Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 38 results
criticalbug_reportVulnerabilityWindows zero-day LegacyHive enables privilege escalation on patched systems
All up-to-date Windows systems. Specific affected versions not disclosed. Exploit enables local privilege escalation from standard user to administrator level. No CVE assigned yet.
highperson_alertThreat ActorArmenia Detains Russian National on U.S. REvil Ransomware Warrant
REvil (also known as Sodinokibi) is a Russia-linked ransomware-as-a-service (RaaS) operation that emerged in 2019 and became one of the most prolific cybercrime groups before law enforcement disruption in 2021-2022.
criticalbug_reportVulnerabilitySiemens ROX II OT switches vulnerable to chained zero-day privilege escalation
Siemens ROX II industrial switches used in operational technology (OT) environments. Specific affected firmware versions not disclosed in summary. Vulnerability chain enables privilege escalation to persistent root access.
highperson_alertThreat ActorShinyHunters Exploits Oracle PeopleSoft Zero-Day in Nissan Breach
ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has established a pattern of exploiting vulnerabilities in enterprise applications to exfiltrate sensitive data, which is th…
highperson_alertThreat ActorShinyHunters Exploits Oracle PeopleSoft Zero-Day at NAIC
ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has historically targeted organizations to exfiltrate sensitive data, which is then leveraged for extortion or sold on under…
highperson_alertThreat ActorU.S. offers $10M reward for intel on UNC5792 and UNC4221 APT groups
UNC5792 and UNC4221 are threat actor groups attributed to Russian intelligence and military services. Both groups have been designated as high-priority targets by the U.S.
highbug_reportVulnerabilityCisco Catalyst SD-WAN zero-day exploited in wild for two months
Cisco Catalyst SD-WAN Manager. Specific affected versions not disclosed. Requires authenticated local access for exploitation.
criticalbug_reportVulnerabilityCisco Catalyst SD-WAN zero-day exploited for root access (CVE-2026-20245)
Cisco Catalyst SD-WAN devices. Specific affected versions not disclosed in available information. Attackers gain root-level access and can create persistent rogue accounts.
highperson_alertThreat ActorRussian-speaking actors compromise 86,644 FortiGate devices via FortiBleed
Russian-speaking threat actors are conducting the FortiBleed campaign, targeting internet-accessible FortiGate appliances at scale. The actors' specific motivation remains unclear from available data, though the mass compromise of 86,644 devices sugg…
highbug_reportVulnerabilityNCSC warns of active global campaign targeting Fortinet firewalls and VPNs
Fortinet firewalls and VPN gateways globally. Specific product lines and versions not disclosed in alert. Organizations using FortiGate, FortiOS, or FortiClient VPN services should assume potential exposure.
highbug_reportVulnerabilityMicrosoft Defender zero-day CVE-2026-50656 enables privilege escalation
Microsoft Defender Malware Protection Engine across all Windows versions. Specific affected engine versions not disclosed. Impacts enterprise and consumer deployments relying on Microsoft Defender for endpoint protection.
highbug_reportVulnerabilityMicrosoft Defender zero-day "RoguePlanet" awaits patch after disclosure
Microsoft Defender (all versions currently deployed). Specific affected versions not disclosed. Impacts organizations relying on Defender for endpoint protection.
criticalbug_reportVulnerabilityCisco Catalyst SD-WAN Manager root privilege escalation under attack
Cisco Catalyst SD-WAN Manager (specific versions not provided). Vulnerability allows privilege escalation to root level on affected systems.
highperson_alertThreat ActorShinyHunters Breaches 137K+ School Staff via Salesforce Attack
ShinyHunters is a financially motivated cybercrime actor specializing in large-scale data theft and extortion operations. The group has established a reputation for targeting cloud-based platforms and third-party service providers to compromise downs…
criticalbug_reportVulnerabilityOracle PeopleSoft zero-day CVE-2026-35273 exploited by ShinyHunters
Oracle PeopleSoft (all versions prior to June 10 patch). Confirmed exploitation targeting enterprise systems and universities. Vulnerability was unpatched during active exploitation window (May 27 - June 9).
