Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-21 · 02:09 UTC
articleTotal: 606 reports

Filtered Reports

30 / 202 results
Active filter:tag: #threat-actor✕ clear
Prinz Eugen ransomware targets recently modified files, omits ransom notehighperson_alertThreat Actor
person_alertThreat Actor

Prinz Eugen ransomware targets recently modified files, omits ransom note

Prinz Eugen is a newly identified ransomware family characterized by unconventional operational tactics. Unlike traditional ransomware operations that encrypt files indiscriminately and leave detailed ransom notes, Prinz Eugen employs a selective enc…

BleepingComputer13:23 UTC
North Korean APT compromised 140+ npm packages via Mastra AI frameworkhighbug_reportVulnerability
bug_reportVulnerability

North Korean APT compromised 140+ npm packages via Mastra AI framework

Mastra AI framework and over 140 dependent npm packages. Organizations using Mastra AI or downstream dependencies in Node.js/JavaScript applications are affected.

Mastra AI12:09 UTC
Icarus Extortion Group Breaches Klue, Steals Salesforce OAuth Tokenshighperson_alertThreat Actor
person_alertThreat Actor

Icarus Extortion Group Breaches Klue, Steals Salesforce OAuth Tokens

Icarus is an extortion-focused threat actor that has publicly claimed responsibility for breaching the market intelligence platform Klue. The group's motivation appears to be financially driven, targeting SaaS and market intelligence platforms to ste…

Klue20:31 UTC
Unpatchable SecureROM exploit for Apple A12/A13 chips publishedcriticalbug_reportVulnerability
bug_reportVulnerability

Unpatchable SecureROM exploit for Apple A12/A13 chips published

Apple devices with A12 and A13 chips (iPhone XS/XR/11 series, iPad Air 3rd gen, iPad mini 5th gen, iPad 8th gen). SecureROM vulnerability is permanent and cannot be patched via software updates.

Apple16:37 UTC
Gentlemen RaaS Deploys GentleKiller EDR Evasion Frameworkhighperson_alertThreat Actor
person_alertThreat Actor

Gentlemen RaaS Deploys GentleKiller EDR Evasion Framework

Gentlemen is a ransomware-as-a-service (RaaS) operation that provides infrastructure, tooling, and support to affiliate threat actors. The group actively develops and distributes specialized frameworks to enhance affiliate success rates, including th…

The Hacker News16:33 UTC
SocGholish Infrastructure Disrupted in Operation Endgame Takedownhighperson_alertThreat Actor
person_alertThreat Actor

SocGholish Infrastructure Disrupted in Operation Endgame Takedown

SocGholish is a threat actor known for compromising web infrastructure, particularly WordPress-based content management systems, to facilitate malware distribution and drive-by download attacks.

WordPress13:07 UTC
Russian-speaking actors compromise 86,644 FortiGate devices via FortiBleedhighperson_alertThreat Actor
person_alertThreat Actor

Russian-speaking actors compromise 86,644 FortiGate devices via FortiBleed

Russian-speaking threat actors are conducting the FortiBleed campaign, targeting internet-accessible FortiGate appliances at scale. The actors' specific motivation remains unclear from available data, though the mass compromise of 86,644 devices sugg…

Fortinet12:00 UTC
Gentlemen RaaS Develops EDR Killer Tools for Affiliate Operationshighperson_alertThreat Actor
person_alertThreat Actor

Gentlemen RaaS Develops EDR Killer Tools for Affiliate Operations

Gentlemen is a ransomware-as-a-service (RaaS) operation that provides infrastructure, tools, and support to affiliate threat actors who conduct ransomware attacks.

BleepingComputer20:31 UTC
NetNut Linked to Popa Android Botnet Enabling Proxy Fraudhighperson_alertThreat Actor
person_alertThreat Actor

NetNut Linked to Popa Android Botnet Enabling Proxy Fraud

NetNut is a residential proxy service operated by Alarum Technologies Ltd (NASDAQ: ALAR), a publicly-traded Israeli firm. Multiple security researchers have linked NetNut to the Popa Android botnet, which has compromised millions of consumer TV boxes…

Alarum Technologies Ltd15:37 UTC
Icarus Threat Actor Exploits OAuth to Steal Salesforce Data via Kluehighperson_alertThreat Actor
person_alertThreat Actor

