Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-21 · 02:09 UTC
articleTotal: 606 reports

Filtered Reports

30 / 390 results
Active filter:tag: #high✕ clear
Russian-speaking actor deploys OXLOADER to distribute CastleStealerhighperson_alertThreat Actor
person_alertThreat Actor

Russian-speaking actor deploys OXLOADER to distribute CastleStealer

The threat actor is a Russian-speaking, financially motivated cybercrime operator leveraging malicious advertising infrastructure for initial access. The actor demonstrates capability in developing or acquiring custom malware tooling, including the p…

Google11:20 UTC
AryStinger Malware Infects 4,300+ Routers for Recon Operationshighperson_alertThreat Actor
person_alertThreat Actor

AryStinger Malware Infects 4,300+ Routers for Recon Operations

AryStinger is a newly discovered malware family identified by QiAnXin's XLab threat research team. Unlike traditional DDoS botnets, AryStinger is purpose-built for pre-attack reconnaissance and distributed proxy operations.

Legacy Router Manufacturers04:57 UTC
AryStinger botnet compromises 4,000+ legacy D-Link routers as proxieshighbug_reportVulnerability
bug_reportVulnerability

AryStinger botnet compromises 4,000+ legacy D-Link routers as proxies

Over 4,000 outdated D-Link routers worldwide, specifically legacy models no longer receiving security updates. Exact models not specified in available data.

D-Link12:14 UTC
Prinz Eugen ransomware targets recently modified files, omits ransom notehighperson_alertThreat Actor
person_alertThreat Actor

Prinz Eugen ransomware targets recently modified files, omits ransom note

Prinz Eugen is a newly identified ransomware family characterized by unconventional operational tactics. Unlike traditional ransomware operations that encrypt files indiscriminately and leave detailed ransom notes, Prinz Eugen employs a selective enc…

BleepingComputer13:23 UTC
North Korean APT compromised 140+ npm packages via Mastra AI frameworkhighbug_reportVulnerability
bug_reportVulnerability

North Korean APT compromised 140+ npm packages via Mastra AI framework

Mastra AI framework and over 140 dependent npm packages. Organizations using Mastra AI or downstream dependencies in Node.js/JavaScript applications are affected.

Mastra AI12:09 UTC
Unit 42 issues guidance on large-scale credential attack campaignshighbug_reportVulnerability
bug_reportVulnerability

Unit 42 issues guidance on large-scale credential attack campaigns

Organizations using security vendor devices targeted in recent credential-based attack campaigns. No specific CVE; threat involves coordinated credential compromise attempts across multiple vendors' products.

Unit 42 (Palo Alto)00:05 UTC
Icarus Extortion Group Breaches Klue, Steals Salesforce OAuth Tokenshighperson_alertThreat Actor
person_alertThreat Actor

Icarus Extortion Group Breaches Klue, Steals Salesforce OAuth Tokens

Icarus is an extortion-focused threat actor that has publicly claimed responsibility for breaching the market intelligence platform Klue. The group's motivation appears to be financially driven, targeting SaaS and market intelligence platforms to ste…

Klue20:31 UTC
Gravity SMTP WordPress plugin under active exploit for info disclosurehighbug_reportVulnerability
bug_reportVulnerability

Gravity SMTP WordPress plugin under active exploit for info disclosure

Gravity SMTP WordPress plugin, affecting approximately 100,000 websites. Specific vulnerable versions not disclosed in available data.

Gravity SMTP18:25 UTC
Gentlemen RaaS Deploys GentleKiller EDR Evasion Frameworkhighperson_alertThreat Actor
person_alertThreat Actor

Gentlemen RaaS Deploys GentleKiller EDR Evasion Framework

Gentlemen is a ransomware-as-a-service (RaaS) operation that provides infrastructure, tooling, and support to affiliate threat actors. The group actively develops and distributes specialized frameworks to enhance affiliate success rates, including th…

The Hacker News16:33 UTC
Texas Parks and Wildlife vendor breach exposes 3M+ recordshighpublicGeopolitical
publicGeopolitical

Texas Parks and Wildlife vendor breach exposes 3M+ records

The breach at a Texas state agency vendor underscores persistent vulnerabilities in third-party supply chains supporting U.S. public administration. While no attribution has been disclosed, the exposure of driver's license data and personally identif…

BleepingComputer14:12 UTC
AutoJack exploit chain enables RCE on AI browsing agents via malicious pageshighbug_reportVulnerability
bug_reportVulnerability

AutoJack exploit chain enables RCE on AI browsing agents via malicious pages

AI browsing agents (autonomous web browsers with AI capabilities) that interact with privileged local services via JavaScript. Specific products and versions not disclosed in Microsoft's research disclosure.

