Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-20 · 02:03 UTC
articleTotal: 593 reports

Filtered Reports

30 / 157 results
Active filter:✕ clear
Arctic Wolf exploits FortiClient EMS flaw for credential thefthighperson_alertThreat Actor
person_alertThreat Actor

Arctic Wolf exploits FortiClient EMS flaw for credential theft

Arctic Wolf is a threat actor exploiting a critical, patched vulnerability in FortiClient Endpoint Management Server (EMS) to deploy credential-stealing malware.

Fortinet13:26 UTC
Storm-2697 Deploys The Gentlemen Go-Based Ransomware with Worm Capabilitieshighperson_alertThreat Actor
person_alertThreat Actor

Storm-2697 Deploys The Gentlemen Go-Based Ransomware with Worm Capabilities

Storm-2697 is a threat actor tracked by Microsoft Threat Intelligence that operates as a ransomware affiliate group. The actor deploys The Gentlemen ransomware, a sophisticated Go-based encryption tool, suggesting technical proficiency in modern prog…

Microsoft13:00 UTC
Romanian National Sentenced for Hacking Oregon Government Networkhighperson_alertThreat Actor
person_alertThreat Actor

Romanian National Sentenced for Hacking Oregon Government Network

A Romanian national individual actor who conducted unauthorized access operations targeting U.S. government and private sector networks. The actor's motivation appears to be financially driven cybercrime, operating from Romania to compromise Oregon s…

BleepingComputer10:43 UTC
ShinyHunters Claims Breach of Carnival Corporation, 6M Recordshighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Claims Breach of Carnival Corporation, 6M Records

ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has been active since at least 2020, specializing in breaching corporate databases and exfiltrating customer and employee re…

Carnival Corporation08:49 UTC
JINX-0164 Targets Cryptocurrency Orgs with macOS Malwarehighperson_alertThreat Actor
person_alertThreat Actor

JINX-0164 Targets Cryptocurrency Orgs with macOS Malware

JINX-0164 is a previously undocumented threat actor with a financial motivation focused on digital asset theft. The group demonstrates technical sophistication through the development of custom macOS malware and operational tradecraft centered on soc…

The Hacker News05:54 UTC
Silent Ransom Group Shifts to Physical Data Theft at U.S. Law Firmshighperson_alertThreat Actor
person_alertThreat Actor

Silent Ransom Group Shifts to Physical Data Theft at U.S. Law Firms

Silent Ransom Group (SRG) is an extortion-focused threat actor that has evolved from traditional ransomware operations to conducting physical, in-person data theft attacks.

BleepingComputer09:51 UTC
ShinyHunters Extorts Charter Communications After Data Breachhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Extorts Charter Communications After Data Breach

ShinyHunters is a financially motivated cybercrime group known for large-scale data breaches and extortion operations targeting organizations across multiple sectors.

Charter Communications17:46 UTC
MuddyWater Q1 2026 espionage campaign hits nine countries via DLL side-loadinghighperson_alertThreat Actor
person_alertThreat Actor

MuddyWater Q1 2026 espionage campaign hits nine countries via DLL side-loading

MuddyWater (also tracked as Earth Vetala, MERCURY, Static Kitten, and Seedworm) is an Iranian state-sponsored APT group attributed to Iran's Ministry of Intelligence and Security (MOIS).

The Hacker News13:48 UTC
Nimbus Manticore deploys MiniFast and MiniJunk V2 via phishing and SEO poisoninghighperson_alertThreat Actor
person_alertThreat Actor

Nimbus Manticore deploys MiniFast and MiniJunk V2 via phishing and SEO poisoning

Nimbus Manticore (also tracked as Screening Serpens and UNC1549) is an Iranian state-sponsored threat actor attributed to Iran's intelligence apparatus.

The Hacker News05:13 UTC
ShinyHunters Breaches 7-Eleven, Exfiltrates 183K Recordshighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Breaches 7-Eleven, Exfiltrates 183K Records

ShinyHunters is a financially motivated cybercrime group known for large-scale data breaches and extortion operations targeting organizations across multiple sectors.

