Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
28 / 28 results
highbug_reportVulnerabilityNCSC warns of increased targeting of internet-exposed OT systems globally
Organizations with operational technology (OT) systems exposed to the internet across multiple sectors globally, including UK critical national infrastructure and non-CNI sectors.
highperson_alertThreat ActorDoJ Disrupts QTFY Chinese State-Sponsored Infrastructure Targeting U.S.
QTFY is a Chinese state-sponsored threat actor employed by Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司), active since May 2018. The group functions as a digital quartermaster serving China's Ministry of State Security (MSS) and People…
highperson_alertThreat ActorU.S. Sanctions Iran-Linked MOIS Cyber Actors for Infrastructure Attacks
Iran-linked cyber actors affiliated with Iran's Ministry of Intelligence and Security (MOIS), specifically members of the Tehran-based Mabna Institute. The group conducts cyber espionage operations in support of Iran's political objectives, including…
highperson_alertThreat ActorAI-Generated Exploits Target Siemens S7 PLCs in U.S. Critical Infrastructure
This campaign involves unattributed threat actors leveraging artificial intelligence to generate exploitation scripts targeting industrial control systems.
highperson_alertThreat ActorAI-Generated Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure
No specific threat actor or group has been attributed to this campaign. The advisory describes ongoing activity by unidentified threat actors targeting Siemens S7 Series programmable logic controllers in U.S. critical infrastructure.
criticalbug_reportVulnerabilityWindows IKE Extension RCE (CVE-2026-33824) actively exploited
All supported Windows 10, Windows 11, and Windows Server versions. The vulnerability affects the Windows Internet Key Exchange (IKE) Service Extensions (MS-IKEE) component accessible via UDP ports 500 and 4500.
criticalperson_alertThreat ActorMedusa Ransomware Gang Breaches 500+ US Critical Infrastructure Orgs
Medusa is a ransomware operation active since January 2021 that evolved from a closed ransomware variant into a Ransomware-as-a-Service (RaaS) model with an affiliate program.
highperson_alertThreat ActorIranian Cavern C2 Framework Evolves with DNS and Google Apps Script Relay
Cavern (aka Cav3rn) is a command-and-control framework attributed to Iranian nation-state threat actors, specifically linked to Cavern Manticore, a hacking group affiliated with Iran's Ministry of Intelligence and Security (MOIS).
criticalbug_reportVulnerabilityCisco Secure Firewall DoS flaw under active exploitation
Cisco Secure Firewall products (specific versions not disclosed in available data). Organizations using Cisco ASA, FTD, or Firepower appliances should assume exposure until vendor advisory is reviewed.
highpublicGeopoliticalCyberattack disrupts North Carolina port operations, critical infrastructure
The incident at North Carolina Ports Authority facilities represents a significant disruption to U.S. critical maritime infrastructure. Port of Wilmington and Port of Morehead City together constitute key logistics nodes on the U.S.
highbug_reportVulnerability4,407 Rockwell PLCs exposed online; 22 in cities hit by water attacks
Rockwell Automation programmable logic controllers (PLCs) globally: 4,407 exposed devices (2,844 in US). Primary models: MicroLogix 1400 (50%) and MicroLogix 1100 (8%).
highbug_reportVulnerabilityCISA warns of rising attacks on internet-exposed PLCs in water systems
Internet-exposed programmable logic controllers (PLCs) in U.S. water and wastewater systems. Specific vendors and models not disclosed in available information.
criticalbug_reportVulnerabilityCisco Secure Firewall Management Center under active exploitation
Cisco Secure Firewall Management Center (formerly Firepower Management Center). Specific affected versions not disclosed in available data. Vulnerability details including CVE identifier not yet published.
highbug_reportVulnerabilityCoordinated OT attack disrupts 30+ Minnesota water systems
Over 30 community water systems in Minnesota. Operational technology (OT) systems at local water utilities targeted, including programmable logic controllers and computerized operating systems. Attacks occurred July 26-27, 2026. Threat actor unknown.
highbug_reportVulnerabilityCoordinated attack hits 30+ Minnesota water systems, causes plant outages
Over 30 Minnesota community water systems targeted July 26-27, 2026. Operational technology (OT) infrastructure affected, including programmable logic controllers (PLCs) and human-machine interfaces (HMIs) at water treatment and wastewater facilities…
highperson_alertThreat ActorJackSkid Adopts Blockchain C2 and Relay Mesh After March Takedown
JackSkid is an IoT botnet operator linked to the Dysphoria botnet family, targeted in coordinated U.S., German, and Canadian law enforcement actions on March 19, 2026.
highperson_alertThreat ActorRussian Intelligence Services Exploit Security Cameras for Military Surveillance
Russian intelligence services are conducting a systematic cyber-espionage campaign targeting internet-connected security cameras across Europe and Ukraine.
criticalbug_reportVulnerabilityCISA adds CVE-2023-4346 KNX Protocol flaw to KEV catalog
KNX Protocol implementations used in building automation and smart home systems. Specific affected products and versions not disclosed in available information.
highpublicGeopoliticalDHS Confirms Breach of Homeland Security Information Network
The compromise of the Homeland Security Information Network (HSIN) represents a significant breach of a critical federal information-sharing infrastructure.
highperson_alertThreat ActorCL-STA-1062 deploys TinyRCT backdoor against Southeast Asian government
CL-STA-1062 is a Chinese-speaking APT actor conducting targeted cyber espionage operations against government entities and critical infrastructure in Southeast Asia.
highperson_alertThreat ActorCL-STA-1062 targets Southeast Asian government with TinyRCT backdoor
CL-STA-1062 is a threat actor conducting cyber espionage operations against government entities and critical infrastructure in Southeast Asia. The actor employs a hybrid toolkit centered around a custom backdoor known as TinyRCT.
highperson_alertThreat ActorScattered Spider Members Plead Guilty to Transport for London Breach
Scattered Spider (G1015), also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944, is a financially motivated cybercrime group known for sophisticated social engineering and identity-based attacks.
highpublicGeopoliticalCISA warns of 74,000 Fortinet credentials exposed in FortiBleed leak
The exposure of approximately 74,000 Fortinet firewall and VPN credentials represents a significant supply-side vulnerability affecting critical infrastructure globally.
highbug_reportVulnerability900+ US fuel tank monitoring systems exposed online, vulnerable to attack
Over 900 automatic tank gauge (ATG) systems in the United States used to monitor fuel and chemical storage tanks in critical infrastructure. Specific vendors and product versions not disclosed.
highperson_alertThreat ActorGREYVIBE: Russian-linked APT targeting Ukraine since August 2025
GREYVIBE is a previously undocumented threat actor attributed by WithSecure as Russian-linked, assessed to operate in support of Kremlin state interests. The group is characterized as Russian-speaking and operates within Russian time zones.
highbug_reportVulnerabilityAnthropic Glasswing project finds 10,000+ critical flaws in key software
Widely used, systemically important software (specific products not disclosed). Over 10,000 high- or critical-severity vulnerabilities identified since project launch last month.
criticalbug_reportVulnerabilitySonicWall Gen6 SSL-VPN exploited for credential brute-force and MFA bypass
SonicWall Gen6 SSL-VPN appliances with incomplete patching. Specific firmware versions not disclosed. Affects organizations using SonicWall SSL-VPN for remote access.
highbug_reportVulnerability3onedata GW1101 Modbus gateway vulnerable to OS command injection
3onedata GW1101-1D(RS-485)-TB-P Modbus gateways. Specific affected firmware versions not disclosed. These are industrial IoT devices used for Modbus protocol conversion in OT/ICS environments.