Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 291 results
Active filter:✕ clear
Kairos extorts $1M from U.S. government via data theft without encryptionhighperson_alertThreat Actor
person_alertThreat Actor

Kairos extorts $1M from U.S. government via data theft without encryption

Kairos is a financially motivated threat actor that employs extortion tactics focused on data theft without deploying traditional ransomware encryption. The group targeted a U.S.

The Hacker News4 Jul · 10:47 UTC
Avalon Modular Malware Framework Delivers CrownX Ransomwarehighperson_alertThreat Actor
person_alertThreat Actor

Avalon Modular Malware Framework Delivers CrownX Ransomware

Avalon is a previously undocumented modular malware framework discovered by cybersecurity researchers. The framework is distributed through multi-stage phishing campaigns and represents a comprehensive attack platform integrating multiple offensive c…

The Hacker News3 Jul · 16:55 UTC
NetNut Residential Proxy Network Disrupted After Compromising 2M Deviceshighperson_alertThreat Actor
person_alertThreat Actor

NetNut Residential Proxy Network Disrupted After Compromising 2M Devices

NetNut operated a residential proxy network that leveraged approximately 2 million compromised Android devices to provide unauthorized proxy services. The actor monetized access to infected devices including smart TVs and streaming boxes, selling res…

Google3 Jul · 15:50 UTC
EvilTokens Affiliate ARToken Exposes M365 Phishing-as-a-Service Platformhighperson_alertThreat Actor
person_alertThreat Actor

EvilTokens Affiliate ARToken Exposes M365 Phishing-as-a-Service Platform

EvilTokens is a threat actor operating a phishing-as-a-service (PhaaS) ecosystem targeting Microsoft 365 credentials. The group utilizes an affiliate model, with ARToken identified as one operational affiliate platform.

Microsoft3 Jul · 12:12 UTC
Armored Likho targets government and energy sectors with BusySnakehighperson_alertThreat Actor
person_alertThreat Actor

Armored Likho targets government and energy sectors with BusySnake

Armored Likho is a previously undocumented threat actor attributed by Kaspersky to cyber attacks targeting government agencies and the electric power sector.

The Hacker News3 Jul · 11:36 UTC
NSO Group's Pegasus Targets EU Parliament Member Investigating Spywarehighperson_alertThreat Actor
person_alertThreat Actor

NSO Group's Pegasus Targets EU Parliament Member Investigating Spyware

NSO Group is an Israeli-based commercial surveillance vendor that develops and sells the Pegasus spyware to government clients. The company markets its tools as lawful intercept solutions for counterterrorism and law enforcement, but has faced repeat…

The Hacker News3 Jul · 09:05 UTC
PamStealer: macOS Info Stealer Masquerades as Maccy Clipboard Managerhighperson_alertThreat Actor
person_alertThreat Actor

PamStealer: macOS Info Stealer Masquerades as Maccy Clipboard Manager

PamStealer is a newly discovered macOS information stealer malware family identified by Jamf Threat Labs. The malware is distributed through social engineering, masquerading as a legitimate Maccy clipboard manager application to deceive users into in…

Apple3 Jul · 06:03 UTC
NetNut (Popa) Residential Proxy Botnet Disrupted by Google, FBIhighperson_alertThreat Actor
person_alertThreat Actor

NetNut (Popa) Residential Proxy Botnet Disrupted by Google, FBI

NetNut, also tracked as Popa, operates a residential proxy network built on approximately 2 million compromised home devices. The actor monetizes this infrastructure by selling proxy services that route malicious traffic through legitimate residentia…

Google2 Jul · 16:54 UTC
Anubis Ransomware Exploits Citrix Bleed 2 (CVE-2025-5777) for Accesshighperson_alertThreat Actor
person_alertThreat Actor

Anubis Ransomware Exploits Citrix Bleed 2 (CVE-2025-5777) for Access

Anubis is a threat actor group operating the Anubis ransomware. The group demonstrates sophisticated tradecraft by exploiting recent vulnerabilities in enterprise infrastructure to gain initial access.

CVE-2025-57772 Jul · 16:30 UTC
ToddyCat Deploys Umbrij Malware to Hijack Gmail via OAuth Abusehighperson_alertThreat Actor
person_alertThreat Actor

ToddyCat Deploys Umbrij Malware to Hijack Gmail via OAuth Abuse

ToddyCat (G1022) is an advanced persistent threat group that has demonstrated sophisticated capabilities in targeting corporate and enterprise environments.

