Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

15 / 15 results
Active filter:tag: #security✕ clear
WatchGuard Agent RCE flaws require immediate patching per CERT.BEcriticalbug_reportVulnerability
bug_reportVulnerability

WatchGuard Agent RCE flaws require immediate patching per CERT.BE

WatchGuard Agent (specific versions not disclosed in available data). Remote code execution vulnerabilities affect the agent software used for endpoint management and authentication.

WatchGuard27 Aug · 04:36 UTC
14,500 Dahua IP cameras compromised via brute-force and known CVEshighbug_reportVulnerability
bug_reportVulnerability

14,500 Dahua IP cameras compromised via brute-force and known CVEs

Dahua IP cameras globally, with concentration in Ukraine and Russia. Devices vulnerable to CVE-2021-33044 and CVE-2021-33045, those exposed on TCP port 37777, and cloud-registered cameras accessible via serial number recovery codes.

Dahua19 Aug · 16:09 UTC
Operation CameraSwarm compromises 14,530+ Dahua IoT deviceshighperson_alertThreat Actor
person_alertThreat Actor

Operation CameraSwarm compromises 14,530+ Dahua IoT devices

Operation CameraSwarm is a campaign disclosed by Hunt.io that compromised over 14,530 Dahua surveillance devices between June 17 and July 22, 2026. The campaign was reconstructed from a 407 MB exposed working directory containing 2,616 files across 2…

Dahua19 Aug · 09:34 UTC
Cisco ASA/FTD VPN flaw CVE-2026-20349 actively exploited for DoShighbug_reportVulnerability
bug_reportVulnerability

Cisco ASA/FTD VPN flaw CVE-2026-20349 actively exploited for DoS

Cisco Secure Firewall ASA (versions 9.16, 9.18, 9.20, 9.22, 9.23, 9.24) and Threat Defense FTD (versions 7.0, 7.2, 7.4, 7.6, 7.7, 10.0) with Remote Access SSL VPN, IKEv2 Remote Access VPN with client services, or Zero Trust Network Access enabled.

Cisco11 Aug · 17:45 UTC
Passkey bypass attacks target Windows, Chrome, and Entra ID implementationshighbug_reportVulnerability
bug_reportVulnerability

Passkey bypass attacks target Windows, Chrome, and Entra ID implementations

Microsoft Windows 10, Windows 11, Windows Server (CVE-2026-34348); Microsoft Entra ID passkey validation; Google Password Manager synced passkeys in Chrome on Windows; Windows Hello for Business.

Microsoft10 Aug · 10:25 UTC
Malware can hijack Google Password Manager passkeys on Windows via TPM abusehighbug_reportVulnerability
bug_reportVulnerability

Malware can hijack Google Password Manager passkeys on Windows via TPM abuse

Google Password Manager synced passkeys on Chrome for Windows with TPM. All three attacks require pre-existing malware on the victim's Windows device. Services that do not properly validate user verification flags (e.g., eBay, now patched) are vulner…

Google3 Aug · 21:58 UTC
Passkey auth bypass via User Verified flag validation gap in relying partieshighbug_reportVulnerability
bug_reportVulnerability

Passkey auth bypass via User Verified flag validation gap in relying parties

Relying parties (websites/services) implementing passkey authentication that fail to validate the User Verified (UV) flag in WebAuthn assertions. Affects passwordless authentication systems across multiple platforms.

Palo Alto Networks3 Aug · 08:00 UTC
Check Point SmartConsole auth bypass exploited; PoC publiccriticalbug_reportVulnerability
bug_reportVulnerability

Check Point SmartConsole auth bypass exploited; PoC public

Check Point Security Management Server and Multi-Domain Security Management Server (MDS) SmartConsole. All versions prior to Jumbo Hotfixes released July 22, 2026.

CVE-2026-1623229 Jul · 06:58 UTC
Ubiquiti patches critical flaws in UniFi products, CVE-2026-50746 CVSS 10.0criticalbug_reportVulnerability
bug_reportVulnerability

Ubiquiti patches critical flaws in UniFi products, CVE-2026-50746 CVSS 10.0

Ubiquiti UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS. Specific vulnerable versions not provided in available data. CVE-2026-50746 rated CVSS 10.0 (critical).

CVE-2026-507468 Jul · 12:38 UTC
Unit 42 issues guidance on large-scale credential attack campaignshighbug_reportVulnerability
bug_reportVulnerability

Unit 42 issues guidance on large-scale credential attack campaigns

Organizations using security vendor devices targeted in recent credential-based attack campaigns. No specific CVE; threat involves coordinated credential compromise attempts across multiple vendors' products.

Unit 42 (Palo Alto)20 Jun · 00:05 UTC
Fortinet FortiSandbox under active exploit for 3 CVEs including critical 9.1criticalbug_reportVulnerability
bug_reportVulnerability

Fortinet FortiSandbox under active exploit for 3 CVEs including critical 9.1

Fortinet FortiSandbox - specific affected versions not disclosed. Three CVEs: CVE-2026-39813 (CVSS 9.1 critical), CVE-2026-39808, CVE-2026-25089. At least one vulnerability recently patched; patch status of others unclear.

CVE-2026-2508916 Jun · 08:30 UTC
Splunk Enterprise RCE flaw allows unauthenticated remote code executioncriticalbug_reportVulnerability
bug_reportVulnerability

Splunk Enterprise RCE flaw allows unauthenticated remote code execution

Splunk Enterprise versions below 10.2.4 and 10.0.7. The vulnerability enables unauthenticated attackers to perform arbitrary file operations and achieve remote code execution. CVSS score 9.8 (Critical).

CVE-2026-2025313 Jun · 11:23 UTC
Ivanti Sentry RCE flaw under active exploitation, root access possiblecriticalbug_reportVulnerability
bug_reportVulnerability

Ivanti Sentry RCE flaw under active exploitation, root access possible

Ivanti Sentry (formerly MobileIron Sentry) - Internet-exposed secure mobile gateways. Specific vulnerable versions not provided in summary, but patch recently released.

Ivanti11 Jun · 04:20 UTC
Trend Micro Apex One & Vision One SEP flaws under active exploitcriticalbug_reportVulnerability
bug_reportVulnerability

Trend Micro Apex One & Vision One SEP flaws under active exploit

Trend Micro Apex One and Trend Micro Vision One Endpoint Security (SEP). Specific vulnerable versions not disclosed in summary; multiple vulnerabilities confirmed under active exploitation.

Trend Micro26 May · 08:17 UTC
Fortinet FortiCloud SSO auth bypass under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Fortinet FortiCloud SSO auth bypass under active exploitation

Fortinet FortiCloud SSO SAML authentication processing (CVE-2025-59718, CVE-2025-59719). Affects management interfaces of FortiGate and potentially other Fortinet products using FortiCloud SSO.

CVE-2025-5971822 Jan · 14:41 UTC