Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 567 results
Active filter:tag: #high✕ clear
HollowGraph Malware Uses Microsoft 365 Calendars for Covert C2highperson_alertThreat Actor
person_alertThreat Actor

HollowGraph Malware Uses Microsoft 365 Calendars for Covert C2

HollowGraph is a newly discovered espionage implant that leverages Microsoft 365 calendar infrastructure for command and control operations. The malware was identified and analyzed by Group-IB.

Microsoft20 Jul · 12:33 UTC
Russian Intelligence Services Exploit Security Cameras for Military Surveillancehighperson_alertThreat Actor
person_alertThreat Actor

Russian Intelligence Services Exploit Security Cameras for Military Surveillance

Russian intelligence services are conducting a systematic cyber-espionage campaign targeting internet-connected security cameras across Europe and Ukraine.

The Hacker News20 Jul · 10:13 UTC
7-Zip heap overflow in XZ handling allows code execution via crafted archiveshighbug_reportVulnerability
bug_reportVulnerability

7-Zip heap overflow in XZ handling allows code execution via crafted archives

7-Zip versions prior to 26.02. Affects all platforms where 7-Zip is deployed (Windows, Linux). Vulnerability triggered when opening malicious XZ archives.

CVE-2026-1426620 Jul · 07:10 UTC
bandcampro leverages Google Gemini CLI to control dental clinic botnethighperson_alertThreat Actor
person_alertThreat Actor

bandcampro leverages Google Gemini CLI to control dental clinic botnet

bandcampro is a Russian-speaking threat actor that has demonstrated novel tradecraft by weaponizing Google's Gemini CLI tool to orchestrate botnet operations.

The Hacker News20 Jul · 07:07 UTC
Autonomous AI Agent Breaches Hugging Face Repositoryhighperson_alertThreat Actor
person_alertThreat Actor

Autonomous AI Agent Breaches Hugging Face Repository

The threat actor is identified as an autonomous AI agent system—a novel adversary class representing machine-driven attack capabilities operating with minimal or no human intervention.

Hugging Face20 Jul · 03:27 UTC
Malicious RubyGems packages deliver payloads to developer workstationshighbug_reportVulnerability
bug_reportVulnerability

Malicious RubyGems packages deliver payloads to developer workstations

RubyGems ecosystem: three malicious packages (git_credential_manager, Dendreo, and one unnamed) published to the official RubyGems repository. Affects Ruby developers who installed these packages.

RubyGems20 Jul · 03:15 UTC
ViPNet update mechanism compromised to target Russian government agencieshighbug_reportVulnerability
bug_reportVulnerability

ViPNet update mechanism compromised to target Russian government agencies

ViPNet private networking software users, primarily Russian government agencies and organizations. All versions using the compromised update delivery mechanism are potentially affected. Specific version range not disclosed.

ViPNet19 Jul · 12:23 UTC
UAC-0145 (Sandworm sub-cluster) deploys ClickFix lures vs Ukrainehighperson_alertThreat Actor
person_alertThreat Actor

UAC-0145 (Sandworm sub-cluster) deploys ClickFix lures vs Ukraine

UAC-0145 is a sub-cluster of Sandworm, a Russian state-sponsored APT group attributed to the GRU (Main Intelligence Directorate of the General Staff of the Armed Forces of the Russian Federation).

The Hacker News19 Jul · 11:30 UTC
7-Zip 26.02 patches RCE flaw via malicious compressed fileshighbug_reportVulnerability
bug_reportVulnerability

7-Zip 26.02 patches RCE flaw via malicious compressed files

7-Zip versions prior to 26.02. All platforms (Windows, Linux, macOS) where 7-Zip is installed and users handle compressed archives from untrusted sources.

7-Zip18 Jul · 17:32 UTC
ACR Stealer campaign targets Microsoft enterprise customershighbug_reportVulnerability
bug_reportVulnerability

ACR Stealer campaign targets Microsoft enterprise customers

Microsoft enterprise customers; targets browser-stored credentials, authentication tokens, and sensitive documents across enterprise environments

Microsoft18 Jul · 12:17 UTC
OpenSSL "HollowByte" DoS allows 11-byte requests to freeze server memoryhighbug_reportVulnerability
bug_reportVulnerability

OpenSSL "HollowByte" DoS allows 11-byte requests to freeze server memory

OpenSSL versions prior to June 2024 patch. Affects TLS servers running on glibc-based Linux systems. Specific vulnerable versions not disclosed; patch applied without CVE or public advisory.