Google2 Jul · 11:04 UTC
JADEPUFFER: First AI-Agent-Orchestrated Ransomware Attackcriticalperson_alertThreat Actor
person_alertThreat Actor

JADEPUFFER: First AI-Agent-Orchestrated Ransomware Attack

JADEPUFFER is a threat actor identified by Sysdig as the operator behind what is claimed to be the first fully AI-agent-orchestrated ransomware attack. The actor leveraged artificial intelligence agents to automate the entire attack lifecycle, repres…

Langflow2 Jul · 07:13 UTC
Scattered Spider Member Extradited to U.S. from Estoniahighperson_alertThreat Actor
person_alertThreat Actor

Scattered Spider Member Extradited to U.S. from Estonia

Scattered Spider (G1015), also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944, is a financially motivated threat actor collective known for sophisticated social engineering and identity-based attacks.

BleepingComputer2 Jul · 06:58 UTC
FortiBleed Campaign Linked to INC and Lynx Ransomware Operationshighperson_alertThreat Actor
person_alertThreat Actor

FortiBleed Campaign Linked to INC and Lynx Ransomware Operations

The FortiBleed campaign is a financially-motivated credential theft operation attributed to actors associated with the INC and Lynx ransomware groups. The campaign focuses on exploiting FortiGate devices to harvest credentials, which are subsequently…

Fortinet2 Jul · 06:00 UTC
ShinyHunters Breaches Medtronic Healthcare Device Manufacturerhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Breaches Medtronic Healthcare Device Manufacturer

ShinyHunters is a financially-motivated cybercrime group known for large-scale data breaches and database exfiltration operations. The group has been active since at least 2020, targeting organizations across multiple sectors to steal sensitive data…

Medtronic2 Jul · 02:25 UTC
INC and Lynx Ransomware Groups Exploit FortiBleed for Credential Thefthighperson_alertThreat Actor
person_alertThreat Actor

INC and Lynx Ransomware Groups Exploit FortiBleed for Credential Theft

INC and Lynx are ransomware threat actors linked to the FortiBleed credential theft campaign. These groups operate with the primary motivation of financial gain through ransomware deployment.

Fortinet1 Jul · 19:37 UTC
Scattered Spider Member Extradited to U.S. on Federal Hacking Chargeshighperson_alertThreat Actor
person_alertThreat Actor

Scattered Spider Member Extradited to U.S. on Federal Hacking Charges

Scattered Spider (also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944) is a financially motivated threat actor group known for sophisticated social engineering and identity-based attacks.

The Hacker News1 Jul · 17:28 UTC
Massive SEO-Poisoned Campaign Distributes AsyncRAT via ScreenConnecthighperson_alertThreat Actor
person_alertThreat Actor

Massive SEO-Poisoned Campaign Distributes AsyncRAT via ScreenConnect

The threat actor behind this campaign remains unattributed. Motivation appears to be financially driven, consistent with commodity RAT deployment for access brokering, credential theft, or follow-on ransomware operations.

OBS Studio1 Jul · 15:53 UTC
VEIL#DROP campaign delivers PureLogs stealer via Blogger pageshighperson_alertThreat Actor
person_alertThreat Actor

VEIL#DROP campaign delivers PureLogs stealer via Blogger pages

VEIL#DROP is a multi-stage malware delivery campaign identified by Securonix researchers. The campaign employs social engineering tactics and abuses legitimate Blogger platform infrastructure to distribute PureLogs, an information-stealing malware.

Google Blogger1 Jul · 15:18 UTC
DeepSeek AI Used to Generate Novel Browser-Based Ransomwarehighperson_alertThreat Actor
person_alertThreat Actor

DeepSeek AI Used to Generate Novel Browser-Based Ransomware

DeepSeek refers to the AI model leveraged by unknown threat actors to generate functional browser-based ransomware code. This marks the first documented instance of a frontier AI model being weaponized to create a novel ransomware technique.

Chromium1 Jul · 10:59 UTC
RustDuck Botnet Targets IoT Devices for DDoS Operationshighperson_alertThreat Actor
person_alertThreat Actor

RustDuck Botnet Targets IoT Devices for DDoS Operations

RustDuck is a two-stage malware family written in Rust, designed to compromise Internet of Things (IoT) devices including home routers, IP cameras, Android set-top boxes, and inadequately secured servers.

