Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 734 results
Active filter:tag: #high✕ clear
France fines hospital €500K for breach exposing 727,000 patient recordshighpublicGeopolitical
publicGeopolitical

France fines hospital €500K for breach exposing 727,000 patient records

The enforcement action by France's CNIL represents a continuation of robust data protection regulatory activity under the EU's General Data Protection Regulation (GDPR) framework.

Hôpital privé de la Loire3 Sep · 20:01 UTC
Coder registry compromised via Cloudflare to deliver malicious Terraform moduleshighbug_reportVulnerability
bug_reportVulnerability

Coder registry compromised via Cloudflare to deliver malicious Terraform modules

Coder registry infrastructure (registry.coder.com) accessed via compromised Cloudflare configuration. Users who downloaded Terraform modules between 07:35 and 21:45 UTC on August 31, 2026 potentially affected.

Coder3 Sep · 18:04 UTC
5,000 Dropbox accounts compromised; OAuth and Teams phishing campaigns activehighbug_reportVulnerability
bug_reportVulnerability

5,000 Dropbox accounts compromised; OAuth and Teams phishing campaigns active

Multiple attack vectors: 5,000+ compromised Dropbox accounts, Microsoft Teams users across 150+ employees in 10+ organizations, OAuth-based applications, and users of phishing-as-a-service kits (BlueKit, Outsider).

Dropbox3 Sep · 16:02 UTC
BraZetsu malware framework enables Initial Access Broker marketplacehighbug_reportVulnerability
bug_reportVulnerability

BraZetsu malware framework enables Initial Access Broker marketplace

Windows hosts in Iberian Peninsula and Latin America, particularly Brazil. Primary targets: e-commerce, corporate, financial, industrial, and law enforcement sectors. Browsers affected: Google Chrome, Microsoft Edge, Brave, Vivaldi, Opera.

Microsoft3 Sep · 13:26 UTC
Thomson Reuters C-Track breach exposes U.S. and Canadian court recordshighpublicGeopolitical
publicGeopolitical

Thomson Reuters C-Track breach exposes U.S. and Canadian court records

The March 2026 breach of Thomson Reuters' C-Track court case management platform represents a significant compromise of judicial infrastructure across multiple U.S. state and Canadian provincial jurisdictions.

Thomson Reuters3 Sep · 12:39 UTC
RMM phishing campaign hits 46 countries, US accounts for 45% of activityhighbug_reportVulnerability
bug_reportVulnerability

RMM phishing campaign hits 46 countries, US accounts for 45% of activity

Organizations across 46 countries, primarily United States (45% of activity), Canada, and others. Top targeted sectors: education, technology, government, banking, finance, and manufacturing.

The Hacker News3 Sep · 09:58 UTC
Plex urges immediate patching of undisclosed flaws in Media Serverhighbug_reportVulnerability
bug_reportVulnerability

Plex urges immediate patching of undisclosed flaws in Media Server

Plex Media Server v1.43.2 and earlier, Plex Desktop client versions prior to 1.115.0. Affects all platforms including Windows, macOS, Linux, and NAS devices running Plex.

Plex3 Sep · 09:02 UTC
Attackers abuse legitimate Node.js runtime to evade detection in attackshighbug_reportVulnerability
bug_reportVulnerability

Attackers abuse legitimate Node.js runtime to evade detection in attacks

Organizations using Node.js in their environments, particularly government departments, technology companies, hotels, fintech, e-commerce, professional services, and retail logistics.

Node.js3 Sep · 08:43 UTC
Shai-Hulud infostealer now targets 469 credential locations in dev toolshighbug_reportVulnerability
bug_reportVulnerability

Shai-Hulud infostealer now targets 469 credential locations in dev tools

Developer workstations, CI/CD pipelines, cloud configurations, AI tool configs, package registries (npm, GitHub, Docker), and any environment storing long-lived credentials or tokens.

The Hacker News3 Sep · 08:36 UTC
AI-assisted campaigns target Latin American orgs with data exfiltrationhighbug_reportVulnerability
bug_reportVulnerability

AI-assisted campaigns target Latin American orgs with data exfiltration

Organizations in Latin America, specifically: Mexican transportation sector, federal government ministries, municipal water utilities in Mexico and Ecuador (CL-CRI-1131); Brazilian financial sector (CL-CRI-1163).

