Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 193 results
highbug_reportVulnerabilityOpenSSL "HollowByte" DoS allows 11-byte requests to freeze server memory
OpenSSL versions prior to June 2024 patch. Affects TLS servers running on glibc-based Linux systems. Specific vulnerable versions not disclosed; patch applied without CVE or public advisory.
highbug_reportVulnerabilitySeven malicious npm packages target Vite ecosystem with blockchain C2 RAT
npm package ecosystem, specifically projects using Vite frontend tooling. Seven malicious packages identified in the ViteVenom campaign. Any JavaScript/Node.js development environments that installed these packages are compromised.
highperson_alertThreat ActorNadMesh Botnet Targets AI Services for AWS and Kubernetes Credential Theft
NadMesh is a Go-based botnet operation discovered in early July that specializes in compromising cloud infrastructure credentials through exploitation of exposed AI and automation services.
criticalbug_reportVulnerabilityDigiCert breach linked to Chinese APT; code-signing certs stolen
DigiCert certificate authority infrastructure compromised in April 2026. Code-signing certificates stolen by CylindricalCanine (GoldenEyeDog/APT-Q-27 subgroup).
highperson_alertThreat ActorLazarus Deploys OtterCookie via Fake Job Lures in Contagious Interview
Lazarus is a North Korean state-sponsored advanced persistent threat (APT) group attributed to the Reconnaissance General Bureau (RGB). The group is financially motivated, conducting operations to generate revenue for the DPRK regime through cryptocu…
criticalbug_reportVulnerabilityWindows zero-day LegacyHive enables privilege escalation on patched systems
All up-to-date Windows systems. Specific affected versions not disclosed. Exploit enables local privilege escalation from standard user to administrator level. No CVE assigned yet.
highperson_alertThreat ActorArmenia Detains Russian National on U.S. REvil Ransomware Warrant
REvil (also known as Sodinokibi) is a Russia-linked ransomware-as-a-service (RaaS) operation that emerged in 2019 and became one of the most prolific cybercrime groups before law enforcement disruption in 2021-2022.
highperson_alertThreat ActorGoSerpent Malware Targets Southeast Asian Government and Diplomacy
GoSerpent is a previously undocumented malware family discovered by Kaspersky researchers in late 2025. The malware is designed for long-term persistent access and intelligence gathering operations.
highperson_alertThreat ActorChina-Linked Cluster Exploits Roundcube at Universities
This China-linked threat cluster targets academic institutions in North America, focusing on credential theft and persistent access through exploitation of vulnerable Roundcube webmail servers.
highperson_alertThreat ActorVishing Campaign Targets Microsoft 365 Users with Entra Passkey Scam
The threat actor behind this campaign remains unattributed. The operation demonstrates sophistication in social engineering tactics, specifically targeting Microsoft 365 environments through voice-based phishing (vishing).
highperson_alertThreat ActorEvilTokens Ghost Phishing Campaign Targets US and European Businesses
EvilTokens is a campaign leveraging "ghost phishing" techniques to target business entities across the United States and Europe. The campaign's primary motivation appears to be credential theft and unauthorized access to Microsoft 365 environments, w…
highperson_alertThreat ActorREF6045 targets Mexican banking sector with SCMBANKER via ClickFix lures
REF6045 is a financially motivated threat actor conducting banking fraud operations against Mexican financial institutions and their customers. The actor targets banking, fintech, and cryptocurrency exchange users in Mexico, leveraging social enginee…
highperson_alertThreat ActorUAT-7810 Expands ORB Network with LONGLEASH Malware on Edge Devices
UAT-7810 is a China-linked advanced persistent threat (APT) actor focused on compromising internet-facing networking and infrastructure devices to build and maintain an Operational Relay Box (ORB) network designated LapDogs.
highperson_alertThreat ActorUAT-7810 Deploys LONGLEASH Malware Against Network Infrastructure
UAT-7810 is a Chinese-linked threat actor focused on compromising internet-facing networking devices to expand their Operational Relay Box (ORB) network infrastructure.
highperson_alertThreat ActorDEBULL Campaign Exploits Microsoft Device Code Flow for M365 Phishing
DEBULL is a phishing campaign active from late June through early July 2026, targeting Microsoft 365 accounts through abuse of Microsoft's legitimate device-code flow authentication mechanism.
