Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 30 results
criticalbug_reportVulnerabilityPaperCut NG/MF flaws chained for unauthenticated RCE, active exploitation
PaperCut NG and PaperCut MF (all unpatched versions). CVE-2026-81578 (CVSS 8.8, improper access control) and CVE-2026-82078 (CVSS 9.4, unsafe dynamic class loading) are chained to bypass authentication and execute arbitrary Java code.
highbug_reportVulnerabilityWeekly roundup: 296K IoT botnet, water system attacks, SharePoint RCE
Multiple products and sectors: 296,000 IoT devices compromised by Dysphoria botnet; 100+ water systems targeted (details not provided in excerpt); SharePoint RCE vulnerability chain (CVE/version unspecified); Android banking apps targeted by Octagon…
criticalbug_reportVulnerabilityWatchGuard Agent RCE flaws require immediate patching
WatchGuard Agent (specific versions not disclosed in available data). Remote code execution vulnerabilities affecting WatchGuard Agent software used for endpoint management and authentication.
highperson_alertThreat ActorOperation QUICSILVER: China-nexus campaign targets Myanmar with QUICAgent
Operation QUICSILVER is attributed with moderate confidence to a China-nexus threat actor conducting cyber espionage operations against Myanmar. The actor demonstrates sophisticated tradecraft, leveraging social engineering lures themed around govern…
criticalbug_reportVulnerabilityIBM i systems face critical vulnerabilities requiring immediate patching
IBM i systems (formerly AS/400). Specific versions and CVE identifiers not disclosed in advisory. Scope appears to be multiple severe vulnerabilities across the platform.
highperson_alertThreat ActorUAC-0145 Targets Ukrainian IT Workers via Fake Job Recruitment Campaign
UAC-0145 is a threat cluster operating as a subgroup within Sandworm (also tracked as APT44, Seashell Blizzard, UAC-0002, ELECTRUM, Telebots, IRON VIKING), a sophisticated nation-state hacking group affiliated with Russia's GRU military intelligence.…
highbug_reportVulnerabilityCSS attacks bypass webmail sanitizers to steal passwords and tokens
Microsoft Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail webmail interfaces. Attacks exploit CSS and HTML parsing discrepancies to escape message boundaries.
criticalbug_reportVulnerabilityCisco Secure Firewall Management Center under active exploitation
Cisco Secure Firewall Management Center (formerly Firepower Management Center). Specific affected versions not disclosed in available data. Vulnerability details including CVE identifier not yet published.
highbug_reportVulnerability24,650 BMCs expose IPMI password hashes via CVE-2013-4786 flaw
36,872 internet-exposed Baseboard Management Controllers (BMCs) running IPMI v2.0 protocol on UDP port 623. Affected vendors include Supermicro, HPE iLO, and Dell.
highbug_reportVulnerability24,000 BMCs leak password hashes via CVE-2013-4786 IPMI flaw
Over 24,000 internet-exposed Baseboard Management Controllers (BMCs) using IPMI 2.0 protocol (introduced 2004). Primarily affects Supermicro and HPE iLO 4 systems. 36,872 hosts found on UDP port 623, with 24,650 leaking authentication material.
highbug_reportVulnerabilityCertighost PoC released: AD CS flaw enables domain takeover via rogue CA
Microsoft Active Directory Certificate Services (AD CS) in Windows domains. CVE-2026-54121 patched in July 2026 Patch Tuesday. Affects environments using AD CS for certificate-based authentication where attackers have low-privileged domain user acces…
highbug_reportVulnerabilityCertighost exploit public for AD CS flaw allowing DC impersonation
Microsoft Active Directory Certificate Services (AD CS) on Windows Server 2012 through 2025 (including Server Core) and Windows 10 versions 1607 and 1809. Environments with Enterprise CA and default Machine certificate template are vulnerable.
criticalbug_reportVulnerabilityMicrosoft SharePoint RCE flaws actively exploited; immediate patching required
Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. Five critical vulnerabilities: CVE-2026-50522 (CVSS 9.8, deserialization RCE), CVE-2026-58644 (CVSS 9.8, unauthenticated RCE), CVE-2026-5…
highbug_reportVulnerabilityFake GitHub PoC repos deliver ChocoPoC trojan to security researchers
Vulnerability researchers and security professionals using GitHub to access proof-of-concept exploit code. The ChocoPoC malware targets Windows systems, stealing credentials, browser data, and files while establishing remote shell access.
