Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

21 / 21 results
Active filter:tag: #unknown✕ clear
155x surge in password spraying exploits MFA gaps and legacy OAuth flowshighperson_alertThreat Actor
person_alertThreat Actor

155x surge in password spraying exploits MFA gaps and legacy OAuth flows

The threat actor behind the LSHIY campaign remains unattributed. Motivation appears financially driven, likely focused on credential validation for resale on dark web markets rather than immediate post-compromise exploitation.

BleepingComputer19 Aug · 12:00 UTC
China-Nexus APT Exploits VMware vCenter Flaws, Deploys Babuk Ransomwarecriticalperson_alertThreat Actor
person_alertThreat Actor

China-Nexus APT Exploits VMware vCenter Flaws, Deploys Babuk Ransomware

A suspected China-nexus advanced persistent threat actor, assessed with moderate confidence by QUIRSO to be Chinese-speaking and operating in the UTC+08:00 time zone.

CVE-2026-5931017 Aug · 05:36 UTC
Malicious LiteLLM PyPI packages stole credentials from 2,100+ orgscriticalbug_reportVulnerability
bug_reportVulnerability

Malicious LiteLLM PyPI packages stole credentials from 2,100+ orgs

LiteLLM versions 1.82.7 and 1.82.8 published on PyPI on March 24, 2026 (10:39-11:19 UTC, treat installs through 16:00 UTC as suspect). Any system that installed these versions or pulled them as transitive dependencies via agent frameworks or orchestr…

LiteLLM12 Aug · 06:04 UTC
Nearly 800 malicious npm packages deliver cross-platform RAT via typosquattingcriticalbug_reportVulnerability
bug_reportVulnerability

Nearly 800 malicious npm packages deliver cross-platform RAT via typosquatting

npm registry: ~800 packages using typosquatting and AI-generated names. Targets all Node.js developers on Windows, macOS (x64/ARM64), and Linux (x64/ARM64). Delivers WEL1DROPPER leading to Sliver C2 framework and platform-specific infostealers.

npm7 Aug · 16:48 UTC
HollowFrame Loader and Matryoshka Backdoor Target Law Firmshighperson_alertThreat Actor
person_alertThreat Actor

HollowFrame Loader and Matryoshka Backdoor Target Law Firms

The threat actor behind this campaign remains unattributed. The operation demonstrates sophisticated tradecraft, deploying a previously undocumented Go-based loader framework (HollowFrame) and a Rust-based backdoor (Matryoshka) in targeted spear-phis…

The Hacker News31 Jul · 14:39 UTC
Fraudulent Sparrow Wallet App on Apple App Store Steals $1.8M in Bitcoinhighperson_alertThreat Actor
person_alertThreat Actor

Fraudulent Sparrow Wallet App on Apple App Store Steals $1.8M in Bitcoin

The threat actor behind this campaign remains unidentified. The operation involved publishing fraudulent cryptocurrency wallet applications on Apple's App Store that impersonated the legitimate Sparrow Wallet.

Apple27 Jul · 15:29 UTC
Hermes AI Agent Used for Post-Exploitation at Thai Finance Ministryhighperson_alertThreat Actor
person_alertThreat Actor

Hermes AI Agent Used for Post-Exploitation at Thai Finance Ministry

The threat actor behind this intrusion remains unattributed. Hunt.io assesses with low-to-medium confidence that the operator is Chinese-speaking or fluent in Chinese, based on linguistic artifacts (password containing "Leishen," meaning thunder god)…

Hermes AI24 Jul · 08:15 UTC
GitHub Actions Abused to Scan and Exploit cPanel/WHM Servershighperson_alertThreat Actor
person_alertThreat Actor

GitHub Actions Abused to Scan and Exploit cPanel/WHM Servers

The threat actor behind this campaign remains unattributed. The operation demonstrates sophisticated understanding of GitHub Actions infrastructure and supply chain attack vectors.

GitHub23 Jul · 09:28 UTC
Vishing Campaign Targets Microsoft 365 Users with Entra Passkey Scamhighperson_alertThreat Actor
person_alertThreat Actor

Vishing Campaign Targets Microsoft 365 Users with Entra Passkey Scam

The threat actor behind this campaign remains unattributed. The operation demonstrates sophistication in social engineering tactics, specifically targeting Microsoft 365 environments through voice-based phishing (vishing).

Microsoft8 Jul · 14:47 UTC
Massive SEO-Poisoned Campaign Distributes AsyncRAT via ScreenConnecthighperson_alertThreat Actor
person_alertThreat Actor

Massive SEO-Poisoned Campaign Distributes AsyncRAT via ScreenConnect

The threat actor behind this campaign remains unattributed. Motivation appears to be financially driven, consistent with commodity RAT deployment for access brokering, credential theft, or follow-on ransomware operations.

