Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 78 results
highbug_reportVulnerabilityClickFix campaigns deploy three malware loaders via fake updates
Education and financial sector organizations targeted by ClickFix social engineering campaigns delivering BabaDeda Loader, Lorem Ipsum Loader, and Potemkin malware loaders through fake software update lures.
highperson_alertThreat ActorGhostTree Abuses NTFS Junctions to Evade Microsoft Defender Scans
GhostTree is a threat actor that has developed an evasion technique exploiting recursive NTFS junctions to bypass antivirus scanning. The actor targets the information technology sector and leverages inherent Windows file system features to create in…
highbug_reportVulnerabilitySprySOCKS malware expands to Windows in government-targeted attacks
Government organizations in at least four countries. Windows systems now targeted alongside previously known Linux variants. Specific Windows versions and attack vector not disclosed.
highperson_alertThreat ActorContagious Interview targets developers via recruitment-themed phishing
Contagious Interview (also tracked as DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, and DEV#POPPER) is a North Korean-aligned threat actor cluster that specializes in social engineering attacks against software developers and technology secto…
highperson_alertThreat ActorFBI disrupts Outsider Enterprise Chinese phishing-as-a-service platform
Outsider Enterprise is a Chinese phishing-as-a-service (PhaaS) operation disrupted by the FBI in coordination with Google and Black Lotus Labs. The actor operated thousands of phishing websites designed to harvest credit card data and passwords from…
highperson_alertThreat ActorChinese Cybercrime Network Weaponizes Google Gemini AI for SMS Phishing
A Chinese cybercrime network operating a phishing-as-a-service (PhaaS) platform called Outsider. The group weaponizes Google's Gemini AI to craft and conduct SMS-based phishing attacks (smishing) targeting American victims.
highperson_alertThreat ActorUNC1151/Ghostwriter Targets Polish Gmail Accounts in Phishing Campaign
UNC1151, also known as Ghostwriter, is a threat actor group attributed by FireEye/Mandiant that has conducted sustained information operations and cyber espionage activities.
highperson_alertThreat ActorINTERPOL arrests Guedz, admin of Sniper Dz phishing-as-a-service platform
Guedz is identified as the primary administrator of Sniper Dz, a phishing-as-a-service (PhaaS) platform that operated for approximately a decade across the Middle East and North Africa (MENA) region.
highbug_reportVulnerabilityNFCShare Android malware distributed via GitHub as fake banking app updates
Android mobile users, particularly customers of targeted banking applications. Malware distributed through GitHub repositories posing as legitimate banking app updates.
highperson_alertThreat ActorNSO Group linked to WhatsApp spear-phishing campaigns
NSO Group is an Israeli cyber intelligence firm that develops and sells commercial surveillance technology, primarily the Pegasus spyware platform. The company markets its tools to government clients for lawful interception and intelligence gathering…
highperson_alertThreat ActorUNC3753 Conducts Data Theft Extortion via Vishing and Physical Intrusion
UNC3753 is a financially motivated threat actor attributed by Mandiant. The group conducted a data theft extortion campaign targeting dozens of organizations in the United States between January and May 2026.
highperson_alertThreat ActorSilent Ransom Group targets U.S. legal sector via fake IT support
Silent Ransom Group is a threat actor conducting social engineering-driven intrusions against U.S. legal services and professional services organizations.
highbug_reportVulnerabilityAsin Android spyware targets Arabic-speaking users via fake apps
Android devices used by Arabic-speaking populations. Malware distributed through fake applications impersonating news sources, PDF utilities, and war-related content. Active campaigns identified since early 2025.
highperson_alertThreat ActorFBI Warns of FIFA World Cup 2026 Fraud Campaign with Banking Malware
This is a cybercrime campaign leveraging the FIFA World Cup 2026 tournament as a lure, rather than a single named threat actor. The campaign involves multiple financially motivated threat actors exploiting public interest in the tournament to distrib…
highperson_alertThreat ActorPCPJack Hijacks 230+ Cloud Servers for Covert SMTP Relay Network
PCPJack is a threat actor focused on compromising cloud infrastructure to establish illicit email relay networks. The actor has demonstrated capability to breach business servers across major cloud service providers (AWS, Google Cloud, Microsoft Azur…
highperson_alertThreat ActorDriveSurge Distributes Malware via ClickFix and FakeUpdate Campaigns
DriveSurge is a threat actor conducting large-scale malware distribution operations. The actor leverages compromised website infrastructure at scale, utilizing thousands of sites to host and deliver malicious payloads.
