Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 415 results
Active filter:tag: #geopolitical✕ clear
ScarCruft Deploys NarwhalRAT via Microsoft Account Phishing Lureshighperson_alertThreat Actor
person_alertThreat Actor

ScarCruft Deploys NarwhalRAT via Microsoft Account Phishing Lures

ScarCruft (also tracked as APT37, InkySquid, Reaper, and Group123) is a North Korean state-sponsored advanced persistent threat group. The actor is attributed to North Korea's intelligence apparatus and conducts espionage operations aligned with Pyon…

Microsoft16 Jun · 06:14 UTC
CISA adds LiteSpeed cPanel Plugin privilege escalation to KEV cataloghighbug_reportVulnerability
bug_reportVulnerability

CISA adds LiteSpeed cPanel Plugin privilege escalation to KEV catalog

LiteSpeed cPanel Plugin (specific versions not disclosed). Affects web hosting environments using cPanel with LiteSpeed integration. Federal agencies and hosting providers running this plugin are in scope.

CVE-2026-5442016 Jun · 03:41 UTC
DOJ seizes AI deepfake sites under new TAKE IT DOWN Act authorityhighpublicGeopolitical
publicGeopolitical

DOJ seizes AI deepfake sites under new TAKE IT DOWN Act authority

The seizure of CFAKE.com and SOCFAKE.com represents the first public enforcement action under the TAKE IT DOWN Act, signaling a U.S. policy shift toward proactive domain-level intervention against AI-enabled image-based sexual abuse.

BleepingComputer15 Jun · 19:56 UTC
China-linked espionage group targets North American research networkscriticalperson_alertThreat Actor
person_alertThreat Actor

China-linked espionage group targets North American research networks

A China-linked espionage group conducted a sustained intrusion campaign lasting over one year against North American institutions. The actor's motivation appears to be intelligence collection focused on medical research, academic intellectual propert…

Google Workspace15 Jun · 17:44 UTC
Contagious Interview targets developers via recruitment-themed phishinghighperson_alertThreat Actor
person_alertThreat Actor

Contagious Interview targets developers via recruitment-themed phishing

Contagious Interview (also tracked as DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, and DEV#POPPER) is a North Korean-aligned threat actor cluster that specializes in social engineering attacks against software developers and technology secto…

The Hacker News15 Jun · 17:32 UTC
ShinyHunters Claims Council of Europe Data Breachhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Claims Council of Europe Data Breach

ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has been active since at least 2020, targeting organizations across multiple sectors to steal sensitive databases and person…

Council of Europe15 Jun · 14:37 UTC
China-Linked Espionage Group Deploys InfiniteRed via REDCap Servershighperson_alertThreat Actor
person_alertThreat Actor

China-Linked Espionage Group Deploys InfiniteRed via REDCap Servers

This activity is attributed to a China-linked espionage group targeting healthcare and medical research sectors. The actor's motivation appears to be intelligence collection focused on sensitive medical research data, consistent with strategic intere…

REDCap15 Jun · 12:00 UTC
Responsive FileManager RCE via unrestricted file upload (CVE-2026-5482)highbug_reportVulnerability
bug_reportVulnerability

Responsive FileManager RCE via unrestricted file upload (CVE-2026-5482)

Responsive FileManager (versions not specified). The vulnerability affects file upload mechanisms allowing unrestricted file uploads leading to remote code execution.

CVE-2026-548215 Jun · 09:55 UTC
Quick.CMS deserialization flaw enables potential remote code executionhighbug_reportVulnerability
bug_reportVulnerability

Quick.CMS deserialization flaw enables potential remote code execution

Quick.CMS software (specific versions not disclosed). Affects systems where untrusted data is deserialized without proper validation.

CVE-2026-1186015 Jun · 08:55 UTC
FBI disrupts Outsider Enterprise Chinese phishing-as-a-service platformhighperson_alertThreat Actor
person_alertThreat Actor

FBI disrupts Outsider Enterprise Chinese phishing-as-a-service platform

Outsider Enterprise is a Chinese phishing-as-a-service (PhaaS) operation disrupted by the FBI in coordination with Google and Black Lotus Labs. The actor operated thousands of phishing websites designed to harvest credit card data and passwords from…

BleepingComputer14 Jun · 12:36 UTC
Former Iowa school IT employee sentenced for insider cyberattackhighpublicGeopolitical
publicGeopolitical

Former Iowa school IT employee sentenced for insider cyberattack

This incident represents a domestic insider threat case within the United States education sector, rather than a state-sponsored or geopolitically motivated cyberattack. The prosecution and sentencing reflect U.S.

