Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 244 results
highpublicGeopoliticalFBI seizes NetNut proxy domains linked to two-million-device botnet
The FBI's seizure of domains associated with NetNut, a residential proxy service operated by Israeli firm Alarum Technologies, represents a significant law enforcement action targeting the infrastructure enabling large-scale botnet operations.
highperson_alertThreat ActorNetNut (Popa) Residential Proxy Botnet Disrupted by Google, FBI
NetNut, also tracked as Popa, operates a residential proxy network built on approximately 2 million compromised home devices. The actor monetizes this infrastructure by selling proxy services that route malicious traffic through legitimate residentia…
highperson_alertThreat ActorScattered Spider Member Extradited to U.S. from Estonia
Scattered Spider (G1015), also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944, is a financially motivated threat actor collective known for sophisticated social engineering and identity-based attacks.
criticalbug_reportVulnerabilityMicrosoft SharePoint RCE flaw under active exploitation (CVE-2026-45659)
Microsoft SharePoint Server, all versions vulnerable to deserialization attacks. Specific affected versions not yet disclosed.
highpublicGeopoliticalKubota North America reports month-long network intrusion in 2024
The extended unauthorized access to Kubota North America's network systems highlights vulnerabilities in critical infrastructure sectors, particularly manufacturing and agriculture.
highperson_alertThreat ActorScattered Spider Member Extradited to U.S. on Federal Hacking Charges
Scattered Spider (also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944) is a financially motivated threat actor group known for sophisticated social engineering and identity-based attacks.
highpublicGeopoliticalDHS Confirms Breach of Homeland Security Information Network
The compromise of the Homeland Security Information Network (HSIN) represents a significant breach of a critical federal information-sharing infrastructure.
highbug_reportVulnerabilityOusaban banking trojan targets Spain and Portugal via phishing
Windows users in Spain and Portugal. Ousaban banking trojan campaign using fake PDF lures with geolocation filtering and steganography techniques. No specific product vulnerability; threat actor campaign identified by Fortinet FortiGuard Labs in May…
criticalbug_reportVulnerabilityProgress Kemp LoadMaster RCE under active exploitation (CVE-2026-8037)
Progress Kemp LoadMaster load balancers. Specific affected versions not disclosed. Pre-authentication vulnerability allows unauthenticated remote attackers to execute OS commands.
highpublicGeopoliticalAflac Japan breach exposes personal and financial data
The breach at Aflac's Japan subsidiary underscores the persistent targeting of financial services firms operating in major economies. Japan represents a high-value target environment due to its advanced digital economy, aging population with signific…
highperson_alertThreat ActorShinyHunters Exploits Oracle PeopleSoft Zero-Day at NAIC
ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has historically targeted organizations to exfiltrate sensitive data, which is then leveraged for extortion or sold on under…
highperson_alertThreat ActorU.S. offers $10M reward for intel on UNC5792 and UNC4221 APT groups
UNC5792 and UNC4221 are threat actor groups attributed to Russian intelligence and military services. Both groups have been designated as high-priority targets by the U.S.
criticalbug_reportVulnerabilityDell Wyse RCE flaw exploitable by low-privileged attackers
Dell Wyse thin client products. Specific affected models and firmware versions not disclosed in summary. Vulnerability enables remote code execution with low privilege requirements.
highperson_alertThreat ActorMustang Panda Targets Indian Government and Hydropower Infrastructure
Mustang Panda (also tracked as TA416, RedDelta, BRONZE PRESIDENT, and STATELY TAURUS) is a China-aligned advanced persistent threat group focused on espionage operations.
highbug_reportVulnerabilityStack buffer overflow in libxml2 enables code execution via malformed input
libxml2 library, all versions not yet patched. Affects systems and applications that parse XML using libxml2, including numerous Linux distributions, Python, PHP, and other software that depends on this widely-deployed XML parsing library.
