Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 702 results
Active filter:tag: #vulnerability✕ clear
Coder registry compromised via Cloudflare to deliver malicious Terraform moduleshighbug_reportVulnerability
bug_reportVulnerability

Coder registry compromised via Cloudflare to deliver malicious Terraform modules

Coder registry infrastructure (registry.coder.com) accessed via compromised Cloudflare configuration. Users who downloaded Terraform modules between 07:35 and 21:45 UTC on August 31, 2026 potentially affected.

Coder3 Sep · 18:04 UTC
HPE patches critical RCE in ArubaOS-CX network switches (CVE-2026-73749)criticalbug_reportVulnerability
bug_reportVulnerability

HPE patches critical RCE in ArubaOS-CX network switches (CVE-2026-73749)

ArubaOS-CX network operating system on HPE Aruba enterprise switches. Affected versions: 10.18.0001, 10.17.1021 and earlier, 10.16.1051 and earlier, 10.13.1180 and earlier, 10.10.1180 and earlier.

Hewlett Packard Enterprise3 Sep · 16:28 UTC
5,000 Dropbox accounts compromised; OAuth and Teams phishing campaigns activehighbug_reportVulnerability
bug_reportVulnerability

5,000 Dropbox accounts compromised; OAuth and Teams phishing campaigns active

Multiple attack vectors: 5,000+ compromised Dropbox accounts, Microsoft Teams users across 150+ employees in 10+ organizations, OAuth-based applications, and users of phishing-as-a-service kits (BlueKit, Outsider).

Dropbox3 Sep · 16:02 UTC
Cisco patches critical RCE in Nexus 9000 and 7 IOS XR umbrella CVEscriticalbug_reportVulnerability
bug_reportVulnerability

Cisco patches critical RCE in Nexus 9000 and 7 IOS XR umbrella CVEs

Cisco Silicon One-based Nexus 9000 switches (10 models, NX-OS 10.3(1) through 10.6(3s)) via CVE-2026-20212. All Cisco IOS XR releases across all platforms via 7 umbrella CVEs (CVE-2026-20274 through 20280), including XR7 (LNT) platforms: Cisco 8000 S…

CVE-2026-202123 Sep · 13:52 UTC
BraZetsu malware framework enables Initial Access Broker marketplacehighbug_reportVulnerability
bug_reportVulnerability

BraZetsu malware framework enables Initial Access Broker marketplace

Windows hosts in Iberian Peninsula and Latin America, particularly Brazil. Primary targets: e-commerce, corporate, financial, industrial, and law enforcement sectors. Browsers affected: Google Chrome, Microsoft Edge, Brave, Vivaldi, Opera.

Microsoft3 Sep · 13:26 UTC
Elementor Pro CVE-2026-32475 actively exploited for webshell uploadscriticalbug_reportVulnerability
bug_reportVulnerability

Elementor Pro CVE-2026-32475 actively exploited for webshell uploads

Elementor Pro plugin for WordPress versions 4.2.1 and earlier. Affects sites with published Elementor Pro Form widgets containing File Upload fields. Over 6 million active installations potentially at risk.

CVE-2026-324753 Sep · 12:52 UTC
RMM phishing campaign hits 46 countries, US accounts for 45% of activityhighbug_reportVulnerability
bug_reportVulnerability

RMM phishing campaign hits 46 countries, US accounts for 45% of activity

Organizations across 46 countries, primarily United States (45% of activity), Canada, and others. Top targeted sectors: education, technology, government, banking, finance, and manufacturing.

The Hacker News3 Sep · 09:58 UTC
Plex urges immediate patching of undisclosed flaws in Media Serverhighbug_reportVulnerability
bug_reportVulnerability

Plex urges immediate patching of undisclosed flaws in Media Server

Plex Media Server v1.43.2 and earlier, Plex Desktop client versions prior to 1.115.0. Affects all platforms including Windows, macOS, Linux, and NAS devices running Plex.

Plex3 Sep · 09:02 UTC
Attackers abuse legitimate Node.js runtime to evade detection in attackshighbug_reportVulnerability
bug_reportVulnerability

Attackers abuse legitimate Node.js runtime to evade detection in attacks

Organizations using Node.js in their environments, particularly government departments, technology companies, hotels, fintech, e-commerce, professional services, and retail logistics.

