Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 356 results
Active filter:tag: #threat-actor✕ clear
FakeGit Campaign Distributes Malware via 7,600 Malicious GitHub Reposhighperson_alertThreat Actor
person_alertThreat Actor

FakeGit Campaign Distributes Malware via 7,600 Malicious GitHub Repos

FakeGit is a threat actor conducting a large-scale supply chain attack campaign targeting the software development community. The actor's motivation centers on mass malware distribution through the compromise of developer trust in the GitHub platform…

GitHub21 Jul · 20:34 UTC
Anubis Ransomware Gang Targets Coca-Cola's Fairlife Subsidiaryhighperson_alertThreat Actor
person_alertThreat Actor

Anubis Ransomware Gang Targets Coca-Cola's Fairlife Subsidiary

Anubis is a ransomware threat actor employing double extortion tactics, claiming responsibility for attacks against the food and beverage sector. The group operates by encrypting victim systems and exfiltrating sensitive corporate data, threatening p…

Coca-Cola21 Jul · 16:50 UTC
Qilin Ransomware Exploits CVE-2026-0257 PAN-OS Flaw for Initial Accesshighperson_alertThreat Actor
person_alertThreat Actor

Qilin Ransomware Exploits CVE-2026-0257 PAN-OS Flaw for Initial Access

Qilin is a ransomware-as-a-service (RaaS) operation that has been active in the cybercrime ecosystem, deploying file-encrypting malware against organizations for financial gain.

CVE-2026-025721 Jul · 12:04 UTC
Qilin Ransomware Gang Exploits PAN-OS GlobalProtect Vulnerabilitycriticalperson_alertThreat Actor
person_alertThreat Actor

Qilin Ransomware Gang Exploits PAN-OS GlobalProtect Vulnerability

Qilin is a ransomware-as-a-service (RaaS) operation that has emerged as a notable threat actor in the cybercrime ecosystem. The group operates a double-extortion model, encrypting victim data while exfiltrating sensitive information for leverage in r…

Palo Alto Networks21 Jul · 08:12 UTC
JadePuffer Deploys EncForge Ransomware Targeting AI Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

JadePuffer Deploys EncForge Ransomware Targeting AI Infrastructure

JadePuffer is characterized as an autonomous AI agent that has been enhanced with offensive capabilities. The actor's motivation centers on targeting artificial intelligence infrastructure, specifically focusing on high-value AI assets such as traini…

BleepingComputer20 Jul · 19:08 UTC
FakeGit Campaign Distributes SmartLoader via 7,600+ Malicious GitHub Reposhighperson_alertThreat Actor
person_alertThreat Actor

FakeGit Campaign Distributes SmartLoader via 7,600+ Malicious GitHub Repos

FakeGit is a campaign (not a named threat actor group) targeting software developers through a large-scale supply chain attack leveraging GitHub's trusted platform.

GitHub20 Jul · 16:23 UTC
HollowGraph Malware Uses Microsoft 365 Calendars for Covert C2highperson_alertThreat Actor
person_alertThreat Actor

HollowGraph Malware Uses Microsoft 365 Calendars for Covert C2

HollowGraph is a newly discovered espionage implant that leverages Microsoft 365 calendar infrastructure for command and control operations. The malware was identified and analyzed by Group-IB.

Microsoft20 Jul · 12:33 UTC
Russian Intelligence Services Exploit Security Cameras for Military Surveillancehighperson_alertThreat Actor
person_alertThreat Actor

Russian Intelligence Services Exploit Security Cameras for Military Surveillance

Russian intelligence services are conducting a systematic cyber-espionage campaign targeting internet-connected security cameras across Europe and Ukraine.

The Hacker News20 Jul · 10:13 UTC
bandcampro leverages Google Gemini CLI to control dental clinic botnethighperson_alertThreat Actor
person_alertThreat Actor

bandcampro leverages Google Gemini CLI to control dental clinic botnet

bandcampro is a Russian-speaking threat actor that has demonstrated novel tradecraft by weaponizing Google's Gemini CLI tool to orchestrate botnet operations.

The Hacker News20 Jul · 07:07 UTC
Autonomous AI Agent Breaches Hugging Face Repositoryhighperson_alertThreat Actor
person_alertThreat Actor

Autonomous AI Agent Breaches Hugging Face Repository

The threat actor is identified as an autonomous AI agent system—a novel adversary class representing machine-driven attack capabilities operating with minimal or no human intervention.

