Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 35 results
Active filter:tag: #google✕ clear
UNC6293, UNC7005, UNC5976 Abuse OAuth and WhatsApp Linking for Espionagehighperson_alertThreat Actor
person_alertThreat Actor

UNC6293, UNC7005, UNC5976 Abuse OAuth and WhatsApp Linking for Espionage

UNC6293, UNC7005, and UNC5976 are three distinct suspected Russian cyber espionage threat clusters conducting persistent account compromise operations. UNC6293 is assessed to be a sub-cluster of Ice Relic (formerly APT29, also tracked as Cozy Bear an…

Google20 Aug · 17:59 UTC
737 fake Chrome VPN extensions route traffic through attacker SOCKS5 proxieshighbug_reportVulnerability
bug_reportVulnerability

737 fake Chrome VPN extensions route traffic through attacker SOCKS5 proxies

Google Chrome Web Store users who installed any of 737 malicious extensions impersonating VPN/proxy services (Proton VPN, NordVPN, Surfshark, ExpressVPN, Cloudflare 1.1.1.1). Approximately 75,000 downloads recorded, primarily Russian users.

Google12 Aug · 16:54 UTC
737 malicious Chrome VPN extensions route traffic through attacker proxieshighbug_reportVulnerability
bug_reportVulnerability

737 malicious Chrome VPN extensions route traffic through attacker proxies

Google Chrome users who installed any of 737 malicious VPN/proxy extensions from Chrome Web Store, primarily targeting Russian-speaking users. 274 extensions impersonated 66 legitimate VPN brands (Proton VPN, NordVPN, Surfshark, AdGuard VPN, Browsec,…

Google12 Aug · 12:09 UTC
OpenAI, Anthropic, Google reasoning APIs leaked secrets via session replayhighbug_reportVulnerability
bug_reportVulnerability

OpenAI, Anthropic, Google reasoning APIs leaked secrets via session replay

OpenAI, Anthropic, and Google reasoning APIs (GPT-5.6 Luna, Claude Haiku 4.5, Gemini Robotics ER-1.6). Affects developers who published raw agent logs containing encrypted reasoning objects.

OpenAI12 Aug · 09:47 UTC
CSS attacks bypass webmail sanitizers to steal passwords and tokenshighbug_reportVulnerability
bug_reportVulnerability

CSS attacks bypass webmail sanitizers to steal passwords and tokens

Microsoft Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail webmail interfaces. Attacks exploit CSS and HTML parsing discrepancies to escape message boundaries.

Microsoft8 Aug · 06:03 UTC
AWS, Google, Vercel agent flaws allow tool execution without model checkshighbug_reportVulnerability
bug_reportVulnerability

AWS, Google, Vercel agent flaws allow tool execution without model checks

Amazon Bedrock AgentCore InvokeHarness API (fixed July 31, 2026; CVE-2026-18830, CVSS 8.6), open-source Strands Python library (unpatched resume path remains), Google Agent Development Kit (ADK) for Python <2.5.0 (CVE-2026-18236, CVSS 9.3), Vercel AI…

Amazon Web Services6 Aug · 06:57 UTC
Google removes ADK workflows after prompt injection exposed CI credentialshighbug_reportVulnerability
bug_reportVulnerability

Google removes ADK workflows after prompt injection exposed CI credentials

Google Agent Development Kit (ADK) Python repository on GitHub. Three workflows removed: issue-analyze.yml, issue-fix.yml, and pr-analyze.yml. Affected repository automation infrastructure, not the distributed ADK Python package itself.

Google4 Aug · 09:16 UTC
Malware can hijack Google Password Manager passkeys on Windows via TPM abusehighbug_reportVulnerability
bug_reportVulnerability

Malware can hijack Google Password Manager passkeys on Windows via TPM abuse

Google Password Manager synced passkeys on Chrome for Windows with TPM. All three attacks require pre-existing malware on the victim's Windows device. Services that do not properly validate user verification flags (e.g., eBay, now patched) are vulner…

Google3 Aug · 21:58 UTC
Chrome Password Manager passkey bypass allows malware to hijack accountshighbug_reportVulnerability
bug_reportVulnerability

Chrome Password Manager passkey bypass allows malware to hijack accounts

Google Chrome Password Manager on Windows systems with TPM. All three attack paths require malware already running as an ordinary user. Specific affected Chrome versions not disclosed.

