Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
22 / 202 results
criticalperson_alertThreat ActorCISA Contractor Leaks AWS GovCloud Keys on Public GitHub Repository
The threat actor is an insider—a contractor working for the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The individual intentionally published sensitive AWS GovCloud credentials and agency secrets to a public GitHub repository.
highperson_alertThreat ActorGhostwriter Targets Ukrainian Government with Prometheus-Themed Phishing
Ghostwriter (also tracked as UAC-0057 and UNC1151) is a Belarus-aligned threat actor known for conducting information operations and cyber espionage campaigns.
highperson_alertThreat ActorScreening Serpens: Iranian APT Targets Tech and Defense with RAT Malware
Screening Serpens is an Iranian APT group attributed by Unit 42, conducting cyber espionage operations. The group is motivated by intelligence collection targeting technology and defense sectors, consistent with Iranian state interests in acquiring s…
highperson_alertThreat ActorMegalodon campaign injects 5,718 malicious commits into GitHub repos
Megalodon is an automated supply chain attack campaign targeting GitHub repositories. The actor's motivation appears to be exfiltration of CI/CD environment data, including secrets, tokens, and credentials stored in GitHub Actions workflows.
highperson_alertThreat ActorROADtools Framework Misused in Nation-State Cloud Intrusions
Multiple threat actors, including nation-state groups, are misusing the open-source ROADtools framework for cloud intrusions. ROADtools is a legitimate Azure AD reconnaissance toolkit designed for security assessments, but has been co-opted by advers…
highperson_alertThreat ActorCanadian National Arrested for Operating KimWolf DDoS Botnet
A Canadian national arrested by U.S. and Canadian authorities for operating the KimWolf DDoS botnet infrastructure. The operator managed a large-scale botnet that compromised nearly two million devices globally, offering DDoS-for-hire services.
highperson_alertThreat ActorJacob Butler Arrested for Operating Kimwolf DDoS Botnet
Jacob Butler, also known as "Dort," is a 23-year-old Canadian national from Ottawa arrested by the U.S. Department of Justice for developing and operating the Kimwolf DDoS botnet.
highperson_alertThreat ActorDort Arrested for Operating Kimwolf IoT Botnet in Multi-Million Device DDoS Campaign
Dort is a 23-year-old cybercriminal based in Ottawa, Canada, suspected of developing and operating the Kimwolf IoT botnet. Motivated by launching large-scale DDoS attacks, doxing, and swatting campaigns, Dort leveraged compromised IoT devices to buil…
highperson_alertThreat ActorShowboat Linux Malware Targets Middle East Telecom Since Mid-2022
The threat actor behind Showboat remains unattributed. The campaign demonstrates sophisticated targeting of telecommunications infrastructure in the Middle East, suggesting a motivated adversary with strategic intelligence collection objectives.
highperson_alertThreat ActorChinese APT Deploys Showboat and JFMBackdoor Against Telecom Sector
Chinese state-sponsored threat actors conducting cyber-espionage operations against telecommunications infrastructure. The actors demonstrate cross-platform capabilities with custom Linux and Windows malware tooling.
highperson_alertThreat ActorInternational Law Enforcement Seizes First VPN Service Used by Cybercriminals
First VPN was a commercial VPN service exploited by multiple threat actors to anonymize their operations. The service provided infrastructure enabling cybercriminals to mask their origin during ransomware deployments and data exfiltration campaigns.
highperson_alertThreat Actor18-Year-Old Infostealer Operator Arrested for Compromising 28K Accounts
An 18-year-old individual from Odesa, Ukraine, identified by Ukrainian cyberpolice in coordination with U.S. law enforcement. The operator is suspected of deploying infostealer malware to harvest credentials and compromise user accounts.
criticalperson_alertThreat ActorMicrosoft Disrupts Fox Tempest Malware-Signing-as-a-Service Operation
Fox Tempest is a threat actor attributed by Microsoft as operating a malware-signing-as-a-service (MSaaS) business model. The actor exploited Microsoft's Artifact Signing system to provide malicious code signing services to other cybercriminals, enab…
highperson_alertThreat ActorWebworm Deploys EchoCreep and GraphWorm Backdoors via Discord and Graph API
Webworm is a China-aligned advanced persistent threat (APT) actor first documented by Symantec in September 2022, with activity traced back to at least 2022.
highperson_alertThreat ActorTeamPCP Lists GitHub Source Code for Sale After Repository Breach
TeamPCP is a threat actor that has emerged in the cybercrime ecosystem, demonstrating capability to compromise high-value technology platforms. The actor's motivation appears financially driven, as evidenced by their decision to monetize stolen GitHu…
highperson_alertThreat ActorMicrosoft Disrupts Malware-Signing-as-a-Service Operation
This operation involved cybercriminals abusing Microsoft's Artifact Signing service to provide malware-signing-as-a-service capabilities. The actors exploited legitimate code-signing infrastructure to generate fraudulent certificates, which were then…
highperson_alertThreat ActorFox Tempest Provides Malware-Signing Services to Ransomware Operators
Fox Tempest is a financially motivated cybercriminal actor that operates as a malware-signing service provider within the ransomware ecosystem. Rather than conducting attacks directly, Fox Tempest enables other threat actors—including Vanilla Tempest…
highperson_alertThreat ActorShinyHunters Claims 7-Eleven Data Breach
ShinyHunters is a financially motivated cybercrime group known for large-scale data breaches and database theft. The group emerged around 2020 and has been linked to numerous high-profile data exfiltration incidents targeting organizations across var…
highperson_alertThreat ActorNCSC UK Issues Guidance on China-Nexus Covert Device Networks
China-nexus threat actors are state-sponsored groups linked to the People's Republic of China. These actors are motivated by strategic intelligence collection, espionage, and maintaining persistent access to foreign networks.
highperson_alertThreat ActorNCSC UK Issues Advisory on China-Linked Covert Network Tactics
China-linked threat actors employing covert network tactics to conceal malicious cyber activity. These actors are characterized by their use of sophisticated techniques to maintain persistent, stealthy access to compromised networks.
highbug_reportVulnerabilityFortinet FortiCloud SSO bypass exploited to extract LDAP passwords
Fortinet FortiGate appliances with FortiCloud SSO enabled. CVE-2025-59718 and CVE-2025-59719 allow authentication bypass. All FortiGate instances share a default static encryption key that enables decryption of LDAP credentials and private keys from…
highperson_alertThreat ActorRansomware Campaigns Target Slovenia via Email, RDP, and Exploits
Unattributed ransomware operators targeting Slovenia. Motivation appears financially driven, consistent with commodity ransomware campaigns. No specific actor attribution available; likely represents multiple threat groups employing common ransomware…