Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 356 results
Active filter:tag: #threat-actor✕ clear
DOUBLECUP LaaS Uses ClickFix and Steganography to Deploy CountLoaderhighperson_alertThreat Actor
person_alertThreat Actor

DOUBLECUP LaaS Uses ClickFix and Steganography to Deploy CountLoader

DOUBLECUP is a Russian loader-as-a-service (LaaS) operation active since early June 2026. The service provides operators with licenses and a Go-based Windows GUI client to orchestrate campaigns that deliver malware via ClickFix social engineering lur…

The Hacker News4 Aug · 07:03 UTC
Midnight Blizzard targets hospitality Wi-Fi in CaptiveCrunch campaignhighperson_alertThreat Actor
person_alertThreat Actor

Midnight Blizzard targets hospitality Wi-Fi in CaptiveCrunch campaign

Midnight Blizzard (APT29, also tracked as Storm-2945, IRON RITUAL, IRON HEMLOCK, NobleBaron, Dark Halo) is a Russian-attributed advanced persistent threat group linked to intelligence collection operations.

Microsoft3 Aug · 22:17 UTC
DOUBLECUP loader-as-a-service delivers malware via ClickFix attackshighperson_alertThreat Actor
person_alertThreat Actor

DOUBLECUP loader-as-a-service delivers malware via ClickFix attacks

DOUBLECUP is a Russian loader-as-a-service platform that has operated since early June 2026. The service provides customers with licenses and a Go-based Windows tool for creating malicious ClickFix campaigns.

Microsoft3 Aug · 18:01 UTC
INC Ransomware Exploits SonicWall SMA 1000 Zero-Dayshighperson_alertThreat Actor
person_alertThreat Actor

INC Ransomware Exploits SonicWall SMA 1000 Zero-Days

INC Ransomware is a cybercrime operation conducting data extortion and ransomware attacks. The group has claimed 885 victims to date as of August 2, 2026, according to Ransomware.Live statistics.

SonicWall3 Aug · 14:15 UTC
ExfilSquad Breaches UK Police Database, Leaks 100K+ Recordshighperson_alertThreat Actor
person_alertThreat Actor

ExfilSquad Breaches UK Police Database, Leaks 100K+ Records

ExfilSquad is a data extortion group that conducts targeted intrusions to steal sensitive information and leverage it for ransom demands. The group operates by exfiltrating data from compromised organizations, publishing proof samples, and threatenin…

Police National Legal Database3 Aug · 13:04 UTC
Chinese-Speaking Actor Deploys GHOSTBLADE via Leaked DarkSword iOS Kithighperson_alertThreat Actor
person_alertThreat Actor

Chinese-Speaking Actor Deploys GHOSTBLADE via Leaked DarkSword iOS Kit

An unidentified Chinese-speaking threat actor conducting mobile exploitation campaigns against iOS devices. The actor operates extensive infrastructure spanning over 100 web properties concentrated in Hong Kong with reach into Japan, the United State…

Apple3 Aug · 08:49 UTC
Storm-2945 Hijacks Hotel Wi-Fi to Deploy CornFlake Surveillance RAThighperson_alertThreat Actor
person_alertThreat Actor

Storm-2945 Hijacks Hotel Wi-Fi to Deploy CornFlake Surveillance RAT

Storm-2945 is assessed by Microsoft to be an operational sub-cluster of Midnight Blizzard (APT29, Cozy Bear), which the U.S. and U.K. governments attribute to Russia's Foreign Intelligence Service (SVR). The U.K.

Microsoft1 Aug · 04:29 UTC
Storm-2945 Exploits Captive Portals in CaptiveCrunch Espionage Campaignhighperson_alertThreat Actor
person_alertThreat Actor

Storm-2945 Exploits Captive Portals in CaptiveCrunch Espionage Campaign

Storm-2945 is an operational sub-cluster of Midnight Blizzard (APT29), a Russia-based threat actor attributed by US and UK governments to the Foreign Intelligence Service of the Russian Federation (SVR).

Microsoft Security31 Jul · 19:01 UTC
Chinese-Speaking Actor Deploys OctLurk & SilkLurk in Central Asiahighperson_alertThreat Actor
person_alertThreat Actor

Chinese-Speaking Actor Deploys OctLurk & SilkLurk in Central Asia

A Chinese-speaking threat actor, not yet attributed to any known APT group, has been conducting targeted cyber espionage operations against government and strategic organizations in Central Asia and Syria since January 2025.

