Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 685 results
highpublicGeopoliticalFormer Iowa school IT employee sentenced for insider cyberattack
This incident represents a domestic insider threat case within the United States education sector, rather than a state-sponsored or geopolitically motivated cyberattack. The prosecution and sentencing reflect U.S.
highpublicGeopoliticalUS orders Anthropic to restrict foreign access to advanced AI models
The directive appears to represent an expansion of US export control philosophy into the AI domain, treating advanced language models as dual-use technologies with national security implications.
highpublicGeopoliticalU.S. orders Anthropic to suspend foreign access to advanced AI models
The directive represents an escalation in U.S. efforts to control the diffusion of advanced artificial intelligence capabilities, treating frontier AI models as dual-use technologies with strategic implications.
highperson_alertThreat ActorChinese Cybercrime Network Weaponizes Google Gemini AI for SMS Phishing
A Chinese cybercrime network operating a phishing-as-a-service (PhaaS) platform called Outsider. The group weaponizes Google's Gemini AI to craft and conduct SMS-based phishing attacks (smishing) targeting American victims.
highbug_reportVulnerability10-year-old phpBB auth bypass enables attacker login as any user
phpBB forum software, versions spanning approximately 10 years (specific affected versions not disclosed). All installations running unpatched versions are vulnerable.
highperson_alertThreat ActorConti Operator Pleads Guilty After Extradition to United States
Conti is a prolific ransomware-as-a-service (RaaS) operation that emerged in 2020 and became one of the most active and financially successful cybercrime groups before its infrastructure was leaked and operations fragmented in 2022.
highbug_reportVulnerabilityAI coding agents vulnerable to code execution via crafted Sentry errors
AI coding agents (e.g., GitHub Copilot, Cursor, Aider) integrated with Sentry error-tracking platform. Affects development environments where AI agents have code execution permissions and process Sentry error reports.
highperson_alertThreat ActorUNC1151/Ghostwriter Targets Polish Gmail Accounts in Phishing Campaign
UNC1151, also known as Ghostwriter, is a threat actor group attributed by FireEye/Mandiant that has conducted sustained information operations and cyber espionage activities.
highpublicGeopoliticalNovo Nordisk discloses clinical trial data breach in Denmark
The breach at Novo Nordisk, a Danish pharmaceutical giant controlling approximately 50% of the global insulin market, highlights the strategic vulnerability of critical healthcare infrastructure.
highperson_alertThreat ActorINTERPOL arrests Guedz, admin of Sniper Dz phishing-as-a-service platform
Guedz is identified as the primary administrator of Sniper Dz, a phishing-as-a-service (PhaaS) platform that operated for approximately a decade across the Middle East and North Africa (MENA) region.
highpublicGeopoliticalFrench Government Messaging Platform Tchap Breached, 73,000 Accounts Affected
The compromise of Tchap, France's sovereign encrypted messaging solution developed as an alternative to foreign platforms, represents a significant breach of government communications infrastructure.
highperson_alertThreat ActorEuropol Disrupts AudiA6 Cryptocurrency Laundering Service
AudiA6 was a cryptocurrency laundering service utilized by ransomware gangs and cybercriminal networks to obfuscate and legitimize illicit proceeds. The service facilitated the conversion and movement of cryptocurrency obtained through ransomware ope…
highpublicGeopoliticalJapanese utility loses drive with 10.9M customer records
The incident at Kyushu Electric Power Co., Inc. represents a physical security failure rather than a cyber intrusion, but underscores the vulnerability of critical infrastructure operators to data exposure.
highbug_reportVulnerabilityOpenClaw AI agent vulnerable to prompt injection via vCards and location pins
OpenClaw self-hosted AI agent platform, all versions. Vulnerability affects input processing mechanisms for vCards, location pins, and potentially other structured data formats.
highbug_reportVulnerabilityBitLocker bypass via recovery partition XML files (GreatXML)
Windows BitLocker encryption on systems with recovery partitions. All Windows versions with BitLocker enabled are potentially affected. Specific version scope not yet published.
