Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-20 · 02:03 UTC
articleTotal: 593 reports

Filtered Reports

30 / 239 results
Active filter:tag: #geopolitical✕ clear
DigiCert breach linked to Chinese APT; code-signing certs stolencriticalbug_reportVulnerability
bug_reportVulnerability

DigiCert breach linked to Chinese APT; code-signing certs stolen

DigiCert certificate authority infrastructure compromised in April 2026. Code-signing certificates stolen by CylindricalCanine (GoldenEyeDog/APT-Q-27 subgroup).

DigiCert14:39 UTC
Lazarus Deploys OtterCookie via Fake Job Lures in Contagious Interviewhighperson_alertThreat Actor
person_alertThreat Actor

Lazarus Deploys OtterCookie via Fake Job Lures in Contagious Interview

Lazarus is a North Korean state-sponsored advanced persistent threat (APT) group attributed to the Reconnaissance General Bureau (RGB). The group is financially motivated, conducting operations to generate revenue for the DPRK regime through cryptocu…

The Hacker News11:48 UTC
Armenia Detains Russian National on U.S. REvil Ransomware Warranthighperson_alertThreat Actor
person_alertThreat Actor

Armenia Detains Russian National on U.S. REvil Ransomware Warrant

REvil (also known as Sodinokibi) is a Russia-linked ransomware-as-a-service (RaaS) operation that emerged in 2019 and became one of the most prolific cybercrime groups before law enforcement disruption in 2021-2022.

The Hacker News08:53 UTC
GoSerpent Malware Targets Southeast Asian Government and Diplomacyhighperson_alertThreat Actor
person_alertThreat Actor

GoSerpent Malware Targets Southeast Asian Government and Diplomacy

GoSerpent is a previously undocumented malware family discovered by Kaspersky researchers in late 2025. The malware is designed for long-term persistent access and intelligence gathering operations.

Kaspersky06:46 UTC
CISA orders patching of actively exploited Fortinet FortiSandbox flawscriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders patching of actively exploited Fortinet FortiSandbox flaws

Fortinet FortiSandbox threat detection platform. Specific versions not provided in available data. Two vulnerabilities confirmed, CVE identifiers not yet disclosed.

Fortinet05:03 UTC
CISA: Microsoft SharePoint RCE CVE-2026-58644 actively exploitedcriticalbug_reportVulnerability
bug_reportVulnerability

CISA: Microsoft SharePoint RCE CVE-2026-58644 actively exploited

Microsoft SharePoint Server (specific versions not disclosed). CVSS 9.8 critical remote code execution vulnerability.

CVE-2026-5864404:42 UTC
Mount Royal University in Calgary confirms data breach and deletionhighpublicGeopolitical
publicGeopolitical

Mount Royal University in Calgary confirms data breach and deletion

The breach of Mount Royal University represents a typical pattern in the current cyber threat landscape affecting higher education institutions across North America.

Mount Royal University19:26 UTC
China-Linked Cluster Exploits Roundcube at Universitieshighperson_alertThreat Actor
person_alertThreat Actor

China-Linked Cluster Exploits Roundcube at Universities

This China-linked threat cluster targets academic institutions in North America, focusing on credential theft and persistent access through exploitation of vulnerable Roundcube webmail servers.

Roundcube16:56 UTC
EvilTokens Ghost Phishing Campaign Targets US and European Businesseshighperson_alertThreat Actor
person_alertThreat Actor

EvilTokens Ghost Phishing Campaign Targets US and European Businesses

EvilTokens is a campaign leveraging "ghost phishing" techniques to target business entities across the United States and Europe. The campaign's primary motivation appears to be credential theft and unauthorized access to Microsoft 365 environments, w…

Microsoft11:00 UTC
REF6045 targets Mexican banking sector with SCMBANKER via ClickFix lureshighperson_alertThreat Actor
person_alertThreat Actor

REF6045 targets Mexican banking sector with SCMBANKER via ClickFix lures

REF6045 is a financially motivated threat actor conducting banking fraud operations against Mexican financial institutions and their customers. The actor targets banking, fintech, and cryptocurrency exchange users in Mexico, leveraging social enginee…

The Hacker News10:52 UTC
KDDI breach exposes 12M records across Japanese ISP ecosystemhighpublicGeopolitical
publicGeopolitical

KDDI breach exposes 12M records across Japanese ISP ecosystem

The breach of KDDI, one of Japan's three major telecommunications carriers, represents a significant compromise of critical infrastructure in a key U.S. Indo-Pacific ally.

