Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 685 results
Active filter:tag: #high✕ clear
Clop Ransomware Gang Exploits CVE-2026-12569 in PTC Windchill Attackshighperson_alertThreat Actor
person_alertThreat Actor

Clop Ransomware Gang Exploits CVE-2026-12569 in PTC Windchill Attacks

Clop is a financially motivated ransomware gang known for mass exploitation campaigns targeting zero-day and n-day vulnerabilities in enterprise software.

Shell14 Aug · 09:55 UTC
ShinyHunters Breaches RingCentral, Leaks 1.6M Account Recordshighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Breaches RingCentral, Leaks 1.6M Account Records

ShinyHunters is a financially motivated extortion group that operates a "pay or leak" model, demanding ransom payments from breached organizations and publishing stolen data on dark web leak sites when victims refuse to pay.

RingCentral14 Aug · 08:52 UTC
Former Brightly Software Contractor Sentenced for $2.5M Extortionhighperson_alertThreat Actor
person_alertThreat Actor

Former Brightly Software Contractor Sentenced for $2.5M Extortion

Cameron Curry (alias "Loot"), a 27-year-old North Carolina resident, was a former data analyst contractor for Brightly Software (formerly SchoolDude, acquired by Siemens in 2022).

Brightly Software14 Aug · 06:27 UTC
Akira Ransomware Affiliate Uses Safe Mode to Evade EDR, Fails Encryptionhighperson_alertThreat Actor
person_alertThreat Actor

Akira Ransomware Affiliate Uses Safe Mode to Evade EDR, Fails Encryption

Akira (also tracked as GOLD SAHARA, PUNK SPIDER, and Howling Scorpius) is a ransomware operation that emerged as a significant threat actor conducting double extortion attacks.

BleepingComputer13 Aug · 18:47 UTC
Jewelbug APT Conducts Dual-Track Espionage and Crypto Fraudhighperson_alertThreat Actor
person_alertThreat Actor

Jewelbug APT Conducts Dual-Track Espionage and Crypto Fraud

Jewelbug (also tracked as Earth Alux and REF7707) is a China-based threat actor conducting parallel espionage and financially-motivated operations. The group targets government and military entities across the Middle East, Southeast Asia, and South A…

BleepingComputer13 Aug · 16:15 UTC
Microsoft patches LegacyHive Windows zero-day granting admin privilegeshighbug_reportVulnerability
bug_reportVulnerability

Microsoft patches LegacyHive Windows zero-day granting admin privileges

Windows User Profile Service in Windows 10 version 2004 and later, Windows Server 2022 and later. Tracked as CVE-2026-62832. All Windows systems running affected versions are vulnerable.

Microsoft13 Aug · 15:46 UTC
Plesk privilege escalation flaw requires immediate patchinghighbug_reportVulnerability
bug_reportVulnerability

Plesk privilege escalation flaw requires immediate patching

Plesk web hosting control panel - specific affected versions not disclosed in advisory. Privilege escalation vulnerability allows attackers to gain elevated access.

Plesk13 Aug · 13:01 UTC
City-Forum Campaign Targets Salesforce and ServiceNow Portalshighperson_alertThreat Actor
person_alertThreat Actor

City-Forum Campaign Targets Salesforce and ServiceNow Portals

City-Forum is an ongoing data theft campaign, not a formally attributed threat actor group. The campaign has been active since at least March 2025 and is characterized by consistent infrastructure use—a single IP address (158.220.87.79) hosted by Ger…

Salesforce12 Aug · 21:07 UTC
WindRelay NFC relay malware + SpyNote RAT steal cards, take loanshighbug_reportVulnerability
bug_reportVulnerability

WindRelay NFC relay malware + SpyNote RAT steal cards, take loans

Android devices in Czechia, Slovakia, and Slovenia. WindRelay NFC relay malware deployed alongside SpyNote RAT (and variants SpyMax, CypherRAT). 24 WindRelay samples identified on VirusTotal from November 2025 to July 2026.

BleepingComputer12 Aug · 20:22 UTC
737 fake Chrome VPN extensions route traffic through attacker SOCKS5 proxieshighbug_reportVulnerability
bug_reportVulnerability

737 fake Chrome VPN extensions route traffic through attacker SOCKS5 proxies

Google Chrome Web Store users who installed any of 737 malicious extensions impersonating VPN/proxy services (Proton VPN, NordVPN, Surfshark, ExpressVPN, Cloudflare 1.1.1.1). Approximately 75,000 downloads recorded, primarily Russian users.

Google12 Aug · 16:54 UTC
Plug and Pwn attacks exploit Windows Plug and Play for SYSTEM accesshighbug_reportVulnerability
bug_reportVulnerability

Plug and Pwn attacks exploit Windows Plug and Play for SYSTEM access

All Windows systems (including fully patched Windows 11) that support Plug and Play device installation. Specific vulnerable vendor packages include Sierra Wireless and Sony FeliCa software.

