Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 685 results
highbug_reportVulnerabilityUnit 42 issues guidance on large-scale credential attack campaigns
Organizations using security vendor devices targeted in recent credential-based attack campaigns. No specific CVE; threat involves coordinated credential compromise attempts across multiple vendors' products.
highperson_alertThreat ActorIcarus Extortion Group Breaches Klue, Steals Salesforce OAuth Tokens
Icarus is an extortion-focused threat actor that has publicly claimed responsibility for breaching the market intelligence platform Klue. The group's motivation appears to be financially driven, targeting SaaS and market intelligence platforms to ste…
highbug_reportVulnerabilityGravity SMTP WordPress plugin under active exploit for info disclosure
Gravity SMTP WordPress plugin, affecting approximately 100,000 websites. Specific vulnerable versions not disclosed in available data.
highperson_alertThreat ActorGentlemen RaaS Deploys GentleKiller EDR Evasion Framework
Gentlemen is a ransomware-as-a-service (RaaS) operation that provides infrastructure, tooling, and support to affiliate threat actors. The group actively develops and distributes specialized frameworks to enhance affiliate success rates, including th…
highpublicGeopoliticalTexas Parks and Wildlife vendor breach exposes 3M+ records
The breach at a Texas state agency vendor underscores persistent vulnerabilities in third-party supply chains supporting U.S. public administration. While no attribution has been disclosed, the exposure of driver's license data and personally identif…
highbug_reportVulnerabilityAutoJack exploit chain enables RCE on AI browsing agents via malicious pages
AI browsing agents (autonomous web browsers with AI capabilities) that interact with privileged local services via JavaScript. Specific products and versions not disclosed in Microsoft's research disclosure.
highperson_alertThreat ActorSocGholish Infrastructure Disrupted in Operation Endgame Takedown
SocGholish is a threat actor known for compromising web infrastructure, particularly WordPress-based content management systems, to facilitate malware distribution and drive-by download attacks.
highperson_alertThreat ActorRussian-speaking actors compromise 86,644 FortiGate devices via FortiBleed
Russian-speaking threat actors are conducting the FortiBleed campaign, targeting internet-accessible FortiGate appliances at scale. The actors' specific motivation remains unclear from available data, though the mass compromise of 86,644 devices sugg…
highbug_reportVulnerabilitySalesforce disables Klue integration after OAuth token abuse exposes data
Salesforce customers using the Klue Battlecards app integration. OAuth tokens were abused to access customer data. Integration disabled as of June 11, 2026.
highbug_reportVulnerabilityF5 patches high-severity flaws in NGINX Open Source and Gateway Fabric
NGINX Open Source and NGINX Gateway Fabric (specific versions not provided). Four CVEs: CVE-2026-11311, CVE-2026-42055, CVE-2026-42530, CVE-2026-50107. Affects organizations running NGINX web servers, reverse proxies, API gateways, and Kubernetes ing…
highpublicGeopoliticalCISA warns of 74,000 Fortinet credentials exposed in FortiBleed leak
The exposure of approximately 74,000 Fortinet firewall and VPN credentials represents a significant supply-side vulnerability affecting critical infrastructure globally.
highbug_reportVulnerabilityApple Beats Studio Buds Bluetooth flaw allows unauthorized pairing
Apple Beats Studio Buds using Airoha Bluetooth audio SDK. Vulnerability affects devices prior to firmware update released by Apple. Attackers must be within Bluetooth range (typically <10 meters).
highperson_alertThreat ActorGentlemen RaaS Develops EDR Killer Tools for Affiliate Operations
Gentlemen is a ransomware-as-a-service (RaaS) operation that provides infrastructure, tools, and support to affiliate threat actors who conduct ransomware attacks.
highperson_alertThreat ActorNetNut Linked to Popa Android Botnet Enabling Proxy Fraud
NetNut is a residential proxy service operated by Alarum Technologies Ltd (NASDAQ: ALAR), a publicly-traded Israeli firm. Multiple security researchers have linked NetNut to the Popa Android botnet, which has compromised millions of consumer TV boxes…
highbug_reportVulnerabilityClipboard-stealing malware spreads via USB, targets crypto wallets
Windows systems with USB connectivity. Targets cryptocurrency wallet users. No specific vendor or product vulnerability; relies on user interaction with malicious Windows shortcut (.lnk) files on removable media.
