Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

5 / 5 results
Active filter:tag: #internet-service-providers✕ clear
Evooo1Bot: Mirai-based botnet targets Linux gateways as SOCKS5 proxieshighbug_reportVulnerability
bug_reportVulnerability

Evooo1Bot: Mirai-based botnet targets Linux gateways as SOCKS5 proxies

Internet-facing Linux gateway devices (routers, firewalls, edge appliances). Specific vendors and models not disclosed. Mirai-based malware with modular architecture targeting devices with weak credentials or known vulnerabilities.

BleepingComputer15 Aug · 12:14 UTC
KDDI breach exposes 12M records across Japanese ISP ecosystemhighpublicGeopolitical
publicGeopolitical

KDDI breach exposes 12M records across Japanese ISP ecosystem

The breach of KDDI, one of Japan's three major telecommunications carriers, represents a significant compromise of critical infrastructure in a key U.S. Indo-Pacific ally.

KDDI8 Jul · 09:24 UTC
KDDI breach exposes 14.2M email accounts across Japanese ISP ecosystemhighpublicGeopolitical
publicGeopolitical

KDDI breach exposes 14.2M email accounts across Japanese ISP ecosystem

The breach at KDDI Corporation, one of Japan's largest telecommunications operators, highlights systemic vulnerabilities in shared infrastructure models within critical communications sectors.

KDDI Corporation28 Jun · 12:13 UTC
AryStinger Malware Infects 4,300+ Routers for Recon Operationshighperson_alertThreat Actor
person_alertThreat Actor

AryStinger Malware Infects 4,300+ Routers for Recon Operations

AryStinger is a newly discovered malware family identified by QiAnXin's XLab threat research team. Unlike traditional DDoS botnets, AryStinger is purpose-built for pre-attack reconnaissance and distributed proxy operations.

Legacy Router Manufacturers22 Jun · 04:57 UTC
Dutch Authorities Disrupt Hosting Infrastructure Linked to Russian Opshighperson_alertThreat Actor
person_alertThreat Actor

Dutch Authorities Disrupt Hosting Infrastructure Linked to Russian Ops

This operation involves Russian state-sponsored cyber activity facilitated through compromised Internet hosting infrastructure in the Netherlands. The arrested co-owners operated hosting companies that assumed control of Stark Industries Solutions' t…

Stark Industries Solutions25 May · 11:21 UTC