7-Eleven05:01 UTC
Dutch Authorities Disrupt Hosting Infrastructure Linked to Russian Opshighperson_alertThreat Actor
person_alertThreat Actor

Dutch Authorities Disrupt Hosting Infrastructure Linked to Russian Ops

This operation involves Russian state-sponsored cyber activity facilitated through compromised Internet hosting infrastructure in the Netherlands. The arrested co-owners operated hosting companies that assumed control of Stark Industries Solutions' t…

Stark Industries Solutions11:21 UTC
FBI warns of Kali365 phishing-as-a-service targeting Microsoft 365highperson_alertThreat Actor
person_alertThreat Actor

FBI warns of Kali365 phishing-as-a-service targeting Microsoft 365

Kali365 is a phishing-as-a-service (PhaaS) platform that enables threat actors to conduct credential harvesting and account takeover operations against Microsoft 365 users.

Microsoft10:45 UTC
Lazarus Group deploys RemotePE cross-platform RAT against finance sectorhighperson_alertThreat Actor
person_alertThreat Actor

Lazarus Group deploys RemotePE cross-platform RAT against finance sector

Lazarus Group is a North Korean state-sponsored advanced persistent threat (APT) actor attributed to the Reconnaissance General Bureau (RGB). The group is financially motivated, conducting operations to generate revenue for the DPRK regime through th…

The Hacker News07:32 UTC
ClickFix Campaign Exploits Ghost CMS SQLi to Inject Malicious JavaScriptcriticalperson_alertThreat Actor
person_alertThreat Actor

ClickFix Campaign Exploits Ghost CMS SQLi to Inject Malicious JavaScript

The threat actor behind this campaign remains unattributed. Motivation appears to be financially driven, leveraging ClickFix social engineering tactics to deliver malware or steal credentials.

CVE-2026-2698012:12 UTC
First VPN Service dismantled by European and North American authoritieshighperson_alertThreat Actor
person_alertThreat Actor

First VPN Service dismantled by European and North American authorities

First VPN Service was a criminal VPN infrastructure provider that facilitated cybercrime operations for approximately 25 ransomware groups. The service enabled threat actors to obscure their geographic origins and true IP addresses during malicious a…

The Hacker News15:35 UTC
F5 BIG-IP Exploitation Leads to Confluence Compromise and Lateral Movementhighperson_alertThreat Actor
person_alertThreat Actor

F5 BIG-IP Exploitation Leads to Confluence Compromise and Lateral Movement

The threat actor behind this campaign remains unattributed. Motivation appears to be credential theft and network persistence within enterprise environments.

F514:53 UTC
CISA Contractor Leaks AWS GovCloud Keys on Public GitHub Repositorycriticalperson_alertThreat Actor
person_alertThreat Actor

CISA Contractor Leaks AWS GovCloud Keys on Public GitHub Repository

The threat actor is an insider—a contractor working for the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The individual intentionally published sensitive AWS GovCloud credentials and agency secrets to a public GitHub repository.

Amazon Web Services14:34 UTC
Ghostwriter Targets Ukrainian Government with Prometheus-Themed Phishinghighperson_alertThreat Actor
person_alertThreat Actor

Ghostwriter Targets Ukrainian Government with Prometheus-Themed Phishing

Ghostwriter (also tracked as UAC-0057 and UNC1151) is a Belarus-aligned threat actor known for conducting information operations and cyber espionage campaigns.

The Hacker News14:20 UTC
Screening Serpens: Iranian APT Targets Tech and Defense with RAT Malwarehighperson_alertThreat Actor
person_alertThreat Actor

Screening Serpens: Iranian APT Targets Tech and Defense with RAT Malware

Screening Serpens is an Iranian APT group attributed by Unit 42, conducting cyber espionage operations. The group is motivated by intelligence collection targeting technology and defense sectors, consistent with Iranian state interests in acquiring s…

Unit 42 (Palo Alto)11:00 UTC
Megalodon campaign injects 5,718 malicious commits into GitHub reposhighperson_alertThreat Actor
person_alertThreat Actor

Megalodon campaign injects 5,718 malicious commits into GitHub repos

Megalodon is an automated supply chain attack campaign targeting GitHub repositories. The actor's motivation appears to be exfiltration of CI/CD environment data, including secrets, tokens, and credentials stored in GitHub Actions workflows.

