Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 154 results
Active filter:tag: #software-development✕ clear
Coder registry compromised via Cloudflare to deliver malicious Terraform moduleshighbug_reportVulnerability
bug_reportVulnerability

Coder registry compromised via Cloudflare to deliver malicious Terraform modules

Coder registry infrastructure (registry.coder.com) accessed via compromised Cloudflare configuration. Users who downloaded Terraform modules between 07:35 and 21:45 UTC on August 31, 2026 potentially affected.

Coder3 Sep · 18:04 UTC
Shai-Hulud infostealer now targets 469 credential locations in dev toolshighbug_reportVulnerability
bug_reportVulnerability

Shai-Hulud infostealer now targets 469 credential locations in dev tools

Developer workstations, CI/CD pipelines, cloud configurations, AI tool configs, package registries (npm, GitHub, Docker), and any environment storing long-lived credentials or tokens.

The Hacker News3 Sep · 08:36 UTC
JFrog Artifactory auth bypass exploited to forge admin tokenscriticalbug_reportVulnerability
bug_reportVulnerability

JFrog Artifactory auth bypass exploited to forge admin tokens

JFrog Artifactory self-managed instances in default configuration. Patched in versions 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, and 7.161.20 (released August 28, 2026). JFrog Cloud environments already protected.

CVE-2026-823292 Sep · 13:47 UTC
AI coding agents execute malicious Git config commands outside sandboxhighbug_reportVulnerability
bug_reportVulnerability

AI coding agents execute malicious Git config commands outside sandbox

Seven command-line AI coding agents: goose (fixed in 1.44.0), Codex CLI/Desktop (fixed in 0.131.0 / 26.519.x), Claude Code (partially fixed in 2.1.196, second path unpatched in 2.1.252+), Hermes Agent 0.18.2–0.21.0 (unpatched), Qwen Code 0.19.6–0.22.…

Anthropic2 Sep · 12:06 UTC
JFrog Artifactory auth bypass CVE-2026-82329 under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

JFrog Artifactory auth bypass CVE-2026-82329 under active exploitation

JFrog Artifactory versions 7.161.0-7.161.19, 7.146.0-7.146.36, 7.133.0-7.133.28, 7.125.0-7.125.19, 7.117.0-7.117.27, and 7.111.4-7.111.21. Affects default configurations of self-managed instances. JFrog Access component specifically vulnerable.

CVE-2026-823291 Sep · 15:53 UTC
13 malicious Packagist packages target iOS devices to steal crypto walletshighbug_reportVulnerability
bug_reportVulnerability

13 malicious Packagist packages target iOS devices to steal crypto wallets

Packagist/Composer ecosystem: 13 malicious theme packages across 5 vendor namespaces (vsmov, vsphim, haiau009, chilltvcms, ophimcms). Targets Vietnamese streaming sites using OphimCMS/KKPhim.

Packagist1 Sep · 12:07 UTC
Langflow and Ruby on Rails flaws actively exploited for RCE and C2criticalbug_reportVulnerability
bug_reportVulnerability

Langflow and Ruby on Rails flaws actively exploited for RCE and C2

Langflow (CVE-2026-0768, CVSS 9.8): arbitrary Python code execution as root via improper input validation. Ruby on Rails (CVE-2026-66066 aka KindaRails2Shell, CVSS 9.5): unauthenticated arbitrary file read, secret leakage, and RCE in applications usi…

CVE-2026-07681 Sep · 05:22 UTC
PaperCut NG/MF flaws chained for unauthenticated RCE, active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

PaperCut NG/MF flaws chained for unauthenticated RCE, active exploitation

PaperCut NG and PaperCut MF (all unpatched versions). CVE-2026-81578 (CVSS 8.8, improper access control) and CVE-2026-82078 (CVSS 9.4, unsafe dynamic class loading) are chained to bypass authentication and execute arbitrary Java code.

PaperCut28 Aug · 15:12 UTC
Next.js critical RCE flaws in AVIF processing and Windows path traversalcriticalbug_reportVulnerability
bug_reportVulnerability

Next.js critical RCE flaws in AVIF processing and Windows path traversal

Next.js versions 13.4–15.5.23 and 16.0–16.3.2. CVE-2026-75604 (Windows path traversal, CVSS 9.0) affects Windows-hosted servers using Pages Router or App Router without Cache Components.

CVE-2026-7560427 Aug · 13:13 UTC
Amazon Kiro IDE prompt injection enables data exfiltration via Powershighbug_reportVulnerability
bug_reportVulnerability

Amazon Kiro IDE prompt injection enables data exfiltration via Powers

Amazon Kiro IDE version 0.7.45 on Windows. Vulnerability fixed in version 0.8.140. Latest version is 1.0.337. Affects both trusted and untrusted workspaces when malicious workspace files are opened.

