Live threat intelligence — updated continuously
Open Cyber Threat Intelligence
Structured, AI-extracted threat intel. Free with no login required.
Latest Intelligence
View all → How One Kubernetes YAML Can Hand Over a GCP Organization
7h ago · bleeping-computer
A security vulnerability dubbed 'ConfigConfusion' allows attackers with access to a Kubernetes namespace to escalate privileges and gain full control of a Google Cloud (GCP) organization by exploiting misconfigurations in Google Kubernetes Config Connector (KCC). KCC uses a single, highly privileged service account to manage cloud resources on behalf of developers, but does not validate whether the requesting user has appropriate Google Cloud IAM permissions. As a result, an attacker can submit a malicious IAMPolicyMember YAML resource to grant themselves owner-level access to the entire GCP organization, even without possessing any cloud credentials. This represents a confused deputy problem where KCC acts as an overprivileged intermediary.
Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape
10h ago · hacker-news
A use-after-free vulnerability in the Linux kernel's AF_UNIX socket subsystem, tracked as CVE-2026-80521, enables container escape to gain root privileges on the host. The flaw affects unpatched Ubuntu 26.04, 24.04, and 22.04 LTS releases, despite an upstream fix being available since August 6, 2026. Security firm DepthFirst released exploit code targeting Ubuntu 26.04, demonstrating the practical risk of containerized environments where default seccomp policies allow access to AF_UNIX sockets. Although no active attacks have been confirmed, the vulnerability undermines container security assumptions, especially as AI-assisted research accelerates discovery of such flaws.
1 IoCs 1 CVEs
New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control
9h ago · hacker-news
cPanel disclosed three security flaws, two of which are critical, allowing privilege escalation and unauthorized access on shared hosting servers. CVE-2026-87899 enables a logged-in cPanel account holder to execute code as root via the CalDAV and CardDAV service, achieving full server control. CVE-2026-87900 affects the WP Toolkit plugin, allowing a user to modify databases belonging to other accounts. CVE-2026-68490 permits local users to read calendar and contact data from other accounts, though not modify it or escalate privileges. All vulnerabilities have been patched, but no exploitation in the wild has been reported.
Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI
7h ago · hacker-news
Unknown threat actors have compromised specific versions of the MemTensor packages on npm and PyPI, injecting a malicious Go-based credential stealer named sckit. The malicious packages, when used in development or CI environments, execute a payload that harvests sensitive credentials from cloud services, source control, package registries, and developer tools. The malware exfiltrates stolen data to the domain skyleen[.]fr and can self-propagate via GitHub, npm, and PyPI. Organizations are advised to pin to known clean versions, rotate secrets, and block the C2 domain.
5 IoCs
Arista patches actively exploited VeloCloud Orchestrator zero-day
9h ago · bleeping-computer
Arista Networks has patched a zero-day vulnerability, tracked as CVE-2026-93952, in its VeloCloud Orchestrator (VCO) On-Prem deployments that was actively exploited in the wild. The flaw stems from improper input validation and allows remote unauthenticated attackers to access privileged internal functionality by exploiting certificate-based authentication mechanisms. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to its Known Exploited Vulnerabilities catalog, requiring federal agencies to remediate by September 25, 2026.
3 IoCs
ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants
16h ago · hacker-news
ShinyHunters, a cyber extortion group, claimed responsibility for breaching the U.S. Federal Bureau of Investigation (FBI), asserting they exfiltrated sensitive data on current and former agents and job applicants. The group reportedly exploited a zero-day vulnerability in Oracle PeopleSoft to gain remote code execution and deface the FBI's jobs portal, FBIjobs.gov, with a taunting banner. They linked the attack to retaliation for an FBI public service announcement criticizing their prior activities, particularly around the Canvas LMS breach. While the FBI has acknowledged awareness of the claims and is investigating, no technical evidence or data dumps have been independently verified yet.
1 IoCs 1 Actors
Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input
14h ago · hacker-news
A critical vulnerability in Next.js, tracked as CVE-2026-94545, allows server-side code execution when attacker-controlled input is processed by the ImageResponse feature during SVG generation. The flaw exists in versions 16.2.0 through 16.3.5 when using the Node.js runtime, where unsanitized input can be interpreted as SVG code due to improper escaping in the underlying Satori library. This could enable remote attackers to execute arbitrary code on the server if user-supplied values are embedded in SVG content, attributes, or styles. The vulnerability was patched in Next.js 16.3.6 and Satori 0.33.5, with no public exploits or active attacks reported at the time of disclosure.
Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
13h ago · hacker-news
A Chinese threat actor, UTA0565, exploited a zero-day chain involving vulnerabilities in Google Chrome and Microsoft Windows to deploy a new malware family named CLEANGULP. The attacks, observed on September 3 and 4, 2026, used fake websites mimicking media organizations and NGOs to deliver the BlueMoon exploit kit, which leveraged CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 to escape the browser sandbox and execute code remotely. The malware, delivered as 'chrome_cleanup.exe', communicates with a hard-coded C2 domain and provides capabilities including command execution, process listing, file upload/download, and beacon object file execution.
5 IoCs 1 CVEs
F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
13h ago · hacker-news
F5 has patched a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager (APM) that allows unauthenticated remote code execution on systems where APM is configured as an OAuth authorization server. The vulnerability is a heap-based buffer overflow with a CVSS v3.1 score of 9.8, and it is actively exploited in the wild. Malicious traffic targeting the virtual server can trigger remote code execution, bypassing protections on the management interface. The U.S. CISA has added the flaw to its Known Exploited Vulnerabilities catalog and mandated federal agencies to apply mitigations within three days.
F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks
14h ago · bleeping-computer
F5 has released security updates to address a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP APM (Access Policy Manager) product that is being actively exploited in remote code execution attacks. The vulnerability affects systems configured as an OAuth Authorization Server with specific access policies and OAuth profiles on a virtual server. Exploitation can lead to remote code execution, and F5 has confirmed active attacks. The Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to its Known Exploited Vulnerabilities catalog and mandated federal agencies to remediate by a specified deadline.