highbug_reportVulnerabilityMeta AI bot exploited to hijack high-profile Instagram accounts
Meta Instagram platform, specifically the AI-powered customer support bot used for account recovery. High-profile accounts including Obama White House and U.S. Space Force Chief Master Sergeant were compromised.
highbug_reportVulnerabilityMalware campaign infects 2,000 WordPress sites using Steam profiles for C2
Nearly 2,000 WordPress websites compromised. All WordPress versions potentially affected depending on initial infection vector (likely vulnerable plugins, themes, or weak credentials).
highperson_alertThreat ActorOperation Dragon Weave targets Czech and Taiwan entities with AdaptixC2
Operation Dragon Weave is a cyber espionage campaign linked to China-aligned threat actors. The campaign's motivation appears to be intelligence collection targeting government officials, researchers, academics, and professionals in the Czech Republi…
highbug_reportVulnerabilityDutch authorities dismantle botnet controlling 17M infected devices
At least 17 million infected devices globally including computers, tablets, smartphones, and IoT devices. Over 200 command-and-control servers located in the Netherlands were seized.
highbug_reportVulnerabilityThreat actors abuse ChatGPT sharing to host fake OpenAI outage pages
OpenAI ChatGPT users globally. Threat actors exploit ChatGPT's legitimate content-sharing feature (chatgpt.com shared links) to host convincing phishing pages that impersonate OpenAI outage notifications and distribute malware posing as the ChatGPT d…
highbug_reportVulnerabilityDutch authorities disrupt 17M-device botnet, seize 200+ servers
Approximately 17 million infected devices globally; over 200 servers seized from a Dutch hosting provider. Specific botnet malware family and affected device types not disclosed.
highperson_alertThreat ActorMini Shai-Hulud: Typosquatted npm Packages Target Developer Credentials
Mini Shai-Hulud is a threat actor campaign focused on compromising software development environments through supply chain attacks. The actor leverages typosquatting techniques against the npm package ecosystem to distribute malicious packages that ma…
highperson_alertThreat ActorGreyVibe Targets Ukraine with AI-Generated Lures and Custom Malware
GreyVibe is a threat cluster assessed with moderate confidence to be linked to Russian interests, based on targeting patterns and geopolitical alignment.
highbug_reportVulnerabilityBTMOB Android RAT offered as MaaS with custom phishing builder
Android devices targeted by BTMOB remote access trojan. No specific vendor or version restrictions; affects users who install malicious APKs distributed through phishing campaigns.
highperson_alertThreat ActorFBI warns of FIFA-impersonating fraud sites targeting 2026 World Cup
Unknown fraud operators are conducting financially motivated cybercrime campaigns targeting fans and consumers interested in the 2026 FIFA World Cup. These actors leverage social engineering and brand impersonation tactics to establish fraudulent web…
highperson_alertThreat ActorArctic Wolf exploits FortiClient EMS flaw for credential theft
Arctic Wolf is a threat actor exploiting a critical, patched vulnerability in FortiClient Endpoint Management Server (EMS) to deploy credential-stealing malware.
highperson_alertThreat ActorJINX-0164 Targets Cryptocurrency Orgs with macOS Malware
JINX-0164 is a previously undocumented threat actor with a financial motivation focused on digital asset theft. The group demonstrates technical sophistication through the development of custom macOS malware and operational tradecraft centered on soc…
highbug_reportVulnerabilityCryptojacking campaign uses SEO poisoning and AI chatbots for GPU malware
High-performance systems with GPUs accessed via search engines and AI chatbot platforms. No specific vendor or product vulnerability; targets users searching for legitimate software or information through poisoned search results and manipulated chatb…
highbug_reportVulnerabilityBanking trojans Grandoreiro and BTMOB target LATAM and Europe
Windows and Android devices in Latin America (Brazil, Mexico) and Europe (Spain, Portugal). Grandoreiro targets Windows systems at companies; BTMOB RAT targets Android mobile users in Brazil.