Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 390 results
highperson_alertThreat ActorRussian-speaking actor deploys OXLOADER to distribute CastleStealer
The threat actor is a Russian-speaking, financially motivated cybercrime operator leveraging malicious advertising infrastructure for initial access. The actor demonstrates capability in developing or acquiring custom malware tooling, including the p…
highperson_alertThreat ActorAryStinger Malware Infects 4,300+ Routers for Recon Operations
AryStinger is a newly discovered malware family identified by QiAnXin's XLab threat research team. Unlike traditional DDoS botnets, AryStinger is purpose-built for pre-attack reconnaissance and distributed proxy operations.
highbug_reportVulnerabilityAryStinger botnet compromises 4,000+ legacy D-Link routers as proxies
Over 4,000 outdated D-Link routers worldwide, specifically legacy models no longer receiving security updates. Exact models not specified in available data.
highperson_alertThreat ActorPrinz Eugen ransomware targets recently modified files, omits ransom note
Prinz Eugen is a newly identified ransomware family characterized by unconventional operational tactics. Unlike traditional ransomware operations that encrypt files indiscriminately and leave detailed ransom notes, Prinz Eugen employs a selective enc…
highbug_reportVulnerabilityNorth Korean APT compromised 140+ npm packages via Mastra AI framework
Mastra AI framework and over 140 dependent npm packages. Organizations using Mastra AI or downstream dependencies in Node.js/JavaScript applications are affected.
highbug_reportVulnerabilityUnit 42 issues guidance on large-scale credential attack campaigns
Organizations using security vendor devices targeted in recent credential-based attack campaigns. No specific CVE; threat involves coordinated credential compromise attempts across multiple vendors' products.
highperson_alertThreat ActorIcarus Extortion Group Breaches Klue, Steals Salesforce OAuth Tokens
Icarus is an extortion-focused threat actor that has publicly claimed responsibility for breaching the market intelligence platform Klue. The group's motivation appears to be financially driven, targeting SaaS and market intelligence platforms to ste…
highbug_reportVulnerabilityGravity SMTP WordPress plugin under active exploit for info disclosure
Gravity SMTP WordPress plugin, affecting approximately 100,000 websites. Specific vulnerable versions not disclosed in available data.
highperson_alertThreat ActorGentlemen RaaS Deploys GentleKiller EDR Evasion Framework
Gentlemen is a ransomware-as-a-service (RaaS) operation that provides infrastructure, tooling, and support to affiliate threat actors. The group actively develops and distributes specialized frameworks to enhance affiliate success rates, including th…
highpublicGeopoliticalTexas Parks and Wildlife vendor breach exposes 3M+ records
The breach at a Texas state agency vendor underscores persistent vulnerabilities in third-party supply chains supporting U.S. public administration. While no attribution has been disclosed, the exposure of driver's license data and personally identif…
highbug_reportVulnerabilityAutoJack exploit chain enables RCE on AI browsing agents via malicious pages
AI browsing agents (autonomous web browsers with AI capabilities) that interact with privileged local services via JavaScript. Specific products and versions not disclosed in Microsoft's research disclosure.
highperson_alertThreat ActorSocGholish Infrastructure Disrupted in Operation Endgame Takedown
SocGholish is a threat actor known for compromising web infrastructure, particularly WordPress-based content management systems, to facilitate malware distribution and drive-by download attacks.
highperson_alertThreat ActorRussian-speaking actors compromise 86,644 FortiGate devices via FortiBleed
Russian-speaking threat actors are conducting the FortiBleed campaign, targeting internet-accessible FortiGate appliances at scale. The actors' specific motivation remains unclear from available data, though the mass compromise of 86,644 devices sugg…
highbug_reportVulnerabilitySalesforce disables Klue integration after OAuth token abuse exposes data
Salesforce customers using the Klue Battlecards app integration. OAuth tokens were abused to access customer data. Integration disabled as of June 11, 2026.
highbug_reportVulnerabilityF5 patches high-severity flaws in NGINX Open Source and Gateway Fabric
NGINX Open Source and NGINX Gateway Fabric (specific versions not provided). Four CVEs: CVE-2026-11311, CVE-2026-42055, CVE-2026-42530, CVE-2026-50107. Affects organizations running NGINX web servers, reverse proxies, API gateways, and Kubernetes ing…
highpublicGeopoliticalCISA warns of 74,000 Fortinet credentials exposed in FortiBleed leak
The exposure of approximately 74,000 Fortinet firewall and VPN credentials represents a significant supply-side vulnerability affecting critical infrastructure globally.
