Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 567 results
Active filter:tag: #high✕ clear
Anubis Ransomware Attacks Coca-Cola's Fairlife Subsidiaryhighperson_alertThreat Actor
person_alertThreat Actor

Anubis Ransomware Attacks Coca-Cola's Fairlife Subsidiary

Anubis is a ransomware operation that employs double extortion tactics, combining data encryption with exfiltration and threatened public release of stolen information.

Coca-Cola Company27 Jul · 13:39 UTC
ShinyHunters Claims Ernst & Young Breach via Supply-Chain Attackhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Claims Ernst & Young Breach via Supply-Chain Attack

ShinyHunters is a financially motivated cybercrime extortion gang known for conducting data breaches and operating a data leak site to pressure victims into paying ransoms.

Ernst & Young27 Jul · 13:12 UTC
n8n sandbox escape lets authenticated editors run OS commandshighbug_reportVulnerability
bug_reportVulnerability

n8n sandbox escape lets authenticated editors run OS commands

n8n workflow automation platform versions <2.31.5 and 2.32.0 to <2.32.1. Exploitation requires authenticated workflow editor account. n8n Cloud impact status not disclosed. No patched 1.x release mentioned.

CVE-2026-2757727 Jul · 11:05 UTC
Operation BlueDash: Phishing Campaign Delivers RMM Tools via Fake Teamshighperson_alertThreat Actor
person_alertThreat Actor

Operation BlueDash: Phishing Campaign Delivers RMM Tools via Fake Teams

Operation BlueDash is a phishing campaign attributed with moderate-to-high confidence to a threat actor group operating from Nigeria. The attribution is based on analysis of infrastructure, code history, and a GitHub environment used to operate the c…

Microsoft27 Jul · 10:37 UTC
China-Linked Group Uses Cruciferra Crypter in Tax-Themed Phishing Campaignshighperson_alertThreat Actor
person_alertThreat Actor

China-Linked Group Uses Cruciferra Crypter in Tax-Themed Phishing Campaigns

A China-linked cybercrime group, tracked as TA4922 by Proofpoint, has been conducting opportunistic phishing campaigns targeting Indian taxpayers, tax professionals, and corporate finance teams.

The Hacker News27 Jul · 08:51 UTC
East Asia-Linked Actor Deploys TELESHIM, MIXEDKEY, BINDCLOAK Against ME Govhighperson_alertThreat Actor
person_alertThreat Actor

East Asia-Linked Actor Deploys TELESHIM, MIXEDKEY, BINDCLOAK Against ME Gov

An unattributed threat actor assessed with moderate-to-high confidence to originate from East Asia, based on operational hours (4 a.m.–12 p.m. UTC, peaking 7–11 a.m.

The Hacker News27 Jul · 06:48 UTC
ClickFix Abuses Steam Forums to Deliver XMRig Cryptominerhighperson_alertThreat Actor
person_alertThreat Actor

ClickFix Abuses Steam Forums to Deliver XMRig Cryptominer

ClickFix is a threat actor conducting social engineering campaigns that leverage fake technical support content to distribute malware. The actor exploits user trust in community-driven platforms, specifically targeting gaming communities through Stea…

Steam25 Jul · 20:37 UTC
SourTrade Campaign Delivers Malware via Browser-Assembled Executableshighperson_alertThreat Actor
person_alertThreat Actor

SourTrade Campaign Delivers Malware via Browser-Assembled Executables

SourTrade is a malvertising campaign (not a named threat actor group) operating since late 2024. The campaign impersonates legitimate trading platforms—TradingView, Solana, and Luno—to distribute malware to retail traders and cryptocurrency investors…

Bun25 Jul · 16:48 UTC
Malvertising campaign targets crypto users with in-memory malware assemblyhighbug_reportVulnerability
bug_reportVulnerability

Malvertising campaign targets crypto users with in-memory malware assembly

Users of Solana, Luno, and TradingView platforms targeted via malicious advertisements. Campaign uses fake webpages that deliver JavaScript-based malware assembled directly in browser memory, affecting users across all platforms and browsers.

Solana25 Jul · 13:21 UTC
ShinyHunters-themed sextortion campaign exploits leaked breach datahighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters-themed sextortion campaign exploits leaked breach data

ShinyHunters is a known extortion group that has leaked data from multiple high-profile breaches including Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread, and McGraw Hill.

