Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

28 / 28 results
Active filter:tag: #infrastructure✕ clear
Apache Log4j2 deserialization filter bypass enables remote code executioncriticalbug_reportVulnerability
bug_reportVulnerability

Apache Log4j2 deserialization filter bypass enables remote code execution

Apache Log4j2 logging library (specific vulnerable versions not disclosed in available data). Affects Java applications using Log4j2 with deserialization features enabled.

Apache27 Aug · 12:57 UTC
VMware vCenter CVE-2026-59310 exploited in wild for RCE and persistencecriticalbug_reportVulnerability
bug_reportVulnerability

VMware vCenter CVE-2026-59310 exploited in wild for RCE and persistence

Broadcom VMware vCenter Server (all unpatched versions prior to late July 2026 patch release). Affects 361+ confirmed victim IPs across 47 countries, primarily Germany, US, Turkey, Iran, and France.

CVE-2026-5931012 Aug · 07:01 UTC
Progress Kemp LoadMaster command injection (CVE-2026-8037) exploitedcriticalbug_reportVulnerability
bug_reportVulnerability

Progress Kemp LoadMaster command injection (CVE-2026-8037) exploited

Progress Kemp LoadMaster appliances. All versions with vulnerable escape_quotes() function. Unauthenticated remote attack vector.

CVE-2026-80378 Aug · 04:52 UTC
NatJack attacks hijack TCP sessions via NAT manipulation; Windows & Linux CVEshighbug_reportVulnerability
bug_reportVulnerability

NatJack attacks hijack TCP sessions via NAT manipulation; Windows & Linux CVEs

Windows NAT (Hyper-V): Windows 11 24H2 <26100.8875, 25H2 <26200.8875, 26H1 <28000.2525, Server 2025 <26100.33158 (CVE-2026-56181, CVSS 8.3). Linux Netfilter conntrack: kernel <5.10.259, <5.15.210, <6.1.176, <6.6.143, <6.12.93, <6.18.35, <7.0.12, <7.1…

Microsoft7 Aug · 08:58 UTC
Zapscape KVM flaw allows L1 guest escape to host with nested virtualizationhighbug_reportVulnerability
bug_reportVulnerability

Zapscape KVM flaw allows L1 guest escape to host with nested virtualization

Linux kernel KVM/x86 shadow MMU in versions 5.9 through 7.1.5. Fixed in stable releases 6.6.148, 6.12.101, 6.18.42, 7.1.6, and 7.2-rc5. Affects systems running KVM hosts with nested virtualization exposed to untrusted guests.

CVE-2026-645616 Aug · 15:58 UTC
Cisco IOS/IOS XE vulnerabilities require immediate patching per CERT.BEhighbug_reportVulnerability
bug_reportVulnerability

Cisco IOS/IOS XE vulnerabilities require immediate patching per CERT.BE

Cisco IOS and IOS XE platforms. Specific affected versions not provided in advisory. Multiple vulnerabilities of high severity impact network infrastructure devices including routers and switches running these operating systems.

Cisco6 Aug · 13:38 UTC
Linux kernel Open vSwitch flaw grants local root; public exploit availablehighbug_reportVulnerability
bug_reportVulnerability

Linux kernel Open vSwitch flaw grants local root; public exploit available

Linux kernel Open vSwitch datapath. Fixed in stable kernels 5.15.212, 6.1.178, 6.6.145, 6.12.97, 6.18.40, and 7.1.5. Affects default configurations of AlmaLinux 9/10, Alpine 3.22-3.24, Amazon Linux 2023, Arch, CentOS Stream 9/10, Debian 12/13, Fedora…

CVE-2026-645315 Aug · 09:43 UTC
TP-Link patches 15 Omada ZTP flaws enabling network infiltration via RCEhighbug_reportVulnerability
bug_reportVulnerability

TP-Link patches 15 Omada ZTP flaws enabling network infiltration via RCE

TP-Link Omada network devices including Controllers, Gateways, Switches, Access Points, OLT platforms, Cloud services, and mobile applications (Omada, Omada Guard, TP-Link apps). Over 1,800 internet-accessible Omada controllers identified.

