Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 415 results
Active filter:tag: #geopolitical✕ clear
Spanish Police Arrest Doxer Targeting National Cybersecurity PersonnelhighpublicGeopolitical
publicGeopolitical

Spanish Police Arrest Doxer Targeting National Cybersecurity Personnel

The arrest underscores Spain's efforts to protect critical cybersecurity infrastructure personnel from targeted information operations. Doxing of government cybersecurity staff represents a significant operational security risk, potentially enabling…

BleepingComputer1 Jun · 19:28 UTC
Meta AI bot exploited to hijack high-profile Instagram accountshighbug_reportVulnerability
bug_reportVulnerability

Meta AI bot exploited to hijack high-profile Instagram accounts

Meta Instagram platform, specifically the AI-powered customer support bot used for account recovery. High-profile accounts including Obama White House and U.S. Space Force Chief Master Sergeant were compromised.

Meta1 Jun · 15:32 UTC
Hard-coded credentials in KS-SOMED software enable unauthorized accesshighbug_reportVulnerability
bug_reportVulnerability

Hard-coded credentials in KS-SOMED software enable unauthorized access

KS-SOMED software (specific versions not disclosed). Hard-coded credentials embedded in application code allow unauthorized access to affected systems.

CVE-2026-422511 Jun · 10:55 UTC
Windows Netlogon RCE under active exploitation after patch releasecriticalbug_reportVulnerability
bug_reportVulnerability

Windows Netlogon RCE under active exploitation after patch release

Microsoft Windows Netlogon service, all versions prior to recent patch. Affects domain controllers and systems with Netlogon service enabled. Specific CVE and affected version details not provided in alert.

Microsoft1 Jun · 10:30 UTC
Operation Dragon Weave targets Czech and Taiwan entities with AdaptixC2highperson_alertThreat Actor
person_alertThreat Actor

Operation Dragon Weave targets Czech and Taiwan entities with AdaptixC2

Operation Dragon Weave is a cyber espionage campaign linked to China-aligned threat actors. The campaign's motivation appears to be intelligence collection targeting government officials, researchers, academics, and professionals in the Czech Republi…

The Hacker News1 Jun · 09:54 UTC
Dutch authorities dismantle botnet controlling 17M infected deviceshighbug_reportVulnerability
bug_reportVulnerability

Dutch authorities dismantle botnet controlling 17M infected devices

At least 17 million infected devices globally including computers, tablets, smartphones, and IoT devices. Over 200 command-and-control servers located in the Netherlands were seized.

The Hacker News31 May · 10:22 UTC
California sues 23andMe over 2023 breach of genetic datahighpublicGeopolitical
publicGeopolitical

California sues 23andMe over 2023 breach of genetic data

The lawsuit against 23andMe highlights growing regulatory enforcement around biometric and genetic data protection in the United States, particularly within the healthcare and biotechnology sectors.

23andMe29 May · 16:08 UTC
Microsoft May 2026 Patch Tuesday: 118 vulnerabilities, 16 criticalcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft May 2026 Patch Tuesday: 118 vulnerabilities, 16 critical

Microsoft products and services across the ecosystem. 118 total vulnerabilities: 16 critical severity, 102 important severity. Specific affected products and CVE identifiers not yet detailed in available information.

Microsoft29 May · 14:06 UTC
Oracle releases critical security patches for multiple productshighbug_reportVulnerability
bug_reportVulnerability

Oracle releases critical security patches for multiple products

Multiple Oracle products affected by high-severity vulnerabilities. Specific product names, versions, and CVE identifiers not provided in CERT.BE advisory. Likely part of Oracle's quarterly Critical Patch Update (CPU).

Oracle29 May · 12:43 UTC
Dutch authorities disrupt 17M-device botnet, seize 200+ servershighbug_reportVulnerability
bug_reportVulnerability

Dutch authorities disrupt 17M-device botnet, seize 200+ servers

Approximately 17 million infected devices globally; over 200 servers seized from a Dutch hosting provider. Specific botnet malware family and affected device types not disclosed.