Google3 Aug · 14:24 UTC
Chrome 149–151 fix 1,442 flaws as AI-driven bug discovery outpaces patchinghighbug_reportVulnerability
bug_reportVulnerability

Chrome 149–151 fix 1,442 flaws as AI-driven bug discovery outpaces patching

Google Chrome versions 149, 150, and 151 (released June–July 2026). All prior Chrome versions are affected by the resolved vulnerabilities. One critical flaw (CVE-2026-3545, CVSS 9.6) is a 13-year-old sandbox escape in Navigation component, patched i…

Google31 Jul · 10:51 UTC
Chaos Ransomware Group Deploys msaRAT Rust Implant via Headless Browsershighperson_alertThreat Actor
person_alertThreat Actor

Chaos Ransomware Group Deploys msaRAT Rust Implant via Headless Browsers

Chaos is a ransomware group that operates through spam floods, vishing campaigns, Quick Assist abuse, and RMM tools for initial access and persistence. The group deploys custom tooling including the msaRAT Rust-based implant as a pre-ransomware stage…

Microsoft23 Jul · 11:11 UTC
Chaos ransomware gang deploys msaRAT backdoor via browser hijackinghighperson_alertThreat Actor
person_alertThreat Actor

Chaos ransomware gang deploys msaRAT backdoor via browser hijacking

Chaos is a ransomware gang that emerged in early 2025, distinct from the earlier same-named ransomware family active since 2021. The group has been linked to Iranian state-backed threat actor MuddyWater, who reportedly leveraged Chaos ransomware to d…

Google23 Jul · 07:59 UTC
Adobe Acrobat Chrome extension flaw exposed WhatsApp Web chatshighbug_reportVulnerability
bug_reportVulnerability

Adobe Acrobat Chrome extension flaw exposed WhatsApp Web chats

Adobe Acrobat extension for Chrome versions 26.5.2.1 and below. Affects approximately 329 million browser installations. Exploitation requires victim to visit attacker-controlled webpage while extension is installed and WhatsApp Web is in use.

Adobe22 Jul · 11:22 UTC
Sandbox escape flaws in Cursor, Codex, Gemini CLI, Antigravity AI toolshighbug_reportVulnerability
bug_reportVulnerability

Sandbox escape flaws in Cursor, Codex, Gemini CLI, Antigravity AI tools

Multiple AI development tools: Cursor IDE, OpenAI Codex, Google Gemini CLI, and Antigravity. Vulnerability affects AI agent sandbox implementations where agents write files executed by host tools, allowing escape from restricted environments.

Cursor20 Jul · 19:14 UTC
Google Dialogflow CX flaw lets attackers hijack agents in same GCP projectcriticalbug_reportVulnerability
bug_reportVulnerability

Google Dialogflow CX flaw lets attackers hijack agents in same GCP project

Google Dialogflow CX agents with Code Block feature enabled, within shared Google Cloud projects. Requires attacker to have edit rights on at least one agent in the project.

Google7 Jul · 14:37 UTC
Phishing campaign targets marketing professionals via fake job interviewshighbug_reportVulnerability
bug_reportVulnerability

Phishing campaign targets marketing professionals via fake job interviews

Marketing professionals with Google accounts; campaign impersonates 30+ brands including Adobe, Netflix, Coca-Cola, OpenAI. Credential theft targeting Google accounts specifically.

Adobe6 Jul · 18:27 UTC
NetNut Residential Proxy Network Disrupted After Compromising 2M Deviceshighperson_alertThreat Actor
person_alertThreat Actor

NetNut Residential Proxy Network Disrupted After Compromising 2M Devices

NetNut operated a residential proxy network that leveraged approximately 2 million compromised Android devices to provide unauthorized proxy services. The actor monetized access to infected devices including smart TVs and streaming boxes, selling res…

Google3 Jul · 15:50 UTC
NetNut (Popa) Residential Proxy Botnet Disrupted by Google, FBIhighperson_alertThreat Actor
person_alertThreat Actor

NetNut (Popa) Residential Proxy Botnet Disrupted by Google, FBI

NetNut, also tracked as Popa, operates a residential proxy network built on approximately 2 million compromised home devices. The actor monetizes this infrastructure by selling proxy services that route malicious traffic through legitimate residentia…

Google2 Jul · 16:54 UTC
ToddyCat Deploys Umbrij Malware to Hijack Gmail via OAuth Abusehighperson_alertThreat Actor
person_alertThreat Actor

ToddyCat Deploys Umbrij Malware to Hijack Gmail via OAuth Abuse

ToddyCat (G1022) is an advanced persistent threat group that has demonstrated sophisticated capabilities in targeting corporate and enterprise environments.

Google2 Jul · 11:04 UTC
Fake Perplexity AI Chrome extension hijacks search traffic on Web Storehighbug_reportVulnerability
bug_reportVulnerability

Fake Perplexity AI Chrome extension hijacks search traffic on Web Store

Google Chrome users who installed the malicious Perplexity AI impersonator extension from the Chrome Web Store. Affects organizations and individuals using Chrome browser seeking AI productivity tools.