TP-Link4 Aug · 20:18 UTC
Chinese-speaking actor uses DeepSeek AI with Hermes Agent for automationhighperson_alertThreat Actor
person_alertThreat Actor

Chinese-speaking actor uses DeepSeek AI with Hermes Agent for automation

A Chinese-speaking threat actor leveraging artificial intelligence models to conduct cyberattacks. The actor employs the DeepSeek AI model in combination with the open-source Hermes Agent framework to enable autonomous offensive operations against in…

BleepingComputer31 Jul · 15:35 UTC
Critical vCenter vulnerabilities require immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical vCenter vulnerabilities require immediate patching

VMware vCenter Server component across multiple VMware product deployments. Specific affected versions not provided in advisory. Widespread impact expected given vCenter's role in VMware infrastructure management.

VMware31 Jul · 13:45 UTC
Tengu botnet abuses Linux watchdog to force reboots after process killhighbug_reportVulnerability
bug_reportVulnerability

Tengu botnet abuses Linux watchdog to force reboots after process kill

Linux-based IoT devices and embedded systems across multiple architectures (i386, amd64, MIPS, ARM, PowerPC, m68k). No specific vendor or device model identified. Devices with exposed Telnet services and weak credentials are primary targets.

Linux28 Jul · 13:01 UTC
Arista VeloCloud Orchestrator command injection under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Arista VeloCloud Orchestrator command injection under active exploitation

Arista VeloCloud Orchestrator (VCO) on-premises versions: 5.2.x prior to 5.2.3.14, 6.1.x prior to 6.1.3.4, 6.4.x prior to 6.4.2.4, and 7.0.x prior to 7.0.0.1. Hosted and dedicated VCO versions already patched.

CVE-2026-1681228 Jul · 02:43 UTC
Critical NGINX heap overflow enables RCE via crafted HTTP requestscriticalbug_reportVulnerability
bug_reportVulnerability

Critical NGINX heap overflow enables RCE via crafted HTTP requests

NGINX open source versions prior to 1.30.4 and 1.31.3, and NGINX Plus versions prior to 37.0.3.1. All deployments accepting HTTP requests from untrusted networks are at risk.

CVE-2026-4253319 Jul · 18:42 UTC
15-year-old Linux kernel flaw allows local privilege escalation to rootcriticalbug_reportVulnerability
bug_reportVulnerability

15-year-old Linux kernel flaw allows local privilege escalation to root

Linux kernel versions since 2011 across all mainstream distributions (Ubuntu, RHEL, Debian, SUSE, etc.). Any system running an unpatched kernel containing CVE-2026-43499 is vulnerable. Requires local authenticated access to exploit.

CVE-2026-434998 Jul · 04:16 UTC
UAT-7810 Deploys LONGLEASH Malware Against Network Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

UAT-7810 Deploys LONGLEASH Malware Against Network Infrastructure

UAT-7810 is a Chinese-linked threat actor focused on compromising internet-facing networking devices to expand their Operational Relay Box (ORB) network infrastructure.

Ruckus7 Jul · 16:52 UTC
Linux kernel traffic-control flaw grants local root via public exploitcriticalbug_reportVulnerability
bug_reportVulnerability

Linux kernel traffic-control flaw grants local root via public exploit

Linux kernel traffic-control subsystem (act_pedit module). All distributions running vulnerable kernel versions are affected. Specific patched versions not provided; assume unpatched kernels prior to June 16, 2026 vendor advisories are vulnerable.

CVE-2026-4633126 Jun · 11:57 UTC
FortiBleed: Russian IAB harvests 110M credentials from FortiGate devicescriticalperson_alertThreat Actor
person_alertThreat Actor

FortiBleed: Russian IAB harvests 110M credentials from FortiGate devices

FortiBleed is attributed to a Russian-speaking initial access broker (IAB) conducting large-scale credential harvesting operations since February 2026. The actor demonstrates advanced operational capabilities through systematic targeting of over 430,…

Fortinet23 Jun · 16:20 UTC
ProxySQL ACL bypass and heap corruption flaws threaten database securitycriticalbug_reportVulnerability
bug_reportVulnerability

ProxySQL ACL bypass and heap corruption flaws threaten database security

ProxySQL (specific versions not provided). Vulnerabilities include ACL bypass allowing unauthorized access and heap memory corruption potentially enabling remote code execution. Database proxy infrastructure is at risk.

