Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 356 results
highperson_alertThreat ActorDeadLock Ransomware Leverages Polygon Blockchain for Resilient Extortion
DeadLock is a ransomware group first detected in July 2025, operating double extortion campaigns that encrypt victim environments and threaten public data release.
highperson_alertThreat ActorExfilSquad Claims 2.6M Records Stolen from Wesco CRM Environment
ExfilSquad is a data extortion group that specializes in exfiltrating sensitive information from organizations and leveraging it for ransom demands. The group operates a data leak site where they publish stolen data after ransom deadlines expire.
highperson_alertThreat ActorNorth Korea IT Worker Infiltration Targets Crypto and Tech Firms
North Korean IT worker operations, attributed by researchers to Famous Chollima (a CrowdStrike designation under the Lazarus umbrella), involve operatives seeking employment at Western technology and cryptocurrency companies under fraudulent identiti…
highperson_alertThreat ActorStorm-1175 Deploys New StormEncryptor Ransomware After Medusa Split
Storm-1175 is a financially motivated threat actor believed to be based in China, previously affiliated with the Medusa ransomware operation. Microsoft Threat Intelligence tracks this actor as a former Medusa affiliate who has now shifted to deployin…
highperson_alertThreat ActorStorm-1175 Deploys StormEncryptor Ransomware via N-central Exploit
Storm-1175 is a China-linked, financially motivated threat actor tracked by Microsoft. The group specializes in high-velocity ransomware operations, exploiting both zero-day and N-day vulnerabilities in internet-facing enterprise software to gain ini…
highperson_alertThreat ActorDeadLock Ransomware: Rust-Based Encryptor with Decentralized Infrastructure
DeadLock is a financially motivated ransomware operation first observed in July 2025. It is not attributed to a single threat actor but has been deployed by multiple groups, including affiliates of the Lynx and INC ransomware ecosystems.
criticalperson_alertThreat ActorRansomware Gangs Exploit SonicWall SMA1000 SSRF and Auth Bypass Flaws
The actors are ransomware gangs—a broad category of financially motivated cybercrime operators—actively exploiting recently patched SonicWall SMA1000 vulnerabilities.
highperson_alertThreat ActorKimsuky Deploys Offline AI Stack for Enhanced Phishing and Malware Automation
Kimsuky (also tracked as Black Banshee, Velvet Chollima, Emerald Sleet, THALLIUM) is a North Korean state-sponsored APT group operating under the Reconnaissance General Bureau. Sanctioned by the U.S.
highperson_alertThreat ActorThe Com cybercrime collective member sentenced for sextortion
The Com (short for "Community") is a loose-knit online cybercrime collective that targets children and teenagers through multiple specialized subgroups.
highperson_alertThreat ActorHead Mare Exploits TrueConf Flaws to Deploy PhantomCore Backdoor
Head Mare is a threat actor conducting targeted intrusion operations against Russian organizations across critical infrastructure and technology sectors.
highperson_alertThreat ActorDecember 2025 Poland Energy Sector Campaign via Private APN
No specific threat actor has been publicly attributed to this campaign. The December 2025 attacks targeted Poland's energy infrastructure with purely destructive intent, representing a coordinated operation against multiple facilities including wind…
criticalbug_reportVulnerabilityHead Mare hacktivists backdoor TrueConf installers via server compromise
TrueConf video conferencing servers (unpatched versions) and client installers distributed from compromised servers. Specific vulnerable versions not disclosed. Affects organizations using TrueConf for video conferencing.
highbug_reportVulnerabilityAtlassian Rovo prompt injection enables data exfiltration from Jira/Confluence
Atlassian Rovo assistant on Standard, Premium, and Enterprise plans. Affects organizations with Rovo enabled (default setting). Exploitable by authenticated users who interact with attacker-controlled content (documents) or links (rovoChatPrompt para…
criticalbug_reportVulnerabilityNearly 800 malicious npm packages deliver cross-platform RAT via typosquatting
npm registry: ~800 packages using typosquatting and AI-generated names. Targets all Node.js developers on Windows, macOS (x64/ARM64), and Linux (x64/ARM64). Delivers WEL1DROPPER leading to Sliver C2 framework and platform-specific infostealers.
highperson_alertThreat ActorUNC6671 Conducts Vishing Attacks to Steal SaaS Credentials
UNC6671 is a financially motivated data extortion group that emerged in early January 2026. The actor operates multiple extortion brands including Redact, Pink (CL-CRI-1147), Helix, and Falcon (CL-CRI-1182), and previously operated under the BlackFil…
highbug_reportVulnerabilityWordPress pre-auth XSS on login page enables RCE via admin interaction
WordPress CMS all versions prior to 7.0.3. Patches backported to 4.7 branch and newer. Versions older than 4.7 remain vulnerable and unpatched. Default installations affected; no special hosting configuration required.
