Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-21 · 02:09 UTC
articleTotal: 606 reports

Filtered Reports

30 / 390 results
Active filter:tag: #high✕ clear
AI browsers leak credentials via BioShocking social engineering attackhighbug_reportVulnerability
bug_reportVulnerability

AI browsers leak credentials via BioShocking social engineering attack

Six AI browsers and assistants including OpenAI ChatGPT Atlas, Perplexity Comet, and Anthropic Claude browser extension. Attack exploits AI reasoning vulnerabilities to extract user credentials through game-based social engineering.

OpenAI06:37 UTC
ShinyHunters Exploits Oracle PeopleSoft Zero-Day in Nissan Breachhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Exploits Oracle PeopleSoft Zero-Day in Nissan Breach

ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has established a pattern of exploiting vulnerabilities in enterprise applications to exfiltrate sensitive data, which is th…

Oracle18:40 UTC
ShinyHunters Exploits Oracle PeopleSoft Zero-Day at NAIChighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Exploits Oracle PeopleSoft Zero-Day at NAIC

ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has historically targeted organizations to exfiltrate sensitive data, which is then leveraged for extortion or sold on under…

Oracle18:30 UTC
Malicious Chrome Extension Impersonates Perplexity AI to Intercept Searcheshighperson_alertThreat Actor
person_alertThreat Actor

Malicious Chrome Extension Impersonates Perplexity AI to Intercept Searches

The threat actor behind this campaign remains unattributed. The operation demonstrates a financially or espionage-motivated adversary leveraging social engineering through brand impersonation of Perplexity AI, a popular search technology.

Google16:40 UTC
U.S. offers $10M reward for intel on UNC5792 and UNC4221 APT groupshighperson_alertThreat Actor
person_alertThreat Actor

U.S. offers $10M reward for intel on UNC5792 and UNC4221 APT groups

UNC5792 and UNC4221 are threat actor groups attributed to Russian intelligence and military services. Both groups have been designated as high-priority targets by the U.S.

BleepingComputer13:09 UTC
Mustang Panda Targets Indian Government and Hydropower Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

Mustang Panda Targets Indian Government and Hydropower Infrastructure

Mustang Panda (also tracked as TA416, RedDelta, BRONZE PRESIDENT, and STATELY TAURUS) is a China-aligned advanced persistent threat group focused on espionage operations.

Zoho13:03 UTC
Stack buffer overflow in libxml2 enables code execution via malformed inputhighbug_reportVulnerability
bug_reportVulnerability

Stack buffer overflow in libxml2 enables code execution via malformed input

libxml2 library, all versions not yet patched. Affects systems and applications that parse XML using libxml2, including numerous Linux distributions, Python, PHP, and other software that depends on this widely-deployed XML parsing library.

CVE-2026-1197911:20 UTC
236K+ malicious sites use DCloud Uni-App templates for crypto scamshighbug_reportVulnerability
bug_reportVulnerability

236K+ malicious sites use DCloud Uni-App templates for crypto scams

Organizations and users interacting with websites built using DCloud Uni-App framework templates. Over 236,000 malicious sites identified conducting cryptocurrency scams, phishing, wallet draining, pig-butchering schemes, and fake gambling platforms.

DCloud09:57 UTC
Gamaredon APT Expands Ukraine Operations with 35 Spear-Phishing Campaignshighperson_alertThreat Actor
person_alertThreat Actor

Gamaredon APT Expands Ukraine Operations with 35 Spear-Phishing Campaigns

Gamaredon (also tracked as Armageddon, Shuckworm, Primitive Bear, and UAC-0010) is a Russian state-sponsored APT group attributed by multiple vendors to Russia's Federal Security Service (FSB).

ESET09:40 UTC
Microsoft removes 119 malicious Edge extensions hiding malware via steganographyhighbug_reportVulnerability
bug_reportVulnerability

Microsoft removes 119 malicious Edge extensions hiding malware via steganography

Microsoft Edge browser users who installed any of 119 malicious extensions from the official Microsoft Edge Add-ons store. Campaign active since at least 2021, affecting unknown number of users globally.