GitHub09:55 UTC
ROADtools Framework Misused in Nation-State Cloud Intrusionshighperson_alertThreat Actor
person_alertThreat Actor

ROADtools Framework Misused in Nation-State Cloud Intrusions

Multiple threat actors, including nation-state groups, are misusing the open-source ROADtools framework for cloud intrusions. ROADtools is a legitimate Azure AD reconnaissance toolkit designed for security assessments, but has been co-opted by advers…

Unit 42 (Palo Alto)08:00 UTC
Canadian National Arrested for Operating KimWolf DDoS Botnethighperson_alertThreat Actor
person_alertThreat Actor

Canadian National Arrested for Operating KimWolf DDoS Botnet

A Canadian national arrested by U.S. and Canadian authorities for operating the KimWolf DDoS botnet infrastructure. The operator managed a large-scale botnet that compromised nearly two million devices globally, offering DDoS-for-hire services.

BleepingComputer07:01 UTC
Jacob Butler Arrested for Operating Kimwolf DDoS Botnethighperson_alertThreat Actor
person_alertThreat Actor

Jacob Butler Arrested for Operating Kimwolf DDoS Botnet

Jacob Butler, also known as "Dort," is a 23-year-old Canadian national from Ottawa arrested by the U.S. Department of Justice for developing and operating the Kimwolf DDoS botnet.

The Hacker News06:50 UTC
Dort Arrested for Operating Kimwolf IoT Botnet in Multi-Million Device DDoS Campaignhighperson_alertThreat Actor
person_alertThreat Actor

Dort Arrested for Operating Kimwolf IoT Botnet in Multi-Million Device DDoS Campaign

Dort is a 23-year-old cybercriminal based in Ottawa, Canada, suspected of developing and operating the Kimwolf IoT botnet. Motivated by launching large-scale DDoS attacks, doxing, and swatting campaigns, Dort leveraged compromised IoT devices to buil…

Krebs on Security19:50 UTC
Showboat Linux Malware Targets Middle East Telecom Since Mid-2022highperson_alertThreat Actor
person_alertThreat Actor

Showboat Linux Malware Targets Middle East Telecom Since Mid-2022

The threat actor behind Showboat remains unattributed. The campaign demonstrates sophisticated targeting of telecommunications infrastructure in the Middle East, suggesting a motivated adversary with strategic intelligence collection objectives.

The Hacker News12:17 UTC
Chinese APT Deploys Showboat and JFMBackdoor Against Telecom Sectorhighperson_alertThreat Actor
person_alertThreat Actor

Chinese APT Deploys Showboat and JFMBackdoor Against Telecom Sector

Chinese state-sponsored threat actors conducting cyber-espionage operations against telecommunications infrastructure. The actors demonstrate cross-platform capabilities with custom Linux and Windows malware tooling.

BleepingComputer12:00 UTC
International Law Enforcement Seizes First VPN Service Used by Cybercriminalshighperson_alertThreat Actor
person_alertThreat Actor

International Law Enforcement Seizes First VPN Service Used by Cybercriminals

First VPN was a commercial VPN service exploited by multiple threat actors to anonymize their operations. The service provided infrastructure enabling cybercriminals to mask their origin during ransomware deployments and data exfiltration campaigns.

BleepingComputer11:09 UTC
18-Year-Old Infostealer Operator Arrested for Compromising 28K Accountshighperson_alertThreat Actor
person_alertThreat Actor

18-Year-Old Infostealer Operator Arrested for Compromising 28K Accounts

An 18-year-old individual from Odesa, Ukraine, identified by Ukrainian cyberpolice in coordination with U.S. law enforcement. The operator is suspected of deploying infostealer malware to harvest credentials and compromise user accounts.

BleepingComputer19:36 UTC
Microsoft Disrupts Fox Tempest Malware-Signing-as-a-Service Operationcriticalperson_alertThreat Actor
person_alertThreat Actor

Microsoft Disrupts Fox Tempest Malware-Signing-as-a-Service Operation

Fox Tempest is a threat actor attributed by Microsoft as operating a malware-signing-as-a-service (MSaaS) business model. The actor exploited Microsoft's Artifact Signing system to provide malicious code signing services to other cybercriminals, enab…

Microsoft12:36 UTC
Webworm Deploys EchoCreep and GraphWorm Backdoors via Discord and Graph APIhighperson_alertThreat Actor
person_alertThreat Actor

Webworm Deploys EchoCreep and GraphWorm Backdoors via Discord and Graph API

Webworm is a China-aligned advanced persistent threat (APT) actor first documented by Symantec in September 2022, with activity traced back to at least 2022.

Microsoft10:51 UTC