Live threat intelligence — updated continuously

Open Cyber Threat Intelligence

Structured, AI-extracted threat intel. Free with no login required.

Latest Intelligence

View all →
Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

6h ago · hacker-news

The China-linked threat actor Warlock, also known as Longlegs or Gold Salem, is actively exploiting vulnerabilities in on-premises Microsoft SharePoint Server deployments to gain initial access, deploy web shells, and achieve remote code execution. The group targets organizations in Portuguese- and Spanish-speaking countries, including critical infrastructure, government, and education sectors. After gaining access, Warlock uses DLL sideloading, legitimate cloud storage services for payload delivery, and the BYOVD technique with a vulnerable driver to disable security tools. The attackers then deploy ransomware at scale by staging payloads in the SYSVOL share and leveraging living-off-the-land techniques such as VS Code tunnels for persistence and lateral movement.
2 IoCs 2 Actors 1 Malware
ShinyHunters hacker reportedly detained in Jordan, aiding FBI

2h ago · bleeping-computer

A suspected member of the ShinyHunters hacking group, known online as 'Rey' and identified as Saif al-Din Khader, has been reportedly detained in Jordan and is cooperating with the FBI. The ShinyHunters group claimed responsibility for breaching FBI systems via an alleged Oracle PeopleSoft zero-day vulnerability, later moving laterally into AWS GovCloud environments and exfiltrating 2–3TB of sensitive data. The group has been linked to multiple high-profile breaches, including attacks on Google, Cisco, Instructure Canvas, and Jaguar Land Rover, often exploiting third-party integrations and stolen authentication tokens. Following recent arrests and detentions, ShinyHunters-linked infrastructure showed signs of disruption, including the temporary takedown of their data leak site, though a new site later emerged indicating ongoing operations.
1 Actors
Danish university DTU breach exposes data of up to 200,000 people

6h ago · bleeping-computer

The Technical University of Denmark (DTU) suffered a data breach in which an attacker used compromised credentials to access DTUBasen, its identity and access management system, and exfiltrated a large volume of user data. The breach potentially exposed personal information of up to 200,000 individuals, including current and former students, employees, guests, and external partners, with data dating back to 2003. Exposed information includes Danish civil registration numbers (CPR), names, home addresses, job titles, office locations, next of kin details, and profile pictures. DTU warns that the stolen data could be used for identity fraud and highly targeted phishing attacks.
Pretty Themes, Hidden Loaders: GlassWorm-Linked Extensions Span VS Code Marketplace and Open VSX

10h ago · socket-dev

Socket discovered a cluster of malicious and high-risk VS Code extensions linked to the GlassWorm supply chain campaign, spanning both the Visual Studio Marketplace and Open VSX. Two confirmed malicious extensions—Aurora Nocturne Night Theme and Cosmic Nebula Themes—were found to deploy JavaScript-based malware loaders that execute obfuscated code, exfiltrate data, and dynamically resolve follow-on payloads via Solana blockchain transaction memos. The threat actor used deceptive tactics including brandjacking, code obfuscation, and Git history manipulation to distribute malicious themes. The campaign avoids Russian systems and has reused infrastructure, code patterns, and publisher identities across multiple extensions, indicating coordinated activity. Although some extensions are no longer weaponized, they retain dangerous executable capabilities and are assessed as high-risk due to their development lineage.
19 IoCs 1 Malware
Sckit Supply Chain Worm Hits MemTensor npm & PyPi scopes

3d ago · step-security

A supply chain attack has compromised specific versions of the @memtensor/memos-cloud-openclaw-plugin npm package (0.1.21, 0.1.23, 0.1.25) and the MemoryOS PyPI package (version 2.0.34). The malicious releases include a hidden launcher that executes a credential-harvesting payload during plugin initialization or import, potentially capturing environment variables, prompts, and secrets. The payload targets developer environments by harvesting credentials for cloud platforms, source control, package registries, and AI services, and exfiltrates data to attacker-controlled domains. The attack includes multiple stages, including a TLS trust fallback, embedded configuration with expiration, and a conditional CI delivery mechanism designed to propagate further compromises.
47 IoCs
Give yourself room to be human

2d ago · talos

Cisco Talos identified a threat actor group, UAT-11587, linked to China, targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia. The campaign delivers a previously undocumented backdoor named 'Antino', identified from developer artifacts. The actors are using targeted malware deployments, with specific malicious files observed in telemetry. This activity represents a focused espionage effort against high-value geopolitical targets.
15 IoCs
Frontline Education breach exposes school district employee data

1d ago · bleeping-computer

Frontline Education suffered a data breach in August 2026 after attackers exploited a vulnerability in a third-party software product, leading to unauthorized access to employee data. The compromised information includes Social Security numbers, email addresses, and physical addresses of school district employees. The company has not disclosed the specific third-party application involved or the exact timeline of the breach, but is offering affected individuals two years of credit monitoring and identity theft protection through TransUnion.
1 IoCs
Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes

1d ago · hacker-news

Dell has disclosed multiple critical vulnerabilities in its Container Storage Modules (CSM) affecting versions prior to 1.17.0, which were patched in version 1.18.0. The most severe flaws include CVE-2026-63688 and CVE-2026-63692, both with a CVSS score of 10.0, enabling unauthenticated remote attackers to gain administrative access to storage infrastructure and Kubernetes clusters. Exploitation of these vulnerabilities could allow full control over storage systems, privilege escalation to root, and unauthorized manipulation of access policies across tenants.
Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

1d ago · hacker-news

A China-nexus threat actor tracked as UAT-11587 has been conducting a cyber espionage campaign since September 2025, targeting government and policy organizations across Asia and Syria. The campaign uses a previously undocumented Rust-compiled Windows backdoor named Antino, which leverages Microsoft 365 services—specifically Outlook and OneDrive—for command-and-control (C2) communications. Initial access is achieved via spear-phishing emails with spoofed sender identities and a fake Gmail attachment preview widget, leading to a multi-stage infection chain culminating in the deployment of the Antino backdoor using DLL sideloading.
4 IoCs 3 Actors
GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

1d ago · hacker-news

GitLab has patched a critical vulnerability, CVE-2026-90970, in its self-hosted AI Gateway that could allow a logged-in user with access to the Duo Agent Platform to execute arbitrary commands on the gateway via a crafted custom flow configuration. The flaw, rated 9.9 on the CVSS scale, stems from a prompt template sandbox escape in the AI Gateway's custom flow feature. Organizations hosting their own AI Gateway instances are advised to update immediately to fixed versions 19.2.4, 19.3.2, or 19.4.1, as no workaround is available and exploitation could lead to command execution on the underlying system.