BleepingComputer13 Jun · 18:53 UTC
Chinese state-sponsored hackers maintain 10-year persistent accesscriticalperson_alertThreat Actor
person_alertThreat Actor

Chinese state-sponsored hackers maintain 10-year persistent access

Chinese state-sponsored hackers, likely an advanced persistent threat (APT) group operating on behalf of the People's Republic of China. The actor demonstrated exceptional operational security and patience, maintaining covert access to a target organ…

BleepingComputer13 Jun · 12:06 UTC
US orders Anthropic to restrict foreign access to advanced AI modelshighpublicGeopolitical
publicGeopolitical

US orders Anthropic to restrict foreign access to advanced AI models

The directive appears to represent an expansion of US export control philosophy into the AI domain, treating advanced language models as dual-use technologies with national security implications.

Anthropic13 Jun · 08:01 UTC
U.S. orders Anthropic to suspend foreign access to advanced AI modelshighpublicGeopolitical
publicGeopolitical

U.S. orders Anthropic to suspend foreign access to advanced AI models

The directive represents an escalation in U.S. efforts to control the diffusion of advanced artificial intelligence capabilities, treating frontier AI models as dual-use technologies with strategic implications.

Anthropic13 Jun · 03:42 UTC
Chinese Cybercrime Network Weaponizes Google Gemini AI for SMS Phishinghighperson_alertThreat Actor
person_alertThreat Actor

Chinese Cybercrime Network Weaponizes Google Gemini AI for SMS Phishing

A Chinese cybercrime network operating a phishing-as-a-service (PhaaS) platform called Outsider. The group weaponizes Google's Gemini AI to craft and conduct SMS-based phishing attacks (smishing) targeting American victims.

Google12 Jun · 16:59 UTC
Velvet Ant: China-linked APT backdoors Linux auth for decade-long accesscriticalperson_alertThreat Actor
person_alertThreat Actor

Velvet Ant: China-linked APT backdoors Linux auth for decade-long access

Velvet Ant (G1047) is a China-linked advanced persistent threat actor characterized by exceptional operational security and long-term persistence capabilities.

Linux12 Jun · 16:17 UTC
Conti Operator Pleads Guilty After Extradition to United Stateshighperson_alertThreat Actor
person_alertThreat Actor

Conti Operator Pleads Guilty After Extradition to United States

Conti is a prolific ransomware-as-a-service (RaaS) operation that emerged in 2020 and became one of the most active and financially successful cybercrime groups before its infrastructure was leaked and operations fragmented in 2022.

BleepingComputer12 Jun · 15:54 UTC
Oracle PeopleSoft RCE actively exploited, immediate patching requiredcriticalbug_reportVulnerability
bug_reportVulnerability

Oracle PeopleSoft RCE actively exploited, immediate patching required

Oracle PeopleSoft (specific versions not disclosed in alert). Remote code execution vulnerability affecting internet-facing PeopleSoft instances.

Oracle12 Jun · 12:39 UTC
UNC1151/Ghostwriter Targets Polish Gmail Accounts in Phishing Campaignhighperson_alertThreat Actor
person_alertThreat Actor

UNC1151/Ghostwriter Targets Polish Gmail Accounts in Phishing Campaign

UNC1151, also known as Ghostwriter, is a threat actor group attributed by FireEye/Mandiant that has conducted sustained information operations and cyber espionage activities.

Google12 Jun · 09:00 UTC
Novo Nordisk discloses clinical trial data breach in DenmarkhighpublicGeopolitical
publicGeopolitical

Novo Nordisk discloses clinical trial data breach in Denmark

The breach at Novo Nordisk, a Danish pharmaceutical giant controlling approximately 50% of the global insulin market, highlights the strategic vulnerability of critical healthcare infrastructure.

