Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 157 results
highperson_alertThreat ActorArctic Wolf exploits FortiClient EMS flaw for credential theft
Arctic Wolf is a threat actor exploiting a critical, patched vulnerability in FortiClient Endpoint Management Server (EMS) to deploy credential-stealing malware.
highperson_alertThreat ActorStorm-2697 Deploys The Gentlemen Go-Based Ransomware with Worm Capabilities
Storm-2697 is a threat actor tracked by Microsoft Threat Intelligence that operates as a ransomware affiliate group. The actor deploys The Gentlemen ransomware, a sophisticated Go-based encryption tool, suggesting technical proficiency in modern prog…
highperson_alertThreat ActorRomanian National Sentenced for Hacking Oregon Government Network
A Romanian national individual actor who conducted unauthorized access operations targeting U.S. government and private sector networks. The actor's motivation appears to be financially driven cybercrime, operating from Romania to compromise Oregon s…
highperson_alertThreat ActorShinyHunters Claims Breach of Carnival Corporation, 6M Records
ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has been active since at least 2020, specializing in breaching corporate databases and exfiltrating customer and employee re…
highperson_alertThreat ActorJINX-0164 Targets Cryptocurrency Orgs with macOS Malware
JINX-0164 is a previously undocumented threat actor with a financial motivation focused on digital asset theft. The group demonstrates technical sophistication through the development of custom macOS malware and operational tradecraft centered on soc…
highperson_alertThreat ActorSilent Ransom Group Shifts to Physical Data Theft at U.S. Law Firms
Silent Ransom Group (SRG) is an extortion-focused threat actor that has evolved from traditional ransomware operations to conducting physical, in-person data theft attacks.
highperson_alertThreat ActorShinyHunters Extorts Charter Communications After Data Breach
ShinyHunters is a financially motivated cybercrime group known for large-scale data breaches and extortion operations targeting organizations across multiple sectors.
highperson_alertThreat ActorMuddyWater Q1 2026 espionage campaign hits nine countries via DLL side-loading
MuddyWater (also tracked as Earth Vetala, MERCURY, Static Kitten, and Seedworm) is an Iranian state-sponsored APT group attributed to Iran's Ministry of Intelligence and Security (MOIS).
highperson_alertThreat ActorNimbus Manticore deploys MiniFast and MiniJunk V2 via phishing and SEO poisoning
Nimbus Manticore (also tracked as Screening Serpens and UNC1549) is an Iranian state-sponsored threat actor attributed to Iran's intelligence apparatus.
highperson_alertThreat ActorShinyHunters Breaches 7-Eleven, Exfiltrates 183K Records
ShinyHunters is a financially motivated cybercrime group known for large-scale data breaches and extortion operations targeting organizations across multiple sectors.
highperson_alertThreat ActorDutch Authorities Disrupt Hosting Infrastructure Linked to Russian Ops
This operation involves Russian state-sponsored cyber activity facilitated through compromised Internet hosting infrastructure in the Netherlands. The arrested co-owners operated hosting companies that assumed control of Stark Industries Solutions' t…
highperson_alertThreat ActorFBI warns of Kali365 phishing-as-a-service targeting Microsoft 365
Kali365 is a phishing-as-a-service (PhaaS) platform that enables threat actors to conduct credential harvesting and account takeover operations against Microsoft 365 users.
highperson_alertThreat ActorLazarus Group deploys RemotePE cross-platform RAT against finance sector
Lazarus Group is a North Korean state-sponsored advanced persistent threat (APT) actor attributed to the Reconnaissance General Bureau (RGB). The group is financially motivated, conducting operations to generate revenue for the DPRK regime through th…
criticalperson_alertThreat ActorClickFix Campaign Exploits Ghost CMS SQLi to Inject Malicious JavaScript
The threat actor behind this campaign remains unattributed. Motivation appears to be financially driven, leveraging ClickFix social engineering tactics to deliver malware or steal credentials.
highperson_alertThreat ActorFirst VPN Service dismantled by European and North American authorities
First VPN Service was a criminal VPN infrastructure provider that facilitated cybercrime operations for approximately 25 ransomware groups. The service enabled threat actors to obscure their geographic origins and true IP addresses during malicious a…
highperson_alertThreat ActorF5 BIG-IP Exploitation Leads to Confluence Compromise and Lateral Movement
The threat actor behind this campaign remains unattributed. Motivation appears to be credential theft and network persistence within enterprise environments.
