Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 685 results
Active filter:tag: #high✕ clear
Scattered Spider Member Extradited to U.S. from Estoniahighperson_alertThreat Actor
person_alertThreat Actor

Scattered Spider Member Extradited to U.S. from Estonia

Scattered Spider (G1015), also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944, is a financially motivated threat actor collective known for sophisticated social engineering and identity-based attacks.

BleepingComputer2 Jul · 06:58 UTC
FortiBleed Campaign Linked to INC and Lynx Ransomware Operationshighperson_alertThreat Actor
person_alertThreat Actor

FortiBleed Campaign Linked to INC and Lynx Ransomware Operations

The FortiBleed campaign is a financially-motivated credential theft operation attributed to actors associated with the INC and Lynx ransomware groups. The campaign focuses on exploiting FortiGate devices to harvest credentials, which are subsequently…

Fortinet2 Jul · 06:00 UTC
Fake GitHub PoC repos deliver ChocoPoC trojan to security researchershighbug_reportVulnerability
bug_reportVulnerability

Fake GitHub PoC repos deliver ChocoPoC trojan to security researchers

Vulnerability researchers and security professionals using GitHub to access proof-of-concept exploit code. The ChocoPoC malware targets Windows systems, stealing credentials, browser data, and files while establishing remote shell access.

GitHub2 Jul · 05:24 UTC
ShinyHunters Breaches Medtronic Healthcare Device Manufacturerhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Breaches Medtronic Healthcare Device Manufacturer

ShinyHunters is a financially-motivated cybercrime group known for large-scale data breaches and database exfiltration operations. The group has been active since at least 2020, targeting organizations across multiple sectors to steal sensitive data…

Medtronic2 Jul · 02:25 UTC
INC and Lynx Ransomware Groups Exploit FortiBleed for Credential Thefthighperson_alertThreat Actor
person_alertThreat Actor

INC and Lynx Ransomware Groups Exploit FortiBleed for Credential Theft

INC and Lynx are ransomware threat actors linked to the FortiBleed credential theft campaign. These groups operate with the primary motivation of financial gain through ransomware deployment.

Fortinet1 Jul · 19:37 UTC
Kubota North America reports month-long network intrusion in 2024highpublicGeopolitical
publicGeopolitical

Kubota North America reports month-long network intrusion in 2024

The extended unauthorized access to Kubota North America's network systems highlights vulnerabilities in critical infrastructure sectors, particularly manufacturing and agriculture.

Kubota1 Jul · 19:09 UTC
Trojanized GitHub PoC exploits deliver ChocoPoC RAT to researchershighbug_reportVulnerability
bug_reportVulnerability

Trojanized GitHub PoC exploits deliver ChocoPoC RAT to researchers

Cybersecurity researchers and security teams downloading proof-of-concept exploit code from GitHub repositories. ChocoPoC is a Python-based remote access trojan with command execution and data exfiltration capabilities.

BleepingComputer1 Jul · 18:08 UTC
Scattered Spider Member Extradited to U.S. on Federal Hacking Chargeshighperson_alertThreat Actor
person_alertThreat Actor

Scattered Spider Member Extradited to U.S. on Federal Hacking Charges

Scattered Spider (also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944) is a financially motivated threat actor group known for sophisticated social engineering and identity-based attacks.

The Hacker News1 Jul · 17:28 UTC
Massive SEO-Poisoned Campaign Distributes AsyncRAT via ScreenConnecthighperson_alertThreat Actor
person_alertThreat Actor

Massive SEO-Poisoned Campaign Distributes AsyncRAT via ScreenConnect

The threat actor behind this campaign remains unattributed. Motivation appears to be financially driven, consistent with commodity RAT deployment for access brokering, credential theft, or follow-on ransomware operations.

OBS Studio1 Jul · 15:53 UTC
DHS Confirms Breach of Homeland Security Information NetworkhighpublicGeopolitical
publicGeopolitical

DHS Confirms Breach of Homeland Security Information Network

The compromise of the Homeland Security Information Network (HSIN) represents a significant breach of a critical federal information-sharing infrastructure.

