Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 356 results
highperson_alertThreat ActorJackSkid Adopts Blockchain C2 and Relay Mesh After March Takedown
JackSkid is an IoT botnet operator linked to the Dysphoria botnet family, targeted in coordinated U.S., German, and Canadian law enforcement actions on March 19, 2026.
highperson_alertThreat ActorAnubis Ransomware Attacks Coca-Cola's Fairlife Subsidiary
Anubis is a ransomware operation that employs double extortion tactics, combining data encryption with exfiltration and threatened public release of stolen information.
highperson_alertThreat ActorShinyHunters Claims Ernst & Young Breach via Supply-Chain Attack
ShinyHunters is a financially motivated cybercrime extortion gang known for conducting data breaches and operating a data leak site to pressure victims into paying ransoms.
highbug_reportVulnerabilityn8n sandbox escape lets authenticated editors run OS commands
n8n workflow automation platform versions <2.31.5 and 2.32.0 to <2.32.1. Exploitation requires authenticated workflow editor account. n8n Cloud impact status not disclosed. No patched 1.x release mentioned.
highperson_alertThreat ActorOperation BlueDash: Phishing Campaign Delivers RMM Tools via Fake Teams
Operation BlueDash is a phishing campaign attributed with moderate-to-high confidence to a threat actor group operating from Nigeria. The attribution is based on analysis of infrastructure, code history, and a GitHub environment used to operate the c…
highperson_alertThreat ActorChina-Linked Group Uses Cruciferra Crypter in Tax-Themed Phishing Campaigns
A China-linked cybercrime group, tracked as TA4922 by Proofpoint, has been conducting opportunistic phishing campaigns targeting Indian taxpayers, tax professionals, and corporate finance teams.
highperson_alertThreat ActorEast Asia-Linked Actor Deploys TELESHIM, MIXEDKEY, BINDCLOAK Against ME Gov
An unattributed threat actor assessed with moderate-to-high confidence to originate from East Asia, based on operational hours (4 a.m.–12 p.m. UTC, peaking 7–11 a.m.
highperson_alertThreat ActorClickFix Abuses Steam Forums to Deliver XMRig Cryptominer
ClickFix is a threat actor conducting social engineering campaigns that leverage fake technical support content to distribute malware. The actor exploits user trust in community-driven platforms, specifically targeting gaming communities through Stea…
highperson_alertThreat ActorSourTrade Campaign Delivers Malware via Browser-Assembled Executables
SourTrade is a malvertising campaign (not a named threat actor group) operating since late 2024. The campaign impersonates legitimate trading platforms—TradingView, Solana, and Luno—to distribute malware to retail traders and cryptocurrency investors…
highperson_alertThreat ActorShinyHunters-themed sextortion campaign exploits leaked breach data
ShinyHunters is a known extortion group that has leaked data from multiple high-profile breaches including Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread, and McGraw Hill.
highbug_reportVulnerabilityGitLab RCE PoC published for unpatched self-managed instances ≤18.11.3
GitLab CE/EE self-managed instances: versions 15.2.0–18.10.7, 18.11.0–18.11.4, and 19.0.0–19.0.1. All tiers (Free through Ultimate) affected. Underlying flaw in Oj gem 3.13.0–3.17.1. GitLab.com SaaS not affected.
criticalperson_alertThreat ActorCl0p Affiliates Exploit PTC Windchill RCE for Manufacturing Data Extortion
Cl0p (also tracked as Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) is a financially-motivated ransomware operation known for systematically exploiting zero-day and N-day vulnerabilities in enterprise file transfer and business-critical…
highperson_alertThreat ActorDevMan RaaS Centralizes Affiliate Operations via Dedicated Portal
DevMan (tracked as Funky Mantis by PRODAFT) is a ransomware-as-a-service operation that emerged in April 2025, initially as an affiliate for Qilin, DragonForce, Apos, and RansomHub before transitioning to independent RaaS operations.
highperson_alertThreat ActorBlueNoroff Phishing Kit Profiles Crypto Wallets Before Malware Delivery
BlueNoroff (also tracked as APT38, NICKEL GLADSTONE, BeagleBoyz, Stardust Chollima) is a North Korean state-sponsored threat actor attributed to financially motivated operations targeting the cryptocurrency and technology sectors.
highbug_reportVulnerabilityCertighost exploit public for AD CS flaw allowing DC impersonation
Microsoft Active Directory Certificate Services (AD CS) on Windows Server 2012 through 2025 (including Server Core) and Windows 10 versions 1607 and 1809. Environments with Enterprise CA and default Machine certificate template are vulnerable.
