Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 258 results
Active filter:tag: #campaign✕ clear
5,000 Dropbox accounts compromised; OAuth and Teams phishing campaigns activehighbug_reportVulnerability
bug_reportVulnerability

5,000 Dropbox accounts compromised; OAuth and Teams phishing campaigns active

Multiple attack vectors: 5,000+ compromised Dropbox accounts, Microsoft Teams users across 150+ employees in 10+ organizations, OAuth-based applications, and users of phishing-as-a-service kits (BlueKit, Outsider).

Dropbox3 Sep · 16:02 UTC
BraZetsu malware framework enables Initial Access Broker marketplacehighbug_reportVulnerability
bug_reportVulnerability

BraZetsu malware framework enables Initial Access Broker marketplace

Windows hosts in Iberian Peninsula and Latin America, particularly Brazil. Primary targets: e-commerce, corporate, financial, industrial, and law enforcement sectors. Browsers affected: Google Chrome, Microsoft Edge, Brave, Vivaldi, Opera.

Microsoft3 Sep · 13:26 UTC
RMM phishing campaign hits 46 countries, US accounts for 45% of activityhighbug_reportVulnerability
bug_reportVulnerability

RMM phishing campaign hits 46 countries, US accounts for 45% of activity

Organizations across 46 countries, primarily United States (45% of activity), Canada, and others. Top targeted sectors: education, technology, government, banking, finance, and manufacturing.

The Hacker News3 Sep · 09:58 UTC
Attackers abuse legitimate Node.js runtime to evade detection in attackshighbug_reportVulnerability
bug_reportVulnerability

Attackers abuse legitimate Node.js runtime to evade detection in attacks

Organizations using Node.js in their environments, particularly government departments, technology companies, hotels, fintech, e-commerce, professional services, and retail logistics.

Node.js3 Sep · 08:43 UTC
Shai-Hulud infostealer now targets 469 credential locations in dev toolshighbug_reportVulnerability
bug_reportVulnerability

Shai-Hulud infostealer now targets 469 credential locations in dev tools

Developer workstations, CI/CD pipelines, cloud configurations, AI tool configs, package registries (npm, GitHub, Docker), and any environment storing long-lived credentials or tokens.

The Hacker News3 Sep · 08:36 UTC
AI-assisted campaigns target Latin American orgs with data exfiltrationhighbug_reportVulnerability
bug_reportVulnerability

AI-assisted campaigns target Latin American orgs with data exfiltration

Organizations in Latin America, specifically: Mexican transportation sector, federal government ministries, municipal water utilities in Mexico and Ecuador (CL-CRI-1131); Brazilian financial sector (CL-CRI-1163).

Unit 42 (Palo Alto)3 Sep · 08:00 UTC
Attackers abuse Microsoft Teams external chat to impersonate IT supporthighbug_reportVulnerability
bug_reportVulnerability

Attackers abuse Microsoft Teams external chat to impersonate IT support

Microsoft Teams users in enterprise environments with external collaboration enabled. All organizations using Teams for business communication are at risk if users accept external contact requests and grant remote access via RMM tools or Quick Assist…

Microsoft2 Sep · 20:51 UTC
Silver Fox campaign uses fake installers to disable Windows Updatehighbug_reportVulnerability
bug_reportVulnerability

Silver Fox campaign uses fake installers to disable Windows Update

Windows systems globally, primarily China-based operations of multinational organizations and Chinese-speaking users across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors.

Microsoft2 Sep · 14:41 UTC
Gambling Goblin Hijacks Brazilian Gov Sites via Malicious Apache Moduleshighperson_alertThreat Actor
person_alertThreat Actor

Gambling Goblin Hijacks Brazilian Gov Sites via Malicious Apache Modules

Gambling Goblin is a Chinese-speaking cybercrime cluster tracked by Check Point Research since mid-2025. The group specializes in SEO manipulation at scale by compromising high-reputation domains, particularly Brazilian government (.gov.br) and educa…

Apache2 Sep · 11:44 UTC
StreamRat Android Banking Trojan Spread via Meta Ads to EU Usershighperson_alertThreat Actor
person_alertThreat Actor

StreamRat Android Banking Trojan Spread via Meta Ads to EU Users

ThreatFabric is the cybersecurity research firm that discovered and analyzed the StreamRat campaign. The actual threat actor behind StreamRat remains unattributed.