Microsoft06:32 UTC
Microsoft Exchange privilege escalation flaw requires immediate patchinghighbug_reportVulnerability
bug_reportVulnerability

Microsoft Exchange privilege escalation flaw requires immediate patching

Microsoft Exchange Server 2016, 2019, and Subscription Edition. All on-premises deployments of these versions are potentially affected.

Microsoft06:06 UTC
Hijacked npm and Go packages deploy cross-platform stealer via VS Codehighbug_reportVulnerability
bug_reportVulnerability

Hijacked npm and Go packages deploy cross-platform stealer via VS Code

Compromised npm and Go packages targeting developers using Microsoft Visual Studio Code on Windows, Linux, and macOS. Attack bypasses npm v12 lifecycle script protections by abusing VS Code task execution.

npm03:36 UTC
KDDI breach exposes 14.2M email accounts across Japanese ISP ecosystemhighpublicGeopolitical
publicGeopolitical

KDDI breach exposes 14.2M email accounts across Japanese ISP ecosystem

The breach at KDDI Corporation, one of Japan's largest telecommunications operators, highlights systemic vulnerabilities in shared infrastructure models within critical communications sectors.

KDDI Corporation12:13 UTC
Russian Intelligence Services Target Messaging Accounts via Phishinghighperson_alertThreat Actor
person_alertThreat Actor

Russian Intelligence Services Target Messaging Accounts via Phishing

Russian intelligence services conducted a long-running credential harvesting campaign targeting messaging platforms. The operation, uncovered jointly by Ukraine's Security Service (SSU) and the FBI, focused on stealing authentication credentials from…

The Hacker News15:27 UTC
Agentic coding tools vulnerable to hidden malicious payloads in reposhighbug_reportVulnerability
bug_reportVulnerability

Agentic coding tools vulnerable to hidden malicious payloads in repos

Agentic coding tools and AI-assisted development platforms that automatically fetch and execute code from GitHub repositories. Specific products not disclosed.

BleepingComputer12:22 UTC
Russian Intelligence Services Target Signal Users in Phishing Campaignhighperson_alertThreat Actor
person_alertThreat Actor

Russian Intelligence Services Target Signal Users in Phishing Campaign

Russian intelligence services are conducting a phishing campaign targeting Signal messaging application users. The operation is attributed by the FBI and CISA, indicating state-sponsored activity aimed at compromising secure communications.

Signal20:06 UTC
Russian Intelligence Escalates Signal Phishing for Backup Recovery Keyshighperson_alertThreat Actor
person_alertThreat Actor

Russian Intelligence Escalates Signal Phishing for Backup Recovery Keys

Russian intelligence actors, as identified by FBI and CISA joint reporting, are conducting targeted phishing operations against Signal messaging platform users.

Signal17:38 UTC
SharkLoader malware deploys Cobalt Strike in attacks on Asian governmentshighbug_reportVulnerability
bug_reportVulnerability

SharkLoader malware deploys Cobalt Strike in attacks on Asian governments

Diplomatic and government organizations in Indonesia and Taiwan. SharkLoader is a newly identified malware family used to deliver Cobalt Strike Beacon payloads in the StrikeShark campaign.

The Hacker News16:17 UTC
Polymarket frontend compromised via third-party vendor; $3M stolenhighbug_reportVulnerability
bug_reportVulnerability

Polymarket frontend compromised via third-party vendor; $3M stolen

Polymarket platform users. Attack vector: malicious JavaScript injected into frontend via compromised third-party vendor. Approximately $3 million in customer funds stolen. No CVE assigned.

Polymarket16:04 UTC
Unknown Actors Exploit OpenAI Tenants to Phish Cybersecurity Firmshighperson_alertThreat Actor
person_alertThreat Actor

Unknown Actors Exploit OpenAI Tenants to Phish Cybersecurity Firms

The threat actors behind this campaign remain unattributed. Their motivation appears to be intelligence gathering and corporate espionage, leveraging the trust associated with OpenAI's platform to deceive employees of cybersecurity companies.

