Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 59 results
Active filter:tag: #government✕ clear
CISA orders federal agencies to patch exploited Citrix NetScaler RCE by Aug 29criticalbug_reportVulnerability
bug_reportVulnerability

CISA orders federal agencies to patch exploited Citrix NetScaler RCE by Aug 29

Citrix NetScaler ADC and NetScaler Gateway appliances configured with Gateway VPN or AAA (Authentication, Authorization, and Auditing) virtual servers. CVE-2026-8452. Over 22,000 NetScaler ADC and 1,800 Gateway instances exposed online globally.

Citrix27 Aug · 07:16 UTC
DDoS campaign disrupts Norway's shared government digital infrastructurehighbug_reportVulnerability
bug_reportVulnerability

DDoS campaign disrupts Norway's shared government digital infrastructure

Norway's Digitaliseringsdirektoratet (Digdir) shared government infrastructure, including ID-porten (public login), eSignering (electronic signatures), secure digital mail, government forms, and data exchange services.

BleepingComputer25 Aug · 13:52 UTC
Operation QUICSILVER: China-nexus campaign targets Myanmar with QUICAgenthighperson_alertThreat Actor
person_alertThreat Actor

Operation QUICSILVER: China-nexus campaign targets Myanmar with QUICAgent

Operation QUICSILVER is attributed with moderate confidence to a China-nexus threat actor conducting cyber espionage operations against Myanmar. The actor demonstrates sophisticated tradecraft, leveraging social engineering lures themed around govern…

The Hacker News24 Aug · 09:51 UTC
CISA orders 3-day patch for exploited Zimbra RCE (CVE-2026-73570)criticalbug_reportVulnerability
bug_reportVulnerability

CISA orders 3-day patch for exploited Zimbra RCE (CVE-2026-73570)

Zimbra Collaboration Suite (ZCS) versions prior to 10.1.20. Exploitation requires SNMP notifications to be enabled. Over 12,000 Zimbra servers exposed online; 270+ confirmed compromised instances detected by Shadowserver.

Zimbra24 Aug · 08:45 UTC
CISA orders patching of two actively exploited TrueConf Server flawscriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders patching of two actively exploited TrueConf Server flaws

TrueConf Server, a self-hosted corporate messaging and video conferencing platform. CVE-2026-72529 (critical missing authentication allowing remote script execution via TCP port 4307) and CVE-2026-72530 (critical sandbox escape enabling arbitrary OS…

TrueConf21 Aug · 10:25 UTC
CISA: Critical MLflow SSRF flaw (CVE-2026-64849) exploited in the wildcriticalbug_reportVulnerability
bug_reportVulnerability

CISA: Critical MLflow SSRF flaw (CVE-2026-64849) exploited in the wild

MLflow open-source AI engineering platform, all versions prior to 3.15.0. Default MLflow Tracking Server deployments without authentication are vulnerable.

MLflow20 Aug · 09:06 UTC
SilkParasite Targets Central Asian Governments with Five New RATshighperson_alertThreat Actor
person_alertThreat Actor

SilkParasite Targets Central Asian Governments with Five New RATs

SilkParasite is a previously unreported cyber espionage operation first discovered in late 2025, assessed with medium confidence to be a China-nexus threat cluster.

The Hacker News19 Aug · 11:12 UTC
Windows IKE Extension RCE (CVE-2026-33824) actively exploitedcriticalbug_reportVulnerability
bug_reportVulnerability

Windows IKE Extension RCE (CVE-2026-33824) actively exploited

All supported Windows 10, Windows 11, and Windows Server versions. The vulnerability affects the Windows Internet Key Exchange (IKE) Service Extensions (MS-IKEE) component accessible via UDP ports 500 and 4500.

Microsoft19 Aug · 08:12 UTC
Iranian Cavern C2 Framework Evolves with DNS and Google Apps Script Relayhighperson_alertThreat Actor
person_alertThreat Actor

Iranian Cavern C2 Framework Evolves with DNS and Google Apps Script Relay

Cavern (aka Cav3rn) is a command-and-control framework attributed to Iranian nation-state threat actors, specifically linked to Cavern Manticore, a hacking group affiliated with Iran's Ministry of Intelligence and Security (MOIS).

