Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-21 · 02:09 UTC
articleTotal: 606 reports

Filtered Reports

30 / 122 results
Active filter:tag: #campaign✕ clear
Meta AI bot exploited to hijack high-profile Instagram accountshighbug_reportVulnerability
bug_reportVulnerability

Meta AI bot exploited to hijack high-profile Instagram accounts

Meta Instagram platform, specifically the AI-powered customer support bot used for account recovery. High-profile accounts including Obama White House and U.S. Space Force Chief Master Sergeant were compromised.

Meta15:32 UTC
Malware campaign infects 2,000 WordPress sites using Steam profiles for C2highbug_reportVulnerability
bug_reportVulnerability

Malware campaign infects 2,000 WordPress sites using Steam profiles for C2

Nearly 2,000 WordPress websites compromised. All WordPress versions potentially affected depending on initial infection vector (likely vulnerable plugins, themes, or weak credentials).

WordPress15:04 UTC
Operation Dragon Weave targets Czech and Taiwan entities with AdaptixC2highperson_alertThreat Actor
person_alertThreat Actor

Operation Dragon Weave targets Czech and Taiwan entities with AdaptixC2

Operation Dragon Weave is a cyber espionage campaign linked to China-aligned threat actors. The campaign's motivation appears to be intelligence collection targeting government officials, researchers, academics, and professionals in the Czech Republi…

The Hacker News09:54 UTC
Dutch authorities dismantle botnet controlling 17M infected deviceshighbug_reportVulnerability
bug_reportVulnerability

Dutch authorities dismantle botnet controlling 17M infected devices

At least 17 million infected devices globally including computers, tablets, smartphones, and IoT devices. Over 200 command-and-control servers located in the Netherlands were seized.

The Hacker News10:22 UTC
Threat actors abuse ChatGPT sharing to host fake OpenAI outage pageshighbug_reportVulnerability
bug_reportVulnerability

Threat actors abuse ChatGPT sharing to host fake OpenAI outage pages

OpenAI ChatGPT users globally. Threat actors exploit ChatGPT's legitimate content-sharing feature (chatgpt.com shared links) to host convincing phishing pages that impersonate OpenAI outage notifications and distribute malware posing as the ChatGPT d…

OpenAI16:21 UTC
Dutch authorities disrupt 17M-device botnet, seize 200+ servershighbug_reportVulnerability
bug_reportVulnerability

Dutch authorities disrupt 17M-device botnet, seize 200+ servers

Approximately 17 million infected devices globally; over 200 servers seized from a Dutch hosting provider. Specific botnet malware family and affected device types not disclosed.

BleepingComputer12:26 UTC
Mini Shai-Hulud: Typosquatted npm Packages Target Developer Credentialshighperson_alertThreat Actor
person_alertThreat Actor

Mini Shai-Hulud: Typosquatted npm Packages Target Developer Credentials

Mini Shai-Hulud is a threat actor campaign focused on compromising software development environments through supply chain attacks. The actor leverages typosquatting techniques against the npm package ecosystem to distribute malicious packages that ma…

npm01:04 UTC
GreyVibe Targets Ukraine with AI-Generated Lures and Custom Malwarehighperson_alertThreat Actor
person_alertThreat Actor

GreyVibe Targets Ukraine with AI-Generated Lures and Custom Malware

GreyVibe is a threat cluster assessed with moderate confidence to be linked to Russian interests, based on targeting patterns and geopolitical alignment.

BleepingComputer20:24 UTC
BTMOB Android RAT offered as MaaS with custom phishing builderhighbug_reportVulnerability
bug_reportVulnerability

BTMOB Android RAT offered as MaaS with custom phishing builder

Android devices targeted by BTMOB remote access trojan. No specific vendor or version restrictions; affects users who install malicious APKs distributed through phishing campaigns.

BleepingComputer19:10 UTC
FBI warns of FIFA-impersonating fraud sites targeting 2026 World Cuphighperson_alertThreat Actor
person_alertThreat Actor

FBI warns of FIFA-impersonating fraud sites targeting 2026 World Cup

Unknown fraud operators are conducting financially motivated cybercrime campaigns targeting fans and consumers interested in the 2026 FIFA World Cup. These actors leverage social engineering and brand impersonation tactics to establish fraudulent web…

BleepingComputer17:08 UTC
Arctic Wolf exploits FortiClient EMS flaw for credential thefthighperson_alertThreat Actor
person_alertThreat Actor

Arctic Wolf exploits FortiClient EMS flaw for credential theft

Arctic Wolf is a threat actor exploiting a critical, patched vulnerability in FortiClient Endpoint Management Server (EMS) to deploy credential-stealing malware.

