Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 415 results
Active filter:tag: #geopolitical✕ clear
LiteSpeed cPanel/WHM plugin under active exploit (CVE-2026-48172)criticalbug_reportVulnerability
bug_reportVulnerability

LiteSpeed cPanel/WHM plugin under active exploit (CVE-2026-48172)

LiteSpeed plugin for cPanel/WHM. Specific vulnerable versions not disclosed in provided data. Affects web hosting environments using LiteSpeed with cPanel/WHM integration.

CVE-2026-4817226 May · 14:28 UTC
Ubiquiti patches critical UniFi OS vulnerabilitiescriticalbug_reportVulnerability
bug_reportVulnerability

Ubiquiti patches critical UniFi OS vulnerabilities

Ubiquiti UniFi OS (specific versions not disclosed). Affects UniFi network management appliances including Dream Machine, Cloud Key, and similar devices running UniFi OS.

Ubiquiti26 May · 14:13 UTC
MuddyWater Q1 2026 espionage campaign hits nine countries via DLL side-loadinghighperson_alertThreat Actor
person_alertThreat Actor

MuddyWater Q1 2026 espionage campaign hits nine countries via DLL side-loading

MuddyWater (also tracked as Earth Vetala, MERCURY, Static Kitten, and Seedworm) is an Iranian state-sponsored APT group attributed to Iran's Ministry of Intelligence and Security (MOIS).

The Hacker News26 May · 13:48 UTC
Trend Micro Apex One & Vision One SEP flaws under active exploitcriticalbug_reportVulnerability
bug_reportVulnerability

Trend Micro Apex One & Vision One SEP flaws under active exploit

Trend Micro Apex One and Trend Micro Vision One Endpoint Security (SEP). Specific vulnerable versions not disclosed in summary; multiple vulnerabilities confirmed under active exploitation.

Trend Micro26 May · 08:17 UTC
India mandates 12-hour patching for critical vulnerabilitieshighpublicGeopolitical
publicGeopolitical

India mandates 12-hour patching for critical vulnerabilities

India's Computer Emergency Response Team (CERT-In) has introduced stringent vulnerability management requirements, mandating that organizations patch critical security flaws in internet-facing systems within 12 hours of notification.

The Hacker News26 May · 07:13 UTC
Critical vulnerability in Cisco Secure Workload requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical vulnerability in Cisco Secure Workload requires immediate patching

Cisco Secure Workload (specific versions not disclosed in advisory). CVE identifier not yet assigned or published.

Cisco26 May · 06:50 UTC
CISA orders emergency patching of exploited Drupal SQL injection flawcriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders emergency patching of exploited Drupal SQL injection flaw

Drupal CMS (specific versions not provided in alert). Affects U.S. government agencies and all organizations running vulnerable Drupal instances.

Drupal26 May · 06:46 UTC
Nimbus Manticore deploys MiniFast and MiniJunk V2 via phishing and SEO poisoninghighperson_alertThreat Actor
person_alertThreat Actor

Nimbus Manticore deploys MiniFast and MiniJunk V2 via phishing and SEO poisoning

Nimbus Manticore (also tracked as Screening Serpens and UNC1549) is an Iranian state-sponsored threat actor attributed to Iran's intelligence apparatus.

The Hacker News26 May · 05:13 UTC
ShinyHunters Breaches 7-Eleven, Exfiltrates 183K Recordshighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Breaches 7-Eleven, Exfiltrates 183K Records

ShinyHunters is a financially motivated cybercrime group known for large-scale data breaches and extortion operations targeting organizations across multiple sectors.

7-Eleven26 May · 05:01 UTC
Digital Knowledge LMS exploited via hardcoded ASP.NET keys (CVE-2026-5426)highbug_reportVulnerability
bug_reportVulnerability

Digital Knowledge LMS exploited via hardcoded ASP.NET keys (CVE-2026-5426)

Digital Knowledge KnowledgeDeliver LMS (specific versions not disclosed). Vulnerability stems from hard-coded ASP.NET machine keys enabling authentication bypass and remote code execution.

