Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
13 / 29 results
highperson_alertThreat Actor155x surge in password spraying exploits MFA gaps and legacy OAuth flows
The threat actor behind the LSHIY campaign remains unattributed. Motivation appears financially driven, likely focused on credential validation for resale on dark web markets rather than immediate post-compromise exploitation.
highperson_alertThreat ActorFraudulent Sparrow Wallet App on Apple App Store Steals $1.8M in Bitcoin
The threat actor behind this campaign remains unidentified. The operation involved publishing fraudulent cryptocurrency wallet applications on Apple's App Store that impersonated the legitimate Sparrow Wallet.
highperson_alertThreat ActorHermes AI Agent Used for Post-Exploitation at Thai Finance Ministry
The threat actor behind this intrusion remains unattributed. Hunt.io assesses with low-to-medium confidence that the operator is Chinese-speaking or fluent in Chinese, based on linguistic artifacts (password containing "Leishen," meaning thunder god)…
highperson_alertThreat ActorMassive SEO-Poisoned Campaign Distributes AsyncRAT via ScreenConnect
The threat actor behind this campaign remains unattributed. Motivation appears to be financially driven, consistent with commodity RAT deployment for access brokering, credential theft, or follow-on ransomware operations.
criticalbug_reportVulnerabilitySimpleHelp OpenID auth bypass (CVE-2026-48558) exploited in wild
SimpleHelp remote support software, all versions using OpenID Connect authentication. CVE-2026-48558 is a critical authentication bypass (CVSS 10.0) in the OpenID Connect flow.
highperson_alertThreat ActorMalicious Chrome Extension Impersonates Perplexity AI to Intercept Searches
The threat actor behind this campaign remains unattributed. The operation demonstrates a financially or espionage-motivated adversary leveraging social engineering through brand impersonation of Perplexity AI, a popular search technology.
highbug_reportVulnerabilityCisco Catalyst SD-WAN zero-day exploited in wild for two months
Cisco Catalyst SD-WAN Manager. Specific affected versions not disclosed. Requires authenticated local access for exploitation.
highbug_reportVulnerabilityShapedPlugin WordPress Pro plugins backdoored via compromised update channel
Multiple ShapedPlugin Pro WordPress plugins distributed through official licensed update channels. Exact plugin names and affected versions not specified.
criticalbug_reportVulnerabilityFortinet FortiSandbox under active exploit for 3 CVEs including critical 9.1
Fortinet FortiSandbox - specific affected versions not disclosed. Three CVEs: CVE-2026-39813 (CVSS 9.1 critical), CVE-2026-39808, CVE-2026-25089. At least one vulnerability recently patched; patch status of others unclear.
highbug_reportVulnerabilityPalo Alto PAN-OS GlobalProtect auth bypass under active exploitation
Palo Alto Networks PAN-OS GlobalProtect VPN portal and gateway components. Specific affected versions not disclosed in provided data. CVE-2026-0257, CVSS 7.8 (High).
highbug_reportVulnerabilityServiceNow patches actively exploited auth bypass on hosted instances
ServiceNow hosted customer instances (specific versions not disclosed). On-premise deployments may also be affected pending vendor guidance.
highbug_reportVulnerabilityCVE-2026-39987 in Marimo actively exploited for cloud credential theft
Marimo notebook platform (specific versions not disclosed). Affects internet-exposed Marimo notebook instances vulnerable to CVE-2026-39987.
highbug_reportVulnerabilityFortinet FortiCloud SSO bypass exploited to extract LDAP passwords
Fortinet FortiGate appliances with FortiCloud SSO enabled. CVE-2025-59718 and CVE-2025-59719 allow authentication bypass. All FortiGate instances share a default static encryption key that enables decryption of LDAP credentials and private keys from…