Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 390 results
highpublicGeopoliticalIndia mandates 12-hour patching for critical vulnerabilities
India's Computer Emergency Response Team (CERT-In) has introduced stringent vulnerability management requirements, mandating that organizations patch critical security flaws in internet-facing systems within 12 hours of notification.
highbug_reportVulnerabilityWindows Server 2016 domain controller lookups fail after KB5087537 update
Windows Server 2016 domain controllers running KB5087537 (May 2026 security update). Impacts Active Directory domain controller lookup functionality and domain connectivity.
highperson_alertThreat ActorNimbus Manticore deploys MiniFast and MiniJunk V2 via phishing and SEO poisoning
Nimbus Manticore (also tracked as Screening Serpens and UNC1549) is an Iranian state-sponsored threat actor attributed to Iran's intelligence apparatus.
highperson_alertThreat ActorShinyHunters Breaches 7-Eleven, Exfiltrates 183K Records
ShinyHunters is a financially motivated cybercrime group known for large-scale data breaches and extortion operations targeting organizations across multiple sectors.
highbug_reportVulnerabilityDigital Knowledge LMS exploited via hardcoded ASP.NET keys (CVE-2026-5426)
Digital Knowledge KnowledgeDeliver LMS (specific versions not disclosed). Vulnerability stems from hard-coded ASP.NET machine keys enabling authentication bypass and remote code execution.
highperson_alertThreat ActorDutch Authorities Disrupt Hosting Infrastructure Linked to Russian Ops
This operation involves Russian state-sponsored cyber activity facilitated through compromised Internet hosting infrastructure in the Netherlands. The arrested co-owners operated hosting companies that assumed control of Stark Industries Solutions' t…
highperson_alertThreat ActorFBI warns of Kali365 phishing-as-a-service targeting Microsoft 365
Kali365 is a phishing-as-a-service (PhaaS) platform that enables threat actors to conduct credential harvesting and account takeover operations against Microsoft 365 users.
highbug_reportVulnerabilityOutSystems Lifetime authorization bypass via user-controlled key
OutSystems Lifetime software. Specific affected versions not disclosed. Vulnerability allows authorization bypass through improper handling of user-controlled keys.
highperson_alertThreat ActorLazarus Group deploys RemotePE cross-platform RAT against finance sector
Lazarus Group is a North Korean state-sponsored advanced persistent threat (APT) actor attributed to the Reconnaissance General Bureau (RGB). The group is financially motivated, conducting operations to generate revenue for the DPRK regime through th…
highbug_reportVulnerabilityLaravel Lang packages compromised to deliver credential-stealing malware
Laravel Lang localization packages distributed via Composer. Affects developers who installed or updated compromised packages during the attack window. Specific package names and versions not yet publicly disclosed.
highbug_reportVulnerabilitySupply chain attack compromises 8 Packagist packages with malicious binary
Eight Composer packages on Packagist containing JavaScript components. Malicious code injected into package.json files executes a Linux binary from GitHub Releases. Downstream projects using these packages are affected.
highpublicGeopoliticalItaly Dismantles CINEMAGOAL Piracy Network Targeting Streaming Platforms
The disruption of the CINEMAGOAL piracy ecosystem represents a law enforcement action against organized digital piracy infrastructure rather than a state-sponsored cyber operation.
highbug_reportVulnerabilityAnthropic Glasswing project finds 10,000+ critical flaws in key software
Widely used, systemically important software (specific products not disclosed). Over 10,000 high- or critical-severity vulnerabilities identified since project launch last month.
highbug_reportVulnerabilityLaravel-Lang packages compromised to deliver credential-stealing malware
Multiple Laravel-Lang PHP packages compromised: laravel-lang/lang, laravel-lang/http-statuses, laravel-lang/attributes, and laravel-lang/actions. Affects Laravel PHP applications using these localization packages.
highperson_alertThreat ActorFirst VPN Service dismantled by European and North American authorities
First VPN Service was a criminal VPN infrastructure provider that facilitated cybercrime operations for approximately 25 ransomware groups. The service enabled threat actors to obscure their geographic origins and true IP addresses during malicious a…
highpublicGeopoliticalDutch authorities dismantle hosting infrastructure linked to cyber ops
The Netherlands has emerged as a key jurisdiction for enforcement against cyber-enabling infrastructure, reflecting both its role as a European internet hub and its proactive stance on transnational cybercrime.
