Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-21 · 02:09 UTC
articleTotal: 606 reports

Filtered Reports

30 / 202 results
Active filter:tag: #threat-actor✕ clear
Velvet Ant: China-linked APT backdoors Linux auth for decade-long accesscriticalperson_alertThreat Actor
person_alertThreat Actor

Velvet Ant: China-linked APT backdoors Linux auth for decade-long access

Velvet Ant (G1047) is a China-linked advanced persistent threat actor characterized by exceptional operational security and long-term persistence capabilities.

Linux16:17 UTC
Conti Operator Pleads Guilty After Extradition to United Stateshighperson_alertThreat Actor
person_alertThreat Actor

Conti Operator Pleads Guilty After Extradition to United States

Conti is a prolific ransomware-as-a-service (RaaS) operation that emerged in 2020 and became one of the most active and financially successful cybercrime groups before its infrastructure was leaked and operations fragmented in 2022.

BleepingComputer15:54 UTC
AI coding agents vulnerable to code execution via crafted Sentry errorshighbug_reportVulnerability
bug_reportVulnerability

AI coding agents vulnerable to code execution via crafted Sentry errors

AI coding agents (e.g., GitHub Copilot, Cursor, Aider) integrated with Sentry error-tracking platform. Affects development environments where AI agents have code execution permissions and process Sentry error reports.

Sentry10:04 UTC
UNC1151/Ghostwriter Targets Polish Gmail Accounts in Phishing Campaignhighperson_alertThreat Actor
person_alertThreat Actor

UNC1151/Ghostwriter Targets Polish Gmail Accounts in Phishing Campaign

UNC1151, also known as Ghostwriter, is a threat actor group attributed by FireEye/Mandiant that has conducted sustained information operations and cyber espionage activities.

Google09:00 UTC
INTERPOL arrests Guedz, admin of Sniper Dz phishing-as-a-service platformhighperson_alertThreat Actor
person_alertThreat Actor

INTERPOL arrests Guedz, admin of Sniper Dz phishing-as-a-service platform

Guedz is identified as the primary administrator of Sniper Dz, a phishing-as-a-service (PhaaS) platform that operated for approximately a decade across the Middle East and North Africa (MENA) region.

The Hacker News06:52 UTC
Europol Disrupts AudiA6 Cryptocurrency Laundering Servicehighperson_alertThreat Actor
person_alertThreat Actor

Europol Disrupts AudiA6 Cryptocurrency Laundering Service

AudiA6 was a cryptocurrency laundering service utilized by ransomware gangs and cybercriminal networks to obfuscate and legitimize illicit proceeds. The service facilitated the conversion and movement of cryptocurrency obtained through ransomware ope…

The Hacker News04:38 UTC
Oracle PeopleSoft zero-day CVE-2026-35273 exploited by ShinyHunterscriticalbug_reportVulnerability
bug_reportVulnerability

Oracle PeopleSoft zero-day CVE-2026-35273 exploited by ShinyHunters

Oracle PeopleSoft (all versions prior to June 10 patch). Confirmed exploitation targeting enterprise systems and universities. Vulnerability was unpatched during active exploitation window (May 27 - June 9).

CVE-2026-3527318:29 UTC
Oracle PeopleSoft zero-day CVE-2026-35273 exploited for RCE by ShinyHuntercriticalbug_reportVulnerability
bug_reportVulnerability

Oracle PeopleSoft zero-day CVE-2026-35273 exploited for RCE by ShinyHunter

Oracle PeopleSoft Suite, all versions (specific affected versions not disclosed). Unauthenticated remote code execution vulnerability affecting internet-facing PeopleSoft instances.

CVE-2026-3527317:39 UTC
BitLocker bypass via recovery partition XML files (GreatXML)highbug_reportVulnerability
bug_reportVulnerability

BitLocker bypass via recovery partition XML files (GreatXML)

Windows BitLocker encryption on systems with recovery partitions. All Windows versions with BitLocker enabled are potentially affected. Specific version scope not yet published.

