Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 356 results
Active filter:tag: #threat-actor✕ clear
DeadLock Ransomware Leverages Polygon Blockchain for Resilient Extortionhighperson_alertThreat Actor
person_alertThreat Actor

DeadLock Ransomware Leverages Polygon Blockchain for Resilient Extortion

DeadLock is a ransomware group first detected in July 2025, operating double extortion campaigns that encrypt victim environments and threaten public data release.

Polygon11 Aug · 14:35 UTC
ExfilSquad Claims 2.6M Records Stolen from Wesco CRM Environmenthighperson_alertThreat Actor
person_alertThreat Actor

ExfilSquad Claims 2.6M Records Stolen from Wesco CRM Environment

ExfilSquad is a data extortion group that specializes in exfiltrating sensitive information from organizations and leveraging it for ransom demands. The group operates a data leak site where they publish stolen data after ransom deadlines expire.

Wesco11 Aug · 13:59 UTC
North Korea IT Worker Infiltration Targets Crypto and Tech Firmshighperson_alertThreat Actor
person_alertThreat Actor

North Korea IT Worker Infiltration Targets Crypto and Tech Firms

North Korean IT worker operations, attributed by researchers to Famous Chollima (a CrowdStrike designation under the Lazarus umbrella), involve operatives seeking employment at Western technology and cryptocurrency companies under fraudulent identiti…

The Hacker News11 Aug · 09:35 UTC
Storm-1175 Deploys New StormEncryptor Ransomware After Medusa Splithighperson_alertThreat Actor
person_alertThreat Actor

Storm-1175 Deploys New StormEncryptor Ransomware After Medusa Split

Storm-1175 is a financially motivated threat actor believed to be based in China, previously affiliated with the Medusa ransomware operation. Microsoft Threat Intelligence tracks this actor as a former Medusa affiliate who has now shifted to deployin…

BleepingComputer10 Aug · 15:42 UTC
Storm-1175 Deploys StormEncryptor Ransomware via N-central Exploithighperson_alertThreat Actor
person_alertThreat Actor

Storm-1175 Deploys StormEncryptor Ransomware via N-central Exploit

Storm-1175 is a China-linked, financially motivated threat actor tracked by Microsoft. The group specializes in high-velocity ransomware operations, exploiting both zero-day and N-day vulnerabilities in internet-facing enterprise software to gain ini…

Microsoft10 Aug · 14:38 UTC
DeadLock Ransomware: Rust-Based Encryptor with Decentralized Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

DeadLock Ransomware: Rust-Based Encryptor with Decentralized Infrastructure

DeadLock is a financially motivated ransomware operation first observed in July 2025. It is not attributed to a single threat actor but has been deployed by multiple groups, including affiliates of the Lynx and INC ransomware ecosystems.

Microsoft10 Aug · 13:00 UTC
Ransomware Gangs Exploit SonicWall SMA1000 SSRF and Auth Bypass Flawscriticalperson_alertThreat Actor
person_alertThreat Actor

Ransomware Gangs Exploit SonicWall SMA1000 SSRF and Auth Bypass Flaws

The actors are ransomware gangs—a broad category of financially motivated cybercrime operators—actively exploiting recently patched SonicWall SMA1000 vulnerabilities.

SonicWall10 Aug · 12:34 UTC
Kimsuky Deploys Offline AI Stack for Enhanced Phishing and Malware Automationhighperson_alertThreat Actor
person_alertThreat Actor

Kimsuky Deploys Offline AI Stack for Enhanced Phishing and Malware Automation

Kimsuky (also tracked as Black Banshee, Velvet Chollima, Emerald Sleet, THALLIUM) is a North Korean state-sponsored APT group operating under the Reconnaissance General Bureau. Sanctioned by the U.S.

The Hacker News10 Aug · 11:19 UTC
The Com cybercrime collective member sentenced for sextortionhighperson_alertThreat Actor
person_alertThreat Actor

The Com cybercrime collective member sentenced for sextortion

The Com (short for "Community") is a loose-knit online cybercrime collective that targets children and teenagers through multiple specialized subgroups.

BleepingComputer10 Aug · 10:56 UTC
Head Mare Exploits TrueConf Flaws to Deploy PhantomCore Backdoorhighperson_alertThreat Actor
person_alertThreat Actor

Head Mare Exploits TrueConf Flaws to Deploy PhantomCore Backdoor

Head Mare is a threat actor conducting targeted intrusion operations against Russian organizations across critical infrastructure and technology sectors.

