Automated feed

Threat Wire

Aggregated every six hours from CISA KEV, NIST NVD, CISA advisories and trade reporting, then deduplicated and stored. Free to read, and it will stay that way — these are links to other people's public work. What a membership adds is the analyst layer on top of them.

Entries
105
Known exploited
25
Last ingest
30 Aug, 18:53 UTC
Sources
5/5
Aggregated threat intelligence, newest first, filtered to Ransomware & Breaches
DateSourceSeverityEntry
BLEEPFulcrumSec claims Manchester Airports hack, theft of 86 GB of dataFulcrumSec claims it stole 86 GB of data from Manchester Airports Group. BleepingComputer validated one traveller's record, while samples revealed detailed customer, booking, and travel information beyond what MAG initially disclosed. [...]
BLEEPAnthropic warns infostealer malware is hijacking Claude sessions to drain usageAnthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions, allowing attackers to access accounts and consume their usage. [...]
BLEEPChrome Web Store extensions caught stealing crypto, browser dataMultiple extensions for Google Chrome and Microsoft Edge delivered a malware framework that deployed modules to steal cryptocurrency, sensitive data, and browser history, as well as inject ClickFix lures. [...]
THNTerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel BackdoorMicrosoft has disclosed details of a new ClickFix variant, dubbed TerminalFix, that aims to trick users into running a malicious command in Windows Terminal or PowerShell. "While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply the same technique but direct users to Windows Terminal or PowerShell instead, increasing the likelihood that complex
BLEEPAnthropic is cutting Claude Code's current weekly limits by 17%Anthropic is permanently increasing Claude Code's standard weekly usage limits by 25% for Pro, Max, Team, and seat-based Enterprise plans, but it's not as good as it sounds. [...]
BLEEPBrave browser adds email aliases to help users evade trackingThe latest version of the Brave browser, 1.94, introduces a feature called 'Email Aliases' that allows users to generate disposable email addresses when signing up to a new service. [...]
BLEEPMcKesson discloses breach after ShinyHunters claims patient data theftHealthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records. [...]
THNCosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was VulnerableCosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026. The vulnerability, designated GHSA-7g4w-cg88-2cq2, is rated Critical by Cosmos Labs and was published without a CVE identifier, a weakness classification, or a CVSS score. Affected versions are =
BLEEPGiveWP WordPress donation plugin flaw lets hackers execute server commandsA maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server. [...]
THNAttackers Chain Two PaperCut Flaws to Execute Code Without AuthenticationMalicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening. "This vulnerability gives an unauthenticated attacker remote control over PaperCut's trusted configuration, which could be used to execute arbitrary Java code inside the application's
BLEEP68-year-old imprisoned after making $1.3 million by pirating IPTV servicesA 68-year-old has been sentenced in the U.K. to more than six years in prison for operating an illegal IPTV (Internet Protocol Television) service that generated £980,812 ($1.3 million) over three years. [...]
THNAndroid 17 Adds OS-Wide ECH to Hide Website Visits From Network ProvidersGoogle on Thursday announced new network security protections in Android 17 to bolster connection privacy, address cellular vulnerabilities, and safeguard the privacy of users' home networks. Topping the list is support for Encrypted Client Hello (ECH), a privacy standard that prevents networks from eavesdropping on which websites a user is visiting. "This new privacy standard works in tandem
BLEEPAI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up?AI is accelerating vulnerability discovery, putting pressure on systems built to enrich, prioritize, and remediate flaws at a slower pace. Action1 explains why defenders increasingly need to correlate multiple intelligence sources and turn vulnerability data into faster remediation. [...]
BLEEPOver 8,300 Gitea servers vulnerable to code execution attacksOver 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, according to cybersecurity watchdog Shadowserver. [...]
BLEEPToy-making giant Hasbro disclose data breach affecting employeesHasbro, one of the world's largest toy and game companies, has disclosed that attackers have accessed the personal and financial information of an undisclosed number of employees. [...]
THNKey Reasons Why Identity Fabric Matters in 2026An Identity Fabric knits fragmented identity systems into a coherent layer that observes how identities behave across applications, APIs, and infrastructure. As enterprise access spans more cloud services and automated workloads, identity security depends less on static configuration and more on runtime visibility. This article covers the architecture, the risks of unmanaged identities, and
THNThree CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQLServiceNow has released patches for four security flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring system and exploitable, in certain circumstances, by an unauthenticated attacker. The company said it deployed a security update to hosted instances and provided the update to its partners and self-hosted customers, which leaves organizations that run their
BLEEPServiceNow warns of three max severity security vulnerabilitiesServiceNow released security patches for three new maximum-severity AI Platform vulnerabilities that can be exploited in code injection, SQL injection, and privilege escalation attacks. [...]
BLEEPWindows 11 KB5120998 update released with 35 changes and fixesMicrosoft released the KB5120998 preview cumulative update for Windows 11 versions 25H2 and 24H2, which comes with 35 changes, including improvements to the Start menu, taskbar, and Windows search. [...]
THNAPT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic OrganizationsCybersecurity researchers have flagged a fresh set of campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026. These campaigns, per Recorded Future Insikt Group, have led to the deployment of a previously undocumented backdoor dubbed HOOKEDGE, a lightweight Windows batch script that's distributed via
BLEEPNearly 700 rogue AI agents coordinated in the Hugging Face attackNew details about the July attack on Hugging Face reveal that hundreds of AI agents driven by OpenAI's internal IM1 model coordinated the compromise through an unauthorized message board. [...]
THNThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New StoriesA fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine. The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in public infrastructure, malicious tools waiting before showing their real behavior, exposed systems getting scanned, and exploit windows shrinking again. Different
THNAmazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro PowersCybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via prompt injection and Kiro Powers. The security flaw, which does not have a CVE identifier, works against Kiro IDE 0.7.45 on Windows, according to Mindgard. The latest version of
CISAAll-Line Equipment Company Fuel-BossView CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to execute arbitrary commands or code remotely on affected systems. The following versions of All-Line Equipment Company Fuel-Boss are affected: Fuel-Boss V1 Standard >=| =| =| =| =| =| =| =| =| =| =| =|<=PHP_7.1.5_7.1.5 Product Status: known_affected Remediations Vendor fix Fixes are available for the Fuel-Boss V1 Standard and Fuel-Boss V1 Portal. Please contact All-Line Equipment Company (866-356-3336) for instructions on how to receive these fixes. Vendor fix Fixes are not yet available for the…
CISAApplied Systems Engineering ASE2000 V2 Communications Test SetView CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to read or write arbitrary local files, cause the application to issue outbound network requests, or intercept the connection to impersonate the trusted peer, complete the TLS handshake, and read or modify the protected communications. The following versions of Applied Systems Engineering ASE2000 V2 Communications Test Set are affected: ASE2000 >=2.25| =2.25| =2.25|<=2.37 Product Status: known_affected Remediations Mitigation ASE/Kalkitech provides an upgraded version 2.38 that fixes both…
THNLearn How to Build Security Operations Ready for AI-Powered AttacksSecurity teams have spent years trying to detect threats faster. AI is changing the harder part: how much time defenders have left to act. Advanced AI models can now help attackers discover vulnerabilities, generate exploit code, and move through weaknesses faster than traditional security processes were built to handle. The challenge is no longer just finding another vulnerability or
CISACISA Vulnerability ReviewMost compromises do not rely on advanced techniques or cutting-edge tools. Cyber threat actors scan the internet looking for exposed, well-known software vulnerabilities to exploit. Basic security failures enable most compromises and organizations can reduce their risk by addressing these underlying weaknesses and prioritizing vulnerabilities for action based on the risk they pose. The CISA Vulnerability Review provides organizations with critical insights into the root causes of insecure software and practical steps they can take to address these flaws to prevent exploitation. Analyzing CISA…
CISASiemens SIMATIC IoT2050 AdvancedView CSAF Summary SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed contain a missing authentication vulnerability in the Node-RED HTTP interface that could allow an unauthenticated remote attacker to create malicious flows and execute arbitrary code on the underlying server with maximum privileges. Siemens has released a new version for SIMATIC IoT2050 Advanced and strongly recommends to update to the latest version. The following versions of Siemens SIMATIC IoT2050 Advanced are affected: SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) vers:intdot/<4.3.4.1 CVSS…
CISAPayRange APIView CSAF Summary Successful exploitation of this vulnerability could allow a remote, authenticated or unauthenticated attacker to disclose sensitive information, arbitrarily modify the device to cause a denial of service, or alter a devices displayed image. The following versions of PayRange API are affected: PayRange API vers:all/* CVSS Vendor Equipment Vulnerabilities v3 8.8 PayRange PayRange API Missing Authorization Background Critical Infrastructure Sectors: Commercial Facilities Countries/Areas Deployed: United States, Canada Company Headquarters Location: United States Vulnerabilities…
CISAA Tale of Two SOCs: Insights From Two Red Team AssessmentsAdvisory at a Glance Title A Tale of Two SOCs: Insights From Two Red Team Assessments Original Publication August 25, 2026 Executive Summary The Cybersecurity and Infrastructure Security Agency (CISA) conducted simultaneous red team assessments at two organizations and observed different defensive outcomes. In both environments, the red team achieved full domain compromise and accessed sensitive business systems (SBSs) and cloud resources. Organization A failed to detect or contain the activity, but Organization B rapidly identified initial compromise attempts, isolated affected systems, and…
CISAEbyte NE2-D11View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized administrative access, disclose sensitive information, modify device configuration, hijack authenticated sessions, and disrupt device operation. The following versions of Ebyte NE2-D11 are affected: NE2-D11 Firmware FW-9167-0-11 CVSS Vendor Equipment Vulnerabilities v3 9.8 Ebyte Ebyte NE2-D11 Missing Authentication for Critical Function, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials, Use of Client-Side Authentication, Use of GET Request Method…
CISABendix EC80 Brake ECUView CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause the loss of ABS functions, steering assist, speedometer, shifting capabilities, or disable automatic traction control. The following versions of Bendix EC80 Brake ECU are affected: EC80ESP+ J1708 Z228999 EC80ESP+ 6S/6M Z228999 EC80ESP+ PLC Z228999 EC80ESP+ 2nd CAN Z228999 EC80ESP+ Integrated TPMS Z228999 EC80ESP 6S/6M Z266494 EC80ESP PLC Z266494 EC80ESP 2nd CAN Z266494 EC80ESP CAN Gateway Z266494 EC80ESP 4S/4M Z286098 EC80ESP PLC Z286098 CVSS Vendor Equipment Vulnerabilities v3 7.5 Bendix…
CISAFURUNO FA-50 Class B AIS TransponderView CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to alter device settings. The following versions of FURUNO FA-50 Class B AIS Transponder are affected: FURUNO FA-50 Class B AIS Transponder vers:all/* CVSS Vendor Equipment Vulnerabilities v3 9.1 FURUNO ELECTRIC CO.,LTD. FURUNO FA-50 Class B AIS Transponder Use of Hard-coded Credentials, Missing Authentication for Critical Function Background Critical Infrastructure Sectors: Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Japan Vulnerabilities Expand All +…

Every entry links to its original source. Severity is the publisher's own rating where one exists — we don't re-score other people's advisories.