Microsoft15:43 UTC
The Gentlemen ransomware group claims 478 victims via multi-RaaS modelhighperson_alertThreat Actor
person_alertThreat Actor

The Gentlemen ransomware group claims 478 victims via multi-RaaS model

The Gentlemen is a financially motivated ransomware threat group that has claimed 478 victims through a hybrid operational model. Initially operating as an affiliate leveraging multiple ransomware-as-a-service (RaaS) platforms—including LockBit, Qili…

The Hacker News14:50 UTC
Law Enforcement Dismantles AudiA6 Cryptocurrency Laundering Servicehighperson_alertThreat Actor
person_alertThreat Actor

Law Enforcement Dismantles AudiA6 Cryptocurrency Laundering Service

AudiA6 was a cryptocurrency laundering service that facilitated money laundering operations for ransomware actors and other cybercriminals. The service allegedly processed over $380 million in illicit proceeds before being dismantled by law enforceme…

BleepingComputer13:55 UTC
OceanLotus Targets Vietnamese Infrastructure with SPECTRALVIPER Backdoorhighperson_alertThreat Actor
person_alertThreat Actor

OceanLotus Targets Vietnamese Infrastructure with SPECTRALVIPER Backdoor

OceanLotus (also tracked as APT32, SeaLotus, APT-C-00, and Canvas Cyclone) is a Vietnam-aligned advanced persistent threat group attributed by multiple vendors to conducting cyber espionage operations.

The Hacker News07:45 UTC
ShinyHunters Targets Oracle PeopleSoft Servers in Mass Data Thefthighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Targets Oracle PeopleSoft Servers in Mass Data Theft

ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has gained notoriety for breaching numerous organizations and exfiltrating sensitive data, which is then used for extortion…

Oracle16:31 UTC
China-Nexus Actors Expand JDY Botnet to 1,500+ IoT/SOHO Deviceshighperson_alertThreat Actor
person_alertThreat Actor

China-Nexus Actors Expand JDY Botnet to 1,500+ IoT/SOHO Devices

China-nexus state-sponsored threat actors operating the JDY botnet infrastructure. The actors leverage compromised small office/home office (SOHO) routers and IoT devices to build a distributed scanning platform for cyber reconnaissance operations.

The Hacker News14:08 UTC
Volt Typhoon Expands JDY Botnet Operations Against U.S. Militaryhighperson_alertThreat Actor
person_alertThreat Actor

Volt Typhoon Expands JDY Botnet Operations Against U.S. Military

Volt Typhoon (also tracked as BRONZE SILHOUETTE, Vanguard Panda, DEV-0391, and UNC3236) is a Chinese state-sponsored APT group attributed to conducting cyber espionage operations targeting critical infrastructure.

BleepingComputer13:00 UTC
The Gentlemen Ransomware: Aggressive Affiliate Model Drives Rapid Growthhighperson_alertThreat Actor
person_alertThreat Actor

The Gentlemen Ransomware: Aggressive Affiliate Model Drives Rapid Growth

The Gentlemen is a ransomware-as-a-service (RaaS) operation that has rapidly ascended to become the second most active ransomware group by victim count.

Krebs on Security12:03 UTC
ServiceNow patches actively exploited auth bypass on hosted instanceshighbug_reportVulnerability
bug_reportVulnerability

ServiceNow patches actively exploited auth bypass on hosted instances

ServiceNow hosted customer instances (specific versions not disclosed). On-premise deployments may also be affected pending vendor guidance.

ServiceNow05:02 UTC
Microsoft Defender zero-day "RoguePlanet" exploited for SYSTEM accesscriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft Defender zero-day "RoguePlanet" exploited for SYSTEM access

Microsoft Defender on all updated Windows systems. No CVE assigned yet. Vulnerability is a race condition enabling local privilege escalation to SYSTEM.

Microsoft03:22 UTC
WinRAR CVE-2025-8088 path traversal exploited by Russian APTs vs Ukrainehighbug_reportVulnerability
bug_reportVulnerability

WinRAR CVE-2025-8088 path traversal exploited by Russian APTs vs Ukraine

WinRAR versions prior to patched release (approximately one year old). Primary targets: Ukrainian organizations. Threat actors: Earth Dahu (Gamaredon) and SHADOW-EARTH-066 (UAC-0226), Russia-aligned APT groups.

