Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
22 / 195 results
highbug_reportVulnerabilityBraZetsu malware framework enables Initial Access Broker marketplace
Windows hosts in Iberian Peninsula and Latin America, particularly Brazil. Primary targets: e-commerce, corporate, financial, industrial, and law enforcement sectors. Browsers affected: Google Chrome, Microsoft Edge, Brave, Vivaldi, Opera.
highbug_reportVulnerabilityAttackers abuse Microsoft Teams external chat to impersonate IT support
Microsoft Teams users in enterprise environments with external collaboration enabled. All organizations using Teams for business communication are at risk if users accept external contact requests and grant remote access via RMM tools or Quick Assist…
highbug_reportVulnerabilitySilver Fox campaign uses fake installers to disable Windows Update
Windows systems globally, primarily China-based operations of multinational organizations and Chinese-speaking users across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors.
highbug_reportVulnerabilityActive malware campaign uses fake vendor sites to deliver Silver Fox malware
Organizations with China-based operations and Chinese-speaking users across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors.
highbug_reportVulnerability22K Exchange servers unpatched for CVE-2026-62911 auth bypass flaw
Microsoft Exchange Server 2016, 2019, and Subscription Edition (SE). Approximately 21,899 internet-exposed servers remain unpatched globally, with highest concentrations in the United States (6,200) and Germany (5,100).
highperson_alertThreat ActorClickFix Operators Dominate Initial Access via Social Engineering
ClickFix operators are threat actors leveraging a social engineering technique that manipulates users into executing malicious commands through clipboard manipulation.
highbug_reportVulnerabilityTerminalFix campaign uses fake CAPTCHAs to deploy reverse tunnels
Windows systems with PowerShell and Windows Terminal enabled. Targets organizations with Active Directory environments. Attack vector: compromised websites displaying fake Cloudflare CAPTCHA prompts.
highperson_alertThreat ActorSpring Ring Campaign Weaponizes Microsoft Teams for Vishing Attacks
Spring Ring is a coordinated social engineering campaign identified between January and April 2026 that leverages external Microsoft Teams accounts to impersonate IT help desk personnel.
highbug_reportVulnerability19 malicious Chrome/Edge extensions steal crypto and credentials
Google Chrome and Microsoft Edge users who installed any of 19 malicious extensions, including "Enable Right Click & Copy" (70,000+ Chrome users, 10,000+ Edge users). Campaign active since early 2024.
highbug_reportVulnerabilityTerminalFix campaign uses fake CAPTCHAs to deploy reverse-tunnel backdoor
Organizations across multiple sectors using Windows environments with PowerShell and Windows Terminal. Attack leverages compromised websites serving fake Cloudflare CAPTCHA pages to social engineer users into executing malicious PowerShell commands.
highperson_alertThreat ActorTerminalFix Campaign Deploys Multi-Stage Attacks via Fake CAPTCHAs
TerminalFix is a coordinated campaign activity (variant of ClickFix social engineering technique) disclosed by Microsoft Threat Intelligence. The campaign targets organizations across multiple industries using compromised websites to deliver sophisti…
highbug_reportVulnerability19 malicious Chrome/Edge extensions drain crypto wallets via auto-updates
19 browser extensions (18 Chrome, 1 Edge) published since February 2024, with "Enable Right Click & Copy — Smart Unlock + OCR" having 80,000 installs. Extensions either created by threat actor or purchased from legitimate owners.
highbug_reportVulnerabilityCoordinated attacks target AI infrastructure for credential theft and cryptomining
AI infrastructure platforms: LiteLLM gateways (CVE-2026-42271, CVE-2026-48710), RAGFlow deployments, and Kestra workflow environments. All exposed instances with administrative surfaces reachable from the internet are at risk.
highbug_reportVulnerabilityMicrosoft SharePoint RCE chain (CVE-2026-55040 + CVE-2026-63520) exploited
Microsoft SharePoint Server (on-premises). CVE-2026-55040: JWT authentication bypass. CVE-2026-63520: Business Connectivity Services RCE. Over 8,700 SharePoint servers exposed online. Specific vulnerable versions not disclosed in article.
highperson_alertThreat ActorNovaCookies PhaaS Toolkit Hijacks Microsoft 365 Sessions via DocuSign
NovaCookies is a subscription-based adversary-in-the-middle (AitM) phishing-as-a-service (PhaaS) platform priced at $320/month, advertised via Telegram.
highperson_alertThreat ActorMirage2FA Campaign Hits 4,500 Orgs via Microsoft 365 AiTM Phishing
Mirage2FA is a commercial phishing-as-a-service (PhaaS) campaign active from 2024 to 2026, targeting Microsoft 365 accounts through adversary-in-the-middle (AiTM) techniques.
highbug_reportVulnerability.NET Framework August 2026 updates break WPF printing and PDF export
.NET Framework cumulative updates released August 2026 Patch Tuesday. Affects Windows Presentation Foundation (WPF) applications on Windows 10, Windows 11, Windows Server 2012 through Windows Server 2025.
highbug_reportVulnerabilityWordlistLoader and SynkLoader malware target Windows via ClickFix and Teams
Windows endpoints exposed to ClearFake/ClickFix campaigns (WordlistLoader delivering Amatera Stealer) and Microsoft Teams phishing (SynkLoader credential theft).
highbug_reportVulnerabilitySynkLoader malware spreads via Microsoft Teams phishing campaigns
Microsoft Teams users across all organizations. SynkLoader is a new credential-stealing malware family delivered through phishing messages on the Teams platform. No specific product versions or CVEs identified.
highbug_reportVulnerabilityMicrosoft Defender BTR.sys driver weaponized for kernel-level sabotage
Microsoft Defender BTR.sys driver on all Windows versions from Windows 7 through Windows 11 25H2. The driver is a required component shipped with every Windows installation and cannot be blocked without breaking Defender functionality.
criticalbug_reportVulnerabilityMicrosoft Entra ID deserialization flaw exploited; already patched
Microsoft Entra ID (formerly Azure Active Directory) cloud-based identity and access management platform. All versions prior to Microsoft's server-side patch.
criticalbug_reportVulnerabilityMicrosoft patches critical Entra ID RCE flaw (CVE-2026-69836, CVSS 10.0)
Microsoft Entra ID (formerly Azure Active Directory), all versions. Cloud-based identity and access management service. Microsoft has already deployed server-side mitigations; no customer action required.