Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 139 results
highbug_reportVulnerabilityCoordinated attacks target AI infrastructure for credential theft and cryptomining
AI infrastructure platforms: LiteLLM gateways (CVE-2026-42271, CVE-2026-48710), RAGFlow deployments, and Kestra workflow environments. All exposed instances with administrative surfaces reachable from the internet are at risk.
highbug_reportVulnerabilityMicrosoft SharePoint RCE chain (CVE-2026-55040 + CVE-2026-63520) exploited
Microsoft SharePoint Server (on-premises). CVE-2026-55040: JWT authentication bypass. CVE-2026-63520: Business Connectivity Services RCE. Over 8,700 SharePoint servers exposed online. Specific vulnerable versions not disclosed in article.
highperson_alertThreat ActorNovaCookies PhaaS Toolkit Hijacks Microsoft 365 Sessions via DocuSign
NovaCookies is a subscription-based adversary-in-the-middle (AitM) phishing-as-a-service (PhaaS) platform priced at $320/month, advertised via Telegram.
highperson_alertThreat ActorMirage2FA Campaign Hits 4,500 Orgs via Microsoft 365 AiTM Phishing
Mirage2FA is a commercial phishing-as-a-service (PhaaS) campaign active from 2024 to 2026, targeting Microsoft 365 accounts through adversary-in-the-middle (AiTM) techniques.
highbug_reportVulnerability.NET Framework August 2026 updates break WPF printing and PDF export
.NET Framework cumulative updates released August 2026 Patch Tuesday. Affects Windows Presentation Foundation (WPF) applications on Windows 10, Windows 11, Windows Server 2012 through Windows Server 2025.
highbug_reportVulnerabilityWordlistLoader and SynkLoader malware target Windows via ClickFix and Teams
Windows endpoints exposed to ClearFake/ClickFix campaigns (WordlistLoader delivering Amatera Stealer) and Microsoft Teams phishing (SynkLoader credential theft).
highbug_reportVulnerabilitySynkLoader malware spreads via Microsoft Teams phishing campaigns
Microsoft Teams users across all organizations. SynkLoader is a new credential-stealing malware family delivered through phishing messages on the Teams platform. No specific product versions or CVEs identified.
highbug_reportVulnerabilityMicrosoft Defender BTR.sys driver weaponized for kernel-level sabotage
Microsoft Defender BTR.sys driver on all Windows versions from Windows 7 through Windows 11 25H2. The driver is a required component shipped with every Windows installation and cannot be blocked without breaking Defender functionality.
criticalbug_reportVulnerabilityMicrosoft Entra ID deserialization flaw exploited; already patched
Microsoft Entra ID (formerly Azure Active Directory) cloud-based identity and access management platform. All versions prior to Microsoft's server-side patch.
criticalbug_reportVulnerabilityMicrosoft patches critical Entra ID RCE flaw (CVE-2026-69836, CVSS 10.0)
Microsoft Entra ID (formerly Azure Active Directory), all versions. Cloud-based identity and access management service. Microsoft has already deployed server-side mitigations; no customer action required.
criticalbug_reportVulnerabilityMicrosoft April 2026 Patch Tuesday: 163 vulnerabilities, 8 critical
Microsoft products and services across the ecosystem. 163 total vulnerabilities patched, including 8 critical severity issues. Specific affected products, CVE identifiers, and version details not provided in source material.
criticalbug_reportVulnerabilityCISA flags 4 critical flaws in macOS, SharePoint, vCenter, IKE under attack
Apple macOS (CVE-2026-65400, Screen Sharing authentication bypass), Microsoft SharePoint (CVE-2026-55040, weak authentication), Broadcom VMware vCenter (CVE-2026-59310, path traversal RCE), Microsoft IKE Service Extensions (CVE-2026-33824, double fre…
criticalbug_reportVulnerabilityWindows IKE Extension RCE (CVE-2026-33824) actively exploited
All supported Windows 10, Windows 11, and Windows Server versions. The vulnerability affects the Windows Internet Key Exchange (IKE) Service Extensions (MS-IKEE) component accessible via UDP ports 500 and 4500.
highbug_reportVulnerabilityMacSync Stealer campaign uses 30+ rotating domains to target macOS users
macOS systems, all versions. Primary targets: users with AWS credentials, SSH keys, Kubernetes configs, browser credentials, and Keychain data. Organizations with macOS endpoints in development, DevOps, and cloud administration roles face elevated ri…
highbug_reportVulnerabilityMicrosoft Copilot Personal flaws enable one-click data exfiltration via URL
Microsoft Copilot Personal (consumer assistant at copilot.microsoft.com). Research does not indicate Microsoft 365 Copilot is affected. Vulnerability tracked as CVE-2026-24301. Patched August 18, 2026.
