Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-05 · 02:16 UTC
articleTotal: 1184 reports

Filtered Reports

21 / 21 results
Active filter:tag: #web-services✕ clear
All-in-One WP Migration plugin SQL injection enables site takeovercriticalbug_reportVulnerability
bug_reportVulnerability

All-in-One WP Migration plugin SQL injection enables site takeover

All-in-One WP Migration and Backup plugin for WordPress, versions through 7.109. Over 5 million active installations, with approximately 3.25 million sites (65%) still running vulnerable versions. Fixed in version 7.110.

All-in-One WP Migration and Backup2 Sep · 17:28 UTC
Attackers abuse npm mirrors as free hosting for Cloudflare phishing pageshighbug_reportVulnerability
bug_reportVulnerability

Attackers abuse npm mirrors as free hosting for Cloudflare phishing pages

npm registry and public mirrors (UNPKG, npmmirror). Organizations using these mirrors to serve package content. At least 24 malicious packages identified hosting fake Cloudflare CAPTCHA pages.

npm25 Aug · 19:39 UTC
24 npm packages abuse unpkg mirrors as phishing infrastructurehighbug_reportVulnerability
bug_reportVulnerability

24 npm packages abuse unpkg mirrors as phishing infrastructure

24 malicious npm packages (e.g., bgzxcuite2, prezdentkxheiw, egair0810) hosted on npm registry and mirrored on unpkg.com and similar CDN services. Affects users who click links to these mirrored HTML pages, not developers installing packages directly…

npm25 Aug · 09:52 UTC
Xecurify miniOrange SAML plugin flaws exploited for WordPress admin accesshighbug_reportVulnerability
bug_reportVulnerability

Xecurify miniOrange SAML plugin flaws exploited for WordPress admin access

Xecurify miniOrange SAML 2.0 Single Sign On WordPress plugin, Standard edition versions prior to 17.0.6. CVE-2026-61979 (CVSS 8.1) fixed in 17.0.5; CVE-2026-15981 (CVSS 9.8) fixed in 17.0.6.

CVE-2026-6197925 Aug · 06:34 UTC
miniOrange SAML SSO plugin flaws actively exploited for WordPress admin accesscriticalbug_reportVulnerability
bug_reportVulnerability

miniOrange SAML SSO plugin flaws actively exploited for WordPress admin access

miniOrange SAML 2.0 Single Sign On plugin for WordPress. Vulnerable versions: Free <5.4.5, Premium single-site <13.0.4, Standard single-site <17.06, Premium/Enterprise/All-Inclusive multisite <20.2.8, Enterprise/All-Inclusive single-site <26.0.3, VIP…

miniOrange24 Aug · 17:26 UTC
Critical sandbox escape in isolated-vm ≤7.0.0 enables RCE on hostcriticalbug_reportVulnerability
bug_reportVulnerability

Critical sandbox escape in isolated-vm ≤7.0.0 enables RCE on host

isolated-vm library versions ≤7.0.0. Patched in versions 6.2.0 and 7.0.1. Affects Node.js environments using isolated-vm for sandboxing untrusted JavaScript. Package has ~1 million weekly npm downloads.

isolated-vm20 Aug · 11:48 UTC
Spectre attack on Cloudflare Workers leaks JWT at 12 bits/sechighbug_reportVulnerability
bug_reportVulnerability

Spectre attack on Cloudflare Workers leaks JWT at 12 bits/sec

Cloudflare Workers running on AMD EPYC Zen 2 and Zen 3 processors (Linux). Attack targets V8 isolates within shared Worker processes. Affects multi-tenant serverless environments relying on language-level isolation.

Cloudflare19 Aug · 17:02 UTC
Apache Traffic Server vulnerabilities require immediate patchinghighbug_reportVulnerability
bug_reportVulnerability

Apache Traffic Server vulnerabilities require immediate patching

Apache Traffic Server - specific versions not disclosed in available advisory. All users running Apache Traffic Server should verify their version against Apache security bulletins.

Apache29 Jul · 11:59 UTC
NodeBB forum software patches 8 high-severity flaws with public exploitshighbug_reportVulnerability
bug_reportVulnerability

NodeBB forum software patches 8 high-severity flaws with public exploits

NodeBB forum software, all versions before 4.14.0. Fixes available in version 4.14.2 and later. Five of eight flaws affect only forums with ActivityPub federation enabled (default in v4 fresh installs, disabled in v3 upgrades).

NodeBB24 Jul · 05:41 UTC
Adobe Acrobat Chrome extension flaw exposed WhatsApp Web chatshighbug_reportVulnerability
bug_reportVulnerability

Adobe Acrobat Chrome extension flaw exposed WhatsApp Web chats

Adobe Acrobat extension for Chrome versions 26.5.2.1 and below. Affects approximately 329 million browser installations. Exploitation requires victim to visit attacker-controlled webpage while extension is installed and WhatsApp Web is in use.

