Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 356 results
Active filter:tag: #threat-actor✕ clear
Operation CameraSwarm compromises 14,530+ Dahua IoT deviceshighperson_alertThreat Actor
person_alertThreat Actor

Operation CameraSwarm compromises 14,530+ Dahua IoT devices

Operation CameraSwarm is a campaign disclosed by Hunt.io that compromised over 14,530 Dahua surveillance devices between June 17 and July 22, 2026. The campaign was reconstructed from a 407 MB exposed working directory containing 2,616 files across 2…

Dahua19 Aug · 09:34 UTC
StopAndProtect Exploits 2,000 Hacked WordPress Sites for Malware Deliveryhighperson_alertThreat Actor
person_alertThreat Actor

StopAndProtect Exploits 2,000 Hacked WordPress Sites for Malware Delivery

StopAndProtect is a global cybercrime operation tracked by Check Point Research since mid-May 2026. The operation is named after a ransomware family discovered during initial investigation.

WordPress19 Aug · 09:25 UTC
Medusa Ransomware Gang Breaches 500+ US Critical Infrastructure Orgscriticalperson_alertThreat Actor
person_alertThreat Actor

Medusa Ransomware Gang Breaches 500+ US Critical Infrastructure Orgs

Medusa is a ransomware operation active since January 2021 that evolved from a closed ransomware variant into a Ransomware-as-a-Service (RaaS) model with an affiliate program.

BleepingComputer19 Aug · 06:00 UTC
Clop deploys custom JSP web shell targeting PTC Windchill and FlexPLMcriticalbug_reportVulnerability
bug_reportVulnerability

Clop deploys custom JSP web shell targeting PTC Windchill and FlexPLM

PTC Windchill and FlexPLM servers vulnerable to CVE-2026-12569 (CVSS 9.3). All unpatched instances are at risk. These enterprise Product Lifecycle Management (PLM) systems store engineering data, product designs, and administrative credentials.

PTC19 Aug · 03:39 UTC
Microsoft Copilot Personal flaws enable one-click data exfiltration via URLhighbug_reportVulnerability
bug_reportVulnerability

Microsoft Copilot Personal flaws enable one-click data exfiltration via URL

Microsoft Copilot Personal (consumer assistant at copilot.microsoft.com). Research does not indicate Microsoft 365 Copilot is affected. Vulnerability tracked as CVE-2026-24301. Patched August 18, 2026.

Microsoft18 Aug · 15:47 UTC
Clop Gang Deploys Custom Java Web Shell for Windchill Data Thefthighperson_alertThreat Actor
person_alertThreat Actor

Clop Gang Deploys Custom Java Web Shell for Windchill Data Theft

Clop is a financially motivated ransomware and extortion gang known for mass-exploitation campaigns targeting enterprise file-sharing and collaboration platforms.

PTC18 Aug · 15:29 UTC
TWINLOOT Implant Abuses Microsoft 365 Services for C2 and Lateral Movementhighperson_alertThreat Actor
person_alertThreat Actor

TWINLOOT Implant Abuses Microsoft 365 Services for C2 and Lateral Movement

No specific threat actor has been attributed to TWINLOOT operations. The malware was discovered by Ontinue's Cyber Defense Center during investigation of an ongoing campaign in July 2026.

Microsoft18 Aug · 10:38 UTC
City Forum campaign scrapes Salesforce and ServiceNow portalshighperson_alertThreat Actor
person_alertThreat Actor

City Forum campaign scrapes Salesforce and ServiceNow portals

City Forum is a campaign name assigned by Reco to a coordinated data harvesting operation targeting enterprise SaaS platforms. The activity is attributed to a single attacker infrastructure operating from IP address 158.220.87.79, hosted on a Contabo…

Salesforce18 Aug · 09:30 UTC
StubMaker Campaign Deploys 16 Typosquatted RubyGems to Steal Credentialshighperson_alertThreat Actor
person_alertThreat Actor

StubMaker Campaign Deploys 16 Typosquatted RubyGems to Steal Credentials

StubMaker is a typosquatting campaign tracked by OpenSourceMalware researchers, discovered on August 15, 2026. The campaign operators published 16 malicious RubyGems packages under user accounts "mod8rz41mje" (Riley Miller) and "rbq95bwt6q" (Alex Dav…

RubyGems18 Aug · 09:20 UTC
CVE-2025-60710: Windows Task Host Flaw Exploited by Ransomware Gangshighperson_alertThreat Actor
person_alertThreat Actor

CVE-2025-60710: Windows Task Host Flaw Exploited by Ransomware Gangs

No specific threat actor or ransomware gang has been publicly attributed to the exploitation of CVE-2025-60710. CISA confirmed that multiple ransomware operators are actively exploiting this vulnerability in the wild as of August 2026.