Node.js3 Sep · 08:43 UTC
Shai-Hulud infostealer now targets 469 credential locations in dev toolshighbug_reportVulnerability
bug_reportVulnerability

Shai-Hulud infostealer now targets 469 credential locations in dev tools

Developer workstations, CI/CD pipelines, cloud configurations, AI tool configs, package registries (npm, GitHub, Docker), and any environment storing long-lived credentials or tokens.

The Hacker News3 Sep · 08:36 UTC
AI-assisted campaigns target Latin American orgs with data exfiltrationhighbug_reportVulnerability
bug_reportVulnerability

AI-assisted campaigns target Latin American orgs with data exfiltration

Organizations in Latin America, specifically: Mexican transportation sector, federal government ministries, municipal water utilities in Mexico and Ecuador (CL-CRI-1131); Brazilian financial sector (CL-CRI-1163).

Unit 42 (Palo Alto)3 Sep · 08:00 UTC
CrowdStrike Falcon zero-day FalconFlank allows privilege escalationhighbug_reportVulnerability
bug_reportVulnerability

CrowdStrike Falcon zero-day FalconFlank allows privilege escalation

CrowdStrike Falcon Sensor on Windows 11 25H2 and Windows Server 2025 (all current versions). The vulnerability exploits the Office malicious macros remediation feature.

CrowdStrike3 Sep · 04:26 UTC
SonicWall SMA 1000 SSRF flaw (CVE-2026-83548) exploited in the wildcriticalbug_reportVulnerability
bug_reportVulnerability

SonicWall SMA 1000 SSRF flaw (CVE-2026-83548) exploited in the wild

SonicWall SMA 1000 Appliances. CVE-2026-83548 is a server-side request forgery (SSRF) vulnerability with CVSS 10.0, allowing remote unauthenticated attackers to gain unauthorized access. Specific affected versions not disclosed.

CVE-2026-835483 Sep · 03:19 UTC
Attackers abuse Microsoft Teams external chat to impersonate IT supporthighbug_reportVulnerability
bug_reportVulnerability

Attackers abuse Microsoft Teams external chat to impersonate IT support

Microsoft Teams users in enterprise environments with external collaboration enabled. All organizations using Teams for business communication are at risk if users accept external contact requests and grant remote access via RMM tools or Quick Assist…

Microsoft2 Sep · 20:51 UTC
Sangoma Switchvox SQL injection exploited for remote code executioncriticalbug_reportVulnerability
bug_reportVulnerability

Sangoma Switchvox SQL injection exploited for remote code execution

Sangoma Switchvox VoIP platform versions prior to 8.4.0.2. Approximately 4,000 internet-exposed instances globally, primarily in the United States. Vulnerability CVE-2026-9586 affects the unauthenticated /pa HTTP endpoint.

CVE-2026-95862 Sep · 19:00 UTC
All-in-One WP Migration plugin SQL injection enables site takeovercriticalbug_reportVulnerability
bug_reportVulnerability

All-in-One WP Migration plugin SQL injection enables site takeover

All-in-One WP Migration and Backup plugin for WordPress, versions through 7.109. Over 5 million active installations, with approximately 3.25 million sites (65%) still running vulnerable versions. Fixed in version 7.110.

All-in-One WP Migration and Backup2 Sep · 17:28 UTC
Silver Fox campaign uses fake installers to disable Windows Updatehighbug_reportVulnerability
bug_reportVulnerability

Silver Fox campaign uses fake installers to disable Windows Update

Windows systems globally, primarily China-based operations of multinational organizations and Chinese-speaking users across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors.

Microsoft2 Sep · 14:41 UTC
JFrog Artifactory auth bypass exploited to forge admin tokenscriticalbug_reportVulnerability
bug_reportVulnerability

JFrog Artifactory auth bypass exploited to forge admin tokens

JFrog Artifactory self-managed instances in default configuration. Patched in versions 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, and 7.161.20 (released August 28, 2026). JFrog Cloud environments already protected.

CVE-2026-823292 Sep · 13:47 UTC
SonicWall SMA1000 RCE vulnerabilities under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

SonicWall SMA1000 RCE vulnerabilities under active exploitation

SonicWall SMA1000 series appliances. Specific vulnerable versions not disclosed in available information. Vulnerabilities enable remote code execution.

SonicWall2 Sep · 13:39 UTC
Langflow RCE vulnerability under active exploitation, patch immediatelycriticalbug_reportVulnerability
bug_reportVulnerability

Langflow RCE vulnerability under active exploitation, patch immediately

Langflow (specific versions not disclosed in available data). The vulnerability affects Langflow installations exposed to network access. No CVE assigned yet.