highperson_alertThreat ActorThe Gentlemen ransomware group claims 478 victims via multi-RaaS model
The Gentlemen is a financially motivated ransomware threat group that has claimed 478 victims through a hybrid operational model. Initially operating as an affiliate leveraging multiple ransomware-as-a-service (RaaS) platforms—including LockBit, Qili…
highperson_alertThreat ActorLaw Enforcement Dismantles AudiA6 Cryptocurrency Laundering Service
AudiA6 was a cryptocurrency laundering service that facilitated money laundering operations for ransomware actors and other cybercriminals. The service allegedly processed over $380 million in illicit proceeds before being dismantled by law enforceme…
highpublicGeopoliticalSouth Korea issues record $409M fine to Coupang for 37M-user breach
The unprecedented fine against Coupang reflects South Korea's increasingly assertive regulatory posture on data protection, aligning Seoul with global trends toward stringent enforcement of privacy frameworks.
highpublicGeopoliticalCISA mandates 3-day patching for exploited flaws in federal agencies
The directive represents a significant tightening of federal cybersecurity posture in response to persistent exploitation of known vulnerabilities by both state-sponsored and criminal actors.
highperson_alertThreat ActorOceanLotus Targets Vietnamese Infrastructure with SPECTRALVIPER Backdoor
OceanLotus (also tracked as APT32, SeaLotus, APT-C-00, and Canvas Cyclone) is a Vietnam-aligned advanced persistent threat group attributed by multiple vendors to conducting cyber espionage operations.
highpublicGeopoliticalUniversity of Nottingham breach exposes 450,000+ student records
The breach at the University of Nottingham represents a significant compromise of a major UK higher education institution, affecting a substantial population of current and former students.
highbug_reportVulnerabilitynpm v12 disables install scripts by default to block supply chain attacks
npm version 12 and later. All Node.js projects using npm for package management. Breaking change affects packages that legitimately rely on install/postinstall lifecycle hooks.
highbug_reportVulnerabilityActive exploitation of path traversal in Langflow AI platform
Langflow AI development platform. Specific affected versions not disclosed. Impacts internet-exposed Langflow servers vulnerable to arbitrary file write via path traversal (CVE-2026-5027).
highbug_reportVulnerabilityMiasma credential-stealing framework source code leaked on GitHub
Open-source software ecosystems and their supply chains. Organizations consuming packages from public repositories (npm, PyPI, RubyGems, etc.) are at increased risk. No specific vendor or product version affected; threat is ecosystem-wide.
highperson_alertThreat ActorShinyHunters Targets Oracle PeopleSoft Servers in Mass Data Theft
ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has gained notoriety for breaching numerous organizations and exfiltrating sensitive data, which is then used for extortion…
highperson_alertThreat ActorChina-Nexus Actors Expand JDY Botnet to 1,500+ IoT/SOHO Devices
China-nexus state-sponsored threat actors operating the JDY botnet infrastructure. The actors leverage compromised small office/home office (SOHO) routers and IoT devices to build a distributed scanning platform for cyber reconnaissance operations.
highperson_alertThreat ActorVolt Typhoon Expands JDY Botnet Operations Against U.S. Military
Volt Typhoon (also tracked as BRONZE SILHOUETTE, Vanguard Panda, DEV-0391, and UNC3236) is a Chinese state-sponsored APT group attributed to conducting cyber espionage operations targeting critical infrastructure.
highbug_reportVulnerabilityCisco Catalyst SD-WAN Manager actively exploited (CVE-2026-20245)
Cisco Catalyst SD-WAN Manager. Specific affected versions not disclosed. Vulnerability involves improper encoding or escaping of output (CVSS 7.8). Also affects products from Google and Arista (details not provided).
highperson_alertThreat ActorThe Gentlemen Ransomware: Aggressive Affiliate Model Drives Rapid Growth
The Gentlemen is a ransomware-as-a-service (RaaS) operation that has rapidly ascended to become the second most active ransomware group by victim count.
highbug_reportVulnerabilityMicrosoft patches actively exploited XSS zero-day in Exchange Server OWA
Microsoft Exchange Server (all versions with Outlook Web Access enabled). Specific patched versions not provided. Affects organizations exposing OWA to users.