Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 231 results
highperson_alertThreat ActorStubMaker Campaign Deploys 16 Typosquatted RubyGems to Steal Credentials
StubMaker is a typosquatting campaign tracked by OpenSourceMalware researchers, discovered on August 15, 2026. The campaign operators published 16 malicious RubyGems packages under user accounts "mod8rz41mje" (Riley Miller) and "rbq95bwt6q" (Alex Dav…
highbug_reportVulnerabilityEvooo1Bot botnet exploits 18 CVEs to turn edge devices into SOCKS5 proxies
Internet-facing Linux-based edge devices including routers (NETGEAR, Tenda, D-Link, TP-Link, Zyxel), IP cameras (Hikvision), enterprise appliances (Alcatel OmniPCX, Mitsubishi ME-RTU, Telesquare SDT-CW3B1/TLR-2005KSH), and servers running vulnerable…
highbug_reportVulnerabilityLarge-scale DDoS campaign disrupts Threema encrypted messaging service
Threema secure messaging service (cloud-hosted instances). Users in Switzerland, India, and China reported outages. Threema On-Prem customers unaffected as they use independent infrastructure. Colocation partner Nine also targeted.
highbug_reportVulnerabilityAmnesiaStealer malware hijacks macOS browser sessions via live remote control
macOS users targeted via ClickFix campaigns using fake GitHub pages. Affects 16 Chromium-based browsers including Chrome, Edge, Brave, Opera, Vivaldi, Arc, and Chromium.
highbug_reportVulnerabilityEvooo1Bot: Mirai-based botnet targets Linux gateways as SOCKS5 proxies
Internet-facing Linux gateway devices (routers, firewalls, edge appliances). Specific vendors and models not disclosed. Mirai-based malware with modular architecture targeting devices with weak credentials or known vulnerabilities.
highperson_alertThreat ActorJewelbug APT Conducts Dual-Track Espionage and Crypto Fraud
Jewelbug (also tracked as Earth Alux and REF7707) is a China-based threat actor conducting parallel espionage and financially-motivated operations. The group targets government and military entities across the Middle East, Southeast Asia, and South A…
highperson_alertThreat ActorCity-Forum Campaign Targets Salesforce and ServiceNow Portals
City-Forum is an ongoing data theft campaign, not a formally attributed threat actor group. The campaign has been active since at least March 2025 and is characterized by consistent infrastructure use—a single IP address (158.220.87.79) hosted by Ger…
highbug_reportVulnerabilityWindRelay NFC relay malware + SpyNote RAT steal cards, take loans
Android devices in Czechia, Slovakia, and Slovenia. WindRelay NFC relay malware deployed alongside SpyNote RAT (and variants SpyMax, CypherRAT). 24 WindRelay samples identified on VirusTotal from November 2025 to July 2026.
highbug_reportVulnerability737 fake Chrome VPN extensions route traffic through attacker SOCKS5 proxies
Google Chrome Web Store users who installed any of 737 malicious extensions impersonating VPN/proxy services (Proton VPN, NordVPN, Surfshark, ExpressVPN, Cloudflare 1.1.1.1). Approximately 75,000 downloads recorded, primarily Russian users.
highperson_alertThreat ActorCybercriminals Target Social Media Accounts for Sexual Exploitation
Unattributed cybercriminals conducting coordinated account compromise campaigns targeting social media and online service accounts belonging to adults, children, and student-athletes in the United States.
highperson_alertThreat ActorSandworm deploys trojanized WireGuard VPN via fake IT job offers
Sandworm (also tracked as APT44, UAC-0145 sub-cluster) is a Russian-linked advanced persistent threat group notorious for targeting critical infrastructure and government entities, particularly in Ukraine and other countries.
highperson_alertThreat ActorKimwolf v7 Botnet Adds HTTP/2 DDoS with Browser Fingerprinting
Kimwolf (also tracked as AISURU) is an Android and IoT botnet operation active since at least mid-2024. The threat actors behind Kimwolf have demonstrated continuous evolution in their tooling, targeting Android TV boxes since August 2025 and Linux I…
highperson_alertThreat ActorUAC-0145 Targets Ukrainian IT Workers via Fake Job Recruitment Campaign
UAC-0145 is a threat cluster operating as a subgroup within Sandworm (also tracked as APT44, Seashell Blizzard, UAC-0002, ELECTRUM, Telebots, IRON VIKING), a sophisticated nation-state hacking group affiliated with Russia's GRU military intelligence.…
highbug_reportVulnerabilityKimwolf v7 botnet targets Android IoT with HTTP/2 DDoS, ENS C2 resolution
Android TV boxes and set-top boxes with unauthenticated Android Debug Bridge (ADB) exposed on port 5555. Primarily affects devices accessible via residential proxy services. ARM-based Android IoT devices running vulnerable configurations.
