Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 310 results
Active filter:✕ clear
ShinyHunters Breaches 137K+ School Staff via Salesforce Attackhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Breaches 137K+ School Staff via Salesforce Attack

ShinyHunters is a financially motivated cybercrime actor specializing in large-scale data theft and extortion operations. The group has established a reputation for targeting cloud-based platforms and third-party service providers to compromise downs…

Salesforce15 Jun · 10:38 UTC
FBI disrupts Outsider Enterprise Chinese phishing-as-a-service platformhighperson_alertThreat Actor
person_alertThreat Actor

FBI disrupts Outsider Enterprise Chinese phishing-as-a-service platform

Outsider Enterprise is a Chinese phishing-as-a-service (PhaaS) operation disrupted by the FBI in coordination with Google and Black Lotus Labs. The actor operated thousands of phishing websites designed to harvest credit card data and passwords from…

BleepingComputer14 Jun · 12:36 UTC
Chinese state-sponsored hackers maintain 10-year persistent accesscriticalperson_alertThreat Actor
person_alertThreat Actor

Chinese state-sponsored hackers maintain 10-year persistent access

Chinese state-sponsored hackers, likely an advanced persistent threat (APT) group operating on behalf of the People's Republic of China. The actor demonstrated exceptional operational security and patience, maintaining covert access to a target organ…

BleepingComputer13 Jun · 12:06 UTC
Chinese Cybercrime Network Weaponizes Google Gemini AI for SMS Phishinghighperson_alertThreat Actor
person_alertThreat Actor

Chinese Cybercrime Network Weaponizes Google Gemini AI for SMS Phishing

A Chinese cybercrime network operating a phishing-as-a-service (PhaaS) platform called Outsider. The group weaponizes Google's Gemini AI to craft and conduct SMS-based phishing attacks (smishing) targeting American victims.

Google12 Jun · 16:59 UTC
Velvet Ant: China-linked APT backdoors Linux auth for decade-long accesscriticalperson_alertThreat Actor
person_alertThreat Actor

Velvet Ant: China-linked APT backdoors Linux auth for decade-long access

Velvet Ant (G1047) is a China-linked advanced persistent threat actor characterized by exceptional operational security and long-term persistence capabilities.

Linux12 Jun · 16:17 UTC
Conti Operator Pleads Guilty After Extradition to United Stateshighperson_alertThreat Actor
person_alertThreat Actor

Conti Operator Pleads Guilty After Extradition to United States

Conti is a prolific ransomware-as-a-service (RaaS) operation that emerged in 2020 and became one of the most active and financially successful cybercrime groups before its infrastructure was leaked and operations fragmented in 2022.

BleepingComputer12 Jun · 15:54 UTC
UNC1151/Ghostwriter Targets Polish Gmail Accounts in Phishing Campaignhighperson_alertThreat Actor
person_alertThreat Actor

UNC1151/Ghostwriter Targets Polish Gmail Accounts in Phishing Campaign

UNC1151, also known as Ghostwriter, is a threat actor group attributed by FireEye/Mandiant that has conducted sustained information operations and cyber espionage activities.

Google12 Jun · 09:00 UTC
INTERPOL arrests Guedz, admin of Sniper Dz phishing-as-a-service platformhighperson_alertThreat Actor
person_alertThreat Actor

INTERPOL arrests Guedz, admin of Sniper Dz phishing-as-a-service platform

Guedz is identified as the primary administrator of Sniper Dz, a phishing-as-a-service (PhaaS) platform that operated for approximately a decade across the Middle East and North Africa (MENA) region.

The Hacker News12 Jun · 06:52 UTC
Europol Disrupts AudiA6 Cryptocurrency Laundering Servicehighperson_alertThreat Actor
person_alertThreat Actor

Europol Disrupts AudiA6 Cryptocurrency Laundering Service

AudiA6 was a cryptocurrency laundering service utilized by ransomware gangs and cybercriminal networks to obfuscate and legitimize illicit proceeds. The service facilitated the conversion and movement of cryptocurrency obtained through ransomware ope…

The Hacker News12 Jun · 04:38 UTC
The Gentlemen ransomware group claims 478 victims via multi-RaaS modelhighperson_alertThreat Actor
person_alertThreat Actor

The Gentlemen ransomware group claims 478 victims via multi-RaaS model

The Gentlemen is a financially motivated ransomware threat group that has claimed 478 victims through a hybrid operational model. Initially operating as an affiliate leveraging multiple ransomware-as-a-service (RaaS) platforms—including LockBit, Qili…

