Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
22 / 22 results
highpublicGeopoliticalKDDI breach exposes 12M records across Japanese ISP ecosystem
The breach of KDDI, one of Japan's three major telecommunications carriers, represents a significant compromise of critical infrastructure in a key U.S. Indo-Pacific ally.
criticalbug_reportVulnerabilityTenda router backdoor allows admin access bypass (CVE-2026-11405)
Tenda routers running vulnerable firmware versions. Specific models and version ranges not disclosed in available data. Affects web management interface authentication mechanism.
highbug_reportVulnerabilityCisco Unified CM vulnerability under active exploitation post-patch
Cisco Unified Communications Manager (Unified CM). Specific vulnerable versions not disclosed; patched versions available since early June 2024. Affects organizations running unpatched Unified CM deployments.
highperson_alertThreat ActorRustDuck Botnet Targets IoT Devices for DDoS Operations
RustDuck is a two-stage malware family written in Rust, designed to compromise Internet of Things (IoT) devices including home routers, IP cameras, Android set-top boxes, and inadequately secured servers.
highpublicGeopoliticalKDDI breach exposes 14.2M email accounts across Japanese ISP ecosystem
The breach at KDDI Corporation, one of Japan's largest telecommunications operators, highlights systemic vulnerabilities in shared infrastructure models within critical communications sectors.
highperson_alertThreat ActorPolish Authorities Dismantle SIM-Swapping Gang Targeting Crypto Assets
This organized cybercrime group operated in Poland, conducting SIM-swapping attacks with the primary motivation of financial gain through cryptocurrency theft.
criticalbug_reportVulnerabilityCisco Catalyst SD-WAN zero-day exploited for root access (CVE-2026-20245)
Cisco Catalyst SD-WAN devices. Specific affected versions not disclosed in available information. Attackers gain root-level access and can create persistent rogue accounts.
criticalbug_reportVulnerabilityCisco Unified CM critical flaw under active exploitation, root access risk
Cisco Unified Communications Manager (CUCM) and Unified CM SME. Specific affected versions not provided in available data. Vulnerability affects HTTP request handling with unauthenticated remote attack vector.
highbug_reportVulnerabilityCisco Unified Communications Manager SSRF under active exploitation
Cisco Unified Communications Manager (CUCM). Specific affected versions not disclosed. SSRF vulnerability (CVE-2026-20230) allows attackers to force the server to make unauthorized requests to internal or external resources.
highperson_alertThreat ActorAryStinger Malware Infects 4,300+ Routers for Recon Operations
AryStinger is a newly discovered malware family identified by QiAnXin's XLab threat research team. Unlike traditional DDoS botnets, AryStinger is purpose-built for pre-attack reconnaissance and distributed proxy operations.
highbug_reportVulnerabilityAryStinger botnet compromises 4,000+ legacy D-Link routers as proxies
Over 4,000 outdated D-Link routers worldwide, specifically legacy models no longer receiving security updates. Exact models not specified in available data.
highbug_reportVulnerabilityThree high-severity XSS flaws in VMware Telco Cloud and Aria Operations
VMware Telco Cloud/vSphere Foundation and VMware Aria Operations. Specific affected versions not provided in advisory; consult VMware security bulletin for version details.
criticalbug_reportVulnerabilityCheck Point VPN auth bypass under active exploit via IKEv1 flaw
Check Point Remote Access VPN and Mobile Access deployments using deprecated IKEv1 protocol. Specific product versions not disclosed. Does not affect IKEv2 configurations.
highbug_reportVulnerabilityGafgyt C0XMO botnet exploits DD-WRT router flaw, kills rival malware
DD-WRT router firmware (specific versions not disclosed). Affects devices across multiple CPU architectures. No CVE assigned yet.
highbug_reportVulnerabilityCisco Unified Communications Manager high severity flaw with public PoC
Cisco Unified Communications Manager (CUCM). Specific affected versions not disclosed in alert. CVE identifier not yet assigned or published.
highbug_reportVulnerabilityDutch authorities dismantle botnet controlling 17M infected devices
At least 17 million infected devices globally including computers, tablets, smartphones, and IoT devices. Over 200 command-and-control servers located in the Netherlands were seized.
highperson_alertThreat ActorShinyHunters Breaches Charter Communications, Exfiltrates 4.9M Records
ShinyHunters is a financially motivated cybercrime group known for large-scale data breaches and extortion operations targeting enterprises. The group specializes in exfiltrating sensitive customer data from corporate databases and either selling the…
highperson_alertThreat ActorShinyHunters Extorts Charter Communications After Data Breach
ShinyHunters is a financially motivated cybercrime group known for large-scale data breaches and extortion operations targeting organizations across multiple sectors.
highperson_alertThreat ActorShowboat Linux Malware Targets Middle East Telecom Since Mid-2022
The threat actor behind Showboat remains unattributed. The campaign demonstrates sophisticated targeting of telecommunications infrastructure in the Middle East, suggesting a motivated adversary with strategic intelligence collection objectives.
highperson_alertThreat ActorChinese APT Deploys Showboat and JFMBackdoor Against Telecom Sector
Chinese state-sponsored threat actors conducting cyber-espionage operations against telecommunications infrastructure. The actors demonstrate cross-platform capabilities with custom Linux and Windows malware tooling.
criticalbug_reportVulnerabilityCisco Catalyst SD-WAN auth bypass grants admin access to attackers
Cisco Catalyst SD-WAN platform. Specific affected versions not disclosed. Vulnerability allows authentication bypass leading to administrative access on SD-WAN infrastructure components.
highbug_reportVulnerabilityMikroTik RouterOS auth bypass via certificate validation flaw
MikroTik RouterOS - versions not specified. Affects OpenVPN, CAPsMAN (wireless management), and 802.1X (Dot1x) services that rely on certificate-based authentication.