Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 685 results
highperson_alertThreat ActorClop Ransomware Gang Exploits CVE-2026-12569 in PTC Windchill Attacks
Clop is a financially motivated ransomware gang known for mass exploitation campaigns targeting zero-day and n-day vulnerabilities in enterprise software.
highperson_alertThreat ActorShinyHunters Breaches RingCentral, Leaks 1.6M Account Records
ShinyHunters is a financially motivated extortion group that operates a "pay or leak" model, demanding ransom payments from breached organizations and publishing stolen data on dark web leak sites when victims refuse to pay.
highperson_alertThreat ActorFormer Brightly Software Contractor Sentenced for $2.5M Extortion
Cameron Curry (alias "Loot"), a 27-year-old North Carolina resident, was a former data analyst contractor for Brightly Software (formerly SchoolDude, acquired by Siemens in 2022).
highperson_alertThreat ActorAkira Ransomware Affiliate Uses Safe Mode to Evade EDR, Fails Encryption
Akira (also tracked as GOLD SAHARA, PUNK SPIDER, and Howling Scorpius) is a ransomware operation that emerged as a significant threat actor conducting double extortion attacks.
highperson_alertThreat ActorJewelbug APT Conducts Dual-Track Espionage and Crypto Fraud
Jewelbug (also tracked as Earth Alux and REF7707) is a China-based threat actor conducting parallel espionage and financially-motivated operations. The group targets government and military entities across the Middle East, Southeast Asia, and South A…
highbug_reportVulnerabilityMicrosoft patches LegacyHive Windows zero-day granting admin privileges
Windows User Profile Service in Windows 10 version 2004 and later, Windows Server 2022 and later. Tracked as CVE-2026-62832. All Windows systems running affected versions are vulnerable.
highbug_reportVulnerabilityPlesk privilege escalation flaw requires immediate patching
Plesk web hosting control panel - specific affected versions not disclosed in advisory. Privilege escalation vulnerability allows attackers to gain elevated access.
highperson_alertThreat ActorCity-Forum Campaign Targets Salesforce and ServiceNow Portals
City-Forum is an ongoing data theft campaign, not a formally attributed threat actor group. The campaign has been active since at least March 2025 and is characterized by consistent infrastructure use—a single IP address (158.220.87.79) hosted by Ger…
highbug_reportVulnerabilityWindRelay NFC relay malware + SpyNote RAT steal cards, take loans
Android devices in Czechia, Slovakia, and Slovenia. WindRelay NFC relay malware deployed alongside SpyNote RAT (and variants SpyMax, CypherRAT). 24 WindRelay samples identified on VirusTotal from November 2025 to July 2026.
highbug_reportVulnerability737 fake Chrome VPN extensions route traffic through attacker SOCKS5 proxies
Google Chrome Web Store users who installed any of 737 malicious extensions impersonating VPN/proxy services (Proton VPN, NordVPN, Surfshark, ExpressVPN, Cloudflare 1.1.1.1). Approximately 75,000 downloads recorded, primarily Russian users.
highbug_reportVulnerabilityPlug and Pwn attacks exploit Windows Plug and Play for SYSTEM access
All Windows systems (including fully patched Windows 11) that support Plug and Play device installation. Specific vulnerable vendor packages include Sierra Wireless and Sony FeliCa software.
highperson_alertThreat ActorCybercriminals Target Social Media Accounts for Sexual Exploitation
Unattributed cybercriminals conducting coordinated account compromise campaigns targeting social media and online service accounts belonging to adults, children, and student-athletes in the United States.
highbug_reportVulnerability737 malicious Chrome VPN extensions route traffic through attacker proxies
Google Chrome users who installed any of 737 malicious VPN/proxy extensions from Chrome Web Store, primarily targeting Russian-speaking users. 274 extensions impersonated 66 legitimate VPN brands (Proton VPN, NordVPN, Surfshark, AdGuard VPN, Browsec,…
highbug_reportVulnerabilityOpenAI, Anthropic, Google reasoning APIs leaked secrets via session replay
OpenAI, Anthropic, and Google reasoning APIs (GPT-5.6 Luna, Claude Haiku 4.5, Gemini Robotics ER-1.6). Affects developers who published raw agent logs containing encrypted reasoning objects.
highbug_reportVulnerabilityShieldBreak zero-day bypasses Microsoft Defender patch, grants SYSTEM access
Microsoft Defender for Windows on Windows 11 25H2, Windows Server 2025, and Windows 10 (all editions). The vulnerability bypasses the patch for CVE-2026-50656 (RoguePlanet) in the Microsoft Malware Protection Engine (mpengine.dll).
