Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 90 results
Active filter:tag: #supply-chain✕ clear
Coder registry compromised via Cloudflare to deliver malicious Terraform moduleshighbug_reportVulnerability
bug_reportVulnerability

Coder registry compromised via Cloudflare to deliver malicious Terraform modules

Coder registry infrastructure (registry.coder.com) accessed via compromised Cloudflare configuration. Users who downloaded Terraform modules between 07:35 and 21:45 UTC on August 31, 2026 potentially affected.

Coder3 Sep · 18:04 UTC
BGP hijack delivers malicious Virtualizor update with root backdoorcriticalbug_reportVulnerability
bug_reportVulnerability

BGP hijack delivers malicious Virtualizor update with root backdoor

Virtualizor hypervisor management software (all versions) from Softaculous. Attack window: August 28, 2026 20:57 UTC to August 30, 2026 06:10 UTC. Any installation that checked for updates during this period may be compromised.

Virtualizor2 Sep · 11:12 UTC
JFrog Artifactory auth bypass CVE-2026-82329 under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

JFrog Artifactory auth bypass CVE-2026-82329 under active exploitation

JFrog Artifactory versions 7.161.0-7.161.19, 7.146.0-7.146.36, 7.133.0-7.133.28, 7.125.0-7.125.19, 7.117.0-7.117.27, and 7.111.4-7.111.21. Affects default configurations of self-managed instances. JFrog Access component specifically vulnerable.

CVE-2026-823291 Sep · 15:53 UTC
BGP hijack delivers malicious Virtualizor updates to VPS management systemscriticalbug_reportVulnerability
bug_reportVulnerability

BGP hijack delivers malicious Virtualizor updates to VPS management systems

Virtualizor VPS management software (all versions prior to 3.2.9.9) from Softaculous. Attack window: August 28, 2026 20:57 UTC to August 30, 2026 06:10 UTC.

Virtualizor1 Sep · 12:45 UTC
13 malicious Packagist packages target iOS devices to steal crypto walletshighbug_reportVulnerability
bug_reportVulnerability

13 malicious Packagist packages target iOS devices to steal crypto wallets

Packagist/Composer ecosystem: 13 malicious theme packages across 5 vendor namespaces (vsmov, vsphim, haiau009, chilltvcms, ophimcms). Targets Vietnamese streaming sites using OphimCMS/KKPhim.

Packagist1 Sep · 12:07 UTC
Australia arrests two TeamPCP members behind global supply chain attackshighbug_reportVulnerability
bug_reportVulnerability

Australia arrests two TeamPCP members behind global supply chain attacks

Over 1,000 organizations worldwide affected by supply chain attacks targeting open-source software and developer platforms. Confirmed victims include Trivy, LiteLLM, Telnyx, SAP, TanStack packages, European Commission, Mistral AI, OpenAI, and GitHub.…

BleepingComputer27 Aug · 11:31 UTC
TeamPCP supply chain attack compromised Trivy, KICS, LiteLLM; 1000+ orgs hitcriticalbug_reportVulnerability
bug_reportVulnerability

TeamPCP supply chain attack compromised Trivy, KICS, LiteLLM; 1000+ orgs hit

Open-source tools: Trivy scanner, Checkmarx KICS, LiteLLM AI gateway. Attack spanned GitHub Actions, Docker Hub, npm, PyPI, OpenVSX ecosystems. Over 1,000 organizations potentially compromised, 500,000+ credentials stolen, 300GB+ data exfiltrated.

Trivy27 Aug · 09:56 UTC
Australian police arrest two TeamPCP members behind supply chain attackshighbug_reportVulnerability
bug_reportVulnerability

Australian police arrest two TeamPCP members behind supply chain attacks

Global software supply chain: hundreds of open-source packages on GitHub, NPM, and other repositories compromised since late 2023. Victims include 2,500+ organizations using LiteLLM AI gateway, 3,800+ GitHub repositories, and developers across major…

Krebs on Security27 Aug · 09:04 UTC
Supply-chain attack targets Android car head units via update apphighbug_reportVulnerability
bug_reportVulnerability

Supply-chain attack targets Android car head units via update app

Android-based automotive head units receiving updates through a compromised legitimate device-update application. Specific vendors, models, and geographic distribution not disclosed.

