Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
12 / 12 results
highbug_reportVulnerability19 malicious Chrome/Edge extensions steal crypto wallets and credentials
Google Chrome and Microsoft Edge users who installed any of 19 malicious extensions, including "Enable Right Click & Copy" (70,000+ Chrome users, 10,000+ Edge users). Campaign active since early 2024.
highbug_reportVulnerabilityBEC fraud campaign surges against Austrian orgs via impersonation
Austrian organizations across all sectors; targets finance, accounting, and HR departments. Attack vectors include email impersonation, compromised supplier accounts, and hijacked email threads. No specific product vulnerabilities exploited.
highpublicGeopoliticalFrench tax authority breach exposes 678,000 records amid rising attacks
The breach of France's General Directorate of Public Finances (DGFiP) represents the latest in a sustained pattern of cyberattacks targeting French government infrastructure throughout 2026.
criticalbug_reportVulnerabilityMetabase SQL injection zero-day exploited to steal customer data
Metabase (specific versions not disclosed). Confirmed victims include Framework and Tally customer instances. All unpatched Metabase deployments potentially at risk.
highbug_reportVulnerabilityAitM phishing campaign targets Microsoft 365 for payroll email theft
Microsoft 365 accounts across healthcare, education, manufacturing, government, and professional services sectors in the U.S., Canada, and Europe. Hundreds of organizations targeted in July 2026, with focus on payroll, HR, and finance personnel.
highbug_reportVulnerabilityPhishing campaign exploits COLDCARD wallet fears to deploy ScreenConnect RAT
COLDCARD hardware wallet users targeted via phishing emails. Attack delivers ConnectWise ScreenConnect remote access tool via malicious batch file (Coldcard_Diagnostic_Tool.bat) hosted on GitHub.
highperson_alertThreat ActorChina-Linked Group Uses Cruciferra Crypter in Tax-Themed Phishing Campaigns
A China-linked cybercrime group, tracked as TA4922 by Proofpoint, has been conducting opportunistic phishing campaigns targeting Indian taxpayers, tax professionals, and corporate finance teams.
highperson_alertThreat ActorHermes AI Agent Used for Post-Exploitation at Thai Finance Ministry
The threat actor behind this intrusion remains unattributed. Hunt.io assesses with low-to-medium confidence that the operator is Chinese-speaking or fluent in Chinese, based on linguistic artifacts (password containing "Leishen," meaning thunder god)…
highperson_alertThreat ActorLazarus Deploys OtterCookie via Fake Job Lures in Contagious Interview
Lazarus is a North Korean state-sponsored advanced persistent threat (APT) group attributed to the Reconnaissance General Bureau (RGB). The group is financially motivated, conducting operations to generate revenue for the DPRK regime through cryptocu…
highperson_alertThreat ActorChina-nexus actor targets Indian finance sector via DcRAT malware
A suspected China-nexus threat actor is conducting Operation DragonReturn, a targeted espionage campaign against Indian taxpayers and finance professionals.
criticalbug_reportVulnerabilityOracle E-Business Suite under active exploit via CVE-2026-46817
Oracle E-Business Suite (EBS) financial application. Specific affected versions not disclosed in available intelligence.
criticalbug_reportVulnerabilityOracle PeopleSoft RCE actively exploited, immediate patching required
Oracle PeopleSoft (specific versions not disclosed in alert). Remote code execution vulnerability affecting internet-facing PeopleSoft instances.