Live threat intelligence — updated continuously
Open Cyber Threat Intelligence
Structured, AI-extracted threat intel. Free with no login required.
Latest Intelligence
View all → Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams
18h ago · unit42
The Spring Ring campaign is a coordinated voice phishing (vishing) operation conducted via Microsoft Teams, where threat actors impersonate IT help desk personnel to manipulate employees into executing malicious payloads. The attackers use spoofed external Microsoft 365 tenants with professionally named accounts and initiate unsolicited voice calls to establish trust. Two distinct attack campaigns were observed: Campaign A delivers an obfuscated PowerShell-based remote access Trojan (RAT) via a malicious domain, while Campaign B uses tailored cloud-hosted executables to deploy malware that enables lateral movement through NTLM relay attacks leveraging PetitPotam. These attacks aim to gain persistent access and escalate privileges to compromise domain controllers.
32 IoCs
Is Cyber missing the Marque?
1w ago · talos
UAT-10147, a Chinese-speaking cybercrime group, is leveraging agentic AI to automate and scale sophisticated post-compromise operations across global web servers. The group uses AI to generate operational playbooks, customize malware, and dynamically validate exploit paths, including through stolen ASP.NET MachineKeys for ViewState deserialization attacks. A newly identified backdoor called SPECTRE features a cross-platform capability with a custom Linux kernel rootkit and Bring Your Own Vulnerable Driver (BYOVD) techniques designed to evade endpoint detection and response (EDR) solutions. Defenders are advised to patch internet-facing applications, secure MachineKeys, block vulnerable drivers, and monitor for anomalous HTTP 500 errors used during exploitation.
15 IoCs
Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network
3d ago · hacker-news
The state government of Berlin confirmed a ransomware attack and data exfiltration from its administrative network between August 7 and August 12, 2026, attributed to the Rhysida ransomware group. The attackers claimed to have stolen 5.79 terabytes of data, including personal information on over 12,000 individuals, and published a post on their darknet leak site on August 28. Despite the extortion attempt, Berlin has refused to pay the ransom. Forensic investigations are ongoing, and affected departments were isolated before being reconnected on August 23.
1 IoCs 1 Actors 1 CVEs
Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
2d ago · hacker-news
Multiple critical vulnerabilities have been identified in popular WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, which could allow unauthenticated attackers to bypass authentication, escalate privileges, steal sensitive data, or achieve remote code execution. The most severe of these, CVE-2026-82222 in the GiveWP plugin, enables arbitrary command execution through a PHP object injection chain involving unsafe unserialization and a gadget chain in shipped code. These flaws affect specific versions of the plugins and themes when certain configurations are enabled, posing significant risk to WordPress sites if left unpatched.
TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
1d ago · hacker-news
Microsoft has uncovered a new variant of the ClickFix campaign dubbed TerminalFix, which uses social engineering to trick users into executing a malicious PowerShell command via fake Cloudflare CAPTCHA pages served through compromised websites. The attack employs DLL sideloading using a legitimate binary and a malicious DLL to execute multi-stage payloads, including steganographic extraction from PNG files and extensive Active Directory reconnaissance. The final payload is a Python-based reverse-tunnel backdoor that establishes persistent C2 access via an encrypted WebSocket, enabling attackers to pivot across internal networks. This campaign poses a serious risk to enterprise environments due to its lateral movement and persistence capabilities.
6 IoCs
China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
19h ago · hacker-news
A China-nexus cyber espionage group tracked as Fire Ant has expanded its operations to compromise Cisco IOS XR routers, TACACS servers, and Linux management hosts, enabling credential theft, traffic interception, and suppression of security telemetry. The group deployed custom malware including TacTap, a library injector targeting the tac_plus authentication process, and BridgeAgent, a Linux backdoor disguised as a Zabbix agent. The attackers manipulated router configurations to hide malicious GRE tunnels and exfiltrated packet captures to external FTP servers, while also obfuscating stolen credentials using XOR encryption. The campaign shows strong overlap with UNC3886, though definitive attribution remains unconfirmed.
18 IoCs 1 Actors
Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets
16h ago · hacker-news
Aurora ransomware operators, a Russian-speaking cybercrime group, have been leveraging SpaceX's AI-powered coding assistant Cursor to plan and execute attacks against at least 10 organizations between April and May 2026. The group used Cursor to assist in attack planning, including Active Directory Certificate Services exploitation, and conducted hands-on exploitation using credentials or existing access. The attack chain includes initial access via email bombing and social engineering, lateral movement using SMB, LDAP, RDP, and RPC, privilege escalation, evasion of security tools, data exfiltration, and deployment of a multi-platform encryptor written in Zig. A related AI-assisted toolkit called Gryxa has also emerged, enabling persistent access, credential theft from Chromium browsers, and evasion of endpoint protection.
3 IoCs 1 Malware
North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales
10h ago · hacker-news
North Korean threat actors, operating under multiple aliases including PurpleDelta, Jasper Sleet, and Wagemole, are conducting a large-scale job fraud campaign to infiltrate global companies in IT, healthcare, sales, and other sectors. These actors use forged identities, AI-generated profiles, and synthetic personas to gain remote employment, often using laptop farms equipped with PiKVM and Guermok USB devices to maintain control. They leverage tools like AnyDesk, Telegram, and Slack for coordination, and abuse legitimate platforms such as Workday, Zoom, and Microsoft Teams during recruitment and employment, posing significant insider threat and sanctions compliance risks.
4 IoCs 1 Actors
Berlin confirms data theft after Rhysida ransomware attack claims
14h ago · bleeping-computer
The city administration of Berlin has confirmed a ransomware attack by the Rhysida group, which claims to have exfiltrated 5.79 TB of data from its administrative network. The stolen data includes sensitive government records, personal information, credentials, and critical infrastructure assessments, with attackers threatening to publish the data unless a ransom is paid. The incident was discovered in mid-August 2026, and investigations are ongoing, involving the State Criminal Police Office, public prosecutor, and federal security agencies. No evidence was found that election data was compromised, and the affected departments were disconnected from the state network on August 14.
Chinese Fire Ant hackers turn Cisco routers into spying platforms
13h ago · bleeping-computer
The Chinese state-sponsored threat actor Fire Ant has shifted tactics to compromise Cisco IOS XR routers, TACACS servers, and Linux management systems, turning routers into surveillance platforms via concealed GRE tunnels. The group deployed a custom backdoor named 'BridgeAgent', disguised as a Zabbix agent, enabling reverse shells and execution of additional payloads. Fire Ant uses stealthy persistence mechanisms, suppresses syslog messages, and exfiltrates network traffic PCAPs to FTP servers, aiming to map and access high-value networks through a 'target behind the target' strategy. The group's activity overlaps with UNC3886 but shows distinct implementation differences.
1 IoCs 1 Actors