Department of Homeland Security1 Jul · 15:32 UTC
VEIL#DROP campaign delivers PureLogs stealer via Blogger pageshighperson_alertThreat Actor
person_alertThreat Actor

VEIL#DROP campaign delivers PureLogs stealer via Blogger pages

VEIL#DROP is a multi-stage malware delivery campaign identified by Securonix researchers. The campaign employs social engineering tactics and abuses legitimate Blogger platform infrastructure to distribute PureLogs, an information-stealing malware.

Google Blogger1 Jul · 15:18 UTC
Password-spray campaign hits Microsoft 365 with 81M login attemptshighbug_reportVulnerability
bug_reportVulnerability

Password-spray campaign hits Microsoft 365 with 81M login attempts

Microsoft 365 environments (Exchange Online, Azure AD/Entra ID, SharePoint, Teams). All organizations using M365 cloud services are potential targets. Attack focuses on user authentication endpoints.

Microsoft1 Jul · 14:38 UTC
Ousaban banking trojan targets Spain and Portugal via phishinghighbug_reportVulnerability
bug_reportVulnerability

Ousaban banking trojan targets Spain and Portugal via phishing

Windows users in Spain and Portugal. Ousaban banking trojan campaign using fake PDF lures with geolocation filtering and steganography techniques. No specific product vulnerability; threat actor campaign identified by Fortinet FortiGuard Labs in May…

Fortinet1 Jul · 13:26 UTC
DeepSeek AI Used to Generate Novel Browser-Based Ransomwarehighperson_alertThreat Actor
person_alertThreat Actor

DeepSeek AI Used to Generate Novel Browser-Based Ransomware

DeepSeek refers to the AI model leveraged by unknown threat actors to generate functional browser-based ransomware code. This marks the first documented instance of a frontier AI model being weaponized to create a novel ransomware technique.

Chromium1 Jul · 10:59 UTC
LLM hallucinations exploited for supply chain attacks via phantom domainshighbug_reportVulnerability
bug_reportVulnerability

LLM hallucinations exploited for supply chain attacks via phantom domains

Organizations using LLMs for development assistance, code generation, or package recommendations. Developers relying on AI-generated domain/package suggestions without verification.

Unit 42 (Palo Alto)30 Jun · 23:00 UTC
Trojanized Pyrogram forks on PyPI target Telegram bot developershighbug_reportVulnerability
bug_reportVulnerability

Trojanized Pyrogram forks on PyPI target Telegram bot developers

Python developers using PyPI packages for Telegram bot development. Malicious forks of Pyrogram library active since November 2024. Affects developers who may have installed compromised packages instead of legitimate Pyrogram.

PyPI30 Jun · 19:02 UTC
AI agents using Model Context Protocol vulnerable to tool poisoning attackshighbug_reportVulnerability
bug_reportVulnerability

AI agents using Model Context Protocol vulnerable to tool poisoning attacks

AI agents implementing Microsoft's Model Context Protocol (MCP). Specific products and versions not disclosed. Affects organizations deploying MCP-based AI agents with access to sensitive internal data and external tool integrations.

Microsoft30 Jun · 15:46 UTC
RustDuck Botnet Targets IoT Devices for DDoS Operationshighperson_alertThreat Actor
person_alertThreat Actor

RustDuck Botnet Targets IoT Devices for DDoS Operations

RustDuck is a two-stage malware family written in Rust, designed to compromise Internet of Things (IoT) devices including home routers, IP cameras, Android set-top boxes, and inadequately secured servers.

Generic routers30 Jun · 15:45 UTC
Fake Perplexity AI Chrome extension hijacks search traffic on Web Storehighbug_reportVulnerability
bug_reportVulnerability

Fake Perplexity AI Chrome extension hijacks search traffic on Web Store

Google Chrome users who installed the malicious Perplexity AI impersonator extension from the Chrome Web Store. Affects organizations and individuals using Chrome browser seeking AI productivity tools.

