Live threat intelligence — updated continuously
Open Cyber Threat Intelligence
Structured, AI-extracted threat intel. Free with no login required.
Latest Intelligence
View all → Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely
9h ago · hacker-news
A critical unpatched vulnerability, CVE-2026-105192, exists in LMCache versions 0.3.9 through 0.5.5 and affects release candidates and the development branch. The flaw resides in the multiprocess mode where the cache server uses ZeroMQ without authentication and deserializes untrusted data using Python's pickle module, allowing unauthenticated remote code execution. Attackers can execute arbitrary code with the privileges of the LMCache process, which runs as root in official container images. JFrog, who discovered the flaw, warns operators to avoid exposing the multiprocess server to routable networks until a fix is available.
1 CVEs
SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances
9h ago · hacker-news
SonicWall has patched four vulnerabilities in its SMA1000 appliances, the most severe being a pre-authentication server-side request forgery (SSRF) flaw tracked as CVE-2026-102255 with a CVSS score of 10.0. This SSRF vulnerability exists in the WorkPlace portal and could allow unauthenticated attackers to send requests through the appliance to access internal functionality and perform unauthorized operations. The other three flaws require authentication and include an OS command injection, a Zip Slip vulnerability, and a stored cross-site scripting (XSS) issue. SonicWall has not observed exploitation in the wild for these newly patched flaws, but notes this is the third time in 2026 a CVSS 10.0 pre-auth SSRF flaw has been fixed in WorkPlace.
Hackers exploit critical Atlassian flaw after public PoC release
12h ago · bleeping-computer
A critical unauthenticated file-access vulnerability, CVE-2026-21589, affecting multiple self-hosted Atlassian products including Jira, Confluence, and Bitbucket, is being actively exploited in the wild. The flaw allows attackers to perform directory traversal via a shared web-resource library that converts double colons into forward slashes, enabling unauthorized access to sensitive files such as crowd.properties containing plaintext credentials. Exploitation attempts were observed within hours of a public proof-of-concept release by watchTowr, and a Nuclei template has since been published, accelerating automated scanning and exploitation. Affected organizations are urged to patch immediately or apply mitigations such as WAF rules or network access restrictions.
3 IoCs
PoeLLM malware infects exposed AI servers in cryptomining attacks
10h ago · bleeping-computer
The PoeLLM malware is a cryptomining campaign targeting exposed AI servers, particularly those running LiteLLM, Ollama, Gotenberg, and Gitea. It uses an ELF file named libgcrypt that retrieves command-and-control (C2) addresses by extracting keywords from a poem hosted on GitHub, which are then mapped to IPv4 addresses via a hardcoded dictionary. The malware enables remote shell access, deploys XMRig and Iron cryptocurrency miners, and turns infected servers into scanners to propagate further, exploiting CVE-2026-42271 and potentially chaining it with CVE-2026-48710 for unauthenticated RCE. Over 3,400 servers have been compromised, primarily in the US and Western Europe, with C2 infrastructure showing signs of Italian origin.
3 IoCs 2 CVEs
Hackers hijack Google domains after breaching ccTLD registries
4h ago · bleeping-computer
Hackers breached third-party operators managing country-code top-level domains (ccTLDs) for Ghana (.GH), Sierra Leone (.SL), and American Samoa (.AS), gaining control of authoritative DNS records. This allowed them to hijack domains and obtain unauthorized HTTPS certificates by passing domain ownership validation at Certificate Authorities. The attackers could then impersonate legitimate services and serve malicious content. Google detected the abuse through Certificate Transparency logs, blocked the rogue certificates in Chrome via CRLSets, and notified affected organizations, though it emphasized its own systems were not compromised.
100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer
18h ago · hacker-news
Over 100 compromised websites have been injected with malicious JavaScript that displays a fake Cloudflare verification page to deliver LunexStealer, an information-stealing malware. The attack, attributed to threat cluster UAC-0277, uses social engineering via the 'ClickFix' technique to trick users into executing a malicious MSI package. The malware installs a malicious browser extension called LUNARAXE, which steals credentials and browsing data, and deploys an auxiliary component NAIVEMESS for file system access via PowerShell. The campaign uses Ethereum-based smart contracts (EtherHiding) to control script behavior and target Windows users arriving from search engines.
3 IoCs
SonicWall warns of max severity SSRF flaw in SMA1000 gateways
13h ago · bleeping-computer
SonicWall has disclosed a maximum-severity server-side request forgery (SSRF) vulnerability, tracked as CVE-2026-102255, affecting SMA1000 series appliances (6210, 7210, and 8200v models). The flaw exists in the Appliance WorkPlace interface and allows unauthenticated remote attackers to direct the appliance to make internal requests, potentially accessing restricted functionality. While there is no current evidence of exploitation in the wild, the vulnerability poses significant risk due to the strategic positioning of SMA1000 gateways in enterprise networks. SonicWall urges customers to apply released hotfixes immediately to mitigate potential attacks.
ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits
1d ago · hacker-news
A new ClickFix attack technique leverages browser cache smuggling to bypass Windows Run dialog character limits and execute malicious payloads. Attackers trick users into pasting commands that retrieve and execute cached scripts, such as VBScript, which then download PowerShell payloads and establish persistence. The attack chain leads to credential theft via .NET assemblies injected into legitimate processes like 'timeout.exe' and connects to malicious domains for further stages. This method has been used by nation-state actors like North Korea's Stardust Chollima and Russia's Sandworm.
7 IoCs 3 Actors
Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account
1d ago · hacker-news
Unauthorized parties accessed the personal data of approximately 8.8 million individuals in Denmark's Central Person Register (CPR) by exploiting a private company's legitimate access rights. The breach occurred over a 10-day period in September, during which a large volume of automated queries were made to identify valid CPR numbers. The Danish digitalization ministry confirmed the incident, noting that names, addresses, and CPR numbers were exposed, though it remains unclear how attackers gained access to the company's credentials or whether the data was exfiltrated or used. The company's access has since been revoked, and investigations are ongoing by both the data protection authority Datatilsynet and law enforcement.
FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach
1d ago · hacker-news
The FBI removed an Accenture contractor following a data breach that exposed personal information of thousands of FBI employees. The breach occurred due to the contractor's failure to apply a critical security patch on Oracle PeopleSoft, which was exploited by the ShinyHunters threat group. ShinyHunters leveraged a URL-encoding bypass technique to exploit CVE-2026-35273 in the PeopleSoft Environment Management Hub (PSEMHUB), circumventing web application firewall protections. The FBI has taken steps to mitigate further risk and is actively investigating with partner agencies, resulting in multiple arrests linked to ShinyHunters.
1 Actors