Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
6 / 6 results
highperson_alertThreat ActorWeedhack Malware Targets Gamers via Fake Minecraft Clients and SEO
Weedhack is a malware family (not a named threat actor group) actively distributed through fake Minecraft client websites and SEO poisoning campaigns. The operators behind Weedhack remain unattributed.
highbug_reportVulnerabilityFake Xeno Executor installers infect Roblox players with RAT malware
Roblox players downloading fake Xeno Executor script launcher installers from gaming forums, Discord communities, and compromised accounts. Campaign active since January 2026 with sharp increase in March.
highperson_alertThreat ActorClickFix Abuses Steam Forums to Deliver XMRig Cryptominer
ClickFix is a threat actor conducting social engineering campaigns that leverage fake technical support content to distribute malware. The actor exploits user trust in community-driven platforms, specifically targeting gaming communities through Stea…
highbug_reportVulnerabilityTrojanized NuGet package targets Digitain betting platform via typosquatting
NuGet package "Newtonsoftt.Json.Net" versions 11.0.4, 11.0.5, 11.0.7, 11.0.8, 11.0.9, 11.0.10, and 11.0.11 (typosquat of Newtonsoft.Json). Primary target: Digitain FG-Crash betting game backend. Downloaded ~1,200 times.
criticalbug_reportVulnerabilityDigiCert breach linked to Chinese APT; code-signing certs stolen
DigiCert certificate authority infrastructure compromised in April 2026. Code-signing certificates stolen by CylindricalCanine (GoldenEyeDog/APT-Q-27 subgroup).
highbug_reportVulnerabilityMalware campaign abuses Steam Workshop via Wallpaper Engine packages
Valve Steam Workshop users, specifically those using Wallpaper Engine application. All versions of Wallpaper Engine that integrate with Steam Workshop are potentially affected. Scope includes users downloading community-created wallpaper content.