Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 390 results
Active filter:tag: #high✕ clear
India mandates 12-hour patching for critical vulnerabilitieshighpublicGeopolitical
publicGeopolitical

India mandates 12-hour patching for critical vulnerabilities

India's Computer Emergency Response Team (CERT-In) has introduced stringent vulnerability management requirements, mandating that organizations patch critical security flaws in internet-facing systems within 12 hours of notification.

The Hacker News26 May · 07:13 UTC
Windows Server 2016 domain controller lookups fail after KB5087537 updatehighbug_reportVulnerability
bug_reportVulnerability

Windows Server 2016 domain controller lookups fail after KB5087537 update

Windows Server 2016 domain controllers running KB5087537 (May 2026 security update). Impacts Active Directory domain controller lookup functionality and domain connectivity.

Microsoft26 May · 05:41 UTC
Nimbus Manticore deploys MiniFast and MiniJunk V2 via phishing and SEO poisoninghighperson_alertThreat Actor
person_alertThreat Actor

Nimbus Manticore deploys MiniFast and MiniJunk V2 via phishing and SEO poisoning

Nimbus Manticore (also tracked as Screening Serpens and UNC1549) is an Iranian state-sponsored threat actor attributed to Iran's intelligence apparatus.

The Hacker News26 May · 05:13 UTC
ShinyHunters Breaches 7-Eleven, Exfiltrates 183K Recordshighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Breaches 7-Eleven, Exfiltrates 183K Records

ShinyHunters is a financially motivated cybercrime group known for large-scale data breaches and extortion operations targeting organizations across multiple sectors.

7-Eleven26 May · 05:01 UTC
Digital Knowledge LMS exploited via hardcoded ASP.NET keys (CVE-2026-5426)highbug_reportVulnerability
bug_reportVulnerability

Digital Knowledge LMS exploited via hardcoded ASP.NET keys (CVE-2026-5426)

Digital Knowledge KnowledgeDeliver LMS (specific versions not disclosed). Vulnerability stems from hard-coded ASP.NET machine keys enabling authentication bypass and remote code execution.

CVE-2026-542626 May · 03:19 UTC
Dutch Authorities Disrupt Hosting Infrastructure Linked to Russian Opshighperson_alertThreat Actor
person_alertThreat Actor

Dutch Authorities Disrupt Hosting Infrastructure Linked to Russian Ops

This operation involves Russian state-sponsored cyber activity facilitated through compromised Internet hosting infrastructure in the Netherlands. The arrested co-owners operated hosting companies that assumed control of Stark Industries Solutions' t…

Stark Industries Solutions25 May · 11:21 UTC
FBI warns of Kali365 phishing-as-a-service targeting Microsoft 365highperson_alertThreat Actor
person_alertThreat Actor

FBI warns of Kali365 phishing-as-a-service targeting Microsoft 365

Kali365 is a phishing-as-a-service (PhaaS) platform that enables threat actors to conduct credential harvesting and account takeover operations against Microsoft 365 users.

Microsoft25 May · 10:45 UTC
OutSystems Lifetime authorization bypass via user-controlled keyhighbug_reportVulnerability
bug_reportVulnerability

OutSystems Lifetime authorization bypass via user-controlled key

OutSystems Lifetime software. Specific affected versions not disclosed. Vulnerability allows authorization bypass through improper handling of user-controlled keys.

CVE-2026-4012725 May · 08:55 UTC
Lazarus Group deploys RemotePE cross-platform RAT against finance sectorhighperson_alertThreat Actor
person_alertThreat Actor

Lazarus Group deploys RemotePE cross-platform RAT against finance sector

Lazarus Group is a North Korean state-sponsored advanced persistent threat (APT) actor attributed to the Reconnaissance General Bureau (RGB). The group is financially motivated, conducting operations to generate revenue for the DPRK regime through th…

The Hacker News25 May · 07:32 UTC
Laravel Lang packages compromised to deliver credential-stealing malwarehighbug_reportVulnerability
bug_reportVulnerability

Laravel Lang packages compromised to deliver credential-stealing malware

Laravel Lang localization packages distributed via Composer. Affects developers who installed or updated compromised packages during the attack window. Specific package names and versions not yet publicly disclosed.

