Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 390 results
highbug_reportVulnerabilityAI browsers leak credentials via BioShocking social engineering attack
Six AI browsers and assistants including OpenAI ChatGPT Atlas, Perplexity Comet, and Anthropic Claude browser extension. Attack exploits AI reasoning vulnerabilities to extract user credentials through game-based social engineering.
highperson_alertThreat ActorShinyHunters Exploits Oracle PeopleSoft Zero-Day in Nissan Breach
ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has established a pattern of exploiting vulnerabilities in enterprise applications to exfiltrate sensitive data, which is th…
highperson_alertThreat ActorShinyHunters Exploits Oracle PeopleSoft Zero-Day at NAIC
ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has historically targeted organizations to exfiltrate sensitive data, which is then leveraged for extortion or sold on under…
highperson_alertThreat ActorMalicious Chrome Extension Impersonates Perplexity AI to Intercept Searches
The threat actor behind this campaign remains unattributed. The operation demonstrates a financially or espionage-motivated adversary leveraging social engineering through brand impersonation of Perplexity AI, a popular search technology.
highperson_alertThreat ActorU.S. offers $10M reward for intel on UNC5792 and UNC4221 APT groups
UNC5792 and UNC4221 are threat actor groups attributed to Russian intelligence and military services. Both groups have been designated as high-priority targets by the U.S.
highperson_alertThreat ActorMustang Panda Targets Indian Government and Hydropower Infrastructure
Mustang Panda (also tracked as TA416, RedDelta, BRONZE PRESIDENT, and STATELY TAURUS) is a China-aligned advanced persistent threat group focused on espionage operations.
highbug_reportVulnerabilityStack buffer overflow in libxml2 enables code execution via malformed input
libxml2 library, all versions not yet patched. Affects systems and applications that parse XML using libxml2, including numerous Linux distributions, Python, PHP, and other software that depends on this widely-deployed XML parsing library.
highbug_reportVulnerability236K+ malicious sites use DCloud Uni-App templates for crypto scams
Organizations and users interacting with websites built using DCloud Uni-App framework templates. Over 236,000 malicious sites identified conducting cryptocurrency scams, phishing, wallet draining, pig-butchering schemes, and fake gambling platforms.
highperson_alertThreat ActorGamaredon APT Expands Ukraine Operations with 35 Spear-Phishing Campaigns
Gamaredon (also tracked as Armageddon, Shuckworm, Primitive Bear, and UAC-0010) is a Russian state-sponsored APT group attributed by multiple vendors to Russia's Federal Security Service (FSB).
highbug_reportVulnerabilityMicrosoft removes 119 malicious Edge extensions hiding malware via steganography
Microsoft Edge browser users who installed any of 119 malicious extensions from the official Microsoft Edge Add-ons store. Campaign active since at least 2021, affecting unknown number of users globally.
highbug_reportVulnerabilityMicrosoft Exchange privilege escalation flaw requires immediate patching
Microsoft Exchange Server 2016, 2019, and Subscription Edition. All on-premises deployments of these versions are potentially affected.
highbug_reportVulnerabilityHijacked npm and Go packages deploy cross-platform stealer via VS Code
Compromised npm and Go packages targeting developers using Microsoft Visual Studio Code on Windows, Linux, and macOS. Attack bypasses npm v12 lifecycle script protections by abusing VS Code task execution.
highpublicGeopoliticalKDDI breach exposes 14.2M email accounts across Japanese ISP ecosystem
The breach at KDDI Corporation, one of Japan's largest telecommunications operators, highlights systemic vulnerabilities in shared infrastructure models within critical communications sectors.
highperson_alertThreat ActorRussian Intelligence Services Target Messaging Accounts via Phishing
Russian intelligence services conducted a long-running credential harvesting campaign targeting messaging platforms. The operation, uncovered jointly by Ukraine's Security Service (SSU) and the FBI, focused on stealing authentication credentials from…
highbug_reportVulnerabilityAgentic coding tools vulnerable to hidden malicious payloads in repos
Agentic coding tools and AI-assisted development platforms that automatically fetch and execute code from GitHub repositories. Specific products not disclosed.
