Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
15 / 15 results
criticalbug_reportVulnerabilityWatchGuard Agent RCE flaws require immediate patching per CERT.BE
WatchGuard Agent (specific versions not disclosed in available data). Remote code execution vulnerabilities affect the agent software used for endpoint management and authentication.
highbug_reportVulnerability14,500 Dahua IP cameras compromised via brute-force and known CVEs
Dahua IP cameras globally, with concentration in Ukraine and Russia. Devices vulnerable to CVE-2021-33044 and CVE-2021-33045, those exposed on TCP port 37777, and cloud-registered cameras accessible via serial number recovery codes.
highperson_alertThreat ActorOperation CameraSwarm compromises 14,530+ Dahua IoT devices
Operation CameraSwarm is a campaign disclosed by Hunt.io that compromised over 14,530 Dahua surveillance devices between June 17 and July 22, 2026. The campaign was reconstructed from a 407 MB exposed working directory containing 2,616 files across 2…
highbug_reportVulnerabilityCisco ASA/FTD VPN flaw CVE-2026-20349 actively exploited for DoS
Cisco Secure Firewall ASA (versions 9.16, 9.18, 9.20, 9.22, 9.23, 9.24) and Threat Defense FTD (versions 7.0, 7.2, 7.4, 7.6, 7.7, 10.0) with Remote Access SSL VPN, IKEv2 Remote Access VPN with client services, or Zero Trust Network Access enabled.
highbug_reportVulnerabilityPasskey bypass attacks target Windows, Chrome, and Entra ID implementations
Microsoft Windows 10, Windows 11, Windows Server (CVE-2026-34348); Microsoft Entra ID passkey validation; Google Password Manager synced passkeys in Chrome on Windows; Windows Hello for Business.
highbug_reportVulnerabilityMalware can hijack Google Password Manager passkeys on Windows via TPM abuse
Google Password Manager synced passkeys on Chrome for Windows with TPM. All three attacks require pre-existing malware on the victim's Windows device. Services that do not properly validate user verification flags (e.g., eBay, now patched) are vulner…
highbug_reportVulnerabilityPasskey auth bypass via User Verified flag validation gap in relying parties
Relying parties (websites/services) implementing passkey authentication that fail to validate the User Verified (UV) flag in WebAuthn assertions. Affects passwordless authentication systems across multiple platforms.
criticalbug_reportVulnerabilityCheck Point SmartConsole auth bypass exploited; PoC public
Check Point Security Management Server and Multi-Domain Security Management Server (MDS) SmartConsole. All versions prior to Jumbo Hotfixes released July 22, 2026.
criticalbug_reportVulnerabilityUbiquiti patches critical flaws in UniFi products, CVE-2026-50746 CVSS 10.0
Ubiquiti UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS. Specific vulnerable versions not provided in available data. CVE-2026-50746 rated CVSS 10.0 (critical).
highbug_reportVulnerabilityUnit 42 issues guidance on large-scale credential attack campaigns
Organizations using security vendor devices targeted in recent credential-based attack campaigns. No specific CVE; threat involves coordinated credential compromise attempts across multiple vendors' products.
criticalbug_reportVulnerabilityFortinet FortiSandbox under active exploit for 3 CVEs including critical 9.1
Fortinet FortiSandbox - specific affected versions not disclosed. Three CVEs: CVE-2026-39813 (CVSS 9.1 critical), CVE-2026-39808, CVE-2026-25089. At least one vulnerability recently patched; patch status of others unclear.
criticalbug_reportVulnerabilitySplunk Enterprise RCE flaw allows unauthenticated remote code execution
Splunk Enterprise versions below 10.2.4 and 10.0.7. The vulnerability enables unauthenticated attackers to perform arbitrary file operations and achieve remote code execution. CVSS score 9.8 (Critical).
criticalbug_reportVulnerabilityIvanti Sentry RCE flaw under active exploitation, root access possible
Ivanti Sentry (formerly MobileIron Sentry) - Internet-exposed secure mobile gateways. Specific vulnerable versions not provided in summary, but patch recently released.
criticalbug_reportVulnerabilityTrend Micro Apex One & Vision One SEP flaws under active exploit
Trend Micro Apex One and Trend Micro Vision One Endpoint Security (SEP). Specific vulnerable versions not disclosed in summary; multiple vulnerabilities confirmed under active exploitation.
criticalbug_reportVulnerabilityFortinet FortiCloud SSO auth bypass under active exploitation
Fortinet FortiCloud SSO SAML authentication processing (CVE-2025-59718, CVE-2025-59719). Affects management interfaces of FortiGate and potentially other Fortinet products using FortiCloud SSO.