Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
21 / 21 results
highbug_reportVulnerabilityMalicious npm and PyPI packages impersonate Paysafe payment SDKs
Developers using npm and PyPI repositories who may have installed counterfeit packages impersonating Paysafe, Skrill, and Neteller payment SDKs. Affects development environments and potentially downstream applications integrating these malicious pack…
highbug_reportVulnerabilityRedWing Android MaaS enables bank fraud via credential theft
Android devices targeted by RedWing malware, distributed as Malware-as-a-Service on Telegram. Variant of Oblivion MaaS. Primarily affects banking applications and users with compromised devices.
highbug_reportVulnerabilityOusaban banking trojan targets Spain and Portugal via phishing
Windows users in Spain and Portugal. Ousaban banking trojan campaign using fake PDF lures with geolocation filtering and steganography techniques. No specific product vulnerability; threat actor campaign identified by Fortinet FortiGuard Labs in May…
highperson_alertThreat ActorSilent Swap Campaign Targets Cryptocurrency via Malicious Browser Extensions
Silent Swap is an active cybercrime campaign leveraging malicious browser extensions to conduct cryptocurrency theft. The operation distributes unsigned installers written in both .NET and Golang variants, masquerading as a legitimate Google Notes br…
highperson_alertThreat ActorPre-Planned Fraud Campaign Targets FIFA World Cup 2026 Across Sectors
The threat actor behind this campaign remains unattributed. Motivation appears financially driven, leveraging the global interest in FIFA World Cup 2026 to conduct fraud operations.
highbug_reportVulnerability236K+ malicious sites use DCloud Uni-App templates for crypto scams
Organizations and users interacting with websites built using DCloud Uni-App framework templates. Over 236,000 malicious sites identified conducting cryptocurrency scams, phishing, wallet draining, pig-butchering schemes, and fake gambling platforms.
highbug_reportVulnerabilityPolymarket frontend compromised via third-party vendor; $3M stolen
Polymarket platform users. Attack vector: malicious JavaScript injected into frontend via compromised third-party vendor. Approximately $3 million in customer funds stolen. No CVE assigned.
highbug_reportVulnerabilityClipboard-stealing malware spreads via USB, targets crypto wallets
Windows systems with USB connectivity. Targets cryptocurrency wallet users. No specific vendor or product vulnerability; relies on user interaction with malicious Windows shortcut (.lnk) files on removable media.
highbug_reportVulnerabilityWindows cryptocurrency clipper campaign uses USB worms and Tor C2
Windows systems with Windows Script Host and ActiveX enabled. Campaign active since February 2026 targeting cryptocurrency users via USB-based LNK worm propagation.
highbug_reportVulnerabilityCryptocurrency clipper malware with worm propagation targets Windows
Windows systems globally. No specific product vulnerability; threat relies on social engineering, malicious downloads, or lateral movement. All cryptocurrency wallet users on Windows are potential targets.
highbug_reportVulnerabilityRokarolla Android banking trojan targets 217 banking and crypto apps
Android devices with 217 targeted banking and cryptocurrency applications. Malware features 137 commands for comprehensive device control and data exfiltration. Specific app list and Android version scope not disclosed.
highperson_alertThreat ActorFBI disrupts Outsider Enterprise Chinese phishing-as-a-service platform
Outsider Enterprise is a Chinese phishing-as-a-service (PhaaS) operation disrupted by the FBI in coordination with Google and Black Lotus Labs. The actor operated thousands of phishing websites designed to harvest credit card data and passwords from…
highbug_reportVulnerabilityNFCShare Android malware distributed via GitHub as fake banking app updates
Android mobile users, particularly customers of targeted banking applications. Malware distributed through GitHub repositories posing as legitimate banking app updates.
highperson_alertThreat ActorUNC3753 Conducts Data Theft Extortion via Vishing and Physical Intrusion
UNC3753 is a financially motivated threat actor attributed by Mandiant. The group conducted a data theft extortion campaign targeting dozens of organizations in the United States between January and May 2026.
highperson_alertThreat ActorFBI Warns of FIFA World Cup 2026 Fraud Campaign with Banking Malware
This is a cybercrime campaign leveraging the FIFA World Cup 2026 tournament as a lure, rather than a single named threat actor. The campaign involves multiple financially motivated threat actors exploiting public interest in the tournament to distrib…
highpublicGeopoliticalUS national sentenced for selling 7M elderly records to Jamaican fraudsters
This case illustrates the transnational nature of cybercrime and data exploitation, where domestic actors facilitate cross-border fraud schemes targeting vulnerable populations.
highbug_reportVulnerabilityMalicious NuGet package "Sicoob.Sdk" steals banking credentials
NuGet package "Sicoob.Sdk" versions 2.0.0 through 2.0.4. Targets developers integrating with Sicoob (Brazilian cooperative banking system). Affects .NET development environments where the malicious package was installed.
highperson_alertThreat ActorFBI warns of FIFA-impersonating fraud sites targeting 2026 World Cup
Unknown fraud operators are conducting financially motivated cybercrime campaigns targeting fans and consumers interested in the 2026 FIFA World Cup. These actors leverage social engineering and brand impersonation tactics to establish fraudulent web…
highbug_reportVulnerabilityBanking trojans Grandoreiro and BTMOB target LATAM and Europe
Windows and Android devices in Latin America (Brazil, Mexico) and Europe (Spain, Portugal). Grandoreiro targets Windows systems at companies; BTMOB RAT targets Android mobile users in Brazil.
highperson_alertThreat ActorLazarus Group deploys RemotePE cross-platform RAT against finance sector
Lazarus Group is a North Korean state-sponsored advanced persistent threat (APT) actor attributed to the Reconnaissance General Bureau (RGB). The group is financially motivated, conducting operations to generate revenue for the DPRK regime through th…
highbug_reportVulnerabilityKieback & Peter DDC controllers vulnerable to XSS attacks
Kieback & Peter DDC (Direct Digital Control) Building Controllers. Specific affected versions not disclosed in available data.