Microsoft18 Aug · 08:32 UTC
Iranian Cavern C2 Framework Evolves with DNS and Google Apps Script Relayhighperson_alertThreat Actor
person_alertThreat Actor

Iranian Cavern C2 Framework Evolves with DNS and Google Apps Script Relay

Cavern (aka Cav3rn) is a command-and-control framework attributed to Iranian nation-state threat actors, specifically linked to Cavern Manticore, a hacking group affiliated with Iran's Ministry of Intelligence and Security (MOIS).

The Hacker News17 Aug · 15:41 UTC
Clop Ransomware Gang Exploits PTC Windchill Flaw to Breach GE, Philipshighperson_alertThreat Actor
person_alertThreat Actor

Clop Ransomware Gang Exploits PTC Windchill Flaw to Breach GE, Philips

Clop is a financially motivated ransomware and extortion gang with a well-established history of exploiting zero-day and n-day vulnerabilities in enterprise file-sharing and product lifecycle management (PLM) platforms to conduct mass data theft camp…

General Electric17 Aug · 09:25 UTC
Microsoft Defender ShieldBreak zero-day grants SYSTEM privileges on Windowshighbug_reportVulnerability
bug_reportVulnerability

Microsoft Defender ShieldBreak zero-day grants SYSTEM privileges on Windows

Microsoft Defender on Windows 10, Windows 11 (including 25H2 and Canary), and Windows Server 2025. All fully patched systems with Defender enabled are vulnerable.

CVE-2026-6941417 Aug · 07:05 UTC
China-Nexus APT Exploits VMware vCenter Flaws, Deploys Babuk Ransomwarecriticalperson_alertThreat Actor
person_alertThreat Actor

China-Nexus APT Exploits VMware vCenter Flaws, Deploys Babuk Ransomware

A suspected China-nexus advanced persistent threat actor, assessed with moderate confidence by QUIRSO to be Chinese-speaking and operating in the UTC+08:00 time zone.

CVE-2026-5931017 Aug · 05:36 UTC
€30M Bank Fraud via Service Provider Exploit Targets Commerzbankhighperson_alertThreat Actor
person_alertThreat Actor

€30M Bank Fraud via Service Provider Exploit Targets Commerzbank

An unknown cybercriminal group, financially motivated, conducted a coordinated bank fraud operation targeting Commerzbank customers. The group operated across multiple jurisdictions, with four members arrested in Brazil and three charged in Europe.

Commerzbank14 Aug · 16:04 UTC
Clop Ransomware Gang Exploits CVE-2026-12569 in PTC Windchill Attackshighperson_alertThreat Actor
person_alertThreat Actor

Clop Ransomware Gang Exploits CVE-2026-12569 in PTC Windchill Attacks

Clop is a financially motivated ransomware gang known for mass exploitation campaigns targeting zero-day and n-day vulnerabilities in enterprise software.

Shell14 Aug · 09:55 UTC
ShinyHunters Breaches RingCentral, Leaks 1.6M Account Recordshighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Breaches RingCentral, Leaks 1.6M Account Records

ShinyHunters is a financially motivated extortion group that operates a "pay or leak" model, demanding ransom payments from breached organizations and publishing stolen data on dark web leak sites when victims refuse to pay.

RingCentral14 Aug · 08:52 UTC
Former Brightly Software Contractor Sentenced for $2.5M Extortionhighperson_alertThreat Actor
person_alertThreat Actor

Former Brightly Software Contractor Sentenced for $2.5M Extortion

Cameron Curry (alias "Loot"), a 27-year-old North Carolina resident, was a former data analyst contractor for Brightly Software (formerly SchoolDude, acquired by Siemens in 2022).

Brightly Software14 Aug · 06:27 UTC
Akira Ransomware Affiliate Uses Safe Mode to Evade EDR, Fails Encryptionhighperson_alertThreat Actor
person_alertThreat Actor

Akira Ransomware Affiliate Uses Safe Mode to Evade EDR, Fails Encryption

Akira (also tracked as GOLD SAHARA, PUNK SPIDER, and Howling Scorpius) is a ransomware operation that emerged as a significant threat actor conducting double extortion attacks.