Fortinet13:26 UTC
JINX-0164 Targets Cryptocurrency Orgs with macOS Malwarehighperson_alertThreat Actor
person_alertThreat Actor

JINX-0164 Targets Cryptocurrency Orgs with macOS Malware

JINX-0164 is a previously undocumented threat actor with a financial motivation focused on digital asset theft. The group demonstrates technical sophistication through the development of custom macOS malware and operational tradecraft centered on soc…

The Hacker News05:54 UTC
Cryptojacking campaign uses SEO poisoning and AI chatbots for GPU malwarehighbug_reportVulnerability
bug_reportVulnerability

Cryptojacking campaign uses SEO poisoning and AI chatbots for GPU malware

High-performance systems with GPUs accessed via search engines and AI chatbot platforms. No specific vendor or product vulnerability; targets users searching for legitimate software or information through poisoned search results and manipulated chatb…

BleepingComputer19:31 UTC
Banking trojans Grandoreiro and BTMOB target LATAM and Europehighbug_reportVulnerability
bug_reportVulnerability

Banking trojans Grandoreiro and BTMOB target LATAM and Europe

Windows and Android devices in Latin America (Brazil, Mexico) and Europe (Spain, Portugal). Grandoreiro targets Windows systems at companies; BTMOB RAT targets Android mobile users in Brazil.

Windows14:10 UTC
Silent Ransom Group Shifts to Physical Data Theft at U.S. Law Firmshighperson_alertThreat Actor
person_alertThreat Actor

Silent Ransom Group Shifts to Physical Data Theft at U.S. Law Firms

Silent Ransom Group (SRG) is an extortion-focused threat actor that has evolved from traditional ransomware operations to conducting physical, in-person data theft attacks.

BleepingComputer09:51 UTC
AI chatbot abuse delivers cryptojacking malware via social engineeringhighbug_reportVulnerability
bug_reportVulnerability

AI chatbot abuse delivers cryptojacking malware via social engineering

Users of AI chatbots (platform-agnostic); Windows systems targeted for cryptojacking payload deployment. Campaign actively observed by Microsoft; no specific product vulnerability, relies on social engineering.

Microsoft05:45 UTC
Cryptojacking campaign uses SEO poisoning and ScreenConnect for GPU mininghighbug_reportVulnerability
bug_reportVulnerability

Cryptojacking campaign uses SEO poisoning and ScreenConnect for GPU mining

Organizations using ScreenConnect remote access software; high-performance PCs with GPUs; users searching for compromised topics via search engines and AI chatbots. Campaign leverages Microsoft .NET utilities for execution.

Microsoft19:35 UTC
Nimbus Manticore deploys MiniFast and MiniJunk V2 via phishing and SEO poisoninghighperson_alertThreat Actor
person_alertThreat Actor

Nimbus Manticore deploys MiniFast and MiniJunk V2 via phishing and SEO poisoning

Nimbus Manticore (also tracked as Screening Serpens and UNC1549) is an Iranian state-sponsored threat actor attributed to Iran's intelligence apparatus.

The Hacker News05:13 UTC
FBI warns of Kali365 phishing-as-a-service targeting Microsoft 365highperson_alertThreat Actor
person_alertThreat Actor

FBI warns of Kali365 phishing-as-a-service targeting Microsoft 365

Kali365 is a phishing-as-a-service (PhaaS) platform that enables threat actors to conduct credential harvesting and account takeover operations against Microsoft 365 users.

Microsoft10:45 UTC
ClickFix Campaign Exploits Ghost CMS SQLi to Inject Malicious JavaScriptcriticalperson_alertThreat Actor
person_alertThreat Actor

ClickFix Campaign Exploits Ghost CMS SQLi to Inject Malicious JavaScript

The threat actor behind this campaign remains unattributed. Motivation appears to be financially driven, leveraging ClickFix social engineering tactics to deliver malware or steal credentials.