The Hacker News17 Aug · 15:41 UTC
French tax authority breach exposes 678,000 records amid rising attackshighpublicGeopolitical
publicGeopolitical

French tax authority breach exposes 678,000 records amid rising attacks

The breach of France's General Directorate of Public Finances (DGFiP) represents the latest in a sustained pattern of cyberattacks targeting French government infrastructure throughout 2026.

French Ministry of the Economy and Finance17 Aug · 08:09 UTC
Swiss government SharePoint breach exposes 200 accounts via July flawshighpublicGeopolitical
publicGeopolitical

Swiss government SharePoint breach exposes 200 accounts via July flaws

The breach of Switzerland's Federal Office for Information Technology and Telecommunication (BIT) represents a significant compromise of neutral state infrastructure.

Microsoft6 Aug · 16:14 UTC
CISA orders 3-day patch for exploited IBM Langflow, N-central, Tomcat flawshighbug_reportVulnerability
bug_reportVulnerability

CISA orders 3-day patch for exploited IBM Langflow, N-central, Tomcat flaws

IBM Langflow (CVE-2026-9198, CVSS 9.8) - default deployments vulnerable to unauthenticated RCE via API endpoint chaining. N-able N-central (CVE-2026-18576) - all versions before 2026.3 allow unauthenticated admin account hijacking; incomplete patch b…

IBM5 Aug · 13:51 UTC
U.K. Police Legal Database Breach Exposes Officer Contact Data on Dark WebhighpublicGeopolitical
publicGeopolitical

U.K. Police Legal Database Breach Exposes Officer Contact Data on Dark Web

The breach of the Police National Legal Database represents a targeted exposure of U.K. law enforcement and criminal justice infrastructure, albeit limited to contact metadata rather than operational intelligence.

Police National Legal Database (PNLD)3 Aug · 07:13 UTC
Chinese-Speaking Actor Deploys OctLurk & SilkLurk in Central Asiahighperson_alertThreat Actor
person_alertThreat Actor

Chinese-Speaking Actor Deploys OctLurk & SilkLurk in Central Asia

A Chinese-speaking threat actor, not yet attributed to any known APT group, has been conducting targeted cyber espionage operations against government and strategic organizations in Central Asia and Syria since January 2025.

The Hacker News31 Jul · 16:52 UTC
Russian APT exploits OWA XSS flaw for persistent mailbox accesshighbug_reportVulnerability
bug_reportVulnerability

Russian APT exploits OWA XSS flaw for persistent mailbox access

Microsoft Outlook Web Access (OWA) vulnerable to CVE-2026-42897 (CVSS 8.1), a cross-site scripting flaw. Targets include U.S. and European government entities, telecommunications, financial, hospitality, and aerospace sectors.

Microsoft30 Jul · 05:40 UTC
East Asia-Linked Actor Deploys TELESHIM, MIXEDKEY, BINDCLOAK Against ME Govhighperson_alertThreat Actor
person_alertThreat Actor

East Asia-Linked Actor Deploys TELESHIM, MIXEDKEY, BINDCLOAK Against ME Gov

An unattributed threat actor assessed with moderate-to-high confidence to originate from East Asia, based on operational hours (4 a.m.–12 p.m. UTC, peaking 7–11 a.m.

The Hacker News27 Jul · 06:48 UTC
Hermes AI Agent Used for Post-Exploitation at Thai Finance Ministryhighperson_alertThreat Actor
person_alertThreat Actor

Hermes AI Agent Used for Post-Exploitation at Thai Finance Ministry

The threat actor behind this intrusion remains unattributed. Hunt.io assesses with low-to-medium confidence that the operator is Chinese-speaking or fluent in Chinese, based on linguistic artifacts (password containing "Leishen," meaning thunder god)…

Hermes AI24 Jul · 08:15 UTC
JadeProx Deploys TriBack Loader Against Asian, Latin American Targetshighperson_alertThreat Actor
person_alertThreat Actor

JadeProx Deploys TriBack Loader Against Asian, Latin American Targets

JadeProx is a China-nexus threat actor tracked by Group-IB, discovered through an exposed Alibaba Cloud server in Singapore in mid-April 2026. The actor targets government, healthcare, and education organizations across Asia and Latin America.

Alibaba Cloud23 Jul · 10:20 UTC
South Korea discloses 10-month breach of diplomatic training platformhighpublicGeopolitical
publicGeopolitical

South Korea discloses 10-month breach of diplomatic training platform

The compromise of South Korea's National Diplomatic Academy represents a significant intelligence collection operation targeting a key U.S. ally in Northeast Asia.