highperson_alertThreat ActorScattered Spider Linked to U.S. Luxury Retail Breach via Device ID
Scattered Spider (also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944) is a financially motivated threat actor known for sophisticated social engineering and identity-focused attacks.
highperson_alertThreat ActorChina-Aligned Cluster Exploits Roundcube Flaws at Universities
This activity cluster is attributed to China-aligned threat actors targeting academic institutions in North America. The group demonstrates a clear strategic interest in research and development sectors, specifically physics and engineering departmen…
highperson_alertThreat ActorIran-linked MOIS group deploys Cavern C2 framework against Israel
An Iranian threat actor affiliated with Iran's Ministry of Intelligence and Security (MOIS), tracked by Check Point Research. The group operates in support of Iranian state intelligence objectives, focusing on espionage operations against adversary n…
criticalbug_reportVulnerabilityGitea Docker auth bypass under active probing (CVE-2026-20896)
Gitea Docker images with improper X-WEBAUTH-USER header validation. Specific vulnerable versions not provided; affects deployments trusting reverse proxy authentication headers without IP restrictions.
highperson_alertThreat ActorChina-nexus actor targets Indian finance sector via DcRAT malware
A suspected China-nexus threat actor is conducting Operation DragonReturn, a targeted espionage campaign against Indian taxpayers and finance professionals.
highperson_alertThreat ActorJadePuffer: First LLM-Driven Ransomware Operation Documented
JadePuffer is a ransomware family representing the first documented instance of a ransomware operation conducted entirely by a large language model (LLM) agent.
highperson_alertThreat ActorKairos extorts $1M from U.S. government via data theft without encryption
Kairos is a financially motivated threat actor that employs extortion tactics focused on data theft without deploying traditional ransomware encryption. The group targeted a U.S.
highbug_reportVulnerabilityNorth Korean actors deploy 108 malicious packages in PolinRider campaign
npm, Packagist (PHP), Go modules, and Google Chrome Web Store. 108 malicious packages and extensions published. Maintainer accounts actively compromised. Campaign linked to North Korean Contagious Interview threat group.
highperson_alertThreat ActorAvalon Modular Malware Framework Delivers CrownX Ransomware
Avalon is a previously undocumented modular malware framework discovered by cybersecurity researchers. The framework is distributed through multi-stage phishing campaigns and represents a comprehensive attack platform integrating multiple offensive c…
highperson_alertThreat ActorNetNut Residential Proxy Network Disrupted After Compromising 2M Devices
NetNut operated a residential proxy network that leveraged approximately 2 million compromised Android devices to provide unauthorized proxy services. The actor monetized access to infected devices including smart TVs and streaming boxes, selling res…
highbug_reportVulnerabilityNorth Korean actors deploy malicious npm packages to steal developer secrets
npm ecosystem: malicious packages "rollup-packages-polyfill-core" and "rollup-runtime-polyfill-core" impersonating legitimate "rollup-plugin-polyfill-node".
highperson_alertThreat ActorEvilTokens Affiliate ARToken Exposes M365 Phishing-as-a-Service Platform
EvilTokens is a threat actor operating a phishing-as-a-service (PhaaS) ecosystem targeting Microsoft 365 credentials. The group utilizes an affiliate model, with ARToken identified as one operational affiliate platform.
highperson_alertThreat ActorArmored Likho targets government and energy sectors with BusySnake
Armored Likho is a previously undocumented threat actor attributed by Kaspersky to cyber attacks targeting government agencies and the electric power sector.
highperson_alertThreat ActorNSO Group's Pegasus Targets EU Parliament Member Investigating Spyware
NSO Group is an Israeli-based commercial surveillance vendor that develops and sells the Pegasus spyware to government clients. The company markets its tools as lawful intercept solutions for counterterrorism and law enforcement, but has faced repeat…
highperson_alertThreat ActorPamStealer: macOS Info Stealer Masquerades as Maccy Clipboard Manager
PamStealer is a newly discovered macOS information stealer malware family identified by Jamf Threat Labs. The malware is distributed through social engineering, masquerading as a legitimate Maccy clipboard manager application to deceive users into in…