Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 90 results
highbug_reportVulnerabilityCoder registry compromised via Cloudflare to deliver malicious Terraform modules
Coder registry infrastructure (registry.coder.com) accessed via compromised Cloudflare configuration. Users who downloaded Terraform modules between 07:35 and 21:45 UTC on August 31, 2026 potentially affected.
criticalbug_reportVulnerabilityBGP hijack delivers malicious Virtualizor update with root backdoor
Virtualizor hypervisor management software (all versions) from Softaculous. Attack window: August 28, 2026 20:57 UTC to August 30, 2026 06:10 UTC. Any installation that checked for updates during this period may be compromised.
criticalbug_reportVulnerabilityJFrog Artifactory auth bypass CVE-2026-82329 under active exploitation
JFrog Artifactory versions 7.161.0-7.161.19, 7.146.0-7.146.36, 7.133.0-7.133.28, 7.125.0-7.125.19, 7.117.0-7.117.27, and 7.111.4-7.111.21. Affects default configurations of self-managed instances. JFrog Access component specifically vulnerable.
criticalbug_reportVulnerabilityBGP hijack delivers malicious Virtualizor updates to VPS management systems
Virtualizor VPS management software (all versions prior to 3.2.9.9) from Softaculous. Attack window: August 28, 2026 20:57 UTC to August 30, 2026 06:10 UTC.
highbug_reportVulnerability13 malicious Packagist packages target iOS devices to steal crypto wallets
Packagist/Composer ecosystem: 13 malicious theme packages across 5 vendor namespaces (vsmov, vsphim, haiau009, chilltvcms, ophimcms). Targets Vietnamese streaming sites using OphimCMS/KKPhim.
highbug_reportVulnerabilityAustralia arrests two TeamPCP members behind global supply chain attacks
Over 1,000 organizations worldwide affected by supply chain attacks targeting open-source software and developer platforms. Confirmed victims include Trivy, LiteLLM, Telnyx, SAP, TanStack packages, European Commission, Mistral AI, OpenAI, and GitHub.…
criticalbug_reportVulnerabilityTeamPCP supply chain attack compromised Trivy, KICS, LiteLLM; 1000+ orgs hit
Open-source tools: Trivy scanner, Checkmarx KICS, LiteLLM AI gateway. Attack spanned GitHub Actions, Docker Hub, npm, PyPI, OpenVSX ecosystems. Over 1,000 organizations potentially compromised, 500,000+ credentials stolen, 300GB+ data exfiltrated.
highbug_reportVulnerabilityAustralian police arrest two TeamPCP members behind supply chain attacks
Global software supply chain: hundreds of open-source packages on GitHub, NPM, and other repositories compromised since late 2023. Victims include 2,500+ organizations using LiteLLM AI gateway, 3,800+ GitHub repositories, and developers across major…
highbug_reportVulnerabilitySupply-chain attack targets Android car head units via update app
Android-based automotive head units receiving updates through a compromised legitimate device-update application. Specific vendors, models, and geographic distribution not disclosed.
highbug_reportVulnerabilityAttackers shift focus to CI/CD pipelines and developer tools in SDLC
All organizations using modern software development practices with CI/CD pipelines, open-source dependencies, and developer tools. Specific recent attacks include ChainDrop npm worm (400+ packages including keyv and cacheable-request), XZ Utils (CVE-…
highbug_reportVulnerability14 trojanized npm packages deliver AI-powered RedC2 4.0 Linux backdoor
14 npm packages (streak-metrics-math, kit-map-vim, streak-map-cache, streak-map-kit, map-streak-kit, streak-cache-map, streak-calc-metrics, streak-calc-math, streak-math-abz, streak-metricsaz, streak-math-metrics, streak-metricazbd, streak-metricsazb…
criticalbug_reportVulnerabilityRust crates compromised via account takeover; build-time malware deployed
Three Rust crates (arrayref 0.3.10, internment 0.8.7, append-only-vec 0.1.9) with 245 million combined downloads. Malicious versions were live for 86-107 minutes on August 20, 2026.
criticalbug_reportVulnerabilityRust crate arrayref compromised via maintainer account takeover
Rust crate arrayref (vendor: arrayref). Specific malicious versions not detailed in source. Affects developers using this dependency during compilation. Scope: Rust ecosystem supply chain.
criticalbug_reportVulnerabilityClop deploys custom JSP web shell targeting PTC Windchill and FlexPLM
PTC Windchill and FlexPLM servers vulnerable to CVE-2026-12569 (CVSS 9.3). All unpatched instances are at risk. These enterprise Product Lifecycle Management (PLM) systems store engineering data, product designs, and administrative credentials.
