Live threat intelligence — updated continuously
Open Cyber Threat Intelligence
Structured, AI-extracted threat intel. Free with no login required.
Latest Intelligence
View all → Discovering and exploiting a remote code execution vulnerability in OpenCode (GHSA-632h-h47v-g4x4)
21h ago · datadog-security-labs
A remote code execution (RCE) vulnerability, tracked as GHSA-632h-h47v-g4x4, was discovered in OpenCode versions 1.14.30 through 1.18.21. The flaw exists in the /global/upgrade API endpoint, where a content-type confusion allows attackers to exploit a code injection vulnerability by submitting a malicious npm package via a cross-origin POST request. The attack can be triggered when a user visits a malicious webpage while running an unsecured OpenCode instance, leading to execution of preinstall scripts from the attacker-controlled package. The vulnerability was patched in OpenCode 1.18.22 by restricting the upgrade target to valid semantic versions and enforcing proper content-type validation.
2 IoCs
Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls
9h ago · hacker-news
A malicious Android spyware dubbed Corp MDM is targeting logistics firms by distributing fake Google Play pages impersonating CEVA and TKW Logistics. The malware, delivered as a trojanized APK with package name 'com.corp.mdm', steals newly received SMS messages, redirects calls, and maintains a hidden foreground service. It communicates with a command-and-control server at 69.55.61.82 via HTTP, exfiltrating SMS content and device identifiers while supporting remote commands such as call forwarding and self-destruction. The campaign is suspected to be financially motivated, with links to a Russian-Armenian threat actor operating a phishing-as-a-service platform called Global Profit.
4 IoCs
Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer
6h ago · hacker-news
A threat campaign dubbed ClickFix is compromising legitimate Ukrainian business websites to serve fake Cloudflare verification pages that trick users into executing a malicious command. The command downloads an MSI installer delivering Psychedelic Stealer, a previously undocumented information stealer that exfiltrates browser credentials, cryptocurrency wallets, and account tokens. The attackers also use a lure management panel hosted on uasputnik.com, and the malware establishes persistence via scheduled tasks and communicates with C2 servers. A second malware chain delivers RemotePanel, a remote access tool, and BoundSiphon, a .NET stealer, using similar social engineering lures.
13 IoCs
Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content
5h ago · hacker-news
The domain third-party[.]com, historically used as a documentation placeholder in code and technical writing, has been registered by an attacker and is now serving a ClickFix social engineering lure targeting Windows users. When accessed from Windows, the site poisons the clipboard with a malicious PowerShell command intended for execution via the Run dialog, while showing a benign or unsupported message to other platforms like macOS. The domain is referenced in over 1,700 public GitHub repositories, including AI agent skills and API documentation, amplifying exposure. Additionally, two other placeholder domains—yoursite[.]com and your-domain[.]com—are actively serving scams and scareware, particularly targeting macOS users with fake security alerts and fraudulent investment offers.
14 IoCs
ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories
3h ago · hacker-news
The article details multiple active cyber threats, including the RemControl Android banking trojan targeting users in Western Europe, the Middle East, and Canada via fake Google Play Store pages distributed through Meta ads. The malware abuses Android Accessibility Services to perform screen streaming, keystroke logging, and remote control, with command-and-control infrastructure dynamically resolved through encrypted Telegram dead-drops. Phishing overlays and operator panels show signs of AI-assisted development, and Russian-language code comments suggest Russian-speaking involvement. The campaign shares infrastructure and tactics with the Medusa UNKN affiliate botnet, indicating a coordinated threat operation.
7 IoCs 2 Malware
Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions
3h ago · hacker-news
A security researcher, Rasmus Moorats, identified two unpatched vulnerabilities in OnePlus devices running OxygenOS that can be chained to allow a locally installed Android app with no permissions to gain full root access. The first flaw is in the AtlasService, which runs as root and accepts unvalidated input from any app, enabling command injection into a restricted root environment. The second flaw leverages the olc2 hardware helper service, which executes arbitrary shell commands if the caller has root—achieved via the first flaw—granting full system-level control. As of September 24, 2026, no fix or CVE had been issued by OnePlus, and the company warned the researcher against public disclosure, citing legal consequences.
Hackers now exploit critical Roundcube flaw in code injection attacks
7h ago · bleeping-computer
A critical pre-authenticated SQL injection vulnerability in Roundcube Webmail, tracked as CVE-2026-48842, is now being actively exploited in the wild. The flaw exists in the virtuser_query plugin and allows unauthenticated attackers to bypass authentication, execute malicious database commands, and steal data without user interaction. The Canadian Centre for Cyber Security has issued an updated advisory warning of ongoing exploitation, urging administrators to update to patched versions 1.6.16 or 1.7.1, or disable the vulnerable plugin if immediate patching is not possible. Roundcube instances have been frequent targets in the past, including by state-backed groups such as APT28 and TA473.
2 Actors 7 CVEs
17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360
12h ago · hacker-news
ClickFix is a social engineering-based initial access technique that manipulates users into pasting malicious commands into trusted system interfaces, bypassing traditional security controls. The attack leverages compromised websites, often WordPress-based, to serve fake verification pages that trigger clipboard manipulation and user-driven command execution. Infrastructure is resilient, using blockchain (Polygon) and Telegram/Steam for dynamic domain resolution, enabling rapid rotation and evasion of blocklists. Payloads are fingerprint-gated, delivering malware like Vidar Stealer only to specific victims based on hardware and account identifiers, making sandbox analysis unreliable.
5 IoCs
CISA: Ransomware gangs now exploiting critical TeamCity flaw
10h ago · bleeping-computer
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that ransomware gangs are actively exploiting a critical authentication bypass vulnerability in JetBrains TeamCity, tracked as CVE-2026-63077. This flaw allows unauthenticated attackers to execute arbitrary operating system commands via the TeamCity agent polling protocol, potentially compromising CI/CD pipelines, stealing credentials, and modifying server state. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog and mandated federal agencies to remediate within three days. Although patching is available, hundreds of internet-exposed TeamCity servers remain unpatched, making them attractive targets for ransomware and state-sponsored actors.
1 Actors
Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure
15h ago · hacker-news
Threat actors are actively exploiting CVE-2026-87902, a critical vulnerability in WordPress that allows unauthenticated remote code execution (RCE) under specific conditions. Exploitation requires the active theme to have a directory starting with 'page-' and a readable local PHP file such as 'pearcmd.php' on the server. Attackers are leveraging the vulnerability to write PHP web shells to temporary directories and are retrieving payloads from a GitHub repository. Multiple IP addresses have been observed conducting exploitation attempts, with the first recorded just hours after the patch was released.
13 IoCs