Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 258 results
highbug_reportVulnerabilityRedWing Android MaaS enables bank fraud via credential theft
Android devices targeted by RedWing malware, distributed as Malware-as-a-Service on Telegram. Variant of Oblivion MaaS. Primarily affects banking applications and users with compromised devices.
highperson_alertThreat ActorDEBULL Campaign Exploits Microsoft Device Code Flow for M365 Phishing
DEBULL is a phishing campaign active from late June through early July 2026, targeting Microsoft 365 accounts through abuse of Microsoft's legitimate device-code flow authentication mechanism.
highbug_reportVulnerabilityPhishing campaign targets marketing professionals via fake job interviews
Marketing professionals with Google accounts; campaign impersonates 30+ brands including Adobe, Netflix, Coca-Cola, OpenAI. Credential theft targeting Google accounts specifically.
highbug_reportVulnerabilityAttackers impersonate IT support on Teams calls to deploy EtherRAT
Organizations using Microsoft Teams for internal communications. All industries are potential targets. The campaign exploits user trust in voice-based IT support interactions rather than a technical vulnerability in Teams itself.
highperson_alertThreat ActorChina-nexus actor targets Indian finance sector via DcRAT malware
A suspected China-nexus threat actor is conducting Operation DragonReturn, a targeted espionage campaign against Indian taxpayers and finance professionals.
highperson_alertThreat ActorNetNut Residential Proxy Network Disrupted After Compromising 2M Devices
NetNut operated a residential proxy network that leveraged approximately 2 million compromised Android devices to provide unauthorized proxy services. The actor monetized access to infected devices including smart TVs and streaming boxes, selling res…
highperson_alertThreat ActorEvilTokens Affiliate ARToken Exposes M365 Phishing-as-a-Service Platform
EvilTokens is a threat actor operating a phishing-as-a-service (PhaaS) ecosystem targeting Microsoft 365 credentials. The group utilizes an affiliate model, with ARToken identified as one operational affiliate platform.
highperson_alertThreat ActorArmored Likho targets government and energy sectors with BusySnake
Armored Likho is a previously undocumented threat actor attributed by Kaspersky to cyber attacks targeting government agencies and the electric power sector.
highperson_alertThreat ActorPamStealer: macOS Info Stealer Masquerades as Maccy Clipboard Manager
PamStealer is a newly discovered macOS information stealer malware family identified by Jamf Threat Labs. The malware is distributed through social engineering, masquerading as a legitimate Maccy clipboard manager application to deceive users into in…
highperson_alertThreat ActorNetNut (Popa) Residential Proxy Botnet Disrupted by Google, FBI
NetNut, also tracked as Popa, operates a residential proxy network built on approximately 2 million compromised home devices. The actor monetizes this infrastructure by selling proxy services that route malicious traffic through legitimate residentia…
highbug_reportVulnerabilityConsentFix and ClickFix campaigns hijack M365 accounts via OAuth token theft
Microsoft 365 accounts across all organizations using OAuth authentication. Campaigns target users through social engineering to approve malicious OAuth consent prompts, bypassing MFA protections by stealing valid authentication tokens.
highperson_alertThreat ActorFortiBleed Campaign Linked to INC and Lynx Ransomware Operations
The FortiBleed campaign is a financially-motivated credential theft operation attributed to actors associated with the INC and Lynx ransomware groups. The campaign focuses on exploiting FortiGate devices to harvest credentials, which are subsequently…
highbug_reportVulnerabilityFake GitHub PoC repos deliver ChocoPoC trojan to security researchers
Vulnerability researchers and security professionals using GitHub to access proof-of-concept exploit code. The ChocoPoC malware targets Windows systems, stealing credentials, browser data, and files while establishing remote shell access.
highperson_alertThreat ActorINC and Lynx Ransomware Groups Exploit FortiBleed for Credential Theft
INC and Lynx are ransomware threat actors linked to the FortiBleed credential theft campaign. These groups operate with the primary motivation of financial gain through ransomware deployment.
highbug_reportVulnerabilityTrojanized GitHub PoC exploits deliver ChocoPoC RAT to researchers
Cybersecurity researchers and security teams downloading proof-of-concept exploit code from GitHub repositories. ChocoPoC is a Python-based remote access trojan with command execution and data exfiltration capabilities.
