Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 356 results
Active filter:tag: #threat-actor✕ clear
AI browsers leak credentials via BioShocking social engineering attackhighbug_reportVulnerability
bug_reportVulnerability

AI browsers leak credentials via BioShocking social engineering attack

Six AI browsers and assistants including OpenAI ChatGPT Atlas, Perplexity Comet, and Anthropic Claude browser extension. Attack exploits AI reasoning vulnerabilities to extract user credentials through game-based social engineering.

OpenAI30 Jun · 06:37 UTC
ShinyHunters Exploits Oracle PeopleSoft Zero-Day in Nissan Breachhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Exploits Oracle PeopleSoft Zero-Day in Nissan Breach

ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has established a pattern of exploiting vulnerabilities in enterprise applications to exfiltrate sensitive data, which is th…

Oracle29 Jun · 18:40 UTC
ShinyHunters Exploits Oracle PeopleSoft Zero-Day at NAIChighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Exploits Oracle PeopleSoft Zero-Day at NAIC

ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has historically targeted organizations to exfiltrate sensitive data, which is then leveraged for extortion or sold on under…

Oracle29 Jun · 18:30 UTC
Malicious Chrome Extension Impersonates Perplexity AI to Intercept Searcheshighperson_alertThreat Actor
person_alertThreat Actor

Malicious Chrome Extension Impersonates Perplexity AI to Intercept Searches

The threat actor behind this campaign remains unattributed. The operation demonstrates a financially or espionage-motivated adversary leveraging social engineering through brand impersonation of Perplexity AI, a popular search technology.

Google29 Jun · 16:40 UTC
U.S. offers $10M reward for intel on UNC5792 and UNC4221 APT groupshighperson_alertThreat Actor
person_alertThreat Actor

U.S. offers $10M reward for intel on UNC5792 and UNC4221 APT groups

UNC5792 and UNC4221 are threat actor groups attributed to Russian intelligence and military services. Both groups have been designated as high-priority targets by the U.S.

BleepingComputer29 Jun · 13:09 UTC
Mustang Panda Targets Indian Government and Hydropower Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

Mustang Panda Targets Indian Government and Hydropower Infrastructure

Mustang Panda (also tracked as TA416, RedDelta, BRONZE PRESIDENT, and STATELY TAURUS) is a China-aligned advanced persistent threat group focused on espionage operations.

Zoho29 Jun · 13:03 UTC
Gamaredon APT Expands Ukraine Operations with 35 Spear-Phishing Campaignshighperson_alertThreat Actor
person_alertThreat Actor

Gamaredon APT Expands Ukraine Operations with 35 Spear-Phishing Campaigns

Gamaredon (also tracked as Armageddon, Shuckworm, Primitive Bear, and UAC-0010) is a Russian state-sponsored APT group attributed by multiple vendors to Russia's Federal Security Service (FSB).

ESET29 Jun · 09:40 UTC
Russian Intelligence Services Target Messaging Accounts via Phishinghighperson_alertThreat Actor
person_alertThreat Actor

Russian Intelligence Services Target Messaging Accounts via Phishing

Russian intelligence services conducted a long-running credential harvesting campaign targeting messaging platforms. The operation, uncovered jointly by Ukraine's Security Service (SSU) and the FBI, focused on stealing authentication credentials from…

The Hacker News27 Jun · 15:27 UTC
Russian Intelligence Services Target Signal Users in Phishing Campaignhighperson_alertThreat Actor
person_alertThreat Actor

Russian Intelligence Services Target Signal Users in Phishing Campaign

Russian intelligence services are conducting a phishing campaign targeting Signal messaging application users. The operation is attributed by the FBI and CISA, indicating state-sponsored activity aimed at compromising secure communications.

Signal26 Jun · 20:06 UTC
Russian Intelligence Escalates Signal Phishing for Backup Recovery Keyshighperson_alertThreat Actor
person_alertThreat Actor

Russian Intelligence Escalates Signal Phishing for Backup Recovery Keys

Russian intelligence actors, as identified by FBI and CISA joint reporting, are conducting targeted phishing operations against Signal messaging platform users.