Langflow2 Sep · 13:35 UTC
AI coding agents execute malicious Git config commands outside sandboxhighbug_reportVulnerability
bug_reportVulnerability

AI coding agents execute malicious Git config commands outside sandbox

Seven command-line AI coding agents: goose (fixed in 1.44.0), Codex CLI/Desktop (fixed in 0.131.0 / 26.519.x), Claude Code (partially fixed in 2.1.196, second path unpatched in 2.1.252+), Hermes Agent 0.18.2–0.21.0 (unpatched), Qwen Code 0.19.6–0.22.…

Anthropic2 Sep · 12:06 UTC
BGP hijack delivers malicious Virtualizor update with root backdoorcriticalbug_reportVulnerability
bug_reportVulnerability

BGP hijack delivers malicious Virtualizor update with root backdoor

Virtualizor hypervisor management software (all versions) from Softaculous. Attack window: August 28, 2026 20:57 UTC to August 30, 2026 06:10 UTC. Any installation that checked for updates during this period may be compromised.

Virtualizor2 Sep · 11:12 UTC
SonicWall SMA 1000 VPN zero-days exploited in chained attackscriticalbug_reportVulnerability
bug_reportVulnerability

SonicWall SMA 1000 VPN zero-days exploited in chained attacks

SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances: models 6210, 7210, and 8200v running versions 12.4.3-03453 and older, or 12.5.0-02835 and older.

CVE-2026-835482 Sep · 08:53 UTC
GeoNetwork RCE chain exploitable without authentication on gov geoportalscriticalbug_reportVulnerability
bug_reportVulnerability

GeoNetwork RCE chain exploitable without authentication on gov geoportals

GeoNetwork open-source geospatial metadata catalog: all 4.4.x versions up to 4.4.11 and all 4.2.x versions up to 4.2.16. Widely deployed in government, military, and national agency Spatial Data Infrastructure backends across 39 countries, including…

GeoNetwork2 Sep · 07:18 UTC
Sality P2P botnet dismantled after 20+ years of operationhighbug_reportVulnerability
bug_reportVulnerability

Sality P2P botnet dismantled after 20+ years of operation

Sality botnet infrastructure (active since 2003), affecting 15,000+ infected devices globally. Primary payload in recent years: EggJagger clipjacking malware targeting cryptocurrency wallets.

BleepingComputer2 Sep · 06:00 UTC
SonicWall SMA1000 zero-days CVE-2026-83548/83549 chained for RCEcriticalbug_reportVulnerability
bug_reportVulnerability

SonicWall SMA1000 zero-days CVE-2026-83548/83549 chained for RCE

SonicWall SMA1000 appliances (models 6210, 7210, 8200v). Does not affect SSL-VPN on SonicWall firewalls or SMA 100 Series. Approximately 400+ appliances exposed online per Shadowserver tracking.

SonicWall2 Sep · 04:39 UTC
Active malware campaign uses fake vendor sites to deliver Silver Fox malwarehighbug_reportVulnerability
bug_reportVulnerability

Active malware campaign uses fake vendor sites to deliver Silver Fox malware

Organizations with China-based operations and Chinese-speaking users across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors.

Microsoft1 Sep · 20:48 UTC
Langflow CVE-2026-0768 exploited to steal OpenAI and AWS credentialscriticalbug_reportVulnerability
bug_reportVulnerability

Langflow CVE-2026-0768 exploited to steal OpenAI and AWS credentials

Langflow versions 1.4.2 and earlier. The vulnerability exists in the code validator of the custom component editor's validate endpoint. Patched in version 1.11.6.

CVE-2026-07681 Sep · 15:54 UTC
JFrog Artifactory auth bypass CVE-2026-82329 under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

JFrog Artifactory auth bypass CVE-2026-82329 under active exploitation

JFrog Artifactory versions 7.161.0-7.161.19, 7.146.0-7.146.36, 7.133.0-7.133.28, 7.125.0-7.125.19, 7.117.0-7.117.27, and 7.111.4-7.111.21. Affects default configurations of self-managed instances. JFrog Access component specifically vulnerable.

CVE-2026-823291 Sep · 15:53 UTC
JFrog Artifactory authentication bypass requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

JFrog Artifactory authentication bypass requires immediate patching

JFrog Artifactory - specific affected versions not disclosed in advisory. Authentication bypass vulnerability allows unauthorized access to artifact repository.

JFrog1 Sep · 13:13 UTC