Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 685 results
Active filter:tag: #high✕ clear
24 npm packages abuse unpkg mirrors as phishing infrastructurehighbug_reportVulnerability
bug_reportVulnerability

24 npm packages abuse unpkg mirrors as phishing infrastructure

24 malicious npm packages (e.g., bgzxcuite2, prezdentkxheiw, egair0810) hosted on npm registry and mirrored on unpkg.com and similar CDN services. Affects users who click links to these mirrored HTML pages, not developers installing packages directly…

npm25 Aug · 09:52 UTC
E4del and PINHOLE RATs abuse FTP banners as dead drop resolvershighbug_reportVulnerability
bug_reportVulnerability

E4del and PINHOLE RATs abuse FTP banners as dead drop resolvers

Organizations globally; no specific vendor or product vulnerability. Attack targets Windows systems via social engineering (Spanish-language vouchers, ClickFix lures).

The Hacker News25 Aug · 09:33 UTC
African Crime Groups Targeted in 22-Country Cybercrime Crackdownhighperson_alertThreat Actor
person_alertThreat Actor

African Crime Groups Targeted in 22-Country Cybercrime Crackdown

African crime groups, particularly West African criminal networks and the Black Axe cybercrime syndicate, are financially-motivated threat actors conducting global-scale cyber-enabled financial fraud.

BleepingComputer25 Aug · 08:53 UTC
Xecurify miniOrange SAML plugin flaws exploited for WordPress admin accesshighbug_reportVulnerability
bug_reportVulnerability

Xecurify miniOrange SAML plugin flaws exploited for WordPress admin access

Xecurify miniOrange SAML 2.0 Single Sign On WordPress plugin, Standard edition versions prior to 17.0.6. CVE-2026-61979 (CVSS 8.1) fixed in 17.0.5; CVE-2026-15981 (CVSS 9.8) fixed in 17.0.6.

CVE-2026-6197925 Aug · 06:34 UTC
Calix GS7 XGS routers expose UPnP on WAN, allow unauthenticated NAT bypasshighbug_reportVulnerability
bug_reportVulnerability

Calix GS7 XGS routers expose UPnP on WAN, allow unauthenticated NAT bypass

Calix GS7 XGS (GS5239XG / GigaSpire 7u10txg) residential routers running EXOS/6.6.47 firmware. Deployed by multiple U.S. ISPs including Cox Communications, Brightspeed, ALLO, CityFibre, and Conexon. No patch available.

Calix24 Aug · 19:14 UTC
Weedhack Malware Targets Gamers via Fake Minecraft Clients and SEOhighperson_alertThreat Actor
person_alertThreat Actor

Weedhack Malware Targets Gamers via Fake Minecraft Clients and SEO

Weedhack is a malware family (not a named threat actor group) actively distributed through fake Minecraft client websites and SEO poisoning campaigns. The operators behind Weedhack remain unattributed.

Minecraft24 Aug · 15:41 UTC
ShinyHunters targets ReliaQuest in failed social engineering attackhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters targets ReliaQuest in failed social engineering attack

ShinyHunters is a notorious data extortion group known for large-scale data breaches and credential theft operations. In this incident, the group demonstrated advanced social engineering capabilities by impersonating ReliaQuest security personnel to…

ReliaQuest24 Aug · 13:17 UTC
South Korean gov't platform breach exposes 5,000 via key management flawhighpublicGeopolitical
publicGeopolitical

South Korean gov't platform breach exposes 5,000 via key management flaw

The breach of South Korea's Ministry of SMEs and Startups-backed platform represents a significant governance failure in a state seeking to position itself as a regional technology leader.

BleepingComputer24 Aug · 12:00 UTC
.NET Framework August 2026 updates break WPF printing and PDF exporthighbug_reportVulnerability
bug_reportVulnerability

.NET Framework August 2026 updates break WPF printing and PDF export

.NET Framework cumulative updates released August 2026 Patch Tuesday. Affects Windows Presentation Foundation (WPF) applications on Windows 10, Windows 11, Windows Server 2012 through Windows Server 2025.

Microsoft24 Aug · 10:40 UTC
WordlistLoader and SynkLoader malware target Windows via ClickFix and Teamshighbug_reportVulnerability
bug_reportVulnerability

WordlistLoader and SynkLoader malware target Windows via ClickFix and Teams

Windows endpoints exposed to ClearFake/ClickFix campaigns (WordlistLoader delivering Amatera Stealer) and Microsoft Teams phishing (SynkLoader credential theft).

