Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 258 results
highbug_reportVulnerability5,000 Dropbox accounts compromised; OAuth and Teams phishing campaigns active
Multiple attack vectors: 5,000+ compromised Dropbox accounts, Microsoft Teams users across 150+ employees in 10+ organizations, OAuth-based applications, and users of phishing-as-a-service kits (BlueKit, Outsider).
highbug_reportVulnerabilityBraZetsu malware framework enables Initial Access Broker marketplace
Windows hosts in Iberian Peninsula and Latin America, particularly Brazil. Primary targets: e-commerce, corporate, financial, industrial, and law enforcement sectors. Browsers affected: Google Chrome, Microsoft Edge, Brave, Vivaldi, Opera.
highbug_reportVulnerabilityRMM phishing campaign hits 46 countries, US accounts for 45% of activity
Organizations across 46 countries, primarily United States (45% of activity), Canada, and others. Top targeted sectors: education, technology, government, banking, finance, and manufacturing.
highbug_reportVulnerabilityAttackers abuse legitimate Node.js runtime to evade detection in attacks
Organizations using Node.js in their environments, particularly government departments, technology companies, hotels, fintech, e-commerce, professional services, and retail logistics.
highbug_reportVulnerabilityShai-Hulud infostealer now targets 469 credential locations in dev tools
Developer workstations, CI/CD pipelines, cloud configurations, AI tool configs, package registries (npm, GitHub, Docker), and any environment storing long-lived credentials or tokens.
highbug_reportVulnerabilityAI-assisted campaigns target Latin American orgs with data exfiltration
Organizations in Latin America, specifically: Mexican transportation sector, federal government ministries, municipal water utilities in Mexico and Ecuador (CL-CRI-1131); Brazilian financial sector (CL-CRI-1163).
highbug_reportVulnerabilityAttackers abuse Microsoft Teams external chat to impersonate IT support
Microsoft Teams users in enterprise environments with external collaboration enabled. All organizations using Teams for business communication are at risk if users accept external contact requests and grant remote access via RMM tools or Quick Assist…
highbug_reportVulnerabilitySilver Fox campaign uses fake installers to disable Windows Update
Windows systems globally, primarily China-based operations of multinational organizations and Chinese-speaking users across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors.
highperson_alertThreat ActorGambling Goblin Hijacks Brazilian Gov Sites via Malicious Apache Modules
Gambling Goblin is a Chinese-speaking cybercrime cluster tracked by Check Point Research since mid-2025. The group specializes in SEO manipulation at scale by compromising high-reputation domains, particularly Brazilian government (.gov.br) and educa…
highperson_alertThreat ActorStreamRat Android Banking Trojan Spread via Meta Ads to EU Users
ThreatFabric is the cybersecurity research firm that discovered and analyzed the StreamRat campaign. The actual threat actor behind StreamRat remains unattributed.
highperson_alertThreat ActorRussian National Charged for 2016-2017 Excel Malware Campaign
Searzhudin Tamirlanovich Aktulaev is a 40-year-old Russian national charged by the U.S. Department of Justice for orchestrating a large-scale malware distribution campaign between June 2016 and November 2017.
highperson_alertThreat ActorRussian National Indicted for TVRAT/DarkVNC Phishing Campaign
Searzhudin Tamirlanovich Aktulaev, a 40-year-old Russian national, orchestrated a large-scale phishing campaign between June 2016 and November 2017. Motivated by financial fraud and credential theft, Aktulaev targeted freelancers on an unnamed freela…
highbug_reportVulnerabilitySality P2P botnet dismantled after 20+ years of operation
Sality botnet infrastructure (active since 2003), affecting 15,000+ infected devices globally. Primary payload in recent years: EggJagger clipjacking malware targeting cryptocurrency wallets.
highbug_reportVulnerabilityActive malware campaign uses fake vendor sites to deliver Silver Fox malware
Organizations with China-based operations and Chinese-speaking users across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors.
highperson_alertThreat ActorPhishing Actors Abuse Faronics Deploy for ScreenConnect Installation
The actors are unattributed phishing operators conducting opportunistic attacks against organizations using social engineering lures. Between July 21 and August 20, 2026, they targeted over 457 endpoints with phishing emails disguised as invoices, ta…
highperson_alertThreat ActorBreeze Comet Targets Brazilian Financial Sector for Payment Fraud
Breeze Comet (formerly UNC5669, overlaps with Plump Spider and SHADOW-AETHER-064) is a financially motivated threat actor operating out of Brazil since September 2023.