KDDI09:24 UTC
CISA orders federal patch for exploited Langflow auth bypass by Fridaycriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders federal patch for exploited Langflow auth bypass by Friday

Langflow visual AI agent framework - specific versions not disclosed in summary. Federal agencies mandated to patch; private sector should assume all unpatched instances at risk.

Langflow07:58 UTC
UAT-7810 Expands ORB Network with LONGLEASH Malware on Edge Deviceshighperson_alertThreat Actor
person_alertThreat Actor

UAT-7810 Expands ORB Network with LONGLEASH Malware on Edge Devices

UAT-7810 is a China-linked advanced persistent threat (APT) actor focused on compromising internet-facing networking and infrastructure devices to build and maintain an Operational Relay Box (ORB) network designated LapDogs.

The Hacker News07:04 UTC
CISA orders patching of actively exploited Adobe ColdFusion flawcriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders patching of actively exploited Adobe ColdFusion flaw

Adobe ColdFusion commercial web application development platform. Specific affected versions not disclosed in summary, but CISA mandatory patching order indicates government-facing installations are priority targets.

Adobe05:16 UTC
UAT-7810 Deploys LONGLEASH Malware Against Network Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

UAT-7810 Deploys LONGLEASH Malware Against Network Infrastructure

UAT-7810 is a Chinese-linked threat actor focused on compromising internet-facing networking devices to expand their Operational Relay Box (ORB) network infrastructure.

Ruckus16:52 UTC
Scattered Spider Linked to U.S. Luxury Retail Breach via Device IDhighperson_alertThreat Actor
person_alertThreat Actor

Scattered Spider Linked to U.S. Luxury Retail Breach via Device ID

Scattered Spider (also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944) is a financially motivated threat actor known for sophisticated social engineering and identity-focused attacks.

The Hacker News11:27 UTC
China-Aligned Cluster Exploits Roundcube Flaws at Universitieshighperson_alertThreat Actor
person_alertThreat Actor

China-Aligned Cluster Exploits Roundcube Flaws at Universities

This activity cluster is attributed to China-aligned threat actors targeting academic institutions in North America. The group demonstrates a clear strategic interest in research and development sectors, specifically physics and engineering departmen…

CVE-2024-4200907:10 UTC
Tenda router backdoor allows admin access bypass (CVE-2026-11405)criticalbug_reportVulnerability
bug_reportVulnerability

Tenda router backdoor allows admin access bypass (CVE-2026-11405)

Tenda routers running vulnerable firmware versions. Specific models and version ranges not disclosed in available data. Affects web management interface authentication mechanism.

CVE-2026-1140504:40 UTC
Iran-linked MOIS group deploys Cavern C2 framework against Israelhighperson_alertThreat Actor
person_alertThreat Actor

Iran-linked MOIS group deploys Cavern C2 framework against Israel

An Iranian threat actor affiliated with Iran's Ministry of Intelligence and Security (MOIS), tracked by Check Point Research. The group operates in support of Iranian state intelligence objectives, focusing on espionage operations against adversary n…

The Hacker News16:34 UTC
China-nexus actor targets Indian finance sector via DcRAT malwarehighperson_alertThreat Actor
person_alertThreat Actor

China-nexus actor targets Indian finance sector via DcRAT malware

A suspected China-nexus threat actor is conducting Operation DragonReturn, a targeted espionage campaign against Indian taxpayers and finance professionals.