Amazon27 Aug · 11:39 UTC
TeamPCP supply chain attack compromised Trivy, KICS, LiteLLM; 1000+ orgs hitcriticalbug_reportVulnerability
bug_reportVulnerability

TeamPCP supply chain attack compromised Trivy, KICS, LiteLLM; 1000+ orgs hit

Open-source tools: Trivy scanner, Checkmarx KICS, LiteLLM AI gateway. Attack spanned GitHub Actions, Docker Hub, npm, PyPI, OpenVSX ecosystems. Over 1,000 organizations potentially compromised, 500,000+ credentials stolen, 300GB+ data exfiltrated.

Trivy27 Aug · 09:56 UTC
Australian police arrest two TeamPCP members behind supply chain attackshighbug_reportVulnerability
bug_reportVulnerability

Australian police arrest two TeamPCP members behind supply chain attacks

Global software supply chain: hundreds of open-source packages on GitHub, NPM, and other repositories compromised since late 2023. Victims include 2,500+ organizations using LiteLLM AI gateway, 3,800+ GitHub repositories, and developers across major…

Krebs on Security27 Aug · 09:04 UTC
Attackers abuse npm mirrors as free hosting for Cloudflare phishing pageshighbug_reportVulnerability
bug_reportVulnerability

Attackers abuse npm mirrors as free hosting for Cloudflare phishing pages

npm registry and public mirrors (UNPKG, npmmirror). Organizations using these mirrors to serve package content. At least 24 malicious packages identified hosting fake Cloudflare CAPTCHA pages.

npm25 Aug · 19:39 UTC
NVIDIA NemoClaw DNS rebinding flaw enables AI model poisoning via browserhighbug_reportVulnerability
bug_reportVulnerability

NVIDIA NemoClaw DNS rebinding flaw enables AI model poisoning via browser

NVIDIA NemoClaw versions prior to v0.0.35 on macOS and Linux. Windows and WSL installations remain vulnerable as of v0.0.34, which added a warning but no technical fix.

NVIDIA25 Aug · 12:07 UTC
24 npm packages abuse unpkg mirrors as phishing infrastructurehighbug_reportVulnerability
bug_reportVulnerability

24 npm packages abuse unpkg mirrors as phishing infrastructure

24 malicious npm packages (e.g., bgzxcuite2, prezdentkxheiw, egair0810) hosted on npm registry and mirrored on unpkg.com and similar CDN services. Affects users who click links to these mirrored HTML pages, not developers installing packages directly…

npm25 Aug · 09:52 UTC
Xecurify miniOrange SAML plugin flaws exploited for WordPress admin accesshighbug_reportVulnerability
bug_reportVulnerability

Xecurify miniOrange SAML plugin flaws exploited for WordPress admin access

Xecurify miniOrange SAML 2.0 Single Sign On WordPress plugin, Standard edition versions prior to 17.0.6. CVE-2026-61979 (CVSS 8.1) fixed in 17.0.5; CVE-2026-15981 (CVSS 9.8) fixed in 17.0.6.

CVE-2026-6197925 Aug · 06:34 UTC
.NET Framework August 2026 updates break WPF printing and PDF exporthighbug_reportVulnerability
bug_reportVulnerability

.NET Framework August 2026 updates break WPF printing and PDF export

.NET Framework cumulative updates released August 2026 Patch Tuesday. Affects Windows Presentation Foundation (WPF) applications on Windows 10, Windows 11, Windows Server 2012 through Windows Server 2025.

Microsoft24 Aug · 10:40 UTC
Critical Keycloak flaw allows unauthenticated account takeover via password resetcriticalbug_reportVulnerability
bug_reportVulnerability

Critical Keycloak flaw allows unauthenticated account takeover via password reset

Keycloak identity and access management server: upstream versions prior to 26.7.2; Red Hat build of Keycloak (RHBK) 26.4 prior to 26.4.15 and 26.6 prior to 26.6.6. All realms with "Forgot password" feature enabled are vulnerable.

CVE-2026-1896324 Aug · 09:56 UTC
Attackers shift focus to CI/CD pipelines and developer tools in SDLChighbug_reportVulnerability
bug_reportVulnerability

Attackers shift focus to CI/CD pipelines and developer tools in SDLC

All organizations using modern software development practices with CI/CD pipelines, open-source dependencies, and developer tools. Specific recent attacks include ChainDrop npm worm (400+ packages including keyv and cacheable-request), XZ Utils (CVE-…

Unit 42 (Palo Alto)21 Aug · 21:00 UTC
14 trojanized npm packages deliver AI-powered RedC2 4.0 Linux backdoorhighbug_reportVulnerability
bug_reportVulnerability

14 trojanized npm packages deliver AI-powered RedC2 4.0 Linux backdoor

14 npm packages (streak-metrics-math, kit-map-vim, streak-map-cache, streak-map-kit, map-streak-kit, streak-cache-map, streak-calc-metrics, streak-calc-math, streak-math-abz, streak-metricsaz, streak-math-metrics, streak-metricazbd, streak-metricsazb…

npm21 Aug · 16:53 UTC
Rust crates compromised via account takeover; build-time malware deployedcriticalbug_reportVulnerability
bug_reportVulnerability

Rust crates compromised via account takeover; build-time malware deployed

Three Rust crates (arrayref 0.3.10, internment 0.8.7, append-only-vec 0.1.9) with 245 million combined downloads. Malicious versions were live for 86-107 minutes on August 20, 2026.

