Live threat intelligence — updated continuously
Open Cyber Threat Intelligence
Structured, AI-extracted threat intel. Free with no login required.
Latest Intelligence
View all → Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products
14h ago · hacker-news
A critical path traversal vulnerability, CVE-2026-21589, affects 8 self-hosted Atlassian Data Center products, allowing unauthenticated attackers to read specific files in the web application root directory if they know the exact filename and path. The vulnerability is rated 9.3 on the CVSS v4.0 scale due to its network accessibility and high confidentiality impact. Atlassian has released fixed versions for affected Data Center products and applied patches to its cloud instances, while advising self-hosted customers to either upgrade or implement temporary mitigations such as WAF rules or Tomcat rewrite rules to block malicious URL patterns containing '..' adjacent to path separators.
LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings
9h ago · hacker-news
A vulnerability in LibreOffice and Apache OpenOffice allows malicious spreadsheets to execute arbitrary code without macro warnings by leveraging Java-based database drivers. The attack abuses legitimate features like database ranges and JDBC drivers, automatically downloading and executing a malicious JAR file when the document is opened. While LibreOffice has patched the issue (CVE-2026-63277), Apache OpenOffice remains vulnerable (CVE-2026-59265) in all versions up to 4.1.16. Users are advised to disable Java support or avoid untrusted spreadsheets until updates are available.
1 CVEs
Nikkei discloses breaches of employees’ Microsoft, Google email accounts
12h ago · bleeping-computer
Japanese media conglomerate Nikkei disclosed two separate breaches involving employee email accounts. In late July 2026, an attacker accessed a Google Workspace account, exposing personal information of 1,646 employees and business partners. In September 2026, another employee's Microsoft 365 account was compromised and used to send approximately 9,000 phishing emails to internal staff and interviewees. The malicious emails contained links to malicious websites, prompting Nikkei to reset passwords and notify affected recipients. The company has not attributed the attacks to any specific threat actor or confirmed if the incidents are related.
1 IoCs
SubQuery Ecosystem Compromise: Hidden Credential Theft and Backdoors
1d ago · step-security
On October 5, 2026, a malicious version of the npm package @subql/[email protected] was discovered containing a hidden payload that steals credentials and enables remote shell access. The backdoor activates during installation or import, targeting developer workstations and CI environments such as GitHub Actions runners. The package downloads malicious artifacts from ci-artifacts.dev, collects sensitive files and environment variables, attempts cloud and Kubernetes secret exfiltration, and can inject malicious GitHub Actions workflows to further propagate. The attacker used a temporary GitHub branch with two commits to publish the compromised version, obfuscating the payload through multiple encryption layers.
7 IoCs
Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
1d ago · hacker-news
A critical vulnerability, CVE-2026-61500, in Rejetto HTTP File Server (HFS) versions 3.0.0 through 3.2.0 is under active exploitation, enabling attackers to forge administrator session cookies and achieve remote code execution. The flaw stems from the use of a predictable pseudo-random number generator (Math.random()) for session-cookie signing keys, which can be reconstructed by unauthenticated attackers through login responses. A proof-of-concept exploit was publicly released by researcher Alejandro Ramos (aramosf), and exploitation attempts have been observed, including by an unnamed threat actor based in China targeting U.S. systems. The vulnerability follows previous exploitation of another Rejetto HFS flaw, CVE-2024-23692, which was used to deploy cryptocurrency miners and malware such as HATVIBE.
1 IoCs 1 Malware 1 CVEs
⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests
1d ago · hacker-news
Multiple critical zero-day vulnerabilities were exploited in the wild this week, including CVE-2026-88779 in Citrix NetScaler ADC and Gateway, and CVE-2026-104286 in Fortinet FortiMail, both allowing remote code execution or arbitrary file writes. Russian state-sponsored group Star Blizzard deployed a new malware delivery technique called RedFlick to install the CosmicPulse backdoor via phishing. A Chinese-linked post-compromise malware, NeedyMantis, has been used in targeted operations since October 2025. Additionally, law enforcement disrupted the KillSec ransomware group and arrested members of ShinyHunters. A new Spectre v2 variant, BTR, enables rapid extraction of Linux root password hashes on Intel systems.
1 Actors
Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes
1d ago · hacker-news
Microsoft disclosed a high-severity vulnerability, CVE-2026-96940, in on-premises Microsoft Exchange Server that allows authenticated attackers to escalate privileges and access other users' mailboxes within the same organization. The flaw stems from weak authorization controls and has been rated 8.8 on the CVSS scale. Although no active exploitation has been observed, Microsoft considers exploitation likely and has issued out-of-band updates for affected versions. Exchange Online has been mitigated via a server-side fix and does not require customer action.
Alleged dev of Ploutus ATM malware appears in US court after arrest
1d ago · bleeping-computer
Anibal Alexander Canelon Aguirre, also known as 'Prometheus' and 'The Engineer,' was arrested and appeared in U.S. court for allegedly developing Ploutus malware, which enabled ATM jackpotting attacks across the United States. Between February 2024 and December 2025, these attacks targeted banks and credit unions in 47 states and the District of Columbia, stealing over $5.4 million in confirmed incidents and attempting to steal an additional $1.4 million. The malware included anti-analysis and self-deletion capabilities to evade detection and forensic investigation. Canelon Aguirre and his co-conspirators laundered the proceeds and transferred them to accounts controlled by the Tren de Aragua (TdA) Venezuelan gang, a designated transnational criminal organization and foreign terrorist organization.
1 Malware
New Dell System Update flaw lets hackers gain root privileges
1d ago · bleeping-computer
Dell has disclosed a critical vulnerability in its System Update (DSU) command-line interface tool, tracked as CVE-2026-86360, which allows unauthenticated remote attackers to exploit a path traversal weakness and execute arbitrary code with root privileges. The flaw affects Linux and Windows systems used in PowerEdge enterprise server infrastructure. Dell recommends updating DSU to version 2.3.0.0 or later to mitigate the issue. The company also patched four high-severity flaws in DSU and two maximum-severity vulnerabilities in Container Storage Modules (CSM). While no active exploitation has been confirmed, state-backed groups like Lazarus and UNC6201 have previously exploited Dell vulnerabilities.
3 Actors
Rejetto HFS servers now actively scanned for critical RCE flaw
1d ago · bleeping-computer
Hackers are actively scanning for a critical remote code execution (RCE) vulnerability, CVE-2026-61500, in Rejetto HFS (HTTP File Server) instances. The flaw stems from a weak session-cookie signing key derived from JavaScript's Math.random() generator, which is also leaked to unauthenticated clients, enabling attackers to reconstruct the key and forge administrator session cookies. Successful exploitation allows full administrative access and remote code execution via server-side JavaScript execution. Probing activity has been observed from a single China Telecom IP address targeting systems in Japan and the United States, likely for reconnaissance ahead of broader exploitation.
1 IoCs 1 CVEs