Signal26 Jun · 17:38 UTC
Unknown Actors Exploit OpenAI Tenants to Phish Cybersecurity Firmshighperson_alertThreat Actor
person_alertThreat Actor

Unknown Actors Exploit OpenAI Tenants to Phish Cybersecurity Firms

The threat actors behind this campaign remain unattributed. Their motivation appears to be intelligence gathering and corporate espionage, leveraging the trust associated with OpenAI's platform to deceive employees of cybersecurity companies.

BleepingComputer26 Jun · 15:49 UTC
CL-STA-1062 deploys TinyRCT backdoor against Southeast Asian governmenthighperson_alertThreat Actor
person_alertThreat Actor

CL-STA-1062 deploys TinyRCT backdoor against Southeast Asian government

CL-STA-1062 is a Chinese-speaking APT actor conducting targeted cyber espionage operations against government entities and critical infrastructure in Southeast Asia.

Palo Alto Networks26 Jun · 14:21 UTC
Polish Authorities Dismantle SIM-Swapping Gang Targeting Crypto Assetshighperson_alertThreat Actor
person_alertThreat Actor

Polish Authorities Dismantle SIM-Swapping Gang Targeting Crypto Assets

This organized cybercrime group operated in Poland, conducting SIM-swapping attacks with the primary motivation of financial gain through cryptocurrency theft.

BleepingComputer25 Jun · 20:37 UTC
CL-STA-1062 targets Southeast Asian government with TinyRCT backdoorhighperson_alertThreat Actor
person_alertThreat Actor

CL-STA-1062 targets Southeast Asian government with TinyRCT backdoor

CL-STA-1062 is a threat actor conducting cyber espionage operations against government entities and critical infrastructure in Southeast Asia. The actor employs a hybrid toolkit centered around a custom backdoor known as TinyRCT.

Unit 42 (Palo Alto)25 Jun · 20:00 UTC
KongTuke Deploys Mistic Backdoor in Multi-Sector Financial Attackshighperson_alertThreat Actor
person_alertThreat Actor

KongTuke Deploys Mistic Backdoor in Multi-Sector Financial Attacks

KongTuke is an initial access broker (IAB) conducting financially motivated operations targeting organizations across insurance, education, IT, and professional services sectors.

The Hacker News25 Jun · 06:54 UTC
Cisco Catalyst SD-WAN zero-day exploited in wild for two monthshighbug_reportVulnerability
bug_reportVulnerability

Cisco Catalyst SD-WAN zero-day exploited in wild for two months

Cisco Catalyst SD-WAN Manager. Specific affected versions not disclosed. Requires authenticated local access for exploitation.

CVE-2026-2024525 Jun · 03:46 UTC
Snoopy Sentenced to 18 Months for DraftKings Account Compromisehighperson_alertThreat Actor
person_alertThreat Actor

Snoopy Sentenced to 18 Months for DraftKings Account Compromise

Snoopy is a 21-year-old individual arrested and sentenced for unauthorized access to customer accounts on the DraftKings sports betting platform in November 2022.

DraftKings24 Jun · 19:55 UTC
Cisco Catalyst SD-WAN zero-day exploited for root access (CVE-2026-20245)criticalbug_reportVulnerability
bug_reportVulnerability

Cisco Catalyst SD-WAN zero-day exploited for root access (CVE-2026-20245)

Cisco Catalyst SD-WAN devices. Specific affected versions not disclosed in available information. Attackers gain root-level access and can create persistent rogue accounts.

CVE-2026-2024524 Jun · 19:29 UTC
Edgecution: Malicious Edge Extension Enables Sandbox Escapehighperson_alertThreat Actor
person_alertThreat Actor

Edgecution: Malicious Edge Extension Enables Sandbox Escape

Edgecution is a malicious browser extension targeting Microsoft Edge, not a threat actor group. It functions as a tool deployed during ransomware operations to facilitate sandbox escape and establish persistence.

Microsoft24 Jun · 18:58 UTC
Europol disrupts Amadey and StealC infrastructure, recovers 27M credentialshighperson_alertThreat Actor
person_alertThreat Actor

Europol disrupts Amadey and StealC infrastructure, recovers 27M credentials

This report describes a law enforcement disruption operation led by Europol in partnership with private sector entities including Bitdefender, Bitsight, ESET, and Microsoft.