highperson_alertThreat ActorMassive SEO-Poisoned Campaign Distributes AsyncRAT via ScreenConnect
The threat actor behind this campaign remains unattributed. Motivation appears to be financially driven, consistent with commodity RAT deployment for access brokering, credential theft, or follow-on ransomware operations.
highperson_alertThreat ActorVEIL#DROP campaign delivers PureLogs stealer via Blogger pages
VEIL#DROP is a multi-stage malware delivery campaign identified by Securonix researchers. The campaign employs social engineering tactics and abuses legitimate Blogger platform infrastructure to distribute PureLogs, an information-stealing malware.
highbug_reportVulnerabilityPassword-spray campaign hits Microsoft 365 with 81M login attempts
Microsoft 365 environments (Exchange Online, Azure AD/Entra ID, SharePoint, Teams). All organizations using M365 cloud services are potential targets. Attack focuses on user authentication endpoints.
highbug_reportVulnerabilityOusaban banking trojan targets Spain and Portugal via phishing
Windows users in Spain and Portugal. Ousaban banking trojan campaign using fake PDF lures with geolocation filtering and steganography techniques. No specific product vulnerability; threat actor campaign identified by Fortinet FortiGuard Labs in May…
highperson_alertThreat ActorRustDuck Botnet Targets IoT Devices for DDoS Operations
RustDuck is a two-stage malware family written in Rust, designed to compromise Internet of Things (IoT) devices including home routers, IP cameras, Android set-top boxes, and inadequately secured servers.
highbug_reportVulnerabilityFake Perplexity AI Chrome extension hijacks search traffic on Web Store
Google Chrome users who installed the malicious Perplexity AI impersonator extension from the Chrome Web Store. Affects organizations and individuals using Chrome browser seeking AI productivity tools.
highperson_alertThreat ActorSilent Swap Campaign Targets Cryptocurrency via Malicious Browser Extensions
Silent Swap is an active cybercrime campaign leveraging malicious browser extensions to conduct cryptocurrency theft. The operation distributes unsigned installers written in both .NET and Golang variants, masquerading as a legitimate Google Notes br…
highperson_alertThreat ActorPre-Planned Fraud Campaign Targets FIFA World Cup 2026 Across Sectors
The threat actor behind this campaign remains unattributed. Motivation appears financially driven, leveraging the global interest in FIFA World Cup 2026 to conduct fraud operations.
highbug_reportVulnerability236K+ malicious sites use DCloud Uni-App templates for crypto scams
Organizations and users interacting with websites built using DCloud Uni-App framework templates. Over 236,000 malicious sites identified conducting cryptocurrency scams, phishing, wallet draining, pig-butchering schemes, and fake gambling platforms.
highbug_reportVulnerabilityMicrosoft removes 119 malicious Edge extensions hiding malware via steganography
Microsoft Edge browser users who installed any of 119 malicious extensions from the official Microsoft Edge Add-ons store. Campaign active since at least 2021, affecting unknown number of users globally.
highperson_alertThreat ActorRussian Intelligence Services Target Messaging Accounts via Phishing
Russian intelligence services conducted a long-running credential harvesting campaign targeting messaging platforms. The operation, uncovered jointly by Ukraine's Security Service (SSU) and the FBI, focused on stealing authentication credentials from…
highperson_alertThreat ActorRussian Intelligence Services Target Signal Users in Phishing Campaign
Russian intelligence services are conducting a phishing campaign targeting Signal messaging application users. The operation is attributed by the FBI and CISA, indicating state-sponsored activity aimed at compromising secure communications.
highbug_reportVulnerabilitySharkLoader malware deploys Cobalt Strike in attacks on Asian governments
Diplomatic and government organizations in Indonesia and Taiwan. SharkLoader is a newly identified malware family used to deliver Cobalt Strike Beacon payloads in the StrikeShark campaign.
highperson_alertThreat ActorUnknown Actors Exploit OpenAI Tenants to Phish Cybersecurity Firms
The threat actors behind this campaign remain unattributed. Their motivation appears to be intelligence gathering and corporate espionage, leveraging the trust associated with OpenAI's platform to deceive employees of cybersecurity companies.
highbug_reportVulnerabilityPhishing campaign targets hotel front desks with Node.js implant
Hotel and hospitality organizations in Europe and Asia. Front-desk systems targeted via photo-themed ZIP file attachments containing Node.js-based malware. Campaign active since April 2026.