criticalbug_reportVulnerability18-year-old Linux SCTP flaw enables local root and container escape
Linux kernel versions since 2.6.25 (2008) through 7.1.5, 6.18.41, 6.12.100, and 6.6.147. Affects systems with SCTP networking enabled. Confirmed vulnerable: Debian 13, Ubuntu 24.04, Rocky Linux 9, RHEL 9, OpenCloudOS.
highperson_alertThreat ActorUNC6671 extortion group targets financial sector via vishing attacks
UNC6671 is a financially motivated extortion group tracked by Google Threat Intelligence Group (GTIG) that operates under multiple public brands including BlackFile, Redact, Pink, Helix, and Falcon.
criticalperson_alertThreat ActorCanadian Cybercriminal Connor Moucka Pleads Guilty to Snowflake Breach
Connor Riley Moucka (aliases "Judische," "Waifu") is a 26-year-old Canadian software engineer from Kitchener, Ontario, who operated as a cybercriminal since at least 2020.
criticalbug_reportVulnerabilityCryptoJS weak RNG drained $5.7M from five crypto wallets over 12 years
CryptoJS versions below 4.0.0 (except 3.2.0 and 3.2.1). Five confirmed affected wallet apps: RRWallet (discontinued), Bexo Wallet (fixed in 20.1.0, builds pending), NanChat (fixed in 1.3.0), Bitcoin Libre (fixed in v4, July 2024), and Milo (discontin…
highperson_alertThreat ActorCybercriminals Steal AI API Keys via Token Jacking for Resale
Cybercriminals targeting the AI development ecosystem are motivated by financial gain through the theft and resale of API keys (tokens) for premium AI platforms.
highperson_alertThreat ActorRansom Cartel Creator Maksim Silnikau Sentenced to 16 Years
Maksim Silnikau is a 40-year-old Belarusian national who created and administered the Ransom Cartel ransomware-as-a-service (RaaS) operation. Active on Russian-speaking cybercrime forums since at least 2005, Silnikau operated under aliases including…
highperson_alertThreat ActorCanadian Cybercriminal Pleads Guilty to Snowflake Data Theft Campaign
Connor Riley Moucka (also known as Alexander Moucka and "Waifu"), a 26-year-old Canadian national, operated as a cybercriminal targeting cloud storage environments for financial gain.
highperson_alertThreat ActorClickFix Campaign Uses Browser Fingerprinting to Target macOS Users
ClickFix is a macOS-focused social engineering campaign tracked by Microsoft Threat Intelligence. The operators remain unidentified, but the campaign demonstrates sophisticated evasion capabilities through server-side browser fingerprinting across mo…
highperson_alertThreat ActorPoipet Scam Network Leveraged ChatGPT for Multi-Scheme Fraud Operations
The Poipet scam network is a Cambodia-based organized criminal operation originating from Poipet, a city with extensive ties to scam compounds and human trafficking.
highperson_alertThreat ActorKali365 Campaign Weaponizes Microsoft Device Code Flow Against US Firms
Kali365 is a device code phishing campaign targeting US organizations through abuse of legitimate Microsoft authentication mechanisms. The campaign leverages a phishing kit designed to trick victims into approving attacker-controlled device codes on…
highperson_alertThreat ActorGreatness PhaaS Expands to AiTM and Device-Code Phishing via RingCentral
Greatness is a phishing-as-a-service (PhaaS) platform active since at least mid-2022, operated by cybercriminals who sell access for $289/month via a Telegram channel with thousands of subscribers.
highperson_alertThreat ActorMicrosoft Defender auto-isolates endpoint in 128 seconds at QNET
No specific threat actor is identified in this incident. The attack represents a common adversary pattern: initial access achieved directly on an endpoint, followed by attempted multi-stage payload delivery using living-off-the-land techniques.
highperson_alertThreat ActorSMOKE#SCREEN Campaign Deploys ScreenConnect via Fake Software Updates
SMOKE#SCREEN is an unattributed multi-wave campaign active as of August 2026 that leverages social engineering to deploy ConnectWise ScreenConnect RMM software for persistent remote access.
highbug_reportVulnerabilityGoogle removes ADK workflows after prompt injection exposed CI credentials
Google Agent Development Kit (ADK) Python repository on GitHub. Three workflows removed: issue-analyze.yml, issue-fix.yml, and pr-analyze.yml. Affected repository automation infrastructure, not the distributed ADK Python package itself.