Laravel23 May · 18:48 UTC
Supply chain attack compromises 8 Packagist packages with malicious binaryhighbug_reportVulnerability
bug_reportVulnerability

Supply chain attack compromises 8 Packagist packages with malicious binary

Eight Composer packages on Packagist containing JavaScript components. Malicious code injected into package.json files executes a Linux binary from GitHub Releases. Downstream projects using these packages are affected.

Packagist23 May · 14:07 UTC
Italy Dismantles CINEMAGOAL Piracy Network Targeting Streaming PlatformshighpublicGeopolitical
publicGeopolitical

Italy Dismantles CINEMAGOAL Piracy Network Targeting Streaming Platforms

The disruption of the CINEMAGOAL piracy ecosystem represents a law enforcement action against organized digital piracy infrastructure rather than a state-sponsored cyber operation.

Netflix23 May · 12:23 UTC
Anthropic Glasswing project finds 10,000+ critical flaws in key softwarehighbug_reportVulnerability
bug_reportVulnerability

Anthropic Glasswing project finds 10,000+ critical flaws in key software

Widely used, systemically important software (specific products not disclosed). Over 10,000 high- or critical-severity vulnerabilities identified since project launch last month.

<UNKNOWN>23 May · 09:55 UTC
Laravel-Lang packages compromised to deliver credential-stealing malwarehighbug_reportVulnerability
bug_reportVulnerability

Laravel-Lang packages compromised to deliver credential-stealing malware

Multiple Laravel-Lang PHP packages compromised: laravel-lang/lang, laravel-lang/http-statuses, laravel-lang/attributes, and laravel-lang/actions. Affects Laravel PHP applications using these localization packages.

Laravel-Lang23 May · 07:51 UTC
First VPN Service dismantled by European and North American authoritieshighperson_alertThreat Actor
person_alertThreat Actor

First VPN Service dismantled by European and North American authorities

First VPN Service was a criminal VPN infrastructure provider that facilitated cybercrime operations for approximately 25 ransomware groups. The service enabled threat actors to obscure their geographic origins and true IP addresses during malicious a…

The Hacker News22 May · 15:35 UTC
Dutch authorities dismantle hosting infrastructure linked to cyber opshighpublicGeopolitical
publicGeopolitical

Dutch authorities dismantle hosting infrastructure linked to cyber ops

The Netherlands has emerged as a key jurisdiction for enforcement against cyber-enabling infrastructure, reflecting both its role as a European internet hub and its proactive stance on transnational cybercrime.

BleepingComputer22 May · 15:24 UTC
F5 BIG-IP Exploitation Leads to Confluence Compromise and Lateral Movementhighperson_alertThreat Actor
person_alertThreat Actor

F5 BIG-IP Exploitation Leads to Confluence Compromise and Lateral Movement

The threat actor behind this campaign remains unattributed. Motivation appears to be credential theft and network persistence within enterprise environments.

F522 May · 14:53 UTC
Ghostwriter Targets Ukrainian Government with Prometheus-Themed Phishinghighperson_alertThreat Actor
person_alertThreat Actor

Ghostwriter Targets Ukrainian Government with Prometheus-Themed Phishing

Ghostwriter (also tracked as UAC-0057 and UNC1151) is a Belarus-aligned threat actor known for conducting information operations and cyber espionage campaigns.

The Hacker News22 May · 14:20 UTC
Screening Serpens: Iranian APT Targets Tech and Defense with RAT Malwarehighperson_alertThreat Actor
person_alertThreat Actor

Screening Serpens: Iranian APT Targets Tech and Defense with RAT Malware

Screening Serpens is an Iranian APT group attributed by Unit 42, conducting cyber espionage operations. The group is motivated by intelligence collection targeting technology and defense sectors, consistent with Iranian state interests in acquiring s…

Unit 42 (Palo Alto)22 May · 11:00 UTC
Megalodon campaign injects 5,718 malicious commits into GitHub reposhighperson_alertThreat Actor
person_alertThreat Actor

Megalodon campaign injects 5,718 malicious commits into GitHub repos

Megalodon is an automated supply chain attack campaign targeting GitHub repositories. The actor's motivation appears to be exfiltration of CI/CD environment data, including secrets, tokens, and credentials stored in GitHub Actions workflows.