TrueConf10 Aug · 09:33 UTC
December 2025 Poland Energy Sector Campaign via Private APNhighperson_alertThreat Actor
person_alertThreat Actor

December 2025 Poland Energy Sector Campaign via Private APN

No specific threat actor has been publicly attributed to this campaign. The December 2025 attacks targeted Poland's energy infrastructure with purely destructive intent, representing a coordinated operation against multiple facilities including wind…

CERT.PL (Poland)8 Aug · 15:00 UTC
Head Mare hacktivists backdoor TrueConf installers via server compromisecriticalbug_reportVulnerability
bug_reportVulnerability

Head Mare hacktivists backdoor TrueConf installers via server compromise

TrueConf video conferencing servers (unpatched versions) and client installers distributed from compromised servers. Specific vulnerable versions not disclosed. Affects organizations using TrueConf for video conferencing.

TrueConf8 Aug · 12:16 UTC
Atlassian Rovo prompt injection enables data exfiltration from Jira/Confluencehighbug_reportVulnerability
bug_reportVulnerability

Atlassian Rovo prompt injection enables data exfiltration from Jira/Confluence

Atlassian Rovo assistant on Standard, Premium, and Enterprise plans. Affects organizations with Rovo enabled (default setting). Exploitable by authenticated users who interact with attacker-controlled content (documents) or links (rovoChatPrompt para…

Atlassian8 Aug · 06:54 UTC
Nearly 800 malicious npm packages deliver cross-platform RAT via typosquattingcriticalbug_reportVulnerability
bug_reportVulnerability

Nearly 800 malicious npm packages deliver cross-platform RAT via typosquatting

npm registry: ~800 packages using typosquatting and AI-generated names. Targets all Node.js developers on Windows, macOS (x64/ARM64), and Linux (x64/ARM64). Delivers WEL1DROPPER leading to Sliver C2 framework and platform-specific infostealers.

npm7 Aug · 16:48 UTC
UNC6671 Conducts Vishing Attacks to Steal SaaS Credentialshighperson_alertThreat Actor
person_alertThreat Actor

UNC6671 Conducts Vishing Attacks to Steal SaaS Credentials

UNC6671 is a financially motivated data extortion group that emerged in early January 2026. The actor operates multiple extortion brands including Redact, Pink (CL-CRI-1147), Helix, and Falcon (CL-CRI-1182), and previously operated under the BlackFil…

The Hacker News7 Aug · 16:16 UTC
WordPress pre-auth XSS on login page enables RCE via admin interactionhighbug_reportVulnerability
bug_reportVulnerability

WordPress pre-auth XSS on login page enables RCE via admin interaction

WordPress CMS all versions prior to 7.0.3. Patches backported to 4.7 branch and newer. Versions older than 4.7 remain vulnerable and unpatched. Default installations affected; no special hosting configuration required.

CVE-2026-646387 Aug · 10:56 UTC
18-year-old Linux SCTP flaw enables local root and container escapecriticalbug_reportVulnerability
bug_reportVulnerability

18-year-old Linux SCTP flaw enables local root and container escape

Linux kernel versions since 2.6.25 (2008) through 7.1.5, 6.18.41, 6.12.100, and 6.6.147. Affects systems with SCTP networking enabled. Confirmed vulnerable: Debian 13, Ubuntu 24.04, Rocky Linux 9, RHEL 9, OpenCloudOS.

Linux7 Aug · 09:10 UTC
UNC6671 extortion group targets financial sector via vishing attackshighperson_alertThreat Actor
person_alertThreat Actor

UNC6671 extortion group targets financial sector via vishing attacks

UNC6671 is a financially motivated extortion group tracked by Google Threat Intelligence Group (GTIG) that operates under multiple public brands including BlackFile, Redact, Pink, Helix, and Falcon.

BleepingComputer6 Aug · 18:07 UTC
Canadian Cybercriminal Connor Moucka Pleads Guilty to Snowflake Breachcriticalperson_alertThreat Actor
person_alertThreat Actor

Canadian Cybercriminal Connor Moucka Pleads Guilty to Snowflake Breach

Connor Riley Moucka (aliases "Judische," "Waifu") is a 26-year-old Canadian software engineer from Kitchener, Ontario, who operated as a cybercriminal since at least 2020.

Snowflake6 Aug · 15:00 UTC
CryptoJS weak RNG drained $5.7M from five crypto wallets over 12 yearscriticalbug_reportVulnerability
bug_reportVulnerability

CryptoJS weak RNG drained $5.7M from five crypto wallets over 12 years

CryptoJS versions below 4.0.0 (except 3.2.0 and 3.2.1). Five confirmed affected wallet apps: RRWallet (discontinued), Bexo Wallet (fixed in 20.1.0, builds pending), NanChat (fixed in 1.3.0), Bitcoin Libre (fixed in v4, July 2024), and Milo (discontin…

CryptoJS6 Aug · 09:49 UTC
Cybercriminals Steal AI API Keys via Token Jacking for Resalehighperson_alertThreat Actor
person_alertThreat Actor

Cybercriminals Steal AI API Keys via Token Jacking for Resale

Cybercriminals targeting the AI development ecosystem are motivated by financial gain through the theft and resale of API keys (tokens) for premium AI platforms.

