Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-20 · 02:03 UTC
articleTotal: 593 reports

Filtered Reports

30 / 78 results
Active filter:tag: #software-development✕ clear
Seven malicious npm packages target Vite ecosystem with blockchain C2 RAThighbug_reportVulnerability
bug_reportVulnerability

Seven malicious npm packages target Vite ecosystem with blockchain C2 RAT

npm package ecosystem, specifically projects using Vite frontend tooling. Seven malicious packages identified in the ViteVenom campaign. Any JavaScript/Node.js development environments that installed these packages are compromised.

npm16:54 UTC
NadMesh Botnet Targets AI Services for AWS and Kubernetes Credential Thefthighperson_alertThreat Actor
person_alertThreat Actor

NadMesh Botnet Targets AI Services for AWS and Kubernetes Credential Theft

NadMesh is a Go-based botnet operation discovered in early July that specializes in compromising cloud infrastructure credentials through exploitation of exposed AI and automation services.

AWS15:12 UTC
Malicious npm and PyPI packages impersonate Paysafe payment SDKshighbug_reportVulnerability
bug_reportVulnerability

Malicious npm and PyPI packages impersonate Paysafe payment SDKs

Developers using npm and PyPI repositories who may have installed counterfeit packages impersonating Paysafe, Skrill, and Neteller payment SDKs. Affects development environments and potentially downstream applications integrating these malicious pack…

Paysafe17:54 UTC
HalluSquatting attack exploits AI coding assistants to distribute malwarehighbug_reportVulnerability
bug_reportVulnerability

HalluSquatting attack exploits AI coding assistants to distribute malware

AI coding assistants (GitHub Copilot, ChatGPT, Claude, etc.) and developers using AI-generated package recommendations. All package ecosystems (npm, PyPI, Maven, etc.) are potential targets.

AI coding assistants13:07 UTC
GitHub commit verification flaw allows signature reuse on rewritten commitshighbug_reportVulnerability
bug_reportVulnerability

GitHub commit verification flaw allows signature reuse on rewritten commits

GitHub's commit verification system for GPG/SSH-signed commits. All repositories using signed commits with GitHub's "Verified" badge are potentially affected. The flaw is in GitHub's verification logic, not Git itself.

GitHub09:51 UTC
GitHub Agentic Workflows leak private repo data via public issueshighbug_reportVulnerability
bug_reportVulnerability

GitHub Agentic Workflows leak private repo data via public issues

GitHub Agentic Workflows with cross-repository read access. Organizations using GitHub agents that can access both public and private repositories are vulnerable. No CVE assigned yet.

GitHub12:04 UTC
Gitea Docker auth bypass under active probing (CVE-2026-20896)criticalbug_reportVulnerability
bug_reportVulnerability

Gitea Docker auth bypass under active probing (CVE-2026-20896)

Gitea Docker images with improper X-WEBAUTH-USER header validation. Specific vulnerable versions not provided; affects deployments trusting reverse proxy authentication headers without IP restrictions.

CVE-2026-2089614:28 UTC
Adobe ColdFusion CVE-2026-48282 under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Adobe ColdFusion CVE-2026-48282 under active exploitation

Adobe ColdFusion (specific versions not disclosed). Maximum severity vulnerability actively exploited in the wild.

CVE-2026-4828211:18 UTC
North Korean actors deploy 108 malicious packages in PolinRider campaignhighbug_reportVulnerability
bug_reportVulnerability

North Korean actors deploy 108 malicious packages in PolinRider campaign

npm, Packagist (PHP), Go modules, and Google Chrome Web Store. 108 malicious packages and extensions published. Maintainer accounts actively compromised. Campaign linked to North Korean Contagious Interview threat group.

The Hacker News09:17 UTC
North Korean actors deploy malicious npm packages to steal developer secretshighbug_reportVulnerability
bug_reportVulnerability

North Korean actors deploy malicious npm packages to steal developer secrets

npm ecosystem: malicious packages "rollup-packages-polyfill-core" and "rollup-runtime-polyfill-core" impersonating legitimate "rollup-plugin-polyfill-node".

npm14:07 UTC
Argo CD repo-server RCE enables cluster takeover, no patch availablecriticalbug_reportVulnerability
bug_reportVulnerability

Argo CD repo-server RCE enables cluster takeover, no patch available

Argo CD repo-server component, all versions (specific affected versions not disclosed). Exploitation requires access to internal network port where repo-server listens.