GitHub22 May · 09:55 UTC
ROADtools Framework Misused in Nation-State Cloud Intrusionshighperson_alertThreat Actor
person_alertThreat Actor

ROADtools Framework Misused in Nation-State Cloud Intrusions

Multiple threat actors, including nation-state groups, are misusing the open-source ROADtools framework for cloud intrusions. ROADtools is a legitimate Azure AD reconnaissance toolkit designed for security assessments, but has been co-opted by advers…

Unit 42 (Palo Alto)22 May · 08:00 UTC
Canadian National Arrested for Operating KimWolf DDoS Botnethighperson_alertThreat Actor
person_alertThreat Actor

Canadian National Arrested for Operating KimWolf DDoS Botnet

A Canadian national arrested by U.S. and Canadian authorities for operating the KimWolf DDoS botnet infrastructure. The operator managed a large-scale botnet that compromised nearly two million devices globally, offering DDoS-for-hire services.

BleepingComputer22 May · 07:01 UTC
Jacob Butler Arrested for Operating Kimwolf DDoS Botnethighperson_alertThreat Actor
person_alertThreat Actor

Jacob Butler Arrested for Operating Kimwolf DDoS Botnet

Jacob Butler, also known as "Dort," is a 23-year-old Canadian national from Ottawa arrested by the U.S. Department of Justice for developing and operating the Kimwolf DDoS botnet.

The Hacker News22 May · 06:50 UTC
Dort Arrested for Operating Kimwolf IoT Botnet in Multi-Million Device DDoS Campaignhighperson_alertThreat Actor
person_alertThreat Actor

Dort Arrested for Operating Kimwolf IoT Botnet in Multi-Million Device DDoS Campaign

Dort is a 23-year-old cybercriminal based in Ottawa, Canada, suspected of developing and operating the Kimwolf IoT botnet. Motivated by launching large-scale DDoS attacks, doxing, and swatting campaigns, Dort leveraged compromised IoT devices to buil…

Krebs on Security21 May · 19:50 UTC
Chromium zero-day disclosed: JavaScript persists after browser closehighbug_reportVulnerability
bug_reportVulnerability

Chromium zero-day disclosed: JavaScript persists after browser close

Chromium-based browsers (Google Chrome, Microsoft Edge, Brave, Opera, Vivaldi) - specific affected versions not disclosed. Vulnerability remains unpatched at time of disclosure.

Google21 May · 16:13 UTC
NLnet Labs patches DoS vulnerabilities in Unbound DNS resolverhighbug_reportVulnerability
bug_reportVulnerability

NLnet Labs patches DoS vulnerabilities in Unbound DNS resolver

Unbound DNS resolver by NLnet Labs. Specific vulnerable versions not provided in advisory; patched versions available. Affects organizations running Unbound for DNS resolution services.

NLnet Labs21 May · 14:21 UTC
Showboat Linux Malware Targets Middle East Telecom Since Mid-2022highperson_alertThreat Actor
person_alertThreat Actor

Showboat Linux Malware Targets Middle East Telecom Since Mid-2022

The threat actor behind Showboat remains unattributed. The campaign demonstrates sophisticated targeting of telecommunications infrastructure in the Middle East, suggesting a motivated adversary with strategic intelligence collection objectives.

The Hacker News21 May · 12:17 UTC
Chinese APT Deploys Showboat and JFMBackdoor Against Telecom Sectorhighperson_alertThreat Actor
person_alertThreat Actor

Chinese APT Deploys Showboat and JFMBackdoor Against Telecom Sector

Chinese state-sponsored threat actors conducting cyber-espionage operations against telecommunications infrastructure. The actors demonstrate cross-platform capabilities with custom Linux and Windows malware tooling.

BleepingComputer21 May · 12:00 UTC
International Law Enforcement Seizes First VPN Service Used by Cybercriminalshighperson_alertThreat Actor
person_alertThreat Actor

International Law Enforcement Seizes First VPN Service Used by Cybercriminals

First VPN was a commercial VPN service exploited by multiple threat actors to anonymize their operations. The service provided infrastructure enabling cybercriminals to mask their origin during ransomware deployments and data exfiltration campaigns.

BleepingComputer21 May · 11:09 UTC
Microsoft Defender privilege escalation CVE-2026-41091 under active exploithighbug_reportVulnerability
bug_reportVulnerability

Microsoft Defender privilege escalation CVE-2026-41091 under active exploit

Microsoft Defender on Windows systems. Specific product versions not disclosed. Vulnerability allows local attackers to escalate privileges to SYSTEM level through improper link resolution handling.

CVE-2026-4109121 May · 08:55 UTC