CVE-2026-542626 May · 03:19 UTC
Dutch Authorities Disrupt Hosting Infrastructure Linked to Russian Opshighperson_alertThreat Actor
person_alertThreat Actor

Dutch Authorities Disrupt Hosting Infrastructure Linked to Russian Ops

This operation involves Russian state-sponsored cyber activity facilitated through compromised Internet hosting infrastructure in the Netherlands. The arrested co-owners operated hosting companies that assumed control of Stark Industries Solutions' t…

Stark Industries Solutions25 May · 11:21 UTC
OutSystems Lifetime authorization bypass via user-controlled keyhighbug_reportVulnerability
bug_reportVulnerability

OutSystems Lifetime authorization bypass via user-controlled key

OutSystems Lifetime software. Specific affected versions not disclosed. Vulnerability allows authorization bypass through improper handling of user-controlled keys.

CVE-2026-4012725 May · 08:55 UTC
Lazarus Group deploys RemotePE cross-platform RAT against finance sectorhighperson_alertThreat Actor
person_alertThreat Actor

Lazarus Group deploys RemotePE cross-platform RAT against finance sector

Lazarus Group is a North Korean state-sponsored advanced persistent threat (APT) actor attributed to the Reconnaissance General Bureau (RGB). The group is financially motivated, conducting operations to generate revenue for the DPRK regime through th…

The Hacker News25 May · 07:32 UTC
Italy Dismantles CINEMAGOAL Piracy Network Targeting Streaming PlatformshighpublicGeopolitical
publicGeopolitical

Italy Dismantles CINEMAGOAL Piracy Network Targeting Streaming Platforms

The disruption of the CINEMAGOAL piracy ecosystem represents a law enforcement action against organized digital piracy infrastructure rather than a state-sponsored cyber operation.

Netflix23 May · 12:23 UTC
First VPN Service dismantled by European and North American authoritieshighperson_alertThreat Actor
person_alertThreat Actor

First VPN Service dismantled by European and North American authorities

First VPN Service was a criminal VPN infrastructure provider that facilitated cybercrime operations for approximately 25 ransomware groups. The service enabled threat actors to obscure their geographic origins and true IP addresses during malicious a…

The Hacker News22 May · 15:35 UTC
Dutch authorities dismantle hosting infrastructure linked to cyber opshighpublicGeopolitical
publicGeopolitical

Dutch authorities dismantle hosting infrastructure linked to cyber ops

The Netherlands has emerged as a key jurisdiction for enforcement against cyber-enabling infrastructure, reflecting both its role as a European internet hub and its proactive stance on transnational cybercrime.

BleepingComputer22 May · 15:24 UTC
CISA Contractor Leaks AWS GovCloud Keys on Public GitHub Repositorycriticalperson_alertThreat Actor
person_alertThreat Actor

CISA Contractor Leaks AWS GovCloud Keys on Public GitHub Repository

The threat actor is an insider—a contractor working for the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The individual intentionally published sensitive AWS GovCloud credentials and agency secrets to a public GitHub repository.

Amazon Web Services22 May · 14:34 UTC
Ghostwriter Targets Ukrainian Government with Prometheus-Themed Phishinghighperson_alertThreat Actor
person_alertThreat Actor

Ghostwriter Targets Ukrainian Government with Prometheus-Themed Phishing

Ghostwriter (also tracked as UAC-0057 and UNC1151) is a Belarus-aligned threat actor known for conducting information operations and cyber espionage campaigns.

The Hacker News22 May · 14:20 UTC
Trend Micro Apex One zero-day actively exploited in the wildcriticalbug_reportVulnerability
bug_reportVulnerability

Trend Micro Apex One zero-day actively exploited in the wild

Trend Micro Apex One on Windows systems. Specific affected versions not disclosed. Zero-day vulnerability with no CVE assigned yet.

Trend Micro22 May · 11:39 UTC
Screening Serpens: Iranian APT Targets Tech and Defense with RAT Malwarehighperson_alertThreat Actor
person_alertThreat Actor

Screening Serpens: Iranian APT Targets Tech and Defense with RAT Malware

Screening Serpens is an Iranian APT group attributed by Unit 42, conducting cyber espionage operations. The group is motivated by intelligence collection targeting technology and defense sectors, consistent with Iranian state interests in acquiring s…

Unit 42 (Palo Alto)22 May · 11:00 UTC
Canadian National Arrested for Operating KimWolf DDoS Botnethighperson_alertThreat Actor
person_alertThreat Actor

Canadian National Arrested for Operating KimWolf DDoS Botnet

A Canadian national arrested by U.S. and Canadian authorities for operating the KimWolf DDoS botnet infrastructure. The operator managed a large-scale botnet that compromised nearly two million devices globally, offering DDoS-for-hire services.