Argo CD17:40 UTC
Adobe patches CVSS 10.0 flaws in ColdFusion and Campaign Classiccriticalbug_reportVulnerability
bug_reportVulnerability

Adobe patches CVSS 10.0 flaws in ColdFusion and Campaign Classic

Adobe ColdFusion and Adobe Campaign Classic (specific versions not provided). Vulnerabilities include arbitrary code execution, privilege escalation, arbitrary file system read, and security feature bypass.

Adobe13:25 UTC
LLM hallucinations exploited for supply chain attacks via phantom domainshighbug_reportVulnerability
bug_reportVulnerability

LLM hallucinations exploited for supply chain attacks via phantom domains

Organizations using LLMs for development assistance, code generation, or package recommendations. Developers relying on AI-generated domain/package suggestions without verification.

Unit 42 (Palo Alto)23:00 UTC
Trojanized Pyrogram forks on PyPI target Telegram bot developershighbug_reportVulnerability
bug_reportVulnerability

Trojanized Pyrogram forks on PyPI target Telegram bot developers

Python developers using PyPI packages for Telegram bot development. Malicious forks of Pyrogram library active since November 2024. Affects developers who may have installed compromised packages instead of legitimate Pyrogram.

PyPI19:02 UTC
GuardFall shell injection bypasses safety checks in 10 of 11 AI coding agentshighbug_reportVulnerability
bug_reportVulnerability

GuardFall shell injection bypasses safety checks in 10 of 11 AI coding agents

10 out of 11 tested open-source AI coding and computer-use agents are vulnerable to GuardFall shell injection bypass. Only "Continue" agent demonstrated resistance.

Adversa AI12:26 UTC
63% of iOS AI chatbot apps leak API keys via unencrypted network traffichighbug_reportVulnerability
bug_reportVulnerability

63% of iOS AI chatbot apps leak API keys via unencrypted network traffic

282 out of 444 iOS AI chatbot applications expose paid AI service credentials (API keys, tokens, backend endpoints) in plaintext network traffic. Affects apps integrating third-party AI services (OpenAI, Anthropic, Google, etc.).

The Hacker News11:49 UTC
Hijacked npm and Go packages deploy cross-platform stealer via VS Codehighbug_reportVulnerability
bug_reportVulnerability

Hijacked npm and Go packages deploy cross-platform stealer via VS Code

Compromised npm and Go packages targeting developers using Microsoft Visual Studio Code on Windows, Linux, and macOS. Attack bypasses npm v12 lifecycle script protections by abusing VS Code task execution.

npm03:36 UTC
Agentic coding tools vulnerable to hidden malicious payloads in reposhighbug_reportVulnerability
bug_reportVulnerability

Agentic coding tools vulnerable to hidden malicious payloads in repos

Agentic coding tools and AI-assisted development platforms that automatically fetch and execute code from GitHub repositories. Specific products not disclosed.

BleepingComputer12:22 UTC
Amazon Q Developer flaw allows credential theft via malicious reposhighbug_reportVulnerability
bug_reportVulnerability

Amazon Q Developer flaw allows credential theft via malicious repos

Amazon Q Developer (all versions prior to patch). Affects developers using the IDE plugin who clone or open malicious repositories containing crafted Model Context Protocol (MCP) server configurations.

CVE-2026-1295711:53 UTC
Miasma malware compromises npm packages LeoPlatform and RStreamshighbug_reportVulnerability
bug_reportVulnerability

Miasma malware compromises npm packages LeoPlatform and RStreams

npm packages LeoPlatform and RStreams compromised by Miasma malware family. Attack extends to GitHub Actions workflows and Go ecosystem. Organizations using these packages or dependent projects are affected.

npm09:05 UTC
CI/CD flaw "Cordyceps" exposes 300+ GitHub repos to supply-chain takeovercriticalbug_reportVulnerability
bug_reportVulnerability

CI/CD flaw "Cordyceps" exposes 300+ GitHub repos to supply-chain takeover

300+ GitHub repositories across major organizations including Microsoft, Google, and Apache. Vulnerability affects GitHub Actions CI/CD workflows. Specific products and versions not disclosed in available data.