Unit 42 (Palo Alto)3 Sep · 08:00 UTC
NSO Group Pegasus deployed via zero-click iMessage exploit in Serbiahighperson_alertThreat Actor
person_alertThreat Actor

NSO Group Pegasus deployed via zero-click iMessage exploit in Serbia

NSO Group is an Israeli cyber intelligence company that develops and sells Pegasus spyware to government clients. The company markets its surveillance technology as a tool for law enforcement and intelligence agencies to combat terrorism and crime.

Apple3 Sep · 06:43 UTC
CrowdStrike Falcon zero-day FalconFlank allows privilege escalationhighbug_reportVulnerability
bug_reportVulnerability

CrowdStrike Falcon zero-day FalconFlank allows privilege escalation

CrowdStrike Falcon Sensor on Windows 11 25H2 and Windows Server 2025 (all current versions). The vulnerability exploits the Office malicious macros remediation feature.

CrowdStrike3 Sep · 04:26 UTC
Attackers abuse Microsoft Teams external chat to impersonate IT supporthighbug_reportVulnerability
bug_reportVulnerability

Attackers abuse Microsoft Teams external chat to impersonate IT support

Microsoft Teams users in enterprise environments with external collaboration enabled. All organizations using Teams for business communication are at risk if users accept external contact requests and grant remote access via RMM tools or Quick Assist…

Microsoft2 Sep · 20:51 UTC
Silver Fox campaign uses fake installers to disable Windows Updatehighbug_reportVulnerability
bug_reportVulnerability

Silver Fox campaign uses fake installers to disable Windows Update

Windows systems globally, primarily China-based operations of multinational organizations and Chinese-speaking users across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors.

Microsoft2 Sep · 14:41 UTC
AI coding agents execute malicious Git config commands outside sandboxhighbug_reportVulnerability
bug_reportVulnerability

AI coding agents execute malicious Git config commands outside sandbox

Seven command-line AI coding agents: goose (fixed in 1.44.0), Codex CLI/Desktop (fixed in 0.131.0 / 26.519.x), Claude Code (partially fixed in 2.1.196, second path unpatched in 2.1.252+), Hermes Agent 0.18.2–0.21.0 (unpatched), Qwen Code 0.19.6–0.22.…

Anthropic2 Sep · 12:06 UTC
Gambling Goblin Hijacks Brazilian Gov Sites via Malicious Apache Moduleshighperson_alertThreat Actor
person_alertThreat Actor

Gambling Goblin Hijacks Brazilian Gov Sites via Malicious Apache Modules

Gambling Goblin is a Chinese-speaking cybercrime cluster tracked by Check Point Research since mid-2025. The group specializes in SEO manipulation at scale by compromising high-reputation domains, particularly Brazilian government (.gov.br) and educa…

Apache2 Sep · 11:44 UTC
StreamRat Android Banking Trojan Spread via Meta Ads to EU Usershighperson_alertThreat Actor
person_alertThreat Actor

StreamRat Android Banking Trojan Spread via Meta Ads to EU Users

ThreatFabric is the cybersecurity research firm that discovered and analyzed the StreamRat campaign. The actual threat actor behind StreamRat remains unattributed.

Meta2 Sep · 10:22 UTC
Russian National Charged for 2016-2017 Excel Malware Campaignhighperson_alertThreat Actor
person_alertThreat Actor

Russian National Charged for 2016-2017 Excel Malware Campaign

Searzhudin Tamirlanovich Aktulaev is a 40-year-old Russian national charged by the U.S. Department of Justice for orchestrating a large-scale malware distribution campaign between June 2016 and November 2017.

The Hacker News2 Sep · 07:10 UTC
Russian National Indicted for TVRAT/DarkVNC Phishing Campaignhighperson_alertThreat Actor
person_alertThreat Actor

Russian National Indicted for TVRAT/DarkVNC Phishing Campaign

Searzhudin Tamirlanovich Aktulaev, a 40-year-old Russian national, orchestrated a large-scale phishing campaign between June 2016 and November 2017. Motivated by financial fraud and credential theft, Aktulaev targeted freelancers on an unnamed freela…

BleepingComputer2 Sep · 07:06 UTC
Sality P2P botnet dismantled after 20+ years of operationhighbug_reportVulnerability
bug_reportVulnerability

Sality P2P botnet dismantled after 20+ years of operation

Sality botnet infrastructure (active since 2003), affecting 15,000+ infected devices globally. Primary payload in recent years: EggJagger clipjacking malware targeting cryptocurrency wallets.