highperson_alertThreat ActorNimbus Manticore Deploys Cross-Platform RATs via Fake Job Coding Tests
Nimbus Manticore is an Iranian threat actor also tracked as Iranian Dream Job, known for using recruitment-themed social engineering lures to compromise targets.
highperson_alertThreat ActorClickFix Operators Dominate Initial Access via Social Engineering
ClickFix operators are threat actors leveraging a social engineering technique that manipulates users into executing malicious commands through clipboard manipulation.
highperson_alertThreat ActorVenezuelan ATM Jackpotting Group Targets U.S. Financial Infrastructure
This threat actor is a coordinated group of Venezuelan nationals conducting ATM jackpotting operations targeting financial institutions in the United States.
highbug_reportVulnerabilityTerminalFix campaign uses fake CAPTCHAs to deploy reverse tunnels
Windows systems with PowerShell and Windows Terminal enabled. Targets organizations with Active Directory environments. Attack vector: compromised websites displaying fake Cloudflare CAPTCHA prompts.
highperson_alertThreat ActorNorth Korean IT Worker Scheme Expands Into Healthcare and Sales Roles
North Korean state-sponsored threat actors, tracked as Famous Chollima, Jasper Sleet, Nickel Tapestry, PurpleDelta (formerly TAG-121), UNC5267, and Wagemole, operate a sophisticated job fraud scheme to generate revenue for the DPRK's nuclear weapons…
highperson_alertThreat ActorSilver Fox Distributes ValleyRAT via Signed Chinese Adware
Silver Fox is a threat actor attributed by Kaspersky to campaigns distributing the ValleyRAT backdoor (also tracked as Winos 4.0). The group has demonstrated consistent use of DLL sideloading techniques leveraging legitimate, signed software to evade…
highperson_alertThreat ActorSpring Ring Campaign Weaponizes Microsoft Teams for Vishing Attacks
Spring Ring is a coordinated social engineering campaign identified between January and April 2026 that leverages external Microsoft Teams accounts to impersonate IT help desk personnel.
highbug_reportVulnerability19 malicious Chrome/Edge extensions steal crypto and credentials
Google Chrome and Microsoft Edge users who installed any of 19 malicious extensions, including "Enable Right Click & Copy" (70,000+ Chrome users, 10,000+ Edge users). Campaign active since early 2024.
highbug_reportVulnerabilityTerminalFix campaign uses fake CAPTCHAs to deploy reverse-tunnel backdoor
Organizations across multiple sectors using Windows environments with PowerShell and Windows Terminal. Attack leverages compromised websites serving fake Cloudflare CAPTCHA pages to social engineer users into executing malicious PowerShell commands.
highperson_alertThreat ActorTerminalFix Campaign Deploys Multi-Stage Attacks via Fake CAPTCHAs
TerminalFix is a coordinated campaign activity (variant of ClickFix social engineering technique) disclosed by Microsoft Threat Intelligence. The campaign targets organizations across multiple industries using compromised websites to deliver sophisti…
highbug_reportVulnerability19 malicious Chrome/Edge extensions drain crypto wallets via auto-updates
19 browser extensions (18 Chrome, 1 Edge) published since February 2024, with "Enable Right Click & Copy — Smart Unlock + OCR" having 80,000 installs. Extensions either created by threat actor or purchased from legitimate owners.
highbug_reportVulnerabilityWeekly roundup: 296K IoT botnet, water system attacks, SharePoint RCE
Multiple products and sectors: 296,000 IoT devices compromised by Dysphoria botnet; 100+ water systems targeted (details not provided in excerpt); SharePoint RCE vulnerability chain (CVE/version unspecified); Android banking apps targeted by Octagon…
highbug_reportVulnerabilityNCSC warns of increased targeting of internet-exposed OT systems globally
Organizations with operational technology (OT) systems exposed to the internet across multiple sectors globally, including UK critical national infrastructure and non-CNI sectors.
highbug_reportVulnerabilitySpark RAT campaign targets Cambodia via OPSWAT driver exploit
Organizations and individuals in Cambodia. Campaign abuses vulnerable OPSWAT AppRemover driver (ardrv.sys, CVE-2026-36425) via BYOVD technique. Targets systems running Microsoft Defender, Huorong Internet Security, Tencent PC Manager, and Qihoo 360.