highbug_reportVulnerability737 malicious Chrome VPN extensions route traffic through attacker proxies
Google Chrome users who installed any of 737 malicious VPN/proxy extensions from Chrome Web Store, primarily targeting Russian-speaking users. 274 extensions impersonated 66 legitimate VPN brands (Proton VPN, NordVPN, Surfshark, AdGuard VPN, Browsec,…
criticalbug_reportVulnerabilityMalicious LiteLLM PyPI packages stole credentials from 2,100+ orgs
LiteLLM versions 1.82.7 and 1.82.8 published on PyPI on March 24, 2026 (10:39-11:19 UTC, treat installs through 16:00 UTC as suspect). Any system that installed these versions or pulled them as transitive dependencies via agent frameworks or orchestr…
highperson_alertThreat ActorExfilSquad Claims 2.6M Records Stolen from Wesco CRM Environment
ExfilSquad is a data extortion group that specializes in exfiltrating sensitive information from organizations and leveraging it for ransom demands. The group operates a data leak site where they publish stolen data after ransom deadlines expire.
highbug_reportVulnerabilityMozilla revokes Firefox/Thunderbird Linux signing key after repo exposure
Mozilla Firefox and Thunderbird Linux downloads (all versions signed with subkey 09BE ED63 F346 2A2D FFAB 3B87 5ECB 6497 C1A2 0256 from April 2025 to August 2026).
highbug_reportVulnerabilityBdThemes WordPress plugins compromised to create rogue admin accounts
BdThemes WordPress plugins including Element Pack (100,000+ active installs), Prime Slider, Ultimate Post Kit, Pixel Gallery, and Ultimate Store Kit. All versions using the vulnerable Biggop Library introduced in March 2026.
highbug_reportVulnerabilityLexisNexis shuts down services after suspicious third-party vendor breach
LexisNexis Diligence, Metabase API, and Newsdesk services. Incident stems from compromise of unnamed third-party vendor's servers hosting these platforms.
highbug_reportVulnerabilityMalicious VS Code extensions steal crypto wallets and credentials from devs
Microsoft Visual Studio Code users who installed "Solidity Pro" extensions (helper-beeps.solidity-pro or web3devtoolsx.solidity-pro) from Open VSX marketplace. Extensions targeted Ethereum/Web3 developers.
criticalbug_reportVulnerabilityHead Mare hacktivists backdoor TrueConf installers via server compromise
TrueConf video conferencing servers (unpatched versions) and client installers distributed from compromised servers. Specific vulnerable versions not disclosed. Affects organizations using TrueConf for video conferencing.
criticalbug_reportVulnerabilityNearly 800 malicious npm packages deliver cross-platform RAT via typosquatting
npm registry: ~800 packages using typosquatting and AI-generated names. Targets all Node.js developers on Windows, macOS (x64/ARM64), and Linux (x64/ARM64). Delivers WEL1DROPPER leading to Sliver C2 framework and platform-specific infostealers.
highbug_reportVulnerabilityChainDrop npm worm infects 400+ packages, steals secrets via blockchain C2
Over 400 npm packages including widely used packages like keyv and cacheable-request. Affects developer workstations, CI/CD pipelines (especially GitHub Actions), cloud environments, and downstream software users.
highbug_reportVulnerabilityTrojanized npm packages use blockchain to hide C2 IPs in supply chain attack
Two npm packages: "bianira-ui" (109 downloads) and "fluid-type-ui" (587 downloads), published July 28, 2026 by users "npmuser1101" and "npmuser3002". Packages now removed from npm.
criticalbug_reportVulnerabilityCredential-stealing worm compromises 400+ npm packages via auto-propagation
Over 400 npm packages across multiple unrelated publishers, including keyv, flat-cache, cache-manager, and other major enterprise software ecosystem packages. Affects developer workstations and CI/CD environments with npm lifecycle scripts enabled.
criticalbug_reportVulnerabilityChainDrop worm compromises 1,300+ npm packages with 2B monthly downloads
Over 1,300 npm packages (1,381 versions) including Keyv, Cacheable, flat-cache, and file-entry-cache. Attack originated from compromised GitHub account of Keyv maintainer.
criticalbug_reportVulnerabilitynpm worm from keyv@6.0.0 poisons 353+ packages, steals credentials via hooks
npm packages: keyv@6.0.0 and at least 353 poisoned versions across 79 package names (SafeDep verified); broader estimates reach 868 packages. Affects developers and CI/CD environments using npm clients prior to npm 12, Claude Code, and VS Code.
highbug_reportVulnerabilityPalo Alto NOVA AI system discovers 14,090 unreported OSS vulnerabilities
3,915 open-source software projects across six ecosystems (Go, JavaScript/TypeScript, PHP, C/C++, Java/JVM, Ruby/Python/Lua/Perl). 99.4% of 14,090 vulnerabilities were previously unreported; 40% rated high or critical severity.
highbug_reportVulnerabilityGoogle removes ADK workflows after prompt injection exposed CI credentials
Google Agent Development Kit (ADK) Python repository on GitHub. Three workflows removed: issue-analyze.yml, issue-fix.yml, and pr-analyze.yml. Affected repository automation infrastructure, not the distributed ADK Python package itself.