highbug_reportVulnerabilityMacSync Stealer targets macOS via ClickFix, rotates 30+ domains
macOS devices. No specific version restrictions identified. Targets Keychain, browser data, credentials, SSH keys, and sensitive user files. Delivered via ClickFix social engineering (malicious Terminal commands).
highperson_alertThreat ActorTWINLOOT Implant Abuses Microsoft 365 Services for C2 and Lateral Movement
No specific threat actor has been attributed to TWINLOOT operations. The malware was discovered by Ontinue's Cyber Defense Center during investigation of an ongoing campaign in July 2026.
highperson_alertThreat ActorCVE-2025-60710: Windows Task Host Flaw Exploited by Ransomware Gangs
No specific threat actor or ransomware gang has been publicly attributed to the exploitation of CVE-2025-60710. CISA confirmed that multiple ransomware operators are actively exploiting this vulnerability in the wild as of August 2026.
highbug_reportVulnerabilityMicrosoft Defender ShieldBreak zero-day grants SYSTEM privileges on Windows
Microsoft Defender on Windows 10, Windows 11 (including 25H2 and Canary), and Windows Server 2025. All fully patched systems with Defender enabled are vulnerable.
highbug_reportVulnerabilityMicrosoft patches LegacyHive Windows zero-day granting admin privileges
Windows User Profile Service in Windows 10 version 2004 and later, Windows Server 2022 and later. Tracked as CVE-2026-62832. All Windows systems running affected versions are vulnerable.
criticalbug_reportVulnerabilitySharePoint CVE-2026-55040 exploited in wild after PoC release
Microsoft SharePoint servers not patched with July 2026 Patch Tuesday updates. All unpatched SharePoint instances are vulnerable to authentication bypass allowing unauthenticated remote attackers to impersonate any site user or administrator.
criticalperson_alertThreat ActorLazarus Exploits Windows Zero-Day in Operation Dream Job Campaign
Lazarus Group is a North Korean state-sponsored advanced persistent threat (APT) actor attributed to Pyongyang-backed cyber operations. The group conducts cyber espionage and financially motivated campaigns targeting organizations worldwide.
highbug_reportVulnerabilityPlug and Pwn attacks exploit Windows Plug and Play for SYSTEM access
All Windows systems (including fully patched Windows 11) that support Plug and Play device installation. Specific vulnerable vendor packages include Sierra Wireless and Sony FeliCa software.
criticalperson_alertThreat ActorLazarus Exploits Windows Zero-Day in Operation Dream Job Campaign
Lazarus is a North Korean state-sponsored advanced persistent threat (APT) group linked to the Reconnaissance General Bureau. The group is financially and strategically motivated, conducting espionage operations targeting defense and critical infrast…
criticalbug_reportVulnerabilityMicrosoft SharePoint JWT auth bypass exploited in wild after PoC release
Microsoft SharePoint Enterprise Server 2016 and SharePoint Server 2019. CVE-2026-55040 is a critical authentication bypass in JWT token validation allowing unauthenticated attackers to impersonate SharePoint users or administrators.
criticalbug_reportVulnerabilityMicrosoft August 2026 Patch Tuesday: 398 vulnerabilities, 42 critical
Microsoft products and services across the ecosystem. Specific affected products, versions, and CVE identifiers not disclosed in available information. 398 total vulnerabilities addressed, including 42 rated critical severity.
highbug_reportVulnerabilityShieldBreak zero-day bypasses Microsoft Defender patch, grants SYSTEM access
Microsoft Defender for Windows on Windows 11 25H2, Windows Server 2025, and Windows 10 (all editions). The vulnerability bypasses the patch for CVE-2026-50656 (RoguePlanet) in the Microsoft Malware Protection Engine (mpengine.dll).
highbug_reportVulnerabilityMicrosoft patches 398 flaws including one actively exploited zero-day
Microsoft Windows operating systems and supported software. All Windows endpoints are affected. Critical focus: CVE-2026-68820 (afd.sys driver privilege escalation, actively exploited), CVE-2026-62832 (Windows User Profile Service privilege escalatio…
criticalbug_reportVulnerabilityWindows kernel driver zero-day CVE-2026-68820 exploited by Lazarus APT
Windows kernel driver afd.sys (Ancillary Function Driver for WinSock) across all supported Windows versions. CVE-2026-68820 is a use-after-free vulnerability enabling local privilege escalation to SYSTEM level. CVSS 7.0.
criticalbug_reportVulnerabilityMicrosoft patches 400 flaws including 3 zero-days, one exploited by Lazarus
All supported Windows versions (Windows 10, Windows 11). Three zero-day vulnerabilities: CVE-2026-68820 (Windows AFD.sys driver, actively exploited by Lazarus APT), CVE-2026-62832 (Windows User Profile Service, publicly disclosed as "LegacyHive"), an…