Rust Project20 Aug · 18:22 UTC
Red Hat Keycloak password-reset flaw enables account takeovercriticalbug_reportVulnerability
bug_reportVulnerability

Red Hat Keycloak password-reset flaw enables account takeover

Red Hat build of Keycloak, specific versions not disclosed in source. Vulnerability exists in the password-reset flow mechanism.

Red Hat20 Aug · 12:36 UTC
Critical sandbox escape in isolated-vm ≤7.0.0 enables RCE on hostcriticalbug_reportVulnerability
bug_reportVulnerability

Critical sandbox escape in isolated-vm ≤7.0.0 enables RCE on host

isolated-vm library versions ≤7.0.0. Patched in versions 6.2.0 and 7.0.1. Affects Node.js environments using isolated-vm for sandboxing untrusted JavaScript. Package has ~1 million weekly npm downloads.

isolated-vm20 Aug · 11:48 UTC
GitLab CE/EE critical code injection flaw with public PoC exploitcriticalbug_reportVulnerability
bug_reportVulnerability

GitLab CE/EE critical code injection flaw with public PoC exploit

GitLab Community Edition (CE) and Enterprise Edition (EE). Specific affected versions not provided in source material. CVE identifier not yet assigned or disclosed.

GitLab18 Aug · 13:12 UTC
StubMaker Campaign Deploys 16 Typosquatted RubyGems to Steal Credentialshighperson_alertThreat Actor
person_alertThreat Actor

StubMaker Campaign Deploys 16 Typosquatted RubyGems to Steal Credentials

StubMaker is a typosquatting campaign tracked by OpenSourceMalware researchers, discovered on August 15, 2026. The campaign operators published 16 malicious RubyGems packages under user accounts "mod8rz41mje" (Riley Miller) and "rbq95bwt6q" (Alex Dav…

RubyGems18 Aug · 09:20 UTC
Critical GitLab GraphQL flaw allows unauthenticated project deletioncriticalbug_reportVulnerability
bug_reportVulnerability

Critical GitLab GraphQL flaw allows unauthenticated project deletion

GitLab Community Edition (CE) and Enterprise Edition (EE) self-managed installations: all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4.

CVE-2026-1947817 Aug · 19:03 UTC
Snowflake GitHub Actions workflow injection exposed Jira credentialshighbug_reportVulnerability
bug_reportVulnerability

Snowflake GitHub Actions workflow injection exposed Jira credentials

Snowflake's snowflakedb/snowflake-connector-net GitHub repository, specifically the .github/workflows/jira_issue.yml workflow. Vulnerable code was present on the default branch from June 18–23, 2026 (5-day window).

Snowflake17 Aug · 16:44 UTC
Adobe patches three CVSS 10.0 flaws in ColdFusion and Campaign Classiccriticalbug_reportVulnerability
bug_reportVulnerability

Adobe patches three CVSS 10.0 flaws in ColdFusion and Campaign Classic

Adobe ColdFusion 2025.0.x (prior to 2025.0.12) and 2023.0.x (prior to 2023.0.23); Adobe Campaign Classic v7 (prior to 7.4.4 build 9400) on-premise and hybrid deployments; Adobe Commerce (version not specified).

CVE-2026-4836212 Aug · 09:13 UTC
Malicious LiteLLM PyPI packages stole credentials from 2,100+ orgscriticalbug_reportVulnerability
bug_reportVulnerability

Malicious LiteLLM PyPI packages stole credentials from 2,100+ orgs

LiteLLM versions 1.82.7 and 1.82.8 published on PyPI on March 24, 2026 (10:39-11:19 UTC, treat installs through 16:00 UTC as suspect). Any system that installed these versions or pulled them as transitive dependencies via agent frameworks or orchestr…

LiteLLM12 Aug · 06:04 UTC
Mozilla revokes Firefox/Thunderbird Linux signing key after repo exposurehighbug_reportVulnerability
bug_reportVulnerability

Mozilla revokes Firefox/Thunderbird Linux signing key after repo exposure

Mozilla Firefox and Thunderbird Linux downloads (all versions signed with subkey 09BE ED63 F346 2A2D FFAB 3B87 5ECB 6497 C1A2 0256 from April 2025 to August 2026).

Mozilla11 Aug · 10:04 UTC