Live threat intelligence — updated continuously
Open Cyber Threat Intelligence
Structured, AI-extracted threat intel. Free with no login required.
Latest Intelligence
View all → DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
1h ago · hacker-news
A macOS malvertising campaign linked to North Korean threat actors has been identified, leveraging fake software update pages to trick users into executing a malicious Terminal command. The attack, part of the Contagious Interview campaign (UNC5342), uses social engineering to induce panic and prompt users to paste a clipboard-staged curl command, leading to malware deployment. The malware employs an EtherHiding technique, retrieving C2 server addresses from Ethereum smart contracts, and delivers a Node.js backdoor and a crypto-stealing payload targeting 157 cryptocurrency wallets and browser data.
4 IoCs 1 Actors
Analog Devices discloses data breach, says operations unaffected
4h ago · bleeping-computer
Analog Devices disclosed a data breach that occurred on June 23, 2026, when an unauthorized party gained access to certain company systems and exfiltrated files. The company activated incident response protocols and engaged external cybersecurity experts to assist with containment and investigation. While the specific data compromised remains unspecified, the company claims operations were unaffected and has not observed stolen data being leaked or misused. The breach may be linked to the data extortion group ExfilSquad, which briefly listed Analog Devices on its leak site before removing it, a common practice during ransom negotiations.
Microsoft Teams vishing attacks lead to Chaos ransomware attacks
4h ago · bleeping-computer
Threat actors are conducting vishing attacks via Microsoft Teams, impersonating IT support staff to trick employees into granting remote access to corporate devices. These intrusions are part of campaign STAC4749, tracked by Sophos, which led to the deployment of Chaos ransomware in at least three organizations. The attackers used fake IT-themed domains and spoofed identities to initiate contact, then deployed remote management tools like RemSupp and PowerShell-based backdoors to establish persistence and move laterally. The campaign targeted primarily North American organizations, with attacks spanning from February to June 2026, and demonstrated rapid progression from initial access to ransomware encryption—sometimes within 17 hours.
6 IoCs 1 Actors 1 Malware
ShinyHunters claims Brinks Home breach, threatens to leak stolen data
3h ago · bleeping-computer
ShinyHunters, a known extortion gang, claimed responsibility for a breach of Brinks Home on July 13, 2026, asserting they stole over 4.9 million Salesforce records containing personally identifiable information (PII) via a Microsoft Entra voice phishing (vishing) attack. The attackers reportedly exfiltrated more than 1.1 million customer data rows from the 'Contacts' Salesforce object, over 4,000 employee PII records, and 3.8 million customer support chat logs from a Brinks Care Cresta instance. Brinks Home confirmed the breach and an ongoing investigation, noting that alarm monitoring systems were unaffected, but warned customers of potential phishing and impersonation attacks stemming from the incident.
1 Actors
VMware fixes three critical flaws allowing auth bypass, VM escapes
1h ago · bleeping-computer
VMware, now under Broadcom, has released emergency security updates to address five vulnerabilities in vCenter, ESX, Workstation, and Fusion, including three critical flaws. CVE-2026-59309 and CVE-2026-59310 are critical authentication bypass and arbitrary code execution vulnerabilities in vCenter that can be exploited by unauthenticated attackers with network access. CVE-2026-47876 is a critical VM escape vulnerability in the VMXNET3 virtual network adapter, allowing a guest VM attacker with local admin privileges to execute code on the host. While there is no evidence of active exploitation, VMware servers are high-value targets for ransomware and advanced threat actors, and these flaws could enable broad lateral movement and persistence if left unpatched.
1 Malware
Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
1h ago · bleeping-computer
Amazon has linked multiple npm supply-chain attacks to the North Korean threat actor Sapphire Sleet (also known as BlueNoroff and Stardust Chollima) with medium confidence. The attacks began in March 2025 with the compromise of the typo-crypto package, followed by the trojanization of widely used packages debug and chalk in September 2025, impacting an estimated 10% of cloud environments within two hours. In March 2026, the axios library—used by over 100 million developers weekly—was targeted, with malicious updates distributed after attackers socially engineered maintainers to gain access. The campaign used sophisticated tactics including delayed execution in real environments, multi-stage payloads, and 'slopsquatting' of AI-hallucinated package names to expand reach.
4 IoCs 2 Actors
Fastjson RCE (≤1.2.83): Active Exploitation Detected — Detection & Mitigation
2h ago · static-urls
A remote code execution (RCE) vulnerability in Fastjson versions ≤ 1.2.83 is under active exploitation in the wild. The vulnerability allows unauthenticated attackers to execute arbitrary code on affected servers by sending specially crafted JSON payloads, without requiring user privileges or victim interaction. Exploitation is possible when Fastjson SafeMode is not enabled. ThreatBook TDP has detected active attacks and provides detection capabilities via signature S3100181015. The recommended mitigations include enabling SafeMode, blocking malicious payloads at the perimeter, and migrating to Fastjson 2.x, as no official patch is available for the 1.x series.
2 IoCs
Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database
6h ago · hacker-news
A critical vulnerability in Azure Cosmos DB, dubbed CosmosEscape by Wiz, allowed attackers to escape the Gremlin query sandbox and achieve remote code execution on a multi-tenant gateway. This enabled access to a platform-wide signing key (Cosmos Master Key) and a regional account directory (Config Store), which could be used to retrieve primary account keys for any Cosmos DB account across tenants and regions. The flaw could have granted full read and write access to databases supporting services like Microsoft Teams and Copilot, though Microsoft confirmed no customer data was accessed. Microsoft patched the vulnerability within 48 hours of disclosure in November 2025, with full remediation completed by July 2026.
ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories
4h ago · hacker-news
A Chinese-speaking threat actor operating under the aliases knaithe and KnYuan has launched an AI-powered autonomous hacking campaign leveraging the Hermes Agent framework with DeepSeek as a reasoning engine to exploit seven critical vulnerabilities in Langflow, n8n, Citrix NetScaler, Apache Tomcat, Marimo Notebook, Palo Alto PAN-OS, and Microsoft Windows IKE Extensions. The campaign uses AI models to autonomously conduct vulnerability assessment, target selection, and exploit generation, with command and control coordinated via Telegram. The actor also leverages publicly available AI tools like Claude Code, Codex, and Qwen Code to support operations. When initial exploitation fails, the system automatically searches for new critical CVEs using GitHub PoCs to prioritize attack surfaces.
2 IoCs 5 CVEs
SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT
9h ago · hacker-news
The Chinese cybercrime group SilverFox targeted a Japanese industrial manufacturing organization using a sophisticated attack chain involving a three-driver BYOVD (Bring Your Own Vulnerable Driver) technique for kernel-level access and defense evasion. The attack began with a phishing email containing an invoice-themed lure, leading to DLL side-loading via malicious ZIP archives that deploy ValleyRAT, a Gh0st RAT variant. The malware uses multiple persistence and recovery mechanisms, including NTDLL unhooking, process injection, and a dual watchdog system to maintain remote access and resist removal.
7 IoCs 2 Malware