BleepingComputer25 Jul · 12:16 UTC
GitLab RCE PoC published for unpatched self-managed instances ≤18.11.3highbug_reportVulnerability
bug_reportVulnerability

GitLab RCE PoC published for unpatched self-managed instances ≤18.11.3

GitLab CE/EE self-managed instances: versions 15.2.0–18.10.7, 18.11.0–18.11.4, and 19.0.0–19.0.1. All tiers (Free through Ultimate) affected. Underlying flaw in Oj gem 3.13.0–3.17.1. GitLab.com SaaS not affected.

GitLab25 Jul · 08:14 UTC
Insurance phishing evolves to real-time account hijacking via OTP relayhighbug_reportVulnerability
bug_reportVulnerability

Insurance phishing evolves to real-time account hijacking via OTP relay

Insurance providers globally, with primary focus on Saudi Arabia; additional activity in Europe, US, and India. Affects customers of multiple insurance brands using online portals for policy management, claims, and payments.

The Hacker News25 Jul · 08:14 UTC
DevMan RaaS Centralizes Affiliate Operations via Dedicated Portalhighperson_alertThreat Actor
person_alertThreat Actor

DevMan RaaS Centralizes Affiliate Operations via Dedicated Portal

DevMan (tracked as Funky Mantis by PRODAFT) is a ransomware-as-a-service operation that emerged in April 2025, initially as an affiliate for Qilin, DragonForce, Apos, and RansomHub before transitioning to independent RaaS operations.

The Hacker News25 Jul · 07:53 UTC
AI Agent Used in Alleged Breach of Thai Finance MinistryhighpublicGeopolitical
publicGeopolitical

AI Agent Used in Alleged Breach of Thai Finance Ministry

The alleged intrusion into Thailand's Ministry of Finance represents a significant evolution in cyber threat tradecraft, demonstrating the operational use of autonomous AI agents to automate post-exploitation activities.

Hermes AI agent24 Jul · 17:09 UTC
DNS hijacking on hotel Wi-Fi redirects users to fake Microsoft 365 loginshighbug_reportVulnerability
bug_reportVulnerability

DNS hijacking on hotel Wi-Fi redirects users to fake Microsoft 365 logins

Wi-Fi gateways at hotels and conference centers in multiple U.S. cities, India, and Saudi Arabia. Targets traveling employees from financial services, professional services, legal, healthcare, energy, and retail sectors accessing Microsoft 365.

Microsoft24 Jul · 15:50 UTC
BlueNoroff Phishing Kit Profiles Crypto Wallets Before Malware Deliveryhighperson_alertThreat Actor
person_alertThreat Actor

BlueNoroff Phishing Kit Profiles Crypto Wallets Before Malware Delivery

BlueNoroff (also tracked as APT38, NICKEL GLADSTONE, BeagleBoyz, Stardust Chollima) is a North Korean state-sponsored threat actor attributed to financially motivated operations targeting the cryptocurrency and technology sectors.

Zoom24 Jul · 13:12 UTC
Certighost exploit public for AD CS flaw allowing DC impersonationhighbug_reportVulnerability
bug_reportVulnerability

Certighost exploit public for AD CS flaw allowing DC impersonation

Microsoft Active Directory Certificate Services (AD CS) on Windows Server 2012 through 2025 (including Server Core) and Windows 10 versions 1607 and 1809. Environments with Enterprise CA and default Machine certificate template are vulnerable.

Microsoft24 Jul · 12:15 UTC
Illinois man sentenced for social engineering attack on 750+ Snapchat usershighpublicGeopolitical
publicGeopolitical

Illinois man sentenced for social engineering attack on 750+ Snapchat users

This case represents a domestic criminal prosecution within the United States for cybercrime targeting individual consumers. The incident reflects the persistent challenge of social engineering attacks against commercial platform users and the exploi…

Snapchat24 Jul · 09:17 UTC
Hermes AI Agent Used for Post-Exploitation at Thai Finance Ministryhighperson_alertThreat Actor
person_alertThreat Actor

Hermes AI Agent Used for Post-Exploitation at Thai Finance Ministry

The threat actor behind this intrusion remains unattributed. Hunt.io assesses with low-to-medium confidence that the operator is Chinese-speaking or fluent in Chinese, based on linguistic artifacts (password containing "Leishen," meaning thunder god)…

Hermes AI24 Jul · 08:15 UTC
Golden Chickens MaaS Resurfaces With Four New Malware Familieshighperson_alertThreat Actor
person_alertThreat Actor

Golden Chickens MaaS Resurfaces With Four New Malware Families

Golden Chickens (also known as Venom Spider, tracked by Recorded Future as TAG-195) is a financially motivated malware-as-a-service (MaaS) developer that provides tooling to multiple cybercrime groups.

