Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-21 · 02:09 UTC
articleTotal: 606 reports

Filtered Reports

9 / 9 results
Active filter:tag: #web-services✕ clear
Critical NGINX heap overflow enables RCE via crafted HTTP requestscriticalbug_reportVulnerability
bug_reportVulnerability

Critical NGINX heap overflow enables RCE via crafted HTTP requests

NGINX open source versions prior to 1.30.4 and 1.31.3, and NGINX Plus versions prior to 37.0.3.1. All deployments accepting HTTP requests from untrusted networks are at risk.

CVE-2026-4253318:42 UTC
29-year-old Squid heap over-read leaks HTTP credentials in default confighighbug_reportVulnerability
bug_reportVulnerability

29-year-old Squid heap over-read leaks HTTP credentials in default config

Squid web proxy, all versions containing FTP parsing code from 1997 onward. Vulnerability present in default configuration. Affects organizations using Squid as forward or reverse proxy.

Squid12:29 UTC
NGINX Open Source RCE via HTTP/3 use-after-free (CVE-2026-42530)criticalbug_reportVulnerability
bug_reportVulnerability

NGINX Open Source RCE via HTTP/3 use-after-free (CVE-2026-42530)

NGINX Open Source versions with ngx_http_v3_module enabled. Specific vulnerable versions not provided in summary. F5 NGINX products potentially affected.

CVE-2026-4253015:32 UTC
Supply chain attack hits PushEngage, OptinMonster, TrustPulse pluginscriticalbug_reportVulnerability
bug_reportVulnerability

Supply chain attack hits PushEngage, OptinMonster, TrustPulse plugins

WordPress sites using PushEngage, OptinMonster, and TrustPulse plugins. All versions loading compromised JavaScript files from vendor infrastructure are affected.

PushEngage07:59 UTC
Malware campaign infects 2,000 WordPress sites using Steam profiles for C2highbug_reportVulnerability
bug_reportVulnerability

Malware campaign infects 2,000 WordPress sites using Steam profiles for C2

Nearly 2,000 WordPress websites compromised. All WordPress versions potentially affected depending on initial infection vector (likely vulnerable plugins, themes, or weak credentials).

WordPress15:04 UTC
WP Maps Pro plugin under active attack via admin account creation flawhighbug_reportVulnerability
bug_reportVulnerability

WP Maps Pro plugin under active attack via admin account creation flaw

WP Maps Pro WordPress plugin (version details not specified). Affects WordPress sites with the plugin installed. Vulnerability allows unauthenticated attackers to create administrator accounts.

WP Maps Pro12:06 UTC
Starlette and FastAPI authentication bypass flaw affects millions of serverscriticalbug_reportVulnerability
bug_reportVulnerability

Starlette and FastAPI authentication bypass flaw affects millions of servers

Starlette web framework and dependent frameworks including FastAPI. Specific vulnerable versions not provided in source data. Affects authentication mechanisms in applications built with these frameworks.

Starlette12:32 UTC
Ghost CMS SQL injection (CVE-2026-26980) exploited in ClickFix campaigncriticalbug_reportVulnerability
bug_reportVulnerability

Ghost CMS SQL injection (CVE-2026-26980) exploited in ClickFix campaign

Ghost CMS Content API, all versions prior to patch. Over 700 sites confirmed compromised. Unauthenticated attackers can exploit the SQL injection vulnerability remotely.

CVE-2026-2698010:02 UTC
ClickFix Campaign Exploits Ghost CMS SQLi to Inject Malicious JavaScriptcriticalperson_alertThreat Actor
person_alertThreat Actor

ClickFix Campaign Exploits Ghost CMS SQLi to Inject Malicious JavaScript

The threat actor behind this campaign remains unattributed. Motivation appears to be financially driven, leveraging ClickFix social engineering tactics to deliver malware or steal credentials.

CVE-2026-2698012:12 UTC