BleepingComputer29 May · 12:26 UTC
GREYVIBE: Russian-linked APT targeting Ukraine since August 2025highperson_alertThreat Actor
person_alertThreat Actor

GREYVIBE: Russian-linked APT targeting Ukraine since August 2025

GREYVIBE is a previously undocumented threat actor attributed by WithSecure as Russian-linked, assessed to operate in support of Kremlin state interests. The group is characterized as Russian-speaking and operates within Russian time zones.

The Hacker News29 May · 09:31 UTC
US national sentenced for selling 7M elderly records to Jamaican fraudstershighpublicGeopolitical
publicGeopolitical

US national sentenced for selling 7M elderly records to Jamaican fraudsters

This case illustrates the transnational nature of cybercrime and data exploitation, where domestic actors facilitate cross-border fraud schemes targeting vulnerable populations.

BleepingComputer29 May · 09:07 UTC
Malicious NuGet package "Sicoob.Sdk" steals banking credentialshighbug_reportVulnerability
bug_reportVulnerability

Malicious NuGet package "Sicoob.Sdk" steals banking credentials

NuGet package "Sicoob.Sdk" versions 2.0.0 through 2.0.4. Targets developers integrating with Sicoob (Brazilian cooperative banking system). Affects .NET development environments where the malicious package was installed.

Sicoob29 May · 07:11 UTC
ShinyHunters Breaches Charter Communications, Exfiltrates 4.9M Recordshighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Breaches Charter Communications, Exfiltrates 4.9M Records

ShinyHunters is a financially motivated cybercrime group known for large-scale data breaches and extortion operations targeting enterprises. The group specializes in exfiltrating sensitive customer data from corporate databases and either selling the…

Charter Communications29 May · 06:29 UTC
Hard-coded secret in Trac PDBM enables unauthorized accesshighbug_reportVulnerability
bug_reportVulnerability

Hard-coded secret in Trac PDBM enables unauthorized access

Trac d.o.o. Process Database Manager (PDBM) - specific affected versions not disclosed. Vulnerability involves hard-coded cryptographic secret embedded in executable binary.

CVE-2026-2560029 May · 05:16 UTC
Kimsuky Targets South Korean Military and Corporate Sectorshighperson_alertThreat Actor
person_alertThreat Actor

Kimsuky Targets South Korean Military and Corporate Sectors

Kimsuky (also tracked as Velvet Chollima, Black Banshee, Emerald Sleet, and THALLIUM) is a North Korean state-sponsored advanced persistent threat group.

The Hacker News29 May · 03:57 UTC
GreyVibe Targets Ukraine with AI-Generated Lures and Custom Malwarehighperson_alertThreat Actor
person_alertThreat Actor

GreyVibe Targets Ukraine with AI-Generated Lures and Custom Malware

GreyVibe is a threat cluster assessed with moderate confidence to be linked to Russian interests, based on targeting patterns and geopolitical alignment.

BleepingComputer28 May · 20:24 UTC
FBI warns of FIFA-impersonating fraud sites targeting 2026 World Cuphighperson_alertThreat Actor
person_alertThreat Actor

FBI warns of FIFA-impersonating fraud sites targeting 2026 World Cup

Unknown fraud operators are conducting financially motivated cybercrime campaigns targeting fans and consumers interested in the 2026 FIFA World Cup. These actors leverage social engineering and brand impersonation tactics to establish fraudulent web…

BleepingComputer28 May · 17:08 UTC
Starlette and FastAPI authentication bypass flaw affects millions of serverscriticalbug_reportVulnerability
bug_reportVulnerability

Starlette and FastAPI authentication bypass flaw affects millions of servers

Starlette web framework and dependent frameworks including FastAPI. Specific vulnerable versions not provided in source data. Affects authentication mechanisms in applications built with these frameworks.

Starlette28 May · 12:32 UTC
Critical RCE vulnerability in LiquidJS requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical RCE vulnerability in LiquidJS requires immediate patching

LiquidJS templating engine, all versions prior to patched release. Specific vulnerable version range not provided in available data.