Microsoft10:48 UTC
GitHub blocks pwn request attacks in actions/checkout starting June 2026highbug_reportVulnerability
bug_reportVulnerability

GitHub blocks pwn request attacks in actions/checkout starting June 2026

GitHub Actions workflows using actions/checkout with pull_request_target trigger. Organizations using GitHub Actions for CI/CD pipelines are affected. The security update applies to all repositories using the actions/checkout action after June 18, 20…

GitHub12:22 UTC
Malicious npm packages deliver Windows RAT to JavaScript developershighbug_reportVulnerability
bug_reportVulnerability

Malicious npm packages deliver Windows RAT to JavaScript developers

Three npm packages (aes-decode-runner-pro, postcss-minify-selector, postcss-minify-selector-parser) published within the past month. Total downloads: 145-615 per package. Affects Windows-based development environments using npm package manager.

npm06:54 UTC
ShapedPlugin WordPress Pro plugins backdoored via compromised update channelhighbug_reportVulnerability
bug_reportVulnerability

ShapedPlugin WordPress Pro plugins backdoored via compromised update channel

Multiple ShapedPlugin Pro WordPress plugins distributed through official licensed update channels. Exact plugin names and affected versions not specified.

ShapedPlugin16:00 UTC
Microsoft patches AutoJack vulnerability chain in AutoGen Studiohighbug_reportVulnerability
bug_reportVulnerability

Microsoft patches AutoJack vulnerability chain in AutoGen Studio

Microsoft AutoGen Studio - all versions prior to the patched release. AutoGen Studio is a low-code interface for building and managing AI agents. The vulnerability chain affects users who interact with untrusted web content while AutoGen Studio is ru…

Microsoft15:28 UTC
Critical RCE and XSS flaws in pgAdmin 4 enable credential theftcriticalbug_reportVulnerability
bug_reportVulnerability

Critical RCE and XSS flaws in pgAdmin 4 enable credential theft

pgAdmin 4 (specific vulnerable versions not provided in alert). pgAdmin is a web-based administration tool for PostgreSQL databases, commonly deployed in enterprise environments for database management.

pgAdmin13:02 UTC
AutoJack exploit chain enables RCE on AI browsing agents via malicious pageshighbug_reportVulnerability
bug_reportVulnerability

AutoJack exploit chain enables RCE on AI browsing agents via malicious pages

AI browsing agents (autonomous web browsers with AI capabilities) that interact with privileged local services via JavaScript. Specific products and versions not disclosed in Microsoft's research disclosure.

Microsoft13:30 UTC
AutoJack exploit chain enables RCE on AI agent hosts via malicious webpagecriticalbug_reportVulnerability
bug_reportVulnerability

AutoJack exploit chain enables RCE on AI agent hosts via malicious webpage

Microsoft AutoGen Studio users running AI browsing agents. Affects deployments where AutoGen Studio's MCP WebSocket is accessible to localhost without authentication. Specific version range not disclosed.

Microsoft22:17 UTC
Weekly threat roundup: Claude abuse, npm poisoning, phishing campaignshighbug_reportVulnerability
bug_reportVulnerability

Weekly threat roundup: Claude abuse, npm poisoning, phishing campaigns

Multiple platforms and products: Claude AI chat interface, npm package ecosystem (NastyC2), OAuth device-code flows, browser extensions (unspecified), macOS systems, cloud management agents, and internet-exposed edge devices.

Claude13:27 UTC
ShapedPlugin WordPress plugins compromised in supply chain attackhighbug_reportVulnerability
bug_reportVulnerability

ShapedPlugin WordPress plugins compromised in supply chain attack

Multiple WordPress plugins from ShapedPlugin vendor. Infected releases distributed to paying customers via official update mechanism. Specific plugin names and version numbers not disclosed in provided data.

ShapedPlugin10:55 UTC