Live threat intelligence — updated continuously

Open Cyber Threat Intelligence

Structured, AI-extracted threat intel. Free with no login required.

Latest Intelligence

View all →
Hackers hijack HBO Max Reddit account to push malware in ClickFix ads

13h ago · bleeping-computer

Hackers hijacked HBO Max's verified Reddit account (u/hbomax) to distribute malicious advertisements as part of a campaign dubbed PasteSwitch. These ads used ClickFix social engineering tactics, tricking users into pasting malicious commands into Windows Run, PowerShell, or macOS Terminal under the guise of installing legitimate software or fixing errors. The attack distributed information-stealing malware such as MacSync and AMOS helper on macOS, and PowerShell-based payloads on Windows, including memory-resident Amatera Stealer. Attackers used domains like hbomaxx[.]us and infrastructure including ember-bridge[.]com to deliver payloads and rotate between campaigns targeting both general users and developers.
7 IoCs
Twitch extension with 30K installs exposes users’ OAuth tokens

13h ago · bleeping-computer

The Twitch Enhanced Viewer | JeetBot browser extension, with over 30,000 installs on Chrome and Firefox, captures users' Twitch OAuth tokens and sends them to proxy servers controlled by JeetBot, a commercial Russian-language streaming and chatbot service. The tokens are transmitted as cleartext in URL query parameters when video playlist requests are proxied, exposing them in server logs. Earlier versions of the extension openly admitted to collecting OAuth tokens, claiming it was necessary for HD streaming functionality. Security researchers recommend users uninstall the extension, revoke Twitch sessions, and re-authenticate to mitigate exposure.
1 IoCs
Japan's Digital Agency says VPN flaw exposed 246,000 personnel records

11h ago · bleeping-computer

Japan's Digital Agency disclosed a data breach resulting from exploitation of a vulnerability in a VPN device used by the Government Solution Service (GSS). The attacker gained unauthorized access by exploiting the flaw, leading to potential exposure of approximately 246,000 records containing personal information of government employees and associated individuals. The exposed data includes names, email addresses, telephone numbers, and physical addresses, though sensitive identifiers such as My Number, bank accounts, and pension numbers were not compromised. The agency contained the breach by suspending the compromised account and isolating the affected system, with no evidence of data misuse found to date.
Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries

15h ago · hacker-news

A suspected Chinese threat actor known as Red Heron has exploited CVE-2026-60004, a critical remote code execution vulnerability in Gitea, to compromise 13 organizations across six countries. The campaign targeted sectors including defense, government, energy, and telecommunications, using automated exploitation to gain initial access, steal source code, and establish persistent access. The attackers deployed a custom Linux backdoor named JITTERLY and a novel LD_PRELOAD rootkit called SIXZUT to maintain stealth and enable post-exploitation activities such as credential theft, lateral movement, and data exfiltration.
2 IoCs 1 CVEs
Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports

14h ago · hacker-news

A vulnerability in Telegram Desktop versions 4.15.1 through 6.9.3 allowed malicious bots to embed hidden JavaScript within inline keyboard buttons, which could be executed when users opened HTML chat exports in a browser. The script could exfiltrate all messages in the exported file or rewrite the page content, such as displaying a fake verification form. The flaw was fixed in versions 6.9.4 (beta) and 7.0.1 (stable) released in July 2026, but previously exported HTML files remain vulnerable if opened in browsers with JavaScript enabled. No CVE has been assigned, and Telegram did not publicly acknowledge the issue despite confirmation and a declined bug bounty.
3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials

14h ago · hacker-news

An attacker gained and maintained persistent access within the network of 3BB, a major Thai broadband provider, by deploying a hidden MeshCentral backdoor configured to report to a malicious command-and-control server. The attacker used legitimate administrative tools and scripts to escalate privileges, conduct internal reconnaissance, and target RADIUS databases containing subscriber credentials. Indicators show active administrative control over internal systems, password spraying, and attempts to exfiltrate sensitive authentication data. The intrusion was discovered via an exposed external server containing attacker tools, though the initial access vector remains unconfirmed despite evidence of exploit capabilities for CVE-2024-21762 in FortiGate devices.
6 IoCs
New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing

14h ago · hacker-news

Researchers have disclosed a hardware-based attack called DDRop that exploits a design flaw in Intel TDX, Intel Scalable SGX, and AMD SEV-SNP confidential computing technologies. The attack uses a low-cost interposer device inserted between the processor and memory module to silently drop memory writes, allowing an attacker to manipulate encrypted memory by forcing the reuse of stale data. This enables privilege escalation, memory read/write access to victim virtual machines, and tampering with attestation mechanisms. The vulnerability stems from the lack of a freshness check in memory encryption designs, and no software patch can fully mitigate it due to its hardware-level nature.
1 IoCs
Hackers target exposed Vite dev servers to steal AWS, Azure secrets

16h ago · bleeping-computer

Hackers are conducting a mass-scanning campaign targeting internet-exposed Vite development servers, exploiting CVE-2026-39364 to bypass file access controls and steal sensitive cloud credentials from AWS and Azure environments. The attackers use specific query parameters to retrieve environment files, cloud credentials, Terraform configurations, and system information. The activity has been observed originating from IP addresses in the United States, Belgium, and the Netherlands, with attackers leveraging Google Cloud infrastructure for evasion.
3 IoCs 4 CVEs
Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users

1d ago · hacker-news

A malicious browser extension named 'Twitch Enhanced Viewer | JeetBot' has leaked OAuth tokens of nearly 31,000 users by forwarding them to proxy servers controlled by a Russian commercial bot service. The extension, available on Chrome and Firefox, sends the user's Twitch OAuth token via an &auth= query parameter during video playlist requests, exposing sensitive credentials that allow access to private messages, chat, and account settings. The token leakage occurs for all channels except a hardcoded list of 10 Russian streamers. While the developer has released a patched version (85.8.7) for Firefox, older versions continue to transmit tokens, and previously exposed tokens are not automatically revoked.
5 IoCs
Revolut discloses data breach exposing financial info, passports

23h ago · bleeping-computer

Revolut disclosed a data breach in which a threat actor impersonated a legitimate government agency by using its authenticated email domain to request customer data. The company inadvertently fulfilled the request, leading to the exposure of personally identifiable information, identity documents, financial records, and transaction history for a limited number of customers. The breach did not impact Revolut's systems or customer funds, and the company claims to have blocked the malicious actor and notified relevant authorities upon detection.