CVE-2026-2698012:12 UTC
First VPN Service dismantled by European and North American authoritieshighperson_alertThreat Actor
person_alertThreat Actor

First VPN Service dismantled by European and North American authorities

First VPN Service was a criminal VPN infrastructure provider that facilitated cybercrime operations for approximately 25 ransomware groups. The service enabled threat actors to obscure their geographic origins and true IP addresses during malicious a…

The Hacker News15:35 UTC
F5 BIG-IP Exploitation Leads to Confluence Compromise and Lateral Movementhighperson_alertThreat Actor
person_alertThreat Actor

F5 BIG-IP Exploitation Leads to Confluence Compromise and Lateral Movement

The threat actor behind this campaign remains unattributed. Motivation appears to be credential theft and network persistence within enterprise environments.

F514:53 UTC
Ghostwriter Targets Ukrainian Government with Prometheus-Themed Phishinghighperson_alertThreat Actor
person_alertThreat Actor

Ghostwriter Targets Ukrainian Government with Prometheus-Themed Phishing

Ghostwriter (also tracked as UAC-0057 and UNC1151) is a Belarus-aligned threat actor known for conducting information operations and cyber espionage campaigns.

The Hacker News14:20 UTC
Megalodon campaign injects 5,718 malicious commits into GitHub reposhighperson_alertThreat Actor
person_alertThreat Actor

Megalodon campaign injects 5,718 malicious commits into GitHub repos

Megalodon is an automated supply chain attack campaign targeting GitHub repositories. The actor's motivation appears to be exfiltration of CI/CD environment data, including secrets, tokens, and credentials stored in GitHub Actions workflows.

GitHub09:55 UTC
Canadian National Arrested for Operating KimWolf DDoS Botnethighperson_alertThreat Actor
person_alertThreat Actor

Canadian National Arrested for Operating KimWolf DDoS Botnet

A Canadian national arrested by U.S. and Canadian authorities for operating the KimWolf DDoS botnet infrastructure. The operator managed a large-scale botnet that compromised nearly two million devices globally, offering DDoS-for-hire services.

BleepingComputer07:01 UTC
Jacob Butler Arrested for Operating Kimwolf DDoS Botnethighperson_alertThreat Actor
person_alertThreat Actor

Jacob Butler Arrested for Operating Kimwolf DDoS Botnet

Jacob Butler, also known as "Dort," is a 23-year-old Canadian national from Ottawa arrested by the U.S. Department of Justice for developing and operating the Kimwolf DDoS botnet.

The Hacker News06:50 UTC
Dort Arrested for Operating Kimwolf IoT Botnet in Multi-Million Device DDoS Campaignhighperson_alertThreat Actor
person_alertThreat Actor

Dort Arrested for Operating Kimwolf IoT Botnet in Multi-Million Device DDoS Campaign

Dort is a 23-year-old cybercriminal based in Ottawa, Canada, suspected of developing and operating the Kimwolf IoT botnet. Motivated by launching large-scale DDoS attacks, doxing, and swatting campaigns, Dort leveraged compromised IoT devices to buil…

Krebs on Security19:50 UTC
Showboat Linux Malware Targets Middle East Telecom Since Mid-2022highperson_alertThreat Actor
person_alertThreat Actor

Showboat Linux Malware Targets Middle East Telecom Since Mid-2022

The threat actor behind Showboat remains unattributed. The campaign demonstrates sophisticated targeting of telecommunications infrastructure in the Middle East, suggesting a motivated adversary with strategic intelligence collection objectives.

The Hacker News12:17 UTC
Chinese APT Deploys Showboat and JFMBackdoor Against Telecom Sectorhighperson_alertThreat Actor
person_alertThreat Actor

Chinese APT Deploys Showboat and JFMBackdoor Against Telecom Sector

Chinese state-sponsored threat actors conducting cyber-espionage operations against telecommunications infrastructure. The actors demonstrate cross-platform capabilities with custom Linux and Windows malware tooling.

BleepingComputer12:00 UTC
Microsoft Disrupts Fox Tempest Malware-Signing-as-a-Service Operationcriticalperson_alertThreat Actor
person_alertThreat Actor

Microsoft Disrupts Fox Tempest Malware-Signing-as-a-Service Operation

Fox Tempest is a threat actor attributed by Microsoft as operating a malware-signing-as-a-service (MSaaS) business model. The actor exploited Microsoft's Artifact Signing system to provide malicious code signing services to other cybercriminals, enab…

Microsoft12:36 UTC