The Hacker News11 Jun · 14:50 UTC
Law Enforcement Dismantles AudiA6 Cryptocurrency Laundering Servicehighperson_alertThreat Actor
person_alertThreat Actor

Law Enforcement Dismantles AudiA6 Cryptocurrency Laundering Service

AudiA6 was a cryptocurrency laundering service that facilitated money laundering operations for ransomware actors and other cybercriminals. The service allegedly processed over $380 million in illicit proceeds before being dismantled by law enforceme…

BleepingComputer11 Jun · 13:55 UTC
OceanLotus Targets Vietnamese Infrastructure with SPECTRALVIPER Backdoorhighperson_alertThreat Actor
person_alertThreat Actor

OceanLotus Targets Vietnamese Infrastructure with SPECTRALVIPER Backdoor

OceanLotus (also tracked as APT32, SeaLotus, APT-C-00, and Canvas Cyclone) is a Vietnam-aligned advanced persistent threat group attributed by multiple vendors to conducting cyber espionage operations.

The Hacker News11 Jun · 07:45 UTC
ShinyHunters Targets Oracle PeopleSoft Servers in Mass Data Thefthighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Targets Oracle PeopleSoft Servers in Mass Data Theft

ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has gained notoriety for breaching numerous organizations and exfiltrating sensitive data, which is then used for extortion…

Oracle10 Jun · 16:31 UTC
China-Nexus Actors Expand JDY Botnet to 1,500+ IoT/SOHO Deviceshighperson_alertThreat Actor
person_alertThreat Actor

China-Nexus Actors Expand JDY Botnet to 1,500+ IoT/SOHO Devices

China-nexus state-sponsored threat actors operating the JDY botnet infrastructure. The actors leverage compromised small office/home office (SOHO) routers and IoT devices to build a distributed scanning platform for cyber reconnaissance operations.

The Hacker News10 Jun · 14:08 UTC
Volt Typhoon Expands JDY Botnet Operations Against U.S. Militaryhighperson_alertThreat Actor
person_alertThreat Actor

Volt Typhoon Expands JDY Botnet Operations Against U.S. Military

Volt Typhoon (also tracked as BRONZE SILHOUETTE, Vanguard Panda, DEV-0391, and UNC3236) is a Chinese state-sponsored APT group attributed to conducting cyber espionage operations targeting critical infrastructure.

BleepingComputer10 Jun · 13:00 UTC
The Gentlemen Ransomware: Aggressive Affiliate Model Drives Rapid Growthhighperson_alertThreat Actor
person_alertThreat Actor

The Gentlemen Ransomware: Aggressive Affiliate Model Drives Rapid Growth

The Gentlemen is a ransomware-as-a-service (RaaS) operation that has rapidly ascended to become the second most active ransomware group by victim count.

Krebs on Security10 Jun · 12:03 UTC
NSO Group linked to WhatsApp spear-phishing campaignshighperson_alertThreat Actor
person_alertThreat Actor

NSO Group linked to WhatsApp spear-phishing campaigns

NSO Group is an Israeli cyber intelligence firm that develops and sells commercial surveillance technology, primarily the Pegasus spyware platform. The company markets its tools to government clients for lawful interception and intelligence gathering…

WhatsApp8 Jun · 16:40 UTC
Meta blocks NSO Group spear-phishing targeting WhatsApp usershighperson_alertThreat Actor
person_alertThreat Actor

Meta blocks NSO Group spear-phishing targeting WhatsApp users

NSO Group is an Israeli commercial surveillance vendor that develops and sells offensive cyber capabilities, primarily the Pegasus spyware platform, to government clients.

Meta8 Jun · 15:08 UTC
VerdantBamboo deploys BSD BRICKSTORM variant with Linux malwarehighperson_alertThreat Actor
person_alertThreat Actor

VerdantBamboo deploys BSD BRICKSTORM variant with Linux malware

VerdantBamboo is a China-nexus cyber espionage group attributed by Volexity, with operational overlap with the threat cluster known as Clay Typhoon. The actor focuses on intelligence collection operations and has demonstrated cross-platform capabilit…

The Hacker News8 Jun · 08:27 UTC
UNC3753 Conducts Data Theft Extortion via Vishing and Physical Intrusionhighperson_alertThreat Actor
person_alertThreat Actor

UNC3753 Conducts Data Theft Extortion via Vishing and Physical Intrusion

UNC3753 is a financially motivated threat actor attributed by Mandiant. The group conducted a data theft extortion campaign targeting dozens of organizations in the United States between January and May 2026.