CVE-2025-808810:26 UTC
PyPI supply chain attack: 19 packages with auto-executing credential stealerhighbug_reportVulnerability
bug_reportVulnerability

PyPI supply chain attack: 19 packages with auto-executing credential stealer

PyPI repository: 19 compromised packages containing 37 malicious wheel artifacts. Affects Python developers who installed these packages. Attack uses .pth files for automatic execution during pip install, targeting credential theft via Bun-based stea…

PyPI07:13 UTC
PyPI supply-chain attack: 19 science packages compromised with malwarehighbug_reportVulnerability
bug_reportVulnerability

PyPI supply-chain attack: 19 science packages compromised with malware

19 science-focused Python packages on PyPI, collectively downloaded hundreds of thousands of times. Specific package names and versions not disclosed in summary. Affects Python developers using PyPI packages in scientific/research workflows.

BleepingComputer18:41 UTC
Linux kernel nf_tables use-after-free enables root escalation (CVE-2026-23111)criticalbug_reportVulnerability
bug_reportVulnerability

Linux kernel nf_tables use-after-free enables root escalation (CVE-2026-23111)

Linux kernel nf_tables subsystem. All distributions using vulnerable kernel versions prior to the February 5, 2026 patch. Affects systems where unprivileged users have local access or container environments.

CVE-2026-2311118:17 UTC
NSO Group linked to WhatsApp spear-phishing campaignshighperson_alertThreat Actor
person_alertThreat Actor

NSO Group linked to WhatsApp spear-phishing campaigns

NSO Group is an Israeli cyber intelligence firm that develops and sells commercial surveillance technology, primarily the Pegasus spyware platform. The company markets its tools to government clients for lawful interception and intelligence gathering…

WhatsApp16:40 UTC
Meta blocks NSO Group spear-phishing targeting WhatsApp usershighperson_alertThreat Actor
person_alertThreat Actor

Meta blocks NSO Group spear-phishing targeting WhatsApp users

NSO Group is an Israeli commercial surveillance vendor that develops and sells offensive cyber capabilities, primarily the Pegasus spyware platform, to government clients.

Meta15:08 UTC
Check Point patches zero-day in VPN/Mobile Access exploited by Qilincriticalbug_reportVulnerability
bug_reportVulnerability

Check Point patches zero-day in VPN/Mobile Access exploited by Qilin

Check Point Remote Access VPN and Mobile Access deployments. Specific product versions not disclosed in summary; refer to vendor advisory for affected releases and patched versions.

Check Point11:05 UTC
VerdantBamboo deploys BSD BRICKSTORM variant with Linux malwarehighperson_alertThreat Actor
person_alertThreat Actor

VerdantBamboo deploys BSD BRICKSTORM variant with Linux malware

VerdantBamboo is a China-nexus cyber espionage group attributed by Volexity, with operational overlap with the threat cluster known as Clay Typhoon. The actor focuses on intelligence collection operations and has demonstrated cross-platform capabilit…

The Hacker News08:27 UTC
UNC3753 Conducts Data Theft Extortion via Vishing and Physical Intrusionhighperson_alertThreat Actor
person_alertThreat Actor

UNC3753 Conducts Data Theft Extortion via Vishing and Physical Intrusion

UNC3753 is a financially motivated threat actor attributed by Mandiant. The group conducted a data theft extortion campaign targeting dozens of organizations in the United States between January and May 2026.

The Hacker News05:39 UTC
Silent Ransom Group targets U.S. legal sector via fake IT supporthighperson_alertThreat Actor
person_alertThreat Actor

Silent Ransom Group targets U.S. legal sector via fake IT support

Silent Ransom Group is a threat actor conducting social engineering-driven intrusions against U.S. legal services and professional services organizations.

BleepingComputer12:09 UTC
UNC5221 Deploys Brickstorm, Plenet, AgentPSD in M365 Espionage Campaignhighperson_alertThreat Actor
person_alertThreat Actor

UNC5221 Deploys Brickstorm, Plenet, AgentPSD in M365 Espionage Campaign

UNC5221 is a Chinese APT group attributed to conducting cyber espionage operations. The group demonstrates advanced capabilities in targeting cloud environments, specifically Microsoft 365 infrastructure.

Microsoft16:09 UTC
npm supply chain attack: 50+ packages deliver IronWorm stealer and rootkitcriticalbug_reportVulnerability
bug_reportVulnerability

npm supply chain attack: 50+ packages deliver IronWorm stealer and rootkit

npm ecosystem: over 50 compromised legitimate packages. Affects developers using npm for JavaScript/Node.js projects. IronWorm targets developer credentials and source code with eBPF kernel-level persistence.

npm16:05 UTC