Live threat intelligence — updated continuously

Open Cyber Threat Intelligence

Structured, AI-extracted threat intel. Free with no login required.

Latest Intelligence

View all →
Malicious Chrome and Firefox Extensions Steal Crypto Traders’ Session and Wallet Data

8h ago · socket-dev

A coordinated campaign involving malicious Chrome and Firefox extensions has been targeting cryptocurrency traders using Axiom Trade and Padre (now Terminal) platforms. The extensions, including J7Tracker, VREO, and Orbit Tracker, steal authenticated session tokens, wallet data, and browser state by injecting malicious JavaScript modules into active trading sessions. Data is exfiltrated via browser navigation to attacker-controlled domains hosted on Vercel and bonto.run infrastructure, bypassing CORS restrictions. The threat actor uses repackaged extensions with cloned functionality and maintains persistence through rotating C2 infrastructure and new publisher accounts, posing a direct risk of account compromise and cryptocurrency theft.
10 IoCs
Off Guard: Breaking LiteLLM from authentication bypass to cloud compromise

8h ago · wiz

Multiple critical vulnerabilities were discovered in LiteLLM, a popular open-source LLM gateway, enabling authentication bypass, remote code execution, and cloud credential theft. CVE-2026-59822 allows unauthenticated access to MCP endpoints via a Bearer token bypass, while CVE-2026-59821 enables post-authentication root-level RCE through unsandboxed custom code guardrails. A default master key (sk-1234) is accepted by 9.6% of public instances, allowing attackers to achieve admin access and exploit these vulnerabilities. Additionally, pass-through endpoints can be abused to exfiltrate cloud metadata and IAM credentials, especially when combined with default or missing authentication.
4 IoCs 3 CVEs
Veradigm warns of patient data breach after ransomware gang claims attack

18h ago · bleeping-computer

Veradigm, a healthcare technology company, disclosed a data breach resulting from a cybersecurity incident at a third-party vendor, which led to unauthorized access to patient data via compromised API credentials. The Gentlemen ransomware group claimed responsibility, stating they exfiltrated 3.5 million patient records containing personally identifiable information, including names, addresses, Social Security numbers, and email addresses. The group threatens to leak the data if a ransom is not paid, with a deadline of September 11, 2026. While clinical data was not accessed, the breach involved sensitive personal information, and Veradigm has initiated incident response procedures and customer notifications.
1 IoCs
Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking

12h ago · bleeping-computer

The Skullcandy Dime 3 wireless earbuds (model S2DCW) running firmware version 1.0.0.28 are vulnerable to Bluetooth hijacking due to a missing authentication flaw in the Airoha Bluetooth Audio SDK. This high-severity vulnerability, tracked as CVE-2025-20701, allows nearby attackers to pair with the device without user interaction or PIN confirmation. Once paired, the attacker's device becomes trusted and can automatically reconnect, enabling audio hijacking, microphone access, and connection disruption. Although Skullcandy released a fix in firmware version 1.0.0.30, there is no user-accessible method to update existing vulnerable units, leaving them permanently exposed.
2 IoCs
AdaptHealth confirms 4.1 million people exposed in July cyberattack

12h ago · bleeping-computer

AdaptHealth, a healthcare provider, confirmed a cyberattack in July 2026 that exposed the personal and health information of 4.1 million individuals. The breach resulted from a social engineering attack that compromised a third-party contractor's privileged account, allowing attackers to exfiltrate data from cloud-based systems. The ShinyHunters threat group claimed responsibility for the attack, which involved the theft of full names, contact details, demographic data, health insurance, and health information. The company detected the intrusion on June 5 and received a ransom demand on June 15, but has found no evidence of data misuse to date.
1 Actors
Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

12h ago · bleeping-computer

Cisco has confirmed active exploitation of a critical authentication bypass vulnerability, CVE-2026-20079, in its Secure Firewall Management Center (FMC) software. The flaw, rated CVSS 10.0, allows unauthenticated remote attackers to execute commands as root by sending crafted HTTP requests. Indicators of compromise, including a specific log entry referencing '/var/tmp/license.tmp', were observed as early as July 23, 2026, suggesting exploitation began before Cisco's public awareness in August. The U.S. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch by September 12, 2026.
1 IoCs
Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets

23h ago · hacker-news

A critical vulnerability in Alby Hub, a self-hosted Lightning wallet, affects versions v1.7.0 through v1.18.5 and could allow attackers to take over internet-exposed wallets and potentially steal funds. The flaw exists when users expose the Hub's management interface to the public internet, contrary to intended deployment on private networks. Alby has confirmed one user was affected, though it is unclear if funds were lost. The company recommends immediately restricting external access and upgrading to version v1.24.0, while also changing the wallet's unlock password if exposed.
DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval

22h ago · hacker-news

A critical vulnerability in DeepSeek Harness, an open-source tool for running AI coding agents, allowed sandboxed agents to disable their own file sandbox by invoking a local web interface without authentication. The flaw, tracked as CVE-2026-82533, enabled an agent to switch its session to 'danger-full-access' mode via a single command, escaping file restrictions and potentially executing commands outside its workspace. The vulnerability affected versions 0.1.1-rc.2 and earlier, with the fix introduced in version 0.1.2-alpha.2, which added one-time token authentication for the local interface. Researchers from OX Research reported the issue, and community members had previously observed the same behavior before official disclosure.
1 CVEs
Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

19h ago · hacker-news

Information stealer malware such as Lumma Stealer and Vidar are harvesting session tokens and API keys from compromised systems, enabling threat actors to replay these credentials and gain unauthorized access to AI services like Google Gemini, OpenAI, Anthropic, and others, bypassing multi-factor authentication. A 7 GB infostealer dump analyzed by Okta contained 44,791 unique JSON Web Tokens (JWTs), 555 of which were likely tied to AI service authentication, along with 2,937 encrypted JWE structures, primarily from OpenAI. Attackers are using stolen tokens to access premium AI models and sell access on underground forums, leveraging anti-detect browsers like Camoufox to avoid detection. The abuse of valid, unexpired API keys and tokens—termed 'LLMjacking'—allows attackers to conduct espionage, resource theft, or run up AI service bills on victims.
3 IoCs 2 Malware
Google warns of new Chrome zero-day bug exploited in attacks

1d ago · bleeping-computer

Google has patched a new Chrome zero-day vulnerability, CVE-2026-87491, which has been actively exploited in the wild. The vulnerability is a high-severity out-of-bounds write issue in the V8 JavaScript and WebAssembly engine, allowing remote attackers to execute arbitrary code within the browser sandbox by luring users to malicious HTML pages. Exploitation can lead to heap corruption, data exposure, or browser crashes. Google has not disclosed further details about the ongoing attacks to avoid exposing technical details before most users are patched.
4 CVEs