BleepingComputer22 Aug · 12:14 UTC
Attackers shift focus to CI/CD pipelines and developer tools in SDLChighbug_reportVulnerability
bug_reportVulnerability

Attackers shift focus to CI/CD pipelines and developer tools in SDLC

All organizations using modern software development practices with CI/CD pipelines, open-source dependencies, and developer tools. Specific recent attacks include ChainDrop npm worm (400+ packages including keyv and cacheable-request), XZ Utils (CVE-…

Unit 42 (Palo Alto)21 Aug · 21:00 UTC
14 trojanized npm packages deliver AI-powered RedC2 4.0 Linux backdoorhighbug_reportVulnerability
bug_reportVulnerability

14 trojanized npm packages deliver AI-powered RedC2 4.0 Linux backdoor

14 npm packages (streak-metrics-math, kit-map-vim, streak-map-cache, streak-map-kit, map-streak-kit, streak-cache-map, streak-calc-metrics, streak-calc-math, streak-math-abz, streak-metricsaz, streak-math-metrics, streak-metricazbd, streak-metricsazb…

npm21 Aug · 16:53 UTC
Rust crates compromised via account takeover; build-time malware deployedcriticalbug_reportVulnerability
bug_reportVulnerability

Rust crates compromised via account takeover; build-time malware deployed

Three Rust crates (arrayref 0.3.10, internment 0.8.7, append-only-vec 0.1.9) with 245 million combined downloads. Malicious versions were live for 86-107 minutes on August 20, 2026.

Rust Project20 Aug · 18:22 UTC
Rust crate arrayref compromised via maintainer account takeovercriticalbug_reportVulnerability
bug_reportVulnerability

Rust crate arrayref compromised via maintainer account takeover

Rust crate arrayref (vendor: arrayref). Specific malicious versions not detailed in source. Affects developers using this dependency during compilation. Scope: Rust ecosystem supply chain.

arrayref20 Aug · 15:53 UTC
Clop deploys custom JSP web shell targeting PTC Windchill and FlexPLMcriticalbug_reportVulnerability
bug_reportVulnerability

Clop deploys custom JSP web shell targeting PTC Windchill and FlexPLM

PTC Windchill and FlexPLM servers vulnerable to CVE-2026-12569 (CVSS 9.3). All unpatched instances are at risk. These enterprise Product Lifecycle Management (PLM) systems store engineering data, product designs, and administrative credentials.

PTC19 Aug · 03:39 UTC
737 malicious Chrome VPN extensions route traffic through attacker proxieshighbug_reportVulnerability
bug_reportVulnerability

737 malicious Chrome VPN extensions route traffic through attacker proxies

Google Chrome users who installed any of 737 malicious VPN/proxy extensions from Chrome Web Store, primarily targeting Russian-speaking users. 274 extensions impersonated 66 legitimate VPN brands (Proton VPN, NordVPN, Surfshark, AdGuard VPN, Browsec,…

Google12 Aug · 12:09 UTC
Malicious LiteLLM PyPI packages stole credentials from 2,100+ orgscriticalbug_reportVulnerability
bug_reportVulnerability

Malicious LiteLLM PyPI packages stole credentials from 2,100+ orgs

LiteLLM versions 1.82.7 and 1.82.8 published on PyPI on March 24, 2026 (10:39-11:19 UTC, treat installs through 16:00 UTC as suspect). Any system that installed these versions or pulled them as transitive dependencies via agent frameworks or orchestr…

LiteLLM12 Aug · 06:04 UTC
ExfilSquad Claims 2.6M Records Stolen from Wesco CRM Environmenthighperson_alertThreat Actor
person_alertThreat Actor

ExfilSquad Claims 2.6M Records Stolen from Wesco CRM Environment

ExfilSquad is a data extortion group that specializes in exfiltrating sensitive information from organizations and leveraging it for ransom demands. The group operates a data leak site where they publish stolen data after ransom deadlines expire.

Wesco11 Aug · 13:59 UTC
Mozilla revokes Firefox/Thunderbird Linux signing key after repo exposurehighbug_reportVulnerability
bug_reportVulnerability

Mozilla revokes Firefox/Thunderbird Linux signing key after repo exposure

Mozilla Firefox and Thunderbird Linux downloads (all versions signed with subkey 09BE ED63 F346 2A2D FFAB 3B87 5ECB 6497 C1A2 0256 from April 2025 to August 2026).

Mozilla11 Aug · 10:04 UTC
BdThemes WordPress plugins compromised to create rogue admin accountshighbug_reportVulnerability
bug_reportVulnerability

BdThemes WordPress plugins compromised to create rogue admin accounts

BdThemes WordPress plugins including Element Pack (100,000+ active installs), Prime Slider, Ultimate Post Kit, Pixel Gallery, and Ultimate Store Kit. All versions using the vulnerable Biggop Library introduced in March 2026.

BdThemes10 Aug · 19:12 UTC
LexisNexis shuts down services after suspicious third-party vendor breachhighbug_reportVulnerability
bug_reportVulnerability

LexisNexis shuts down services after suspicious third-party vendor breach

LexisNexis Diligence, Metabase API, and Newsdesk services. Incident stems from compromise of unnamed third-party vendor's servers hosting these platforms.