ProxySQL22 Jun · 12:48 UTC
F5 patches high-severity flaws in NGINX Open Source and Gateway Fabrichighbug_reportVulnerability
bug_reportVulnerability

F5 patches high-severity flaws in NGINX Open Source and Gateway Fabric

NGINX Open Source and NGINX Gateway Fabric (specific versions not provided). Four CVEs: CVE-2026-11311, CVE-2026-42055, CVE-2026-42530, CVE-2026-50107. Affects organizations running NGINX web servers, reverse proxies, API gateways, and Kubernetes ing…

CVE-2026-1131119 Jun · 06:24 UTC
Cisco Catalyst SD-WAN Manager under active exploit (CVE-2026-20262)highbug_reportVulnerability
bug_reportVulnerability

Cisco Catalyst SD-WAN Manager under active exploit (CVE-2026-20262)

Cisco Catalyst SD-WAN Manager. Specific vulnerable versions not provided in summary. Affects web UI component accessible to authenticated remote users.

CVE-2026-2026216 Jun · 04:05 UTC
Cisco Catalyst SD-WAN Manager root privilege escalation under attackcriticalbug_reportVulnerability
bug_reportVulnerability

Cisco Catalyst SD-WAN Manager root privilege escalation under attack

Cisco Catalyst SD-WAN Manager (specific versions not provided). Vulnerability allows privilege escalation to root level on affected systems.

CVE-2026-2026215 Jun · 15:12 UTC
OceanLotus Targets Vietnamese Infrastructure with SPECTRALVIPER Backdoorhighperson_alertThreat Actor
person_alertThreat Actor

OceanLotus Targets Vietnamese Infrastructure with SPECTRALVIPER Backdoor

OceanLotus (also tracked as APT32, SeaLotus, APT-C-00, and Canvas Cyclone) is a Vietnam-aligned advanced persistent threat group attributed by multiple vendors to conducting cyber espionage operations.

The Hacker News11 Jun · 07:45 UTC
Cisco Catalyst SD-WAN Manager actively exploited (CVE-2026-20245)highbug_reportVulnerability
bug_reportVulnerability

Cisco Catalyst SD-WAN Manager actively exploited (CVE-2026-20245)

Cisco Catalyst SD-WAN Manager. Specific affected versions not disclosed. Vulnerability involves improper encoding or escaping of output (CVSS 7.8). Also affects products from Google and Arista (details not provided).

CVE-2026-2024510 Jun · 12:44 UTC
Linux kernel nf_tables use-after-free enables root escalation (CVE-2026-23111)criticalbug_reportVulnerability
bug_reportVulnerability

Linux kernel nf_tables use-after-free enables root escalation (CVE-2026-23111)

Linux kernel nf_tables subsystem. All distributions using vulnerable kernel versions prior to the February 5, 2026 patch. Affects systems where unprivileged users have local access or container environments.

CVE-2026-231118 Jun · 18:17 UTC
Cisco SD-WAN Manager zero-day CVE-2026-20245 exploited for root accesscriticalbug_reportVulnerability
bug_reportVulnerability

Cisco SD-WAN Manager zero-day CVE-2026-20245 exploited for root access

Cisco Catalyst SD-WAN Manager, all versions (specific affected versions not disclosed). Unpatched zero-day vulnerability enabling root privilege escalation.

CVE-2026-202455 Jun · 04:24 UTC
CIFSwitch: Linux kernel CIFS flaw enables local privilege escalationhighbug_reportVulnerability
bug_reportVulnerability

CIFSwitch: Linux kernel CIFS flaw enables local privilege escalation

Linux kernel CIFS implementation across multiple distributions. Specific affected kernel versions not yet disclosed. Requires local access to exploit.

Linux30 May · 12:16 UTC
Cisco SD-WAN Manager auth bypass exploited in wild since 2023criticalbug_reportVulnerability
bug_reportVulnerability

Cisco SD-WAN Manager auth bypass exploited in wild since 2023

Cisco Catalyst SD-WAN controllers and Cisco SD-WAN Manager. Specific affected versions not provided in advisory summary. CVE-2026-20127 allows administrative access compromise.

CVE-2026-2012726 Feb · 18:38 UTC
Fortinet FortiCloud SSO bypass exploited to extract LDAP passwordshighbug_reportVulnerability
bug_reportVulnerability

Fortinet FortiCloud SSO bypass exploited to extract LDAP passwords

Fortinet FortiGate appliances with FortiCloud SSO enabled. CVE-2025-59718 and CVE-2025-59719 allow authentication bypass. All FortiGate instances share a default static encryption key that enables decryption of LDAP credentials and private keys from…

CVE-2025-5971827 Jan · 15:16 UTC