Microsoft12 Aug · 14:05 UTC
Cybercriminals Target Social Media Accounts for Sexual Exploitationhighperson_alertThreat Actor
person_alertThreat Actor

Cybercriminals Target Social Media Accounts for Sexual Exploitation

Unattributed cybercriminals conducting coordinated account compromise campaigns targeting social media and online service accounts belonging to adults, children, and student-athletes in the United States.

BleepingComputer12 Aug · 12:15 UTC
737 malicious Chrome VPN extensions route traffic through attacker proxieshighbug_reportVulnerability
bug_reportVulnerability

737 malicious Chrome VPN extensions route traffic through attacker proxies

Google Chrome users who installed any of 737 malicious VPN/proxy extensions from Chrome Web Store, primarily targeting Russian-speaking users. 274 extensions impersonated 66 legitimate VPN brands (Proton VPN, NordVPN, Surfshark, AdGuard VPN, Browsec,…

Google12 Aug · 12:09 UTC
OpenAI, Anthropic, Google reasoning APIs leaked secrets via session replayhighbug_reportVulnerability
bug_reportVulnerability

OpenAI, Anthropic, Google reasoning APIs leaked secrets via session replay

OpenAI, Anthropic, and Google reasoning APIs (GPT-5.6 Luna, Claude Haiku 4.5, Gemini Robotics ER-1.6). Affects developers who published raw agent logs containing encrypted reasoning objects.

OpenAI12 Aug · 09:47 UTC
ShieldBreak zero-day bypasses Microsoft Defender patch, grants SYSTEM accesshighbug_reportVulnerability
bug_reportVulnerability

ShieldBreak zero-day bypasses Microsoft Defender patch, grants SYSTEM access

Microsoft Defender for Windows on Windows 11 25H2, Windows Server 2025, and Windows 10 (all editions). The vulnerability bypasses the patch for CVE-2026-50656 (RoguePlanet) in the Microsoft Malware Protection Engine (mpengine.dll).

CVE-2026-5065612 Aug · 04:41 UTC
Cisco ASA/FTD remote DoS flaw exploited in wild, CISA orders patch by Aug 14highbug_reportVulnerability
bug_reportVulnerability

Cisco ASA/FTD remote DoS flaw exploited in wild, CISA orders patch by Aug 14

Cisco Secure Firewall ASA Software (versions 9.16.1, 9.18.1, 9.20, 9.22, 9.23, 9.24) and FTD Software (versions 7.0, 7.2, 7.4, 7.6, 7.7, 10.0) with IKEv2 Remote Access VPN, SSL-VPN, or Zero Trust Network Access enabled.

CVE-2026-2034912 Aug · 04:15 UTC
DeadLock ransomware uses blockchain infrastructure to evade takedownhighperson_alertThreat Actor
person_alertThreat Actor

DeadLock ransomware uses blockchain infrastructure to evade takedown

DeadLock is a ransomware-as-a-service (RaaS) operation that emerged in mid-2025, employing double-extortion tactics combining data theft with file encryption.

BleepingComputer11 Aug · 20:15 UTC
Microsoft patches 398 flaws including one actively exploited zero-dayhighbug_reportVulnerability
bug_reportVulnerability

Microsoft patches 398 flaws including one actively exploited zero-day

Microsoft Windows operating systems and supported software. All Windows endpoints are affected. Critical focus: CVE-2026-68820 (afd.sys driver privilege escalation, actively exploited), CVE-2026-62832 (Windows User Profile Service privilege escalatio…

Microsoft11 Aug · 19:28 UTC
Sandworm deploys trojanized WireGuard VPN via fake IT job offershighperson_alertThreat Actor
person_alertThreat Actor

Sandworm deploys trojanized WireGuard VPN via fake IT job offers

Sandworm (also tracked as APT44, UAC-0145 sub-cluster) is a Russian-linked advanced persistent threat group notorious for targeting critical infrastructure and government entities, particularly in Ukraine and other countries.

BleepingComputer11 Aug · 19:07 UTC
Cisco ASA/FTD VPN flaw CVE-2026-20349 actively exploited for DoShighbug_reportVulnerability
bug_reportVulnerability

Cisco ASA/FTD VPN flaw CVE-2026-20349 actively exploited for DoS

Cisco Secure Firewall ASA (versions 9.16, 9.18, 9.20, 9.22, 9.23, 9.24) and Threat Defense FTD (versions 7.0, 7.2, 7.4, 7.6, 7.7, 10.0) with Remote Access SSL VPN, IKEv2 Remote Access VPN with client services, or Zero Trust Network Access enabled.