Microsoft24 Aug · 10:35 UTC
Operation QUICSILVER: China-nexus campaign targets Myanmar with QUICAgenthighperson_alertThreat Actor
person_alertThreat Actor

Operation QUICSILVER: China-nexus campaign targets Myanmar with QUICAgent

Operation QUICSILVER is attributed with moderate confidence to a China-nexus threat actor conducting cyber espionage operations against Myanmar. The actor demonstrates sophisticated tradecraft, leveraging social engineering lures themed around govern…

The Hacker News24 Aug · 09:51 UTC
UAT-10147 Deploys AI-Assisted Attacks and SPECTRE Malware Globallyhighperson_alertThreat Actor
person_alertThreat Actor

UAT-10147 Deploys AI-Assisted Attacks and SPECTRE Malware Globally

UAT-10147 is a Chinese-speaking cybercrime group conducting large-scale attacks against Windows and Linux web servers globally. The actor's primary motivation appears to be SEO fraud and data theft.

The Hacker News24 Aug · 06:08 UTC
ToxicPanda 2.0 abuses VPN and ADB to evade Google Play Protecthighbug_reportVulnerability
bug_reportVulnerability

ToxicPanda 2.0 abuses VPN and ADB to evade Google Play Protect

Android devices running Android 11 or later (Wireless ADB support). Targets 349 banking, financial, cryptocurrency, and e-wallet apps across 16 countries. Specific OEM persistence mechanisms for Xiaomi, OPPO, Vivo, Samsung, and Huawei devices.

BleepingComputer23 Aug · 12:23 UTC
Supply-chain attack targets Android car head units via update apphighbug_reportVulnerability
bug_reportVulnerability

Supply-chain attack targets Android car head units via update app

Android-based automotive head units receiving updates through a compromised legitimate device-update application. Specific vendors, models, and geographic distribution not disclosed.

BleepingComputer22 Aug · 12:14 UTC
Attackers shift focus to CI/CD pipelines and developer tools in SDLChighbug_reportVulnerability
bug_reportVulnerability

Attackers shift focus to CI/CD pipelines and developer tools in SDLC

All organizations using modern software development practices with CI/CD pipelines, open-source dependencies, and developer tools. Specific recent attacks include ChainDrop npm worm (400+ packages including keyv and cacheable-request), XZ Utils (CVE-…

Unit 42 (Palo Alto)21 Aug · 21:00 UTC
14 trojanized npm packages deliver AI-powered RedC2 4.0 Linux backdoorhighbug_reportVulnerability
bug_reportVulnerability

14 trojanized npm packages deliver AI-powered RedC2 4.0 Linux backdoor

14 npm packages (streak-metrics-math, kit-map-vim, streak-map-cache, streak-map-kit, map-streak-kit, streak-cache-map, streak-calc-metrics, streak-calc-math, streak-math-abz, streak-metricsaz, streak-math-metrics, streak-metricazbd, streak-metricsazb…

npm21 Aug · 16:53 UTC
SynkLoader malware spreads via Microsoft Teams phishing campaignshighbug_reportVulnerability
bug_reportVulnerability

SynkLoader malware spreads via Microsoft Teams phishing campaigns

Microsoft Teams users across all organizations. SynkLoader is a new credential-stealing malware family delivered through phishing messages on the Teams platform. No specific product versions or CVEs identified.

Microsoft21 Aug · 16:01 UTC
Microsoft Defender BTR.sys driver weaponized for kernel-level sabotagehighbug_reportVulnerability
bug_reportVulnerability

Microsoft Defender BTR.sys driver weaponized for kernel-level sabotage

Microsoft Defender BTR.sys driver on all Windows versions from Windows 7 through Windows 11 25H2. The driver is a required component shipped with every Windows installation and cannot be blocked without breaking Defender functionality.

Microsoft21 Aug · 13:52 UTC
Threat actors abuse FTP banners to deliver E4del and PINHOLE RATshighbug_reportVulnerability
bug_reportVulnerability

Threat actors abuse FTP banners to deliver E4del and PINHOLE RATs

Windows systems targeted via phishing campaigns delivering LNK files. Two RATs deployed: E4del (Node.js/Electron-based, masquerading as Discord) and PINHOLE (memory-resident, using Pinterest/SurveyMonkey for C2).