Unit 42 (Palo Alto)6 Aug · 08:00 UTC
Ransom Cartel Creator Maksim Silnikau Sentenced to 16 Yearshighperson_alertThreat Actor
person_alertThreat Actor

Ransom Cartel Creator Maksim Silnikau Sentenced to 16 Years

Maksim Silnikau is a 40-year-old Belarusian national who created and administered the Ransom Cartel ransomware-as-a-service (RaaS) operation. Active on Russian-speaking cybercrime forums since at least 2005, Silnikau operated under aliases including…

BleepingComputer5 Aug · 21:00 UTC
Canadian Cybercriminal Pleads Guilty to Snowflake Data Theft Campaignhighperson_alertThreat Actor
person_alertThreat Actor

Canadian Cybercriminal Pleads Guilty to Snowflake Data Theft Campaign

Connor Riley Moucka (also known as Alexander Moucka and "Waifu"), a 26-year-old Canadian national, operated as a cybercriminal targeting cloud storage environments for financial gain.

Snowflake5 Aug · 19:53 UTC
ClickFix Campaign Uses Browser Fingerprinting to Target macOS Usershighperson_alertThreat Actor
person_alertThreat Actor

ClickFix Campaign Uses Browser Fingerprinting to Target macOS Users

ClickFix is a macOS-focused social engineering campaign tracked by Microsoft Threat Intelligence. The operators remain unidentified, but the campaign demonstrates sophisticated evasion capabilities through server-side browser fingerprinting across mo…

Apple5 Aug · 16:44 UTC
Poipet Scam Network Leveraged ChatGPT for Multi-Scheme Fraud Operationshighperson_alertThreat Actor
person_alertThreat Actor

Poipet Scam Network Leveraged ChatGPT for Multi-Scheme Fraud Operations

The Poipet scam network is a Cambodia-based organized criminal operation originating from Poipet, a city with extensive ties to scam compounds and human trafficking.

OpenAI5 Aug · 16:33 UTC
Kali365 Campaign Weaponizes Microsoft Device Code Flow Against US Firmshighperson_alertThreat Actor
person_alertThreat Actor

Kali365 Campaign Weaponizes Microsoft Device Code Flow Against US Firms

Kali365 is a device code phishing campaign targeting US organizations through abuse of legitimate Microsoft authentication mechanisms. The campaign leverages a phishing kit designed to trick victims into approving attacker-controlled device codes on…

Microsoft5 Aug · 09:43 UTC
Greatness PhaaS Expands to AiTM and Device-Code Phishing via RingCentralhighperson_alertThreat Actor
person_alertThreat Actor

Greatness PhaaS Expands to AiTM and Device-Code Phishing via RingCentral

Greatness is a phishing-as-a-service (PhaaS) platform active since at least mid-2022, operated by cybercriminals who sell access for $289/month via a Telegram channel with thousands of subscribers.

Microsoft4 Aug · 19:45 UTC
Microsoft Defender auto-isolates endpoint in 128 seconds at QNEThighperson_alertThreat Actor
person_alertThreat Actor

Microsoft Defender auto-isolates endpoint in 128 seconds at QNET

No specific threat actor is identified in this incident. The attack represents a common adversary pattern: initial access achieved directly on an endpoint, followed by attempted multi-stage payload delivery using living-off-the-land techniques.

Microsoft4 Aug · 15:54 UTC
SMOKE#SCREEN Campaign Deploys ScreenConnect via Fake Software Updateshighperson_alertThreat Actor
person_alertThreat Actor

SMOKE#SCREEN Campaign Deploys ScreenConnect via Fake Software Updates

SMOKE#SCREEN is an unattributed multi-wave campaign active as of August 2026 that leverages social engineering to deploy ConnectWise ScreenConnect RMM software for persistent remote access.

Adobe4 Aug · 11:11 UTC
Google removes ADK workflows after prompt injection exposed CI credentialshighbug_reportVulnerability
bug_reportVulnerability

Google removes ADK workflows after prompt injection exposed CI credentials

Google Agent Development Kit (ADK) Python repository on GitHub. Three workflows removed: issue-analyze.yml, issue-fix.yml, and pr-analyze.yml. Affected repository automation infrastructure, not the distributed ADK Python package itself.

Google4 Aug · 09:16 UTC