Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-06 · 02:16 UTC
articleTotal: 1194 reports

Filtered Reports

5 / 5 results
Active filter:tag: #red-hat✕ clear
Critical Keycloak flaw allows unauthenticated account takeover via password resetcriticalbug_reportVulnerability
bug_reportVulnerability

Critical Keycloak flaw allows unauthenticated account takeover via password reset

Keycloak identity and access management server: upstream versions prior to 26.7.2; Red Hat build of Keycloak (RHBK) 26.4 prior to 26.4.15 and 26.6 prior to 26.6.6. All realms with "Forgot password" feature enabled are vulnerable.

CVE-2026-1896324 Aug · 09:56 UTC
Red Hat Keycloak password-reset flaw enables account takeovercriticalbug_reportVulnerability
bug_reportVulnerability

Red Hat Keycloak password-reset flaw enables account takeover

Red Hat build of Keycloak, specific versions not disclosed in source. Vulnerability exists in the password-reset flow mechanism.

Red Hat20 Aug · 12:36 UTC
RefluXFS kernel flaw grants local root on default RHEL, Fedora, Amazon Linuxcriticalbug_reportVulnerability
bug_reportVulnerability

RefluXFS kernel flaw grants local root on default RHEL, Fedora, Amazon Linux

Linux kernel 4.11+ (2017–July 2026) on systems with XFS filesystems created with reflink=1. Default installations of RHEL/CentOS Stream/Oracle/Rocky/AlmaLinux/CloudLinux 8/9/10, Fedora Server 31+, Amazon Linux 2023, and Amazon Linux 2 (Dec 2022+) are…

CVE-2026-6460023 Jul · 06:04 UTC
Red Hat npm packages compromised with Miasma credential stealerhighbug_reportVulnerability
bug_reportVulnerability

Red Hat npm packages compromised with Miasma credential stealer

Over 30 npm packages in the '@redhat-cloud-services' namespace on npm registry. Affects developers and CI/CD pipelines consuming these packages. Specific package names and versions not yet disclosed.

Red Hat1 Jun · 19:38 UTC
Miasma supply chain attack compromises Red Hat npm packagescriticalbug_reportVulnerability
bug_reportVulnerability

Miasma supply chain attack compromises Red Hat npm packages

Red Hat Cloud Services npm packages (@redhat-cloud-services scope). Affects developers and CI/CD pipelines using these packages. Scope includes any environment where compromised packages were installed.

Red Hat1 Jun · 15:40 UTC