Google30 Jun · 13:46 UTC
Silent Swap Campaign Targets Cryptocurrency via Malicious Browser Extensionshighperson_alertThreat Actor
person_alertThreat Actor

Silent Swap Campaign Targets Cryptocurrency via Malicious Browser Extensions

Silent Swap is an active cybercrime campaign leveraging malicious browser extensions to conduct cryptocurrency theft. The operation distributes unsigned installers written in both .NET and Golang variants, masquerading as a legitimate Google Notes br…

Google30 Jun · 13:40 UTC
GuardFall shell injection bypasses safety checks in 10 of 11 AI coding agentshighbug_reportVulnerability
bug_reportVulnerability

GuardFall shell injection bypasses safety checks in 10 of 11 AI coding agents

10 out of 11 tested open-source AI coding and computer-use agents are vulnerable to GuardFall shell injection bypass. Only "Continue" agent demonstrated resistance.

Adversa AI30 Jun · 12:26 UTC
63% of iOS AI chatbot apps leak API keys via unencrypted network traffichighbug_reportVulnerability
bug_reportVulnerability

63% of iOS AI chatbot apps leak API keys via unencrypted network traffic

282 out of 444 iOS AI chatbot applications expose paid AI service credentials (API keys, tokens, backend endpoints) in plaintext network traffic. Affects apps integrating third-party AI services (OpenAI, Anthropic, Google, etc.).

The Hacker News30 Jun · 11:49 UTC
Pre-Planned Fraud Campaign Targets FIFA World Cup 2026 Across Sectorshighperson_alertThreat Actor
person_alertThreat Actor

Pre-Planned Fraud Campaign Targets FIFA World Cup 2026 Across Sectors

The threat actor behind this campaign remains unattributed. Motivation appears financially driven, leveraging the global interest in FIFA World Cup 2026 to conduct fraud operations.

The Hacker News30 Jun · 09:30 UTC
Aflac Japan breach exposes personal and financial datahighpublicGeopolitical
publicGeopolitical

Aflac Japan breach exposes personal and financial data

The breach at Aflac's Japan subsidiary underscores the persistent targeting of financial services firms operating in major economies. Japan represents a high-value target environment due to its advanced digital economy, aging population with signific…

Aflac30 Jun · 09:12 UTC
AirDrop and Quick Share flaws enable wireless DoS and security bypasshighbug_reportVulnerability
bug_reportVulnerability

AirDrop and Quick Share flaws enable wireless DoS and security bypass

Apple AirDrop and Google Quick Share wireless file transfer features on iOS, macOS, and Android devices. Specific affected versions not disclosed. Attack requires physical proximity (wireless range).

Apple30 Jun · 07:27 UTC
AI browsers leak credentials via BioShocking social engineering attackhighbug_reportVulnerability
bug_reportVulnerability

AI browsers leak credentials via BioShocking social engineering attack

Six AI browsers and assistants including OpenAI ChatGPT Atlas, Perplexity Comet, and Anthropic Claude browser extension. Attack exploits AI reasoning vulnerabilities to extract user credentials through game-based social engineering.

OpenAI30 Jun · 06:37 UTC
ShinyHunters Exploits Oracle PeopleSoft Zero-Day in Nissan Breachhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Exploits Oracle PeopleSoft Zero-Day in Nissan Breach

ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has established a pattern of exploiting vulnerabilities in enterprise applications to exfiltrate sensitive data, which is th…

Oracle29 Jun · 18:40 UTC
ShinyHunters Exploits Oracle PeopleSoft Zero-Day at NAIChighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Exploits Oracle PeopleSoft Zero-Day at NAIC

ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has historically targeted organizations to exfiltrate sensitive data, which is then leveraged for extortion or sold on under…

Oracle29 Jun · 18:30 UTC
Malicious Chrome Extension Impersonates Perplexity AI to Intercept Searcheshighperson_alertThreat Actor
person_alertThreat Actor

Malicious Chrome Extension Impersonates Perplexity AI to Intercept Searches

The threat actor behind this campaign remains unattributed. The operation demonstrates a financially or espionage-motivated adversary leveraging social engineering through brand impersonation of Perplexity AI, a popular search technology.

Google29 Jun · 16:40 UTC
U.S. offers $10M reward for intel on UNC5792 and UNC4221 APT groupshighperson_alertThreat Actor
person_alertThreat Actor

U.S. offers $10M reward for intel on UNC5792 and UNC4221 APT groups

UNC5792 and UNC4221 are threat actor groups attributed to Russian intelligence and military services. Both groups have been designated as high-priority targets by the U.S.

BleepingComputer29 Jun · 13:09 UTC