The Hacker News24 Jul · 08:09 UTC
NodeBB forum software patches 8 high-severity flaws with public exploitshighbug_reportVulnerability
bug_reportVulnerability

NodeBB forum software patches 8 high-severity flaws with public exploits

NodeBB forum software, all versions before 4.14.0. Fixes available in version 4.14.2 and later. Five of eight flaws affect only forums with ActivityPub federation enabled (default in v4 fresh installs, disabled in v3 upgrades).

NodeBB24 Jul · 05:41 UTC
Clop Ransomware Gang Exploits PTC Windchill and FlexPLM Vulnerabilitieshighperson_alertThreat Actor
person_alertThreat Actor

Clop Ransomware Gang Exploits PTC Windchill and FlexPLM Vulnerabilities

Clop (also tracked as Cl0p) is a financially motivated ransomware and data extortion gang with a well-established pattern of targeting enterprise software platforms to steal sensitive data and extort victims.

PTC24 Jul · 05:36 UTC
UAC-0099 Deploys MATCHBOIL.V2 via Fake Notepad++ Pluginhighperson_alertThreat Actor
person_alertThreat Actor

UAC-0099 Deploys MATCHBOIL.V2 via Fake Notepad++ Plugin

UAC-0099 is a Russia-aligned threat group active since at least mid-2022. The actor conducts cyber espionage operations primarily targeting Ukrainian entities.

Notepad++24 Jul · 04:50 UTC
Dolphin X RAT uses AI profiling to prioritize high-value victimshighbug_reportVulnerability
bug_reportVulnerability

Dolphin X RAT uses AI profiling to prioritize high-value victims

Organizations and individuals infected with Dolphin X remote access trojan. No specific vendor products or CVEs associated; threat affects Windows endpoints where the malware is deployed via social engineering or other distribution methods.

BleepingComputer23 Jul · 19:20 UTC
Origin Energy breach exposes 2M Australian customer recordshighpublicGeopolitical
publicGeopolitical

Origin Energy breach exposes 2M Australian customer records

The breach of Origin Energy, Australia's largest energy retailer with $8.5 billion in annual revenue and cross-border holdings in UK renewable energy, underscores the persistent targeting of critical infrastructure providers in the Indo-Pacific regio…

Origin Energy23 Jul · 18:14 UTC
Bing malvertising pushes fake Claude installer delivering SectopRAThighbug_reportVulnerability
bug_reportVulnerability

Bing malvertising pushes fake Claude installer delivering SectopRAT

Microsoft Bing search users seeking Claude AI desktop app. Malicious Claude Artifact hosted on legitimate claude.ai domain (removed by Anthropic). At least 29 organizations compromised July 21-22, 2026.

Microsoft23 Jul · 17:48 UTC
Laundry Bear exploits Zimbra XSS zero-day for email thefthighperson_alertThreat Actor
person_alertThreat Actor

Laundry Bear exploits Zimbra XSS zero-day for email theft

Laundry Bear (also tracked as Void Blizzard by Microsoft) is a Russian state-sponsored APT group first publicly attributed by Dutch intelligence agencies in May 2025 following their 2024 compromise of the Dutch National Police.

Zimbra23 Jul · 14:49 UTC
UAC-0099 abuses Notepad++ plugin loading to deploy LunchPoke malwarehighbug_reportVulnerability
bug_reportVulnerability

UAC-0099 abuses Notepad++ plugin loading to deploy LunchPoke malware

Organizations in Ukraine using Notepad++ 8.8.3. The attack does not exploit a vulnerability in Notepad++; it abuses legitimate plugin-loading functionality to deploy LunchPoke, BurnyBear, and MatchBoil V2 malware loaders via social engineering (malic…

Notepad++23 Jul · 14:32 UTC
Microsoft 365 outage disrupts cloud services across North AmericahighpublicGeopolitical
publicGeopolitical

Microsoft 365 outage disrupts cloud services across North America

The incident represents a technical service disruption affecting critical cloud infrastructure rather than a geopolitical cyber event. Microsoft 365's position as backbone infrastructure for government, defense, and commercial operations in North Ame…

Microsoft23 Jul · 13:34 UTC
Russian cyberespionage campaign targets Zimbra via JavaScript injectionhighperson_alertThreat Actor
person_alertThreat Actor

Russian cyberespionage campaign targets Zimbra via JavaScript injection

This campaign is attributed by Unit 42 to Russian cyberespionage interests. The actor's motivation centers on intelligence gathering through compromise of email infrastructure.

Zimbra23 Jul · 12:10 UTC