Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 685 results
highperson_alertThreat ActorEuropol disrupts Amadey and StealC infrastructure, recovers 27M credentials
This report describes a law enforcement disruption operation led by Europol in partnership with private sector entities including Bitdefender, Bitsight, ESET, and Microsoft.
highperson_alertThreat ActorEuropol-led Operation Endgame disrupts Amadey and StealC infrastructure
Europol is a law enforcement agency coordinating international cybercrime investigations. In this context, Europol led Operation Endgame, a coordinated law enforcement action involving Microsoft and international partners targeting cybercriminal infr…
highbug_reportVulnerabilityMicrosoft DCU disrupts StealC and Amadey infostealer infrastructure
Organizations globally using Windows systems targeted by StealC and Amadey infostealer malware-as-a-service operations. Infrastructure takedown executed June 24, 2026.
highperson_alertThreat ActorKongTuke Deploys Mistic Backdoor in Multi-Sector Intrusions
KongTuke is a financially motivated threat actor operating as a ransomware access broker. The group specializes in gaining initial access to corporate networks and establishing persistent backdoor access, which is then sold or provided to ransomware…
highperson_alertThreat ActorU.S. seizes HuiOne Group assets, sanctions Prince Group entities
HuiOne Group and Prince Group are entities linked to cyber scam money laundering operations with infrastructure in Cambodia. HuiOne Group subsidiaries allegedly operated cloud computing infrastructure used to facilitate financial transactions related…
highbug_reportVulnerabilityMalicious AI skills in ClawHub marketplace evade scanners, deploy infostealers
ClawHub marketplace users consuming third-party AI skills. Specific affected products: OpenClaw and ClawHub platforms. Scope includes organizations deploying AI agents with marketplace-sourced skills that may contain evasive malware delivering infost…
highbug_reportVulnerabilityCisco Unified Communications Manager SSRF under active exploitation
Cisco Unified Communications Manager (CUCM). Specific affected versions not disclosed. SSRF vulnerability (CVE-2026-20230) allows attackers to force the server to make unauthorized requests to internal or external resources.
highpublicGeopoliticalTata Electronics confirms cyberattack and data leak on IT infrastructure
Tata Electronics, a subsidiary of India's Tata Group conglomerate, has confirmed a cyberattack that compromised portions of its IT infrastructure and resulted in data exfiltration.
highperson_alertThreat ActorClickFix Targets macOS with Terminal-Based Infostealer Campaign
ClickFix is a threat actor conducting social engineering campaigns that trick users into executing malicious commands. The actor leverages deceptive techniques to convince victims to manually run Terminal commands on macOS systems, facilitating the d…
highperson_alertThreat ActorScattered Spider Members Plead Guilty to Transport for London Attack
Scattered Spider (also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944 by various vendors) is a financially motivated cybercrime group known for sophisticated social engineering and identity-based attacks.
highperson_alertThreat ActorScattered Spider Members Plead Guilty to Transport for London Breach
Scattered Spider (G1015), also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944, is a financially motivated cybercrime group known for sophisticated social engineering and identity-based attacks.
highbug_reportVulnerabilityGitHub blocks pwn request attacks in actions/checkout starting June 2026
GitHub Actions workflows using actions/checkout with pull_request_target trigger. Organizations using GitHub Actions for CI/CD pipelines are affected. The security update applies to all repositories using the actions/checkout action after June 18, 20…
highbug_reportVulnerabilityLastPass breached via Klue supply chain attack; OAuth tokens stolen
LastPass customers. Attack vector: compromised Klue third-party service leading to OAuth token theft and unauthorized access to LastPass Salesforce environment containing customer data.
highbug_reportVulnerabilityTotolink EX1200L router vulnerable to stack buffer overflow (RCE)
Totolink EX1200L router software. Specific affected firmware versions not disclosed. Vulnerability is a stack-based buffer overflow enabling potential remote code execution.
highbug_reportVulnerabilityMalicious npm packages deliver Windows RAT to JavaScript developers
Three npm packages (aes-decode-runner-pro, postcss-minify-selector, postcss-minify-selector-parser) published within the past month. Total downloads: 145-615 per package. Affects Windows-based development environments using npm package manager.