Icarus Threat Actor Exploits OAuth to Steal Salesforce Data via Klue

Icarus is a threat actor conducting an ongoing extortion campaign targeting organizations through supply chain compromise. The actor exploited OAuth authentication mechanisms to breach Klue, a market intelligence platform, gaining unauthorized access…

Klue12:19 UTC
INC Ransomware Expands Operations Following LockBit and BlackCat Disruptionshighperson_alertThreat Actor
person_alertThreat Actor

INC Ransomware Expands Operations Following LockBit and BlackCat Disruptions

INC is a ransomware-as-a-service (RaaS) operation that has emerged as a major threat actor since August 2023. The group operates a multi-affiliate model, providing ransomware tooling and infrastructure to criminal partners in exchange for a share of…

The Hacker News12:12 UTC
DragonForce Deploys Backdoor.Turn RAT via Microsoft Teams Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

DragonForce Deploys Backdoor.Turn RAT via Microsoft Teams Infrastructure

DragonForce is a threat actor associated with ransomware operations. The group has demonstrated advanced capabilities in developing custom tooling and leveraging legitimate cloud infrastructure for command-and-control communications.

Microsoft11:30 UTC
Evil Corp SocGholish botnet dismantled: 15,000 sites, 100+ servershighperson_alertThreat Actor
person_alertThreat Actor

Evil Corp SocGholish botnet dismantled: 15,000 sites, 100+ servers

Evil Corp (also tracked as Indrik Spider, Manatee Tempest, DEV-0243, UNC2165) is a financially motivated cybercrime group linked to Russia. The group has operated since at least 2014 and is known for deploying banking trojans and ransomware variants…

WordPress11:25 UTC
Junior Hacker targets French automotive sector with credential thefthighperson_alertThreat Actor
person_alertThreat Actor

Junior Hacker targets French automotive sector with credential theft

Junior Hacker is a French-speaking threat actor targeting small businesses in the French automotive sector. The actor demonstrates financially motivated objectives, focusing on credential theft for banking and email access.

The Hacker News14:00 UTC
Supply chain attack compromises 144 Mastra npm packages via hijacked accountcriticalbug_reportVulnerability
bug_reportVulnerability

Supply chain attack compromises 144 Mastra npm packages via hijacked account

144 npm packages in the @mastra/* namespace (Mastra AI framework for JavaScript/TypeScript). Attack vector: compromised npm contributor account (ehindero). All downstream projects using affected Mastra packages are potentially impacted.

Mastra05:38 UTC
ShinyHunters Claims Responsibility for Kodak Data Breachhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Claims Responsibility for Kodak Data Breach

ShinyHunters is a financially motivated cybercrime group known for conducting data theft and extortion operations against organizations across multiple sectors.

Kodak05:07 UTC
GhostTree Abuses NTFS Junctions to Evade Microsoft Defender Scanshighperson_alertThreat Actor
person_alertThreat Actor

GhostTree Abuses NTFS Junctions to Evade Microsoft Defender Scans

GhostTree is a threat actor that has developed an evasion technique exploiting recursive NTFS junctions to bypass antivirus scanning. The actor targets the information technology sector and leverages inherent Windows file system features to create in…

Microsoft12:17 UTC
Fortinet FortiSandbox under active exploit for 3 CVEs including critical 9.1criticalbug_reportVulnerability
bug_reportVulnerability

Fortinet FortiSandbox under active exploit for 3 CVEs including critical 9.1

Fortinet FortiSandbox - specific affected versions not disclosed. Three CVEs: CVE-2026-39813 (CVSS 9.1 critical), CVE-2026-39808, CVE-2026-25089. At least one vulnerability recently patched; patch status of others unclear.

CVE-2026-2508908:30 UTC
DragonForce Ransomware Gang Deploys Backdoor.Turn via Teams Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

DragonForce Ransomware Gang Deploys Backdoor.Turn via Teams Infrastructure

DragonForce is a ransomware gang that has developed custom tooling to support their extortion operations. The group demonstrates advanced capabilities in developing bespoke malware and leveraging legitimate cloud infrastructure for command-and-contro…

Microsoft08:18 UTC
China-Linked Actor Deploys Windows Variants of SprySOCKS Backdoorhighperson_alertThreat Actor
person_alertThreat Actor

