Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-21 · 02:09 UTC
articleTotal: 606 reports

Filtered Reports

30 / 390 results
Active filter:tag: #high✕ clear
GREYVIBE: Russian-linked APT targeting Ukraine since August 2025highperson_alertThreat Actor
person_alertThreat Actor

GREYVIBE: Russian-linked APT targeting Ukraine since August 2025

GREYVIBE is a previously undocumented threat actor attributed by WithSecure as Russian-linked, assessed to operate in support of Kremlin state interests. The group is characterized as Russian-speaking and operates within Russian time zones.

The Hacker News09:31 UTC
US national sentenced for selling 7M elderly records to Jamaican fraudstershighpublicGeopolitical
publicGeopolitical

US national sentenced for selling 7M elderly records to Jamaican fraudsters

This case illustrates the transnational nature of cybercrime and data exploitation, where domestic actors facilitate cross-border fraud schemes targeting vulnerable populations.

BleepingComputer09:07 UTC
Malicious NuGet package "Sicoob.Sdk" steals banking credentialshighbug_reportVulnerability
bug_reportVulnerability

Malicious NuGet package "Sicoob.Sdk" steals banking credentials

NuGet package "Sicoob.Sdk" versions 2.0.0 through 2.0.4. Targets developers integrating with Sicoob (Brazilian cooperative banking system). Affects .NET development environments where the malicious package was installed.

Sicoob07:11 UTC
ShinyHunters Breaches Charter Communications, Exfiltrates 4.9M Recordshighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Breaches Charter Communications, Exfiltrates 4.9M Records

ShinyHunters is a financially motivated cybercrime group known for large-scale data breaches and extortion operations targeting enterprises. The group specializes in exfiltrating sensitive customer data from corporate databases and either selling the…

Charter Communications06:29 UTC
Hard-coded secret in Trac PDBM enables unauthorized accesshighbug_reportVulnerability
bug_reportVulnerability

Hard-coded secret in Trac PDBM enables unauthorized access

Trac d.o.o. Process Database Manager (PDBM) - specific affected versions not disclosed. Vulnerability involves hard-coded cryptographic secret embedded in executable binary.

CVE-2026-2560005:16 UTC
Kimsuky Targets South Korean Military and Corporate Sectorshighperson_alertThreat Actor
person_alertThreat Actor

Kimsuky Targets South Korean Military and Corporate Sectors

Kimsuky (also tracked as Velvet Chollima, Black Banshee, Emerald Sleet, and THALLIUM) is a North Korean state-sponsored advanced persistent threat group.

The Hacker News03:57 UTC
Mini Shai-Hulud: Typosquatted npm Packages Target Developer Credentialshighperson_alertThreat Actor
person_alertThreat Actor

Mini Shai-Hulud: Typosquatted npm Packages Target Developer Credentials

Mini Shai-Hulud is a threat actor campaign focused on compromising software development environments through supply chain attacks. The actor leverages typosquatting techniques against the npm package ecosystem to distribute malicious packages that ma…

npm01:04 UTC
GreyVibe Targets Ukraine with AI-Generated Lures and Custom Malwarehighperson_alertThreat Actor
person_alertThreat Actor

GreyVibe Targets Ukraine with AI-Generated Lures and Custom Malware

GreyVibe is a threat cluster assessed with moderate confidence to be linked to Russian interests, based on targeting patterns and geopolitical alignment.

BleepingComputer20:24 UTC
BTMOB Android RAT offered as MaaS with custom phishing builderhighbug_reportVulnerability
bug_reportVulnerability

BTMOB Android RAT offered as MaaS with custom phishing builder

Android devices targeted by BTMOB remote access trojan. No specific vendor or version restrictions; affects users who install malicious APKs distributed through phishing campaigns.

