Live threat intelligence — updated continuously
Open Cyber Threat Intelligence
Structured, AI-extracted threat intel. Free with no login required.
Latest Intelligence
View all → Making sure the checks get printed
1d ago · talos
Cisco Talos has identified a growing trend called 'A3: AI-Analysis Evasion', where malware authors embed natural-language instructions in code to manipulate AI-based analysis systems. These techniques range from simple comments to advanced template spraying designed to deceive large language models (LLMs), with a success rate of approximately 35% in skewing AI verdicts. The evasion methods are used in conjunction with serious threats, such as MANTLEMAZE malware, which abuses vulnerable drivers to disable EDR from kernel space. Since the instructions must be in plaintext, defenders can detect them by monitoring for imperative language in binaries, treating such text as evidence rather than system directives.
13 IoCs
ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms
1d ago · hacker-news
A targeted campaign against South Korean financial firms, including Shinhan Bank and Yegaram Savings Bank, leveraged the open-source AI-powered penetration testing tool ARTEX, developed by Autumn-27, to conduct data theft operations. The attacks, active from late September to early October 2026, involved a suspected Chinese-speaking threat actor using a Hong Kong-based IP address hosting the ARTEX instance and interacting with LLMs such as DeepSeek, GLM, and Grok. The actor also used Claude to research methods for selling stolen Korean data on Telegram and referenced the Telegram account @YY520CN. CrowdStrike linked the activity to financial motivation, though no group has been definitively attributed. In response, the ARTEX developer discontinued the project and moved it to closed source due to misuse.
8 IoCs
Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments
13h ago · hacker-news
Citrix has patched a critical vulnerability, CVE-2026-107406, in NetScaler ADC and NetScaler Gateway appliances that could allow remote code execution or denial-of-service when the devices are configured as SAML identity providers or service providers. The flaw, which has a CVSS score of 9.5, is memory overflow-based and requires specific SAML-related configurations to be exploitable. While there is no evidence of active exploitation to date, Citrix warns that Secure Private Access Hybrid deployments are also affected and must be upgraded to patched versions to mitigate risk.
GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys
12h ago · hacker-news
A critical vulnerability in GoBalance, a Go-based reimplementation of Tor's OnionBalance used by dark web sites for availability, allows attackers to recover the full private key of a .onion service from publicly available descriptors. This flaw stems from GoBalance using only the first 32 bytes of a 64-byte Tor private key during signing, effectively exposing the secret randomness used in signatures and enabling full key recovery from a single descriptor. As a result, attackers can hijack .onion addresses by creating valid descriptors for the same address, redirecting traffic to malicious sites. High-profile dark web services including Dread and Omega were confirmed compromised, with Dread attributing the incident to this flaw after initially suspecting operator error.
Citrix warns admins to patch new NetScaler RCE flaw immediately
12h ago · bleeping-computer
Citrix has issued an urgent warning for administrators to patch a critical remote code execution (RCE) vulnerability, tracked as CVE-2026-107406, affecting NetScaler ADC and NetScaler Gateway appliances configured as SAML Identity Providers or Service Providers. The flaw arises from a memory overflow condition that could allow attackers to execute arbitrary code or cause denial-of-service conditions. While there are no known active exploits in the wild at the time of disclosure, Citrix has previously seen rapid exploitation of similar NetScaler vulnerabilities, and over 21,000 NetScaler instances are exposed to the internet, increasing the risk of widespread compromise if left unpatched.
Low-cost Android phones ship with residential proxy malware
1d ago · bleeping-computer
A malware campaign dubbed 'Midnight Mimosa' has been discovered on low-cost Android smartphones, where malicious software is embedded directly into the firmware of devices using MediaTek chipsets. The malware, which operates with system-level privileges, enables silent app installation, ad fraud via fake utility apps, and turns infected devices into residential proxies. The campaign has affected thousands of devices across over 150 countries, with notable impact in Mexico, France, Italy, and the U.S., and persists through preinstalled system apps that cannot be uninstalled normally.
7 IoCs
Uranium crypto exchange hacker convicted for stealing $53 million
1d ago · bleeping-computer
Jonathan Spalletta, also known as 'Jspalletta' and 'Cthulhon', was convicted of hacking the decentralized crypto exchange Uranium Finance in April 2021, exploiting flaws in its smart contract code to steal approximately $53.3 million in cryptocurrency. In the first attack, he exploited a vulnerability to issue zero-token withdrawal commands and drain $1.4 million, later extorting a 'bug bounty' of nearly $386,000. Three weeks later, he exploited another coding error—causing transaction verification to use 1,000 instead of 10,000—enabling him to withdraw nearly 90% of the exchange's liquidity pools. Spalletta laundered the stolen funds through Tornado Cash and decentralized exchanges, leading to the collapse of Uranium Finance.
1 IoCs
FakeGit malware campaign returns with 17,610 malicious GitHub repos
1d ago · bleeping-computer
The FakeGit malware campaign has reemerged, leveraging 17,610 malicious GitHub repositories to distribute the SmartLoader malware, which in turn delivers the StealC infostealer. The attack uses throwaway and compromised developer accounts to host repositories with deceptive README files that include download links to malicious ZIP archives. The campaign rapidly redeployed, creating over 13,000 repositories in 34 hours, with 97% of commits modifying only the README to point to SmartLoader payloads. Attackers maintain persistence by using forks, release assets, and issue attachments to host backup copies of malware, evading takedown efforts.
1 IoCs 2 Malware
Ransomware attack disrupts Japan's IDCF Cloud used by govt clients
1d ago · bleeping-computer
IDC Frontier, a Japanese cloud provider subsidiary of SoftBank Group, suffered a ransomware attack on its IDCF Cloud service in the East Japan Region 1, leading to a system outage and impacting 495 organizations, including government clients. The attackers claimed to have encrypted 225 databases (3.6 PB), accessed 239 hypervisors, sealed 16,000 VM disks, and wiped over 554,000 snapshots. The company has isolated affected systems, disabled customer console access proactively, and is investigating the intrusion vector and full impact.
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
1d ago · socket-dev
The npm package [email protected] was compromised in a supply chain attack linked to the ChainDrop/Shai-Hulud campaign, delivering a credential-stealing malware payload via a preinstall hook. The malicious code executes during installation, harvesting secrets from local files, CI environments, Kubernetes, Vault, and AI development tools, then exfiltrates them. The payload also establishes persistence using a 'hostage token' mechanism that triggers destructive actions if stolen tokens are revoked, and it propagates by republishing compromised npm packages under the victim's identity.
5 IoCs