highperson_alertThreat ActorHermes AI Agent Used for Post-Exploitation at Thai Finance Ministry
The threat actor behind this intrusion remains unattributed. Hunt.io assesses with low-to-medium confidence that the operator is Chinese-speaking or fluent in Chinese, based on linguistic artifacts (password containing "Leishen," meaning thunder god)…
highperson_alertThreat ActorGolden Chickens MaaS Resurfaces With Four New Malware Families
Golden Chickens (also known as Venom Spider, tracked by Recorded Future as TAG-195) is a financially motivated malware-as-a-service (MaaS) developer that provides tooling to multiple cybercrime groups.
highperson_alertThreat ActorClop Ransomware Gang Exploits PTC Windchill and FlexPLM Vulnerabilities
Clop (also tracked as Cl0p) is a financially motivated ransomware and data extortion gang with a well-established pattern of targeting enterprise software platforms to steal sensitive data and extort victims.
highperson_alertThreat ActorUAC-0099 Deploys MATCHBOIL.V2 via Fake Notepad++ Plugin
UAC-0099 is a Russia-aligned threat group active since at least mid-2022. The actor conducts cyber espionage operations primarily targeting Ukrainian entities.
criticalperson_alertThreat ActorRussian Espionage Group Exploited Zimbra Zero-Day for Email Theft
A Russian state-sponsored espionage group conducted a sustained campaign exploiting a zero-day vulnerability in Zimbra's webmail client. The actor, tracked as TA488 by Proofpoint and CL-STA-1114 by Unit 42, operated undetected for at least five month…
highperson_alertThreat ActorLaundry Bear exploits Zimbra XSS zero-day for email theft
Laundry Bear (also tracked as Void Blizzard by Microsoft) is a Russian state-sponsored APT group first publicly attributed by Dutch intelligence agencies in May 2025 following their 2024 compromise of the Dutch National Police.
highperson_alertThreat ActorRussian cyberespionage campaign targets Zimbra via JavaScript injection
This campaign is attributed by Unit 42 to Russian cyberespionage interests. The actor's motivation centers on intelligence gathering through compromise of email infrastructure.
highperson_alertThreat ActorChaos Ransomware Group Deploys msaRAT Rust Implant via Headless Browsers
Chaos is a ransomware group that operates through spam floods, vishing campaigns, Quick Assist abuse, and RMM tools for initial access and persistence. The group deploys custom tooling including the msaRAT Rust-based implant as a pre-ransomware stage…
highperson_alertThreat ActorJadeProx Deploys TriBack Loader Against Asian, Latin American Targets
JadeProx is a China-nexus threat actor tracked by Group-IB, discovered through an exposed Alibaba Cloud server in Singapore in mid-April 2026. The actor targets government, healthcare, and education organizations across Asia and Latin America.
highperson_alertThreat ActorLaundry Bear: Russian APT deploys zero-click phishing via Zimbra exploit
Laundry Bear is an advanced persistent threat (APT) group attributed to Russian state support, specializing in covert email data acquisition. The group conducts espionage operations targeting Western organizations and NATO members.
highperson_alertThreat ActorGitHub Actions Abused to Scan and Exploit cPanel/WHM Servers
The threat actor behind this campaign remains unattributed. The operation demonstrates sophisticated understanding of GitHub Actions infrastructure and supply chain attack vectors.
highperson_alertThreat ActorChaos ransomware gang deploys msaRAT backdoor via browser hijacking
Chaos is a ransomware gang that emerged in early 2025, distinct from the earlier same-named ransomware family active since 2021. The group has been linked to Iranian state-backed threat actor MuddyWater, who reportedly leveraged Chaos ransomware to d…
highperson_alertThreat ActorEverest Gang Demands $12.3M from Stadler Rail After Supplier Breach
Everest is a ransomware operation that emerged in 2020, initially deploying file encryption but later pivoted to pure data theft extortion tactics. The group threatens to leak stolen data unless ransom demands are met.
highperson_alertThreat ActorKratos Phishing Kit Dismantled After Stealing Microsoft 365 Sessions
The Kratos operator is an Indonesian individual arrested by local authorities for allegedly developing and operating the Kratos phishing-as-a-service (PhaaS) platform.
highperson_alertThreat ActorKratos PhaaS Platform Dismantled in Joint Law Enforcement Operation
Kratos is a phishing-as-a-service (PhaaS) platform operator that provided cybercriminal infrastructure enabling third-party threat actors to conduct phishing campaigns at scale.