Generic routers30 Jun · 15:45 UTC
Silent Swap Campaign Targets Cryptocurrency via Malicious Browser Extensionshighperson_alertThreat Actor
person_alertThreat Actor

Silent Swap Campaign Targets Cryptocurrency via Malicious Browser Extensions

Silent Swap is an active cybercrime campaign leveraging malicious browser extensions to conduct cryptocurrency theft. The operation distributes unsigned installers written in both .NET and Golang variants, masquerading as a legitimate Google Notes br…

Google30 Jun · 13:40 UTC
Pre-Planned Fraud Campaign Targets FIFA World Cup 2026 Across Sectorshighperson_alertThreat Actor
person_alertThreat Actor

Pre-Planned Fraud Campaign Targets FIFA World Cup 2026 Across Sectors

The threat actor behind this campaign remains unattributed. Motivation appears financially driven, leveraging the global interest in FIFA World Cup 2026 to conduct fraud operations.

The Hacker News30 Jun · 09:30 UTC
ShinyHunters Exploits Oracle PeopleSoft Zero-Day in Nissan Breachhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Exploits Oracle PeopleSoft Zero-Day in Nissan Breach

ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has established a pattern of exploiting vulnerabilities in enterprise applications to exfiltrate sensitive data, which is th…

Oracle29 Jun · 18:40 UTC
ShinyHunters Exploits Oracle PeopleSoft Zero-Day at NAIChighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Exploits Oracle PeopleSoft Zero-Day at NAIC

ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has historically targeted organizations to exfiltrate sensitive data, which is then leveraged for extortion or sold on under…

Oracle29 Jun · 18:30 UTC
Malicious Chrome Extension Impersonates Perplexity AI to Intercept Searcheshighperson_alertThreat Actor
person_alertThreat Actor

Malicious Chrome Extension Impersonates Perplexity AI to Intercept Searches

The threat actor behind this campaign remains unattributed. The operation demonstrates a financially or espionage-motivated adversary leveraging social engineering through brand impersonation of Perplexity AI, a popular search technology.

Google29 Jun · 16:40 UTC
U.S. offers $10M reward for intel on UNC5792 and UNC4221 APT groupshighperson_alertThreat Actor
person_alertThreat Actor

U.S. offers $10M reward for intel on UNC5792 and UNC4221 APT groups

UNC5792 and UNC4221 are threat actor groups attributed to Russian intelligence and military services. Both groups have been designated as high-priority targets by the U.S.

BleepingComputer29 Jun · 13:09 UTC
Mustang Panda Targets Indian Government and Hydropower Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

Mustang Panda Targets Indian Government and Hydropower Infrastructure

Mustang Panda (also tracked as TA416, RedDelta, BRONZE PRESIDENT, and STATELY TAURUS) is a China-aligned advanced persistent threat group focused on espionage operations.

Zoho29 Jun · 13:03 UTC
Gamaredon APT Expands Ukraine Operations with 35 Spear-Phishing Campaignshighperson_alertThreat Actor
person_alertThreat Actor

Gamaredon APT Expands Ukraine Operations with 35 Spear-Phishing Campaigns

Gamaredon (also tracked as Armageddon, Shuckworm, Primitive Bear, and UAC-0010) is a Russian state-sponsored APT group attributed by multiple vendors to Russia's Federal Security Service (FSB).

ESET29 Jun · 09:40 UTC
Russian Intelligence Services Target Messaging Accounts via Phishinghighperson_alertThreat Actor
person_alertThreat Actor

Russian Intelligence Services Target Messaging Accounts via Phishing

Russian intelligence services conducted a long-running credential harvesting campaign targeting messaging platforms. The operation, uncovered jointly by Ukraine's Security Service (SSU) and the FBI, focused on stealing authentication credentials from…

The Hacker News27 Jun · 15:27 UTC
Russian Intelligence Services Target Signal Users in Phishing Campaignhighperson_alertThreat Actor
person_alertThreat Actor

Russian Intelligence Services Target Signal Users in Phishing Campaign

Russian intelligence services are conducting a phishing campaign targeting Signal messaging application users. The operation is attributed by the FBI and CISA, indicating state-sponsored activity aimed at compromising secure communications.

Signal26 Jun · 20:06 UTC