Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-21 · 02:09 UTC
articleTotal: 606 reports

Filtered Reports

15 / 44 results
Active filter:vendor: google✕ clear
Sandbox escape flaws in Cursor, Codex, Gemini CLI, Antigravity AI toolshighbug_reportVulnerability
bug_reportVulnerability

Sandbox escape flaws in Cursor, Codex, Gemini CLI, Antigravity AI tools

Multiple AI development tools: Cursor IDE, OpenAI Codex, Google Gemini CLI, and Antigravity. Vulnerability affects AI agent sandbox implementations where agents write files executed by host tools, enabling sandbox escape.

Cursor19:14 UTC
Google Dialogflow CX flaw lets attackers hijack agents in same GCP projectcriticalbug_reportVulnerability
bug_reportVulnerability

Google Dialogflow CX flaw lets attackers hijack agents in same GCP project

Google Dialogflow CX agents with Code Block feature enabled, within shared Google Cloud projects. Requires attacker to have edit rights on at least one agent in the project.

Google14:37 UTC
Phishing campaign targets marketing professionals via fake job interviewshighbug_reportVulnerability
bug_reportVulnerability

Phishing campaign targets marketing professionals via fake job interviews

Marketing professionals with Google accounts; campaign impersonates 30+ brands including Adobe, Netflix, Coca-Cola, OpenAI. Credential theft targeting Google accounts specifically.

Adobe18:27 UTC
NetNut Residential Proxy Network Disrupted After Compromising 2M Deviceshighperson_alertThreat Actor
person_alertThreat Actor

NetNut Residential Proxy Network Disrupted After Compromising 2M Devices

NetNut operated a residential proxy network that leveraged approximately 2 million compromised Android devices to provide unauthorized proxy services. The actor monetized access to infected devices including smart TVs and streaming boxes, selling res…

Google15:50 UTC
NetNut (Popa) Residential Proxy Botnet Disrupted by Google, FBIhighperson_alertThreat Actor
person_alertThreat Actor

NetNut (Popa) Residential Proxy Botnet Disrupted by Google, FBI

NetNut, also tracked as Popa, operates a residential proxy network built on approximately 2 million compromised home devices. The actor monetizes this infrastructure by selling proxy services that route malicious traffic through legitimate residentia…

Google16:54 UTC
ToddyCat Deploys Umbrij Malware to Hijack Gmail via OAuth Abusehighperson_alertThreat Actor
person_alertThreat Actor

ToddyCat Deploys Umbrij Malware to Hijack Gmail via OAuth Abuse

ToddyCat (G1022) is an advanced persistent threat group that has demonstrated sophisticated capabilities in targeting corporate and enterprise environments.

Google11:04 UTC
Fake Perplexity AI Chrome extension hijacks search traffic on Web Storehighbug_reportVulnerability
bug_reportVulnerability

Fake Perplexity AI Chrome extension hijacks search traffic on Web Store

Google Chrome users who installed the malicious Perplexity AI impersonator extension from the Chrome Web Store. Affects organizations and individuals using Chrome browser seeking AI productivity tools.

Google13:46 UTC
Silent Swap Campaign Targets Cryptocurrency via Malicious Browser Extensionshighperson_alertThreat Actor
person_alertThreat Actor

Silent Swap Campaign Targets Cryptocurrency via Malicious Browser Extensions

Silent Swap is an active cybercrime campaign leveraging malicious browser extensions to conduct cryptocurrency theft. The operation distributes unsigned installers written in both .NET and Golang variants, masquerading as a legitimate Google Notes br…

Google13:40 UTC
AirDrop and Quick Share flaws enable wireless DoS and security bypasshighbug_reportVulnerability
bug_reportVulnerability

AirDrop and Quick Share flaws enable wireless DoS and security bypass

Apple AirDrop and Google Quick Share wireless file transfer features on iOS, macOS, and Android devices. Specific affected versions not disclosed. Attack requires physical proximity (wireless range).

Apple07:27 UTC
Malicious Chrome Extension Impersonates Perplexity AI to Intercept Searcheshighperson_alertThreat Actor
person_alertThreat Actor

Malicious Chrome Extension Impersonates Perplexity AI to Intercept Searches

The threat actor behind this campaign remains unattributed. The operation demonstrates a financially or espionage-motivated adversary leveraging social engineering through brand impersonation of Perplexity AI, a popular search technology.

Google16:40 UTC
Adblock for YouTube extension with 10M+ installs contains code injection riskhighbug_reportVulnerability
bug_reportVulnerability

Adblock for YouTube extension with 10M+ installs contains code injection risk

Chrome extension "Adblock for YouTube" (10+ million active installations). All users with the extension installed are potentially affected. Extension currently holds Featured badge status in Chrome Web Store.

Google12:12 UTC
CI/CD flaw "Cordyceps" exposes 300+ GitHub repos to supply-chain takeovercriticalbug_reportVulnerability
bug_reportVulnerability

CI/CD flaw "Cordyceps" exposes 300+ GitHub repos to supply-chain takeover

300+ GitHub repositories across major organizations including Microsoft, Google, and Apache. Vulnerability affects GitHub Actions CI/CD workflows. Specific products and versions not disclosed in available data.

Microsoft10:48 UTC
Russian-speaking actor deploys OXLOADER to distribute CastleStealerhighperson_alertThreat Actor
person_alertThreat Actor

Russian-speaking actor deploys OXLOADER to distribute CastleStealer

The threat actor is a Russian-speaking, financially motivated cybercrime operator leveraging malicious advertising infrastructure for initial access. The actor demonstrates capability in developing or acquiring custom malware tooling, including the p…

Google11:20 UTC
Google Cloud Vertex AI SDK flaw enables ML model hijacking via pickle attackhighbug_reportVulnerability
bug_reportVulnerability

Google Cloud Vertex AI SDK flaw enables ML model hijacking via pickle attack

Google Cloud Vertex AI SDK for Python. Specific affected versions not disclosed. Impacts organizations using the SDK to upload and deploy machine learning models to Google Cloud's serving infrastructure.

Google17:05 UTC
Vertex AI Python SDK vulnerable to RCE via bucket squatting attackshighbug_reportVulnerability
bug_reportVulnerability

Vertex AI Python SDK vulnerable to RCE via bucket squatting attacks

Google Vertex AI Python SDK. Affects users uploading models to Vertex AI. Vulnerability exploits bucket squatting during model upload process combined with pickle deserialization to achieve cross-tenant remote code execution.

Google08:00 UTC