Curated Cyber Threat Intelligence
Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
scheduleUpdated 2026-07-21 · 02:09 UTC
articleTotal: 606 reports
Filtered Reports
3 / 3 results
highbug_reportVulnerabilitybug_reportVulnerability
PyPI supply-chain attack: 19 science packages compromised with malware
19 science-focused Python packages on PyPI, collectively downloaded hundreds of thousands of times. Specific package names and versions not disclosed in summary. Affects Python developers using PyPI packages in scientific/research workflows.
BleepingComputer18:41 UTC
highbug_reportVulnerabilitybug_reportVulnerability
Red Hat npm packages compromised with Miasma credential stealer
Over 30 npm packages in the '@redhat-cloud-services' namespace on npm registry. Affects developers and CI/CD pipelines consuming these packages. Specific package names and versions not yet disclosed.
Red Hat19:38 UTC
highbug_reportVulnerabilitybug_reportVulnerability
Over 600 malicious npm packages published in Shai-Hulud campaign
npm ecosystem: 600+ malicious packages published by threat actors. Affects organizations using npm for JavaScript/Node.js dependency management. Specific package names not provided in summary.
npm12:30 UTC