Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 734 results
highperson_alertThreat ActorF5 BIG-IP Exploitation Leads to Confluence Compromise and Lateral Movement
The threat actor behind this campaign remains unattributed. Motivation appears to be credential theft and network persistence within enterprise environments.
highperson_alertThreat ActorGhostwriter Targets Ukrainian Government with Prometheus-Themed Phishing
Ghostwriter (also tracked as UAC-0057 and UNC1151) is a Belarus-aligned threat actor known for conducting information operations and cyber espionage campaigns.
highperson_alertThreat ActorScreening Serpens: Iranian APT Targets Tech and Defense with RAT Malware
Screening Serpens is an Iranian APT group attributed by Unit 42, conducting cyber espionage operations. The group is motivated by intelligence collection targeting technology and defense sectors, consistent with Iranian state interests in acquiring s…
highperson_alertThreat ActorMegalodon campaign injects 5,718 malicious commits into GitHub repos
Megalodon is an automated supply chain attack campaign targeting GitHub repositories. The actor's motivation appears to be exfiltration of CI/CD environment data, including secrets, tokens, and credentials stored in GitHub Actions workflows.
highperson_alertThreat ActorROADtools Framework Misused in Nation-State Cloud Intrusions
Multiple threat actors, including nation-state groups, are misusing the open-source ROADtools framework for cloud intrusions. ROADtools is a legitimate Azure AD reconnaissance toolkit designed for security assessments, but has been co-opted by advers…
highperson_alertThreat ActorCanadian National Arrested for Operating KimWolf DDoS Botnet
A Canadian national arrested by U.S. and Canadian authorities for operating the KimWolf DDoS botnet infrastructure. The operator managed a large-scale botnet that compromised nearly two million devices globally, offering DDoS-for-hire services.
highperson_alertThreat ActorJacob Butler Arrested for Operating Kimwolf DDoS Botnet
Jacob Butler, also known as "Dort," is a 23-year-old Canadian national from Ottawa arrested by the U.S. Department of Justice for developing and operating the Kimwolf DDoS botnet.
highperson_alertThreat ActorDort Arrested for Operating Kimwolf IoT Botnet in Multi-Million Device DDoS Campaign
Dort is a 23-year-old cybercriminal based in Ottawa, Canada, suspected of developing and operating the Kimwolf IoT botnet. Motivated by launching large-scale DDoS attacks, doxing, and swatting campaigns, Dort leveraged compromised IoT devices to buil…
highbug_reportVulnerabilityChromium zero-day disclosed: JavaScript persists after browser close
Chromium-based browsers (Google Chrome, Microsoft Edge, Brave, Opera, Vivaldi) - specific affected versions not disclosed. Vulnerability remains unpatched at time of disclosure.
highbug_reportVulnerabilityNLnet Labs patches DoS vulnerabilities in Unbound DNS resolver
Unbound DNS resolver by NLnet Labs. Specific vulnerable versions not provided in advisory; patched versions available. Affects organizations running Unbound for DNS resolution services.
highperson_alertThreat ActorShowboat Linux Malware Targets Middle East Telecom Since Mid-2022
The threat actor behind Showboat remains unattributed. The campaign demonstrates sophisticated targeting of telecommunications infrastructure in the Middle East, suggesting a motivated adversary with strategic intelligence collection objectives.
highperson_alertThreat ActorChinese APT Deploys Showboat and JFMBackdoor Against Telecom Sector
Chinese state-sponsored threat actors conducting cyber-espionage operations against telecommunications infrastructure. The actors demonstrate cross-platform capabilities with custom Linux and Windows malware tooling.
highperson_alertThreat ActorInternational Law Enforcement Seizes First VPN Service Used by Cybercriminals
First VPN was a commercial VPN service exploited by multiple threat actors to anonymize their operations. The service provided infrastructure enabling cybercriminals to mask their origin during ransomware deployments and data exfiltration campaigns.
highbug_reportVulnerabilityMicrosoft Defender privilege escalation CVE-2026-41091 under active exploit
Microsoft Defender on Windows systems. Specific product versions not disclosed. Vulnerability allows local attackers to escalate privileges to SYSTEM level through improper link resolution handling.