Hugging Face20 Jul · 03:27 UTC
Malicious RubyGems packages deliver payloads to developer workstationshighbug_reportVulnerability
bug_reportVulnerability

Malicious RubyGems packages deliver payloads to developer workstations

RubyGems ecosystem: three malicious packages (git_credential_manager, Dendreo, and one unnamed) published to the official RubyGems repository. Affects Ruby developers who installed these packages.

RubyGems20 Jul · 03:15 UTC
UAC-0145 (Sandworm sub-cluster) deploys ClickFix lures vs Ukrainehighperson_alertThreat Actor
person_alertThreat Actor

UAC-0145 (Sandworm sub-cluster) deploys ClickFix lures vs Ukraine

UAC-0145 is a sub-cluster of Sandworm, a Russian state-sponsored APT group attributed to the GRU (Main Intelligence Directorate of the General Staff of the Armed Forces of the Russian Federation).

The Hacker News19 Jul · 11:30 UTC
SonicWall SMA 1000 VPN zero-days exploited by UTA0533 for root accesscriticalbug_reportVulnerability
bug_reportVulnerability

SonicWall SMA 1000 VPN zero-days exploited by UTA0533 for root access

SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. Specific vulnerable versions not disclosed. All SMA 1000 deployments should be considered at risk until vendor guidance is available.

SonicWall19 Jul · 11:18 UTC
OpenSSL "HollowByte" DoS allows 11-byte requests to freeze server memoryhighbug_reportVulnerability
bug_reportVulnerability

OpenSSL "HollowByte" DoS allows 11-byte requests to freeze server memory

OpenSSL versions prior to June 2024 patch. Affects TLS servers running on glibc-based Linux systems. Specific vulnerable versions not disclosed; patch applied without CVE or public advisory.

OpenSSL17 Jul · 18:20 UTC
Seven malicious npm packages target Vite ecosystem with blockchain C2 RAThighbug_reportVulnerability
bug_reportVulnerability

Seven malicious npm packages target Vite ecosystem with blockchain C2 RAT

npm package ecosystem, specifically projects using Vite frontend tooling. Seven malicious packages identified in the ViteVenom campaign. Any JavaScript/Node.js development environments that installed these packages are compromised.

npm17 Jul · 16:54 UTC
NadMesh Botnet Targets AI Services for AWS and Kubernetes Credential Thefthighperson_alertThreat Actor
person_alertThreat Actor

NadMesh Botnet Targets AI Services for AWS and Kubernetes Credential Theft

NadMesh is a Go-based botnet operation discovered in early July that specializes in compromising cloud infrastructure credentials through exploitation of exposed AI and automation services.

AWS17 Jul · 15:12 UTC
DigiCert breach linked to Chinese APT; code-signing certs stolencriticalbug_reportVulnerability
bug_reportVulnerability

DigiCert breach linked to Chinese APT; code-signing certs stolen

DigiCert certificate authority infrastructure compromised in April 2026. Code-signing certificates stolen by CylindricalCanine (GoldenEyeDog/APT-Q-27 subgroup).

DigiCert17 Jul · 14:39 UTC
Lazarus Deploys OtterCookie via Fake Job Lures in Contagious Interviewhighperson_alertThreat Actor
person_alertThreat Actor

Lazarus Deploys OtterCookie via Fake Job Lures in Contagious Interview

Lazarus is a North Korean state-sponsored advanced persistent threat (APT) group attributed to the Reconnaissance General Bureau (RGB). The group is financially motivated, conducting operations to generate revenue for the DPRK regime through cryptocu…

The Hacker News17 Jul · 11:48 UTC
Windows zero-day LegacyHive enables privilege escalation on patched systemscriticalbug_reportVulnerability
bug_reportVulnerability

Windows zero-day LegacyHive enables privilege escalation on patched systems

All up-to-date Windows systems. Specific affected versions not disclosed. Exploit enables local privilege escalation from standard user to administrator level. No CVE assigned yet.

Microsoft17 Jul · 09:05 UTC
Armenia Detains Russian National on U.S. REvil Ransomware Warranthighperson_alertThreat Actor
person_alertThreat Actor

Armenia Detains Russian National on U.S. REvil Ransomware Warrant

REvil (also known as Sodinokibi) is a Russia-linked ransomware-as-a-service (RaaS) operation that emerged in 2019 and became one of the most prolific cybercrime groups before law enforcement disruption in 2021-2022.

