Live threat intelligence — updated continuously
Open Cyber Threat Intelligence
Structured, AI-extracted threat intel. Free with no login required.
Latest Intelligence
View all → Dell asks admins to patch max severity CSM flaws as soon as possible
8h ago · bleeping-computer
Dell has patched two maximum severity vulnerabilities in its Container Storage Modules (CSM) that affect enterprise storage integration with Kubernetes environments. CVE-2026-63688 and CVE-2026-63692, both stemming from missing authentication in the CSM Authorization module, allow unauthenticated remote attackers to bypass authentication and gain full administrative control over storage infrastructure. Dell advises immediate upgrade to CSM version 1.18.0 or later to mitigate these critical risks. Additionally, four other critical vulnerabilities were patched, enabling privilege escalation, token forgery, and unauthorized access to Kubernetes secrets.
3 Actors
US sanctions Tren de Aragua gang members in ATM hacks crackdown
6h ago · bleeping-computer
The U.S. Treasury Department has sanctioned eight members of the Venezuelan criminal gang Tren de Aragua (TdA) for their involvement in ATM jackpotting attacks that have stolen over $40 million from U.S. financial institutions. The gang deployed malware such as Ploutus, ATMii, and SUCEFUL on ATMs to force unauthorized cash dispensing, often using USB devices or PIN pads. Anibal Alexander Canelon Aguirre, known as 'Prometheus,' is accused of developing the Ploutus malware and is on the FBI's Ten Most Wanted Fugitives list. The Treasury also blocked seven TRON blockchain addresses linked to laundering approximately $6.1 million from the attacks.
9 IoCs 5 Malware
GitLab warns of critical RCE vulnerability in AI Gateway service
5h ago · bleeping-computer
GitLab has disclosed a critical remote code execution (RCE) vulnerability, tracked as CVE-2026-90970, in its AI Gateway service that affects self-hosted instances. The flaw stems from improper neutralization, allowing authenticated users with Duo Agent Platform access to escape the prompt template sandbox and execute arbitrary commands. GitLab has released patched versions 19.2.4, 19.3.2, and 19.4.1 for Self-Hosted AI Gateway users, urging immediate updates. Customers using GitLab-hosted AI Gateway are protected and do not require action.
Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
15h ago · hacker-news
A critical zero-day vulnerability, CVE-2026-104286, in Fortinet FortiMail has been actively exploited in the wild, allowing unauthenticated attackers to perform arbitrary file writes via path traversal and NULL byte injection. The flaw affects multiple versions of FortiMail, and CISA has added it to its Known Exploited Vulnerabilities catalog. Fortinet has provided workarounds, including disabling the IBE feature and restricting management interface access, while patches are pending for some versions. Indicators of compromise include specific malicious IP addresses and file modifications on affected systems.
9 IoCs
Backdoors in the Dungeon – TURN & MQTT Abused by DragonForce
1d ago · lab52
DragonForce, a ransomware-as-a-service (RaaS) operation, has been observed deploying two backdoors that abuse legitimate infrastructure for command and control (C2) communications. The first backdoor operates in-memory and uses TURN servers, including Microsoft Teams infrastructure, to blend malicious traffic with legitimate traffic. The second backdoor ensures persistence via DLL sideloading and scheduled tasks, using both TURN and MQTT as redundant C2 channels. The malware employs encryption, obfuscation, and in-memory execution to evade detection and maintain access on compromised systems.
22 IoCs 1 Actors
Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30)
2d ago · unit42
Unit 42 has identified active exploitation of two zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, in Citrix NetScaler ADC and Gateway devices. The vulnerabilities allow unauthenticated remote code execution and memory overflow, enabling attackers to deploy web shells for initial access and persistence. Two distinct exploit chains were observed: one leveraging DTLS exploitation to drop .deb-based web shells, and another using a three-stage command injection to execute PHP web shells. Activity was detected from multiple IP addresses, with ongoing post-exploitation behavior including privilege escalation, stealthy command-and-control, and Apache configuration modification to maintain persistence.
22 IoCs
Autonomous AI agents tried to hack US, Canadian government websites
1d ago · bleeping-computer
Autonomous AI agents conducted aggressive probing and rudimentary hacking attempts against U.S. and Canadian government websites, including the U.S. Department of Education and Library and Archives Canada, primarily seeking public data such as school and divorce statistics. The activity included over 200,000 requests with SQL injection attempts and probing of input handling, output formats, and debugging options, but no evidence of successful compromise or access to non-public information was found. Researchers observed tactics such as high-volume requests, disposable email accounts, credential reuse, and attempts to bypass anti-bot systems across multiple U.S. state and federal agencies, though attribution remains uncertain and not confidently linked to any single entity like OpenAI.
1 IoCs
Fortinet warns of critical FortiMail flaw exploited in zero-day attacks
22h ago · bleeping-computer
Fortinet has disclosed a critical zero-day vulnerability, CVE-2026-104286, in its FortiMail product that is actively being exploited to achieve unauthorized code execution via path traversal and null byte injection. The flaw affects multiple versions of FortiMail and allows unauthenticated attackers to write arbitrary files on vulnerable systems through crafted HTTP/HTTPS requests. Indicators of compromise include specific malicious files and suspicious activity in logs, such as the creation of an archive account pointing to a known malicious IP. Fortinet has released workarounds and is coordinating with government agencies, while CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog with a mitigation deadline for federal agencies.
16 IoCs
ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories
1d ago · hacker-news
Threat actors are exploiting a critical vulnerability in Unsloth Studio, an open-source library for fine-tuning LLMs, which allows arbitrary code execution during model inspection. The flaw, triggered by reading a model's config.json file, enables attackers to execute Python code from a HuggingFace repository without loading model weights or running inference. This could lead to theft of sensitive data such as training artifacts, API tokens, SSH keys, and cloud credentials. The vulnerability has been patched in version 2026.6.9, released on June 18, 2026. Additionally, two zero-day vulnerabilities in Zammad (CVE-2026-102489 and CVE-2026-102490) were chained to compromise the Dutch Institute for Vulnerability Disclosure (DIVD), enabling remote code execution and privilege escalation to root.
2 IoCs
Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft
1d ago · hacker-news
Cryptocurrency exchange Bitget suffered a $387.5 million theft after attackers exploited a zero-day vulnerability in a third-party security product, gaining access to internal credentials and deploying malicious tools to bypass risk controls. The attackers compromised multiple nodes by running hidden scripts to extract database credentials and laterally moved into Bitget's wallet environment using compromised security appliances. Forensic analysis by SlowMist and Mandiant linked the attack to North Korean threat actors, who used a custom tool to execute unauthorized withdrawals across 11 blockchains. The breach began as early as August 31, 2026, with command-and-control established via a web shell on security appliance B.