Cisco11 Aug · 17:45 UTC
Kimwolf v7 Botnet Adds HTTP/2 DDoS with Browser Fingerprintinghighperson_alertThreat Actor
person_alertThreat Actor

Kimwolf v7 Botnet Adds HTTP/2 DDoS with Browser Fingerprinting

Kimwolf (also tracked as AISURU) is an Android and IoT botnet operation active since at least mid-2024. The threat actors behind Kimwolf have demonstrated continuous evolution in their tooling, targeting Android TV boxes since August 2025 and Linux I…

Palo Alto Networks11 Aug · 17:36 UTC
UAC-0145 Targets Ukrainian IT Workers via Fake Job Recruitment Campaignhighperson_alertThreat Actor
person_alertThreat Actor

UAC-0145 Targets Ukrainian IT Workers via Fake Job Recruitment Campaign

UAC-0145 is a threat cluster operating as a subgroup within Sandworm (also tracked as APT44, Seashell Blizzard, UAC-0002, ELECTRUM, Telebots, IRON VIKING), a sophisticated nation-state hacking group affiliated with Russia's GRU military intelligence.…

The Hacker News11 Aug · 16:36 UTC
DeadLock Ransomware Leverages Polygon Blockchain for Resilient Extortionhighperson_alertThreat Actor
person_alertThreat Actor

DeadLock Ransomware Leverages Polygon Blockchain for Resilient Extortion

DeadLock is a ransomware group first detected in July 2025, operating double extortion campaigns that encrypt victim environments and threaten public data release.

Polygon11 Aug · 14:35 UTC
ExfilSquad Claims 2.6M Records Stolen from Wesco CRM Environmenthighperson_alertThreat Actor
person_alertThreat Actor

ExfilSquad Claims 2.6M Records Stolen from Wesco CRM Environment

ExfilSquad is a data extortion group that specializes in exfiltrating sensitive information from organizations and leveraging it for ransom demands. The group operates a data leak site where they publish stolen data after ransom deadlines expire.

Wesco11 Aug · 13:59 UTC
Malicious SIM cards can execute code on IoT cellular modules via RUN AThighbug_reportVulnerability
bug_reportVulnerability

Malicious SIM cards can execute code on IoT cellular modules via RUN AT

Cellular IoT modules (6 of 8 tested, primarily Quectel parts with Qualcomm processors) in EV chargers, industrial routers, car telematics units. Limited phone impact: OPPO Find X5, OPPO Reno 14 F 5G, ASUS Zenfone 9.

The Hacker News11 Aug · 10:05 UTC
Mozilla revokes Firefox/Thunderbird Linux signing key after repo exposurehighbug_reportVulnerability
bug_reportVulnerability

Mozilla revokes Firefox/Thunderbird Linux signing key after repo exposure

Mozilla Firefox and Thunderbird Linux downloads (all versions signed with subkey 09BE ED63 F346 2A2D FFAB 3B87 5ECB 6497 C1A2 0256 from April 2025 to August 2026).

Mozilla11 Aug · 10:04 UTC
North Korea IT Worker Infiltration Targets Crypto and Tech Firmshighperson_alertThreat Actor
person_alertThreat Actor

North Korea IT Worker Infiltration Targets Crypto and Tech Firms

North Korean IT worker operations, attributed by researchers to Famous Chollima (a CrowdStrike designation under the Lazarus umbrella), involve operatives seeking employment at Western technology and cryptocurrency companies under fraudulent identiti…

The Hacker News11 Aug · 09:35 UTC
Kimwolf v7 botnet targets Android IoT with HTTP/2 DDoS, ENS C2 resolutionhighbug_reportVulnerability
bug_reportVulnerability

Kimwolf v7 botnet targets Android IoT with HTTP/2 DDoS, ENS C2 resolution

Android TV boxes and set-top boxes with unauthenticated Android Debug Bridge (ADB) exposed on port 5555. Primarily affects devices accessible via residential proxy services. ARM-based Android IoT devices running vulnerable configurations.

Unit 42 (Palo Alto)11 Aug · 08:00 UTC
Polish energy plant breached via private APN in coordinated OT attackhighpublicGeopolitical
publicGeopolitical

Polish energy plant breached via private APN in coordinated OT attack

The December 2025 incident represents a sophisticated multi-site campaign against Polish critical infrastructure, attributed by Polish authorities to the Russian Electrum threat group.

BleepingComputer10 Aug · 21:07 UTC
Aeternum botnet uses Polygon blockchain for decentralized C2 infrastructurehighbug_reportVulnerability
bug_reportVulnerability

Aeternum botnet uses Polygon blockchain for decentralized C2 infrastructure

Windows systems infected with Aeternum C++ botnet loader (Build.exe). The malware targets Windows environments and uses Polygon blockchain smart contracts for command and control, making traditional domain/IP-based blocking ineffective.

Unit 42 (Palo Alto)10 Aug · 20:00 UTC