Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 356 results
highperson_alertThreat ActorIran-linked MOIS group deploys Cavern C2 framework against Israel
An Iranian threat actor affiliated with Iran's Ministry of Intelligence and Security (MOIS), tracked by Check Point Research. The group operates in support of Iranian state intelligence objectives, focusing on espionage operations against adversary n…
criticalbug_reportVulnerabilityGitea Docker auth bypass under active probing (CVE-2026-20896)
Gitea Docker images with improper X-WEBAUTH-USER header validation. Specific vulnerable versions not provided; affects deployments trusting reverse proxy authentication headers without IP restrictions.
highperson_alertThreat ActorChina-nexus actor targets Indian finance sector via DcRAT malware
A suspected China-nexus threat actor is conducting Operation DragonReturn, a targeted espionage campaign against Indian taxpayers and finance professionals.
highperson_alertThreat ActorJadePuffer: First LLM-Driven Ransomware Operation Documented
JadePuffer is a ransomware family representing the first documented instance of a ransomware operation conducted entirely by a large language model (LLM) agent.
highperson_alertThreat ActorKairos extorts $1M from U.S. government via data theft without encryption
Kairos is a financially motivated threat actor that employs extortion tactics focused on data theft without deploying traditional ransomware encryption. The group targeted a U.S.
highbug_reportVulnerabilityNorth Korean actors deploy 108 malicious packages in PolinRider campaign
npm, Packagist (PHP), Go modules, and Google Chrome Web Store. 108 malicious packages and extensions published. Maintainer accounts actively compromised. Campaign linked to North Korean Contagious Interview threat group.
highperson_alertThreat ActorAvalon Modular Malware Framework Delivers CrownX Ransomware
Avalon is a previously undocumented modular malware framework discovered by cybersecurity researchers. The framework is distributed through multi-stage phishing campaigns and represents a comprehensive attack platform integrating multiple offensive c…
highperson_alertThreat ActorNetNut Residential Proxy Network Disrupted After Compromising 2M Devices
NetNut operated a residential proxy network that leveraged approximately 2 million compromised Android devices to provide unauthorized proxy services. The actor monetized access to infected devices including smart TVs and streaming boxes, selling res…
highbug_reportVulnerabilityNorth Korean actors deploy malicious npm packages to steal developer secrets
npm ecosystem: malicious packages "rollup-packages-polyfill-core" and "rollup-runtime-polyfill-core" impersonating legitimate "rollup-plugin-polyfill-node".
highperson_alertThreat ActorEvilTokens Affiliate ARToken Exposes M365 Phishing-as-a-Service Platform
EvilTokens is a threat actor operating a phishing-as-a-service (PhaaS) ecosystem targeting Microsoft 365 credentials. The group utilizes an affiliate model, with ARToken identified as one operational affiliate platform.
highperson_alertThreat ActorArmored Likho targets government and energy sectors with BusySnake
Armored Likho is a previously undocumented threat actor attributed by Kaspersky to cyber attacks targeting government agencies and the electric power sector.
highperson_alertThreat ActorNSO Group's Pegasus Targets EU Parliament Member Investigating Spyware
NSO Group is an Israeli-based commercial surveillance vendor that develops and sells the Pegasus spyware to government clients. The company markets its tools as lawful intercept solutions for counterterrorism and law enforcement, but has faced repeat…
highperson_alertThreat ActorPamStealer: macOS Info Stealer Masquerades as Maccy Clipboard Manager
PamStealer is a newly discovered macOS information stealer malware family identified by Jamf Threat Labs. The malware is distributed through social engineering, masquerading as a legitimate Maccy clipboard manager application to deceive users into in…
highperson_alertThreat ActorNetNut (Popa) Residential Proxy Botnet Disrupted by Google, FBI
NetNut, also tracked as Popa, operates a residential proxy network built on approximately 2 million compromised home devices. The actor monetizes this infrastructure by selling proxy services that route malicious traffic through legitimate residentia…
highperson_alertThreat ActorAnubis Ransomware Exploits Citrix Bleed 2 (CVE-2025-5777) for Access
Anubis is a threat actor group operating the Anubis ransomware. The group demonstrates sophisticated tradecraft by exploiting recent vulnerabilities in enterprise infrastructure to gain initial access.
