Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

7 / 7 results
Active filter:tag: #it-services✕ clear
Veeam ONE authentication bypass requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Veeam ONE authentication bypass requires immediate patching

Veeam ONE backup management platform - specific affected versions not disclosed in available information. Authentication mechanism vulnerable to bypass allowing unauthorized access.

Veeam27 Aug · 12:51 UTC
Sandworm deploys trojanized WireGuard VPN via fake IT job offershighperson_alertThreat Actor
person_alertThreat Actor

Sandworm deploys trojanized WireGuard VPN via fake IT job offers

Sandworm (also tracked as APT44, UAC-0145 sub-cluster) is a Russian-linked advanced persistent threat group notorious for targeting critical infrastructure and government entities, particularly in Ukraine and other countries.

BleepingComputer11 Aug · 19:07 UTC
N-able N-central exploited; attackers persist via Cloudflare tunnelscriticalbug_reportVulnerability
bug_reportVulnerability

N-able N-central exploited; attackers persist via Cloudflare tunnels

N-able N-central RMM product, all versions prior to 2026.3.1.7. CVE-2026-18577 (CVSS 8.2) is an incomplete fix for CVE-2026-18556 (CVSS 8.2), both enabling authentication bypass and account takeover. On-premise deployments are affected.

N-able8 Aug · 04:57 UTC
N-able N-central auth bypass exploited; incomplete patch requires upgradecriticalbug_reportVulnerability
bug_reportVulnerability

N-able N-central auth bypass exploited; incomplete patch requires upgrade

N-able N-central builds prior to 2026.3.1.7. All versions before the August 2 emergency hotfix are vulnerable. Affects MSPs and IT teams using N-central for remote monitoring and management of customer endpoints.

CVE-2026-185773 Aug · 04:41 UTC
BeyondTrust Remote Support/PRA critical auth bypass (CVE-2026-40138)criticalbug_reportVulnerability
bug_reportVulnerability

BeyondTrust Remote Support/PRA critical auth bypass (CVE-2026-40138)

BeyondTrust Remote Support and Privileged Remote Access (PRA) products. Specific affected versions not provided in available data. CVE-2026-40138 is a pre-authentication vulnerability with CVSS 9.2.

CVE-2026-401387 Jul · 03:16 UTC
Iran-linked MOIS group deploys Cavern C2 framework against Israelhighperson_alertThreat Actor
person_alertThreat Actor

Iran-linked MOIS group deploys Cavern C2 framework against Israel

An Iranian threat actor affiliated with Iran's Ministry of Intelligence and Security (MOIS), tracked by Check Point Research. The group operates in support of Iranian state intelligence objectives, focusing on espionage operations against adversary n…

The Hacker News6 Jul · 16:34 UTC
SimpleHelp OIDC flaw allows unauthenticated account creationhighbug_reportVulnerability
bug_reportVulnerability

SimpleHelp OIDC flaw allows unauthenticated account creation

SimpleHelp remote management software servers with OpenID Connect (OIDC) authentication enabled. Specific affected versions not disclosed. All SimpleHelp deployments using OIDC for technician authentication are potentially vulnerable.

SimpleHelp15 Jun · 18:06 UTC