highbug_reportVulnerabilityCisco ASA/FTD remote DoS flaw exploited in wild, CISA orders patch by Aug 14
Cisco Secure Firewall ASA Software (versions 9.16.1, 9.18.1, 9.20, 9.22, 9.23, 9.24) and FTD Software (versions 7.0, 7.2, 7.4, 7.6, 7.7, 10.0) with IKEv2 Remote Access VPN, SSL-VPN, or Zero Trust Network Access enabled.
highperson_alertThreat ActorDeadLock ransomware uses blockchain infrastructure to evade takedown
DeadLock is a ransomware-as-a-service (RaaS) operation that emerged in mid-2025, employing double-extortion tactics combining data theft with file encryption.
highbug_reportVulnerabilityMicrosoft patches 398 flaws including one actively exploited zero-day
Microsoft Windows operating systems and supported software. All Windows endpoints are affected. Critical focus: CVE-2026-68820 (afd.sys driver privilege escalation, actively exploited), CVE-2026-62832 (Windows User Profile Service privilege escalatio…
highperson_alertThreat ActorSandworm deploys trojanized WireGuard VPN via fake IT job offers
Sandworm (also tracked as APT44, UAC-0145 sub-cluster) is a Russian-linked advanced persistent threat group notorious for targeting critical infrastructure and government entities, particularly in Ukraine and other countries.
highbug_reportVulnerabilityCisco ASA/FTD VPN flaw CVE-2026-20349 actively exploited for DoS
Cisco Secure Firewall ASA (versions 9.16, 9.18, 9.20, 9.22, 9.23, 9.24) and Threat Defense FTD (versions 7.0, 7.2, 7.4, 7.6, 7.7, 10.0) with Remote Access SSL VPN, IKEv2 Remote Access VPN with client services, or Zero Trust Network Access enabled.
highperson_alertThreat ActorKimwolf v7 Botnet Adds HTTP/2 DDoS with Browser Fingerprinting
Kimwolf (also tracked as AISURU) is an Android and IoT botnet operation active since at least mid-2024. The threat actors behind Kimwolf have demonstrated continuous evolution in their tooling, targeting Android TV boxes since August 2025 and Linux I…
highperson_alertThreat ActorUAC-0145 Targets Ukrainian IT Workers via Fake Job Recruitment Campaign
UAC-0145 is a threat cluster operating as a subgroup within Sandworm (also tracked as APT44, Seashell Blizzard, UAC-0002, ELECTRUM, Telebots, IRON VIKING), a sophisticated nation-state hacking group affiliated with Russia's GRU military intelligence.…
highperson_alertThreat ActorDeadLock Ransomware Leverages Polygon Blockchain for Resilient Extortion
DeadLock is a ransomware group first detected in July 2025, operating double extortion campaigns that encrypt victim environments and threaten public data release.
highperson_alertThreat ActorExfilSquad Claims 2.6M Records Stolen from Wesco CRM Environment
ExfilSquad is a data extortion group that specializes in exfiltrating sensitive information from organizations and leveraging it for ransom demands. The group operates a data leak site where they publish stolen data after ransom deadlines expire.
highbug_reportVulnerabilityMalicious SIM cards can execute code on IoT cellular modules via RUN AT
Cellular IoT modules (6 of 8 tested, primarily Quectel parts with Qualcomm processors) in EV chargers, industrial routers, car telematics units. Limited phone impact: OPPO Find X5, OPPO Reno 14 F 5G, ASUS Zenfone 9.
highbug_reportVulnerabilityMozilla revokes Firefox/Thunderbird Linux signing key after repo exposure
Mozilla Firefox and Thunderbird Linux downloads (all versions signed with subkey 09BE ED63 F346 2A2D FFAB 3B87 5ECB 6497 C1A2 0256 from April 2025 to August 2026).
highperson_alertThreat ActorNorth Korea IT Worker Infiltration Targets Crypto and Tech Firms
North Korean IT worker operations, attributed by researchers to Famous Chollima (a CrowdStrike designation under the Lazarus umbrella), involve operatives seeking employment at Western technology and cryptocurrency companies under fraudulent identiti…
highbug_reportVulnerabilityKimwolf v7 botnet targets Android IoT with HTTP/2 DDoS, ENS C2 resolution
Android TV boxes and set-top boxes with unauthenticated Android Debug Bridge (ADB) exposed on port 5555. Primarily affects devices accessible via residential proxy services. ARM-based Android IoT devices running vulnerable configurations.
highpublicGeopoliticalPolish energy plant breached via private APN in coordinated OT attack
The December 2025 incident represents a sophisticated multi-site campaign against Polish critical infrastructure, attributed by Polish authorities to the Russian Electrum threat group.
highbug_reportVulnerabilityAeternum botnet uses Polygon blockchain for decentralized C2 infrastructure
Windows systems infected with Aeternum C++ botnet loader (Build.exe). The malware targets Windows environments and uses Polygon blockchain smart contracts for command and control, making traditional domain/IP-based blocking ineffective.