Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 239 results
criticalbug_reportVulnerabilityDigiCert breach linked to Chinese APT; code-signing certs stolen
DigiCert certificate authority infrastructure compromised in April 2026. Code-signing certificates stolen by CylindricalCanine (GoldenEyeDog/APT-Q-27 subgroup).
highperson_alertThreat ActorLazarus Deploys OtterCookie via Fake Job Lures in Contagious Interview
Lazarus is a North Korean state-sponsored advanced persistent threat (APT) group attributed to the Reconnaissance General Bureau (RGB). The group is financially motivated, conducting operations to generate revenue for the DPRK regime through cryptocu…
highperson_alertThreat ActorArmenia Detains Russian National on U.S. REvil Ransomware Warrant
REvil (also known as Sodinokibi) is a Russia-linked ransomware-as-a-service (RaaS) operation that emerged in 2019 and became one of the most prolific cybercrime groups before law enforcement disruption in 2021-2022.
highperson_alertThreat ActorGoSerpent Malware Targets Southeast Asian Government and Diplomacy
GoSerpent is a previously undocumented malware family discovered by Kaspersky researchers in late 2025. The malware is designed for long-term persistent access and intelligence gathering operations.
criticalbug_reportVulnerabilityCISA orders patching of actively exploited Fortinet FortiSandbox flaws
Fortinet FortiSandbox threat detection platform. Specific versions not provided in available data. Two vulnerabilities confirmed, CVE identifiers not yet disclosed.
criticalbug_reportVulnerabilityCISA: Microsoft SharePoint RCE CVE-2026-58644 actively exploited
Microsoft SharePoint Server (specific versions not disclosed). CVSS 9.8 critical remote code execution vulnerability.
highpublicGeopoliticalMount Royal University in Calgary confirms data breach and deletion
The breach of Mount Royal University represents a typical pattern in the current cyber threat landscape affecting higher education institutions across North America.
highperson_alertThreat ActorChina-Linked Cluster Exploits Roundcube at Universities
This China-linked threat cluster targets academic institutions in North America, focusing on credential theft and persistent access through exploitation of vulnerable Roundcube webmail servers.
highperson_alertThreat ActorEvilTokens Ghost Phishing Campaign Targets US and European Businesses
EvilTokens is a campaign leveraging "ghost phishing" techniques to target business entities across the United States and Europe. The campaign's primary motivation appears to be credential theft and unauthorized access to Microsoft 365 environments, w…
highperson_alertThreat ActorREF6045 targets Mexican banking sector with SCMBANKER via ClickFix lures
REF6045 is a financially motivated threat actor conducting banking fraud operations against Mexican financial institutions and their customers. The actor targets banking, fintech, and cryptocurrency exchange users in Mexico, leveraging social enginee…
highpublicGeopoliticalKDDI breach exposes 12M records across Japanese ISP ecosystem
The breach of KDDI, one of Japan's three major telecommunications carriers, represents a significant compromise of critical infrastructure in a key U.S. Indo-Pacific ally.
criticalbug_reportVulnerabilityCISA orders federal patch for exploited Langflow auth bypass by Friday
Langflow visual AI agent framework - specific versions not disclosed in summary. Federal agencies mandated to patch; private sector should assume all unpatched instances at risk.
highperson_alertThreat ActorUAT-7810 Expands ORB Network with LONGLEASH Malware on Edge Devices
UAT-7810 is a China-linked advanced persistent threat (APT) actor focused on compromising internet-facing networking and infrastructure devices to build and maintain an Operational Relay Box (ORB) network designated LapDogs.
criticalbug_reportVulnerabilityCISA orders patching of actively exploited Adobe ColdFusion flaw
Adobe ColdFusion commercial web application development platform. Specific affected versions not disclosed in summary, but CISA mandatory patching order indicates government-facing installations are priority targets.
highperson_alertThreat ActorUAT-7810 Deploys LONGLEASH Malware Against Network Infrastructure
UAT-7810 is a Chinese-linked threat actor focused on compromising internet-facing networking devices to expand their Operational Relay Box (ORB) network infrastructure.
