Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 734 results
highpublicGeopoliticalFrance fines hospital €500K for breach exposing 727,000 patient records
The enforcement action by France's CNIL represents a continuation of robust data protection regulatory activity under the EU's General Data Protection Regulation (GDPR) framework.
highbug_reportVulnerabilityCoder registry compromised via Cloudflare to deliver malicious Terraform modules
Coder registry infrastructure (registry.coder.com) accessed via compromised Cloudflare configuration. Users who downloaded Terraform modules between 07:35 and 21:45 UTC on August 31, 2026 potentially affected.
highbug_reportVulnerability5,000 Dropbox accounts compromised; OAuth and Teams phishing campaigns active
Multiple attack vectors: 5,000+ compromised Dropbox accounts, Microsoft Teams users across 150+ employees in 10+ organizations, OAuth-based applications, and users of phishing-as-a-service kits (BlueKit, Outsider).
highbug_reportVulnerabilityBraZetsu malware framework enables Initial Access Broker marketplace
Windows hosts in Iberian Peninsula and Latin America, particularly Brazil. Primary targets: e-commerce, corporate, financial, industrial, and law enforcement sectors. Browsers affected: Google Chrome, Microsoft Edge, Brave, Vivaldi, Opera.
highpublicGeopoliticalThomson Reuters C-Track breach exposes U.S. and Canadian court records
The March 2026 breach of Thomson Reuters' C-Track court case management platform represents a significant compromise of judicial infrastructure across multiple U.S. state and Canadian provincial jurisdictions.
highbug_reportVulnerabilityRMM phishing campaign hits 46 countries, US accounts for 45% of activity
Organizations across 46 countries, primarily United States (45% of activity), Canada, and others. Top targeted sectors: education, technology, government, banking, finance, and manufacturing.
highbug_reportVulnerabilityPlex urges immediate patching of undisclosed flaws in Media Server
Plex Media Server v1.43.2 and earlier, Plex Desktop client versions prior to 1.115.0. Affects all platforms including Windows, macOS, Linux, and NAS devices running Plex.
highbug_reportVulnerabilityAttackers abuse legitimate Node.js runtime to evade detection in attacks
Organizations using Node.js in their environments, particularly government departments, technology companies, hotels, fintech, e-commerce, professional services, and retail logistics.
highbug_reportVulnerabilityShai-Hulud infostealer now targets 469 credential locations in dev tools
Developer workstations, CI/CD pipelines, cloud configurations, AI tool configs, package registries (npm, GitHub, Docker), and any environment storing long-lived credentials or tokens.
highbug_reportVulnerabilityAI-assisted campaigns target Latin American orgs with data exfiltration
Organizations in Latin America, specifically: Mexican transportation sector, federal government ministries, municipal water utilities in Mexico and Ecuador (CL-CRI-1131); Brazilian financial sector (CL-CRI-1163).
highperson_alertThreat ActorNSO Group Pegasus deployed via zero-click iMessage exploit in Serbia
NSO Group is an Israeli cyber intelligence company that develops and sells Pegasus spyware to government clients. The company markets its surveillance technology as a tool for law enforcement and intelligence agencies to combat terrorism and crime.
highbug_reportVulnerabilityCrowdStrike Falcon zero-day FalconFlank allows privilege escalation
CrowdStrike Falcon Sensor on Windows 11 25H2 and Windows Server 2025 (all current versions). The vulnerability exploits the Office malicious macros remediation feature.
highbug_reportVulnerabilityAttackers abuse Microsoft Teams external chat to impersonate IT support
Microsoft Teams users in enterprise environments with external collaboration enabled. All organizations using Teams for business communication are at risk if users accept external contact requests and grant remote access via RMM tools or Quick Assist…
highbug_reportVulnerabilitySilver Fox campaign uses fake installers to disable Windows Update
Windows systems globally, primarily China-based operations of multinational organizations and Chinese-speaking users across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors.
