Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 567 results
highperson_alertThreat ActorHollowGraph Malware Uses Microsoft 365 Calendars for Covert C2
HollowGraph is a newly discovered espionage implant that leverages Microsoft 365 calendar infrastructure for command and control operations. The malware was identified and analyzed by Group-IB.
highperson_alertThreat ActorRussian Intelligence Services Exploit Security Cameras for Military Surveillance
Russian intelligence services are conducting a systematic cyber-espionage campaign targeting internet-connected security cameras across Europe and Ukraine.
highbug_reportVulnerability7-Zip heap overflow in XZ handling allows code execution via crafted archives
7-Zip versions prior to 26.02. Affects all platforms where 7-Zip is deployed (Windows, Linux). Vulnerability triggered when opening malicious XZ archives.
highperson_alertThreat Actorbandcampro leverages Google Gemini CLI to control dental clinic botnet
bandcampro is a Russian-speaking threat actor that has demonstrated novel tradecraft by weaponizing Google's Gemini CLI tool to orchestrate botnet operations.
highperson_alertThreat ActorAutonomous AI Agent Breaches Hugging Face Repository
The threat actor is identified as an autonomous AI agent system—a novel adversary class representing machine-driven attack capabilities operating with minimal or no human intervention.
highbug_reportVulnerabilityMalicious RubyGems packages deliver payloads to developer workstations
RubyGems ecosystem: three malicious packages (git_credential_manager, Dendreo, and one unnamed) published to the official RubyGems repository. Affects Ruby developers who installed these packages.
highbug_reportVulnerabilityViPNet update mechanism compromised to target Russian government agencies
ViPNet private networking software users, primarily Russian government agencies and organizations. All versions using the compromised update delivery mechanism are potentially affected. Specific version range not disclosed.
highperson_alertThreat ActorUAC-0145 (Sandworm sub-cluster) deploys ClickFix lures vs Ukraine
UAC-0145 is a sub-cluster of Sandworm, a Russian state-sponsored APT group attributed to the GRU (Main Intelligence Directorate of the General Staff of the Armed Forces of the Russian Federation).
highbug_reportVulnerability7-Zip 26.02 patches RCE flaw via malicious compressed files
7-Zip versions prior to 26.02. All platforms (Windows, Linux, macOS) where 7-Zip is installed and users handle compressed archives from untrusted sources.
highbug_reportVulnerabilityACR Stealer campaign targets Microsoft enterprise customers
Microsoft enterprise customers; targets browser-stored credentials, authentication tokens, and sensitive documents across enterprise environments
highbug_reportVulnerabilityOpenSSL "HollowByte" DoS allows 11-byte requests to freeze server memory
OpenSSL versions prior to June 2024 patch. Affects TLS servers running on glibc-based Linux systems. Specific vulnerable versions not disclosed; patch applied without CVE or public advisory.
highbug_reportVulnerabilitySeven malicious npm packages target Vite ecosystem with blockchain C2 RAT
npm package ecosystem, specifically projects using Vite frontend tooling. Seven malicious packages identified in the ViteVenom campaign. Any JavaScript/Node.js development environments that installed these packages are compromised.
highbug_reportVulnerabilityHollowByte flaw enables DoS on OpenSSL servers via 11-byte payload
OpenSSL servers (specific versions not disclosed). Unauthenticated remote attackers can exploit the vulnerability. Scope includes any internet-facing OpenSSL server implementations susceptible to the malicious payload.
highperson_alertThreat ActorNadMesh Botnet Targets AI Services for AWS and Kubernetes Credential Theft
NadMesh is a Go-based botnet operation discovered in early July that specializes in compromising cloud infrastructure credentials through exploitation of exposed AI and automation services.
highbug_reportVulnerabilitySpring Authorization Server authentication bypass requires immediate patch
Spring Authorization Server (part of Spring Security framework by VMware/Pivotal). Specific affected versions not disclosed in available information. Authentication mechanism is impacted.
