Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-20 · 02:03 UTC
articleTotal: 593 reports

Filtered Reports

13 / 13 results
Active filter:tag: #unknown✕ clear
Vishing Campaign Targets Microsoft 365 Users with Entra Passkey Scamhighperson_alertThreat Actor
person_alertThreat Actor

Vishing Campaign Targets Microsoft 365 Users with Entra Passkey Scam

The threat actor behind this campaign remains unattributed. The operation demonstrates sophistication in social engineering tactics, specifically targeting Microsoft 365 environments through voice-based phishing (vishing).

Microsoft14:47 UTC
Massive SEO-Poisoned Campaign Distributes AsyncRAT via ScreenConnecthighperson_alertThreat Actor
person_alertThreat Actor

Massive SEO-Poisoned Campaign Distributes AsyncRAT via ScreenConnect

The threat actor behind this campaign remains unattributed. Motivation appears to be financially driven, consistent with commodity RAT deployment for access brokering, credential theft, or follow-on ransomware operations.

OBS Studio15:53 UTC
Pre-Planned Fraud Campaign Targets FIFA World Cup 2026 Across Sectorshighperson_alertThreat Actor
person_alertThreat Actor

Pre-Planned Fraud Campaign Targets FIFA World Cup 2026 Across Sectors

The threat actor behind this campaign remains unattributed. Motivation appears financially driven, leveraging the global interest in FIFA World Cup 2026 to conduct fraud operations.

The Hacker News09:30 UTC
SimpleHelp OpenID auth bypass (CVE-2026-48558) exploited in wildcriticalbug_reportVulnerability
bug_reportVulnerability

SimpleHelp OpenID auth bypass (CVE-2026-48558) exploited in wild

SimpleHelp remote support software, all versions using OpenID Connect authentication. CVE-2026-48558 is a critical authentication bypass (CVSS 10.0) in the OpenID Connect flow.

CVE-2026-4855809:18 UTC
Malicious Chrome Extension Impersonates Perplexity AI to Intercept Searcheshighperson_alertThreat Actor
person_alertThreat Actor

Malicious Chrome Extension Impersonates Perplexity AI to Intercept Searches

The threat actor behind this campaign remains unattributed. The operation demonstrates a financially or espionage-motivated adversary leveraging social engineering through brand impersonation of Perplexity AI, a popular search technology.

Google16:40 UTC
Cisco Catalyst SD-WAN zero-day exploited in wild for two monthshighbug_reportVulnerability
bug_reportVulnerability

Cisco Catalyst SD-WAN zero-day exploited in wild for two months

Cisco Catalyst SD-WAN Manager. Specific affected versions not disclosed. Requires authenticated local access for exploitation.

CVE-2026-2024503:46 UTC
WhatsApp VBScript Campaign Deploys ManageEngine RMM Across 9 Countrieshighperson_alertThreat Actor
person_alertThreat Actor

WhatsApp VBScript Campaign Deploys ManageEngine RMM Across 9 Countries

This campaign represents an unattributed threat activity leveraging WhatsApp as an initial access vector. The actor's motivation appears to be establishing persistent remote access to victim systems through legitimate remote monitoring and management…

WhatsApp03:38 UTC
ShapedPlugin WordPress Pro plugins backdoored via compromised update channelhighbug_reportVulnerability
bug_reportVulnerability

ShapedPlugin WordPress Pro plugins backdoored via compromised update channel

Multiple ShapedPlugin Pro WordPress plugins distributed through official licensed update channels. Exact plugin names and affected versions not specified.

ShapedPlugin16:00 UTC
Fortinet FortiSandbox under active exploit for 3 CVEs including critical 9.1criticalbug_reportVulnerability
bug_reportVulnerability

Fortinet FortiSandbox under active exploit for 3 CVEs including critical 9.1

Fortinet FortiSandbox - specific affected versions not disclosed. Three CVEs: CVE-2026-39813 (CVSS 9.1 critical), CVE-2026-39808, CVE-2026-25089. At least one vulnerability recently patched; patch status of others unclear.

CVE-2026-2508908:30 UTC
Palo Alto PAN-OS GlobalProtect auth bypass under active exploitationhighbug_reportVulnerability
bug_reportVulnerability

Palo Alto PAN-OS GlobalProtect auth bypass under active exploitation

Palo Alto Networks PAN-OS GlobalProtect VPN portal and gateway components. Specific affected versions not disclosed in provided data. CVE-2026-0257, CVSS 7.8 (High).

CVE-2026-025704:17 UTC
ServiceNow patches actively exploited auth bypass on hosted instanceshighbug_reportVulnerability
bug_reportVulnerability

ServiceNow patches actively exploited auth bypass on hosted instances

ServiceNow hosted customer instances (specific versions not disclosed). On-premise deployments may also be affected pending vendor guidance.

ServiceNow05:02 UTC
CVE-2026-39987 in Marimo actively exploited for cloud credential thefthighbug_reportVulnerability
bug_reportVulnerability

CVE-2026-39987 in Marimo actively exploited for cloud credential theft

Marimo notebook platform (specific versions not disclosed). Affects internet-exposed Marimo notebook instances vulnerable to CVE-2026-39987.

CVE-2026-3998712:39 UTC
Fortinet FortiCloud SSO bypass exploited to extract LDAP passwordshighbug_reportVulnerability
bug_reportVulnerability

Fortinet FortiCloud SSO bypass exploited to extract LDAP passwords

Fortinet FortiGate appliances with FortiCloud SSO enabled. CVE-2025-59718 and CVE-2025-59719 allow authentication bypass. All FortiGate instances share a default static encryption key that enables decryption of LDAP credentials and private keys from…

CVE-2025-5971815:16 UTC