criticalbug_reportVulnerabilityOracle PeopleSoft zero-day CVE-2026-35273 exploited for RCE by ShinyHunter
Oracle PeopleSoft Suite, all versions (specific affected versions not disclosed). Unauthenticated remote code execution vulnerability affecting internet-facing PeopleSoft instances.
highbug_reportVulnerabilityMicrosoft patches actively exploited XSS zero-day in Exchange Server OWA
Microsoft Exchange Server (all versions with Outlook Web Access enabled). Specific patched versions not provided. Affects organizations exposing OWA to users.
criticalbug_reportVulnerabilityMicrosoft patches 3 zero-days: YellowKey, GreenPlasma, MiniPlasma
All fully patched Windows systems prior to latest patch release. YellowKey and GreenPlasma enable SYSTEM privilege escalation; MiniPlasma bypasses BitLocker encryption on protected drives.
criticalbug_reportVulnerabilityMicrosoft patches 206 vulnerabilities including 3 zero-days, 39 critical
Microsoft software portfolio: 206 vulnerabilities patched including 56 remote code execution (RCE) flaws, 63 privilege escalation issues, 39 critical-severity vulnerabilities, and 3 actively exploited zero-day flaws.
highbug_reportVulnerabilityServiceNow patches actively exploited auth bypass on hosted instances
ServiceNow hosted customer instances (specific versions not disclosed). On-premise deployments may also be affected pending vendor guidance.
criticalbug_reportVulnerabilityMicrosoft Defender zero-day "RoguePlanet" exploited for SYSTEM access
Microsoft Defender on all updated Windows systems. No CVE assigned yet. Vulnerability is a race condition enabling local privilege escalation to SYSTEM.
criticalbug_reportVulnerabilityMicrosoft Defender zero-day 'RoguePlanet' enables SYSTEM privilege escalation
Microsoft Defender on Windows systems. Specific affected versions not disclosed. Given Defender's deployment, scope includes enterprise endpoints, servers running Defender, and consumer Windows installations with default security configuration.
highbug_reportVulnerabilityMicrosoft June 2026 Patch Tuesday: 200 flaws, 3 disclosed zero-days
Microsoft products across the ecosystem. 200 vulnerabilities patched, including 3 publicly disclosed zero-day vulnerabilities. Specific affected products and CVE identifiers not yet detailed in available information.
highbug_reportVulnerabilityWinRAR CVE-2025-8088 path traversal exploited by Russian APTs vs Ukraine
WinRAR versions prior to patched release (approximately one year old). Primary targets: Ukrainian organizations. Threat actors: Earth Dahu (Gamaredon) and SHADOW-EARTH-066 (UAC-0226), Russia-aligned APT groups.
criticalbug_reportVulnerabilityChrome V8 zero-day CVE-2026-11645 exploited in wild, patch immediately
Google Chrome versions prior to 149.0.7827.103 on all platforms. The vulnerability resides in the V8 JavaScript engine, affecting out-of-bounds memory access.
highperson_alertThreat ActorMeta blocks NSO Group spear-phishing targeting WhatsApp users
NSO Group is an Israeli commercial surveillance vendor that develops and sells offensive cyber capabilities, primarily the Pegasus spyware platform, to government clients.
criticalbug_reportVulnerabilityGogs patches critical RCE zero-day affecting Internet-facing instances
Gogs Git service, Internet-facing instances (specific vulnerable versions not disclosed). All repositories including private repos accessible post-exploitation.
criticalbug_reportVulnerabilityCheck Point patches zero-day in VPN/Mobile Access exploited by Qilin
Check Point Remote Access VPN and Mobile Access deployments. Specific product versions not disclosed in summary; refer to vendor advisory for affected releases and patched versions.
highbug_reportVulnerabilityAI finds 21 zero-days in FFmpeg; Chrome 149 patches 429 bugs
FFmpeg media library (all versions prior to upcoming patch release); Google Chrome versions prior to 149 (all platforms). FFmpeg is embedded in countless applications, browsers, media players, and server-side processing pipelines.
criticalbug_reportVulnerabilityCisco SD-WAN Manager zero-day CVE-2026-20245 exploited for root access
Cisco Catalyst SD-WAN Manager, all versions (specific affected versions not disclosed). Unpatched zero-day vulnerability enabling root privilege escalation.