highbug_reportVulnerabilityApple Beats Studio Buds Bluetooth flaw allows unauthorized pairing
Apple Beats Studio Buds using Airoha Bluetooth audio SDK. Vulnerability affects devices prior to firmware update released by Apple. Attackers must be within Bluetooth range (typically <10 meters).
highperson_alertThreat ActorGentlemen RaaS Develops EDR Killer Tools for Affiliate Operations
Gentlemen is a ransomware-as-a-service (RaaS) operation that provides infrastructure, tools, and support to affiliate threat actors who conduct ransomware attacks.
highperson_alertThreat ActorNetNut Linked to Popa Android Botnet Enabling Proxy Fraud
NetNut is a residential proxy service operated by Alarum Technologies Ltd (NASDAQ: ALAR), a publicly-traded Israeli firm. Multiple security researchers have linked NetNut to the Popa Android botnet, which has compromised millions of consumer TV boxes…
highbug_reportVulnerabilityClipboard-stealing malware spreads via USB, targets crypto wallets
Windows systems with USB connectivity. Targets cryptocurrency wallet users. No specific vendor or product vulnerability; relies on user interaction with malicious Windows shortcut (.lnk) files on removable media.
highbug_reportVulnerabilityWeekly threat roundup: Claude abuse, npm poisoning, phishing campaigns
Multiple platforms and products: Claude AI chat interface, npm package ecosystem (NastyC2), OAuth device-code flows, browser extensions (unspecified), macOS systems, cloud management agents, and internet-exposed edge devices.
highbug_reportVulnerabilityWindows cryptocurrency clipper campaign uses USB worms and Tor C2
Windows systems with Windows Script Host and ActiveX enabled. Campaign active since February 2026 targeting cryptocurrency users via USB-based LNK worm propagation.
highperson_alertThreat ActorIcarus Threat Actor Exploits OAuth to Steal Salesforce Data via Klue
Icarus is a threat actor conducting an ongoing extortion campaign targeting organizations through supply chain compromise. The actor exploited OAuth authentication mechanisms to breach Klue, a market intelligence platform, gaining unauthorized access…
highperson_alertThreat ActorINC Ransomware Expands Operations Following LockBit and BlackCat Disruptions
INC is a ransomware-as-a-service (RaaS) operation that has emerged as a major threat actor since August 2023. The group operates a multi-affiliate model, providing ransomware tooling and infrastructure to criminal partners in exchange for a share of…
highperson_alertThreat ActorDragonForce Deploys Backdoor.Turn RAT via Microsoft Teams Infrastructure
DragonForce is a threat actor associated with ransomware operations. The group has demonstrated advanced capabilities in developing custom tooling and leveraging legitimate cloud infrastructure for command-and-control communications.
highperson_alertThreat ActorEvil Corp SocGholish botnet dismantled: 15,000 sites, 100+ servers
Evil Corp (also tracked as Indrik Spider, Manatee Tempest, DEV-0243, UNC2165) is a financially motivated cybercrime group linked to Russia. The group has operated since at least 2014 and is known for deploying banking trojans and ransomware variants…
highbug_reportVulnerabilityShapedPlugin WordPress plugins compromised in supply chain attack
Multiple WordPress plugins from ShapedPlugin vendor. Infected releases distributed to paying customers via official update mechanism. Specific plugin names and version numbers not disclosed in provided data.
highbug_reportVulnerabilityApple patches Bluetooth eavesdropping flaw in Beats Studio Buds
Apple Beats Studio Buds wireless earbuds. Specific firmware versions not disclosed. Vulnerability requires attacker to be within Bluetooth range (typically 10-30 meters).
highbug_reportVulnerabilityNCSC warns of active global campaign targeting Fortinet firewalls and VPNs
Fortinet firewalls and VPN gateways globally. Specific product lines and versions not disclosed in alert. Organizations using FortiGate, FortiOS, or FortiClient VPN services should assume potential exposure.
highbug_reportVulnerabilityPoisoned npm package compromises 140+ projects via postinstall payload
140+ projects using a malicious npm package containing a hidden postinstall script. Affects Node.js/JavaScript development environments consuming npm dependencies. Specific package name not disclosed in summary.