Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 154 results
highbug_reportVulnerabilityCoder registry compromised via Cloudflare to deliver malicious Terraform modules
Coder registry infrastructure (registry.coder.com) accessed via compromised Cloudflare configuration. Users who downloaded Terraform modules between 07:35 and 21:45 UTC on August 31, 2026 potentially affected.
highbug_reportVulnerabilityShai-Hulud infostealer now targets 469 credential locations in dev tools
Developer workstations, CI/CD pipelines, cloud configurations, AI tool configs, package registries (npm, GitHub, Docker), and any environment storing long-lived credentials or tokens.
criticalbug_reportVulnerabilityJFrog Artifactory auth bypass exploited to forge admin tokens
JFrog Artifactory self-managed instances in default configuration. Patched in versions 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, and 7.161.20 (released August 28, 2026). JFrog Cloud environments already protected.
highbug_reportVulnerabilityAI coding agents execute malicious Git config commands outside sandbox
Seven command-line AI coding agents: goose (fixed in 1.44.0), Codex CLI/Desktop (fixed in 0.131.0 / 26.519.x), Claude Code (partially fixed in 2.1.196, second path unpatched in 2.1.252+), Hermes Agent 0.18.2–0.21.0 (unpatched), Qwen Code 0.19.6–0.22.…
criticalbug_reportVulnerabilityJFrog Artifactory auth bypass CVE-2026-82329 under active exploitation
JFrog Artifactory versions 7.161.0-7.161.19, 7.146.0-7.146.36, 7.133.0-7.133.28, 7.125.0-7.125.19, 7.117.0-7.117.27, and 7.111.4-7.111.21. Affects default configurations of self-managed instances. JFrog Access component specifically vulnerable.
highbug_reportVulnerability13 malicious Packagist packages target iOS devices to steal crypto wallets
Packagist/Composer ecosystem: 13 malicious theme packages across 5 vendor namespaces (vsmov, vsphim, haiau009, chilltvcms, ophimcms). Targets Vietnamese streaming sites using OphimCMS/KKPhim.
criticalbug_reportVulnerabilityLangflow and Ruby on Rails flaws actively exploited for RCE and C2
Langflow (CVE-2026-0768, CVSS 9.8): arbitrary Python code execution as root via improper input validation. Ruby on Rails (CVE-2026-66066 aka KindaRails2Shell, CVSS 9.5): unauthenticated arbitrary file read, secret leakage, and RCE in applications usi…
criticalbug_reportVulnerabilityPaperCut NG/MF flaws chained for unauthenticated RCE, active exploitation
PaperCut NG and PaperCut MF (all unpatched versions). CVE-2026-81578 (CVSS 8.8, improper access control) and CVE-2026-82078 (CVSS 9.4, unsafe dynamic class loading) are chained to bypass authentication and execute arbitrary Java code.
criticalbug_reportVulnerabilityNext.js critical RCE flaws in AVIF processing and Windows path traversal
Next.js versions 13.4–15.5.23 and 16.0–16.3.2. CVE-2026-75604 (Windows path traversal, CVSS 9.0) affects Windows-hosted servers using Pages Router or App Router without Cache Components.
highbug_reportVulnerabilityAmazon Kiro IDE prompt injection enables data exfiltration via Powers
Amazon Kiro IDE version 0.7.45 on Windows. Vulnerability fixed in version 0.8.140. Latest version is 1.0.337. Affects both trusted and untrusted workspaces when malicious workspace files are opened.
criticalbug_reportVulnerabilityTeamPCP supply chain attack compromised Trivy, KICS, LiteLLM; 1000+ orgs hit
Open-source tools: Trivy scanner, Checkmarx KICS, LiteLLM AI gateway. Attack spanned GitHub Actions, Docker Hub, npm, PyPI, OpenVSX ecosystems. Over 1,000 organizations potentially compromised, 500,000+ credentials stolen, 300GB+ data exfiltrated.
highbug_reportVulnerabilityAustralian police arrest two TeamPCP members behind supply chain attacks
Global software supply chain: hundreds of open-source packages on GitHub, NPM, and other repositories compromised since late 2023. Victims include 2,500+ organizations using LiteLLM AI gateway, 3,800+ GitHub repositories, and developers across major…
highbug_reportVulnerabilityAttackers abuse npm mirrors as free hosting for Cloudflare phishing pages
npm registry and public mirrors (UNPKG, npmmirror). Organizations using these mirrors to serve package content. At least 24 malicious packages identified hosting fake Cloudflare CAPTCHA pages.
highbug_reportVulnerabilityNVIDIA NemoClaw DNS rebinding flaw enables AI model poisoning via browser
NVIDIA NemoClaw versions prior to v0.0.35 on macOS and Linux. Windows and WSL installations remain vulnerable as of v0.0.34, which added a warning but no technical fix.