highperson_alertThreat ActorRussian Intelligence Services Target Signal Users in Phishing Campaign
Russian intelligence services are conducting a phishing campaign targeting Signal messaging application users. The operation is attributed by the FBI and CISA, indicating state-sponsored activity aimed at compromising secure communications.
highperson_alertThreat ActorRussian Intelligence Escalates Signal Phishing for Backup Recovery Keys
Russian intelligence actors, as identified by FBI and CISA joint reporting, are conducting targeted phishing operations against Signal messaging platform users.
highbug_reportVulnerabilitySharkLoader malware deploys Cobalt Strike in attacks on Asian governments
Diplomatic and government organizations in Indonesia and Taiwan. SharkLoader is a newly identified malware family used to deliver Cobalt Strike Beacon payloads in the StrikeShark campaign.
highbug_reportVulnerabilityPolymarket frontend compromised via third-party vendor; $3M stolen
Polymarket platform users. Attack vector: malicious JavaScript injected into frontend via compromised third-party vendor. Approximately $3 million in customer funds stolen. No CVE assigned.
highperson_alertThreat ActorUnknown Actors Exploit OpenAI Tenants to Phish Cybersecurity Firms
The threat actors behind this campaign remain unattributed. Their motivation appears to be intelligence gathering and corporate espionage, leveraging the trust associated with OpenAI's platform to deceive employees of cybersecurity companies.
highperson_alertThreat ActorCL-STA-1062 deploys TinyRCT backdoor against Southeast Asian government
CL-STA-1062 is a Chinese-speaking APT actor conducting targeted cyber espionage operations against government entities and critical infrastructure in Southeast Asia.
highbug_reportVulnerabilityAmazon Q Developer flaw allows credential theft via malicious repos
Amazon Q Developer (all versions prior to patch). Affects developers using the IDE plugin who clone or open malicious repositories containing crafted Model Context Protocol (MCP) server configurations.
highbug_reportVulnerabilityDirtyClone Linux kernel flaw enables local privilege escalation to root
Linux kernel (specific vulnerable versions not disclosed). Affects systems where local users can trigger network packet cloning operations. Part of the DirtyFrag vulnerability family.
highbug_reportVulnerabilityMiasma malware compromises npm packages LeoPlatform and RStreams
npm packages LeoPlatform and RStreams compromised by Miasma malware family. Attack extends to GitHub Actions workflows and Go ecosystem. Organizations using these packages or dependent projects are affected.
highbug_reportVulnerabilityPhishing campaign targets hotel front desks with Node.js implant
Hotel and hospitality organizations in Europe and Asia. Front-desk systems targeted via photo-themed ZIP file attachments containing Node.js-based malware. Campaign active since April 2026.
highperson_alertThreat ActorPolish Authorities Dismantle SIM-Swapping Gang Targeting Crypto Assets
This organized cybercrime group operated in Poland, conducting SIM-swapping attacks with the primary motivation of financial gain through cryptocurrency theft.
highbug_reportVulnerabilityActive campaign targets hospitality in Europe/Asia via ZIP archives
Hospitality organizations in Europe and Asia. Attack vector: photo-themed ZIP archives containing malicious shortcut files that deploy a Node.js implant.
highperson_alertThreat ActorCL-STA-1062 targets Southeast Asian government with TinyRCT backdoor
CL-STA-1062 is a threat actor conducting cyber espionage operations against government entities and critical infrastructure in Southeast Asia. The actor employs a hybrid toolkit centered around a custom backdoor known as TinyRCT.
highbug_reportVulnerabilityShopify Shop app abused for callback phishing via fake order receipts
Shopify Shop order-tracking app users. Threat actors inject fraudulent purchase receipts into legitimate user order histories, leveraging Shopify's trusted platform to deliver phishing lures.
highbug_reportVulnerabilityBluekit PhaaS expands with 70 new domains, adds browser-in-the-middle
Organizations using cloud services and SaaS platforms targeted by Bluekit phishing-as-a-service infrastructure. Approximately 70 new phishing hostnames deployed in the past week.