Adobe22 Jul · 11:22 UTC
WordPress Core wp2shell flaws actively exploited for webshell deploymentcriticalbug_reportVulnerability
bug_reportVulnerability

WordPress Core wp2shell flaws actively exploited for webshell deployment

WordPress Core (specific versions not disclosed). Both CVE-2026-63030 and CVE-2026-60137 affect core WordPress installations, enabling remote attackers to deploy webshells and malicious plugins.

CVE-2026-6013721 Jul · 14:41 UTC
WordPress wp2shell flaws enable unauthenticated RCE, active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

WordPress wp2shell flaws enable unauthenticated RCE, active exploitation

WordPress core (specific versions not disclosed). CVE-2026-63030 and CVE-2026-60137 must be chained for unauthenticated remote code execution. All unpatched WordPress installations are potentially vulnerable.

CVE-2026-6013721 Jul · 06:59 UTC
Critical NGINX heap overflow enables RCE via crafted HTTP requestscriticalbug_reportVulnerability
bug_reportVulnerability

Critical NGINX heap overflow enables RCE via crafted HTTP requests

NGINX open source versions prior to 1.30.4 and 1.31.3, and NGINX Plus versions prior to 37.0.3.1. All deployments accepting HTTP requests from untrusted networks are at risk.

CVE-2026-4253319 Jul · 18:42 UTC
29-year-old Squid heap over-read leaks HTTP credentials in default confighighbug_reportVulnerability
bug_reportVulnerability

29-year-old Squid heap over-read leaks HTTP credentials in default config

Squid web proxy, all versions containing FTP parsing code from 1997 onward. Vulnerability present in default configuration. Affects organizations using Squid as forward or reverse proxy.

Squid22 Jun · 12:29 UTC
NGINX Open Source RCE via HTTP/3 use-after-free (CVE-2026-42530)criticalbug_reportVulnerability
bug_reportVulnerability

NGINX Open Source RCE via HTTP/3 use-after-free (CVE-2026-42530)

NGINX Open Source versions with ngx_http_v3_module enabled. Specific vulnerable versions not provided in summary. F5 NGINX products potentially affected.

CVE-2026-4253018 Jun · 15:32 UTC
Supply chain attack hits PushEngage, OptinMonster, TrustPulse pluginscriticalbug_reportVulnerability
bug_reportVulnerability

Supply chain attack hits PushEngage, OptinMonster, TrustPulse plugins

WordPress sites using PushEngage, OptinMonster, and TrustPulse plugins. All versions loading compromised JavaScript files from vendor infrastructure are affected.

PushEngage15 Jun · 07:59 UTC
Malware campaign infects 2,000 WordPress sites using Steam profiles for C2highbug_reportVulnerability
bug_reportVulnerability

Malware campaign infects 2,000 WordPress sites using Steam profiles for C2

Nearly 2,000 WordPress websites compromised. All WordPress versions potentially affected depending on initial infection vector (likely vulnerable plugins, themes, or weak credentials).

WordPress1 Jun · 15:04 UTC
WP Maps Pro plugin under active attack via admin account creation flawhighbug_reportVulnerability
bug_reportVulnerability

WP Maps Pro plugin under active attack via admin account creation flaw

WP Maps Pro WordPress plugin (version details not specified). Affects WordPress sites with the plugin installed. Vulnerability allows unauthenticated attackers to create administrator accounts.

WP Maps Pro31 May · 12:06 UTC
Starlette and FastAPI authentication bypass flaw affects millions of serverscriticalbug_reportVulnerability
bug_reportVulnerability

Starlette and FastAPI authentication bypass flaw affects millions of servers

Starlette web framework and dependent frameworks including FastAPI. Specific vulnerable versions not provided in source data. Affects authentication mechanisms in applications built with these frameworks.

Starlette28 May · 12:32 UTC
Ghost CMS SQL injection (CVE-2026-26980) exploited in ClickFix campaigncriticalbug_reportVulnerability
bug_reportVulnerability

Ghost CMS SQL injection (CVE-2026-26980) exploited in ClickFix campaign

Ghost CMS Content API, all versions prior to patch. Over 700 sites confirmed compromised. Unauthenticated attackers can exploit the SQL injection vulnerability remotely.

CVE-2026-2698025 May · 10:02 UTC
ClickFix Campaign Exploits Ghost CMS SQLi to Inject Malicious JavaScriptcriticalperson_alertThreat Actor
person_alertThreat Actor

ClickFix Campaign Exploits Ghost CMS SQLi to Inject Malicious JavaScript

The threat actor behind this campaign remains unattributed. Motivation appears to be financially driven, leveraging ClickFix social engineering tactics to deliver malware or steal credentials.

CVE-2026-2698024 May · 12:12 UTC