highbug_reportVulnerability24 npm packages abuse unpkg mirrors as phishing infrastructure
24 malicious npm packages (e.g., bgzxcuite2, prezdentkxheiw, egair0810) hosted on npm registry and mirrored on unpkg.com and similar CDN services. Affects users who click links to these mirrored HTML pages, not developers installing packages directly…
highbug_reportVulnerabilityXecurify miniOrange SAML plugin flaws exploited for WordPress admin access
Xecurify miniOrange SAML 2.0 Single Sign On WordPress plugin, Standard edition versions prior to 17.0.6. CVE-2026-61979 (CVSS 8.1) fixed in 17.0.5; CVE-2026-15981 (CVSS 9.8) fixed in 17.0.6.
highbug_reportVulnerability.NET Framework August 2026 updates break WPF printing and PDF export
.NET Framework cumulative updates released August 2026 Patch Tuesday. Affects Windows Presentation Foundation (WPF) applications on Windows 10, Windows 11, Windows Server 2012 through Windows Server 2025.
criticalbug_reportVulnerabilityCritical Keycloak flaw allows unauthenticated account takeover via password reset
Keycloak identity and access management server: upstream versions prior to 26.7.2; Red Hat build of Keycloak (RHBK) 26.4 prior to 26.4.15 and 26.6 prior to 26.6.6. All realms with "Forgot password" feature enabled are vulnerable.
highbug_reportVulnerabilityAttackers shift focus to CI/CD pipelines and developer tools in SDLC
All organizations using modern software development practices with CI/CD pipelines, open-source dependencies, and developer tools. Specific recent attacks include ChainDrop npm worm (400+ packages including keyv and cacheable-request), XZ Utils (CVE-…
highbug_reportVulnerability14 trojanized npm packages deliver AI-powered RedC2 4.0 Linux backdoor
14 npm packages (streak-metrics-math, kit-map-vim, streak-map-cache, streak-map-kit, map-streak-kit, streak-cache-map, streak-calc-metrics, streak-calc-math, streak-math-abz, streak-metricsaz, streak-math-metrics, streak-metricazbd, streak-metricsazb…
criticalbug_reportVulnerabilityRust crates compromised via account takeover; build-time malware deployed
Three Rust crates (arrayref 0.3.10, internment 0.8.7, append-only-vec 0.1.9) with 245 million combined downloads. Malicious versions were live for 86-107 minutes on August 20, 2026.
criticalbug_reportVulnerabilityRed Hat Keycloak password-reset flaw enables account takeover
Red Hat build of Keycloak, specific versions not disclosed in source. Vulnerability exists in the password-reset flow mechanism.
criticalbug_reportVulnerabilityCritical sandbox escape in isolated-vm ≤7.0.0 enables RCE on host
isolated-vm library versions ≤7.0.0. Patched in versions 6.2.0 and 7.0.1. Affects Node.js environments using isolated-vm for sandboxing untrusted JavaScript. Package has ~1 million weekly npm downloads.
criticalbug_reportVulnerabilityGitLab CE/EE critical code injection flaw with public PoC exploit
GitLab Community Edition (CE) and Enterprise Edition (EE). Specific affected versions not provided in source material. CVE identifier not yet assigned or disclosed.
highperson_alertThreat ActorStubMaker Campaign Deploys 16 Typosquatted RubyGems to Steal Credentials
StubMaker is a typosquatting campaign tracked by OpenSourceMalware researchers, discovered on August 15, 2026. The campaign operators published 16 malicious RubyGems packages under user accounts "mod8rz41mje" (Riley Miller) and "rbq95bwt6q" (Alex Dav…
criticalbug_reportVulnerabilityCritical GitLab GraphQL flaw allows unauthenticated project deletion
GitLab Community Edition (CE) and Enterprise Edition (EE) self-managed installations: all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4.
highbug_reportVulnerabilitySnowflake GitHub Actions workflow injection exposed Jira credentials
Snowflake's snowflakedb/snowflake-connector-net GitHub repository, specifically the .github/workflows/jira_issue.yml workflow. Vulnerable code was present on the default branch from June 18–23, 2026 (5-day window).
criticalbug_reportVulnerabilityAdobe patches three CVSS 10.0 flaws in ColdFusion and Campaign Classic
Adobe ColdFusion 2025.0.x (prior to 2025.0.12) and 2023.0.x (prior to 2023.0.23); Adobe Campaign Classic v7 (prior to 7.4.4 build 9400) on-premise and hybrid deployments; Adobe Commerce (version not specified).
criticalbug_reportVulnerabilityMalicious LiteLLM PyPI packages stole credentials from 2,100+ orgs
LiteLLM versions 1.82.7 and 1.82.8 published on PyPI on March 24, 2026 (10:39-11:19 UTC, treat installs through 16:00 UTC as suspect). Any system that installed these versions or pulled them as transitive dependencies via agent frameworks or orchestr…
highbug_reportVulnerabilityMozilla revokes Firefox/Thunderbird Linux signing key after repo exposure
Mozilla Firefox and Thunderbird Linux downloads (all versions signed with subkey 09BE ED63 F346 2A2D FFAB 3B87 5ECB 6497 C1A2 0256 from April 2025 to August 2026).