The Hacker News08:58 UTC
Kairos extorts $1M from U.S. government via data theft without encryptionhighperson_alertThreat Actor
person_alertThreat Actor

Kairos extorts $1M from U.S. government via data theft without encryption

Kairos is a financially motivated threat actor that employs extortion tactics focused on data theft without deploying traditional ransomware encryption. The group targeted a U.S.

The Hacker News10:47 UTC
North Korean actors deploy 108 malicious packages in PolinRider campaignhighbug_reportVulnerability
bug_reportVulnerability

North Korean actors deploy 108 malicious packages in PolinRider campaign

npm, Packagist (PHP), Go modules, and Google Chrome Web Store. 108 malicious packages and extensions published. Maintainer accounts actively compromised. Campaign linked to North Korean Contagious Interview threat group.

The Hacker News09:17 UTC
North Korean actors deploy malicious npm packages to steal developer secretshighbug_reportVulnerability
bug_reportVulnerability

North Korean actors deploy malicious npm packages to steal developer secrets

npm ecosystem: malicious packages "rollup-packages-polyfill-core" and "rollup-runtime-polyfill-core" impersonating legitimate "rollup-plugin-polyfill-node".

npm14:07 UTC
Armored Likho targets government and energy sectors with BusySnakehighperson_alertThreat Actor
person_alertThreat Actor

Armored Likho targets government and energy sectors with BusySnake

Armored Likho is a previously undocumented threat actor attributed by Kaspersky to cyber attacks targeting government agencies and the electric power sector.

The Hacker News11:36 UTC
NSO Group's Pegasus Targets EU Parliament Member Investigating Spywarehighperson_alertThreat Actor
person_alertThreat Actor

NSO Group's Pegasus Targets EU Parliament Member Investigating Spyware

NSO Group is an Israeli-based commercial surveillance vendor that develops and sells the Pegasus spyware to government clients. The company markets its tools as lawful intercept solutions for counterterrorism and law enforcement, but has faced repeat…

The Hacker News09:05 UTC
FBI seizes NetNut proxy domains linked to two-million-device botnethighpublicGeopolitical
publicGeopolitical

FBI seizes NetNut proxy domains linked to two-million-device botnet

The FBI's seizure of domains associated with NetNut, a residential proxy service operated by Israeli firm Alarum Technologies, represents a significant law enforcement action targeting the infrastructure enabling large-scale botnet operations.

Alarum Technologies17:27 UTC
NetNut (Popa) Residential Proxy Botnet Disrupted by Google, FBIhighperson_alertThreat Actor
person_alertThreat Actor

NetNut (Popa) Residential Proxy Botnet Disrupted by Google, FBI

NetNut, also tracked as Popa, operates a residential proxy network built on approximately 2 million compromised home devices. The actor monetizes this infrastructure by selling proxy services that route malicious traffic through legitimate residentia…

Google16:54 UTC
Scattered Spider Member Extradited to U.S. from Estoniahighperson_alertThreat Actor
person_alertThreat Actor

Scattered Spider Member Extradited to U.S. from Estonia

Scattered Spider (G1015), also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944, is a financially motivated threat actor collective known for sophisticated social engineering and identity-based attacks.

BleepingComputer06:58 UTC
Microsoft SharePoint RCE flaw under active exploitation (CVE-2026-45659)criticalbug_reportVulnerability
bug_reportVulnerability

Microsoft SharePoint RCE flaw under active exploitation (CVE-2026-45659)

Microsoft SharePoint Server, all versions vulnerable to deserialization attacks. Specific affected versions not yet disclosed.

CVE-2026-4565903:46 UTC
Kubota North America reports month-long network intrusion in 2024highpublicGeopolitical
publicGeopolitical

Kubota North America reports month-long network intrusion in 2024

The extended unauthorized access to Kubota North America's network systems highlights vulnerabilities in critical infrastructure sectors, particularly manufacturing and agriculture.

Kubota19:09 UTC