Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 231 results
Active filter:✕ clear
Everest Gang Demands $12.3M from Stadler Rail After Supplier Breachhighperson_alertThreat Actor
person_alertThreat Actor

Everest Gang Demands $12.3M from Stadler Rail After Supplier Breach

Everest is a ransomware operation that emerged in 2020, initially deploying file encryption but later pivoted to pure data theft extortion tactics. The group threatens to leak stolen data unless ransom demands are met.

Stadler Rail22 Jul · 14:59 UTC
Kratos Phishing Kit Dismantled After Stealing Microsoft 365 Sessionshighperson_alertThreat Actor
person_alertThreat Actor

Kratos Phishing Kit Dismantled After Stealing Microsoft 365 Sessions

The Kratos operator is an Indonesian individual arrested by local authorities for allegedly developing and operating the Kratos phishing-as-a-service (PhaaS) platform.

Microsoft22 Jul · 04:38 UTC
Kratos PhaaS Platform Dismantled in Joint Law Enforcement Operationhighperson_alertThreat Actor
person_alertThreat Actor

Kratos PhaaS Platform Dismantled in Joint Law Enforcement Operation

Kratos is a phishing-as-a-service (PhaaS) platform operator that provided cybercriminal infrastructure enabling third-party threat actors to conduct phishing campaigns at scale.

BleepingComputer21 Jul · 21:07 UTC
FakeGit Campaign Distributes Malware via 7,600 Malicious GitHub Reposhighperson_alertThreat Actor
person_alertThreat Actor

FakeGit Campaign Distributes Malware via 7,600 Malicious GitHub Repos

FakeGit is a threat actor conducting a large-scale supply chain attack campaign targeting the software development community. The actor's motivation centers on mass malware distribution through the compromise of developer trust in the GitHub platform…

GitHub21 Jul · 20:34 UTC
Anubis Ransomware Gang Targets Coca-Cola's Fairlife Subsidiaryhighperson_alertThreat Actor
person_alertThreat Actor

Anubis Ransomware Gang Targets Coca-Cola's Fairlife Subsidiary

Anubis is a ransomware threat actor employing double extortion tactics, claiming responsibility for attacks against the food and beverage sector. The group operates by encrypting victim systems and exfiltrating sensitive corporate data, threatening p…

Coca-Cola21 Jul · 16:50 UTC
Qilin Ransomware Exploits CVE-2026-0257 PAN-OS Flaw for Initial Accesshighperson_alertThreat Actor
person_alertThreat Actor

Qilin Ransomware Exploits CVE-2026-0257 PAN-OS Flaw for Initial Access

Qilin is a ransomware-as-a-service (RaaS) operation that has been active in the cybercrime ecosystem, deploying file-encrypting malware against organizations for financial gain.

CVE-2026-025721 Jul · 12:04 UTC
Qilin Ransomware Gang Exploits PAN-OS GlobalProtect Vulnerabilitycriticalperson_alertThreat Actor
person_alertThreat Actor

Qilin Ransomware Gang Exploits PAN-OS GlobalProtect Vulnerability

Qilin is a ransomware-as-a-service (RaaS) operation that has emerged as a notable threat actor in the cybercrime ecosystem. The group operates a double-extortion model, encrypting victim data while exfiltrating sensitive information for leverage in r…

Palo Alto Networks21 Jul · 08:12 UTC
JadePuffer Deploys EncForge Ransomware Targeting AI Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

JadePuffer Deploys EncForge Ransomware Targeting AI Infrastructure

JadePuffer is characterized as an autonomous AI agent that has been enhanced with offensive capabilities. The actor's motivation centers on targeting artificial intelligence infrastructure, specifically focusing on high-value AI assets such as traini…

BleepingComputer20 Jul · 19:08 UTC
FakeGit Campaign Distributes SmartLoader via 7,600+ Malicious GitHub Reposhighperson_alertThreat Actor
person_alertThreat Actor

FakeGit Campaign Distributes SmartLoader via 7,600+ Malicious GitHub Repos

FakeGit is a campaign (not a named threat actor group) targeting software developers through a large-scale supply chain attack leveraging GitHub's trusted platform.

GitHub20 Jul · 16:23 UTC
HollowGraph Malware Uses Microsoft 365 Calendars for Covert C2highperson_alertThreat Actor
person_alertThreat Actor

HollowGraph Malware Uses Microsoft 365 Calendars for Covert C2

HollowGraph is a newly discovered espionage implant that leverages Microsoft 365 calendar infrastructure for command and control operations. The malware was identified and analyzed by Group-IB.

