Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 420 results
Active filter:tag: #geopolitical✕ clear
FulcrumSec claims 86 GB Manchester Airports Group data thefthighperson_alertThreat Actor
person_alertThreat Actor

FulcrumSec claims 86 GB Manchester Airports Group data theft

FulcrumSec is a financially motivated data-extortion group active since 2025. The group specializes in stealing sensitive corporate data and threatening to publish it rather than deploying ransomware or encrypting victim systems.

Manchester Airports Group30 Aug · 13:00 UTC
Berlin refuses ransom demand after Rhysida-linked breach of state networkhighpublicGeopolitical
publicGeopolitical

Berlin refuses ransom demand after Rhysida-linked breach of state network

The August 2026 compromise of Berlin's state administrative network represents a significant escalation in ransomware targeting of European critical infrastructure and government services.

The Hacker News28 Aug · 19:30 UTC
ownCloud CVE-2023-49105 exploited to steal nuclear records from Philippinescriticalbug_reportVulnerability
bug_reportVulnerability

ownCloud CVE-2023-49105 exploited to steal nuclear records from Philippines

ownCloud core versions 10.6.0 through 10.13.0. The vulnerability is a WebDAV API authentication bypass allowing unauthenticated file access when usernames are known and no signing-key is configured (default state). Fixed in version 10.13.1.

CVE-2023-4910528 Aug · 13:56 UTC
WatchGuard Fireware OS vulnerabilities require immediate patchinghighbug_reportVulnerability
bug_reportVulnerability

WatchGuard Fireware OS vulnerabilities require immediate patching

WatchGuard Fireware OS - specific versions not provided in advisory. Affects WatchGuard firewall appliances running vulnerable Fireware OS versions.

WatchGuard28 Aug · 13:08 UTC
ZBT routers ship with factory implants granting root access via networkcriticalbug_reportVulnerability
bug_reportVulnerability

ZBT routers ship with factory implants granting root access via network

ZBT (Shenzhen Zhibotong Electronics) routers and white-labeled variants. CVE-2026-74233 (DARKLANTERN) affects 16+ models including WE1326, WE826-T2, WE5926, WG3526 on firmware builds from 2019-2020.

CVE-2026-7423228 Aug · 08:58 UTC
Manchester Airports Group breach exposes traveler data across UK hubshighpublicGeopolitical
publicGeopolitical

Manchester Airports Group breach exposes traveler data across UK hubs

The breach of Manchester Airports Group—the UK's largest airport operator handling over 66 million passengers annually—represents a significant incident within critical national infrastructure.

Manchester Airports Group27 Aug · 14:12 UTC
Apache Log4j2 deserialization filter bypass enables remote code executioncriticalbug_reportVulnerability
bug_reportVulnerability

Apache Log4j2 deserialization filter bypass enables remote code execution

Apache Log4j2 logging library. Specific affected versions not disclosed in available information. Impacts Java applications using Log4j2 with deserialization features enabled.

Apache27 Aug · 12:57 UTC
Veeam ONE authentication bypass requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Veeam ONE authentication bypass requires immediate patching

Veeam ONE backup management platform. Specific affected versions not disclosed in available information. Authentication bypass vulnerability allows unauthorized access.

Veeam27 Aug · 12:51 UTC
Australia arrests two TeamPCP members behind global supply chain attackshighbug_reportVulnerability
bug_reportVulnerability

Australia arrests two TeamPCP members behind global supply chain attacks

Over 1,000 organizations worldwide affected by supply chain attacks targeting open-source software and developer platforms. Confirmed victims include Trivy, LiteLLM, Telnyx, SAP, TanStack packages, European Commission, Mistral AI, OpenAI, and GitHub.…

BleepingComputer27 Aug · 11:31 UTC
NCSC warns of increased targeting of internet-exposed OT systems globallyhighbug_reportVulnerability
bug_reportVulnerability

NCSC warns of increased targeting of internet-exposed OT systems globally

Organizations with operational technology (OT) systems exposed to the internet across multiple sectors globally, including UK critical national infrastructure and non-CNI sectors.

NCSC UK27 Aug · 10:00 UTC
TeamPCP supply chain attack compromised Trivy, KICS, LiteLLM; 1000+ orgs hitcriticalbug_reportVulnerability
bug_reportVulnerability

TeamPCP supply chain attack compromised Trivy, KICS, LiteLLM; 1000+ orgs hit

Open-source tools: Trivy scanner, Checkmarx KICS, LiteLLM AI gateway. Attack spanned GitHub Actions, Docker Hub, npm, PyPI, OpenVSX ecosystems. Over 1,000 organizations potentially compromised, 500,000+ credentials stolen, 300GB+ data exfiltrated.

