Live threat intelligence — updated continuously
Open Cyber Threat Intelligence
Structured, AI-extracted threat intel. Free with no login required.
Latest Intelligence
View all → PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
14h ago · hacker-news
PEEP is a post-compromise Chromium-based toolkit that installs a malicious browser extension to establish persistence and enable command-and-control (C2) operations within compromised Chrome or Edge browsers. The malware bypasses browser security checks by manipulating Secure Preferences and uses native messaging to execute host-level commands, steal credentials, and exfiltrate browsing data. It communicates with C2 servers every 30 seconds over HTTP, supports remote updates, and includes PowerShell and Python scripts for cross-platform deployment, indicating active targeting of both Windows and Linux environments.
9 IoCs 1 Malware
ConnectWise warns of new ScreenConnect flaw without patch
23h ago · bleeping-computer
ConnectWise has identified a vulnerability in its ScreenConnect remote access platform that affects both cloud and on-premises deployments, specifically related to insecure file transfer behavior. A CVE ID has not yet been assigned, and no patch is currently available, though temporary mitigations are recommended. The vulnerability could allow attackers to abuse file transfer permissions during sessions, posing a risk to managed service providers and IT support teams. Given the history of exploitation of ScreenConnect flaws by ransomware groups and state-backed actors, this issue is considered high risk.
1 Actors
Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
16h ago · bleeping-computer
A zero-day vulnerability dubbed 'StyleSmuggler' in Magento and Adobe Commerce is actively exploited to achieve remote code execution and deploy a Rust-based Linux backdoor. The exploit leverages PHP code injection via Magento's template system to trigger malicious activity, including the creation of a disguised backdoor process and a persistent cron job. The backdoor communicates with C2 infrastructure using spoofed NTP traffic on UDP port 123 to evade detection, and checks for tracing before beaconing. Adobe has not yet released a patch, but mitigation advice includes disabling GraphQL.
7 IoCs
Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released
21h ago · hacker-news
A public proof-of-concept exploit has been released that chains multiple vulnerabilities in Telerik UI for ASP.NET AJAX to achieve unauthenticated remote code execution. The attack chain leverages a padding oracle (CVE-2026-13182) to decrypt and forge encrypted state, leading to type confusion and deserialization of a malicious mixed-mode DLL via an unguarded type resolution flaw (CVE-2026-13181). Successful exploitation requires non-default configurations, including use of a custom encryption key and presence of the RadAsyncUpload control. While no confirmed in-the-wild exploitation has been reported, the release of working tooling increases risk for misconfigured systems.
2 IoCs
Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts
21h ago · hacker-news
Cybersecurity firm Huntress identified worm-like activity abusing ConnectWise ScreenConnect to propagate a four-stage VBScript chain across newly connected hosts. The attack uses social engineering, phishing, or fake refund forms to deploy rogue ScreenConnect clients, which then execute a sequence of malicious VBScripts (1.vbs to 4.vbs) for reconnaissance, payload retrieval, and execution. The final stage deploys backdoors, privilege escalation tools, or cryptocurrency miners based on system state, and the infected host re-infects new connections, creating self-propagating behavior. ConnectWise issued an advisory recommending disabling file transfer permissions to mitigate the risk.
13 IoCs 1 Malware
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
18h ago · hacker-news
Multiple active threats were reported this week, including a Chrome zero-day under active exploitation (CVE-2026-85046), which allows remote code execution via a crafted HTML page. MikroTik RouterOS devices are being targeted using an exploit chain called MikroTrick, combining CVE-2026-67276 and CVE-2026-86060 to achieve unauthenticated remote code execution. Unpatched Magento and Adobe Commerce stores are being compromised via a zero-day named StyleSmuggler, leading to backdoor installation. A supply chain attack on Coder's infrastructure delivered malicious Terraform modules that steal credentials. Additionally, the RevStealer information stealer is spreading via fake game cheats and a counterfeit Claude desktop app, using blockchain-based dead drops for resilience.
4 IoCs 1 CVEs
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
17h ago · hacker-news
A threat cluster tracked as PREY-0058 by Arctic Wolf is conducting data theft and extortion attacks targeting Microsoft 365 users, primarily executives, through vishing (voice phishing) and adversary-in-the-middle (AitM) attacks. Attackers impersonate IT help desk personnel and direct victims to malicious authentication pages using domains that mimic legitimate services, such as 'mfaregister[.]com', to steal credentials and MFA tokens. These tokens are then replayed via residential proxy infrastructure to access Microsoft 365 services, enabling large-scale data exfiltration from SharePoint, OneDrive, Exchange, and Box without deploying malware or moving laterally within networks.
9 IoCs 1 Actors 1 Malware
Trezor data breach impact now reaches 81,000 customers
20h ago · bleeping-computer
A data breach at Trezor's shipping provider, ShipMonk, has impacted 81,000 customers, with personal data including names, email addresses, phone numbers, and shipping addresses exposed. The breach originated from a critical SQL injection zero-day vulnerability in the third-party analytics platform Metabase, which was exploited by the ShinyHunters extortion gang. Trezor warns affected users of increased phishing and physical security risks, though its own systems and devices remain secure.
1 Actors
Mathspace discloses data breach affecting over 1 million people
20h ago · bleeping-computer
Mathspace disclosed a data breach affecting over 1 million individuals, primarily students, staff, and parents in Australia and New Zealand, following the exploitation of a critical SQL injection vulnerability in its self-hosted Metabase instance. The attackers gained unauthorized access on August 10, 2026, and exfiltrated data from the Australian reporting database on August 27. The compromised data included personal information, though academic records, credentials, and authentication tokens were not exposed. The breach is part of a broader campaign by the ShinyHunters extortion gang, which has targeted multiple organizations through similar Metabase vulnerabilities.
1 Actors
BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
17h ago · bleeping-computer
The BigBear 2.0 phishing-as-a-service platform has been used to bypass multi-factor authentication (MFA) and steal over 5,000 Microsoft 365 credentials from 258 organizations. The service leverages an Evilginx2-based adversary-in-the-middle (AiTM) framework to intercept passwords, session cookies, and MFA tokens by proxying traffic between victims and Microsoft's legitimate authentication infrastructure. Attackers use the 'offy' configuration to capture credentials and session data, which is then exfiltrated in real time to affiliate operators via Telegram bots. The platform also employs custom JavaScript to disable FIDO2/WebAuthn support in browsers, forcing users toward weaker authentication methods, and uses geo-matched residential proxies across 69 countries to evade detection.
2 IoCs