Bitdefender24 Jun · 13:59 UTC
Europol-led Operation Endgame disrupts Amadey and StealC infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

Europol-led Operation Endgame disrupts Amadey and StealC infrastructure

Europol is a law enforcement agency coordinating international cybercrime investigations. In this context, Europol led Operation Endgame, a coordinated law enforcement action involving Microsoft and international partners targeting cybercriminal infr…

Microsoft24 Jun · 12:35 UTC
CI/CD flaw "Cordyceps" exposes 300+ GitHub repos to supply-chain takeovercriticalbug_reportVulnerability
bug_reportVulnerability

CI/CD flaw "Cordyceps" exposes 300+ GitHub repos to supply-chain takeover

300+ GitHub repositories across major organizations including Microsoft, Google, and Apache. Vulnerability affects GitHub Actions CI/CD workflows. Specific products and versions not disclosed in available data.

Microsoft24 Jun · 10:48 UTC
KongTuke Deploys Mistic Backdoor in Multi-Sector Intrusionshighperson_alertThreat Actor
person_alertThreat Actor

KongTuke Deploys Mistic Backdoor in Multi-Sector Intrusions

KongTuke is a financially motivated threat actor operating as a ransomware access broker. The group specializes in gaining initial access to corporate networks and establishing persistent backdoor access, which is then sold or provided to ransomware…

BleepingComputer24 Jun · 08:41 UTC
U.S. seizes HuiOne Group assets, sanctions Prince Group entitieshighperson_alertThreat Actor
person_alertThreat Actor

U.S. seizes HuiOne Group assets, sanctions Prince Group entities

HuiOne Group and Prince Group are entities linked to cyber scam money laundering operations with infrastructure in Cambodia. HuiOne Group subsidiaries allegedly operated cloud computing infrastructure used to facilitate financial transactions related…

Huione Cloud24 Jun · 06:55 UTC
Malicious AI skills in ClawHub marketplace evade scanners, deploy infostealershighbug_reportVulnerability
bug_reportVulnerability

Malicious AI skills in ClawHub marketplace evade scanners, deploy infostealers

ClawHub marketplace users consuming third-party AI skills. Specific affected products: OpenClaw and ClawHub platforms. Scope includes organizations deploying AI agents with marketplace-sourced skills that may contain evasive malware delivering infost…

OpenClaw, ClawHub23 Jun · 20:00 UTC
ClickFix Targets macOS with Terminal-Based Infostealer Campaignhighperson_alertThreat Actor
person_alertThreat Actor

ClickFix Targets macOS with Terminal-Based Infostealer Campaign

ClickFix is a threat actor conducting social engineering campaigns that trick users into executing malicious commands. The actor leverages deceptive techniques to convince victims to manually run Terminal commands on macOS systems, facilitating the d…

Apple23 Jun · 16:30 UTC
FortiBleed: Russian IAB harvests 110M credentials from FortiGate devicescriticalperson_alertThreat Actor
person_alertThreat Actor

FortiBleed: Russian IAB harvests 110M credentials from FortiGate devices

FortiBleed is attributed to a Russian-speaking initial access broker (IAB) conducting large-scale credential harvesting operations since February 2026. The actor demonstrates advanced operational capabilities through systematic targeting of over 430,…

Fortinet23 Jun · 16:20 UTC
Scattered Spider Members Plead Guilty to Transport for London Attackhighperson_alertThreat Actor
person_alertThreat Actor

Scattered Spider Members Plead Guilty to Transport for London Attack

Scattered Spider (also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944 by various vendors) is a financially motivated cybercrime group known for sophisticated social engineering and identity-based attacks.

Transport for London23 Jun · 14:12 UTC
Scattered Spider Members Plead Guilty to Transport for London Breachhighperson_alertThreat Actor
person_alertThreat Actor

Scattered Spider Members Plead Guilty to Transport for London Breach

Scattered Spider (G1015), also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944, is a financially motivated cybercrime group known for sophisticated social engineering and identity-based attacks.

Transport for London23 Jun · 13:31 UTC
WhatsApp VBScript Campaign Deploys ManageEngine RMM Across 9 Countrieshighperson_alertThreat Actor
person_alertThreat Actor

WhatsApp VBScript Campaign Deploys ManageEngine RMM Across 9 Countries

This campaign represents an unattributed threat activity leveraging WhatsApp as an initial access vector. The actor's motivation appears to be establishing persistent remote access to victim systems through legitimate remote monitoring and management…

WhatsApp23 Jun · 03:38 UTC