Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

6 / 6 results
Active filter:tag: #gaming✕ clear
Weedhack Malware Targets Gamers via Fake Minecraft Clients and SEOhighperson_alertThreat Actor
person_alertThreat Actor

Weedhack Malware Targets Gamers via Fake Minecraft Clients and SEO

Weedhack is a malware family (not a named threat actor group) actively distributed through fake Minecraft client websites and SEO poisoning campaigns. The operators behind Weedhack remain unattributed.

Minecraft24 Aug · 15:41 UTC
Fake Xeno Executor installers infect Roblox players with RAT malwarehighbug_reportVulnerability
bug_reportVulnerability

Fake Xeno Executor installers infect Roblox players with RAT malware

Roblox players downloading fake Xeno Executor script launcher installers from gaming forums, Discord communities, and compromised accounts. Campaign active since January 2026 with sharp increase in March.

BleepingComputer3 Aug · 17:25 UTC
ClickFix Abuses Steam Forums to Deliver XMRig Cryptominerhighperson_alertThreat Actor
person_alertThreat Actor

ClickFix Abuses Steam Forums to Deliver XMRig Cryptominer

ClickFix is a threat actor conducting social engineering campaigns that leverage fake technical support content to distribute malware. The actor exploits user trust in community-driven platforms, specifically targeting gaming communities through Stea…

Steam25 Jul · 20:37 UTC
Trojanized NuGet package targets Digitain betting platform via typosquattinghighbug_reportVulnerability
bug_reportVulnerability

Trojanized NuGet package targets Digitain betting platform via typosquatting

NuGet package "Newtonsoftt.Json.Net" versions 11.0.4, 11.0.5, 11.0.7, 11.0.8, 11.0.9, 11.0.10, and 11.0.11 (typosquat of Newtonsoft.Json). Primary target: Digitain FG-Crash betting game backend. Downloaded ~1,200 times.

Newtonsoft22 Jul · 04:00 UTC
DigiCert breach linked to Chinese APT; code-signing certs stolencriticalbug_reportVulnerability
bug_reportVulnerability

DigiCert breach linked to Chinese APT; code-signing certs stolen

DigiCert certificate authority infrastructure compromised in April 2026. Code-signing certificates stolen by CylindricalCanine (GoldenEyeDog/APT-Q-27 subgroup).

DigiCert17 Jul · 14:39 UTC
Malware campaign abuses Steam Workshop via Wallpaper Engine packageshighbug_reportVulnerability
bug_reportVulnerability

Malware campaign abuses Steam Workshop via Wallpaper Engine packages

Valve Steam Workshop users, specifically those using Wallpaper Engine application. All versions of Wallpaper Engine that integrate with Steam Workshop are potentially affected. Scope includes users downloading community-created wallpaper content.

Valve16 Jun · 16:27 UTC