OpenSSL17 Jul · 18:20 UTC
Seven malicious npm packages target Vite ecosystem with blockchain C2 RAThighbug_reportVulnerability
bug_reportVulnerability

Seven malicious npm packages target Vite ecosystem with blockchain C2 RAT

npm package ecosystem, specifically projects using Vite frontend tooling. Seven malicious packages identified in the ViteVenom campaign. Any JavaScript/Node.js development environments that installed these packages are compromised.

npm17 Jul · 16:54 UTC
HollowByte flaw enables DoS on OpenSSL servers via 11-byte payloadhighbug_reportVulnerability
bug_reportVulnerability

HollowByte flaw enables DoS on OpenSSL servers via 11-byte payload

OpenSSL servers (specific versions not disclosed). Unauthenticated remote attackers can exploit the vulnerability. Scope includes any internet-facing OpenSSL server implementations susceptible to the malicious payload.

OpenSSL17 Jul · 15:56 UTC
NadMesh Botnet Targets AI Services for AWS and Kubernetes Credential Thefthighperson_alertThreat Actor
person_alertThreat Actor

NadMesh Botnet Targets AI Services for AWS and Kubernetes Credential Theft

NadMesh is a Go-based botnet operation discovered in early July that specializes in compromising cloud infrastructure credentials through exploitation of exposed AI and automation services.

AWS17 Jul · 15:12 UTC
Spring Authorization Server authentication bypass requires immediate patchhighbug_reportVulnerability
bug_reportVulnerability

Spring Authorization Server authentication bypass requires immediate patch

Spring Authorization Server (part of Spring Security framework by VMware/Pivotal). Specific affected versions not disclosed in available information. Authentication mechanism is impacted.

Spring (Pivotal/VMware)17 Jul · 13:32 UTC
Lazarus Deploys OtterCookie via Fake Job Lures in Contagious Interviewhighperson_alertThreat Actor
person_alertThreat Actor

Lazarus Deploys OtterCookie via Fake Job Lures in Contagious Interview

Lazarus is a North Korean state-sponsored advanced persistent threat (APT) group attributed to the Reconnaissance General Bureau (RGB). The group is financially motivated, conducting operations to generate revenue for the DPRK regime through cryptocu…

The Hacker News17 Jul · 11:48 UTC
Armenia Detains Russian National on U.S. REvil Ransomware Warranthighperson_alertThreat Actor
person_alertThreat Actor

Armenia Detains Russian National on U.S. REvil Ransomware Warrant

REvil (also known as Sodinokibi) is a Russia-linked ransomware-as-a-service (RaaS) operation that emerged in 2019 and became one of the most prolific cybercrime groups before law enforcement disruption in 2021-2022.

The Hacker News17 Jul · 08:53 UTC
ACR Stealer campaign uses ClickFix social engineering to steal M365 datahighbug_reportVulnerability
bug_reportVulnerability

ACR Stealer campaign uses ClickFix social engineering to steal M365 data

Microsoft 365 enterprise users and organizations. ACR Stealer targets browser credentials, session tokens, and M365 documents. Active since 2024 with two documented delivery chains using ClickFix social engineering lures.

Microsoft17 Jul · 06:56 UTC
GoSerpent Malware Targets Southeast Asian Government and Diplomacyhighperson_alertThreat Actor
person_alertThreat Actor

GoSerpent Malware Targets Southeast Asian Government and Diplomacy

GoSerpent is a previously undocumented malware family discovered by Kaspersky researchers in late 2025. The malware is designed for long-term persistent access and intelligence gathering operations.

Kaspersky17 Jul · 06:46 UTC
CERT.BE warns of multiple high-severity NGINX vulnerabilitieshighbug_reportVulnerability
bug_reportVulnerability

CERT.BE warns of multiple high-severity NGINX vulnerabilities

NGINX components (specific versions not disclosed in available information). Affects web servers, reverse proxies, and load balancers running vulnerable NGINX installations.