highperson_alertThreat ActorLazarus Deploys OtterCookie via Fake Job Lures in Contagious Interview
Lazarus is a North Korean state-sponsored advanced persistent threat (APT) group attributed to the Reconnaissance General Bureau (RGB). The group is financially motivated, conducting operations to generate revenue for the DPRK regime through cryptocu…
highperson_alertThreat ActorArmenia Detains Russian National on U.S. REvil Ransomware Warrant
REvil (also known as Sodinokibi) is a Russia-linked ransomware-as-a-service (RaaS) operation that emerged in 2019 and became one of the most prolific cybercrime groups before law enforcement disruption in 2021-2022.
highbug_reportVulnerabilityACR Stealer campaign uses ClickFix social engineering to steal M365 data
Microsoft 365 enterprise users and organizations. ACR Stealer targets browser credentials, session tokens, and M365 documents. Active since 2024 with two documented delivery chains using ClickFix social engineering lures.
highperson_alertThreat ActorGoSerpent Malware Targets Southeast Asian Government and Diplomacy
GoSerpent is a previously undocumented malware family discovered by Kaspersky researchers in late 2025. The malware is designed for long-term persistent access and intelligence gathering operations.
highbug_reportVulnerabilityCERT.BE warns of multiple high-severity NGINX vulnerabilities
NGINX components (specific versions not disclosed in available information). Affects web servers, reverse proxies, and load balancers running vulnerable NGINX installations.
highpublicGeopoliticalMount Royal University in Calgary confirms data breach and deletion
The breach of Mount Royal University represents a typical pattern in the current cyber threat landscape affecting higher education institutions across North America.
highbug_reportVulnerabilityMalicious npm and PyPI packages impersonate Paysafe payment SDKs
Developers using npm and PyPI repositories who may have installed counterfeit packages impersonating Paysafe, Skrill, and Neteller payment SDKs. Affects development environments and potentially downstream applications integrating these malicious pack…
highperson_alertThreat ActorChina-Linked Cluster Exploits Roundcube at Universities
This China-linked threat cluster targets academic institutions in North America, focusing on credential theft and persistent access through exploitation of vulnerable Roundcube webmail servers.
highperson_alertThreat ActorVishing Campaign Targets Microsoft 365 Users with Entra Passkey Scam
The threat actor behind this campaign remains unattributed. The operation demonstrates sophistication in social engineering tactics, specifically targeting Microsoft 365 environments through voice-based phishing (vishing).
highbug_reportVulnerabilityHalluSquatting attack exploits AI coding assistants to distribute malware
AI coding assistants (GitHub Copilot, ChatGPT, Claude, etc.) and developers using AI-generated package recommendations. All package ecosystems (npm, PyPI, Maven, etc.) are potential targets.
highperson_alertThreat ActorEvilTokens Ghost Phishing Campaign Targets US and European Businesses
EvilTokens is a campaign leveraging "ghost phishing" techniques to target business entities across the United States and Europe. The campaign's primary motivation appears to be credential theft and unauthorized access to Microsoft 365 environments, w…
highperson_alertThreat ActorREF6045 targets Mexican banking sector with SCMBANKER via ClickFix lures
REF6045 is a financially motivated threat actor conducting banking fraud operations against Mexican financial institutions and their customers. The actor targets banking, fintech, and cryptocurrency exchange users in Mexico, leveraging social enginee…
highbug_reportVulnerabilityGitHub commit verification flaw allows signature reuse on rewritten commits
GitHub's commit verification system for GPG/SSH-signed commits. All repositories using signed commits with GitHub's "Verified" badge are potentially affected. The flaw is in GitHub's verification logic, not Git itself.
highpublicGeopoliticalKDDI breach exposes 12M records across Japanese ISP ecosystem
The breach of KDDI, one of Japan's three major telecommunications carriers, represents a significant compromise of critical infrastructure in a key U.S. Indo-Pacific ally.
highperson_alertThreat ActorUAT-7810 Expands ORB Network with LONGLEASH Malware on Edge Devices
UAT-7810 is a China-linked advanced persistent threat (APT) actor focused on compromising internet-facing networking and infrastructure devices to build and maintain an Operational Relay Box (ORB) network designated LapDogs.