BleepingComputer19:10 UTC
FBI warns of FIFA-impersonating fraud sites targeting 2026 World Cuphighperson_alertThreat Actor
person_alertThreat Actor

FBI warns of FIFA-impersonating fraud sites targeting 2026 World Cup

Unknown fraud operators are conducting financially motivated cybercrime campaigns targeting fans and consumers interested in the 2026 FIFA World Cup. These actors leverage social engineering and brand impersonation tactics to establish fraudulent web…

BleepingComputer17:08 UTC
Fortinet FortiClient EMS auth bypass exploited to deploy EKZ malwarehighbug_reportVulnerability
bug_reportVulnerability

Fortinet FortiClient EMS auth bypass exploited to deploy EKZ malware

Fortinet FortiClient Enterprise Management Server (EMS). Specific vulnerable versions not provided in available data. Authentication bypass vulnerability CVE-2026-35616 allows unauthorized access.

CVE-2026-3561615:25 UTC
Arctic Wolf exploits FortiClient EMS flaw for credential thefthighperson_alertThreat Actor
person_alertThreat Actor

Arctic Wolf exploits FortiClient EMS flaw for credential theft

Arctic Wolf is a threat actor exploiting a critical, patched vulnerability in FortiClient Endpoint Management Server (EMS) to deploy credential-stealing malware.

Fortinet13:26 UTC
Storm-2697 Deploys The Gentlemen Go-Based Ransomware with Worm Capabilitieshighperson_alertThreat Actor
person_alertThreat Actor

Storm-2697 Deploys The Gentlemen Go-Based Ransomware with Worm Capabilities

Storm-2697 is a threat actor tracked by Microsoft Threat Intelligence that operates as a ransomware affiliate group. The actor deploys The Gentlemen ransomware, a sophisticated Go-based encryption tool, suggesting technical proficiency in modern prog…

Microsoft13:00 UTC
Kidsview authentication bypass allows unauthorized access (CVE-2026-8990)highbug_reportVulnerability
bug_reportVulnerability

Kidsview authentication bypass allows unauthorized access (CVE-2026-8990)

Kidsview application (specific versions not disclosed). Authentication mechanisms can be bypassed, potentially affecting all deployments until patched versions are confirmed.

CVE-2026-899011:55 UTC
Romanian National Sentenced for Hacking Oregon Government Networkhighperson_alertThreat Actor
person_alertThreat Actor

Romanian National Sentenced for Hacking Oregon Government Network

A Romanian national individual actor who conducted unauthorized access operations targeting U.S. government and private sector networks. The actor's motivation appears to be financially driven cybercrime, operating from Romania to compromise Oregon s…

BleepingComputer10:43 UTC
Out-of-bounds write in bzip2 enables code execution or DoShighbug_reportVulnerability
bug_reportVulnerability

Out-of-bounds write in bzip2 enables code execution or DoS

bzip2 compression software, all versions not yet patched. Affects systems using bzip2 for file compression/decompression, including Linux distributions, BSD variants, and applications embedding libbz2.

CVE-2026-4225010:15 UTC
ShinyHunters Claims Breach of Carnival Corporation, 6M Recordshighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Claims Breach of Carnival Corporation, 6M Records

ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has been active since at least 2020, specializing in breaching corporate databases and exfiltrating customer and employee re…

Carnival Corporation08:49 UTC
JINX-0164 Targets Cryptocurrency Orgs with macOS Malwarehighperson_alertThreat Actor
person_alertThreat Actor

JINX-0164 Targets Cryptocurrency Orgs with macOS Malware

JINX-0164 is a previously undocumented threat actor with a financial motivation focused on digital asset theft. The group demonstrates technical sophistication through the development of custom macOS malware and operational tradecraft centered on soc…

The Hacker News05:54 UTC
Cryptojacking campaign uses SEO poisoning and AI chatbots for GPU malwarehighbug_reportVulnerability
bug_reportVulnerability

Cryptojacking campaign uses SEO poisoning and AI chatbots for GPU malware

High-performance systems with GPUs accessed via search engines and AI chatbot platforms. No specific vendor or product vulnerability; targets users searching for legitimate software or information through poisoned search results and manipulated chatb…

BleepingComputer19:31 UTC
Banking trojans Grandoreiro and BTMOB target LATAM and Europehighbug_reportVulnerability
bug_reportVulnerability

Banking trojans Grandoreiro and BTMOB target LATAM and Europe

Windows and Android devices in Latin America (Brazil, Mexico) and Europe (Spain, Portugal). Grandoreiro targets Windows systems at companies; BTMOB RAT targets Android mobile users in Brazil.

