Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
14 / 14 results
highperson_alertThreat ActorGambling Goblin Hijacks Brazilian Gov Sites via Malicious Apache Modules
Gambling Goblin is a Chinese-speaking cybercrime cluster tracked by Check Point Research since mid-2025. The group specializes in SEO manipulation at scale by compromising high-reputation domains, particularly Brazilian government (.gov.br) and educa…
highperson_alertThreat ActorUAT-10147 Deploys AI-Assisted Attacks and SPECTRE Malware Globally
UAT-10147 is a Chinese-speaking cybercrime group conducting large-scale attacks against Windows and Linux web servers globally. The actor's primary motivation appears to be SEO fraud and data theft.
highperson_alertThreat ActorJadeProx Deploys TriBack Loader Against Asian, Latin American Targets
JadeProx is a China-nexus threat actor tracked by Group-IB, discovered through an exposed Alibaba Cloud server in Singapore in mid-April 2026. The actor targets government, healthcare, and education organizations across Asia and Latin America.
highperson_alertThreat ActorChina-Linked Cluster Exploits Roundcube at Universities
This China-linked threat cluster targets academic institutions in North America, focusing on credential theft and persistent access through exploitation of vulnerable Roundcube webmail servers.
highperson_alertThreat ActorChina-Aligned Cluster Exploits Roundcube Flaws at Universities
This activity cluster is attributed to China-aligned threat actors targeting academic institutions in North America. The group demonstrates a clear strategic interest in research and development sectors, specifically physics and engineering departmen…
highperson_alertThreat ActorKongTuke Deploys Mistic Backdoor in Multi-Sector Financial Attacks
KongTuke is an initial access broker (IAB) conducting financially motivated operations targeting organizations across insurance, education, IT, and professional services sectors.
highperson_alertThreat ActorKongTuke Deploys Mistic Backdoor in Multi-Sector Intrusions
KongTuke is a financially motivated threat actor operating as a ransomware access broker. The group specializes in gaining initial access to corporate networks and establishing persistent backdoor access, which is then sold or provided to ransomware…
highbug_reportVulnerabilityClickFix campaigns deploy three malware loaders via fake updates
Education and financial sector organizations targeted by ClickFix social engineering campaigns delivering BabaDeda Loader, Lorem Ipsum Loader, and Potemkin malware loaders through fake software update lures.
highperson_alertThreat ActorShinyHunters Breaches 137K+ School Staff via Salesforce Attack
ShinyHunters is a financially motivated cybercrime actor specializing in large-scale data theft and extortion operations. The group has established a reputation for targeting cloud-based platforms and third-party service providers to compromise downs…
highpublicGeopoliticalFormer Iowa school IT employee sentenced for insider cyberattack
This incident represents a domestic insider threat case within the United States education sector, rather than a state-sponsored or geopolitically motivated cyberattack. The prosecution and sentencing reflect U.S.
criticalbug_reportVulnerabilityOracle PeopleSoft zero-day CVE-2026-35273 exploited by ShinyHunters
Oracle PeopleSoft (all versions prior to June 10 patch). Confirmed exploitation targeting enterprise systems and universities. Vulnerability was unpatched during active exploitation window (May 27 - June 9).
criticalbug_reportVulnerabilityZero-day in KnowledgeDeliver LMS exploited to deploy Godzilla web shell
KnowledgeDeliver learning management system (specific versions unknown). Exploitation results in web shell deployment enabling persistent remote access to affected servers.
highperson_alertThreat ActorMuddyWater Q1 2026 espionage campaign hits nine countries via DLL side-loading
MuddyWater (also tracked as Earth Vetala, MERCURY, Static Kitten, and Seedworm) is an Iranian state-sponsored APT group attributed to Iran's Ministry of Intelligence and Security (MOIS).
highbug_reportVulnerabilityDigital Knowledge LMS exploited via hardcoded ASP.NET keys (CVE-2026-5426)
Digital Knowledge KnowledgeDeliver LMS (specific versions not disclosed). Vulnerability stems from hard-coded ASP.NET machine keys enabling authentication bypass and remote code execution.