Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
7 / 7 results
highperson_alertThreat ActorAnonyMousKIT PhaaS automates iPhone passcode theft via voice AI
AnonyMousKIT is a phishing-as-a-service (PhaaS) platform active since early 2024, operated by unknown threat actors who provide automated infrastructure for stealing iPhone passcodes and disabling Apple's Activation Lock.
highbug_reportVulnerabilityApple iCloud Private Relay leaks real IP via WebKit proxy bypasses
Apple iCloud Private Relay on iOS 15+, macOS, and iPadOS. Affects Safari and all WebKit-based browsers (Chrome, Edge, Firefox, Brave) on Apple platforms. Impacts users with iCloud+ subscriptions using Private Relay for privacy protection.
highperson_alertThreat ActorFuyao Campaign: Android TV Boxes Weaponized for Ad Fraud and Proxy Abuse
Zhejiang Fengwo IoT Technology Co., Ltd. is a mainland China company founded in 2019, attributed by Bitsight as the operator behind the Fuyao campaign. The attribution is based on shared TLS certificate data, exposed wiki files, reused email addresse…
highperson_alertThreat ActorNetNut Residential Proxy Network Disrupted After Compromising 2M Devices
NetNut operated a residential proxy network that leveraged approximately 2 million compromised Android devices to provide unauthorized proxy services. The actor monetized access to infected devices including smart TVs and streaming boxes, selling res…
highperson_alertThreat ActorRustDuck Botnet Targets IoT Devices for DDoS Operations
RustDuck is a two-stage malware family written in Rust, designed to compromise Internet of Things (IoT) devices including home routers, IP cameras, Android set-top boxes, and inadequately secured servers.
highbug_reportVulnerabilityAirDrop and Quick Share flaws enable wireless DoS and security bypass
Apple AirDrop and Google Quick Share wireless file transfer features on iOS, macOS, and Android devices. Specific affected versions not disclosed. Attack requires physical proximity (wireless range).
highbug_reportVulnerabilityApple Beats Studio Buds Bluetooth flaw allows unauthorized pairing
Apple Beats Studio Buds using Airoha Bluetooth audio SDK. Vulnerability affects devices prior to firmware update released by Apple. Attackers must be within Bluetooth range (typically <10 meters).