Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 30 results
Active filter:tag: #information-technology✕ clear
PaperCut NG/MF flaws chained for unauthenticated RCE, active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

PaperCut NG/MF flaws chained for unauthenticated RCE, active exploitation

PaperCut NG and PaperCut MF (all unpatched versions). CVE-2026-81578 (CVSS 8.8, improper access control) and CVE-2026-82078 (CVSS 9.4, unsafe dynamic class loading) are chained to bypass authentication and execute arbitrary Java code.

PaperCut28 Aug · 15:12 UTC
Weekly roundup: 296K IoT botnet, water system attacks, SharePoint RCEhighbug_reportVulnerability
bug_reportVulnerability

Weekly roundup: 296K IoT botnet, water system attacks, SharePoint RCE

Multiple products and sectors: 296,000 IoT devices compromised by Dysphoria botnet; 100+ water systems targeted (details not provided in excerpt); SharePoint RCE vulnerability chain (CVE/version unspecified); Android banking apps targeted by Octagon…

The Hacker News27 Aug · 13:12 UTC
WatchGuard Agent RCE flaws require immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

WatchGuard Agent RCE flaws require immediate patching

WatchGuard Agent (specific versions not disclosed in available data). Remote code execution vulnerabilities affecting WatchGuard Agent software used for endpoint management and authentication.

WatchGuard27 Aug · 04:36 UTC
Operation QUICSILVER: China-nexus campaign targets Myanmar with QUICAgenthighperson_alertThreat Actor
person_alertThreat Actor

Operation QUICSILVER: China-nexus campaign targets Myanmar with QUICAgent

Operation QUICSILVER is attributed with moderate confidence to a China-nexus threat actor conducting cyber espionage operations against Myanmar. The actor demonstrates sophisticated tradecraft, leveraging social engineering lures themed around govern…

The Hacker News24 Aug · 09:51 UTC
IBM i systems face critical vulnerabilities requiring immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

IBM i systems face critical vulnerabilities requiring immediate patching

IBM i systems (formerly AS/400). Specific versions and CVE identifiers not disclosed in advisory. Scope appears to be multiple severe vulnerabilities across the platform.

IBM17 Aug · 07:37 UTC
UAC-0145 Targets Ukrainian IT Workers via Fake Job Recruitment Campaignhighperson_alertThreat Actor
person_alertThreat Actor

UAC-0145 Targets Ukrainian IT Workers via Fake Job Recruitment Campaign

UAC-0145 is a threat cluster operating as a subgroup within Sandworm (also tracked as APT44, Seashell Blizzard, UAC-0002, ELECTRUM, Telebots, IRON VIKING), a sophisticated nation-state hacking group affiliated with Russia's GRU military intelligence.…

The Hacker News11 Aug · 16:36 UTC
CSS attacks bypass webmail sanitizers to steal passwords and tokenshighbug_reportVulnerability
bug_reportVulnerability

CSS attacks bypass webmail sanitizers to steal passwords and tokens

Microsoft Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail webmail interfaces. Attacks exploit CSS and HTML parsing discrepancies to escape message boundaries.

Microsoft8 Aug · 06:03 UTC
Cisco Secure Firewall Management Center under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Cisco Secure Firewall Management Center under active exploitation

Cisco Secure Firewall Management Center (formerly Firepower Management Center). Specific affected versions not disclosed in available data. Vulnerability details including CVE identifier not yet published.

Cisco31 Jul · 06:58 UTC
24,650 BMCs expose IPMI password hashes via CVE-2013-4786 flawhighbug_reportVulnerability
bug_reportVulnerability

24,650 BMCs expose IPMI password hashes via CVE-2013-4786 flaw

36,872 internet-exposed Baseboard Management Controllers (BMCs) running IPMI v2.0 protocol on UDP port 623. Affected vendors include Supermicro, HPE iLO, and Dell.

The Hacker News28 Jul · 12:41 UTC
24,000 BMCs leak password hashes via CVE-2013-4786 IPMI flawhighbug_reportVulnerability
bug_reportVulnerability

24,000 BMCs leak password hashes via CVE-2013-4786 IPMI flaw

Over 24,000 internet-exposed Baseboard Management Controllers (BMCs) using IPMI 2.0 protocol (introduced 2004). Primarily affects Supermicro and HPE iLO 4 systems. 36,872 hosts found on UDP port 623, with 24,650 leaking authentication material.