highbug_reportVulnerabilityAI coding agents execute malicious Git config commands outside sandbox
Seven command-line AI coding agents: goose (fixed in 1.44.0), Codex CLI/Desktop (fixed in 0.131.0 / 26.519.x), Claude Code (partially fixed in 2.1.196, second path unpatched in 2.1.252+), Hermes Agent 0.18.2–0.21.0 (unpatched), Qwen Code 0.19.6–0.22.…
highperson_alertThreat ActorGambling Goblin Hijacks Brazilian Gov Sites via Malicious Apache Modules
Gambling Goblin is a Chinese-speaking cybercrime cluster tracked by Check Point Research since mid-2025. The group specializes in SEO manipulation at scale by compromising high-reputation domains, particularly Brazilian government (.gov.br) and educa…
highperson_alertThreat ActorStreamRat Android Banking Trojan Spread via Meta Ads to EU Users
ThreatFabric is the cybersecurity research firm that discovered and analyzed the StreamRat campaign. The actual threat actor behind StreamRat remains unattributed.
highperson_alertThreat ActorRussian National Charged for 2016-2017 Excel Malware Campaign
Searzhudin Tamirlanovich Aktulaev is a 40-year-old Russian national charged by the U.S. Department of Justice for orchestrating a large-scale malware distribution campaign between June 2016 and November 2017.
highperson_alertThreat ActorRussian National Indicted for TVRAT/DarkVNC Phishing Campaign
Searzhudin Tamirlanovich Aktulaev, a 40-year-old Russian national, orchestrated a large-scale phishing campaign between June 2016 and November 2017. Motivated by financial fraud and credential theft, Aktulaev targeted freelancers on an unnamed freela…
highbug_reportVulnerabilitySality P2P botnet dismantled after 20+ years of operation
Sality botnet infrastructure (active since 2003), affecting 15,000+ infected devices globally. Primary payload in recent years: EggJagger clipjacking malware targeting cryptocurrency wallets.
highbug_reportVulnerabilityActive malware campaign uses fake vendor sites to deliver Silver Fox malware
Organizations with China-based operations and Chinese-speaking users across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors.
highperson_alertThreat ActorPhishing Actors Abuse Faronics Deploy for ScreenConnect Installation
The actors are unattributed phishing operators conducting opportunistic attacks against organizations using social engineering lures. Between July 21 and August 20, 2026, they targeted over 457 endpoints with phishing emails disguised as invoices, ta…
highperson_alertThreat ActorBreeze Comet Targets Brazilian Financial Sector for Payment Fraud
Breeze Comet (formerly UNC5669, overlaps with Plump Spider and SHADOW-AETHER-064) is a financially motivated threat actor operating out of Brazil since September 2023.
highpublicGeopoliticalNovocure breach exposes 1,400+ U.S. cancer patient records
The Novocure incident reflects the sustained targeting of healthcare infrastructure, particularly oncology and patient data repositories, which has intensified across North American providers since late 2025.
highbug_reportVulnerability13 malicious Packagist packages target iOS devices to steal crypto wallets
Packagist/Composer ecosystem: 13 malicious theme packages across 5 vendor namespaces (vsmov, vsphim, haiau009, chilltvcms, ophimcms). Targets Vietnamese streaming sites using OphimCMS/KKPhim.
highperson_alertThreat ActorNimbus Manticore Deploys Cross-Platform RATs via Fake Job Coding Tests
Nimbus Manticore is an Iranian threat actor also tracked as Iranian Dream Job, known for using recruitment-themed social engineering lures to compromise targets.
highbug_reportVulnerability22K Exchange servers unpatched for CVE-2026-62911 auth bypass flaw
Microsoft Exchange Server 2016, 2019, and Subscription Edition (SE). Approximately 21,899 internet-exposed servers remain unpatched globally, with highest concentrations in the United States (6,200) and Germany (5,100).
highperson_alertThreat ActorClickFix Operators Dominate Initial Access via Social Engineering
ClickFix operators are threat actors leveraging a social engineering technique that manipulates users into executing malicious commands through clipboard manipulation.
highpublicGeopoliticalLatvia's cyber threat level remains high amid Russia-linked activity
Latvia's elevated cybersecurity posture reflects its position as a NATO frontline state and vocal supporter of Ukraine. CERT.LV's Q2 2026 report indicates that while incident volumes have moderated from peak levels, they remain substantially above hi…
highperson_alertThreat ActorVenezuelan ATM Jackpotting Group Targets U.S. Financial Infrastructure
This threat actor is a coordinated group of Venezuelan nationals conducting ATM jackpotting operations targeting financial institutions in the United States.