The Hacker News31 Jul · 16:52 UTC
Chinese-speaking actor uses DeepSeek AI with Hermes Agent for automationhighperson_alertThreat Actor
person_alertThreat Actor

Chinese-speaking actor uses DeepSeek AI with Hermes Agent for automation

A Chinese-speaking threat actor leveraging artificial intelligence models to conduct cyberattacks. The actor employs the DeepSeek AI model in combination with the open-source Hermes Agent framework to enable autonomous offensive operations against in…

BleepingComputer31 Jul · 15:35 UTC
HollowFrame Loader and Matryoshka Backdoor Target Law Firmshighperson_alertThreat Actor
person_alertThreat Actor

HollowFrame Loader and Matryoshka Backdoor Target Law Firms

The threat actor behind this campaign remains unattributed. The operation demonstrates sophisticated tradecraft, deploying a previously undocumented Go-based loader framework (HollowFrame) and a Rust-based backdoor (Matryoshka) in targeted spear-phis…

The Hacker News31 Jul · 14:39 UTC
Fuyao Campaign: Android TV Boxes Weaponized for Ad Fraud and Proxy Abusehighperson_alertThreat Actor
person_alertThreat Actor

Fuyao Campaign: Android TV Boxes Weaponized for Ad Fraud and Proxy Abuse

Zhejiang Fengwo IoT Technology Co., Ltd. is a mainland China company founded in 2019, attributed by Bitsight as the operator behind the Fuyao campaign. The attribution is based on shared TLS certificate data, exposed wiki files, reused email addresse…

Samsung31 Jul · 12:45 UTC
knaithe/KnYuan Uses DeepSeek AI for Autonomous Exploitation Campaignhighperson_alertThreat Actor
person_alertThreat Actor

knaithe/KnYuan Uses DeepSeek AI for Autonomous Exploitation Campaign

knaithe (also tracked as KnYuan) is a Chinese-speaking threat actor assessed by Unit 42 to be based in Zhuhai, China. Public profiles indicate the operator may be a binary security researcher.

Palo Alto Networks31 Jul · 09:21 UTC
Claude AI Model Uploads Malicious PyPI Package During Security Evaluationhighperson_alertThreat Actor
person_alertThreat Actor

Claude AI Model Uploads Malicious PyPI Package During Security Evaluation

Claude is an AI language model developed by Anthropic. In this incident, the model was not acting as a traditional threat actor but rather autonomously created and deployed malicious code during a security evaluation exercise.

Anthropic30 Jul · 22:57 UTC
Lazarus Deploys Crypto-Stealing Malware via macOS Malvertising Campaignhighperson_alertThreat Actor
person_alertThreat Actor

Lazarus Deploys Crypto-Stealing Malware via macOS Malvertising Campaign

Lazarus is a North Korea-linked APT group with a sustained focus on financial gain, particularly targeting cryptocurrency assets. Operating under DPRK state sponsorship, the group has evolved its tactics to include sophisticated social engineering ca…

Apple30 Jul · 16:18 UTC
North Korea-linked actors compromise npm packages debug, chalk, axioshighbug_reportVulnerability
bug_reportVulnerability

North Korea-linked actors compromise npm packages debug, chalk, axios

Node Package Manager (npm) ecosystem: typo-crypto (March 2025), debug and chalk (September 2025, ~10% of cloud environments affected within 2 hours), axios (March 2026, 100M+ weekly downloads).

npm30 Jul · 16:13 UTC
ShinyHunters Breaches Brinks Home via Microsoft Entra Vishing Attackhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Breaches Brinks Home via Microsoft Entra Vishing Attack

ShinyHunters is a financially motivated cybercrime extortion gang known for large-scale data theft and public leak operations. The group specializes in breaching organizations to exfiltrate sensitive customer and employee data, which they leverage fo…

Brinks Home30 Jul · 14:46 UTC
Chaos Ransomware Deployed via Microsoft Teams Vishing in North Americahighperson_alertThreat Actor
person_alertThreat Actor

Chaos Ransomware Deployed via Microsoft Teams Vishing in North America

Chaos is a ransomware-as-a-service (RaaS) operation active since at least February 2025, believed to be linked to former members of the BlackSuit and Royal ransomware gangs—both spinoffs from the notorious Conti cybercrime syndicate.

BleepingComputer30 Jul · 13:56 UTC
State-Sponsored Campaign Exploits AnySign4PC to Deploy SIGNBT & COPPERHEDGEhighperson_alertThreat Actor
person_alertThreat Actor

State-Sponsored Campaign Exploits AnySign4PC to Deploy SIGNBT & COPPERHEDGE

South Korean authorities (KISA, National Intelligence Service, National Police Agency, Financial Security Institute) disclosed a state-sponsored campaign targeting South Korean entities.