highbug_reportVulnerability236K+ malicious sites use DCloud Uni-App templates for crypto scams
Organizations and users interacting with websites built using DCloud Uni-App framework templates. Over 236,000 malicious sites identified conducting cryptocurrency scams, phishing, wallet draining, pig-butchering schemes, and fake gambling platforms.
highperson_alertThreat ActorGamaredon APT Expands Ukraine Operations with 35 Spear-Phishing Campaigns
Gamaredon (also tracked as Armageddon, Shuckworm, Primitive Bear, and UAC-0010) is a Russian state-sponsored APT group attributed by multiple vendors to Russia's Federal Security Service (FSB).
criticalbug_reportVulnerabilityCritical RCE flaw in PTC Windchill and FlexPLM requires immediate patching
PTC Windchill and FlexPLM products. Specific affected versions not disclosed in available data. Both products are enterprise Product Lifecycle Management (PLM) platforms widely used in manufacturing and engineering environments.
highbug_reportVulnerabilityMicrosoft Exchange privilege escalation flaw requires immediate patching
Microsoft Exchange Server 2016, 2019, and Subscription Edition. All on-premises deployments of these versions are potentially affected.
highpublicGeopoliticalKDDI breach exposes 14.2M email accounts across Japanese ISP ecosystem
The breach at KDDI Corporation, one of Japan's largest telecommunications operators, highlights systemic vulnerabilities in shared infrastructure models within critical communications sectors.
highperson_alertThreat ActorRussian Intelligence Services Target Messaging Accounts via Phishing
Russian intelligence services conducted a long-running credential harvesting campaign targeting messaging platforms. The operation, uncovered jointly by Ukraine's Security Service (SSU) and the FBI, focused on stealing authentication credentials from…
highperson_alertThreat ActorRussian Intelligence Services Target Signal Users in Phishing Campaign
Russian intelligence services are conducting a phishing campaign targeting Signal messaging application users. The operation is attributed by the FBI and CISA, indicating state-sponsored activity aimed at compromising secure communications.
criticalbug_reportVulnerabilityCISA orders federal patch for exploited Cisco Unified Comms flaw
Cisco Unified Communications Manager Server. Specific versions not disclosed. Federal agencies mandated to patch; all organizations running this product should consider affected.
highperson_alertThreat ActorRussian Intelligence Escalates Signal Phishing for Backup Recovery Keys
Russian intelligence actors, as identified by FBI and CISA joint reporting, are conducting targeted phishing operations against Signal messaging platform users.
highbug_reportVulnerabilitySharkLoader malware deploys Cobalt Strike in attacks on Asian governments
Diplomatic and government organizations in Indonesia and Taiwan. SharkLoader is a newly identified malware family used to deliver Cobalt Strike Beacon payloads in the StrikeShark campaign.
highperson_alertThreat ActorCL-STA-1062 deploys TinyRCT backdoor against Southeast Asian government
CL-STA-1062 is a Chinese-speaking APT actor conducting targeted cyber espionage operations against government entities and critical infrastructure in Southeast Asia.
criticalbug_reportVulnerabilityPTC Windchill and FlexPLM RCE actively exploited in web shell attacks
PTC Windchill PDMlink and PTC FlexPLM Product Lifecycle Management systems. Specific affected versions not disclosed in summary; consult CISA KEV catalog and PTC security advisories for version details.
highbug_reportVulnerabilityPhishing campaign targets hotel front desks with Node.js implant
Hotel and hospitality organizations in Europe and Asia. Front-desk systems targeted via photo-themed ZIP file attachments containing Node.js-based malware. Campaign active since April 2026.
highperson_alertThreat ActorPolish Authorities Dismantle SIM-Swapping Gang Targeting Crypto Assets
This organized cybercrime group operated in Poland, conducting SIM-swapping attacks with the primary motivation of financial gain through cryptocurrency theft.
highbug_reportVulnerabilityActive campaign targets hospitality in Europe/Asia via ZIP archives
Hospitality organizations in Europe and Asia. Attack vector: photo-themed ZIP archives containing malicious shortcut files that deploy a Node.js implant.