highperson_alertThreat ActorF5 BIG-IP Exploitation Leads to Confluence Compromise and Lateral Movement
The threat actor behind this campaign remains unattributed. Motivation appears to be credential theft and network persistence within enterprise environments.
highperson_alertThreat ActorGhostwriter Targets Ukrainian Government with Prometheus-Themed Phishing
Ghostwriter (also tracked as UAC-0057 and UNC1151) is a Belarus-aligned threat actor known for conducting information operations and cyber espionage campaigns.
highperson_alertThreat ActorScreening Serpens: Iranian APT Targets Tech and Defense with RAT Malware
Screening Serpens is an Iranian APT group attributed by Unit 42, conducting cyber espionage operations. The group is motivated by intelligence collection targeting technology and defense sectors, consistent with Iranian state interests in acquiring s…
highperson_alertThreat ActorMegalodon campaign injects 5,718 malicious commits into GitHub repos
Megalodon is an automated supply chain attack campaign targeting GitHub repositories. The actor's motivation appears to be exfiltration of CI/CD environment data, including secrets, tokens, and credentials stored in GitHub Actions workflows.
highperson_alertThreat ActorROADtools Framework Misused in Nation-State Cloud Intrusions
Multiple threat actors, including nation-state groups, are misusing the open-source ROADtools framework for cloud intrusions. ROADtools is a legitimate Azure AD reconnaissance toolkit designed for security assessments, but has been co-opted by advers…
highperson_alertThreat ActorCanadian National Arrested for Operating KimWolf DDoS Botnet
A Canadian national arrested by U.S. and Canadian authorities for operating the KimWolf DDoS botnet infrastructure. The operator managed a large-scale botnet that compromised nearly two million devices globally, offering DDoS-for-hire services.
highperson_alertThreat ActorJacob Butler Arrested for Operating Kimwolf DDoS Botnet
Jacob Butler, also known as "Dort," is a 23-year-old Canadian national from Ottawa arrested by the U.S. Department of Justice for developing and operating the Kimwolf DDoS botnet.
highperson_alertThreat ActorDort Arrested for Operating Kimwolf IoT Botnet in Multi-Million Device DDoS Campaign
Dort is a 23-year-old cybercriminal based in Ottawa, Canada, suspected of developing and operating the Kimwolf IoT botnet. Motivated by launching large-scale DDoS attacks, doxing, and swatting campaigns, Dort leveraged compromised IoT devices to buil…
highbug_reportVulnerabilityChromium zero-day disclosed: JavaScript persists after browser close
Chromium-based browsers (Google Chrome, Microsoft Edge, Brave, Opera, Vivaldi) - specific affected versions not disclosed. Vulnerability remains unpatched at time of disclosure.
highbug_reportVulnerabilityNLnet Labs patches DoS vulnerabilities in Unbound DNS resolver
Unbound DNS resolver by NLnet Labs. Specific vulnerable versions not provided in advisory; patched versions available. Affects organizations running Unbound for DNS resolution services.
highperson_alertThreat ActorShowboat Linux Malware Targets Middle East Telecom Since Mid-2022
The threat actor behind Showboat remains unattributed. The campaign demonstrates sophisticated targeting of telecommunications infrastructure in the Middle East, suggesting a motivated adversary with strategic intelligence collection objectives.
highperson_alertThreat ActorChinese APT Deploys Showboat and JFMBackdoor Against Telecom Sector
Chinese state-sponsored threat actors conducting cyber-espionage operations against telecommunications infrastructure. The actors demonstrate cross-platform capabilities with custom Linux and Windows malware tooling.
highperson_alertThreat ActorInternational Law Enforcement Seizes First VPN Service Used by Cybercriminals
First VPN was a commercial VPN service exploited by multiple threat actors to anonymize their operations. The service provided infrastructure enabling cybercriminals to mask their origin during ransomware deployments and data exfiltration campaigns.
highbug_reportVulnerabilityMicrosoft Defender privilege escalation CVE-2026-41091 under active exploit
Microsoft Defender on Windows systems. Specific product versions not disclosed. Vulnerability allows local attackers to escalate privileges to SYSTEM level through improper link resolution handling.