Live threat intelligence — updated continuously

Open Cyber Threat Intelligence

Structured, AI-extracted threat intel. Free with no login required.

Latest Intelligence

View all →
IT threat evolution in Q2 2026. Mobile statistics

4d ago · securelist

In Q2 2026, mobile threats continued to evolve with a notable presence of banking Trojans, particularly variants of Mamont and Creduz. Attackers increasingly used malicious loaders distributed through Google Play, including trojanized apps like a PDF reader and the Cleanova app, to deliver banking malware such as Anatsa. These loaders employed sophisticated evasion techniques, including conditional payload delivery based on installation source telemetry, to bypass app store reviews and target specific users.
2 IoCs 1 Malware
737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection

6h ago · socket-dev

A large-scale malicious Chrome extension campaign involving 737 extensions has been identified, primarily targeting Russian-speaking users seeking access to blocked services like Instagram and YouTube. These extensions impersonate 66 legitimate VPN brands—including Proton VPN, NordVPN, and AmneziaVPN—and route all browser traffic through attacker-controlled SOCKS5 proxies on port 1082, enabling man-in-the-middle attacks. The campaign uses DNS-over-HTTPS for evasion, falsely advertises premium server locations that do not exist, and employs post-approval code substitution to bypass store review. One threat actor behind the operation runs a subscription-based business under the name 'Myxa VPN', which also sells access to the malicious extensions.
90 IoCs
Hackers exploit macOS Screen Sharing flaw to deploy Monero miner

16h ago · bleeping-computer

The Netherlands' National Cyber Security Centre (NCSC) has issued a warning that attackers are actively exploiting a macOS Screen Sharing vulnerability, CVE-2026-65400, to gain unauthorized access to systems with exposed port 5900. The flaw allows network-based attackers to bypass authentication and obtain root access without valid credentials. In confirmed attacks, the threat actors have deployed Monero cryptocurrency miners on compromised systems. Apple has patched the vulnerability in recent macOS updates, including Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9.
1 Malware
Max severity SAP Commerce Cloud flaw now targeted in attacks

18h ago · bleeping-computer

A critical remote code execution vulnerability, CVE-2026-58231, in SAP Commerce Cloud is being actively exploited in the wild just three days after the patch was released. The flaw, which has a CVSS score of 10.0, stems from improper authorization in the Data Hub Adapter extension, allowing unauthenticated attackers to execute arbitrary code by exploiting a default authentication client. Threat intelligence firm Defused confirmed exploitation attempts are already occurring, as observed through honeypot traffic, despite the absence of a public proof-of-concept. The vulnerability affects internet-exposed SAP Commerce Cloud instances, with over 4,200 such systems identified globally, primarily in Europe and North America.
1 CVEs
Shell investigates 'potential incident' after Clop data theft claims

20h ago · bleeping-computer

The Clop ransomware gang claimed responsibility for stealing 89GB of data from energy giant Shell, allegedly exploiting a critical vulnerability, CVE-2026-12569, in Internet-exposed PTC Windchill and FlexPLM instances. The same vulnerability was actively exploited to target other major companies, including General Electric and Philips, with attackers deploying JSP webshells to exfiltrate sensitive data such as engineering drawings, project plans, and facility reports. U.S. CISA and German BSI issued urgent advisories urging immediate patching, and the flaw has been added to CISA's Known Exploited Vulnerabilities catalog.
RingCentral data breach exposed info of 1.6 million accounts

21h ago · bleeping-computer

In July 2026, the ShinyHunters extortion group breached RingCentral through a sophisticated social engineering campaign, exfiltrating personal information from 1.6 million customer accounts. The stolen data included names, email addresses, phone numbers, and physical addresses. After RingCentral refused to pay a ransom, ShinyHunters leaked a 280GB compressed archive of the stolen data on their dark web leak site. The breach did not impact RingCentral's core platform, and no further unauthorized activity has been observed since remediation efforts were implemented.
1 Actors
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit

22h ago · securelist

The HoneyMyte APT group, also known as Mustang Panda, has upgraded its CoolClient backdoor with a kernel-mode Windows rootkit to enhance stealth and persistence. The new variant uses a signed kernel driver, msagent.sys, deployed as a Windows service to hide malicious processes, files, registry keys, and network connections. The malware chain begins with DLL sideloading via a renamed Sangfor executable (defender.exe), establishes persistence through scheduled tasks and registry entries, performs UAC bypass using RPC techniques, and injects into synchost.exe before deploying the driver. The driver communicates with user-mode components via IOCTLs and employs minifilter and registry callbacks to protect its artifacts.
22 IoCs 1 Actors 1 Malware
Armored Likho expands its cyber-espionage toolkit

1d ago · securelist

In May 2026, the Armored Likho (aka Eagle Werewolf) threat actor group expanded its cyber-espionage operations targeting individuals and organizations in Russia through a fake donation app dropper written in Rust using the Tauri framework. The campaign delivers a new Rust-based toolkit called Still Toolkit, consisting of two components: Still Sync, which steals Telegram session data and exfiltrates chat logs and media via the Telegram API, and Still Audio, an audio surveillance implant that records microphone input when voice activity is detected. The malware uses gRPC and FlatBuffers for C2 communication, leverages the SeBackupPrivilege for file access, and employs a Dead Drop Resolver via a GitHub repository to retrieve updated C2 addresses.
27 IoCs
Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt

1d ago · bleeping-computer

An Akira ransomware affiliate gained initial access via an exposed SonicWall VPN without MFA, then used RDP to move laterally and exfiltrate data. The attacker rebooted the compromised host into Safe Mode with Networking to disable EDR and AV solutions, including the Huntress agent and Microsoft Defender. Data was stolen using s5cmd and uploaded to an attacker-controlled S3 bucket, while AnyDesk was installed and configured to persist in Safe Mode. The ransomware payload (akira.exe) failed to execute due to low virtual memory, preventing encryption. Despite the failure, the actor exfiltrated sensitive data within five hours.
1 IoCs 1 Actors
Curiouser and Curiouser

1d ago · talos

Cisco Talos discovered 'JWR', a previously undocumented real-time phishing framework and likely variant of the 'The Outsider' phishing-as-a-service platform. JWR uses open WebSocket connections to enable attackers to monitor victim keystrokes in real time and dynamically guide them through fake login and checkout flows. The campaign is currently distributed via SMS lures impersonating regional toll and postal authorities, allowing threat actors to steal payment data, two-factor authentication (2FA) codes, identity documents, and device fingerprints.
15 IoCs