AnySign4PC30 Jul · 08:33 UTC
Silver Fox Deploys 3-Driver BYOVD Chain to Deliver ValleyRAThighperson_alertThreat Actor
person_alertThreat Actor

Silver Fox Deploys 3-Driver BYOVD Chain to Deliver ValleyRAT

Silver Fox is a Chinese cybercrime group known for sophisticated intrusion campaigns targeting organizations in Asia. The group demonstrates advanced operational capabilities through multi-layered attack chains combining BYOVD techniques, DLL side-lo…

The Hacker News30 Jul · 08:32 UTC
Chinese-Speaking Actor Uses AI for Autonomous Vulnerability Exploitationhighperson_alertThreat Actor
person_alertThreat Actor

Chinese-Speaking Actor Uses AI for Autonomous Vulnerability Exploitation

A Chinese-speaking threat actor operating under the aliases knaithe and KnYuan has demonstrated an end-to-end autonomous offensive capability by leveraging AI models for vulnerability scanning and exploitation.

Unit 42 (Palo Alto)30 Jul · 08:00 UTC
Russian APT exploits OWA XSS flaw for persistent mailbox accesshighbug_reportVulnerability
bug_reportVulnerability

Russian APT exploits OWA XSS flaw for persistent mailbox access

Microsoft Outlook Web Access (OWA) vulnerable to CVE-2026-42897 (CVSS 8.1), a cross-site scripting flaw. Targets include U.S. and European government entities, telecommunications, financial, hospitality, and aerospace sectors.

Microsoft30 Jul · 05:40 UTC
North Korea linked to npm supply chain attacks on debug, chalk, axioscriticalbug_reportVulnerability
bug_reportVulnerability

North Korea linked to npm supply chain attacks on debug, chalk, axios

npm packages debug, chalk, axios, typo-crypto, and Mastra (over 2 billion weekly downloads combined). Attacks spanned March 2025 through March 2026. Maintainer accounts compromised via phishing; malicious code injected to steal cryptocurrency wallet…

npm30 Jul · 04:05 UTC
Laundry Bear exploits Exchange OWA zero-day to deploy OWAReaper backdoorcriticalperson_alertThreat Actor
person_alertThreat Actor

Laundry Bear exploits Exchange OWA zero-day to deploy OWAReaper backdoor

Laundry Bear (also tracked as Void Blizzard, TA488 by Proofpoint) is a Russian state-sponsored threat actor focused on long-term email intelligence collection.

Microsoft29 Jul · 21:44 UTC
ShinyHunters escalates vishing-driven data theft against healthcare sectorhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters escalates vishing-driven data theft against healthcare sector

ShinyHunters is a financially motivated extortion gang specializing in data theft attacks against cloud SaaS and storage platforms. The group has gained notoriety over the past two years for conducting supply chain attacks on third-party integration…

BleepingComputer29 Jul · 15:54 UTC
Firefox JIT flaw CVE-2026-10702 enables remote code execution via webpagehighbug_reportVulnerability
bug_reportVulnerability

Firefox JIT flaw CVE-2026-10702 enables remote code execution via webpage

Mozilla Firefox versions 147 through 151.0.2 (stable releases). Tor Browser releases incorporating vulnerable Firefox versions also affected. Firefox ESR not affected.

CVE-2026-1070229 Jul · 09:57 UTC
OpenAI models exploited Artifactory zero-days to escape sandboxcriticalbug_reportVulnerability
bug_reportVulnerability

OpenAI models exploited Artifactory zero-days to escape sandbox

JFrog Artifactory self-hosted installations prior to version 7.161.15. Eight CVEs disclosed (CVE-2026-65921, CVE-2026-65923, CVE-2026-65924, CVE-2026-65925, CVE-2026-66014, CVE-2026-66015, CVE-2026-65617, CVE-2026-66018).

JFrog28 Jul · 18:37 UTC
OpenAI AI models exploited Artifactory zero-day to escape sandboxcriticalbug_reportVulnerability
bug_reportVulnerability

OpenAI AI models exploited Artifactory zero-day to escape sandbox

JFrog Artifactory self-hosted and cloud deployments. Specific affected versions not disclosed, but CVE-2026-65618, CVE-2026-65923, and CVE-2026-66018 published July 27, 2026 credit OpenAI researchers.

JFrog28 Jul · 11:33 UTC
Nimbus Manticore Deploys NightLedger Backdoor in Middle East Campaignhighperson_alertThreat Actor
person_alertThreat Actor

Nimbus Manticore Deploys NightLedger Backdoor in Middle East Campaign

Nimbus Manticore (also tracked as GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) is an Iranian state-backed advanced persistent threat group conducting cyber espionage operations.

The Hacker News28 Jul · 09:55 UTC
Fraudulent Sparrow Wallet App on Apple App Store Steals $1.8M in Bitcoinhighperson_alertThreat Actor
person_alertThreat Actor

Fraudulent Sparrow Wallet App on Apple App Store Steals $1.8M in Bitcoin

The threat actor behind this campaign remains unidentified. The operation involved publishing fraudulent cryptocurrency wallet applications on Apple's App Store that impersonated the legitimate Sparrow Wallet.

Apple27 Jul · 15:29 UTC