LexisNexis10 Aug · 10:11 UTC
Malicious VS Code extensions steal crypto wallets and credentials from devshighbug_reportVulnerability
bug_reportVulnerability

Malicious VS Code extensions steal crypto wallets and credentials from devs

Microsoft Visual Studio Code users who installed "Solidity Pro" extensions (helper-beeps.solidity-pro or web3devtoolsx.solidity-pro) from Open VSX marketplace. Extensions targeted Ethereum/Web3 developers.

Microsoft10 Aug · 05:38 UTC
Head Mare hacktivists backdoor TrueConf installers via server compromisecriticalbug_reportVulnerability
bug_reportVulnerability

Head Mare hacktivists backdoor TrueConf installers via server compromise

TrueConf video conferencing servers (unpatched versions) and client installers distributed from compromised servers. Specific vulnerable versions not disclosed. Affects organizations using TrueConf for video conferencing.

TrueConf8 Aug · 12:16 UTC
Nearly 800 malicious npm packages deliver cross-platform RAT via typosquattingcriticalbug_reportVulnerability
bug_reportVulnerability

Nearly 800 malicious npm packages deliver cross-platform RAT via typosquatting

npm registry: ~800 packages using typosquatting and AI-generated names. Targets all Node.js developers on Windows, macOS (x64/ARM64), and Linux (x64/ARM64). Delivers WEL1DROPPER leading to Sliver C2 framework and platform-specific infostealers.

npm7 Aug · 16:48 UTC
ChainDrop npm worm infects 400+ packages, steals secrets via blockchain C2highbug_reportVulnerability
bug_reportVulnerability

ChainDrop npm worm infects 400+ packages, steals secrets via blockchain C2

Over 400 npm packages including widely used packages like keyv and cacheable-request. Affects developer workstations, CI/CD pipelines (especially GitHub Actions), cloud environments, and downstream software users.

npm6 Aug · 20:26 UTC
Trojanized npm packages use blockchain to hide C2 IPs in supply chain attackhighbug_reportVulnerability
bug_reportVulnerability

Trojanized npm packages use blockchain to hide C2 IPs in supply chain attack

Two npm packages: "bianira-ui" (109 downloads) and "fluid-type-ui" (587 downloads), published July 28, 2026 by users "npmuser1101" and "npmuser3002". Packages now removed from npm.

npm5 Aug · 11:41 UTC
Credential-stealing worm compromises 400+ npm packages via auto-propagationcriticalbug_reportVulnerability
bug_reportVulnerability

Credential-stealing worm compromises 400+ npm packages via auto-propagation

Over 400 npm packages across multiple unrelated publishers, including keyv, flat-cache, cache-manager, and other major enterprise software ecosystem packages. Affects developer workstations and CI/CD environments with npm lifecycle scripts enabled.

npm4 Aug · 21:46 UTC
ChainDrop worm compromises 1,300+ npm packages with 2B monthly downloadscriticalbug_reportVulnerability
bug_reportVulnerability

ChainDrop worm compromises 1,300+ npm packages with 2B monthly downloads

Over 1,300 npm packages (1,381 versions) including Keyv, Cacheable, flat-cache, and file-entry-cache. Attack originated from compromised GitHub account of Keyv maintainer.

npm4 Aug · 13:24 UTC
npm worm from keyv@6.0.0 poisons 353+ packages, steals credentials via hookscriticalbug_reportVulnerability
bug_reportVulnerability

npm worm from keyv@6.0.0 poisons 353+ packages, steals credentials via hooks

npm packages: keyv@6.0.0 and at least 353 poisoned versions across 79 package names (SafeDep verified); broader estimates reach 868 packages. Affects developers and CI/CD environments using npm clients prior to npm 12, Claude Code, and VS Code.

npm4 Aug · 11:30 UTC
Palo Alto NOVA AI system discovers 14,090 unreported OSS vulnerabilitieshighbug_reportVulnerability
bug_reportVulnerability

Palo Alto NOVA AI system discovers 14,090 unreported OSS vulnerabilities

3,915 open-source software projects across six ecosystems (Go, JavaScript/TypeScript, PHP, C/C++, Java/JVM, Ruby/Python/Lua/Perl). 99.4% of 14,090 vulnerabilities were previously unreported; 40% rated high or critical severity.

open-source software projects4 Aug · 11:00 UTC
Google removes ADK workflows after prompt injection exposed CI credentialshighbug_reportVulnerability
bug_reportVulnerability

Google removes ADK workflows after prompt injection exposed CI credentials

Google Agent Development Kit (ADK) Python repository on GitHub. Three workflows removed: issue-analyze.yml, issue-fix.yml, and pr-analyze.yml. Affected repository automation infrastructure, not the distributed ADK Python package itself.

Google4 Aug · 09:16 UTC