Microsoft13:30 UTC
SocGholish Infrastructure Disrupted in Operation Endgame Takedownhighperson_alertThreat Actor
person_alertThreat Actor

SocGholish Infrastructure Disrupted in Operation Endgame Takedown

SocGholish is a threat actor known for compromising web infrastructure, particularly WordPress-based content management systems, to facilitate malware distribution and drive-by download attacks.

WordPress13:07 UTC
Russian-speaking actors compromise 86,644 FortiGate devices via FortiBleedhighperson_alertThreat Actor
person_alertThreat Actor

Russian-speaking actors compromise 86,644 FortiGate devices via FortiBleed

Russian-speaking threat actors are conducting the FortiBleed campaign, targeting internet-accessible FortiGate appliances at scale. The actors' specific motivation remains unclear from available data, though the mass compromise of 86,644 devices sugg…

Fortinet12:00 UTC
Salesforce disables Klue integration after OAuth token abuse exposes datahighbug_reportVulnerability
bug_reportVulnerability

Salesforce disables Klue integration after OAuth token abuse exposes data

Salesforce customers using the Klue Battlecards app integration. OAuth tokens were abused to access customer data. Integration disabled as of June 11, 2026.

Salesforce07:03 UTC
F5 patches high-severity flaws in NGINX Open Source and Gateway Fabrichighbug_reportVulnerability
bug_reportVulnerability

F5 patches high-severity flaws in NGINX Open Source and Gateway Fabric

NGINX Open Source and NGINX Gateway Fabric (specific versions not provided). Four CVEs: CVE-2026-11311, CVE-2026-42055, CVE-2026-42530, CVE-2026-50107. Affects organizations running NGINX web servers, reverse proxies, API gateways, and Kubernetes ing…

CVE-2026-1131106:24 UTC
CISA warns of 74,000 Fortinet credentials exposed in FortiBleed leakhighpublicGeopolitical
publicGeopolitical

CISA warns of 74,000 Fortinet credentials exposed in FortiBleed leak

The exposure of approximately 74,000 Fortinet firewall and VPN credentials represents a significant supply-side vulnerability affecting critical infrastructure globally.

Fortinet04:47 UTC
Apple Beats Studio Buds Bluetooth flaw allows unauthorized pairinghighbug_reportVulnerability
bug_reportVulnerability

Apple Beats Studio Buds Bluetooth flaw allows unauthorized pairing

Apple Beats Studio Buds using Airoha Bluetooth audio SDK. Vulnerability affects devices prior to firmware update released by Apple. Attackers must be within Bluetooth range (typically <10 meters).

CVE-2025-2070104:36 UTC
Gentlemen RaaS Develops EDR Killer Tools for Affiliate Operationshighperson_alertThreat Actor
person_alertThreat Actor

Gentlemen RaaS Develops EDR Killer Tools for Affiliate Operations

Gentlemen is a ransomware-as-a-service (RaaS) operation that provides infrastructure, tools, and support to affiliate threat actors who conduct ransomware attacks.

BleepingComputer20:31 UTC
NetNut Linked to Popa Android Botnet Enabling Proxy Fraudhighperson_alertThreat Actor
person_alertThreat Actor

NetNut Linked to Popa Android Botnet Enabling Proxy Fraud

NetNut is a residential proxy service operated by Alarum Technologies Ltd (NASDAQ: ALAR), a publicly-traded Israeli firm. Multiple security researchers have linked NetNut to the Popa Android botnet, which has compromised millions of consumer TV boxes…

Alarum Technologies Ltd15:37 UTC
Clipboard-stealing malware spreads via USB, targets crypto walletshighbug_reportVulnerability
bug_reportVulnerability

Clipboard-stealing malware spreads via USB, targets crypto wallets

Windows systems with USB connectivity. Targets cryptocurrency wallet users. No specific vendor or product vulnerability; relies on user interaction with malicious Windows shortcut (.lnk) files on removable media.