China-Linked Actor Deploys Windows Variants of SprySOCKS Backdoor

A China-linked threat actor has expanded the SprySOCKS malware family beyond its original Linux platform. The actor demonstrates advanced development capabilities through the creation of two distinct Windows variants (WIN_DRV and WIN_PLUS) featuring…

Windows07:44 UTC
ScarCruft Deploys NarwhalRAT via Microsoft Account Phishing Lureshighperson_alertThreat Actor
person_alertThreat Actor

ScarCruft Deploys NarwhalRAT via Microsoft Account Phishing Lures

ScarCruft (also tracked as APT37, InkySquid, Reaper, and Group123) is a North Korean state-sponsored advanced persistent threat group. The actor is attributed to North Korea's intelligence apparatus and conducts espionage operations aligned with Pyon…

Microsoft06:14 UTC
China-linked espionage group targets North American research networkscriticalperson_alertThreat Actor
person_alertThreat Actor

China-linked espionage group targets North American research networks

A China-linked espionage group conducted a sustained intrusion campaign lasting over one year against North American institutions. The actor's motivation appears to be intelligence collection focused on medical research, academic intellectual propert…

Google Workspace17:44 UTC
Contagious Interview targets developers via recruitment-themed phishinghighperson_alertThreat Actor
person_alertThreat Actor

Contagious Interview targets developers via recruitment-themed phishing

Contagious Interview (also tracked as DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, and DEV#POPPER) is a North Korean-aligned threat actor cluster that specializes in social engineering attacks against software developers and technology secto…

The Hacker News17:32 UTC
ShinyHunters Claims Council of Europe Data Breachhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Claims Council of Europe Data Breach

ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has been active since at least 2020, targeting organizations across multiple sectors to steal sensitive databases and person…

Council of Europe14:37 UTC
China-Linked Espionage Group Deploys InfiniteRed via REDCap Servershighperson_alertThreat Actor
person_alertThreat Actor

China-Linked Espionage Group Deploys InfiniteRed via REDCap Servers

This activity is attributed to a China-linked espionage group targeting healthcare and medical research sectors. The actor's motivation appears to be intelligence collection focused on sensitive medical research data, consistent with strategic intere…

REDCap12:00 UTC
ShinyHunters Breaches 137K+ School Staff via Salesforce Attackhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Breaches 137K+ School Staff via Salesforce Attack

ShinyHunters is a financially motivated cybercrime actor specializing in large-scale data theft and extortion operations. The group has established a reputation for targeting cloud-based platforms and third-party service providers to compromise downs…

Salesforce10:38 UTC
Palo Alto PAN-OS GlobalProtect auth bypass under active exploitationhighbug_reportVulnerability
bug_reportVulnerability

Palo Alto PAN-OS GlobalProtect auth bypass under active exploitation

Palo Alto Networks PAN-OS GlobalProtect VPN portal and gateway components. Specific affected versions not disclosed in provided data. CVE-2026-0257, CVSS 7.8 (High).

CVE-2026-025704:17 UTC
FBI disrupts Outsider Enterprise Chinese phishing-as-a-service platformhighperson_alertThreat Actor
person_alertThreat Actor

FBI disrupts Outsider Enterprise Chinese phishing-as-a-service platform

Outsider Enterprise is a Chinese phishing-as-a-service (PhaaS) operation disrupted by the FBI in coordination with Google and Black Lotus Labs. The actor operated thousands of phishing websites designed to harvest credit card data and passwords from…

BleepingComputer12:36 UTC
Chinese state-sponsored hackers maintain 10-year persistent accesscriticalperson_alertThreat Actor
person_alertThreat Actor

Chinese state-sponsored hackers maintain 10-year persistent access

Chinese state-sponsored hackers, likely an advanced persistent threat (APT) group operating on behalf of the People's Republic of China. The actor demonstrated exceptional operational security and patience, maintaining covert access to a target organ…

BleepingComputer12:06 UTC
Chinese Cybercrime Network Weaponizes Google Gemini AI for SMS Phishinghighperson_alertThreat Actor
person_alertThreat Actor

Chinese Cybercrime Network Weaponizes Google Gemini AI for SMS Phishing

A Chinese cybercrime network operating a phishing-as-a-service (PhaaS) platform called Outsider. The group weaponizes Google's Gemini AI to craft and conduct SMS-based phishing attacks (smishing) targeting American victims.

Google16:59 UTC