highbug_reportVulnerabilityAeternum botnet uses Polygon blockchain for decentralized C2 infrastructure
Windows systems infected with Aeternum C++ botnet loader (Build.exe). The malware targets Windows environments and uses Polygon blockchain smart contracts for command and control, making traditional domain/IP-based blocking ineffective.
highperson_alertThreat ActorThe Com cybercrime collective member sentenced for sextortion
The Com (short for "Community") is a loose-knit online cybercrime collective that targets children and teenagers through multiple specialized subgroups.
highperson_alertThreat ActorHead Mare Exploits TrueConf Flaws to Deploy PhantomCore Backdoor
Head Mare is a threat actor conducting targeted intrusion operations against Russian organizations across critical infrastructure and technology sectors.
highbug_reportVulnerabilityClickFix attacks deliver macOS stealer targeting crypto wallets and Keychain
macOS systems (all CPU architectures). Users tricked into pasting malicious commands into Terminal. Targets cryptocurrency wallets (Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, XRP), browser passwords, Apple iCloud Keychain, and cached credentials.
highperson_alertThreat ActorUNC6671 Conducts Vishing Attacks to Steal SaaS Credentials
UNC6671 is a financially motivated data extortion group that emerged in early January 2026. The actor operates multiple extortion brands including Redact, Pink (CL-CRI-1147), Helix, and Falcon (CL-CRI-1182), and previously operated under the BlackFil…
highbug_reportVulnerabilityTwo H1 2026 campaigns use compromised email and clipboard hijacking
Campaign 1: Users in Czechia, Slovakia, Poland, and Lithuania targeted by GepyS banking malware via compromised corporate email accounts. Campaign 2: Cryptocurrency users globally affected by Rust-based clipboard hijacker monitoring 21 blockchain typ…
highbug_reportVulnerabilityAitM phishing campaign targets Microsoft 365 for payroll email theft
Microsoft 365 accounts across healthcare, education, manufacturing, government, and professional services sectors in the U.S., Canada, and Europe. Hundreds of organizations targeted in July 2026, with focus on payroll, HR, and finance personnel.
highbug_reportVulnerabilityClickFix campaign delivers Go-based macOS stealer targeting crypto wallets
macOS users across all versions; targets cryptocurrency wallets (Bitcoin, Ethereum, Litecoin, Dogecoin, Monero, XRP), browser password databases, Apple Keychain, and cached browser credentials.
highperson_alertThreat ActorUNC6671 extortion group targets financial sector via vishing attacks
UNC6671 is a financially motivated extortion group tracked by Google Threat Intelligence Group (GTIG) that operates under multiple public brands including BlackFile, Redact, Pink, Helix, and Falcon.
highperson_alertThreat ActorCybercriminals Steal AI API Keys via Token Jacking for Resale
Cybercriminals targeting the AI development ecosystem are motivated by financial gain through the theft and resale of API keys (tokens) for premium AI platforms.
highperson_alertThreat ActorClickFix Campaign Uses Browser Fingerprinting to Target macOS Users
ClickFix is a macOS-focused social engineering campaign tracked by Microsoft Threat Intelligence. The operators remain unidentified, but the campaign demonstrates sophisticated evasion capabilities through server-side browser fingerprinting across mo…
highperson_alertThreat ActorPoipet Scam Network Leveraged ChatGPT for Multi-Scheme Fraud Operations
The Poipet scam network is a Cambodia-based organized criminal operation originating from Poipet, a city with extensive ties to scam compounds and human trafficking.
highbug_reportVulnerabilityPhishing campaign exploits COLDCARD wallet fears to deploy ScreenConnect RAT
COLDCARD hardware wallet users targeted via phishing emails. Attack delivers ConnectWise ScreenConnect remote access tool via malicious batch file (Coldcard_Diagnostic_Tool.bat) hosted on GitHub.
highbug_reportVulnerabilitymacOS ClickFix campaign adds fingerprinting to evade detection
macOS users targeted via 250+ algorithmically generated domains (e.g., filecopperbasket, apricotfilepoint[.]com). Campaign delivers MacSync and Atomic Stealer (AMOS) infostealers. All macOS versions susceptible to social engineering technique.
highperson_alertThreat ActorKali365 Campaign Weaponizes Microsoft Device Code Flow Against US Firms
Kali365 is a device code phishing campaign targeting US organizations through abuse of legitimate Microsoft authentication mechanisms. The campaign leverages a phishing kit designed to trick victims into approving attacker-controlled device codes on…
highperson_alertThreat ActorGreatness PhaaS Expands to AiTM and Device-Code Phishing via RingCentral
Greatness is a phishing-as-a-service (PhaaS) platform active since at least mid-2022, operated by cybercriminals who sell access for $289/month via a Telegram channel with thousands of subscribers.