Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
7 / 7 results
highbug_reportVulnerabilityAttackers abuse legitimate Node.js runtime to evade detection in attacks
Organizations using Node.js in their environments, particularly government departments, technology companies, hotels, fintech, e-commerce, professional services, and retail logistics.
highperson_alertThreat ActorMidnight Blizzard targets hospitality Wi-Fi in CaptiveCrunch campaign
Midnight Blizzard (APT29, also tracked as Storm-2945, IRON RITUAL, IRON HEMLOCK, NobleBaron, Dark Halo) is a Russian-attributed advanced persistent threat group linked to intelligence collection operations.
highperson_alertThreat ActorStorm-2945 Hijacks Hotel Wi-Fi to Deploy CornFlake Surveillance RAT
Storm-2945 is assessed by Microsoft to be an operational sub-cluster of Midnight Blizzard (APT29, Cozy Bear), which the U.S. and U.K. governments attribute to Russia's Foreign Intelligence Service (SVR). The U.K.
highperson_alertThreat ActorStorm-2945 Exploits Captive Portals in CaptiveCrunch Espionage Campaign
Storm-2945 is an operational sub-cluster of Midnight Blizzard (APT29), a Russia-based threat actor attributed by US and UK governments to the Foreign Intelligence Service of the Russian Federation (SVR).
highbug_reportVulnerabilityDNS hijacking on hotel Wi-Fi redirects users to fake Microsoft 365 logins
Wi-Fi gateways at hotels and conference centers in multiple U.S. cities, India, and Saudi Arabia. Targets traveling employees from financial services, professional services, legal, healthcare, energy, and retail sectors accessing Microsoft 365.
highbug_reportVulnerabilityPhishing campaign targets hotel front desks with Node.js implant
Hotel and hospitality organizations in Europe and Asia. Front-desk systems targeted via photo-themed ZIP file attachments containing Node.js-based malware. Campaign active since April 2026.
highbug_reportVulnerabilityActive campaign targets hospitality in Europe/Asia via ZIP archives
Hospitality organizations in Europe and Asia. Attack vector: photo-themed ZIP archives containing malicious shortcut files that deploy a Node.js implant.