManchester Airports Group breach exposes traveler data across UK hubs
The breach of Manchester Airports Group—the UK's largest airport operator handling over 66 million passengers annually—represents a significant incident within critical national infrastructure.
criticalbug_reportVulnerabilityApache Log4j2 deserialization filter bypass enables remote code execution
Apache Log4j2 logging library. Specific affected versions not disclosed in available information. Impacts Java applications using Log4j2 with deserialization features enabled.
criticalbug_reportVulnerabilityVeeam ONE authentication bypass requires immediate patching
Veeam ONE backup management platform. Specific affected versions not disclosed in available information. Authentication bypass vulnerability allows unauthorized access.
highbug_reportVulnerabilityAustralia arrests two TeamPCP members behind global supply chain attacks
Over 1,000 organizations worldwide affected by supply chain attacks targeting open-source software and developer platforms. Confirmed victims include Trivy, LiteLLM, Telnyx, SAP, TanStack packages, European Commission, Mistral AI, OpenAI, and GitHub.…
highbug_reportVulnerabilityNCSC warns of increased targeting of internet-exposed OT systems globally
Organizations with operational technology (OT) systems exposed to the internet across multiple sectors globally, including UK critical national infrastructure and non-CNI sectors.
criticalbug_reportVulnerabilityTeamPCP supply chain attack compromised Trivy, KICS, LiteLLM; 1000+ orgs hit
Open-source tools: Trivy scanner, Checkmarx KICS, LiteLLM AI gateway. Attack spanned GitHub Actions, Docker Hub, npm, PyPI, OpenVSX ecosystems. Over 1,000 organizations potentially compromised, 500,000+ credentials stolen, 300GB+ data exfiltrated.
highbug_reportVulnerabilityAustralian police arrest two TeamPCP members behind supply chain attacks
Global software supply chain: hundreds of open-source packages on GitHub, NPM, and other repositories compromised since late 2023. Victims include 2,500+ organizations using LiteLLM AI gateway, 3,800+ GitHub repositories, and developers across major…
highbug_reportVulnerabilitySpark RAT campaign targets Cambodia via OPSWAT driver exploit
Organizations and individuals in Cambodia. Campaign abuses vulnerable OPSWAT AppRemover driver (ardrv.sys, CVE-2026-36425) via BYOVD technique. Targets systems running Microsoft Defender, Huorong Internet Security, Tencent PC Manager, and Qihoo 360.
highperson_alertThreat ActorDark Caracal deploys Go-based GoCaracal malware in Venezuela telecom
Dark Caracal (G0070) is a threat actor with a documented history of operations in Latin America since at least 2018. Arctic Wolf attributes the June 2026 GoCaracal intrusion to Dark Caracal with medium confidence based on multiple behavioral and tech…
criticalbug_reportVulnerabilityCISA orders federal agencies to patch exploited Citrix NetScaler RCE by Aug 29
Citrix NetScaler ADC and NetScaler Gateway appliances with Gateway VPN or AAA virtual server configurations. CVE-2026-8452 (high severity). Over 22,000 NetScaler ADC and 1,800 Gateway instances exposed online globally.
highbug_reportVulnerabilityGPUThor Rowhammer defeats ECC on NVIDIA RTX A6000, enables root escalation
NVIDIA Ampere workstation GPUs with GDDR6 memory: RTX A6000 (48GB), RTX A5000 (24GB), RTX A4500 (20GB), RTX A4000 (16GB). Attack requires unprivileged CUDA kernel execution. Other NVIDIA GPUs tested (A10, L4, L40, RTX 4090, A30) showed no bit flips.
criticalbug_reportVulnerabilityWatchGuard Agent RCE flaws require immediate patching
WatchGuard Agent (specific versions not disclosed in available data). Remote code execution vulnerabilities affecting WatchGuard Agent software used for endpoint management and authentication.
highperson_alertThreat ActorDoJ Disrupts QTFY Chinese State-Sponsored Infrastructure Targeting U.S.
QTFY is a Chinese state-sponsored threat actor employed by Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司), active since May 2018. The group functions as a digital quartermaster serving China's Ministry of State Security (MSS) and People…
highperson_alertThreat ActorNimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor
Nimbus Manticore is an Iranian state-sponsored APT group affiliated with the Islamic Revolutionary Guard Corps (IRGC). Also tracked as GalaxyGato, Mirage Kitten, Screening Serpens, Smoke Sandstorm, Subtle Snail, and UNC1549, the group is assessed to…
highpublicGeopoliticalBoston Scientific cyberattack disrupts global medical device operations
The cyberattack on Boston Scientific, one of the world's largest medical device manufacturers with operations in 127 countries and over $20 billion in annual revenue, underscores the persistent vulnerability of critical healthcare supply chains to cy…
highperson_alertThreat ActorFBI disrupts QTFY quartermaster infrastructure for Chinese espionage
QTFY (also tracked as QT, QTCYBER) is a China-based threat actor operating as a technical "quartermaster" providing reconnaissance, proxy management, and operational routing capabilities for Chinese cyber espionage operations.
highperson_alertThreat ActorINTERPOL Operation Jackal IV Targets Black Axe and West African Crime
Black Axe and associated West African organized crime groups are transnational criminal networks responsible for a significant share of global cyber-enabled financial fraud.
highpublicGeopoliticalLACMA discloses 2025 breach exposing SSNs and health data
The Los Angeles County Museum of Art breach represents a typical example of the persistent threat to U.S. cultural and public institutions from cybercriminal activity.
highbug_reportVulnerabilityBEC fraud campaign surges against Austrian orgs via impersonation
Austrian organizations across all sectors; targets finance, accounting, and HR departments. Attack vectors include email impersonation, compromised supplier accounts, and hijacked email threads. No specific product vulnerabilities exploited.
highperson_alertThreat ActorU.S. Sanctions Iran-Linked MOIS Cyber Actors for Infrastructure Attacks
Iran-linked cyber actors affiliated with Iran's Ministry of Intelligence and Security (MOIS), specifically members of the Tehran-based Mabna Institute. The group conducts cyber espionage operations in support of Iran's political objectives, including…
highbug_reportVulnerabilityDDoS campaign disrupts Norway's shared government digital infrastructure
Norway's Digitaliseringsdirektoratet (Digdir) shared government infrastructure, including ID-porten (public login), eSignering (electronic signatures), secure digital mail, government forms, and data exchange services.
criticalbug_reportVulnerabilityOAuth2 Proxy authentication bypass allows unauthorized access
OAuth2 Proxy (specific versions not disclosed in available data). All deployments using OAuth2 Proxy for authentication are potentially at risk.
criticalbug_reportVulnerabilityOracle critical vulnerability under active exploitation, patching urgent
Multiple Oracle products affected. Specific product names, versions, and CVE identifiers not disclosed in available advisory. CERT.BE warning indicates at least one critical-severity vulnerability among multiple flaws.
highperson_alertThreat ActorMirage2FA Campaign Hits 4,500 Orgs via Microsoft 365 AiTM Phishing
Mirage2FA is a commercial phishing-as-a-service (PhaaS) campaign active from 2024 to 2026, targeting Microsoft 365 accounts through adversary-in-the-middle (AiTM) techniques.
highperson_alertThreat ActorAfrican Crime Groups Targeted in 22-Country Cybercrime Crackdown
African crime groups, particularly West African criminal networks and the Black Axe cybercrime syndicate, are financially-motivated threat actors conducting global-scale cyber-enabled financial fraud.