Meta2 Sep · 10:22 UTC
Russian National Charged for 2016-2017 Excel Malware Campaignhighperson_alertThreat Actor
person_alertThreat Actor

Russian National Charged for 2016-2017 Excel Malware Campaign

Searzhudin Tamirlanovich Aktulaev is a 40-year-old Russian national charged by the U.S. Department of Justice for orchestrating a large-scale malware distribution campaign between June 2016 and November 2017.

The Hacker News2 Sep · 07:10 UTC
Russian National Indicted for TVRAT/DarkVNC Phishing Campaignhighperson_alertThreat Actor
person_alertThreat Actor

Russian National Indicted for TVRAT/DarkVNC Phishing Campaign

Searzhudin Tamirlanovich Aktulaev, a 40-year-old Russian national, orchestrated a large-scale phishing campaign between June 2016 and November 2017. Motivated by financial fraud and credential theft, Aktulaev targeted freelancers on an unnamed freela…

BleepingComputer2 Sep · 07:06 UTC
Sality P2P botnet dismantled after 20+ years of operationhighbug_reportVulnerability
bug_reportVulnerability

Sality P2P botnet dismantled after 20+ years of operation

Sality botnet infrastructure (active since 2003), affecting 15,000+ infected devices globally. Primary payload in recent years: EggJagger clipjacking malware targeting cryptocurrency wallets.

BleepingComputer2 Sep · 06:00 UTC
Active malware campaign uses fake vendor sites to deliver Silver Fox malwarehighbug_reportVulnerability
bug_reportVulnerability

Active malware campaign uses fake vendor sites to deliver Silver Fox malware

Organizations with China-based operations and Chinese-speaking users across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors.

Microsoft1 Sep · 20:48 UTC
Phishing Actors Abuse Faronics Deploy for ScreenConnect Installationhighperson_alertThreat Actor
person_alertThreat Actor

Phishing Actors Abuse Faronics Deploy for ScreenConnect Installation

The actors are unattributed phishing operators conducting opportunistic attacks against organizations using social engineering lures. Between July 21 and August 20, 2026, they targeted over 457 endpoints with phishing emails disguised as invoices, ta…

Faronics1 Sep · 18:53 UTC
Breeze Comet Targets Brazilian Financial Sector for Payment Fraudhighperson_alertThreat Actor
person_alertThreat Actor

Breeze Comet Targets Brazilian Financial Sector for Payment Fraud

Breeze Comet (formerly UNC5669, overlaps with Plump Spider and SHADOW-AETHER-064) is a financially motivated threat actor operating out of Brazil since September 2023.

The Hacker News1 Sep · 15:19 UTC
Nimbus Manticore Deploys Cross-Platform RATs via Fake Job Coding Testshighperson_alertThreat Actor
person_alertThreat Actor

Nimbus Manticore Deploys Cross-Platform RATs via Fake Job Coding Tests

Nimbus Manticore is an Iranian threat actor also tracked as Iranian Dream Job, known for using recruitment-themed social engineering lures to compromise targets.

The Hacker News1 Sep · 11:08 UTC
ClickFix Operators Dominate Initial Access via Social Engineeringhighperson_alertThreat Actor
person_alertThreat Actor

ClickFix Operators Dominate Initial Access via Social Engineering

ClickFix operators are threat actors leveraging a social engineering technique that manipulates users into executing malicious commands through clipboard manipulation.

Microsoft1 Sep · 09:30 UTC
Venezuelan ATM Jackpotting Group Targets U.S. Financial Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

Venezuelan ATM Jackpotting Group Targets U.S. Financial Infrastructure

This threat actor is a coordinated group of Venezuelan nationals conducting ATM jackpotting operations targeting financial institutions in the United States.

BleepingComputer1 Sep · 07:15 UTC
TerminalFix campaign uses fake CAPTCHAs to deploy reverse tunnelshighbug_reportVulnerability
bug_reportVulnerability

TerminalFix campaign uses fake CAPTCHAs to deploy reverse tunnels

Windows systems with PowerShell and Windows Terminal enabled. Targets organizations with Active Directory environments. Attack vector: compromised websites displaying fake Cloudflare CAPTCHA prompts.