highperson_alertThreat ActorScattered Spider Linked to U.S. Luxury Retail Breach via Device ID
Scattered Spider (also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944) is a financially motivated threat actor known for sophisticated social engineering and identity-focused attacks.
highperson_alertThreat ActorChina-Aligned Cluster Exploits Roundcube Flaws at Universities
This activity cluster is attributed to China-aligned threat actors targeting academic institutions in North America. The group demonstrates a clear strategic interest in research and development sectors, specifically physics and engineering departmen…
criticalbug_reportVulnerabilityTenda router backdoor allows admin access bypass (CVE-2026-11405)
Tenda routers running vulnerable firmware versions. Specific models and version ranges not disclosed in available data. Affects web management interface authentication mechanism.
highperson_alertThreat ActorIran-linked MOIS group deploys Cavern C2 framework against Israel
An Iranian threat actor affiliated with Iran's Ministry of Intelligence and Security (MOIS), tracked by Check Point Research. The group operates in support of Iranian state intelligence objectives, focusing on espionage operations against adversary n…
highperson_alertThreat ActorChina-nexus actor targets Indian finance sector via DcRAT malware
A suspected China-nexus threat actor is conducting Operation DragonReturn, a targeted espionage campaign against Indian taxpayers and finance professionals.
highperson_alertThreat ActorKairos extorts $1M from U.S. government via data theft without encryption
Kairos is a financially motivated threat actor that employs extortion tactics focused on data theft without deploying traditional ransomware encryption. The group targeted a U.S.
highbug_reportVulnerabilityNorth Korean actors deploy 108 malicious packages in PolinRider campaign
npm, Packagist (PHP), Go modules, and Google Chrome Web Store. 108 malicious packages and extensions published. Maintainer accounts actively compromised. Campaign linked to North Korean Contagious Interview threat group.
highbug_reportVulnerabilityNorth Korean actors deploy malicious npm packages to steal developer secrets
npm ecosystem: malicious packages "rollup-packages-polyfill-core" and "rollup-runtime-polyfill-core" impersonating legitimate "rollup-plugin-polyfill-node".
highperson_alertThreat ActorArmored Likho targets government and energy sectors with BusySnake
Armored Likho is a previously undocumented threat actor attributed by Kaspersky to cyber attacks targeting government agencies and the electric power sector.
highperson_alertThreat ActorNSO Group's Pegasus Targets EU Parliament Member Investigating Spyware
NSO Group is an Israeli-based commercial surveillance vendor that develops and sells the Pegasus spyware to government clients. The company markets its tools as lawful intercept solutions for counterterrorism and law enforcement, but has faced repeat…
highpublicGeopoliticalFBI seizes NetNut proxy domains linked to two-million-device botnet
The FBI's seizure of domains associated with NetNut, a residential proxy service operated by Israeli firm Alarum Technologies, represents a significant law enforcement action targeting the infrastructure enabling large-scale botnet operations.
highperson_alertThreat ActorNetNut (Popa) Residential Proxy Botnet Disrupted by Google, FBI
NetNut, also tracked as Popa, operates a residential proxy network built on approximately 2 million compromised home devices. The actor monetizes this infrastructure by selling proxy services that route malicious traffic through legitimate residentia…
highperson_alertThreat ActorScattered Spider Member Extradited to U.S. from Estonia
Scattered Spider (G1015), also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944, is a financially motivated threat actor collective known for sophisticated social engineering and identity-based attacks.
criticalbug_reportVulnerabilityMicrosoft SharePoint RCE flaw under active exploitation (CVE-2026-45659)
Microsoft SharePoint Server, all versions vulnerable to deserialization attacks. Specific affected versions not yet disclosed.
highpublicGeopoliticalKubota North America reports month-long network intrusion in 2024
The extended unauthorized access to Kubota North America's network systems highlights vulnerabilities in critical infrastructure sectors, particularly manufacturing and agriculture.