highperson_alertThreat Actor18-Year-Old Infostealer Operator Arrested for Compromising 28K Accounts
An 18-year-old individual from Odesa, Ukraine, identified by Ukrainian cyberpolice in coordination with U.S. law enforcement. The operator is suspected of deploying infostealer malware to harvest credentials and compromise user accounts.
highbug_reportVulnerabilityGrafana breach via unrotated GitHub token after TanStack npm compromise
Grafana Labs infrastructure. Organizations using Grafana products are not directly affected by the breach itself, but should monitor for potential secondary impacts.
highperson_alertThreat ActorWebworm Deploys EchoCreep and GraphWorm Backdoors via Discord and Graph API
Webworm is a China-aligned advanced persistent threat (APT) actor first documented by Symantec in September 2022, with activity traced back to at least 2022.
highbug_reportVulnerabilityPinTheft Linux privilege escalation PoC released for Arch Linux
Arch Linux systems. Specific affected package versions not disclosed; vulnerability has been patched in recent updates. Other Linux distributions may be affected depending on package configurations.
highbug_reportVulnerabilityMicrosoft mitigates YellowKey BitLocker bypass (CVE-2026-45585)
Microsoft BitLocker on Windows systems. Specific affected versions not disclosed. Vulnerability allows bypass of BitLocker disk encryption protections.
highbug_reportVulnerabilityMicrosoft mitigates YellowKey BitLocker zero-day bypass vulnerability
Windows BitLocker across all supported Windows versions. The vulnerability allows unauthorized access to BitLocker-protected drives. No CVE assigned yet.
highbug_reportVulnerabilityPostgreSQL patches multiple high-severity flaws; version 14 EOL announced
PostgreSQL database server, multiple versions affected by security vulnerabilities. Version 14 reaching end-of-life, no longer receiving security updates after EOL date.
highperson_alertThreat ActorTeamPCP Lists GitHub Source Code for Sale After Repository Breach
TeamPCP is a threat actor that has emerged in the cybercrime ecosystem, demonstrating capability to compromise high-value technology platforms. The actor's motivation appears financially driven, as evidenced by their decision to monetize stolen GitHu…
highperson_alertThreat ActorMicrosoft Disrupts Malware-Signing-as-a-Service Operation
This operation involved cybercriminals abusing Microsoft's Artifact Signing service to provide malware-signing-as-a-service capabilities. The actors exploited legitimate code-signing infrastructure to generate fraudulent certificates, which were then…
highperson_alertThreat ActorFox Tempest Provides Malware-Signing Services to Ransomware Operators
Fox Tempest is a financially motivated cybercriminal actor that operates as a malware-signing service provider within the ransomware ecosystem. Rather than conducting attacks directly, Fox Tempest enables other threat actors—including Vanilla Tempest…
highbug_reportVulnerabilityPoC released for DirtyDecrypt LPE in Linux kernel (CVE-2026-31635)
Linux kernel - specific vulnerable versions not provided. Local privilege escalation vulnerability affecting systems running vulnerable kernel versions.
highbug_reportVulnerabilityOver 600 malicious npm packages published in Shai-Hulud campaign
npm ecosystem: 600+ malicious packages published by threat actors. Affects organizations using npm for JavaScript/Node.js dependency management. Specific package names not provided in summary.
highbug_reportVulnerabilitySonicWall releases patches for multiple high-severity vulnerabilities
SonicWall products (specific models and versions not disclosed in summary). CERT.BE advisory indicates multiple vulnerabilities requiring immediate patching across SonicWall product line.
highperson_alertThreat ActorShinyHunters Claims 7-Eleven Data Breach
ShinyHunters is a financially motivated cybercrime group known for large-scale data breaches and database theft. The group emerged around 2020 and has been linked to numerous high-profile data exfiltration incidents targeting organizations across var…
highbug_reportVulnerabilityMicrosoft sees rise in privilege escalation and identity abuse flaws
Microsoft products and services experiencing increased critical vulnerabilities focused on privilege escalation and identity abuse. Specific affected products and versions not detailed in available data.
highbug_reportVulnerabilityABB CoreSense path traversal flaw allows unauthenticated system access
ABB CoreSense HM (versions prior to v2.3.4) and CoreSense M10 (versions prior to v1.4.1.31). Path traversal vulnerability affects unauthenticated remote attackers.