BleepingComputer22 Jul · 18:06 UTC
AI-assisted phishing toolkit targets Windows users in Mexico via fake gov sitehighbug_reportVulnerability
bug_reportVulnerability

AI-assisted phishing toolkit targets Windows users in Mexico via fake gov site

Windows users in Mexico targeted via fake government ID-lookup website. Delivery mechanism uses WebDAV to distribute infostealer malware. Toolkit contains 1,048 files including phishing templates, droppers, and builder documentation.

Microsoft20 Jul · 15:29 UTC
ViPNet update mechanism compromised to target Russian government agencieshighbug_reportVulnerability
bug_reportVulnerability

ViPNet update mechanism compromised to target Russian government agencies

ViPNet private networking software users, primarily Russian government agencies and organizations. All versions using the compromised update delivery mechanism are potentially affected. Specific version range not disclosed.

ViPNet19 Jul · 12:23 UTC
GoSerpent Malware Targets Southeast Asian Government and Diplomacyhighperson_alertThreat Actor
person_alertThreat Actor

GoSerpent Malware Targets Southeast Asian Government and Diplomacy

GoSerpent is a previously undocumented malware family discovered by Kaspersky researchers in late 2025. The malware is designed for long-term persistent access and intelligence gathering operations.

Kaspersky17 Jul · 06:46 UTC
CISA orders patching of actively exploited Fortinet FortiSandbox flawscriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders patching of actively exploited Fortinet FortiSandbox flaws

Fortinet FortiSandbox threat detection platform. Specific versions not provided in available data. Two vulnerabilities confirmed, CVE identifiers not yet disclosed.

Fortinet17 Jul · 05:03 UTC
CISA: Microsoft SharePoint RCE CVE-2026-58644 actively exploitedcriticalbug_reportVulnerability
bug_reportVulnerability

CISA: Microsoft SharePoint RCE CVE-2026-58644 actively exploited

Microsoft SharePoint Server (specific versions not disclosed). CVSS 9.8 critical remote code execution vulnerability.

CVE-2026-5864417 Jul · 04:42 UTC
CISA orders federal patch for exploited Langflow auth bypass by Fridaycriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders federal patch for exploited Langflow auth bypass by Friday

Langflow visual AI agent framework - specific versions not disclosed in summary. Federal agencies mandated to patch; private sector should assume all unpatched instances at risk.

Langflow8 Jul · 07:58 UTC
CISA orders patching of actively exploited Adobe ColdFusion flawcriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders patching of actively exploited Adobe ColdFusion flaw

Adobe ColdFusion commercial web application development platform. Specific affected versions not disclosed in summary, but CISA mandatory patching order indicates government-facing installations are priority targets.

Adobe8 Jul · 05:16 UTC
Iran-linked MOIS group deploys Cavern C2 framework against Israelhighperson_alertThreat Actor
person_alertThreat Actor

Iran-linked MOIS group deploys Cavern C2 framework against Israel

An Iranian threat actor affiliated with Iran's Ministry of Intelligence and Security (MOIS), tracked by Check Point Research. The group operates in support of Iranian state intelligence objectives, focusing on espionage operations against adversary n…

The Hacker News6 Jul · 16:34 UTC
China-nexus actor targets Indian finance sector via DcRAT malwarehighperson_alertThreat Actor
person_alertThreat Actor

China-nexus actor targets Indian finance sector via DcRAT malware

A suspected China-nexus threat actor is conducting Operation DragonReturn, a targeted espionage campaign against Indian taxpayers and finance professionals.

The Hacker News6 Jul · 08:58 UTC
Kairos extorts $1M from U.S. government via data theft without encryptionhighperson_alertThreat Actor
person_alertThreat Actor

Kairos extorts $1M from U.S. government via data theft without encryption

Kairos is a financially motivated threat actor that employs extortion tactics focused on data theft without deploying traditional ransomware encryption. The group targeted a U.S.

The Hacker News4 Jul · 10:47 UTC
Armored Likho targets government and energy sectors with BusySnakehighperson_alertThreat Actor
person_alertThreat Actor

Armored Likho targets government and energy sectors with BusySnake

Armored Likho is a previously undocumented threat actor attributed by Kaspersky to cyber attacks targeting government agencies and the electric power sector.

The Hacker News3 Jul · 11:36 UTC