BleepingComputer14:20 UTC
Weekly threat roundup: Claude abuse, npm poisoning, phishing campaignshighbug_reportVulnerability
bug_reportVulnerability

Weekly threat roundup: Claude abuse, npm poisoning, phishing campaigns

Multiple platforms and products: Claude AI chat interface, npm package ecosystem (NastyC2), OAuth device-code flows, browser extensions (unspecified), macOS systems, cloud management agents, and internet-exposed edge devices.

Claude13:27 UTC
Windows cryptocurrency clipper campaign uses USB worms and Tor C2highbug_reportVulnerability
bug_reportVulnerability

Windows cryptocurrency clipper campaign uses USB worms and Tor C2

Windows systems with Windows Script Host and ActiveX enabled. Campaign active since February 2026 targeting cryptocurrency users via USB-based LNK worm propagation.

Microsoft12:30 UTC
Icarus Threat Actor Exploits OAuth to Steal Salesforce Data via Kluehighperson_alertThreat Actor
person_alertThreat Actor

Icarus Threat Actor Exploits OAuth to Steal Salesforce Data via Klue

Icarus is a threat actor conducting an ongoing extortion campaign targeting organizations through supply chain compromise. The actor exploited OAuth authentication mechanisms to breach Klue, a market intelligence platform, gaining unauthorized access…

Klue12:19 UTC
INC Ransomware Expands Operations Following LockBit and BlackCat Disruptionshighperson_alertThreat Actor
person_alertThreat Actor

INC Ransomware Expands Operations Following LockBit and BlackCat Disruptions

INC is a ransomware-as-a-service (RaaS) operation that has emerged as a major threat actor since August 2023. The group operates a multi-affiliate model, providing ransomware tooling and infrastructure to criminal partners in exchange for a share of…

The Hacker News12:12 UTC
DragonForce Deploys Backdoor.Turn RAT via Microsoft Teams Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

DragonForce Deploys Backdoor.Turn RAT via Microsoft Teams Infrastructure

DragonForce is a threat actor associated with ransomware operations. The group has demonstrated advanced capabilities in developing custom tooling and leveraging legitimate cloud infrastructure for command-and-control communications.

Microsoft11:30 UTC
Evil Corp SocGholish botnet dismantled: 15,000 sites, 100+ servershighperson_alertThreat Actor
person_alertThreat Actor

Evil Corp SocGholish botnet dismantled: 15,000 sites, 100+ servers

Evil Corp (also tracked as Indrik Spider, Manatee Tempest, DEV-0243, UNC2165) is a financially motivated cybercrime group linked to Russia. The group has operated since at least 2014 and is known for deploying banking trojans and ransomware variants…

WordPress11:25 UTC
ShapedPlugin WordPress plugins compromised in supply chain attackhighbug_reportVulnerability
bug_reportVulnerability

ShapedPlugin WordPress plugins compromised in supply chain attack

Multiple WordPress plugins from ShapedPlugin vendor. Infected releases distributed to paying customers via official update mechanism. Specific plugin names and version numbers not disclosed in provided data.

ShapedPlugin10:55 UTC
Apple patches Bluetooth eavesdropping flaw in Beats Studio Budshighbug_reportVulnerability
bug_reportVulnerability

Apple patches Bluetooth eavesdropping flaw in Beats Studio Buds

Apple Beats Studio Buds wireless earbuds. Specific firmware versions not disclosed. Vulnerability requires attacker to be within Bluetooth range (typically 10-30 meters).

Apple10:23 UTC
NCSC warns of active global campaign targeting Fortinet firewalls and VPNshighbug_reportVulnerability
bug_reportVulnerability

NCSC warns of active global campaign targeting Fortinet firewalls and VPNs

Fortinet firewalls and VPN gateways globally. Specific product lines and versions not disclosed in alert. Organizations using FortiGate, FortiOS, or FortiClient VPN services should assume potential exposure.

Fortinet10:00 UTC
Poisoned npm package compromises 140+ projects via postinstall payloadhighbug_reportVulnerability
bug_reportVulnerability

Poisoned npm package compromises 140+ projects via postinstall payload

140+ projects using a malicious npm package containing a hidden postinstall script. Affects Node.js/JavaScript development environments consuming npm dependencies. Specific package name not disclosed in summary.

npm01:43 UTC