Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
12 / 21 results
highperson_alertThreat ActorKimwolf v7 Botnet Adds HTTP/2 DDoS with Browser Fingerprinting
Kimwolf (also tracked as AISURU) is an Android and IoT botnet operation active since at least mid-2024. The threat actors behind Kimwolf have demonstrated continuous evolution in their tooling, targeting Android TV boxes since August 2025 and Linux I…
highbug_reportVulnerabilityChrome Password Manager passkey bypass allows malware to hijack accounts
Google Chrome Password Manager on Windows systems with TPM. All three attack paths require malware already running as an ordinary user. Specific affected Chrome versions not disclosed.
highbug_reportVulnerabilityPasskey auth bypass via User Verified flag validation gap in relying parties
Relying parties (websites/services) implementing passkey authentication that fail to validate the User Verified (UV) flag in WebAuthn assertions. Affects passwordless authentication systems across multiple platforms.
highperson_alertThreat Actorknaithe/KnYuan Uses DeepSeek AI for Autonomous Exploitation Campaign
knaithe (also tracked as KnYuan) is a Chinese-speaking threat actor assessed by Unit 42 to be based in Zhuhai, China. Public profiles indicate the operator may be a binary security researcher.
highperson_alertThreat ActorQilin Ransomware Exploits CVE-2026-0257 PAN-OS Flaw for Initial Access
Qilin is a ransomware-as-a-service (RaaS) operation that has been active in the cybercrime ecosystem, deploying file-encrypting malware against organizations for financial gain.
criticalperson_alertThreat ActorQilin Ransomware Gang Exploits PAN-OS GlobalProtect Vulnerability
Qilin is a ransomware-as-a-service (RaaS) operation that has emerged as a notable threat actor in the cybercrime ecosystem. The group operates a double-extortion model, encrypting victim data while exfiltrating sensitive information for leverage in r…
highperson_alertThreat ActorCL-STA-1062 deploys TinyRCT backdoor against Southeast Asian government
CL-STA-1062 is a Chinese-speaking APT actor conducting targeted cyber espionage operations against government entities and critical infrastructure in Southeast Asia.
highbug_reportVulnerabilityPalo Alto PAN-OS GlobalProtect auth bypass under active exploitation
Palo Alto Networks PAN-OS GlobalProtect VPN portal and gateway components. Specific affected versions not disclosed in provided data. CVE-2026-0257, CVSS 7.8 (High).
highbug_reportVulnerabilityActive exploitation of PAN-OS CVE-2026-0257 reported by Unit 42
Palo Alto Networks PAN-OS (specific affected versions not provided in available data)
criticalbug_reportVulnerabilityPAN-OS GlobalProtect auth bypass CVE-2026-0257 under active exploit
Palo Alto Networks PAN-OS GlobalProtect VPN. Specific affected versions not disclosed in provided data. Impacts corporate networks using GlobalProtect for remote access.
highbug_reportVulnerabilityPalo Alto PAN-OS auth bypass (CVE-2026-0257) exploited in the wild
Palo Alto Networks PAN-OS and Prisma Access. Specific affected versions not disclosed in provided data. Vulnerability impacts VPN authentication mechanisms.
criticalbug_reportVulnerabilityCritical PAN-OS vulnerabilities enable auth bypass and code execution
Palo Alto Networks PAN-OS (specific versions not provided in summary). Affects authentication controls, code execution surface, and availability.