BleepingComputer13 Aug · 18:47 UTC
Jewelbug APT Conducts Dual-Track Espionage and Crypto Fraudhighperson_alertThreat Actor
person_alertThreat Actor

Jewelbug APT Conducts Dual-Track Espionage and Crypto Fraud

Jewelbug (also tracked as Earth Alux and REF7707) is a China-based threat actor conducting parallel espionage and financially-motivated operations. The group targets government and military entities across the Middle East, Southeast Asia, and South A…

BleepingComputer13 Aug · 16:15 UTC
City-Forum Campaign Targets Salesforce and ServiceNow Portalshighperson_alertThreat Actor
person_alertThreat Actor

City-Forum Campaign Targets Salesforce and ServiceNow Portals

City-Forum is an ongoing data theft campaign, not a formally attributed threat actor group. The campaign has been active since at least March 2025 and is characterized by consistent infrastructure use—a single IP address (158.220.87.79) hosted by Ger…

Salesforce12 Aug · 21:07 UTC
Lazarus Exploits Windows Zero-Day in Operation Dream Job Campaigncriticalperson_alertThreat Actor
person_alertThreat Actor

Lazarus Exploits Windows Zero-Day in Operation Dream Job Campaign

Lazarus Group is a North Korean state-sponsored advanced persistent threat (APT) actor attributed to Pyongyang-backed cyber operations. The group conducts cyber espionage and financially motivated campaigns targeting organizations worldwide.

Microsoft12 Aug · 15:39 UTC
Lazarus Exploits Windows Zero-Day in Operation Dream Job Campaigncriticalperson_alertThreat Actor
person_alertThreat Actor

Lazarus Exploits Windows Zero-Day in Operation Dream Job Campaign

Lazarus is a North Korean state-sponsored advanced persistent threat (APT) group linked to the Reconnaissance General Bureau. The group is financially and strategically motivated, conducting espionage operations targeting defense and critical infrast…

CVE-2026-6882012 Aug · 13:38 UTC
Cybercriminals Target Social Media Accounts for Sexual Exploitationhighperson_alertThreat Actor
person_alertThreat Actor

Cybercriminals Target Social Media Accounts for Sexual Exploitation

Unattributed cybercriminals conducting coordinated account compromise campaigns targeting social media and online service accounts belonging to adults, children, and student-athletes in the United States.

BleepingComputer12 Aug · 12:15 UTC
Malicious LiteLLM PyPI packages stole credentials from 2,100+ orgscriticalbug_reportVulnerability
bug_reportVulnerability

Malicious LiteLLM PyPI packages stole credentials from 2,100+ orgs

LiteLLM versions 1.82.7 and 1.82.8 published on PyPI on March 24, 2026 (10:39-11:19 UTC, treat installs through 16:00 UTC as suspect). Any system that installed these versions or pulled them as transitive dependencies via agent frameworks or orchestr…

LiteLLM12 Aug · 06:04 UTC
ShieldBreak zero-day bypasses Microsoft Defender patch, grants SYSTEM accesshighbug_reportVulnerability
bug_reportVulnerability

ShieldBreak zero-day bypasses Microsoft Defender patch, grants SYSTEM access

Microsoft Defender for Windows on Windows 11 25H2, Windows Server 2025, and Windows 10 (all editions). The vulnerability bypasses the patch for CVE-2026-50656 (RoguePlanet) in the Microsoft Malware Protection Engine (mpengine.dll).

CVE-2026-5065612 Aug · 04:41 UTC
DeadLock ransomware uses blockchain infrastructure to evade takedownhighperson_alertThreat Actor
person_alertThreat Actor

DeadLock ransomware uses blockchain infrastructure to evade takedown

DeadLock is a ransomware-as-a-service (RaaS) operation that emerged in mid-2025, employing double-extortion tactics combining data theft with file encryption.

BleepingComputer11 Aug · 20:15 UTC
Sandworm deploys trojanized WireGuard VPN via fake IT job offershighperson_alertThreat Actor
person_alertThreat Actor

Sandworm deploys trojanized WireGuard VPN via fake IT job offers

Sandworm (also tracked as APT44, UAC-0145 sub-cluster) is a Russian-linked advanced persistent threat group notorious for targeting critical infrastructure and government entities, particularly in Ukraine and other countries.

BleepingComputer11 Aug · 19:07 UTC
Kimwolf v7 Botnet Adds HTTP/2 DDoS with Browser Fingerprintinghighperson_alertThreat Actor
person_alertThreat Actor

Kimwolf v7 Botnet Adds HTTP/2 DDoS with Browser Fingerprinting

Kimwolf (also tracked as AISURU) is an Android and IoT botnet operation active since at least mid-2024. The threat actors behind Kimwolf have demonstrated continuous evolution in their tooling, targeting Android TV boxes since August 2025 and Linux I…

Palo Alto Networks11 Aug · 17:36 UTC
UAC-0145 Targets Ukrainian IT Workers via Fake Job Recruitment Campaignhighperson_alertThreat Actor
person_alertThreat Actor

UAC-0145 Targets Ukrainian IT Workers via Fake Job Recruitment Campaign

UAC-0145 is a threat cluster operating as a subgroup within Sandworm (also tracked as APT44, Seashell Blizzard, UAC-0002, ELECTRUM, Telebots, IRON VIKING), a sophisticated nation-state hacking group affiliated with Russia's GRU military intelligence.…

The Hacker News11 Aug · 16:36 UTC