Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 157 results
highperson_alertThreat ActorINC and Lynx Ransomware Groups Exploit FortiBleed for Credential Theft
INC and Lynx are ransomware threat actors linked to the FortiBleed credential theft campaign. These groups operate with the primary motivation of financial gain through ransomware deployment.
highperson_alertThreat ActorScattered Spider Member Extradited to U.S. on Federal Hacking Charges
Scattered Spider (also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944) is a financially motivated threat actor group known for sophisticated social engineering and identity-based attacks.
highperson_alertThreat ActorMassive SEO-Poisoned Campaign Distributes AsyncRAT via ScreenConnect
The threat actor behind this campaign remains unattributed. Motivation appears to be financially driven, consistent with commodity RAT deployment for access brokering, credential theft, or follow-on ransomware operations.
highperson_alertThreat ActorVEIL#DROP campaign delivers PureLogs stealer via Blogger pages
VEIL#DROP is a multi-stage malware delivery campaign identified by Securonix researchers. The campaign employs social engineering tactics and abuses legitimate Blogger platform infrastructure to distribute PureLogs, an information-stealing malware.
highperson_alertThreat ActorDeepSeek AI Used to Generate Novel Browser-Based Ransomware
DeepSeek refers to the AI model leveraged by unknown threat actors to generate functional browser-based ransomware code. This marks the first documented instance of a frontier AI model being weaponized to create a novel ransomware technique.
highperson_alertThreat ActorRustDuck Botnet Targets IoT Devices for DDoS Operations
RustDuck is a two-stage malware family written in Rust, designed to compromise Internet of Things (IoT) devices including home routers, IP cameras, Android set-top boxes, and inadequately secured servers.
highperson_alertThreat ActorSilent Swap Campaign Targets Cryptocurrency via Malicious Browser Extensions
Silent Swap is an active cybercrime campaign leveraging malicious browser extensions to conduct cryptocurrency theft. The operation distributes unsigned installers written in both .NET and Golang variants, masquerading as a legitimate Google Notes br…
highperson_alertThreat ActorPre-Planned Fraud Campaign Targets FIFA World Cup 2026 Across Sectors
The threat actor behind this campaign remains unattributed. Motivation appears financially driven, leveraging the global interest in FIFA World Cup 2026 to conduct fraud operations.
highperson_alertThreat ActorShinyHunters Exploits Oracle PeopleSoft Zero-Day in Nissan Breach
ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has established a pattern of exploiting vulnerabilities in enterprise applications to exfiltrate sensitive data, which is th…
highperson_alertThreat ActorShinyHunters Exploits Oracle PeopleSoft Zero-Day at NAIC
ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has historically targeted organizations to exfiltrate sensitive data, which is then leveraged for extortion or sold on under…
highperson_alertThreat ActorMalicious Chrome Extension Impersonates Perplexity AI to Intercept Searches
The threat actor behind this campaign remains unattributed. The operation demonstrates a financially or espionage-motivated adversary leveraging social engineering through brand impersonation of Perplexity AI, a popular search technology.
highperson_alertThreat ActorU.S. offers $10M reward for intel on UNC5792 and UNC4221 APT groups
UNC5792 and UNC4221 are threat actor groups attributed to Russian intelligence and military services. Both groups have been designated as high-priority targets by the U.S.
highperson_alertThreat ActorMustang Panda Targets Indian Government and Hydropower Infrastructure
Mustang Panda (also tracked as TA416, RedDelta, BRONZE PRESIDENT, and STATELY TAURUS) is a China-aligned advanced persistent threat group focused on espionage operations.
highperson_alertThreat ActorGamaredon APT Expands Ukraine Operations with 35 Spear-Phishing Campaigns
Gamaredon (also tracked as Armageddon, Shuckworm, Primitive Bear, and UAC-0010) is a Russian state-sponsored APT group attributed by multiple vendors to Russia's Federal Security Service (FSB).
highperson_alertThreat ActorRussian Intelligence Services Target Messaging Accounts via Phishing
Russian intelligence services conducted a long-running credential harvesting campaign targeting messaging platforms. The operation, uncovered jointly by Ukraine's Security Service (SSU) and the FBI, focused on stealing authentication credentials from…
highperson_alertThreat ActorRussian Intelligence Services Target Signal Users in Phishing Campaign
Russian intelligence services are conducting a phishing campaign targeting Signal messaging application users. The operation is attributed by the FBI and CISA, indicating state-sponsored activity aimed at compromising secure communications.
