Live threat intelligence — updated continuously
Open Cyber Threat Intelligence
Structured, AI-extracted threat intel. Free with no login required.
Latest Intelligence
View all → New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline
14h ago · hacker-news
A high-severity zero-day vulnerability, CVE-2026-88779, in Citrix NetScaler ADC and NetScaler Gateway is being actively exploited in targeted attacks to cause denial-of-service conditions on SAML-enabled deployments. The flaw is a memory overflow issue that can be triggered when the appliance is configured as a SAML service provider or identity provider. Citrix has released patches for affected versions, and CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch by October 7, 2026. No data integrity impact has been observed, but repeated exploitation can render services unavailable.
Citrix patches NetScaler SAML zero-day exploited in attacks
23h ago · bleeping-computer
Citrix has released emergency patches for a zero-day vulnerability, CVE-2026-88779, affecting NetScaler ADC and NetScaler Gateway appliances with SAML authentication enabled. The flaw, which stems from a memory buffer issue, has been exploited in active attacks to cause denial-of-service conditions, with evidence suggesting potential for remote code execution. Researchers and administrators have observed malicious activity, including shell command injection in authentication attempts and crashes of the nsaaad and Pitboss processes. A specific IP address, 213.209.159.55, has been linked to payload delivery, and CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch by October 7.
1 IoCs
China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing
1d ago · hacker-news
China-aligned threat actor TA419 has conducted credential phishing campaigns targeting U.S. AI policy experts at think tanks, universities, and legal organizations since at least April 2025. The attacks involve impersonation of trusted individuals and use a multi-stage phishing flow featuring shortened URLs that redirect to a malicious OneDrive-based adversary-in-the-middle (AitM) page. This page employs a 'Frameless BitB' technique—using HTML, CSS, and JavaScript without iframes—to spoof Microsoft login pages and stealthily capture session cookies while relaying authentication to legitimate Microsoft infrastructure, making detection difficult.
ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members
1d ago · hacker-news
ShinyHunters, a prolific cybercriminal group known for data breaches and extortion, is under increased law enforcement pressure following the reported detention of a key suspect, Saif al-Din Khader (alias Rey/ReyXBF), in Jordan. Khader, allegedly a former administrator of BreachForums and Scattered LAPSUS$ Hunters, is cooperating with the FBI to identify other group members. The group has been linked to over 140 breaches and $70 million in extortion payments, recently exploiting a Grav CMS vulnerability to hijack the Cl0p ransomware group's darknet site and breaching the FBI’s job portal, stealing approximately three terabytes of data. ShinyHunters claims the FBI breach was not financially motivated but intended to challenge false allegations and their alleged ties to The Com cybercrime collective.
1 IoCs 3 Actors 2 Malware
Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
2d ago · hacker-news
The China-linked threat actor Warlock, also known as Longlegs or Gold Salem, is actively exploiting vulnerabilities in on-premises Microsoft SharePoint Server deployments to gain initial access, deploy web shells, and achieve remote code execution. The group targets organizations in Portuguese- and Spanish-speaking countries, including critical infrastructure, government, and education sectors. After gaining access, Warlock uses DLL sideloading, legitimate cloud storage services for payload delivery, and the BYOVD technique with a vulnerable driver to disable security tools. The attackers then deploy ransomware at scale by staging payloads in the SYSVOL share and leveraging living-off-the-land techniques such as VS Code tunnels for persistence and lateral movement.
2 IoCs 2 Actors 1 Malware
ShinyHunters hacker reportedly detained in Jordan, aiding FBI
2d ago · bleeping-computer
A suspected member of the ShinyHunters hacking group, known online as 'Rey' and identified as Saif al-Din Khader, has been reportedly detained in Jordan and is cooperating with the FBI. The ShinyHunters group claimed responsibility for breaching FBI systems via an alleged Oracle PeopleSoft zero-day vulnerability, later moving laterally into AWS GovCloud environments and exfiltrating 2–3TB of sensitive data. The group has been linked to multiple high-profile breaches, including attacks on Google, Cisco, Instructure Canvas, and Jaguar Land Rover, often exploiting third-party integrations and stolen authentication tokens. Following recent arrests and detentions, ShinyHunters-linked infrastructure showed signs of disruption, including the temporary takedown of their data leak site, though a new site later emerged indicating ongoing operations.
1 Actors
Danish university DTU breach exposes data of up to 200,000 people
2d ago · bleeping-computer
The Technical University of Denmark (DTU) suffered a data breach in which an attacker used compromised credentials to access DTUBasen, its identity and access management system, and exfiltrated a large volume of user data. The breach potentially exposed personal information of up to 200,000 individuals, including current and former students, employees, guests, and external partners, with data dating back to 2003. Exposed information includes Danish civil registration numbers (CPR), names, home addresses, job titles, office locations, next of kin details, and profile pictures. DTU warns that the stolen data could be used for identity fraud and highly targeted phishing attacks.
Pretty Themes, Hidden Loaders: GlassWorm-Linked Extensions Span VS Code Marketplace and Open VSX
2d ago · socket-dev
Socket discovered a cluster of malicious and high-risk VS Code extensions linked to the GlassWorm supply chain campaign, spanning both the Visual Studio Marketplace and Open VSX. Two confirmed malicious extensions—Aurora Nocturne Night Theme and Cosmic Nebula Themes—were found to deploy JavaScript-based malware loaders that execute obfuscated code, exfiltrate data, and dynamically resolve follow-on payloads via Solana blockchain transaction memos. The threat actor used deceptive tactics including brandjacking, code obfuscation, and Git history manipulation to distribute malicious themes. The campaign avoids Russian systems and has reused infrastructure, code patterns, and publisher identities across multiple extensions, indicating coordinated activity. Although some extensions are no longer weaponized, they retain dangerous executable capabilities and are assessed as high-risk due to their development lineage.
19 IoCs 1 Malware
Sckit Supply Chain Worm Hits MemTensor npm & PyPi scopes
5d ago · step-security
A supply chain attack has compromised specific versions of the @memtensor/memos-cloud-openclaw-plugin npm package (0.1.21, 0.1.23, 0.1.25) and the MemoryOS PyPI package (version 2.0.34). The malicious releases include a hidden launcher that executes a credential-harvesting payload during plugin initialization or import, potentially capturing environment variables, prompts, and secrets. The payload targets developer environments by harvesting credentials for cloud platforms, source control, package registries, and AI services, and exfiltrates data to attacker-controlled domains. The attack includes multiple stages, including a TLS trust fallback, embedded configuration with expiration, and a conditional CI delivery mechanism designed to propagate further compromises.
47 IoCs
Give yourself room to be human
4d ago · talos
Cisco Talos identified a threat actor group, UAT-11587, linked to China, targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia. The campaign delivers a previously undocumented backdoor named 'Antino', identified from developer artifacts. The actors are using targeted malware deployments, with specific malicious files observed in telemetry. This activity represents a focused espionage effort against high-value geopolitical targets.
15 IoCs