Live threat intelligence — updated continuously

Open Cyber Threat Intelligence

Structured, AI-extracted threat intel. Free with no login required.

Latest Intelligence

View all →
Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine

3h ago · hacker-news

In December 2025, attackers breached a Polish combined heat and power (CHP) plant by exploiting a private cellular network (APN) used by the grid operator. The intrusion originated from a compromised wind farm's FortiGate firewall, which had internet-exposed VPN services without multi-factor authentication. From there, attackers pivoted via SSH tunneling through a Teltonika RUTX50 router to access a WAGO PFC200 controller with default credentials, ultimately gaining control of Siemens PLCs and shutting down critical systems including a steam turbine and water treatment. No malware was used; destructive actions were carried out using legitimate device functions. The attack highlights risks in misconfigured private APNs and poor credential hygiene in operational technology environments.
BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

4h ago · hacker-news

A supply chain attack on WordPress plugins distributed by BdThemes exploited a cross-site scripting (XSS) vulnerability in a remote JSON data stream used by the 'Biggopti' component. Attackers compromised a DigitalOcean Spaces bucket to inject malicious JavaScript payloads that execute in the browser of logged-in administrators, creating rogue admin accounts and deploying a PHP web shell. The attack does not modify plugin source code but instead poisons JSON responses, enabling silent exploitation on every wp-admin page load. Two payloads were identified: one retrieves targeting instructions from a C2 server, while the other generates deterministic credentials based on the victim's hostname, allowing attackers to access compromised sites without centralized credential storage.
4 IoCs
Hackers breached a small Polish energy plant via private APN last year

11h ago · bleeping-computer

In December 2025, a threat actor linked to the Russian Electrum group breached a small Polish combined heat-and-power (CHP) plant by exploiting a misconfigured private Access Point Name (APN) network. The attackers gained initial access through a compromised FortiGate firewall and Teltonika cellular router at a wind farm, then moved laterally through the private APN to reach the CHP plant's operational technology (OT) network. They exploited default credentials on a WAGO PFC200 PLC, used it as a bridge to access Siemens PLCs, and ultimately shut down critical systems including the steam turbine and water treatment system.
3 IoCs 1 Actors
BdThemes plugins supply-chain hack creates rogue WordPress admins

13h ago · bleeping-computer

A supply-chain attack on BdThemes, a developer of premium WordPress plugins, allowed a threat actor to compromise its infrastructure and inject malicious JavaScript into a remote JSON feed used by its plugins. This feed is loaded in the WordPress admin dashboard, where the attacker exploited a cross-site scripting (XSS) vulnerability in the Biggop Library to create rogue administrator accounts on affected sites. The attack was stealthy, required no user interaction, and used a webshell for persistence. The same actor is believed to be behind recent similar attacks on other WordPress plugins.
3 IoCs
Valve notifies Steam hardware customers of a data breach

22h ago · bleeping-computer

Valve notified European Steam hardware customers of a data breach resulting from a cyberattack on its shipping partner, CEVA Logistics, between July 29 and August 1, 2026. Attackers accessed CEVA's systems and likely exfiltrated customer data including names, addresses, phone numbers, email addresses, and details of hardware orders. Valve confirmed that no Steam account credentials, payment information, or other sensitive account data were exposed. The company warned customers about potential phishing attempts leveraging the stolen personal information.
⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors

19h ago · hacker-news

A zero-day vulnerability in Metabase, a business intelligence platform, is being exploited in the wild, allowing unauthenticated remote attackers to perform SQL injection and gain full administrator access to affected instances. This enables attackers to steal database credentials, exfiltrate data, and modify configurations. The vulnerability has a CVSS score of 10.0 but lacks a CVE identifier. One confirmed victim is Framework. Additionally, Chinese-made Zbtlink routers were found shipping with a factory-installed backdoor that phones home to Chinese C2 servers every 35 seconds, affecting at least 20 models. The backdoor enables remote command execution. Separately, the threat actor UNC6671 is conducting vishing attacks against financial firms, using voice phishing to capture credentials and MFA tokens via adversary-in-the-middle infrastructure, then deploying scripts for data exfiltration from cloud environments.
2 IoCs 1 Actors
China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

17h ago · hacker-news

Storm-1175, a China-linked financially motivated threat actor, has deployed a new ransomware named StormEncryptor, written in C++, which appends the '.encrypted' extension to encrypted files and drops a ransom note titled '!!!README_FIRST!!!.txt'. The group likely gained initial access by exploiting CVE-2026-18577, a patch bypass vulnerability in N-able N-central, which allows authentication bypass and account takeover. Storm-1175 has a history of exploiting vulnerabilities in internet-facing systems, rapidly moving from initial access to data exfiltration and ransomware deployment within days, using tools like AnyDesk, SimpleHelp, Advanced IP Scanner, and Mimikatz for credential dumping.
1 IoCs 1 Actors 2 CVEs
New StormEncryptor ransomware used by former Medusa affiliate

16h ago · bleeping-computer

A China-based threat actor tracked as Storm-1175, previously associated with the Medusa ransomware operation, has shifted to using a new ransomware variant called StormEncryptor. The actor exploits a vulnerability in the N-central RMM tool (CVE-2026-18577) to gain initial access, then uses tools like AnyDesk, SimpleHelp, Advanced IP Scanner, and Mimikatz for lateral movement and credential dumping. StormEncryptor is written in C++, encrypts files appending the '.encrypted' extension, and drops a ransom note titled '!!!README_FIRST!!!.txt', threatening data leakage if payment is not negotiated within three days.
8 IoCs 1 Actors
CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs

19h ago · bleeping-computer

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are actively exploiting two recently patched vulnerabilities in SonicWall SMA1000 appliances, tracked as CVE-2026-15409 and CVE-2026-15410. These flaws, including a critical server-side request forgery (SSRF) vulnerability, were exploited in zero-day attacks as early as June 22, prior to public disclosure. A threat actor known as UTA0533 has been linked to the exploitation of these vulnerabilities to deploy custom malware such as KNUCKLEBALL, Sou5, ROOTRUN, and ORANGETAIL on vulnerable systems. CISA added the vulnerabilities to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch within three days.
Inside the Metabase SQLi: Exploited in the Wild

19h ago · wiz

A zero-day SQL injection vulnerability in Metabase, tracked as GHSA-vwf4-m7j8-wcjf, has been exploited in the wild against Metabase Cloud and potentially self-hosted instances. The vulnerability exists in versions 1.58 and later, where an attacker can inject malicious SQL by including a 'user-id' parameter with a 'raw' SQL payload in the /api/session/reset_password endpoint. The flaw stems from improper handling of JSON input, merging of unvalidated user input, and unsafe use of HoneySQL's :raw directive, leading to arbitrary blind SQL injection. Wiz Research reverse-engineered the vulnerability after the patch was not publicly disclosed, and observed public proof-of-concept exploits as of August 10, 2026.
3 IoCs