Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

13 / 29 results
Active filter:actor: unknown✕ clear
155x surge in password spraying exploits MFA gaps and legacy OAuth flowshighperson_alertThreat Actor
person_alertThreat Actor

155x surge in password spraying exploits MFA gaps and legacy OAuth flows

The threat actor behind the LSHIY campaign remains unattributed. Motivation appears financially driven, likely focused on credential validation for resale on dark web markets rather than immediate post-compromise exploitation.

BleepingComputer19 Aug · 12:00 UTC
Fraudulent Sparrow Wallet App on Apple App Store Steals $1.8M in Bitcoinhighperson_alertThreat Actor
person_alertThreat Actor

Fraudulent Sparrow Wallet App on Apple App Store Steals $1.8M in Bitcoin

The threat actor behind this campaign remains unidentified. The operation involved publishing fraudulent cryptocurrency wallet applications on Apple's App Store that impersonated the legitimate Sparrow Wallet.

Apple27 Jul · 15:29 UTC
Hermes AI Agent Used for Post-Exploitation at Thai Finance Ministryhighperson_alertThreat Actor
person_alertThreat Actor

Hermes AI Agent Used for Post-Exploitation at Thai Finance Ministry

The threat actor behind this intrusion remains unattributed. Hunt.io assesses with low-to-medium confidence that the operator is Chinese-speaking or fluent in Chinese, based on linguistic artifacts (password containing "Leishen," meaning thunder god)…

Hermes AI24 Jul · 08:15 UTC
Massive SEO-Poisoned Campaign Distributes AsyncRAT via ScreenConnecthighperson_alertThreat Actor
person_alertThreat Actor

Massive SEO-Poisoned Campaign Distributes AsyncRAT via ScreenConnect

The threat actor behind this campaign remains unattributed. Motivation appears to be financially driven, consistent with commodity RAT deployment for access brokering, credential theft, or follow-on ransomware operations.

OBS Studio1 Jul · 15:53 UTC
SimpleHelp OpenID auth bypass (CVE-2026-48558) exploited in wildcriticalbug_reportVulnerability
bug_reportVulnerability

SimpleHelp OpenID auth bypass (CVE-2026-48558) exploited in wild

SimpleHelp remote support software, all versions using OpenID Connect authentication. CVE-2026-48558 is a critical authentication bypass (CVSS 10.0) in the OpenID Connect flow.

CVE-2026-4855830 Jun · 09:18 UTC
Malicious Chrome Extension Impersonates Perplexity AI to Intercept Searcheshighperson_alertThreat Actor
person_alertThreat Actor

Malicious Chrome Extension Impersonates Perplexity AI to Intercept Searches

The threat actor behind this campaign remains unattributed. The operation demonstrates a financially or espionage-motivated adversary leveraging social engineering through brand impersonation of Perplexity AI, a popular search technology.

Google29 Jun · 16:40 UTC
Cisco Catalyst SD-WAN zero-day exploited in wild for two monthshighbug_reportVulnerability
bug_reportVulnerability

Cisco Catalyst SD-WAN zero-day exploited in wild for two months

Cisco Catalyst SD-WAN Manager. Specific affected versions not disclosed. Requires authenticated local access for exploitation.

CVE-2026-2024525 Jun · 03:46 UTC
ShapedPlugin WordPress Pro plugins backdoored via compromised update channelhighbug_reportVulnerability
bug_reportVulnerability

ShapedPlugin WordPress Pro plugins backdoored via compromised update channel

Multiple ShapedPlugin Pro WordPress plugins distributed through official licensed update channels. Exact plugin names and affected versions not specified.

ShapedPlugin22 Jun · 16:00 UTC
Fortinet FortiSandbox under active exploit for 3 CVEs including critical 9.1criticalbug_reportVulnerability
bug_reportVulnerability

Fortinet FortiSandbox under active exploit for 3 CVEs including critical 9.1

Fortinet FortiSandbox - specific affected versions not disclosed. Three CVEs: CVE-2026-39813 (CVSS 9.1 critical), CVE-2026-39808, CVE-2026-25089. At least one vulnerability recently patched; patch status of others unclear.

CVE-2026-2508916 Jun · 08:30 UTC
Palo Alto PAN-OS GlobalProtect auth bypass under active exploitationhighbug_reportVulnerability
bug_reportVulnerability

Palo Alto PAN-OS GlobalProtect auth bypass under active exploitation

Palo Alto Networks PAN-OS GlobalProtect VPN portal and gateway components. Specific affected versions not disclosed in provided data. CVE-2026-0257, CVSS 7.8 (High).

CVE-2026-025715 Jun · 04:17 UTC
ServiceNow patches actively exploited auth bypass on hosted instanceshighbug_reportVulnerability
bug_reportVulnerability

ServiceNow patches actively exploited auth bypass on hosted instances

ServiceNow hosted customer instances (specific versions not disclosed). On-premise deployments may also be affected pending vendor guidance.

ServiceNow10 Jun · 05:02 UTC
CVE-2026-39987 in Marimo actively exploited for cloud credential thefthighbug_reportVulnerability
bug_reportVulnerability

CVE-2026-39987 in Marimo actively exploited for cloud credential theft

Marimo notebook platform (specific versions not disclosed). Affects internet-exposed Marimo notebook instances vulnerable to CVE-2026-39987.

CVE-2026-3998729 May · 12:39 UTC
Fortinet FortiCloud SSO bypass exploited to extract LDAP passwordshighbug_reportVulnerability
bug_reportVulnerability

Fortinet FortiCloud SSO bypass exploited to extract LDAP passwords

Fortinet FortiGate appliances with FortiCloud SSO enabled. CVE-2025-59718 and CVE-2025-59719 allow authentication bypass. All FortiGate instances share a default static encryption key that enables decryption of LDAP credentials and private keys from…

CVE-2025-5971827 Jan · 15:16 UTC