Threat feed

Build your own threat feed

Pick the vendors you run, your industry and where you operate. Your feed, digest and alerts then narrow to what can actually reach you.

Used by 100+ security teams.

China-Linked QTFY Group Targets Critical Infrastructure with Malicious Tools

The Joint Cybersecurity Advisory JCSA-20260826-01, issued on August 26, 2026, by the FBI, NSA, and CNMF, warns of ongoing operations by the China-linked hacking group QTFY. Active since 2018, QTFY exp

Multiple Kernel Vulnerabilities Impacting Red Hat Systems

Red Hat has released several kernel updates addressing multiple vulnerabilities rated as Important. These vulnerabilities affect various versions of Red Hat Enterprise Linux, including 8.4, 8.6, and 8

Sality Botnet Disrupted in International Cyber Operation

On August 31, 2026, CrowdStrike, in collaboration with international law enforcement, executed a coordinated disruption of the Sality peer-to-peer botnet, which had been active since 2003 and infected

Congress Extends Cyber Info Sharing Law Amid Rising Cyber Threats

On September 1, 2026, Congress passed a continuing resolution extending the Cybersecurity Information Sharing Act (CISA) of 2015 through December 11, 2026. This extension comes as industry groups expr

Threat Actors Exploit Faronics Deploy for Remote Access via Phishing

Threat actors are exploiting Faronics Deploy, a legitimate endpoint management tool, to execute malicious PowerShell scripts and install ScreenConnect on compromised systems. Between July 21 and Augus

Critical JFrog Artifactory CVE-2026-82329 Under Active Exploitation

A critical vulnerability, CVE-2026-82329, in JFrog Artifactory has been disclosed with a CVSS score of 9.8. Attackers can exploit this flaw without authentication, allowing them to mint admin tokens a

Ransomware Attacks Target EP Manufacturing and Howard Lumber

On September 1, 2026, two separate ransomware attacks were reported, affecting EP Manufacturing and Howard Lumber. EP Manufacturing was targeted by the ransomware group Thegentlemen, while Howard Lumb

Critical DoS Vulnerabilities in python3-sqlparse Affecting SUSE Systems

Recent updates for python3-sqlparse have revealed multiple critical denial of service (DoS) vulnerabilities. The vulnerabilities, identified as CVE-2026-54284, CVE-2026-59893, CVE-2026-59894, and CVE-

SUSE and openSUSE BusyBox Vulnerabilities Addressed in Recent Updates

On September 1, 2026, SUSE and openSUSE released updates addressing multiple vulnerabilities in BusyBox. The updates fix five critical issues, including CVE-2023-42366, a heap buffer overflow, and CVE

Photon Achieves CyberVadis Platinum Rating for Cybersecurity Maturity

Photon has achieved the CyberVadis Platinum Rating, scoring 987 out of 1,000 in the 2026 cybersecurity assessment. This rating validates the maturity of Photon's cybersecurity governance, operational

BugHunting Campaign 2026 Launches for Vulnerability Detection

The BugHunting Campaign 2026 opened for registration on September 1, 2026, co-organized by the Cyber Security and Technology Crime Bureau of the Hong Kong Police Force and Cyberbay. This initiative ai

Novocure Cyberattack Exposes Data of Over 1,400 Cancer Patients

Healthtech company Novocure reported a data breach resulting from a cyberattack in mid-August 2026, affecting more than 1,400 U.S. cancer patients and an undisclosed number of employees. The breach ex

Guildma (Astaroth) Malware Infection via Geofenced Brazilian Email

On August 31, 2026, a Windows host was infected with Guildma (Astaroth) malware through a malicious email targeting Brazilian users. The email contained a geofenced link that delivered a ZIP archive w

PackClient RAT Targets Global Firms via Tax Phishing Campaigns

TA4922, a financially motivated threat actor, has been distributing the PackClient RAT since late May 2026, primarily targeting organizations in China and India. The malware is delivered through spoof

Multiple Vulnerabilities Discovered in libevent Affecting Ubuntu Systems

On September 1, 2026, Ubuntu published a security notice detailing multiple vulnerabilities in the libevent library, affecting Ubuntu 18.04 LTS, 20.04 LTS, 22.04 LTS, 24.04 LTS, and 26.04 LTS. Key iss

Critical Command Injection Vulnerability in Cobham SATCOM Routers

A critical command-injection vulnerability, tracked as CVE-2026-83772, has been disclosed in Cobham SATCOM VSAT7090 satellite communication routers, affecting maritime fleets globally. This flaw allow

Sevii Launches AI-Driven Autonomous Defense Against Cyber Threats

On September 1, 2026, Sevii announced the expansion of its Autonomous Defense & Remediation (ADR) platform with a new Autonomous Preemptive Security (APS) module. This module aims to counter AI-driven

Critical Langflow flaw exploited to steal OpenAI and AWS keys

No articles found for this cluster.

Breeze Comet Targets Brazilian Financial Sector with Fraudulent Transactions

Since 2024, the financially motivated threat actor Breeze Comet has targeted Brazilian financial services, retail, and e-commerce organizations, successfully executing hundreds of fraudulent transacti

Launch of Synthetic Insider Threat Matrix to Combat AI Risks

Above Security has launched the Synthetic Insider Threat Matrix (SITM) to address risks from synthetic insiders, a new category of insider threats posed by AI agents. This initiative is a collaboratio

Trending Threats

Gaining coverage