The Hacker News8 Jun · 05:39 UTC
Silent Ransom Group targets U.S. legal sector via fake IT supporthighperson_alertThreat Actor
person_alertThreat Actor

Silent Ransom Group targets U.S. legal sector via fake IT support

Silent Ransom Group is a threat actor conducting social engineering-driven intrusions against U.S. legal services and professional services organizations.

BleepingComputer7 Jun · 12:09 UTC
UNC5221 Deploys Brickstorm, Plenet, AgentPSD in M365 Espionage Campaignhighperson_alertThreat Actor
person_alertThreat Actor

UNC5221 Deploys Brickstorm, Plenet, AgentPSD in M365 Espionage Campaign

UNC5221 is a Chinese APT group attributed to conducting cyber espionage operations. The group demonstrates advanced capabilities in targeting cloud environments, specifically Microsoft 365 infrastructure.

Microsoft5 Jun · 16:09 UTC
OP-512 Targets IIS Servers with Custom Web Shell Frameworkhighperson_alertThreat Actor
person_alertThreat Actor

OP-512 Targets IIS Servers with Custom Web Shell Framework

OP-512 is a previously unreported threat cluster assessed by ReliaQuest with moderate to high confidence to be linked to China. The actor demonstrates espionage-focused objectives, leveraging custom web shell frameworks to compromise Microsoft Intern…

Microsoft5 Jun · 10:33 UTC
FBI Warns of FIFA World Cup 2026 Fraud Campaign with Banking Malwarehighperson_alertThreat Actor
person_alertThreat Actor

FBI Warns of FIFA World Cup 2026 Fraud Campaign with Banking Malware

This is a cybercrime campaign leveraging the FIFA World Cup 2026 tournament as a lure, rather than a single named threat actor. The campaign involves multiple financially motivated threat actors exploiting public interest in the tournament to distrib…

The Hacker News5 Jun · 05:01 UTC
PCPJack Hijacks 230+ Cloud Servers for Covert SMTP Relay Networkhighperson_alertThreat Actor
person_alertThreat Actor

PCPJack Hijacks 230+ Cloud Servers for Covert SMTP Relay Network

PCPJack is a threat actor focused on compromising cloud infrastructure to establish illicit email relay networks. The actor has demonstrated capability to breach business servers across major cloud service providers (AWS, Google Cloud, Microsoft Azur…

Amazon Web Services5 Jun · 03:34 UTC
DriveSurge Distributes Malware via ClickFix and FakeUpdate Campaignshighperson_alertThreat Actor
person_alertThreat Actor

DriveSurge Distributes Malware via ClickFix and FakeUpdate Campaigns

DriveSurge is a threat actor conducting large-scale malware distribution operations. The actor leverages compromised website infrastructure at scale, utilizing thousands of sites to host and deliver malicious payloads.

BleepingComputer1 Jun · 20:14 UTC
Operation Dragon Weave targets Czech and Taiwan entities with AdaptixC2highperson_alertThreat Actor
person_alertThreat Actor

Operation Dragon Weave targets Czech and Taiwan entities with AdaptixC2

Operation Dragon Weave is a cyber espionage campaign linked to China-aligned threat actors. The campaign's motivation appears to be intelligence collection targeting government officials, researchers, academics, and professionals in the Czech Republi…

The Hacker News1 Jun · 09:54 UTC
GREYVIBE: Russian-linked APT targeting Ukraine since August 2025highperson_alertThreat Actor
person_alertThreat Actor

GREYVIBE: Russian-linked APT targeting Ukraine since August 2025

GREYVIBE is a previously undocumented threat actor attributed by WithSecure as Russian-linked, assessed to operate in support of Kremlin state interests. The group is characterized as Russian-speaking and operates within Russian time zones.

The Hacker News29 May · 09:31 UTC
ShinyHunters Breaches Charter Communications, Exfiltrates 4.9M Recordshighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Breaches Charter Communications, Exfiltrates 4.9M Records

ShinyHunters is a financially motivated cybercrime group known for large-scale data breaches and extortion operations targeting enterprises. The group specializes in exfiltrating sensitive customer data from corporate databases and either selling the…

Charter Communications29 May · 06:29 UTC
Kimsuky Targets South Korean Military and Corporate Sectorshighperson_alertThreat Actor
person_alertThreat Actor

Kimsuky Targets South Korean Military and Corporate Sectors

Kimsuky (also tracked as Velvet Chollima, Black Banshee, Emerald Sleet, and THALLIUM) is a North Korean state-sponsored advanced persistent threat group.

The Hacker News29 May · 03:57 UTC