Windows14:10 UTC
Malicious npm package targets Claude AI user data directoryhighbug_reportVulnerability
bug_reportVulnerability

Malicious npm package targets Claude AI user data directory

npm package "mouse5212-super-formatter" (all versions). Targets developers using Anthropic Claude AI tools with access to /mnt/user-data directory. Affects Node.js development environments where the malicious package was installed.

npm13:44 UTC
Glassworm botnet targeting developers disrupted via C2 takedownhighbug_reportVulnerability
bug_reportVulnerability

Glassworm botnet targeting developers disrupted via C2 takedown

Software developers and development environments targeted by Glassworm botnet. The botnet leveraged Solana blockchain and BitTorrent DHT for command-and-control infrastructure, indicating attacks against software supply chains.

BleepingComputer11:28 UTC
Silent Ransom Group Shifts to Physical Data Theft at U.S. Law Firmshighperson_alertThreat Actor
person_alertThreat Actor

Silent Ransom Group Shifts to Physical Data Theft at U.S. Law Firms

Silent Ransom Group (SRG) is an extortion-focused threat actor that has evolved from traditional ransomware operations to conducting physical, in-person data theft attacks.

BleepingComputer09:51 UTC
CrowdStrike, Google disrupt GlassWorm C2 targeting software developershighbug_reportVulnerability
bug_reportVulnerability

CrowdStrike, Google disrupt GlassWorm C2 targeting software developers

Software developers using third-party packages and browser extensions. GlassWorm campaign active since early 2025, distributing malware through supply chain vectors including malicious packages and extensions.

CrowdStrike09:48 UTC
Gitea auth bypass exposes private container images to unauthenticated usershighbug_reportVulnerability
bug_reportVulnerability

Gitea auth bypass exposes private container images to unauthenticated users

Gitea versions prior to 1.26.2. All deployments using Gitea's container registry feature are affected. Unauthenticated remote attackers can pull private container images without credentials.

CVE-2026-2777108:06 UTC
AI chatbot abuse delivers cryptojacking malware via social engineeringhighbug_reportVulnerability
bug_reportVulnerability

AI chatbot abuse delivers cryptojacking malware via social engineering

Users of AI chatbots (platform-agnostic); Windows systems targeted for cryptojacking payload deployment. Campaign actively observed by Microsoft; no specific product vulnerability, relies on social engineering.

Microsoft05:45 UTC
Cryptojacking campaign uses SEO poisoning and ScreenConnect for GPU mininghighbug_reportVulnerability
bug_reportVulnerability

Cryptojacking campaign uses SEO poisoning and ScreenConnect for GPU mining

Organizations using ScreenConnect remote access software; high-performance PCs with GPUs; users searching for compromised topics via search engines and AI chatbots. Campaign leverages Microsoft .NET utilities for execution.

Microsoft19:35 UTC
ShinyHunters Extorts Charter Communications After Data Breachhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Extorts Charter Communications After Data Breach

ShinyHunters is a financially motivated cybercrime group known for large-scale data breaches and extortion operations targeting organizations across multiple sectors.

Charter Communications17:46 UTC
MuddyWater Q1 2026 espionage campaign hits nine countries via DLL side-loadinghighperson_alertThreat Actor
person_alertThreat Actor

MuddyWater Q1 2026 espionage campaign hits nine countries via DLL side-loading

MuddyWater (also tracked as Earth Vetala, MERCURY, Static Kitten, and Seedworm) is an Iranian state-sponsored APT group attributed to Iran's Ministry of Intelligence and Security (MOIS).

The Hacker News13:48 UTC
Microsoft patches SharePoint RCE flaw via unsafe deserializationhighbug_reportVulnerability
bug_reportVulnerability

Microsoft patches SharePoint RCE flaw via unsafe deserialization

Microsoft SharePoint Server (specific versions not disclosed). Vulnerability involves deserialization of untrusted data leading to remote code execution with CVSS 8.8.

CVE-2026-4565909:49 UTC