Skip to content
Threat Feed

Vendor

Meta

10 briefs RSS
high advisory

Arbitrary Code Execution via hydra.utils.instantiate

The hydra.utils.instantiate() function in hydra-core versions 1.3.3 and below is vulnerable to arbitrary code execution when processing untrusted configuration input, allowing attackers to hijack object instantiation.

hydra-core
1t 1c
high threat

Russian-Linked Clusters Abuse Authentication Flows for Targeted Credential Theft

Suspected Russian threat clusters UNC6293 and UNC7005 are abusing legitimate OAuth, app password, and device code authentication workflows to bypass MFA and compromise high-value targets in academia, government, and defense.

Microsoft Account +1 ICE RELIC phishing credential-theft oauth espionage ice-relic
3t 1i
high threat

Astaroth Botnet Deploys New WhatsApp Web Spambot Component

Operators of the Astaroth (aka Guildma) botnet, which targets Brazil-based users, introduced a new spambot component in Q4 2025 that leverages WhatsApp Web in headless browser mode for malware distribution, exhibiting evasion techniques like payload encryption and WebDriver automation indicator stripping.

Windows +5 Astaroth botnet malware spambot latin-america
1r 9t 8i updated
low advisory

Denial of Service Vulnerability in React Server Components

A denial of service vulnerability (CVE-2026-44907) affects multiple versions of the react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack packages, allowing threat actors to trigger out-of-memory exceptions or excessive CPU usage by sending specially crafted HTTP requests to server function endpoints.

react-server-dom-webpack +2 react denial-of-service web vulnerability
1t 1c
high advisory

meta-ads-mcp Authentication Bypass via X-Pipeboard-Token Header

An authentication bypass vulnerability in `meta-ads-mcp` version 1.0.113 allows unauthenticated network callers to gain unauthorized access by sending an arbitrary value in the `X-Pipeboard-Token` HTTP header, leading to the reuse of the server operator's `META_ACCESS_TOKEN` for full read and write access to Meta Ads data.

meta-ads-mcp authentication-bypass web-vulnerability meta python cwe-287
3t
high advisory

Unauthenticated Server-Side Request Forgery in meta-ads-mcp via image_url

An unauthenticated remote attacker can exploit a Server-Side Request Forgery (SSRF) vulnerability in `meta-ads-mcp` v1.0.113, specifically within the `upload_ad_image` function, by providing a malicious `image_url` parameter that causes the server to make arbitrary outbound HTTP requests to internal services, RFC 1918 addresses, or cloud metadata endpoints, leading to information disclosure and potential internal network compromise.

meta-ads-mcp 1.0.113 ssrf vulnerability web python unauthenticated
3t 2i
high advisory

Meta Business Manager Phishing Campaign Leveraging Legitimate Services

A threat actor group is actively conducting a phishing campaign since November 2025, abusing Meta's legitimate Business Account Manager service to send emails from noreply@business.facebook.com containing malicious Google Sites URLs that redirect to sophisticated phishing pages, ultimately aiming to steal Meta account credentials, MFA codes, personal and business contact information, and identification documents from targeted businesses, with recent evolutions including a Facebook Messenger chatbot and exfiltration to Telegram.

Meta Business Account Manager Service +4 phishing credential-theft cloud email-security
1r 5t 5i
high advisory

Adobe Security Updates — July 2026

Roundup of Adobe security advisories published in July 2026.

PoC ColdFusion <= 2025.9 +91 roundup
5c 15i updated
critical advisory

CVE-2026-9181: Unauthenticated Directory Traversal in ArcGIS Server

An unauthenticated attacker can exploit CVE-2026-9181, a critical directory traversal vulnerability in ArcGIS Server versions 12.0 and prior, by sending crafted path parameters to access sensitive files, leading to unauthorized information disclosure.

ArcGIS Server +17 directory-traversal web-vulnerability esri cve
2t 1i updated
high threat

Vect and TeamPCP Partner for Ransomware Campaigns Exploiting Supply Chain Compromises

The threat groups Vect and TeamPCP have formally partnered since March 2026 to conduct widespread ransomware deployment and extortion campaigns by leveraging TeamPCP's credential harvesting and data theft capabilities, often initiated through supply chain compromises involving poisoned software updates and exploitation of critical vulnerabilities like CVE-2025-55182, leading to significant data exfiltration and encrypted systems across multiple sectors.

React Server Components +10 Vect +1 ransomware supply-chain-attack data-theft credential-access extortion python github pypi
1r 10t 1i updated