criticalbug_reportVulnerabilityMicrosoft SharePoint RCE flaw under active exploitation (CVE-2026-45659)
Microsoft SharePoint Server, all versions vulnerable to deserialization attacks. Specific affected versions not yet disclosed.
highbug_reportVulnerabilityWhatsApp malware campaign uses fake business docs to deploy VBScript RATs
WhatsApp users across multiple countries. Attack vector: social engineering via WhatsApp messages containing malicious VBScript files disguised as business documents. Enables remote access to Windows PCs.
highbug_reportVulnerabilityCloud bucket hijacking flaw exploits global namespace across AWS, Azure, GCP
AWS S3, Azure Blob Storage, and Google Cloud Storage bucket naming systems. Affects organizations using cloud storage services across all three major cloud providers.
criticalbug_reportVulnerabilityCritical RCE in Splunk Enterprise under active exploitation
Splunk Enterprise (specific versions not disclosed in alert). The vulnerability enables remote code execution. CVE identifier not yet assigned or published.
highperson_alertThreat ActorGhostTree Abuses NTFS Junctions to Evade Microsoft Defender Scans
GhostTree is a threat actor that has developed an evasion technique exploiting recursive NTFS junctions to bypass antivirus scanning. The actor targets the information technology sector and leverages inherent Windows file system features to create in…
criticalbug_reportVulnerabilityIvanti Sentry RCE flaw under active exploitation, root access possible
Ivanti Sentry (formerly MobileIron Sentry) - Internet-exposed secure mobile gateways. Specific vulnerable versions not provided in summary, but patch recently released.
criticalbug_reportVulnerabilityWindows Server domain controllers under active RCE attack
Windows Server domain controllers (all supported versions). Specific version details not yet published by Microsoft. Unauthenticated remote code execution vulnerability.
FROST attack enables website-based user tracking via SSD timing analysis
All systems with SSDs accessed via web browsers supporting high-resolution JavaScript timers. Attack affects users across Windows, Linux, and macOS platforms. No specific browser, SSD model, or OS version is immune.
highbug_reportVulnerabilitySolarWinds Serv-U DoS flaw actively exploited, added to CISA KEV
SolarWinds Serv-U multi-protocol file server. Specific affected versions not disclosed in provided data. The vulnerability causes service crashes via denial-of-service attacks.
highperson_alertThreat ActorOP-512 Targets IIS Servers with Custom Web Shell Framework
OP-512 is a previously unreported threat cluster assessed by ReliaQuest with moderate to high confidence to be linked to China. The actor demonstrates espionage-focused objectives, leveraging custom web shell frameworks to compromise Microsoft Intern…
criticalbug_reportVulnerabilityCritical vulnerabilities in Gladinet Triofox require immediate patching
Gladinet Triofox file sharing and collaboration platform. Specific affected versions not disclosed in available data. All unpatched instances should be considered at risk.
highbug_reportVulnerabilityMicrosoft patches SharePoint RCE flaw via unsafe deserialization
Microsoft SharePoint Server (specific versions not disclosed). Vulnerability involves deserialization of untrusted data leading to remote code execution with CVSS 8.8.
criticalbug_reportVulnerabilityTrend Micro Apex One & Vision One SEP flaws under active exploit
Trend Micro Apex One and Trend Micro Vision One Endpoint Security (SEP). Specific vulnerable versions not disclosed in summary; multiple vulnerabilities confirmed under active exploitation.
criticalbug_reportVulnerabilityTrend Micro Apex One zero-day actively exploited in the wild
Trend Micro Apex One on Windows systems. Specific affected versions not disclosed. Zero-day vulnerability with no CVE assigned yet.
criticalbug_reportVulnerabilityMultiple critical vulnerabilities in Fortinet products require patching
Fortinet products: FortiSandbox, FortiOS, FortiAP, FortiAnalyzer, and FortiManager. Specific affected versions not provided in advisory. Multiple vulnerabilities ranging from critical to medium severity.
criticalbug_reportVulnerabilityMicrosoft patches critical WSUS RCE flaw with public PoC exploit
Windows Server Update Service (WSUS) on Windows Server. Specific versions not disclosed in out-of-band update. Affects organizations running WSUS infrastructure for Windows update management.