Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
20 / 20 results
criticalbug_reportVulnerabilityApache Log4j2 deserialization filter bypass enables remote code execution
Apache Log4j2 logging library. Specific affected versions not disclosed in available information. Impacts Java applications using Log4j2 with deserialization features enabled.
highbug_reportVulnerabilityMicrosoft Copilot Personal flaws enable one-click data exfiltration via URL
Microsoft Copilot Personal (consumer assistant at copilot.microsoft.com). Research does not indicate Microsoft 365 Copilot is affected. Vulnerability tracked as CVE-2026-24301. Patched August 18, 2026.
criticalbug_reportVulnerabilitySAP Commerce Cloud, NetWeaver, MII: 4 critical flaws, 1 exploited
SAP Commerce Cloud, SAP NetWeaver, and SAP Manufacturing Integration and Intelligence (MII). Specific versions not disclosed in available data. At least 4 critical vulnerabilities confirmed.
criticalbug_reportVulnerabilitySAP Commerce Cloud critical flaw allows unauthenticated RCE (CVSS 10.0)
SAP Commerce Cloud (Data Hub Adapter). All unpatched versions are affected. The vulnerability impacts the default authentication client and certain functions lacking input validation.
highbug_reportVulnerabilityMicrosoft patches 398 flaws including one actively exploited zero-day
Microsoft Windows operating systems and supported software. All Windows endpoints are affected. Critical focus: CVE-2026-68820 (afd.sys driver privilege escalation, actively exploited), CVE-2026-62832 (Windows User Profile Service privilege escalatio…
criticalbug_reportVulnerabilityZoom annotation tool flaws enabled zero-click client hijacking
Zoom Workplace (all platforms) before 7.1.5 and 7.0.6; Zoom Workplace VDI Client for Windows before 7.0.11 and 6.6.16; Zoom Rooms and Zoom Meeting SDK (all platforms) before 7.1.0 and 7.1.5. Affects both screen sharers and meeting viewers.
criticalbug_reportVulnerabilityAdobe Campaign Classic critical RCE and file read flaws require patching
Adobe Campaign Classic (specific versions not disclosed in advisory). Two vulnerabilities: one critical severity enabling arbitrary code execution, one high severity allowing file system read access.
highbug_reportVulnerabilityChrome 149–151 fix 1,442 flaws as AI-driven bug discovery outpaces patching
Google Chrome versions 149, 150, and 151 (released June–July 2026). All prior Chrome versions are affected by the resolved vulnerabilities. One critical flaw (CVE-2026-3545, CVSS 9.6) is a 13-year-old sandbox escape in Navigation component, patched i…
criticalbug_reportVulnerabilityProgress Telerik UI for AJAX RCE vulnerability requires immediate patching
Progress Telerik UI for AJAX - specific affected versions not disclosed in available information. Vulnerability enables remote code execution.
highbug_reportVulnerabilityAdobe Acrobat Chrome extension flaw allows WhatsApp data theft via UXSS
Adobe Acrobat Chrome extension (ID: efaidnbmnnnibpcajpcglclefindmkaj) versions up to and including 26.5.2.2. Affects 314+ million users. Exploitation impacts any web application data accessible in victim's browser, demonstrated against WhatsApp Web.
highbug_reportVulnerabilityAdobe Acrobat Chrome extension flaw exposed WhatsApp Web chats
Adobe Acrobat extension for Chrome versions 26.5.2.1 and below. Affects approximately 329 million browser installations. Exploitation requires victim to visit attacker-controlled webpage while extension is installed and WhatsApp Web is in use.
highbug_reportVulnerabilityWindows June updates break Office launch from third-party apps
Windows systems with June 2024 updates installed. Affects third-party applications attempting to launch Microsoft Office applications or open Office documents. Specific Windows versions not yet disclosed by Microsoft.
highbug_reportVulnerabilityMalware campaign abuses Steam Workshop via Wallpaper Engine packages
Valve Steam Workshop users, specifically those using Wallpaper Engine application. All versions of Wallpaper Engine that integrate with Steam Workshop are potentially affected. Scope includes users downloading community-created wallpaper content.
highbug_reportVulnerability10-year-old phpBB auth bypass enables attacker login as any user
phpBB forum software, versions spanning approximately 10 years (specific affected versions not disclosed). All installations running unpatched versions are vulnerable.
highbug_reportVulnerabilityMicrosoft patches actively exploited XSS zero-day in Exchange Server OWA
Microsoft Exchange Server (all versions with Outlook Web Access enabled). Specific patched versions not provided. Affects organizations exposing OWA to users.
criticalbug_reportVulnerabilityMicrosoft June 2026 Patch Tuesday: ~200 patches, 36 critical, 3 with PoCs
Microsoft products across the portfolio. Approximately 200 vulnerabilities patched, including ~36 critical-severity issues. At least 3 vulnerabilities have public proof-of-concept exploit code available.
criticalbug_reportVulnerabilitySolarWinds Serv-U actively exploited for resource exhaustion attacks
SolarWinds Serv-U file transfer software, unpatched versions. Specific vulnerable version range not disclosed in summary. CVE identifier not yet assigned.
highbug_reportVulnerabilityAI finds 21 zero-days in FFmpeg; Chrome 149 patches 429 bugs
FFmpeg media library (all versions prior to upcoming patch release); Google Chrome versions prior to 149 (all platforms). FFmpeg is embedded in countless applications, browsers, media players, and server-side processing pipelines.
criticalbug_reportVulnerabilityApache ActiveMQ NMS AMQP Client deserialization flaw enables RCE
Apache ActiveMQ NMS AMQP Client - specific vulnerable versions not provided. Affects .NET/C# applications using the NMS AMQP client library for message queue operations.
highperson_alertThreat ActorNimbus Manticore deploys MiniFast and MiniJunk V2 via phishing and SEO poisoning
Nimbus Manticore (also tracked as Screening Serpens and UNC1549) is an Iranian state-sponsored threat actor attributed to Iran's intelligence apparatus.