Live threat intelligence — updated continuously

Open Cyber Threat Intelligence

Structured, AI-extracted threat intel. Free with no login required.

Latest Intelligence

View all →
Fake Roblox Xeno script launcher pushes infostealer, RAT malware

43m ago · bleeping-computer

A malicious campaign distributes fake Xeno Executor installers to Roblox players, delivering a Java-based information stealer and remote access trojan (RAT). The malware is promoted through gaming forums and Discord, masquerading as an 'undetected' version of the legitimate tool. Once executed, it deploys a multi-stage payload that steals browser data, credentials, cryptocurrency wallets, and enables surveillance and full remote control of the infected system. Bitdefender links this campaign to a previously documented threat known as Powercat, now with enhanced capabilities and updated C2 infrastructure.
2 IoCs
Before the first prompt: Code execution paths in trusted coding-agent projects

20h ago · datadog-security-labs

This article details two novel code execution techniques in trusted coding-agent projects that occur after project trust but before the first user prompt, bypassing traditional security controls. In Codex, a malicious project can define a project-scoped Model Context Protocol (MCP) server in .codex/config.toml, causing immediate execution of attacker-controlled processes upon project open. In Claude Code, an attacker can manipulate the PATH environment variable via .claude/settings.json to hijack Git calls and execute a malicious git wrapper script from within the repository. These techniques allow code execution without model interaction or user approval, highlighting the risk of treating project trust as safe.
5 IoCs
INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

3h ago · hacker-news

The INC Ransomware group has become the dominant threat actor exploiting zero-day vulnerabilities in SonicWall SMA 1000 series VPN appliances, specifically CVE-2026-15409 and CVE-2026-15410, which allow for arbitrary command execution. The group has exploited these flaws since at least June 22, 2026, deploying a Python script called KNUCKLEBALL to launch the Suo5 proxy and a custom Java web shell named ORANGETAIL. Victims span multiple countries including the U.S., Australia, and Switzerland, with attackers using social engineering tactics such as phone calls from an individual claiming to be 'Andrew' and using the number +1 (304) 384-0401 to pressure victims into negotiations via info@helprans[.]com.
4 IoCs
Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

3h ago · hacker-news

Unit 42 researchers identified three post-compromise attack paths—Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key—targeting Chrome's Google Password Manager on Windows systems with TPM. These attacks allow malware with local access to hijack passkey-protected accounts by exploiting weaknesses in device key handling, user-verification key re-enrollment, and extraction of the 32-byte Security Domain Secret (SDS) from memory. While no active exploitation in the wild is reported, the techniques enable silent authentication, persistent access, and passkey decryption if an attacker gains initial endpoint access.
ExfilSquad hackers leak info of over 100,000 UK police officers, staff

5h ago · bleeping-computer

The ExfilSquad data extortion group claimed responsibility for a cyberattack on the U.K.'s Police National Legal Database (PNLD), compromising contact data of over 100,000 police officers, staff, and criminal justice professionals. The breach exposed full names, organizations, and email addresses of PNLD subscribers and Ask the Police users. ExfilSquad claims to have stolen 1.9 GB of data containing approximately 135,000 records and demanded a ransom to prevent further data release. The incident is under investigation with support from cybersecurity experts and the National Crime Agency (NCA), though no passwords or sensitive investigative data were compromised.
N-able warns of N-central auth bypass flaw exploited in attacks

3h ago · bleeping-computer

N-able has warned customers of active exploitation of an authentication bypass vulnerability, CVE-2026-18577, affecting both hosted and on-premises versions of its N-central Remote Monitoring and Management (RMM) platform. The flaw, stemming from an incomplete patch for a previously addressed vulnerability (CVE-2026-18576), allows attackers to achieve administrative account takeover. N-able released hotfix 2026.3.1.7 to remediate the issue and urged all customers to upgrade immediately, with hosted deployments already updated. Indicators of compromise include malicious use of Cloudflared, suspicious IP addresses, and 'svchost.exe' located in user documents folders.
6 IoCs
An analysis of incidents at Brazilian educational institutions

7h ago · securelist

SecureList analyzed cyber incidents at Brazilian educational institutions from 2025 to 2026, identifying ransomware attacks and insider threats. Two major ransomware families observed were LockBit 3 and DragonForce, with attackers using leaked LockBit builders and valid credentials for initial access. In one case, LockBit was deployed via PsExec after disabling defenses using a batch script; in another, DragonForce was delivered via AnyDesk. An insider used a custom Python keylogger to capture credentials on shared machines, storing logs in hidden files later retrieved via USB.
7 IoCs 1 Actors
⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks

6h ago · hacker-news

Multiple active threats were reported this week, including Russian threat actors exploiting a Microsoft OWA XSS vulnerability (CVE-2026-42897) to deploy a JavaScript-based implant called OWAReaper for persistent mailbox access. A critical Ruby on Rails vulnerability (CVE-2026-66066) allows unauthenticated attackers to read arbitrary files via crafted image uploads, potentially leading to remote code execution. Additionally, Iranian-linked actors are suspected in coordinated attacks on over 30 Minnesota water systems, where exposed PLCs were targeted to disrupt operations. Storm-2945 (APT29) conducted DNS hijacking via compromised Wi-Fi networks to deliver CornFlake malware and ChocoShell infostealer, while a malicious campaign in RubyGems distributed 199 trojanized packages embedding XMRig cryptojacking payloads.
3 IoCs 2 Actors 1 Malware 4 CVEs
Inside the Underground Business of BTMOB RAT

5h ago · bleeping-computer

BTMOB is an Android remote access trojan (RAT) offered as malware-as-a-service (MaaS), enabling attackers to steal data and remotely control infected devices. Initially operated as a centralized service, BTMOB's ecosystem has fragmented after the original operator sold the full source code in 2025, leading to independent resellers, counterfeit versions, and impersonators. The official operation continues to release new versions and sell access, private infrastructure, and source code, while cheaper alternatives have emerged on Telegram and underground forums, creating a decentralized and untrustworthy marketplace. This proliferation complicates attribution and increases the risk of scams and unstable or malicious variants.
3 IoCs 1 Malware
Pass the Passkey: A Novel Attack Surface in Passwordless Authentication

10h ago · unit42

This article details three novel attack classes against Google's synced passkey ecosystem, collectively termed 'Pass-ta-key', that exploit weaknesses in passwordless authentication implementations. The attacks enable account takeover by malware on a compromised endpoint without user interaction, bypassing user verification requirements and extracting synced passkey private keys. The 'Golden Pass-ta-key' attack is particularly severe, as it allows extraction of the master key (security domain secret) from Chrome's memory during re-onboarding, enabling decryption of all synced passkeys and persistent access. These attacks highlight implementation gaps in relying party validation, device re-registration flows, and exposure of sensitive key material on clients.
2 IoCs