OBS Studio1 Jul · 15:53 UTC
Pre-Planned Fraud Campaign Targets FIFA World Cup 2026 Across Sectorshighperson_alertThreat Actor
person_alertThreat Actor

Pre-Planned Fraud Campaign Targets FIFA World Cup 2026 Across Sectors

The threat actor behind this campaign remains unattributed. Motivation appears financially driven, leveraging the global interest in FIFA World Cup 2026 to conduct fraud operations.

The Hacker News30 Jun · 09:30 UTC
SimpleHelp OpenID auth bypass (CVE-2026-48558) exploited in wildcriticalbug_reportVulnerability
bug_reportVulnerability

SimpleHelp OpenID auth bypass (CVE-2026-48558) exploited in wild

SimpleHelp remote support software, all versions using OpenID Connect authentication. CVE-2026-48558 is a critical authentication bypass (CVSS 10.0) in the OpenID Connect flow.

CVE-2026-4855830 Jun · 09:18 UTC
Malicious Chrome Extension Impersonates Perplexity AI to Intercept Searcheshighperson_alertThreat Actor
person_alertThreat Actor

Malicious Chrome Extension Impersonates Perplexity AI to Intercept Searches

The threat actor behind this campaign remains unattributed. The operation demonstrates a financially or espionage-motivated adversary leveraging social engineering through brand impersonation of Perplexity AI, a popular search technology.

Google29 Jun · 16:40 UTC
Cisco Catalyst SD-WAN zero-day exploited in wild for two monthshighbug_reportVulnerability
bug_reportVulnerability

Cisco Catalyst SD-WAN zero-day exploited in wild for two months

Cisco Catalyst SD-WAN Manager. Specific affected versions not disclosed. Requires authenticated local access for exploitation.

CVE-2026-2024525 Jun · 03:46 UTC
WhatsApp VBScript Campaign Deploys ManageEngine RMM Across 9 Countrieshighperson_alertThreat Actor
person_alertThreat Actor

WhatsApp VBScript Campaign Deploys ManageEngine RMM Across 9 Countries

This campaign represents an unattributed threat activity leveraging WhatsApp as an initial access vector. The actor's motivation appears to be establishing persistent remote access to victim systems through legitimate remote monitoring and management…

WhatsApp23 Jun · 03:38 UTC
ShapedPlugin WordPress Pro plugins backdoored via compromised update channelhighbug_reportVulnerability
bug_reportVulnerability

ShapedPlugin WordPress Pro plugins backdoored via compromised update channel

Multiple ShapedPlugin Pro WordPress plugins distributed through official licensed update channels. Exact plugin names and affected versions not specified.

ShapedPlugin22 Jun · 16:00 UTC
Fortinet FortiSandbox under active exploit for 3 CVEs including critical 9.1criticalbug_reportVulnerability
bug_reportVulnerability

Fortinet FortiSandbox under active exploit for 3 CVEs including critical 9.1

Fortinet FortiSandbox - specific affected versions not disclosed. Three CVEs: CVE-2026-39813 (CVSS 9.1 critical), CVE-2026-39808, CVE-2026-25089. At least one vulnerability recently patched; patch status of others unclear.

CVE-2026-2508916 Jun · 08:30 UTC
Palo Alto PAN-OS GlobalProtect auth bypass under active exploitationhighbug_reportVulnerability
bug_reportVulnerability

Palo Alto PAN-OS GlobalProtect auth bypass under active exploitation

Palo Alto Networks PAN-OS GlobalProtect VPN portal and gateway components. Specific affected versions not disclosed in provided data. CVE-2026-0257, CVSS 7.8 (High).

CVE-2026-025715 Jun · 04:17 UTC
ServiceNow patches actively exploited auth bypass on hosted instanceshighbug_reportVulnerability
bug_reportVulnerability

ServiceNow patches actively exploited auth bypass on hosted instances

ServiceNow hosted customer instances (specific versions not disclosed). On-premise deployments may also be affected pending vendor guidance.

ServiceNow10 Jun · 05:02 UTC
CVE-2026-39987 in Marimo actively exploited for cloud credential thefthighbug_reportVulnerability
bug_reportVulnerability

CVE-2026-39987 in Marimo actively exploited for cloud credential theft

Marimo notebook platform (specific versions not disclosed). Affects internet-exposed Marimo notebook instances vulnerable to CVE-2026-39987.

CVE-2026-3998729 May · 12:39 UTC
Fortinet FortiCloud SSO bypass exploited to extract LDAP passwordshighbug_reportVulnerability
bug_reportVulnerability

Fortinet FortiCloud SSO bypass exploited to extract LDAP passwords

Fortinet FortiGate appliances with FortiCloud SSO enabled. CVE-2025-59718 and CVE-2025-59719 allow authentication bypass. All FortiGate instances share a default static encryption key that enables decryption of LDAP credentials and private keys from…

CVE-2025-5971827 Jan · 15:16 UTC