Microsoft31 Aug · 16:51 UTC
North Korean IT Worker Scheme Expands Into Healthcare and Sales Roleshighperson_alertThreat Actor
person_alertThreat Actor

North Korean IT Worker Scheme Expands Into Healthcare and Sales Roles

North Korean state-sponsored threat actors, tracked as Famous Chollima, Jasper Sleet, Nickel Tapestry, PurpleDelta (formerly TAG-121), UNC5267, and Wagemole, operate a sophisticated job fraud scheme to generate revenue for the DPRK's nuclear weapons…

The Hacker News31 Aug · 15:24 UTC
Silver Fox Distributes ValleyRAT via Signed Chinese Adwarehighperson_alertThreat Actor
person_alertThreat Actor

Silver Fox Distributes ValleyRAT via Signed Chinese Adware

Silver Fox is a threat actor attributed by Kaspersky to campaigns distributing the ValleyRAT backdoor (also tracked as Winos 4.0). The group has demonstrated consistent use of DLL sideloading techniques leveraging legitimate, signed software to evade…

Kaspersky31 Aug · 10:14 UTC
Spring Ring Campaign Weaponizes Microsoft Teams for Vishing Attackshighperson_alertThreat Actor
person_alertThreat Actor

Spring Ring Campaign Weaponizes Microsoft Teams for Vishing Attacks

Spring Ring is a coordinated social engineering campaign identified between January and April 2026 that leverages external Microsoft Teams accounts to impersonate IT help desk personnel.

Microsoft31 Aug · 08:00 UTC
19 malicious Chrome/Edge extensions steal crypto and credentialshighbug_reportVulnerability
bug_reportVulnerability

19 malicious Chrome/Edge extensions steal crypto and credentials

Google Chrome and Microsoft Edge users who installed any of 19 malicious extensions, including "Enable Right Click & Copy" (70,000+ Chrome users, 10,000+ Edge users). Campaign active since early 2024.

Google30 Aug · 12:17 UTC
TerminalFix campaign uses fake CAPTCHAs to deploy reverse-tunnel backdoorhighbug_reportVulnerability
bug_reportVulnerability

TerminalFix campaign uses fake CAPTCHAs to deploy reverse-tunnel backdoor

Organizations across multiple sectors using Windows environments with PowerShell and Windows Terminal. Attack leverages compromised websites serving fake Cloudflare CAPTCHA pages to social engineer users into executing malicious PowerShell commands.

Microsoft30 Aug · 05:36 UTC
TerminalFix Campaign Deploys Multi-Stage Attacks via Fake CAPTCHAshighperson_alertThreat Actor
person_alertThreat Actor

TerminalFix Campaign Deploys Multi-Stage Attacks via Fake CAPTCHAs

TerminalFix is a coordinated campaign activity (variant of ClickFix social engineering technique) disclosed by Microsoft Threat Intelligence. The campaign targets organizations across multiple industries using compromised websites to deliver sophisti…

Microsoft29 Aug · 01:43 UTC
19 malicious Chrome/Edge extensions drain crypto wallets via auto-updateshighbug_reportVulnerability
bug_reportVulnerability

19 malicious Chrome/Edge extensions drain crypto wallets via auto-updates

19 browser extensions (18 Chrome, 1 Edge) published since February 2024, with "Enable Right Click & Copy — Smart Unlock + OCR" having 80,000 installs. Extensions either created by threat actor or purchased from legitimate owners.

Google28 Aug · 13:27 UTC
Weekly roundup: 296K IoT botnet, water system attacks, SharePoint RCEhighbug_reportVulnerability
bug_reportVulnerability

Weekly roundup: 296K IoT botnet, water system attacks, SharePoint RCE

Multiple products and sectors: 296,000 IoT devices compromised by Dysphoria botnet; 100+ water systems targeted (details not provided in excerpt); SharePoint RCE vulnerability chain (CVE/version unspecified); Android banking apps targeted by Octagon…

The Hacker News27 Aug · 13:12 UTC
NCSC warns of increased targeting of internet-exposed OT systems globallyhighbug_reportVulnerability
bug_reportVulnerability

NCSC warns of increased targeting of internet-exposed OT systems globally

Organizations with operational technology (OT) systems exposed to the internet across multiple sectors globally, including UK critical national infrastructure and non-CNI sectors.

NCSC UK27 Aug · 10:00 UTC
Spark RAT campaign targets Cambodia via OPSWAT driver exploithighbug_reportVulnerability
bug_reportVulnerability

Spark RAT campaign targets Cambodia via OPSWAT driver exploit

Organizations and individuals in Cambodia. Campaign abuses vulnerable OPSWAT AppRemover driver (ardrv.sys, CVE-2026-36425) via BYOVD technique. Targets systems running Microsoft Defender, Huorong Internet Security, Tencent PC Manager, and Qihoo 360.

OPSWAT27 Aug · 09:00 UTC