Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 332 results
highbug_reportVulnerabilityCVE-2026-39987 in Marimo actively exploited for cloud credential theft
Marimo notebook platform (specific versions not disclosed). Affects internet-exposed Marimo notebook instances vulnerable to CVE-2026-39987.
highbug_reportVulnerabilityDutch authorities disrupt 17M-device botnet, seize 200+ servers
Approximately 17 million infected devices globally; over 200 servers seized from a Dutch hosting provider. Specific botnet malware family and affected device types not disclosed.
highperson_alertThreat ActorGREYVIBE: Russian-linked APT targeting Ukraine since August 2025
GREYVIBE is a previously undocumented threat actor attributed by WithSecure as Russian-linked, assessed to operate in support of Kremlin state interests. The group is characterized as Russian-speaking and operates within Russian time zones.
highpublicGeopoliticalUS national sentenced for selling 7M elderly records to Jamaican fraudsters
This case illustrates the transnational nature of cybercrime and data exploitation, where domestic actors facilitate cross-border fraud schemes targeting vulnerable populations.
highbug_reportVulnerabilityMalicious NuGet package "Sicoob.Sdk" steals banking credentials
NuGet package "Sicoob.Sdk" versions 2.0.0 through 2.0.4. Targets developers integrating with Sicoob (Brazilian cooperative banking system). Affects .NET development environments where the malicious package was installed.
highperson_alertThreat ActorShinyHunters Breaches Charter Communications, Exfiltrates 4.9M Records
ShinyHunters is a financially motivated cybercrime group known for large-scale data breaches and extortion operations targeting enterprises. The group specializes in exfiltrating sensitive customer data from corporate databases and either selling the…
highbug_reportVulnerabilityHard-coded secret in Trac PDBM enables unauthorized access
Trac d.o.o. Process Database Manager (PDBM) - specific affected versions not disclosed. Vulnerability involves hard-coded cryptographic secret embedded in executable binary.
highperson_alertThreat ActorKimsuky Targets South Korean Military and Corporate Sectors
Kimsuky (also tracked as Velvet Chollima, Black Banshee, Emerald Sleet, and THALLIUM) is a North Korean state-sponsored advanced persistent threat group.
highperson_alertThreat ActorMini Shai-Hulud: Typosquatted npm Packages Target Developer Credentials
Mini Shai-Hulud is a threat actor campaign focused on compromising software development environments through supply chain attacks. The actor leverages typosquatting techniques against the npm package ecosystem to distribute malicious packages that ma…
highperson_alertThreat ActorGreyVibe Targets Ukraine with AI-Generated Lures and Custom Malware
GreyVibe is a threat cluster assessed with moderate confidence to be linked to Russian interests, based on targeting patterns and geopolitical alignment.
highbug_reportVulnerabilityBTMOB Android RAT offered as MaaS with custom phishing builder
Android devices targeted by BTMOB remote access trojan. No specific vendor or version restrictions; affects users who install malicious APKs distributed through phishing campaigns.
highperson_alertThreat ActorFBI warns of FIFA-impersonating fraud sites targeting 2026 World Cup
Unknown fraud operators are conducting financially motivated cybercrime campaigns targeting fans and consumers interested in the 2026 FIFA World Cup. These actors leverage social engineering and brand impersonation tactics to establish fraudulent web…
highbug_reportVulnerabilityFortinet FortiClient EMS auth bypass exploited to deploy EKZ malware
Fortinet FortiClient Enterprise Management Server (EMS). Specific vulnerable versions not provided in available data. Authentication bypass vulnerability CVE-2026-35616 allows unauthorized access.
highperson_alertThreat ActorArctic Wolf exploits FortiClient EMS flaw for credential theft
Arctic Wolf is a threat actor exploiting a critical, patched vulnerability in FortiClient Endpoint Management Server (EMS) to deploy credential-stealing malware.