Trivy27 Aug · 09:56 UTC
Australian police arrest two TeamPCP members behind supply chain attackshighbug_reportVulnerability
bug_reportVulnerability

Australian police arrest two TeamPCP members behind supply chain attacks

Global software supply chain: hundreds of open-source packages on GitHub, NPM, and other repositories compromised since late 2023. Victims include 2,500+ organizations using LiteLLM AI gateway, 3,800+ GitHub repositories, and developers across major…

Krebs on Security27 Aug · 09:04 UTC
Spark RAT campaign targets Cambodia via OPSWAT driver exploithighbug_reportVulnerability
bug_reportVulnerability

Spark RAT campaign targets Cambodia via OPSWAT driver exploit

Organizations and individuals in Cambodia. Campaign abuses vulnerable OPSWAT AppRemover driver (ardrv.sys, CVE-2026-36425) via BYOVD technique. Targets systems running Microsoft Defender, Huorong Internet Security, Tencent PC Manager, and Qihoo 360.

OPSWAT27 Aug · 09:00 UTC
Dark Caracal deploys Go-based GoCaracal malware in Venezuela telecomhighperson_alertThreat Actor
person_alertThreat Actor

Dark Caracal deploys Go-based GoCaracal malware in Venezuela telecom

Dark Caracal (G0070) is a threat actor with a documented history of operations in Latin America since at least 2018. Arctic Wolf attributes the June 2026 GoCaracal intrusion to Dark Caracal with medium confidence based on multiple behavioral and tech…

The Hacker News27 Aug · 07:33 UTC
CISA orders federal agencies to patch exploited Citrix NetScaler RCE by Aug 29criticalbug_reportVulnerability
bug_reportVulnerability

CISA orders federal agencies to patch exploited Citrix NetScaler RCE by Aug 29

Citrix NetScaler ADC and NetScaler Gateway appliances with Gateway VPN or AAA virtual server configurations. CVE-2026-8452 (high severity). Over 22,000 NetScaler ADC and 1,800 Gateway instances exposed online globally.

Citrix27 Aug · 07:16 UTC
GPUThor Rowhammer defeats ECC on NVIDIA RTX A6000, enables root escalationhighbug_reportVulnerability
bug_reportVulnerability

GPUThor Rowhammer defeats ECC on NVIDIA RTX A6000, enables root escalation

NVIDIA Ampere workstation GPUs with GDDR6 memory: RTX A6000 (48GB), RTX A5000 (24GB), RTX A4500 (20GB), RTX A4000 (16GB). Attack requires unprivileged CUDA kernel execution. Other NVIDIA GPUs tested (A10, L4, L40, RTX 4090, A30) showed no bit flips.

NVIDIA27 Aug · 06:13 UTC
WatchGuard Agent RCE flaws require immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

WatchGuard Agent RCE flaws require immediate patching

WatchGuard Agent (specific versions not disclosed in available data). Remote code execution vulnerabilities affecting WatchGuard Agent software used for endpoint management and authentication.

WatchGuard27 Aug · 04:36 UTC
DoJ Disrupts QTFY Chinese State-Sponsored Infrastructure Targeting U.S.highperson_alertThreat Actor
person_alertThreat Actor

DoJ Disrupts QTFY Chinese State-Sponsored Infrastructure Targeting U.S.

QTFY is a Chinese state-sponsored threat actor employed by Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司), active since May 2018. The group functions as a digital quartermaster serving China's Ministry of State Security (MSS) and People…

U.S. critical infrastructure operators26 Aug · 14:42 UTC
Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoorhighperson_alertThreat Actor
person_alertThreat Actor

Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor

Nimbus Manticore is an Iranian state-sponsored APT group affiliated with the Islamic Revolutionary Guard Corps (IRGC). Also tracked as GalaxyGato, Mirage Kitten, Screening Serpens, Smoke Sandstorm, Subtle Snail, and UNC1549, the group is assessed to…

The Hacker News26 Aug · 13:35 UTC
Boston Scientific cyberattack disrupts global medical device operationshighpublicGeopolitical
publicGeopolitical

Boston Scientific cyberattack disrupts global medical device operations

The cyberattack on Boston Scientific, one of the world's largest medical device manufacturers with operations in 127 countries and over $20 billion in annual revenue, underscores the persistent vulnerability of critical healthcare supply chains to cy…

Boston Scientific26 Aug · 13:19 UTC
FBI disrupts QTFY quartermaster infrastructure for Chinese espionagehighperson_alertThreat Actor
person_alertThreat Actor

FBI disrupts QTFY quartermaster infrastructure for Chinese espionage

QTFY (also tracked as QT, QTCYBER) is a China-based threat actor operating as a technical "quartermaster" providing reconnaissance, proxy management, and operational routing capabilities for Chinese cyber espionage operations.