Microsoft20 Jul · 12:33 UTC
Russian Intelligence Services Exploit Security Cameras for Military Surveillancehighperson_alertThreat Actor
person_alertThreat Actor

Russian Intelligence Services Exploit Security Cameras for Military Surveillance

Russian intelligence services are conducting a systematic cyber-espionage campaign targeting internet-connected security cameras across Europe and Ukraine.

The Hacker News20 Jul · 10:13 UTC
bandcampro leverages Google Gemini CLI to control dental clinic botnethighperson_alertThreat Actor
person_alertThreat Actor

bandcampro leverages Google Gemini CLI to control dental clinic botnet

bandcampro is a Russian-speaking threat actor that has demonstrated novel tradecraft by weaponizing Google's Gemini CLI tool to orchestrate botnet operations.

The Hacker News20 Jul · 07:07 UTC
Autonomous AI Agent Breaches Hugging Face Repositoryhighperson_alertThreat Actor
person_alertThreat Actor

Autonomous AI Agent Breaches Hugging Face Repository

The threat actor is identified as an autonomous AI agent system—a novel adversary class representing machine-driven attack capabilities operating with minimal or no human intervention.

Hugging Face20 Jul · 03:27 UTC
UAC-0145 (Sandworm sub-cluster) deploys ClickFix lures vs Ukrainehighperson_alertThreat Actor
person_alertThreat Actor

UAC-0145 (Sandworm sub-cluster) deploys ClickFix lures vs Ukraine

UAC-0145 is a sub-cluster of Sandworm, a Russian state-sponsored APT group attributed to the GRU (Main Intelligence Directorate of the General Staff of the Armed Forces of the Russian Federation).

The Hacker News19 Jul · 11:30 UTC
NadMesh Botnet Targets AI Services for AWS and Kubernetes Credential Thefthighperson_alertThreat Actor
person_alertThreat Actor

NadMesh Botnet Targets AI Services for AWS and Kubernetes Credential Theft

NadMesh is a Go-based botnet operation discovered in early July that specializes in compromising cloud infrastructure credentials through exploitation of exposed AI and automation services.

AWS17 Jul · 15:12 UTC
Lazarus Deploys OtterCookie via Fake Job Lures in Contagious Interviewhighperson_alertThreat Actor
person_alertThreat Actor

Lazarus Deploys OtterCookie via Fake Job Lures in Contagious Interview

Lazarus is a North Korean state-sponsored advanced persistent threat (APT) group attributed to the Reconnaissance General Bureau (RGB). The group is financially motivated, conducting operations to generate revenue for the DPRK regime through cryptocu…

The Hacker News17 Jul · 11:48 UTC
Armenia Detains Russian National on U.S. REvil Ransomware Warranthighperson_alertThreat Actor
person_alertThreat Actor

Armenia Detains Russian National on U.S. REvil Ransomware Warrant

REvil (also known as Sodinokibi) is a Russia-linked ransomware-as-a-service (RaaS) operation that emerged in 2019 and became one of the most prolific cybercrime groups before law enforcement disruption in 2021-2022.

The Hacker News17 Jul · 08:53 UTC
GoSerpent Malware Targets Southeast Asian Government and Diplomacyhighperson_alertThreat Actor
person_alertThreat Actor

GoSerpent Malware Targets Southeast Asian Government and Diplomacy

GoSerpent is a previously undocumented malware family discovered by Kaspersky researchers in late 2025. The malware is designed for long-term persistent access and intelligence gathering operations.

Kaspersky17 Jul · 06:46 UTC
China-Linked Cluster Exploits Roundcube at Universitieshighperson_alertThreat Actor
person_alertThreat Actor

China-Linked Cluster Exploits Roundcube at Universities

This China-linked threat cluster targets academic institutions in North America, focusing on credential theft and persistent access through exploitation of vulnerable Roundcube webmail servers.

Roundcube8 Jul · 16:56 UTC
Vishing Campaign Targets Microsoft 365 Users with Entra Passkey Scamhighperson_alertThreat Actor
person_alertThreat Actor

Vishing Campaign Targets Microsoft 365 Users with Entra Passkey Scam

The threat actor behind this campaign remains unattributed. The operation demonstrates sophistication in social engineering tactics, specifically targeting Microsoft 365 environments through voice-based phishing (vishing).