highbug_reportVulnerabilityWeekly threat roundup: Claude abuse, npm poisoning, phishing campaigns
Multiple platforms and products: Claude AI chat interface, npm package ecosystem (NastyC2), OAuth device-code flows, browser extensions (unspecified), macOS systems, cloud management agents, and internet-exposed edge devices.
highbug_reportVulnerabilityWindows cryptocurrency clipper campaign uses USB worms and Tor C2
Windows systems with Windows Script Host and ActiveX enabled. Campaign active since February 2026 targeting cryptocurrency users via USB-based LNK worm propagation.
highperson_alertThreat ActorIcarus Threat Actor Exploits OAuth to Steal Salesforce Data via Klue
Icarus is a threat actor conducting an ongoing extortion campaign targeting organizations through supply chain compromise. The actor exploited OAuth authentication mechanisms to breach Klue, a market intelligence platform, gaining unauthorized access…
highperson_alertThreat ActorINC Ransomware Expands Operations Following LockBit and BlackCat Disruptions
INC is a ransomware-as-a-service (RaaS) operation that has emerged as a major threat actor since August 2023. The group operates a multi-affiliate model, providing ransomware tooling and infrastructure to criminal partners in exchange for a share of…
highperson_alertThreat ActorDragonForce Deploys Backdoor.Turn RAT via Microsoft Teams Infrastructure
DragonForce is a threat actor associated with ransomware operations. The group has demonstrated advanced capabilities in developing custom tooling and leveraging legitimate cloud infrastructure for command-and-control communications.
highperson_alertThreat ActorEvil Corp SocGholish botnet dismantled: 15,000 sites, 100+ servers
Evil Corp (also tracked as Indrik Spider, Manatee Tempest, DEV-0243, UNC2165) is a financially motivated cybercrime group linked to Russia. The group has operated since at least 2014 and is known for deploying banking trojans and ransomware variants…
highbug_reportVulnerabilityShapedPlugin WordPress plugins compromised in supply chain attack
Multiple WordPress plugins from ShapedPlugin vendor. Infected releases distributed to paying customers via official update mechanism. Specific plugin names and version numbers not disclosed in provided data.
highbug_reportVulnerabilityApple patches Bluetooth eavesdropping flaw in Beats Studio Buds
Apple Beats Studio Buds wireless earbuds. Specific firmware versions not disclosed. Vulnerability requires attacker to be within Bluetooth range (typically 10-30 meters).
highbug_reportVulnerabilityNCSC warns of active global campaign targeting Fortinet firewalls and VPNs
Fortinet firewalls and VPN gateways globally. Specific product lines and versions not disclosed in alert. Organizations using FortiGate, FortiOS, or FortiClient VPN services should assume potential exposure.
highbug_reportVulnerabilityPoisoned npm package compromises 140+ projects via postinstall payload
140+ projects using a malicious npm package containing a hidden postinstall script. Affects Node.js/JavaScript development environments consuming npm dependencies. Specific package name not disclosed in summary.
highbug_reportVulnerabilityCryptocurrency clipper malware with worm propagation targets Windows
Windows systems globally. No specific product vulnerability; threat relies on social engineering, malicious downloads, or lateral movement. All cryptocurrency wallet users on Windows are potential targets.
highbug_reportVulnerabilityMicrosoft Defender zero-day CVE-2026-50656 enables privilege escalation
Microsoft Defender Malware Protection Engine across all Windows versions. Specific affected engine versions not disclosed. Impacts enterprise and consumer deployments relying on Microsoft Defender for endpoint protection.
highperson_alertThreat ActorJunior Hacker targets French automotive sector with credential theft
Junior Hacker is a French-speaking threat actor targeting small businesses in the French automotive sector. The actor demonstrates financially motivated objectives, focusing on credential theft for banking and email access.
highbug_reportVulnerabilityMalicious AI plugins on JetBrains Marketplace exfiltrate developer API keys
JetBrains Marketplace users who installed any of 15+ malicious plugins impersonating AI coding assistants (DeepSeek and other LLM-based tools). Affects developers using JetBrains IDEs (IntelliJ IDEA, PyCharm, WebStorm, etc.).
highpublicGeopoliticalUK NCSC: Hostile states linked to 75% of critical infrastructure attacks
The NCSC assessment underscores the strategic shift in cyber threat landscape from predominantly criminal actors to state-aligned operations targeting national critical infrastructure.