Live threat intelligence — updated continuously

Open Cyber Threat Intelligence

Structured, AI-extracted threat intel. Free with no login required.

Latest Intelligence

View all →
Hackers breach TrueConf to trojanize client installers with backdoors

13h ago · bleeping-computer

The hacktivist group Head Mare breached unpatched TrueConf video conferencing servers to replace legitimate client installers with trojanized versions delivering the PhantomCore and PhantomGraph backdoors. Attackers exploited vulnerabilities in TrueConf Server, including CVE-2026-3502, to gain unauthorized access, execute arbitrary code, and deploy web shells for persistent access. The malicious installers are distributed to organization members and third parties connecting to compromised servers, enabling credential theft via LSASS memory dumping and remote command execution through a OneDrive-based C2 channel.
4 IoCs 1 Actors 1 Malware
Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

19h ago · hacker-news

Security researchers from PromptArmor and Varonis independently discovered vulnerabilities in Atlassian Rovo that allow attackers to exfiltrate Jira and Confluence data via maliciously crafted inputs. Varonis identified a one-click attack using the 'rovoChatPrompt' URL parameter to preload malicious instructions, which Atlassian patched server-side on July 8, 2026. PromptArmor demonstrated an indirect prompt injection via uploaded files that causes Rovo to send sensitive data to attacker-controlled servers, a vector that remains unpatched as of August 5, 2026, with no CVE assigned.
1 IoCs
Unlimited Technology Systems breach impacts 3.8 million people

1d ago · bleeping-computer

In October 2025, Unlimited Technology Systems, a healthcare software provider, suffered a data breach that exposed sensitive personal and medical information of approximately 3.8 million individuals. The breach occurred due to unauthorized access to its commercial data center between October 5 and October 10, 2025, during which attackers accessed files containing personal, financial, and health-related data. The company detected the activity on October 19, 2025, and confirmed the breach in July 2026, though no threat actor has been identified and no ransomware or extortion claims were made.
Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

21h ago · hacker-news

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-8037, a critical command injection vulnerability in Progress Kemp LoadMaster, to its Known Exploited Vulnerabilities (KEV) catalog due to active exploitation. The flaw allows unauthenticated attackers to execute arbitrary commands on affected devices via unsanitized input in multiple command endpoints. A total of 792 exploitation attempts have been observed from 65 unique IP addresses across 18 countries, with recent activity detected as of August 4, 2026. Federal agencies are urged to patch by August 10, 2026, per BOD 26-04.
3 IoCs
N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist

21h ago · hacker-news

N-able has released Hotfix 2 for its N-central Remote Monitoring and Management (RMM) product to address ongoing exploitation of a critical authentication bypass vulnerability, CVE-2026-18577, which has been actively exploited in the wild. The vulnerability, impacting versions prior to 2026.3.1.7, allows attackers to achieve remote administrative access and perform account takeover. Once inside, threat actors have used the Take Control feature to access managed systems and establish persistence via Cloudflare Tunnel services, even after N-central access was revoked.
10 IoCs
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

21h ago · hacker-news

A zero-day vulnerability in Metabase versions 1.58 and above is being actively exploited in the wild, allowing unauthenticated attackers to gain administrator access by injecting arbitrary SQL into the application database. The attack chain involves sending a POST request to '/api/session/reset_password' followed by a GET to '/api/user/current', which can be detected in logs as an indicator of compromise. Metabase Cloud instances have been patched, but self-hosted users are urged to update immediately. The PC maker Framework confirmed customer data was accessed, including names, IPs, addresses, phone numbers, and emails, though no payment data was involved.
2 IoCs 1 CVEs
UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

1d ago · hacker-news

UNC6671, a financially motivated threat actor group, is conducting vishing attacks to steal credentials and multi-factor authentication tokens by impersonating IT help desk personnel and contacting employees on their personal mobile devices. The attackers use adversary-in-the-middle (AitM) infrastructure to capture credentials and session tokens, enabling access to SaaS platforms such as Microsoft 365 and Okta. The group operates under multiple extortion brands including Redact, Pink, Helix, and Falcon, and has exfiltrated data from organizations in North America, Australia, and the U.K., collecting over $10.6 million in Bitcoin between January and May 2026. Google and CrowdStrike assess that the group leverages social engineering rather than technical vulnerabilities, highlighting the need for phishing-resistant MFA and improved session controls.
3 IoCs 2 Actors
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

1d ago · hacker-news

A large-scale npm supply chain campaign has distributed nearly 800 malicious packages designed to deliver a cross-platform RAT and infostealer. The packages bypass typical lifecycle hook detection by instructing developers to load them via require(), triggering a downloader named WEL1DROPPER that fetches payloads from Cloudflare Workers or fallback domains using DNS TXT record exfiltration. The payloads target Windows, Mac, and Linux systems, establishing persistence, evading detection, and deploying secondary malware such as Sliver C2. The campaign, tracked as Flooding Dropper, may target Russian financial institutions and appears to evolve from the earlier Moika campaign.
12 IoCs 1 Malware
North Carolina Ports confirms cyberattack disrupting operations

1d ago · bleeping-computer

The North Carolina Ports Authority confirmed a cyberattack that disrupted IT systems and port operations at the Port of Wilmington, Port of Morehead City, and Charlotte Inland Port. The incident was detected on August 4, 2026, leading to a systems-wide outage and operational delays starting August 5. The authority activated its cybersecurity contingency plan and began recovery efforts, but did not attribute the attack to a specific threat actor or confirm data exfiltration. Operations were gradually returning to normal by August 7, though delays were still expected.
ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets

1d ago · hacker-news

ClickFix-style attacks are delivering a Go-based macOS stealer that profiles the system, escalates privileges via a fake system error prompt, and steals sensitive data including browser passwords, Apple iCloud Keychain, and cryptocurrency wallet contents. The malware includes a 'DRAIN' routine that siphons partial or full balances from wallets supporting Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and XRP into attacker-controlled accounts. The infrastructure used in the attack is linked to Aeza Group, a Russian bulletproof hosting provider under international sanctions.