BleepingComputer28 Jul · 10:10 UTC
Certighost PoC released: AD CS flaw enables domain takeover via rogue CAhighbug_reportVulnerability
bug_reportVulnerability

Certighost PoC released: AD CS flaw enables domain takeover via rogue CA

Microsoft Active Directory Certificate Services (AD CS) in Windows domains. CVE-2026-54121 patched in July 2026 Patch Tuesday. Affects environments using AD CS for certificate-based authentication where attackers have low-privileged domain user acces…

Microsoft27 Jul · 19:00 UTC
Certighost exploit public for AD CS flaw allowing DC impersonationhighbug_reportVulnerability
bug_reportVulnerability

Certighost exploit public for AD CS flaw allowing DC impersonation

Microsoft Active Directory Certificate Services (AD CS) on Windows Server 2012 through 2025 (including Server Core) and Windows 10 versions 1607 and 1809. Environments with Enterprise CA and default Machine certificate template are vulnerable.

Microsoft24 Jul · 12:15 UTC
Microsoft SharePoint RCE flaws actively exploited; immediate patching requiredcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft SharePoint RCE flaws actively exploited; immediate patching required

Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. Five critical vulnerabilities: CVE-2026-50522 (CVSS 9.8, deserialization RCE), CVE-2026-58644 (CVSS 9.8, unauthenticated RCE), CVE-2026-5…

Microsoft22 Jul · 08:39 UTC
Fake GitHub PoC repos deliver ChocoPoC trojan to security researchershighbug_reportVulnerability
bug_reportVulnerability

Fake GitHub PoC repos deliver ChocoPoC trojan to security researchers

Vulnerability researchers and security professionals using GitHub to access proof-of-concept exploit code. The ChocoPoC malware targets Windows systems, stealing credentials, browser data, and files while establishing remote shell access.

GitHub2 Jul · 05:24 UTC
Microsoft SharePoint RCE flaw under active exploitation (CVE-2026-45659)criticalbug_reportVulnerability
bug_reportVulnerability

Microsoft SharePoint RCE flaw under active exploitation (CVE-2026-45659)

Microsoft SharePoint Server, all versions vulnerable to deserialization attacks. Specific affected versions not yet disclosed.

CVE-2026-456592 Jul · 03:46 UTC
WhatsApp malware campaign uses fake business docs to deploy VBScript RATshighbug_reportVulnerability
bug_reportVulnerability

WhatsApp malware campaign uses fake business docs to deploy VBScript RATs

WhatsApp users across multiple countries. Attack vector: social engineering via WhatsApp messages containing malicious VBScript files disguised as business documents. Enables remote access to Windows PCs.

BleepingComputer22 Jun · 20:42 UTC
Cloud bucket hijacking flaw exploits global namespace across AWS, Azure, GCPhighbug_reportVulnerability
bug_reportVulnerability

Cloud bucket hijacking flaw exploits global namespace across AWS, Azure, GCP

AWS S3, Azure Blob Storage, and Google Cloud Storage bucket naming systems. Affects organizations using cloud storage services across all three major cloud providers.

Amazon Web Services22 Jun · 20:00 UTC
Critical RCE in Splunk Enterprise under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Critical RCE in Splunk Enterprise under active exploitation

Splunk Enterprise (specific versions not disclosed in alert). The vulnerability enables remote code execution. CVE identifier not yet assigned or published.

Splunk19 Jun · 13:33 UTC
GhostTree Abuses NTFS Junctions to Evade Microsoft Defender Scanshighperson_alertThreat Actor
person_alertThreat Actor

GhostTree Abuses NTFS Junctions to Evade Microsoft Defender Scans

GhostTree is a threat actor that has developed an evasion technique exploiting recursive NTFS junctions to bypass antivirus scanning. The actor targets the information technology sector and leverages inherent Windows file system features to create in…

Microsoft16 Jun · 12:17 UTC
Ivanti Sentry RCE flaw under active exploitation, root access possiblecriticalbug_reportVulnerability
bug_reportVulnerability

Ivanti Sentry RCE flaw under active exploitation, root access possible

Ivanti Sentry (formerly MobileIron Sentry) - Internet-exposed secure mobile gateways. Specific vulnerable versions not provided in summary, but patch recently released.

