THREAT FEED

Clear filters

Real-time security alerts filtered for your threat landscape.

//ALERTS · 7 found
Zoom Zero-Day Meeting Infiltration Vulnerability 2026-03-06

Zero-day vulnerability in Zoom client versions prior to 6.1.2 allows unauthenticated attackers to join private meetings without a passcode. Exploit bypasses the waiting room feature and has been observed in targeted attacks against corporate meetings.

Zero Day Initiative · national
Zoom
Xfinity Router Firmware Remote Code Execution Vulnerability 2026-03-03

Critical vulnerability discovered in Xfinity xFi gateway routers allowing unauthenticated remote code execution. Firmware versions prior to 3.2.1 are affected. Attackers can gain full control of the router and intercept all network traffic.

CISA · national
Comcast
Slack Webhook Data Exfiltration Vulnerability 2026-03-02

Attackers exploiting misconfigured Slack incoming webhooks to exfiltrate sensitive data from private channels. Organizations with default webhook permissions are particularly vulnerable. Data is sent to attacker-controlled servers via outbound webhook posts.

Palo Alto Networks Unit 42 · national
Slack
Google Workspace OAuth Token Theft Vulnerability 2026-03-01

New attack vector exploiting Google Workspace OAuth consent flow to steal long-lived access tokens. Malicious third-party apps request broad permissions and exfiltrate email, Drive, and Calendar data. Particularly targeting organizations using Slack-Gmail integrations.

Palo Alto Networks Unit 42 · national
Gmail Slack
NPM Supply Chain Attack Affecting Developer Tools Vulnerability 2026-02-28

Compromised npm packages discovered containing backdoors that exfiltrate environment variables and SSH keys. Over 45,000 downloads before removal. Developers using VS Code and Slack desktop apps with Node.js backends may be affected.

Palo Alto Networks Unit 42 · national
Microsoft Slack
Outlook Zero-Click Calendar Vulnerability Vulnerability 2026-02-27

Critical vulnerability in Microsoft Outlook allows remote code execution via specially crafted calendar invitations. No user interaction required. Affects Outlook desktop clients on Windows. Patch available in March 2026 security update.

CISA · national
Outlook Microsoft
NYC Subway Wi-Fi Man-in-the-Middle Attacks Vulnerability 2026-02-19

Man-in-the-middle attacks detected on NYC subway Wi-Fi networks. Attackers intercepting unencrypted traffic and injecting malicious content into HTTP connections. Email credentials sent over non-HTTPS connections are at risk.

NYC Cyber Command · nyc_metro
Gmail Outlook