highperson_alertThreat ActorStorm-2697 Deploys The Gentlemen Go-Based Ransomware with Worm Capabilities
Storm-2697 is a threat actor tracked by Microsoft Threat Intelligence that operates as a ransomware affiliate group. The actor deploys The Gentlemen ransomware, a sophisticated Go-based encryption tool, suggesting technical proficiency in modern prog…
highbug_reportVulnerabilityKidsview authentication bypass allows unauthorized access (CVE-2026-8990)
Kidsview application (specific versions not disclosed). Authentication mechanisms can be bypassed, potentially affecting all deployments until patched versions are confirmed.
highperson_alertThreat ActorRomanian National Sentenced for Hacking Oregon Government Network
A Romanian national individual actor who conducted unauthorized access operations targeting U.S. government and private sector networks. The actor's motivation appears to be financially driven cybercrime, operating from Romania to compromise Oregon s…
highbug_reportVulnerabilityOut-of-bounds write in bzip2 enables code execution or DoS
bzip2 compression software, all versions not yet patched. Affects systems using bzip2 for file compression/decompression, including Linux distributions, BSD variants, and applications embedding libbz2.
highperson_alertThreat ActorShinyHunters Claims Breach of Carnival Corporation, 6M Records
ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has been active since at least 2020, specializing in breaching corporate databases and exfiltrating customer and employee re…
highperson_alertThreat ActorJINX-0164 Targets Cryptocurrency Orgs with macOS Malware
JINX-0164 is a previously undocumented threat actor with a financial motivation focused on digital asset theft. The group demonstrates technical sophistication through the development of custom macOS malware and operational tradecraft centered on soc…
highbug_reportVulnerabilityCryptojacking campaign uses SEO poisoning and AI chatbots for GPU malware
High-performance systems with GPUs accessed via search engines and AI chatbot platforms. No specific vendor or product vulnerability; targets users searching for legitimate software or information through poisoned search results and manipulated chatb…
highbug_reportVulnerabilityBanking trojans Grandoreiro and BTMOB target LATAM and Europe
Windows and Android devices in Latin America (Brazil, Mexico) and Europe (Spain, Portugal). Grandoreiro targets Windows systems at companies; BTMOB RAT targets Android mobile users in Brazil.
highbug_reportVulnerabilityMalicious npm package targets Claude AI user data directory
npm package "mouse5212-super-formatter" (all versions). Targets developers using Anthropic Claude AI tools with access to /mnt/user-data directory. Affects Node.js development environments where the malicious package was installed.
highbug_reportVulnerabilityGlassworm botnet targeting developers disrupted via C2 takedown
Software developers and development environments targeted by Glassworm botnet. The botnet leveraged Solana blockchain and BitTorrent DHT for command-and-control infrastructure, indicating attacks against software supply chains.
highperson_alertThreat ActorSilent Ransom Group Shifts to Physical Data Theft at U.S. Law Firms
Silent Ransom Group (SRG) is an extortion-focused threat actor that has evolved from traditional ransomware operations to conducting physical, in-person data theft attacks.
highbug_reportVulnerabilityCrowdStrike, Google disrupt GlassWorm C2 targeting software developers
Software developers using third-party packages and browser extensions. GlassWorm campaign active since early 2025, distributing malware through supply chain vectors including malicious packages and extensions.
highbug_reportVulnerabilityGitea auth bypass exposes private container images to unauthenticated users
Gitea versions prior to 1.26.2. All deployments using Gitea's container registry feature are affected. Unauthenticated remote attackers can pull private container images without credentials.
highbug_reportVulnerabilityAI chatbot abuse delivers cryptojacking malware via social engineering
Users of AI chatbots (platform-agnostic); Windows systems targeted for cryptojacking payload deployment. Campaign actively observed by Microsoft; no specific product vulnerability, relies on social engineering.
highbug_reportVulnerabilityCryptojacking campaign uses SEO poisoning and ScreenConnect for GPU mining
Organizations using ScreenConnect remote access software; high-performance PCs with GPUs; users searching for compromised topics via search engines and AI chatbots. Campaign leverages Microsoft .NET utilities for execution.
highperson_alertThreat ActorShinyHunters Extorts Charter Communications After Data Breach
ShinyHunters is a financially motivated cybercrime group known for large-scale data breaches and extortion operations targeting organizations across multiple sectors.