NGINX16 Jul · 12:42 UTC
Mount Royal University in Calgary confirms data breach and deletionhighpublicGeopolitical
publicGeopolitical

Mount Royal University in Calgary confirms data breach and deletion

The breach of Mount Royal University represents a typical pattern in the current cyber threat landscape affecting higher education institutions across North America.

Mount Royal University8 Jul · 19:26 UTC
Malicious npm and PyPI packages impersonate Paysafe payment SDKshighbug_reportVulnerability
bug_reportVulnerability

Malicious npm and PyPI packages impersonate Paysafe payment SDKs

Developers using npm and PyPI repositories who may have installed counterfeit packages impersonating Paysafe, Skrill, and Neteller payment SDKs. Affects development environments and potentially downstream applications integrating these malicious pack…

Paysafe8 Jul · 17:54 UTC
China-Linked Cluster Exploits Roundcube at Universitieshighperson_alertThreat Actor
person_alertThreat Actor

China-Linked Cluster Exploits Roundcube at Universities

This China-linked threat cluster targets academic institutions in North America, focusing on credential theft and persistent access through exploitation of vulnerable Roundcube webmail servers.

Roundcube8 Jul · 16:56 UTC
Vishing Campaign Targets Microsoft 365 Users with Entra Passkey Scamhighperson_alertThreat Actor
person_alertThreat Actor

Vishing Campaign Targets Microsoft 365 Users with Entra Passkey Scam

The threat actor behind this campaign remains unattributed. The operation demonstrates sophistication in social engineering tactics, specifically targeting Microsoft 365 environments through voice-based phishing (vishing).

Microsoft8 Jul · 14:47 UTC
HalluSquatting attack exploits AI coding assistants to distribute malwarehighbug_reportVulnerability
bug_reportVulnerability

HalluSquatting attack exploits AI coding assistants to distribute malware

AI coding assistants (GitHub Copilot, ChatGPT, Claude, etc.) and developers using AI-generated package recommendations. All package ecosystems (npm, PyPI, Maven, etc.) are potential targets.

AI coding assistants8 Jul · 13:07 UTC
EvilTokens Ghost Phishing Campaign Targets US and European Businesseshighperson_alertThreat Actor
person_alertThreat Actor

EvilTokens Ghost Phishing Campaign Targets US and European Businesses

EvilTokens is a campaign leveraging "ghost phishing" techniques to target business entities across the United States and Europe. The campaign's primary motivation appears to be credential theft and unauthorized access to Microsoft 365 environments, w…

Microsoft8 Jul · 11:00 UTC
REF6045 targets Mexican banking sector with SCMBANKER via ClickFix lureshighperson_alertThreat Actor
person_alertThreat Actor

REF6045 targets Mexican banking sector with SCMBANKER via ClickFix lures

REF6045 is a financially motivated threat actor conducting banking fraud operations against Mexican financial institutions and their customers. The actor targets banking, fintech, and cryptocurrency exchange users in Mexico, leveraging social enginee…

The Hacker News8 Jul · 10:52 UTC
GitHub commit verification flaw allows signature reuse on rewritten commitshighbug_reportVulnerability
bug_reportVulnerability

GitHub commit verification flaw allows signature reuse on rewritten commits

GitHub's commit verification system for GPG/SSH-signed commits. All repositories using signed commits with GitHub's "Verified" badge are potentially affected. The flaw is in GitHub's verification logic, not Git itself.

GitHub8 Jul · 09:51 UTC
KDDI breach exposes 12M records across Japanese ISP ecosystemhighpublicGeopolitical
publicGeopolitical

KDDI breach exposes 12M records across Japanese ISP ecosystem

The breach of KDDI, one of Japan's three major telecommunications carriers, represents a significant compromise of critical infrastructure in a key U.S. Indo-Pacific ally.

KDDI8 Jul · 09:24 UTC
UAT-7810 Expands ORB Network with LONGLEASH Malware on Edge Deviceshighperson_alertThreat Actor
person_alertThreat Actor

UAT-7810 Expands ORB Network with LONGLEASH Malware on Edge Devices

UAT-7810 is a China-linked advanced persistent threat (APT) actor focused on compromising internet-facing networking and infrastructure devices to build and maintain an Operational Relay Box (ORB) network designated LapDogs.

The Hacker News8 Jul · 07:04 UTC