Google30 Jun · 13:46 UTC
Silent Swap Campaign Targets Cryptocurrency via Malicious Browser Extensionshighperson_alertThreat Actor
person_alertThreat Actor

Silent Swap Campaign Targets Cryptocurrency via Malicious Browser Extensions

Silent Swap is an active cybercrime campaign leveraging malicious browser extensions to conduct cryptocurrency theft. The operation distributes unsigned installers written in both .NET and Golang variants, masquerading as a legitimate Google Notes br…

Google30 Jun · 13:40 UTC
AirDrop and Quick Share flaws enable wireless DoS and security bypasshighbug_reportVulnerability
bug_reportVulnerability

AirDrop and Quick Share flaws enable wireless DoS and security bypass

Apple AirDrop and Google Quick Share wireless file transfer features on iOS, macOS, and Android devices. Specific affected versions not disclosed. Attack requires physical proximity (wireless range).

Apple30 Jun · 07:27 UTC
Malicious Chrome Extension Impersonates Perplexity AI to Intercept Searcheshighperson_alertThreat Actor
person_alertThreat Actor

Malicious Chrome Extension Impersonates Perplexity AI to Intercept Searches

The threat actor behind this campaign remains unattributed. The operation demonstrates a financially or espionage-motivated adversary leveraging social engineering through brand impersonation of Perplexity AI, a popular search technology.

Google29 Jun · 16:40 UTC
Adblock for YouTube extension with 10M+ installs contains code injection riskhighbug_reportVulnerability
bug_reportVulnerability

Adblock for YouTube extension with 10M+ installs contains code injection risk

Chrome extension "Adblock for YouTube" (10+ million active installations). All users with the extension installed are potentially affected. Extension currently holds Featured badge status in Chrome Web Store.

Google25 Jun · 12:12 UTC
CI/CD flaw "Cordyceps" exposes 300+ GitHub repos to supply-chain takeovercriticalbug_reportVulnerability
bug_reportVulnerability

CI/CD flaw "Cordyceps" exposes 300+ GitHub repos to supply-chain takeover

300+ GitHub repositories across major organizations including Microsoft, Google, and Apache. Vulnerability affects GitHub Actions CI/CD workflows. Specific products and versions not disclosed in available data.

Microsoft24 Jun · 10:48 UTC
Russian-speaking actor deploys OXLOADER to distribute CastleStealerhighperson_alertThreat Actor
person_alertThreat Actor

Russian-speaking actor deploys OXLOADER to distribute CastleStealer

The threat actor is a Russian-speaking, financially motivated cybercrime operator leveraging malicious advertising infrastructure for initial access. The actor demonstrates capability in developing or acquiring custom malware tooling, including the p…

Google22 Jun · 11:20 UTC
Google Cloud Vertex AI SDK flaw enables ML model hijacking via pickle attackhighbug_reportVulnerability
bug_reportVulnerability

Google Cloud Vertex AI SDK flaw enables ML model hijacking via pickle attack

Google Cloud Vertex AI SDK for Python. Specific affected versions not disclosed. Impacts organizations using the SDK to upload and deploy machine learning models to Google Cloud's serving infrastructure.

Google16 Jun · 17:05 UTC
Vertex AI Python SDK vulnerable to RCE via bucket squatting attackshighbug_reportVulnerability
bug_reportVulnerability

Vertex AI Python SDK vulnerable to RCE via bucket squatting attacks

Google Vertex AI Python SDK. Affects users uploading models to Vertex AI. Vulnerability exploits bucket squatting during model upload process combined with pickle deserialization to achieve cross-tenant remote code execution.

Google16 Jun · 08:00 UTC
Chinese Cybercrime Network Weaponizes Google Gemini AI for SMS Phishinghighperson_alertThreat Actor
person_alertThreat Actor

Chinese Cybercrime Network Weaponizes Google Gemini AI for SMS Phishing

A Chinese cybercrime network operating a phishing-as-a-service (PhaaS) platform called Outsider. The group weaponizes Google's Gemini AI to craft and conduct SMS-based phishing attacks (smishing) targeting American victims.

Google12 Jun · 16:59 UTC
UNC1151/Ghostwriter Targets Polish Gmail Accounts in Phishing Campaignhighperson_alertThreat Actor
person_alertThreat Actor

UNC1151/Ghostwriter Targets Polish Gmail Accounts in Phishing Campaign

UNC1151, also known as Ghostwriter, is a threat actor group attributed by FireEye/Mandiant that has conducted sustained information operations and cyber espionage activities.

Google12 Jun · 09:00 UTC