highperson_alertThreat ActorToddyCat Deploys Umbrij Malware to Hijack Gmail via OAuth Abuse
ToddyCat (G1022) is an advanced persistent threat group that has demonstrated sophisticated capabilities in targeting corporate and enterprise environments.
criticalperson_alertThreat ActorJADEPUFFER: First AI-Agent-Orchestrated Ransomware Attack
JADEPUFFER is a threat actor identified by Sysdig as the operator behind what is claimed to be the first fully AI-agent-orchestrated ransomware attack. The actor leveraged artificial intelligence agents to automate the entire attack lifecycle, repres…
highperson_alertThreat ActorScattered Spider Member Extradited to U.S. from Estonia
Scattered Spider (G1015), also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944, is a financially motivated threat actor collective known for sophisticated social engineering and identity-based attacks.
highperson_alertThreat ActorFortiBleed Campaign Linked to INC and Lynx Ransomware Operations
The FortiBleed campaign is a financially-motivated credential theft operation attributed to actors associated with the INC and Lynx ransomware groups. The campaign focuses on exploiting FortiGate devices to harvest credentials, which are subsequently…
highperson_alertThreat ActorShinyHunters Breaches Medtronic Healthcare Device Manufacturer
ShinyHunters is a financially-motivated cybercrime group known for large-scale data breaches and database exfiltration operations. The group has been active since at least 2020, targeting organizations across multiple sectors to steal sensitive data…
highperson_alertThreat ActorINC and Lynx Ransomware Groups Exploit FortiBleed for Credential Theft
INC and Lynx are ransomware threat actors linked to the FortiBleed credential theft campaign. These groups operate with the primary motivation of financial gain through ransomware deployment.
highperson_alertThreat ActorScattered Spider Member Extradited to U.S. on Federal Hacking Charges
Scattered Spider (also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944) is a financially motivated threat actor group known for sophisticated social engineering and identity-based attacks.
highperson_alertThreat ActorMassive SEO-Poisoned Campaign Distributes AsyncRAT via ScreenConnect
The threat actor behind this campaign remains unattributed. Motivation appears to be financially driven, consistent with commodity RAT deployment for access brokering, credential theft, or follow-on ransomware operations.
highperson_alertThreat ActorVEIL#DROP campaign delivers PureLogs stealer via Blogger pages
VEIL#DROP is a multi-stage malware delivery campaign identified by Securonix researchers. The campaign employs social engineering tactics and abuses legitimate Blogger platform infrastructure to distribute PureLogs, an information-stealing malware.
criticalbug_reportVulnerabilityCursor AI editor vulnerable to sandbox escape via prompt injection
Cursor AI code editor, all versions prior to patch. Both CVE-2026-50548 (CVSS 9.8) and CVE-2026-50549 (CVSS 9.3) enable sandbox escape and arbitrary command execution via prompt injection without user interaction.
highperson_alertThreat ActorDeepSeek AI Used to Generate Novel Browser-Based Ransomware
DeepSeek refers to the AI model leveraged by unknown threat actors to generate functional browser-based ransomware code. This marks the first documented instance of a frontier AI model being weaponized to create a novel ransomware technique.
highperson_alertThreat ActorRustDuck Botnet Targets IoT Devices for DDoS Operations
RustDuck is a two-stage malware family written in Rust, designed to compromise Internet of Things (IoT) devices including home routers, IP cameras, Android set-top boxes, and inadequately secured servers.
highperson_alertThreat ActorSilent Swap Campaign Targets Cryptocurrency via Malicious Browser Extensions
Silent Swap is an active cybercrime campaign leveraging malicious browser extensions to conduct cryptocurrency theft. The operation distributes unsigned installers written in both .NET and Golang variants, masquerading as a legitimate Google Notes br…
highperson_alertThreat ActorPre-Planned Fraud Campaign Targets FIFA World Cup 2026 Across Sectors
The threat actor behind this campaign remains unattributed. Motivation appears financially driven, leveraging the global interest in FIFA World Cup 2026 to conduct fraud operations.
criticalbug_reportVulnerabilitySimpleHelp OpenID auth bypass (CVE-2026-48558) exploited in wild
SimpleHelp remote support software, all versions using OpenID Connect authentication. CVE-2026-48558 is a critical authentication bypass (CVSS 10.0) in the OpenID Connect flow.