Novo Nordisk12 Jun · 08:13 UTC
INTERPOL arrests Guedz, admin of Sniper Dz phishing-as-a-service platformhighperson_alertThreat Actor
person_alertThreat Actor

INTERPOL arrests Guedz, admin of Sniper Dz phishing-as-a-service platform

Guedz is identified as the primary administrator of Sniper Dz, a phishing-as-a-service (PhaaS) platform that operated for approximately a decade across the Middle East and North Africa (MENA) region.

The Hacker News12 Jun · 06:52 UTC
CISA orders federal agencies to patch exploited Ivanti Sentry flawcriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders federal agencies to patch exploited Ivanti Sentry flaw

Ivanti Sentry (specific versions not disclosed in summary). U.S. federal agencies under BOD 26-04 mandate, but all Ivanti Sentry deployments at risk given active exploitation.

Ivanti12 Jun · 06:26 UTC
French Government Messaging Platform Tchap Breached, 73,000 Accounts AffectedhighpublicGeopolitical
publicGeopolitical

French Government Messaging Platform Tchap Breached, 73,000 Accounts Affected

The compromise of Tchap, France's sovereign encrypted messaging solution developed as an alternative to foreign platforms, represents a significant breach of government communications infrastructure.

Tchap12 Jun · 05:09 UTC
Europol Disrupts AudiA6 Cryptocurrency Laundering Servicehighperson_alertThreat Actor
person_alertThreat Actor

Europol Disrupts AudiA6 Cryptocurrency Laundering Service

AudiA6 was a cryptocurrency laundering service utilized by ransomware gangs and cybercriminal networks to obfuscate and legitimize illicit proceeds. The service facilitated the conversion and movement of cryptocurrency obtained through ransomware ope…

The Hacker News12 Jun · 04:38 UTC
Japanese utility loses drive with 10.9M customer recordshighpublicGeopolitical
publicGeopolitical

Japanese utility loses drive with 10.9M customer records

The incident at Kyushu Electric Power Co., Inc. represents a physical security failure rather than a cyber intrusion, but underscores the vulnerability of critical infrastructure operators to data exposure.

Kyushu Electric Power Co., Inc.11 Jun · 21:14 UTC
Critical command injection flaw in Fortinet FortiSandbox requires patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical command injection flaw in Fortinet FortiSandbox requires patching

Fortinet FortiSandbox (specific versions not disclosed in available data). Command injection vulnerability allows unauthorized command execution.

Fortinet11 Jun · 12:31 UTC
South Korea issues record $409M fine to Coupang for 37M-user breachhighpublicGeopolitical
publicGeopolitical

South Korea issues record $409M fine to Coupang for 37M-user breach

The unprecedented fine against Coupang reflects South Korea's increasingly assertive regulatory posture on data protection, aligning Seoul with global trends toward stringent enforcement of privacy frameworks.

Coupang11 Jun · 10:52 UTC
CISA mandates 3-day patching for exploited flaws in federal agencieshighpublicGeopolitical
publicGeopolitical

CISA mandates 3-day patching for exploited flaws in federal agencies

The directive represents a significant tightening of federal cybersecurity posture in response to persistent exploitation of known vulnerabilities by both state-sponsored and criminal actors.

BleepingComputer11 Jun · 10:46 UTC
OceanLotus Targets Vietnamese Infrastructure with SPECTRALVIPER Backdoorhighperson_alertThreat Actor
person_alertThreat Actor

OceanLotus Targets Vietnamese Infrastructure with SPECTRALVIPER Backdoor

OceanLotus (also tracked as APT32, SeaLotus, APT-C-00, and Canvas Cyclone) is a Vietnam-aligned advanced persistent threat group attributed by multiple vendors to conducting cyber espionage operations.

The Hacker News11 Jun · 07:45 UTC
University of Nottingham breach exposes 450,000+ student recordshighpublicGeopolitical
publicGeopolitical

University of Nottingham breach exposes 450,000+ student records

The breach at the University of Nottingham represents a significant compromise of a major UK higher education institution, affecting a substantial population of current and former students.

University of Nottingham11 Jun · 05:27 UTC