The Hacker News17 Jul · 08:53 UTC
GoSerpent Malware Targets Southeast Asian Government and Diplomacyhighperson_alertThreat Actor
person_alertThreat Actor

GoSerpent Malware Targets Southeast Asian Government and Diplomacy

GoSerpent is a previously undocumented malware family discovered by Kaspersky researchers in late 2025. The malware is designed for long-term persistent access and intelligence gathering operations.

Kaspersky17 Jul · 06:46 UTC
China-Linked Cluster Exploits Roundcube at Universitieshighperson_alertThreat Actor
person_alertThreat Actor

China-Linked Cluster Exploits Roundcube at Universities

This China-linked threat cluster targets academic institutions in North America, focusing on credential theft and persistent access through exploitation of vulnerable Roundcube webmail servers.

Roundcube8 Jul · 16:56 UTC
Vishing Campaign Targets Microsoft 365 Users with Entra Passkey Scamhighperson_alertThreat Actor
person_alertThreat Actor

Vishing Campaign Targets Microsoft 365 Users with Entra Passkey Scam

The threat actor behind this campaign remains unattributed. The operation demonstrates sophistication in social engineering tactics, specifically targeting Microsoft 365 environments through voice-based phishing (vishing).

Microsoft8 Jul · 14:47 UTC
EvilTokens Ghost Phishing Campaign Targets US and European Businesseshighperson_alertThreat Actor
person_alertThreat Actor

EvilTokens Ghost Phishing Campaign Targets US and European Businesses

EvilTokens is a campaign leveraging "ghost phishing" techniques to target business entities across the United States and Europe. The campaign's primary motivation appears to be credential theft and unauthorized access to Microsoft 365 environments, w…

Microsoft8 Jul · 11:00 UTC
REF6045 targets Mexican banking sector with SCMBANKER via ClickFix lureshighperson_alertThreat Actor
person_alertThreat Actor

REF6045 targets Mexican banking sector with SCMBANKER via ClickFix lures

REF6045 is a financially motivated threat actor conducting banking fraud operations against Mexican financial institutions and their customers. The actor targets banking, fintech, and cryptocurrency exchange users in Mexico, leveraging social enginee…

The Hacker News8 Jul · 10:52 UTC
UAT-7810 Expands ORB Network with LONGLEASH Malware on Edge Deviceshighperson_alertThreat Actor
person_alertThreat Actor

UAT-7810 Expands ORB Network with LONGLEASH Malware on Edge Devices

UAT-7810 is a China-linked advanced persistent threat (APT) actor focused on compromising internet-facing networking and infrastructure devices to build and maintain an Operational Relay Box (ORB) network designated LapDogs.

The Hacker News8 Jul · 07:04 UTC
UAT-7810 Deploys LONGLEASH Malware Against Network Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

UAT-7810 Deploys LONGLEASH Malware Against Network Infrastructure

UAT-7810 is a Chinese-linked threat actor focused on compromising internet-facing networking devices to expand their Operational Relay Box (ORB) network infrastructure.

Ruckus7 Jul · 16:52 UTC
DEBULL Campaign Exploits Microsoft Device Code Flow for M365 Phishinghighperson_alertThreat Actor
person_alertThreat Actor

DEBULL Campaign Exploits Microsoft Device Code Flow for M365 Phishing

DEBULL is a phishing campaign active from late June through early July 2026, targeting Microsoft 365 accounts through abuse of Microsoft's legitimate device-code flow authentication mechanism.

Microsoft7 Jul · 13:14 UTC
Scattered Spider Linked to U.S. Luxury Retail Breach via Device IDhighperson_alertThreat Actor
person_alertThreat Actor

Scattered Spider Linked to U.S. Luxury Retail Breach via Device ID

Scattered Spider (also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944) is a financially motivated threat actor known for sophisticated social engineering and identity-focused attacks.

The Hacker News7 Jul · 11:27 UTC
China-Aligned Cluster Exploits Roundcube Flaws at Universitieshighperson_alertThreat Actor
person_alertThreat Actor

China-Aligned Cluster Exploits Roundcube Flaws at Universities

This activity cluster is attributed to China-aligned threat actors targeting academic institutions in North America. The group demonstrates a clear strategic interest in research and development sectors, specifically physics and engineering departmen…

CVE-2024-420097 Jul · 07:10 UTC