highperson_alertThreat ActorRussian Intelligence Escalates Signal Phishing for Backup Recovery Keys
Russian intelligence actors, as identified by FBI and CISA joint reporting, are conducting targeted phishing operations against Signal messaging platform users.
highperson_alertThreat ActorUnknown Actors Exploit OpenAI Tenants to Phish Cybersecurity Firms
The threat actors behind this campaign remain unattributed. Their motivation appears to be intelligence gathering and corporate espionage, leveraging the trust associated with OpenAI's platform to deceive employees of cybersecurity companies.
highperson_alertThreat ActorCL-STA-1062 deploys TinyRCT backdoor against Southeast Asian government
CL-STA-1062 is a Chinese-speaking APT actor conducting targeted cyber espionage operations against government entities and critical infrastructure in Southeast Asia.
highperson_alertThreat ActorPolish Authorities Dismantle SIM-Swapping Gang Targeting Crypto Assets
This organized cybercrime group operated in Poland, conducting SIM-swapping attacks with the primary motivation of financial gain through cryptocurrency theft.
highperson_alertThreat ActorCL-STA-1062 targets Southeast Asian government with TinyRCT backdoor
CL-STA-1062 is a threat actor conducting cyber espionage operations against government entities and critical infrastructure in Southeast Asia. The actor employs a hybrid toolkit centered around a custom backdoor known as TinyRCT.
highperson_alertThreat ActorKongTuke Deploys Mistic Backdoor in Multi-Sector Financial Attacks
KongTuke is an initial access broker (IAB) conducting financially motivated operations targeting organizations across insurance, education, IT, and professional services sectors.
highperson_alertThreat ActorSnoopy Sentenced to 18 Months for DraftKings Account Compromise
Snoopy is a 21-year-old individual arrested and sentenced for unauthorized access to customer accounts on the DraftKings sports betting platform in November 2022.
highperson_alertThreat ActorEdgecution: Malicious Edge Extension Enables Sandbox Escape
Edgecution is a malicious browser extension targeting Microsoft Edge, not a threat actor group. It functions as a tool deployed during ransomware operations to facilitate sandbox escape and establish persistence.
highperson_alertThreat ActorEuropol disrupts Amadey and StealC infrastructure, recovers 27M credentials
This report describes a law enforcement disruption operation led by Europol in partnership with private sector entities including Bitdefender, Bitsight, ESET, and Microsoft.
highperson_alertThreat ActorEuropol-led Operation Endgame disrupts Amadey and StealC infrastructure
Europol is a law enforcement agency coordinating international cybercrime investigations. In this context, Europol led Operation Endgame, a coordinated law enforcement action involving Microsoft and international partners targeting cybercriminal infr…
highperson_alertThreat ActorKongTuke Deploys Mistic Backdoor in Multi-Sector Intrusions
KongTuke is a financially motivated threat actor operating as a ransomware access broker. The group specializes in gaining initial access to corporate networks and establishing persistent backdoor access, which is then sold or provided to ransomware…
highperson_alertThreat ActorU.S. seizes HuiOne Group assets, sanctions Prince Group entities
HuiOne Group and Prince Group are entities linked to cyber scam money laundering operations with infrastructure in Cambodia. HuiOne Group subsidiaries allegedly operated cloud computing infrastructure used to facilitate financial transactions related…
highperson_alertThreat ActorClickFix Targets macOS with Terminal-Based Infostealer Campaign
ClickFix is a threat actor conducting social engineering campaigns that trick users into executing malicious commands. The actor leverages deceptive techniques to convince victims to manually run Terminal commands on macOS systems, facilitating the d…
criticalperson_alertThreat ActorFortiBleed: Russian IAB harvests 110M credentials from FortiGate devices
FortiBleed is attributed to a Russian-speaking initial access broker (IAB) conducting large-scale credential harvesting operations since February 2026. The actor demonstrates advanced operational capabilities through systematic targeting of over 430,…