BleepingComputer22 May · 07:01 UTC
Jacob Butler Arrested for Operating Kimwolf DDoS Botnethighperson_alertThreat Actor
person_alertThreat Actor

Jacob Butler Arrested for Operating Kimwolf DDoS Botnet

Jacob Butler, also known as "Dort," is a 23-year-old Canadian national from Ottawa arrested by the U.S. Department of Justice for developing and operating the Kimwolf DDoS botnet.

The Hacker News22 May · 06:50 UTC
CISA: Langflow and Trend Micro Apex One flaws actively exploitedcriticalbug_reportVulnerability
bug_reportVulnerability

CISA: Langflow and Trend Micro Apex One flaws actively exploited

Langflow (CVE-2025-34291, CVSS 9.4, origin validation error) and Trend Micro Apex One (CVE unspecified). Both products confirmed under active exploitation. Specific affected versions not disclosed in summary.

CVE-2025-3429122 May · 03:47 UTC
Dort Arrested for Operating Kimwolf IoT Botnet in Multi-Million Device DDoS Campaignhighperson_alertThreat Actor
person_alertThreat Actor

Dort Arrested for Operating Kimwolf IoT Botnet in Multi-Million Device DDoS Campaign

Dort is a 23-year-old cybercriminal based in Ottawa, Canada, suspected of developing and operating the Kimwolf IoT botnet. Motivated by launching large-scale DDoS attacks, doxing, and swatting campaigns, Dort leveraged compromised IoT devices to buil…

Krebs on Security21 May · 19:50 UTC
Critical SQL injection in Drupal Core requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical SQL injection in Drupal Core requires immediate patching

Drupal Core, all versions (specific affected versions not disclosed in alert). Impacts all Drupal installations until patched.

Drupal21 May · 14:42 UTC
NLnet Labs patches DoS vulnerabilities in Unbound DNS resolverhighbug_reportVulnerability
bug_reportVulnerability

NLnet Labs patches DoS vulnerabilities in Unbound DNS resolver

Unbound DNS resolver by NLnet Labs. Specific vulnerable versions not provided in advisory; patched versions available. Affects organizations running Unbound for DNS resolution services.

NLnet Labs21 May · 14:21 UTC
Showboat Linux Malware Targets Middle East Telecom Since Mid-2022highperson_alertThreat Actor
person_alertThreat Actor

Showboat Linux Malware Targets Middle East Telecom Since Mid-2022

The threat actor behind Showboat remains unattributed. The campaign demonstrates sophisticated targeting of telecommunications infrastructure in the Middle East, suggesting a motivated adversary with strategic intelligence collection objectives.

The Hacker News21 May · 12:17 UTC
Chinese APT Deploys Showboat and JFMBackdoor Against Telecom Sectorhighperson_alertThreat Actor
person_alertThreat Actor

Chinese APT Deploys Showboat and JFMBackdoor Against Telecom Sector

Chinese state-sponsored threat actors conducting cyber-espionage operations against telecommunications infrastructure. The actors demonstrate cross-platform capabilities with custom Linux and Windows malware tooling.

BleepingComputer21 May · 12:00 UTC
Critical flaws in Sparx Pro Cloud Server actively exploited in the wildcriticalbug_reportVulnerability
bug_reportVulnerability

Critical flaws in Sparx Pro Cloud Server actively exploited in the wild

Sparx Systems Pro Cloud Server and Enterprise Architect products. Specific vulnerable versions not disclosed in summary; CERT.BE advisory should be consulted for version details.

Sparx Systems21 May · 06:49 UTC
18-Year-Old Infostealer Operator Arrested for Compromising 28K Accountshighperson_alertThreat Actor
person_alertThreat Actor

18-Year-Old Infostealer Operator Arrested for Compromising 28K Accounts

An 18-year-old individual from Odesa, Ukraine, identified by Ukrainian cyberpolice in coordination with U.S. law enforcement. The operator is suspected of deploying infostealer malware to harvest credentials and compromise user accounts.

BleepingComputer20 May · 19:36 UTC