Ivanti11 Jun · 04:20 UTC
Windows Server domain controllers under active RCE attackcriticalbug_reportVulnerability
bug_reportVulnerability

Windows Server domain controllers under active RCE attack

Windows Server domain controllers (all supported versions). Specific version details not yet published by Microsoft. Unauthenticated remote code execution vulnerability.

Microsoft10 Jun · 06:47 UTC
FROST attack enables website-based user tracking via SSD timing analysishighbug_reportVulnerability
bug_reportVulnerability

FROST attack enables website-based user tracking via SSD timing analysis

All systems with SSDs accessed via web browsers supporting high-resolution JavaScript timers. Attack affects users across Windows, Linux, and macOS platforms. No specific browser, SSD model, or OS version is immune.

The Hacker News9 Jun · 07:50 UTC
SolarWinds Serv-U DoS flaw actively exploited, added to CISA KEVhighbug_reportVulnerability
bug_reportVulnerability

SolarWinds Serv-U DoS flaw actively exploited, added to CISA KEV

SolarWinds Serv-U multi-protocol file server. Specific affected versions not disclosed in provided data. The vulnerability causes service crashes via denial-of-service attacks.

CVE-2026-283186 Jun · 06:14 UTC
OP-512 Targets IIS Servers with Custom Web Shell Frameworkhighperson_alertThreat Actor
person_alertThreat Actor

OP-512 Targets IIS Servers with Custom Web Shell Framework

OP-512 is a previously unreported threat cluster assessed by ReliaQuest with moderate to high confidence to be linked to China. The actor demonstrates espionage-focused objectives, leveraging custom web shell frameworks to compromise Microsoft Intern…

Microsoft5 Jun · 10:33 UTC
Critical vulnerabilities in Gladinet Triofox require immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical vulnerabilities in Gladinet Triofox require immediate patching

Gladinet Triofox file sharing and collaboration platform. Specific affected versions not disclosed in available data. All unpatched instances should be considered at risk.

Gladinet5 Jun · 03:54 UTC
Microsoft patches SharePoint RCE flaw via unsafe deserializationhighbug_reportVulnerability
bug_reportVulnerability

Microsoft patches SharePoint RCE flaw via unsafe deserialization

Microsoft SharePoint Server (specific versions not disclosed). Vulnerability involves deserialization of untrusted data leading to remote code execution with CVSS 8.8.

CVE-2026-4565926 May · 09:49 UTC
Trend Micro Apex One & Vision One SEP flaws under active exploitcriticalbug_reportVulnerability
bug_reportVulnerability

Trend Micro Apex One & Vision One SEP flaws under active exploit

Trend Micro Apex One and Trend Micro Vision One Endpoint Security (SEP). Specific vulnerable versions not disclosed in summary; multiple vulnerabilities confirmed under active exploitation.

Trend Micro26 May · 08:17 UTC
Trend Micro Apex One zero-day actively exploited in the wildcriticalbug_reportVulnerability
bug_reportVulnerability

Trend Micro Apex One zero-day actively exploited in the wild

Trend Micro Apex One on Windows systems. Specific affected versions not disclosed. Zero-day vulnerability with no CVE assigned yet.

Trend Micro22 May · 11:39 UTC
Multiple critical vulnerabilities in Fortinet products require patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Multiple critical vulnerabilities in Fortinet products require patching

Fortinet products: FortiSandbox, FortiOS, FortiAP, FortiAnalyzer, and FortiManager. Specific affected versions not provided in advisory. Multiple vulnerabilities ranging from critical to medium severity.

Fortinet14 May · 05:08 UTC
Microsoft patches critical WSUS RCE flaw with public PoC exploitcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft patches critical WSUS RCE flaw with public PoC exploit

Windows Server Update Service (WSUS) on Windows Server. Specific versions not disclosed in out-of-band update. Affects organizations running WSUS infrastructure for Windows update management.

Microsoft24 Oct · 16:42 UTC