Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
9 / 9 results
highbug_reportVulnerabilityWindows June updates break Office launch from third-party apps
Windows systems with June 2024 updates installed. Affects third-party applications attempting to launch Microsoft Office applications or open Office documents. Specific Windows versions not yet disclosed by Microsoft.
highbug_reportVulnerabilityMalware campaign abuses Steam Workshop via Wallpaper Engine packages
Valve Steam Workshop users, specifically those using Wallpaper Engine application. All versions of Wallpaper Engine that integrate with Steam Workshop are potentially affected. Scope includes users downloading community-created wallpaper content.
highbug_reportVulnerability10-year-old phpBB auth bypass enables attacker login as any user
phpBB forum software, versions spanning approximately 10 years (specific affected versions not disclosed). All installations running unpatched versions are vulnerable.
highbug_reportVulnerabilityMicrosoft patches actively exploited XSS zero-day in Exchange Server OWA
Microsoft Exchange Server (all versions with Outlook Web Access enabled). Specific patched versions not provided. Affects organizations exposing OWA to users.
criticalbug_reportVulnerabilityMicrosoft June 2026 Patch Tuesday: ~200 patches, 36 critical, 3 with PoCs
Microsoft products across the portfolio. Approximately 200 vulnerabilities patched, including ~36 critical-severity issues. At least 3 vulnerabilities have public proof-of-concept exploit code available.
criticalbug_reportVulnerabilitySolarWinds Serv-U actively exploited for resource exhaustion attacks
SolarWinds Serv-U file transfer software, unpatched versions. Specific vulnerable version range not disclosed in summary. CVE identifier not yet assigned.
highbug_reportVulnerabilityAI finds 21 zero-days in FFmpeg; Chrome 149 patches 429 bugs
FFmpeg media library (all versions prior to upcoming patch release); Google Chrome versions prior to 149 (all platforms). FFmpeg is embedded in countless applications, browsers, media players, and server-side processing pipelines.
criticalbug_reportVulnerabilityApache ActiveMQ NMS AMQP Client deserialization flaw enables RCE
Apache ActiveMQ NMS AMQP Client - specific vulnerable versions not provided. Affects .NET/C# applications using the NMS AMQP client library for message queue operations.
highperson_alertThreat ActorNimbus Manticore deploys MiniFast and MiniJunk V2 via phishing and SEO poisoning
Nimbus Manticore (also tracked as Screening Serpens and UNC1549) is an Iranian state-sponsored threat actor attributed to Iran's intelligence apparatus.