Live threat intelligence — updated continuously
Open Cyber Threat Intelligence
Structured, AI-extracted threat intel. Free with no login required.
Latest Intelligence
View all → PolinRider Spreads Through Compromised GitHub Accounts and Packagist
10h ago · socket-dev
The PolinRider campaign continues to spread through compromised GitHub accounts and Packagist, leveraging Git-based infrastructure to inject malicious code into development versions of popular packages. Researchers identified malicious activity in the dev branches of the visanduma/nova-two-factor Packagist package, which has over 700,000 downloads. The attackers use compromised developer accounts to insert obfuscated JavaScript into configuration files and PHP entry points, enabling automatic execution upon repository access or build processes. The campaign employs staged payload delivery via dead-drop resolvers and maintains persistence by rewriting Git history and exploiting IDE integrations such as VS Code tasks.
18 IoCs
Brevo supply-chain attack injected ClickFix scripts on customer sites
14h ago · bleeping-computer
Brevo suffered a supply-chain attack where attackers stole a long-lived Cloudflare API key hardcoded in source code, allowing them to deploy a malicious Cloudflare Worker that injected malicious ClickFix scripts into Brevo's web assets. The compromised scripts were distributed to customer sites embedding Brevo components, affecting up to 100,000 websites. On WordPress sites, the attack attempted to upload a malicious plugin called 'Web Media Optimizer' that acts as a persistent backdoor and injects further malicious JavaScript, including fake Cloudflare verification pages prompting users to run harmful commands.
6 IoCs
U.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS Attacks
1d ago · hacker-news
The U.S. Department of Justice, in coordination with the FBI and the Royal Canadian Mounted Police, seized domains associated with NightmareStresser, a DDoS-for-hire service that has been used to launch hundreds of thousands of attacks since 2022. The service, advertised as a stress-testing tool, enabled users to conduct Layer 4 and Layer 7 DDoS attacks with features like 'Stop All' flood controls and cryptocurrency payments. The takedown is part of Operation PowerOFF, a broader law enforcement initiative targeting criminal DDoS infrastructure globally.
2 IoCs
Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks
1d ago · hacker-news
Cisco has disclosed a critical zero-day vulnerability, CVE-2026-76460, affecting its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) that is actively being exploited. The flaw, rated CVSS 10.0, allows unauthenticated remote attackers to bypass authentication by sending a crafted request to an affected API endpoint, potentially leading to full system compromise with root privileges. Cisco confirms active exploitation and advises immediate patching, as no workarounds exist. The U.S. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch by September 19, 2026.
2 IoCs
Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records
1d ago · hacker-news
A breach at Gyazo, an image-sharing service operated by Helpfeel, exposed approximately 23.62 million user records and 490 million image metadata records. The attacker exploited a vulnerability in Gyazo's image upload server to gain unauthorized access, execute arbitrary commands, and extract sensitive data including email addresses, password hashes, session IDs, and image metadata such as image IDs, upload IP addresses, User-Agent strings, EXIF location data, OCR-extracted text, and hashed passphrases for private images. Helpfeel confirmed the breach on September 14, 2026, reported it to Japanese authorities, and took steps to block the attacker and fix the vulnerability, though it did not disclose the specific nature of the flaw. The company temporarily disabled access to some images to prevent further unauthorized viewing and urged all users to change their passwords due to the risk of credential reuse.
BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS
23h ago · hacker-news
The Internet Systems Consortium (ISC) released updates for BIND 9, addressing 14 security vulnerabilities, including a high-severity flaw allowing an unauthenticated attacker to crash a DNS-over-HTTPS (DoH) server with a single malformed request. Several other flaws can lead to denial-of-service conditions via crafted DNS queries or responses, memory/CPU exhaustion, or cache poisoning through DNSSEC validation bypasses. The vulnerabilities affect multiple versions of BIND 9 across stable and development branches, with no workarounds available. While ISC reports no known active exploitation, public reproduction tests exist, increasing the risk of future exploitation.
China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America
21h ago · hacker-news
The China-aligned state-sponsored threat actor FamousSparrow has been deploying a new modular C++ backdoor named SparroWocky in targeted cyber espionage attacks across Latin America since at least August 2025. The malware, which replaces the group's previous SparrowDoor implant, supports command execution, file exfiltration, periodic screenshots, and acts as a TCP proxy. It uses anti-analysis techniques and integrates open-source tools like Mbed TLS, MinHook, and COFF Loader for secure communications, evasion, and in-memory plugin execution. Targets include governmental entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela, with 90% of observed activity focused on the region.
1 IoCs 2 Actors 1 Malware
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
19h ago · hacker-news
A critical heap overflow vulnerability (CVE-2026-81642) exists in Unbound DNS resolver versions up to and including 1.26.0, which can be exploited remotely by an attacker controlling a malicious DNS zone to trigger denial of service or potentially achieve remote code execution. The vulnerability resides in the DNSSEC validator when processing a DNSKEY record with a compression pointer pointing into the record's own data. A second high-severity vulnerability (CVE-2026-82717), a heap corruption in CNAME synthesis, also affects the same versions and could lead to remote code execution under specific conditions. Both flaws are patched in Unbound 1.26.1.
US takes down NightmareStresser DDoS-for-hire platform
20h ago · bleeping-computer
The FBI has seized the domains of NightmareStresser, a long-running DDoS-for-hire ('booter') service that enabled users to launch large-scale distributed denial-of-service attacks using compromised IoT devices and routers. The service, which claimed to be the '#1 online IP booter,' was used in hundreds of thousands of attacks since 2022, targeting networks globally with attack volumes up to 200 Gbps across multiple layers. The takedown was part of Operation PowerOFF, an international law enforcement effort targeting criminal DDoS infrastructure, which has previously dismantled similar services and led to multiple arrests and domain seizures worldwide.
2 IoCs
Cisco warns of max severity ISE zero-day exploited in attacks
1d ago · bleeping-computer
Cisco has warned of active exploitation of a maximum-severity zero-day vulnerability, CVE-2026-76460, in its Identity Services Engine (ISE) and ISE-PIC software. The flaw allows remote attackers to bypass authentication by exploiting insufficient controls on an API endpoint, enabling unauthorized access to the web-based management interface. No workarounds exist, and Cisco strongly recommends applying security updates immediately. The Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to its Known Exploited Vulnerabilities catalog and mandated federal agencies to patch within three days.