LiquidJS28 May · 12:20 UTC
Dell Container Storage Modules info disclosure enables data exfiltrationcriticalbug_reportVulnerability
bug_reportVulnerability

Dell Container Storage Modules info disclosure enables data exfiltration

Dell Container Storage Modules (specific versions not disclosed in summary). Vulnerability allows information disclosure that can lead to data exfiltration and lateral movement within containerized environments.

Dell28 May · 11:55 UTC
Kidsview authentication bypass allows unauthorized access (CVE-2026-8990)highbug_reportVulnerability
bug_reportVulnerability

Kidsview authentication bypass allows unauthorized access (CVE-2026-8990)

Kidsview application (specific versions not disclosed). Authentication mechanisms can be bypassed, potentially affecting all deployments until patched versions are confirmed.

CVE-2026-899028 May · 11:55 UTC
Romanian National Sentenced for Hacking Oregon Government Networkhighperson_alertThreat Actor
person_alertThreat Actor

Romanian National Sentenced for Hacking Oregon Government Network

A Romanian national individual actor who conducted unauthorized access operations targeting U.S. government and private sector networks. The actor's motivation appears to be financially driven cybercrime, operating from Romania to compromise Oregon s…

BleepingComputer28 May · 10:43 UTC
Out-of-bounds write in bzip2 enables code execution or DoShighbug_reportVulnerability
bug_reportVulnerability

Out-of-bounds write in bzip2 enables code execution or DoS

bzip2 compression software, all versions not yet patched. Affects systems using bzip2 for file compression/decompression, including Linux distributions, BSD variants, and applications embedding libbz2.

CVE-2026-4225028 May · 10:15 UTC
Apache ActiveMQ NMS AMQP Client deserialization flaw enables RCEcriticalbug_reportVulnerability
bug_reportVulnerability

Apache ActiveMQ NMS AMQP Client deserialization flaw enables RCE

Apache ActiveMQ NMS AMQP Client - specific vulnerable versions not provided. Affects .NET/C# applications using the NMS AMQP client library for message queue operations.

Apache27 May · 14:59 UTC
Microsoft SharePoint RCE vulnerability requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft SharePoint RCE vulnerability requires immediate patching

Microsoft SharePoint Server (specific versions not disclosed in advisory). Organizations running on-premises SharePoint deployments are affected. SharePoint Online managed by Microsoft likely already patched.

Microsoft27 May · 14:23 UTC
Banking trojans Grandoreiro and BTMOB target LATAM and Europehighbug_reportVulnerability
bug_reportVulnerability

Banking trojans Grandoreiro and BTMOB target LATAM and Europe

Windows and Android devices in Latin America (Brazil, Mexico) and Europe (Spain, Portugal). Grandoreiro targets Windows systems at companies; BTMOB RAT targets Android mobile users in Brazil.

Windows27 May · 14:10 UTC
Silent Ransom Group Shifts to Physical Data Theft at U.S. Law Firmshighperson_alertThreat Actor
person_alertThreat Actor

Silent Ransom Group Shifts to Physical Data Theft at U.S. Law Firms

Silent Ransom Group (SRG) is an extortion-focused threat actor that has evolved from traditional ransomware operations to conducting physical, in-person data theft attacks.

BleepingComputer27 May · 09:51 UTC
CISA orders federal agencies to patch LiteSpeed cPanel plugin in 4 dayscriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders federal agencies to patch LiteSpeed cPanel plugin in 4 days

LiteSpeed cPanel user-end plugin. Specific vulnerable versions not disclosed. Affects organizations using cPanel with LiteSpeed integration.

LiteSpeed27 May · 08:06 UTC
ShinyHunters Extorts Charter Communications After Data Breachhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Extorts Charter Communications After Data Breach

ShinyHunters is a financially motivated cybercrime group known for large-scale data breaches and extortion operations targeting organizations across multiple sectors.

Charter Communications26 May · 17:46 UTC