Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 356 results
highperson_alertThreat ActorOperation CameraSwarm compromises 14,530+ Dahua IoT devices
Operation CameraSwarm is a campaign disclosed by Hunt.io that compromised over 14,530 Dahua surveillance devices between June 17 and July 22, 2026. The campaign was reconstructed from a 407 MB exposed working directory containing 2,616 files across 2…
highperson_alertThreat ActorStopAndProtect Exploits 2,000 Hacked WordPress Sites for Malware Delivery
StopAndProtect is a global cybercrime operation tracked by Check Point Research since mid-May 2026. The operation is named after a ransomware family discovered during initial investigation.
criticalperson_alertThreat ActorMedusa Ransomware Gang Breaches 500+ US Critical Infrastructure Orgs
Medusa is a ransomware operation active since January 2021 that evolved from a closed ransomware variant into a Ransomware-as-a-Service (RaaS) model with an affiliate program.
criticalbug_reportVulnerabilityClop deploys custom JSP web shell targeting PTC Windchill and FlexPLM
PTC Windchill and FlexPLM servers vulnerable to CVE-2026-12569 (CVSS 9.3). All unpatched instances are at risk. These enterprise Product Lifecycle Management (PLM) systems store engineering data, product designs, and administrative credentials.
highbug_reportVulnerabilityMicrosoft Copilot Personal flaws enable one-click data exfiltration via URL
Microsoft Copilot Personal (consumer assistant at copilot.microsoft.com). Research does not indicate Microsoft 365 Copilot is affected. Vulnerability tracked as CVE-2026-24301. Patched August 18, 2026.
highperson_alertThreat ActorClop Gang Deploys Custom Java Web Shell for Windchill Data Theft
Clop is a financially motivated ransomware and extortion gang known for mass-exploitation campaigns targeting enterprise file-sharing and collaboration platforms.
highperson_alertThreat ActorTWINLOOT Implant Abuses Microsoft 365 Services for C2 and Lateral Movement
No specific threat actor has been attributed to TWINLOOT operations. The malware was discovered by Ontinue's Cyber Defense Center during investigation of an ongoing campaign in July 2026.
highperson_alertThreat ActorCity Forum campaign scrapes Salesforce and ServiceNow portals
City Forum is a campaign name assigned by Reco to a coordinated data harvesting operation targeting enterprise SaaS platforms. The activity is attributed to a single attacker infrastructure operating from IP address 158.220.87.79, hosted on a Contabo…
highperson_alertThreat ActorStubMaker Campaign Deploys 16 Typosquatted RubyGems to Steal Credentials
StubMaker is a typosquatting campaign tracked by OpenSourceMalware researchers, discovered on August 15, 2026. The campaign operators published 16 malicious RubyGems packages under user accounts "mod8rz41mje" (Riley Miller) and "rbq95bwt6q" (Alex Dav…
highperson_alertThreat ActorCVE-2025-60710: Windows Task Host Flaw Exploited by Ransomware Gangs
No specific threat actor or ransomware gang has been publicly attributed to the exploitation of CVE-2025-60710. CISA confirmed that multiple ransomware operators are actively exploiting this vulnerability in the wild as of August 2026.
highperson_alertThreat ActorIranian Cavern C2 Framework Evolves with DNS and Google Apps Script Relay
Cavern (aka Cav3rn) is a command-and-control framework attributed to Iranian nation-state threat actors, specifically linked to Cavern Manticore, a hacking group affiliated with Iran's Ministry of Intelligence and Security (MOIS).
highperson_alertThreat ActorClop Ransomware Gang Exploits PTC Windchill Flaw to Breach GE, Philips
Clop is a financially motivated ransomware and extortion gang with a well-established history of exploiting zero-day and n-day vulnerabilities in enterprise file-sharing and product lifecycle management (PLM) platforms to conduct mass data theft camp…
highbug_reportVulnerabilityMicrosoft Defender ShieldBreak zero-day grants SYSTEM privileges on Windows
Microsoft Defender on Windows 10, Windows 11 (including 25H2 and Canary), and Windows Server 2025. All fully patched systems with Defender enabled are vulnerable.
criticalperson_alertThreat ActorChina-Nexus APT Exploits VMware vCenter Flaws, Deploys Babuk Ransomware
A suspected China-nexus advanced persistent threat actor, assessed with moderate confidence by QUIRSO to be Chinese-speaking and operating in the UTC+08:00 time zone.
highperson_alertThreat Actor€30M Bank Fraud via Service Provider Exploit Targets Commerzbank
An unknown cybercriminal group, financially motivated, conducted a coordinated bank fraud operation targeting Commerzbank customers. The group operated across multiple jurisdictions, with four members arrested in Brazil and three charged in Europe.