BleepingComputer26 Aug · 12:17 UTC
INTERPOL Operation Jackal IV Targets Black Axe and West African Crimehighperson_alertThreat Actor
person_alertThreat Actor

INTERPOL Operation Jackal IV Targets Black Axe and West African Crime

Black Axe and associated West African organized crime groups are transnational criminal networks responsible for a significant share of global cyber-enabled financial fraud.

The Hacker News26 Aug · 05:54 UTC
LACMA discloses 2025 breach exposing SSNs and health datahighpublicGeopolitical
publicGeopolitical

LACMA discloses 2025 breach exposing SSNs and health data

The Los Angeles County Museum of Art breach represents a typical example of the persistent threat to U.S. cultural and public institutions from cybercriminal activity.

Los Angeles County Museum of Art (LACMA)25 Aug · 19:58 UTC
BEC fraud campaign surges against Austrian orgs via impersonationhighbug_reportVulnerability
bug_reportVulnerability

BEC fraud campaign surges against Austrian orgs via impersonation

Austrian organizations across all sectors; targets finance, accounting, and HR departments. Attack vectors include email impersonation, compromised supplier accounts, and hijacked email threads. No specific product vulnerabilities exploited.

CERT.at (Austria)25 Aug · 18:04 UTC
U.S. Sanctions Iran-Linked MOIS Cyber Actors for Infrastructure Attackshighperson_alertThreat Actor
person_alertThreat Actor

U.S. Sanctions Iran-Linked MOIS Cyber Actors for Infrastructure Attacks

Iran-linked cyber actors affiliated with Iran's Ministry of Intelligence and Security (MOIS), specifically members of the Tehran-based Mabna Institute. The group conducts cyber espionage operations in support of Iran's political objectives, including…

The Hacker News25 Aug · 16:17 UTC
DDoS campaign disrupts Norway's shared government digital infrastructurehighbug_reportVulnerability
bug_reportVulnerability

DDoS campaign disrupts Norway's shared government digital infrastructure

Norway's Digitaliseringsdirektoratet (Digdir) shared government infrastructure, including ID-porten (public login), eSignering (electronic signatures), secure digital mail, government forms, and data exchange services.

BleepingComputer25 Aug · 13:52 UTC
OAuth2 Proxy authentication bypass allows unauthorized accesscriticalbug_reportVulnerability
bug_reportVulnerability

OAuth2 Proxy authentication bypass allows unauthorized access

OAuth2 Proxy (specific versions not disclosed in available data). All deployments using OAuth2 Proxy for authentication are potentially at risk.

OAuth2 Proxy25 Aug · 13:03 UTC
Oracle critical vulnerability under active exploitation, patching urgentcriticalbug_reportVulnerability
bug_reportVulnerability

Oracle critical vulnerability under active exploitation, patching urgent

Multiple Oracle products affected. Specific product names, versions, and CVE identifiers not disclosed in available advisory. CERT.BE warning indicates at least one critical-severity vulnerability among multiple flaws.

Oracle25 Aug · 11:51 UTC
Mirage2FA Campaign Hits 4,500 Orgs via Microsoft 365 AiTM Phishinghighperson_alertThreat Actor
person_alertThreat Actor

Mirage2FA Campaign Hits 4,500 Orgs via Microsoft 365 AiTM Phishing

Mirage2FA is a commercial phishing-as-a-service (PhaaS) campaign active from 2024 to 2026, targeting Microsoft 365 accounts through adversary-in-the-middle (AiTM) techniques.

Microsoft25 Aug · 09:56 UTC
African Crime Groups Targeted in 22-Country Cybercrime Crackdownhighperson_alertThreat Actor
person_alertThreat Actor

African Crime Groups Targeted in 22-Country Cybercrime Crackdown

African crime groups, particularly West African criminal networks and the Black Axe cybercrime syndicate, are financially-motivated threat actors conducting global-scale cyber-enabled financial fraud.

BleepingComputer25 Aug · 08:53 UTC