highperson_alertThreat ActorWhatsApp VBScript Campaign Deploys ManageEngine RMM Across 9 Countries
This campaign represents an unattributed threat activity leveraging WhatsApp as an initial access vector. The actor's motivation appears to be establishing persistent remote access to victim systems through legitimate remote monitoring and management…
highbug_reportVulnerabilityWhatsApp malware campaign uses fake business docs to deploy VBScript RATs
WhatsApp users across multiple countries. Attack vector: social engineering via WhatsApp messages containing malicious VBScript files disguised as business documents. Enables remote access to Windows PCs.
highbug_reportVulnerabilityCloud bucket hijacking flaw exploits global namespace across AWS, Azure, GCP
AWS S3, Azure Blob Storage, and Google Cloud Storage bucket naming systems. Affects organizations using cloud storage services across all three major cloud providers.
FFmpeg 'PixelSmash' flaw enables RCE on Jellyfin, DoS on multiple apps
FFmpeg (version details not specified). Downstream impact: Jellyfin (remote code execution), Kodi, Emby, Nextcloud, PhotoPrism, OBS Studio (denial-of-service). Affects media processing and streaming applications using vulnerable FFmpeg libraries.
highperson_alertThreat ActorFortiBleed Campaign Targets FortiGate Devices with Credential Sniffers
FortiBleed is a campaign-level designation for coordinated activity targeting Fortinet FortiGate network security appliances. The campaign's primary objective is credential harvesting through the deployment of custom sniffers on compromised firewalls…
highbug_reportVulnerabilityShapedPlugin WordPress Pro plugins backdoored via compromised update channel
Multiple ShapedPlugin Pro WordPress plugins distributed through official licensed update channels. Exact plugin names and affected versions not specified.
highbug_reportVulnerabilityMicrosoft patches AutoJack vulnerability chain in AutoGen Studio
Microsoft AutoGen Studio - all versions prior to the patched release. AutoGen Studio is a low-code interface for building and managing AI agents. The vulnerability chain affects users who interact with untrusted web content while AutoGen Studio is ru…
highbug_reportVulnerabilityDifyTap flaws enable cross-tenant AI conversation theft in Dify platform
Dify open-source agentic workflow platform. Specific affected versions not disclosed. Vulnerability enables cross-tenant data access, affecting multi-tenant deployments and cloud-hosted instances.
highbug_reportVulnerabilityDual ransomware actors operate simultaneously in Microsoft environments
Organizations using Microsoft environments, particularly those with insufficient network segmentation and endpoint visibility. No specific product vulnerability; threat involves operational security gaps enabling parallel intrusions.
highbug_reportVulnerability29-year-old Squid heap over-read leaks HTTP credentials in default config
Squid web proxy, all versions containing FTP parsing code from 1997 onward. Vulnerability present in default configuration. Affects organizations using Squid as forward or reverse proxy.
highperson_alertThreat ActorRussian-speaking actor deploys OXLOADER to distribute CastleStealer
The threat actor is a Russian-speaking, financially motivated cybercrime operator leveraging malicious advertising infrastructure for initial access. The actor demonstrates capability in developing or acquiring custom malware tooling, including the p…
highperson_alertThreat ActorAryStinger Malware Infects 4,300+ Routers for Recon Operations
AryStinger is a newly discovered malware family identified by QiAnXin's XLab threat research team. Unlike traditional DDoS botnets, AryStinger is purpose-built for pre-attack reconnaissance and distributed proxy operations.
highbug_reportVulnerabilityAryStinger botnet compromises 4,000+ legacy D-Link routers as proxies
Over 4,000 outdated D-Link routers worldwide, specifically legacy models no longer receiving security updates. Exact models not specified in available data.
highperson_alertThreat ActorPrinz Eugen ransomware targets recently modified files, omits ransom note
Prinz Eugen is a newly identified ransomware family characterized by unconventional operational tactics. Unlike traditional ransomware operations that encrypt files indiscriminately and leave detailed ransom notes, Prinz Eugen employs a selective enc…
highbug_reportVulnerabilityNorth Korean APT compromised 140+ npm packages via Mastra AI framework
Mastra AI framework and over 140 dependent npm packages. Organizations using Mastra AI or downstream dependencies in Node.js/JavaScript applications are affected.