highperson_alertThreat ActorClop Ransomware Gang Exploits CVE-2026-12569 in PTC Windchill Attacks
Clop is a financially motivated ransomware gang known for mass exploitation campaigns targeting zero-day and n-day vulnerabilities in enterprise software.
highperson_alertThreat ActorShinyHunters Breaches RingCentral, Leaks 1.6M Account Records
ShinyHunters is a financially motivated extortion group that operates a "pay or leak" model, demanding ransom payments from breached organizations and publishing stolen data on dark web leak sites when victims refuse to pay.
highperson_alertThreat ActorFormer Brightly Software Contractor Sentenced for $2.5M Extortion
Cameron Curry (alias "Loot"), a 27-year-old North Carolina resident, was a former data analyst contractor for Brightly Software (formerly SchoolDude, acquired by Siemens in 2022).
highperson_alertThreat ActorAkira Ransomware Affiliate Uses Safe Mode to Evade EDR, Fails Encryption
Akira (also tracked as GOLD SAHARA, PUNK SPIDER, and Howling Scorpius) is a ransomware operation that emerged as a significant threat actor conducting double extortion attacks.
highperson_alertThreat ActorJewelbug APT Conducts Dual-Track Espionage and Crypto Fraud
Jewelbug (also tracked as Earth Alux and REF7707) is a China-based threat actor conducting parallel espionage and financially-motivated operations. The group targets government and military entities across the Middle East, Southeast Asia, and South A…
highperson_alertThreat ActorCity-Forum Campaign Targets Salesforce and ServiceNow Portals
City-Forum is an ongoing data theft campaign, not a formally attributed threat actor group. The campaign has been active since at least March 2025 and is characterized by consistent infrastructure use—a single IP address (158.220.87.79) hosted by Ger…
criticalperson_alertThreat ActorLazarus Exploits Windows Zero-Day in Operation Dream Job Campaign
Lazarus Group is a North Korean state-sponsored advanced persistent threat (APT) actor attributed to Pyongyang-backed cyber operations. The group conducts cyber espionage and financially motivated campaigns targeting organizations worldwide.
criticalperson_alertThreat ActorLazarus Exploits Windows Zero-Day in Operation Dream Job Campaign
Lazarus is a North Korean state-sponsored advanced persistent threat (APT) group linked to the Reconnaissance General Bureau. The group is financially and strategically motivated, conducting espionage operations targeting defense and critical infrast…
highperson_alertThreat ActorCybercriminals Target Social Media Accounts for Sexual Exploitation
Unattributed cybercriminals conducting coordinated account compromise campaigns targeting social media and online service accounts belonging to adults, children, and student-athletes in the United States.
criticalbug_reportVulnerabilityMalicious LiteLLM PyPI packages stole credentials from 2,100+ orgs
LiteLLM versions 1.82.7 and 1.82.8 published on PyPI on March 24, 2026 (10:39-11:19 UTC, treat installs through 16:00 UTC as suspect). Any system that installed these versions or pulled them as transitive dependencies via agent frameworks or orchestr…
highbug_reportVulnerabilityShieldBreak zero-day bypasses Microsoft Defender patch, grants SYSTEM access
Microsoft Defender for Windows on Windows 11 25H2, Windows Server 2025, and Windows 10 (all editions). The vulnerability bypasses the patch for CVE-2026-50656 (RoguePlanet) in the Microsoft Malware Protection Engine (mpengine.dll).
highperson_alertThreat ActorDeadLock ransomware uses blockchain infrastructure to evade takedown
DeadLock is a ransomware-as-a-service (RaaS) operation that emerged in mid-2025, employing double-extortion tactics combining data theft with file encryption.
highperson_alertThreat ActorSandworm deploys trojanized WireGuard VPN via fake IT job offers
Sandworm (also tracked as APT44, UAC-0145 sub-cluster) is a Russian-linked advanced persistent threat group notorious for targeting critical infrastructure and government entities, particularly in Ukraine and other countries.
highperson_alertThreat ActorKimwolf v7 Botnet Adds HTTP/2 DDoS with Browser Fingerprinting
Kimwolf (also tracked as AISURU) is an Android and IoT botnet operation active since at least mid-2024. The threat actors behind Kimwolf have demonstrated continuous evolution in their tooling, targeting Android TV boxes since August 2025 and Linux I…
highperson_alertThreat ActorUAC-0145 Targets Ukrainian IT Workers via Fake Job Recruitment Campaign
UAC-0145 is a threat cluster operating as a subgroup within Sandworm (also tracked as APT44, Seashell Blizzard, UAC-0002, ELECTRUM, Telebots, IRON VIKING), a sophisticated nation-state hacking group affiliated with Russia's GRU military intelligence.…