criticalperson_alertThreat ActorCISA Contractor Leaks AWS GovCloud Keys on Public GitHub Repository
The threat actor is an insider—a contractor working for the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The individual intentionally published sensitive AWS GovCloud credentials and agency secrets to a public GitHub repository.
highperson_alertThreat ActorGhostwriter Targets Ukrainian Government with Prometheus-Themed Phishing
Ghostwriter (also tracked as UAC-0057 and UNC1151) is a Belarus-aligned threat actor known for conducting information operations and cyber espionage campaigns.
highperson_alertThreat ActorScreening Serpens: Iranian APT Targets Tech and Defense with RAT Malware
Screening Serpens is an Iranian APT group attributed by Unit 42, conducting cyber espionage operations. The group is motivated by intelligence collection targeting technology and defense sectors, consistent with Iranian state interests in acquiring s…
highperson_alertThreat ActorMegalodon campaign injects 5,718 malicious commits into GitHub repos
Megalodon is an automated supply chain attack campaign targeting GitHub repositories. The actor's motivation appears to be exfiltration of CI/CD environment data, including secrets, tokens, and credentials stored in GitHub Actions workflows.
highperson_alertThreat ActorROADtools Framework Misused in Nation-State Cloud Intrusions
Multiple threat actors, including nation-state groups, are misusing the open-source ROADtools framework for cloud intrusions. ROADtools is a legitimate Azure AD reconnaissance toolkit designed for security assessments, but has been co-opted by advers…
highperson_alertThreat ActorCanadian National Arrested for Operating KimWolf DDoS Botnet
A Canadian national arrested by U.S. and Canadian authorities for operating the KimWolf DDoS botnet infrastructure. The operator managed a large-scale botnet that compromised nearly two million devices globally, offering DDoS-for-hire services.
highperson_alertThreat ActorJacob Butler Arrested for Operating Kimwolf DDoS Botnet
Jacob Butler, also known as "Dort," is a 23-year-old Canadian national from Ottawa arrested by the U.S. Department of Justice for developing and operating the Kimwolf DDoS botnet.
highperson_alertThreat ActorDort Arrested for Operating Kimwolf IoT Botnet in Multi-Million Device DDoS Campaign
Dort is a 23-year-old cybercriminal based in Ottawa, Canada, suspected of developing and operating the Kimwolf IoT botnet. Motivated by launching large-scale DDoS attacks, doxing, and swatting campaigns, Dort leveraged compromised IoT devices to buil…
highperson_alertThreat ActorShowboat Linux Malware Targets Middle East Telecom Since Mid-2022
The threat actor behind Showboat remains unattributed. The campaign demonstrates sophisticated targeting of telecommunications infrastructure in the Middle East, suggesting a motivated adversary with strategic intelligence collection objectives.
highperson_alertThreat ActorChinese APT Deploys Showboat and JFMBackdoor Against Telecom Sector
Chinese state-sponsored threat actors conducting cyber-espionage operations against telecommunications infrastructure. The actors demonstrate cross-platform capabilities with custom Linux and Windows malware tooling.
highperson_alertThreat ActorInternational Law Enforcement Seizes First VPN Service Used by Cybercriminals
First VPN was a commercial VPN service exploited by multiple threat actors to anonymize their operations. The service provided infrastructure enabling cybercriminals to mask their origin during ransomware deployments and data exfiltration campaigns.
highperson_alertThreat Actor18-Year-Old Infostealer Operator Arrested for Compromising 28K Accounts
An 18-year-old individual from Odesa, Ukraine, identified by Ukrainian cyberpolice in coordination with U.S. law enforcement. The operator is suspected of deploying infostealer malware to harvest credentials and compromise user accounts.
criticalperson_alertThreat ActorMicrosoft Disrupts Fox Tempest Malware-Signing-as-a-Service Operation
Fox Tempest is a threat actor attributed by Microsoft as operating a malware-signing-as-a-service (MSaaS) business model. The actor exploited Microsoft's Artifact Signing system to provide malicious code signing services to other cybercriminals, enab…
highperson_alertThreat ActorWebworm Deploys EchoCreep and GraphWorm Backdoors via Discord and Graph API
Webworm is a China-aligned advanced persistent threat (APT) actor first documented by Symantec in September 2022, with activity traced back to at least 2022.