BleepingComputer2 Sep · 06:00 UTC
Active malware campaign uses fake vendor sites to deliver Silver Fox malwarehighbug_reportVulnerability
bug_reportVulnerability

Active malware campaign uses fake vendor sites to deliver Silver Fox malware

Organizations with China-based operations and Chinese-speaking users across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors.

Microsoft1 Sep · 20:48 UTC
Phishing Actors Abuse Faronics Deploy for ScreenConnect Installationhighperson_alertThreat Actor
person_alertThreat Actor

Phishing Actors Abuse Faronics Deploy for ScreenConnect Installation

The actors are unattributed phishing operators conducting opportunistic attacks against organizations using social engineering lures. Between July 21 and August 20, 2026, they targeted over 457 endpoints with phishing emails disguised as invoices, ta…

Faronics1 Sep · 18:53 UTC
Breeze Comet Targets Brazilian Financial Sector for Payment Fraudhighperson_alertThreat Actor
person_alertThreat Actor

Breeze Comet Targets Brazilian Financial Sector for Payment Fraud

Breeze Comet (formerly UNC5669, overlaps with Plump Spider and SHADOW-AETHER-064) is a financially motivated threat actor operating out of Brazil since September 2023.

The Hacker News1 Sep · 15:19 UTC
Novocure breach exposes 1,400+ U.S. cancer patient recordshighpublicGeopolitical
publicGeopolitical

Novocure breach exposes 1,400+ U.S. cancer patient records

The Novocure incident reflects the sustained targeting of healthcare infrastructure, particularly oncology and patient data repositories, which has intensified across North American providers since late 2025.

Novocure1 Sep · 12:28 UTC
13 malicious Packagist packages target iOS devices to steal crypto walletshighbug_reportVulnerability
bug_reportVulnerability

13 malicious Packagist packages target iOS devices to steal crypto wallets

Packagist/Composer ecosystem: 13 malicious theme packages across 5 vendor namespaces (vsmov, vsphim, haiau009, chilltvcms, ophimcms). Targets Vietnamese streaming sites using OphimCMS/KKPhim.

Packagist1 Sep · 12:07 UTC
Nimbus Manticore Deploys Cross-Platform RATs via Fake Job Coding Testshighperson_alertThreat Actor
person_alertThreat Actor

Nimbus Manticore Deploys Cross-Platform RATs via Fake Job Coding Tests

Nimbus Manticore is an Iranian threat actor also tracked as Iranian Dream Job, known for using recruitment-themed social engineering lures to compromise targets.

The Hacker News1 Sep · 11:08 UTC
22K Exchange servers unpatched for CVE-2026-62911 auth bypass flawhighbug_reportVulnerability
bug_reportVulnerability

22K Exchange servers unpatched for CVE-2026-62911 auth bypass flaw

Microsoft Exchange Server 2016, 2019, and Subscription Edition (SE). Approximately 21,899 internet-exposed servers remain unpatched globally, with highest concentrations in the United States (6,200) and Germany (5,100).

Microsoft1 Sep · 10:38 UTC
ClickFix Operators Dominate Initial Access via Social Engineeringhighperson_alertThreat Actor
person_alertThreat Actor

ClickFix Operators Dominate Initial Access via Social Engineering

ClickFix operators are threat actors leveraging a social engineering technique that manipulates users into executing malicious commands through clipboard manipulation.

Microsoft1 Sep · 09:30 UTC
Latvia's cyber threat level remains high amid Russia-linked activityhighpublicGeopolitical
publicGeopolitical

Latvia's cyber threat level remains high amid Russia-linked activity

Latvia's elevated cybersecurity posture reflects its position as a NATO frontline state and vocal supporter of Ukraine. CERT.LV's Q2 2026 report indicates that while incident volumes have moderated from peak levels, they remain substantially above hi…

CERT.LV (Latvia)1 Sep · 09:25 UTC
Venezuelan ATM Jackpotting Group Targets U.S. Financial Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

Venezuelan ATM Jackpotting Group Targets U.S. Financial Infrastructure

This threat actor is a coordinated group of Venezuelan nationals conducting ATM jackpotting operations targeting financial institutions in the United States.

BleepingComputer1 Sep · 07:15 UTC