BleepingComputer21 Aug · 09:00 UTC
UNC6293, UNC7005, UNC5976 Abuse OAuth and WhatsApp Linking for Espionagehighperson_alertThreat Actor
person_alertThreat Actor

UNC6293, UNC7005, UNC5976 Abuse OAuth and WhatsApp Linking for Espionage

UNC6293, UNC7005, and UNC5976 are three distinct suspected Russian cyber espionage threat clusters conducting persistent account compromise operations. UNC6293 is assessed to be a sub-cluster of Ice Relic (formerly APT29, also tracked as Cozy Bear an…

Google20 Aug · 17:59 UTC
Gogs 10.0 RCE and n8n workflow-to-RCE vulnerabilities disclosedhighbug_reportVulnerability
bug_reportVulnerability

Gogs 10.0 RCE and n8n workflow-to-RCE vulnerabilities disclosed

Gogs version 10.0 (Git service) and n8n (workflow automation platform) - specific n8n versions not provided. Multiple attack vectors disclosed including signed driver abuse (Microsoft Defender BTR.sys), DLL sideloading via Grandoreiro, and ErrTraffic…

Gogs20 Aug · 15:23 UTC
AI-Generated Exploits Target Siemens S7 PLCs in U.S. Critical Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

AI-Generated Exploits Target Siemens S7 PLCs in U.S. Critical Infrastructure

This campaign involves unattributed threat actors leveraging artificial intelligence to generate exploitation scripts targeting industrial control systems.

Siemens20 Aug · 14:59 UTC
Grok chatbot vulnerable to data exfiltration via encrypted prompt injectionhighbug_reportVulnerability
bug_reportVulnerability

Grok chatbot vulnerable to data exfiltration via encrypted prompt injection

xAI Grok 4.5 Fast (web chat at grok.com). Google Gemini 3 Flash (Web) in Deep Thinking mode also demonstrated vulnerable in March 2026. Affects users requesting web page summaries through the chatbot interface.

xAI20 Aug · 12:36 UTC
Zimbra SNMP flaw CVE-2026-73570 under active exploitation for RCEhighbug_reportVulnerability
bug_reportVulnerability

Zimbra SNMP flaw CVE-2026-73570 under active exploitation for RCE

Zimbra Collaboration Server (ZCS) versions before 10.1.20, only when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Unauthenticated remote attackers can exploit this command injection flaw.

CVE-2026-7357020 Aug · 11:24 UTC
Citrix urges immediate patching of NetScaler auth bypass and DoS flawshighbug_reportVulnerability
bug_reportVulnerability

Citrix urges immediate patching of NetScaler auth bypass and DoS flaws

Citrix NetScaler ADC and NetScaler Gateway appliances (all supported versions prior to 14.1-73.32 and 13.1-63.21). CVE-2026-19490 affects appliances configured as AAA virtual server or Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) with SAML authentic…

Citrix20 Aug · 10:14 UTC
Zombie Card attack revives expired Visa contactless cards via NFC relayhighbug_reportVulnerability
bug_reportVulnerability

Zombie Card attack revives expired Visa contactless cards via NFC relay

Visa contactless credit cards using Kernel 3 specification. Attack requires physical card access or sustained NFC proximity, plus relay device between card and terminal. Five major US banks tested; three confirmed vulnerable with varying policies.

Visa20 Aug · 10:01 UTC
Manic Android malware exfiltrates data via nearby infected deviceshighbug_reportVulnerability
bug_reportVulnerability

Manic Android malware exfiltrates data via nearby infected devices

Android users in Central and Western Europe (including UK), Russia, and primarily Ukraine. Targets 169 banking, government/eID, payment, crypto wallet, messaging, and 2FA apps. Active since at least February 2026.

BleepingComputer20 Aug · 08:02 UTC
Ransom Busters: Rogue Affiliate Impersonates Recovery Firmhighperson_alertThreat Actor
person_alertThreat Actor

Ransom Busters: Rogue Affiliate Impersonates Recovery Firm

Ransom Busters is a suspected ransomware affiliate operating across multiple Ransomware-as-a-Service (RaaS) platforms, including DragonForce, Settra, and Anubis.

BleepingComputer19 Aug · 18:59 UTC
Sakura Internet breach exposes 1.36M accounts at Japan Gov Cloud providerhighpublicGeopolitical
publicGeopolitical

Sakura Internet breach exposes 1.36M accounts at Japan Gov Cloud provider

The breach of Sakura Internet carries strategic significance beyond typical commercial cloud incidents due to the company's designation as a domestic provider for Japan's Government Cloud program.

Sakura Internet19 Aug · 18:53 UTC
CareCloud breach exposes 3.7M patient records in AWS environmenthighpublicGeopolitical
publicGeopolitical

CareCloud breach exposes 3.7M patient records in AWS environment

The CareCloud incident reflects the persistent vulnerability of U.S. healthcare infrastructure to cyber intrusions, particularly cloud-hosted environments containing sensitive medical data.

CareCloud19 Aug · 18:07 UTC