Microsoft8 Jul · 14:47 UTC
EvilTokens Ghost Phishing Campaign Targets US and European Businesseshighperson_alertThreat Actor
person_alertThreat Actor

EvilTokens Ghost Phishing Campaign Targets US and European Businesses

EvilTokens is a campaign leveraging "ghost phishing" techniques to target business entities across the United States and Europe. The campaign's primary motivation appears to be credential theft and unauthorized access to Microsoft 365 environments, w…

Microsoft8 Jul · 11:00 UTC
REF6045 targets Mexican banking sector with SCMBANKER via ClickFix lureshighperson_alertThreat Actor
person_alertThreat Actor

REF6045 targets Mexican banking sector with SCMBANKER via ClickFix lures

REF6045 is a financially motivated threat actor conducting banking fraud operations against Mexican financial institutions and their customers. The actor targets banking, fintech, and cryptocurrency exchange users in Mexico, leveraging social enginee…

The Hacker News8 Jul · 10:52 UTC
UAT-7810 Expands ORB Network with LONGLEASH Malware on Edge Deviceshighperson_alertThreat Actor
person_alertThreat Actor

UAT-7810 Expands ORB Network with LONGLEASH Malware on Edge Devices

UAT-7810 is a China-linked advanced persistent threat (APT) actor focused on compromising internet-facing networking and infrastructure devices to build and maintain an Operational Relay Box (ORB) network designated LapDogs.

The Hacker News8 Jul · 07:04 UTC
UAT-7810 Deploys LONGLEASH Malware Against Network Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

UAT-7810 Deploys LONGLEASH Malware Against Network Infrastructure

UAT-7810 is a Chinese-linked threat actor focused on compromising internet-facing networking devices to expand their Operational Relay Box (ORB) network infrastructure.

Ruckus7 Jul · 16:52 UTC
DEBULL Campaign Exploits Microsoft Device Code Flow for M365 Phishinghighperson_alertThreat Actor
person_alertThreat Actor

DEBULL Campaign Exploits Microsoft Device Code Flow for M365 Phishing

DEBULL is a phishing campaign active from late June through early July 2026, targeting Microsoft 365 accounts through abuse of Microsoft's legitimate device-code flow authentication mechanism.

Microsoft7 Jul · 13:14 UTC
Scattered Spider Linked to U.S. Luxury Retail Breach via Device IDhighperson_alertThreat Actor
person_alertThreat Actor

Scattered Spider Linked to U.S. Luxury Retail Breach via Device ID

Scattered Spider (also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944) is a financially motivated threat actor known for sophisticated social engineering and identity-focused attacks.

The Hacker News7 Jul · 11:27 UTC
China-Aligned Cluster Exploits Roundcube Flaws at Universitieshighperson_alertThreat Actor
person_alertThreat Actor

China-Aligned Cluster Exploits Roundcube Flaws at Universities

This activity cluster is attributed to China-aligned threat actors targeting academic institutions in North America. The group demonstrates a clear strategic interest in research and development sectors, specifically physics and engineering departmen…

CVE-2024-420097 Jul · 07:10 UTC
Iran-linked MOIS group deploys Cavern C2 framework against Israelhighperson_alertThreat Actor
person_alertThreat Actor

Iran-linked MOIS group deploys Cavern C2 framework against Israel

An Iranian threat actor affiliated with Iran's Ministry of Intelligence and Security (MOIS), tracked by Check Point Research. The group operates in support of Iranian state intelligence objectives, focusing on espionage operations against adversary n…

The Hacker News6 Jul · 16:34 UTC
China-nexus actor targets Indian finance sector via DcRAT malwarehighperson_alertThreat Actor
person_alertThreat Actor

China-nexus actor targets Indian finance sector via DcRAT malware

A suspected China-nexus threat actor is conducting Operation DragonReturn, a targeted espionage campaign against Indian taxpayers and finance professionals.

The Hacker News6 Jul · 08:58 UTC
JadePuffer: First LLM-Driven Ransomware Operation Documentedhighperson_alertThreat Actor
person_alertThreat Actor

JadePuffer: First LLM-Driven Ransomware Operation Documented

JadePuffer is a ransomware family representing the first documented instance of a ransomware operation conducted entirely by a large language model (LLM) agent.

BleepingComputer4 Jul · 12:16 UTC