BleepingComputer15:49 UTC
CL-STA-1062 deploys TinyRCT backdoor against Southeast Asian governmenthighperson_alertThreat Actor
person_alertThreat Actor

CL-STA-1062 deploys TinyRCT backdoor against Southeast Asian government

CL-STA-1062 is a Chinese-speaking APT actor conducting targeted cyber espionage operations against government entities and critical infrastructure in Southeast Asia.

Palo Alto Networks14:21 UTC
Amazon Q Developer flaw allows credential theft via malicious reposhighbug_reportVulnerability
bug_reportVulnerability

Amazon Q Developer flaw allows credential theft via malicious repos

Amazon Q Developer (all versions prior to patch). Affects developers using the IDE plugin who clone or open malicious repositories containing crafted Model Context Protocol (MCP) server configurations.

CVE-2026-1295711:53 UTC
DirtyClone Linux kernel flaw enables local privilege escalation to roothighbug_reportVulnerability
bug_reportVulnerability

DirtyClone Linux kernel flaw enables local privilege escalation to root

Linux kernel (specific vulnerable versions not disclosed). Affects systems where local users can trigger network packet cloning operations. Part of the DirtyFrag vulnerability family.

CVE-2026-4350309:51 UTC
Miasma malware compromises npm packages LeoPlatform and RStreamshighbug_reportVulnerability
bug_reportVulnerability

Miasma malware compromises npm packages LeoPlatform and RStreams

npm packages LeoPlatform and RStreams compromised by Miasma malware family. Attack extends to GitHub Actions workflows and Go ecosystem. Organizations using these packages or dependent projects are affected.

npm09:05 UTC
Phishing campaign targets hotel front desks with Node.js implanthighbug_reportVulnerability
bug_reportVulnerability

Phishing campaign targets hotel front desks with Node.js implant

Hotel and hospitality organizations in Europe and Asia. Front-desk systems targeted via photo-themed ZIP file attachments containing Node.js-based malware. Campaign active since April 2026.

Microsoft07:27 UTC
Polish Authorities Dismantle SIM-Swapping Gang Targeting Crypto Assetshighperson_alertThreat Actor
person_alertThreat Actor

Polish Authorities Dismantle SIM-Swapping Gang Targeting Crypto Assets

This organized cybercrime group operated in Poland, conducting SIM-swapping attacks with the primary motivation of financial gain through cryptocurrency theft.

BleepingComputer20:37 UTC
Active campaign targets hospitality in Europe/Asia via ZIP archiveshighbug_reportVulnerability
bug_reportVulnerability

Active campaign targets hospitality in Europe/Asia via ZIP archives

Hospitality organizations in Europe and Asia. Attack vector: photo-themed ZIP archives containing malicious shortcut files that deploy a Node.js implant.

Microsoft20:30 UTC
CL-STA-1062 targets Southeast Asian government with TinyRCT backdoorhighperson_alertThreat Actor
person_alertThreat Actor

CL-STA-1062 targets Southeast Asian government with TinyRCT backdoor

CL-STA-1062 is a threat actor conducting cyber espionage operations against government entities and critical infrastructure in Southeast Asia. The actor employs a hybrid toolkit centered around a custom backdoor known as TinyRCT.

Unit 42 (Palo Alto)20:00 UTC
Shopify Shop app abused for callback phishing via fake order receiptshighbug_reportVulnerability
bug_reportVulnerability

Shopify Shop app abused for callback phishing via fake order receipts

Shopify Shop order-tracking app users. Threat actors inject fraudulent purchase receipts into legitimate user order histories, leveraging Shopify's trusted platform to deliver phishing lures.

Shopify17:45 UTC
Bluekit PhaaS expands with 70 new domains, adds browser-in-the-middlehighbug_reportVulnerability
bug_reportVulnerability

Bluekit PhaaS expands with 70 new domains, adds browser-in-the-middle

Organizations using cloud services and SaaS platforms targeted by Bluekit phishing-as-a-service infrastructure. Approximately 70 new phishing hostnames deployed in the past week.

BleepingComputer13:00 UTC