Live threat intelligence — updated continuously
Open Cyber Threat Intelligence
Structured, AI-extracted threat intel. Free with no login required.
Latest Intelligence
View all → Attacker infrastructure, but vibe-coded: tracking the evolution of credential harvesting platforms
1d ago · datadog-security-labs
Datadog Security Research has identified two credential harvesting platforms, Loot and UltraVault, which are used to inventory, validate, and exploit stolen credentials, including API keys for cloud and AI services. The platforms are accessible without authentication and support automated validation and post-exploitation actions, such as re-probing credentials and recommending local privilege escalation exploits. The attacker infrastructure has been observed abusing Amazon Bedrock through API calls like GetCallerIdentity, ListFoundationModels, and InvokeModel, indicating active exploitation of compromised AWS credentials, including both long-term and temporary STS credentials.
1 IoCs 2 CVEs
Happy Birthday, Shai-Hulud
6h ago · socket-dev
Shai-Hulud is a self-propagating worm that first appeared on npm in September 2025 by compromising the @ctrl/tinycolor package, which had over two million weekly downloads. The worm harvested credentials using TruffleHog, exfiltrated data to a public GitHub repository named Shai-Hulud, and used stolen npm tokens to propagate to other packages maintained by the victim. It established persistence via GitHub Actions workflows and evolved through multiple waves in late 2025 and 2026, with increasing sophistication and destructive capabilities. In May 2026, the source code was released publicly by TeamPCP, leading to widespread replication and new campaigns, including one leveraging short-lived OIDC tokens in CI environments. The original authors remain unattributed, though two alleged members of TeamPCP were arrested in August 2026.
6 IoCs 1 Actors 1 Malware
Should you care about an “AI slowdown?”
1d ago · talos
Cisco Talos reports on a rising ransomware threat landscape in Japan, with a nearly 5% increase in incidents in the first half of 2026. Two prominent ransomware actors, 'The Gentlemen' and 'Qilin', are driving this surge. Qilin leverages generative AI to accelerate attacks by creating destructive scripts, while The Gentlemen uses legitimate red-teaming tools like AdaptixC2 to blend in and evade detection. Both groups target small- and medium-sized enterprises using double-extortion tactics, emphasizing the need for improved credential management, MFA enforcement, and updated defenses using available Snort rules.
15 IoCs 2 Malware
Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root
14h ago · hacker-news
Security researcher Asim Manizada publicly released exploit code for four Linux kernel vulnerabilities—DirtyAH6, TUNderflow, PPPoEject, and DiagSpill—that enable local privilege escalation to root. All four flaws are memory-safety bugs in kernel networking code, with CVEs assigned and fixes available in updated kernel versions. While no in-the-wild exploitation has been reported, the public release of working, targeted exploits increases risk for unpatched systems, especially shared or multi-user environments. DiagSpill is particularly concerning as it requires no special privileges, only the SCTP module being loaded with non-default options.
4 CVEs
Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use
1d ago · talos
In the first half of 2026, ransomware incidents in Japan increased slightly by 4.7%, with The Gentlemen emerging as the most active group, responsible for 14 incidents. The group operates via a Ransomware-as-a-Service (RaaS) model and uses a double-extortion tactic, leveraging infrastructure including AdaptixC2 for command-and-control. Evidence from Russian-language artifacts in scripts and bash history suggests Russian-speaking actors are involved. Qilin, the second most active group, showed signs of using generative AI in developing attack scripts, with code exhibiting structured, LLM-like patterns in tools for deploying ransomware and wiping backups.
1 IoCs 2 Malware 2 CVEs
WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
21h ago · hacker-news
A new JavaScript stealer named WeaselBiscuit has been distributed through 13 malicious npm packages, targeting developers by harvesting Chrome extension storage data. The malware is lightweight and memory-resident, importing and executing its payload from an Npoint.io dead drop. It communicates with a C2 server at 103.170.217.184:8787 to receive commands and exfiltrate data, including clipboard contents and keystrokes on Windows. While it shares functional and tradecraft similarities with DPRK-linked malware BeaverTail and OtterCookie, no definitive attribution has been made.
18 IoCs 2 Malware
Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents
21h ago · hacker-news
A vulnerability dubbed Plugin4Shell affects four AI coding agents—Anthropic Claude Code, OpenAI Codex, GitHub Copilot, and Google Gemini CLI—allowing repository owners to swap pinned plugin code with malicious versions by exploiting how commit hashes are validated. The flaw arises because agents fetch a specific commit hash but fail to verify that the retrieved code matches it, enabling attackers to create a branch name that mimics the hash and point it to different, malicious code. While Anthropic and OpenAI have released patches in versions 2.1.179 and 0.146.0 respectively, GitHub Copilot has no fix available and Google will not patch the retiring Gemini CLI. The attack can lead to unauthorized access to user files, credentials, and systems, especially when combined with background auto-update features enabled by default in some agents.
Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2
16h ago · hacker-news
Transparent Tribe (APT36), a Pakistan-aligned threat actor, has launched a new campaign dubbed Operation RapidRust, targeting government and defense entities in India and Afghanistan. The group deployed a Rust-based backdoor called RUSTYSHADE that uses private GitHub repositories for encrypted command-and-control (C2) communications. Additional tools include RUSTYMOVE, a USB propagation tool, and file stealers PSNATCH (PowerShell) and BASHNATCH (bash) for Windows and Linux systems. Attackers used typosquatted domains impersonating Indian news sites to host malicious payloads and conducted post-compromise activities including reconnaissance and lateral movement.
11 IoCs 1 Actors
New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
15h ago · hacker-news
WordPress patched a vulnerability dubbed Click2Shell, which allows a specially crafted URL to force the installation of a theme from the WordPress.org directory when clicked by a logged-in administrator, without requiring additional interaction. While the core flaw alone only installs a legitimate theme, it can be chained with a vulnerability in the installed theme to achieve remote code execution. The attack exploits inconsistent parsing of URL parameters between WordPress.org and the administrator's browser, leading to unintended automatic clicks on the Install button. The full exploit chain was demonstrated using the 'Mobile Repair Zone' theme, which contains a handler that downloads and executes arbitrary code without authentication.
1 IoCs
Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer
16h ago · bleeping-computer
A malware campaign is distributing a new information stealer named Rapuncel through SEO-optimized fake GitHub repositories impersonating LastPass and 39 other software brands. The attack delivers the Rapuncel infostealer alongside a Microsoft-signed kernel driver, Alinubx.sys, which disables 145 antivirus and EDR products by exploiting kernel-level access. The malware steals credentials from browsers, cryptocurrency wallets, Discord, Steam, Telegram, Windows Credential Manager, and specific documents, while also capturing screenshots and system information, exfiltrating data to a C2 server via raw TCP.
7 IoCs