Live threat intelligence — updated continuously

Open Cyber Threat Intelligence

Structured, AI-extracted threat intel. Free with no login required.

Latest Intelligence

View all →
Atomic macOS (AMOS) Stealer Activity

22h ago · unit42

This report details an analysis of the Atomic macOS (AMOS) stealer malware, observed in a lab environment on August 5, 2026. AMOS stealer is distributed via malicious websites and cracked software campaigns, using social engineering to trick users into pasting malicious commands into Terminal. The infection chain involves downloading a Zsh script that retrieves and executes a Mach-O binary, which establishes persistence and collects sensitive data including credentials, browser data, cryptocurrency wallets, and messaging app data. Exfiltration occurs via HTTP POST requests to command and control servers, with infrastructure and indicators frequently changing, indicating active development and evasion tactics.
17 IoCs
Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers

16h ago · hacker-news

Three distinct threat groups—NightEagle, Hacking Cat, and Toy Ghouls—are targeting Russian enterprises using backdoors, ransomware, and wipers. NightEagle exploits vulnerabilities like CVE-2019-0708 and CVE-2020-0688 to deploy the GhostContainer backdoor on Microsoft Exchange servers, enabling code execution and lateral movement. Hacking Cat, a pro-Ukrainian hacktivist group, uses Gorilla RAT and multiple variants of Monkey ransomware written in different languages, along with wiper malware Nemo Wiper, often in collaboration with other groups. Toy Ghouls has shifted to custom tools, deploying a new backdoor called Bird Agent that uses HiveMQ MQTT or Element (Matrix) for C2 communication, delivered via WinRM using tools like Evil-WinRM.
5 IoCs 2 Actors
One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude

17h ago · hacker-news

Security researchers at Forever Security demonstrated a method to hijack AI assistants in multiple Chromium-based browsers and extensions by exploiting browser extension permissions to intercept trusted communication channels. The technique leverages two common extension permissions—content modification and network request manipulation—to inject malicious code into trusted AI service pages, enabling unauthorized access to sensitive capabilities such as file reading, screenshot capture, and AI agent control. While no active exploitation in the wild has been observed, the research highlights critical design flaws in how AI agents are integrated into browsers, with CVE-2026-0628 (Chrome) and CVE-2026-55945 (Edge) officially recognized and patched, while similar issues in Comet, Opera Neon, and Claude in Chrome remain less formally addressed.
1 CVEs
Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution

16h ago · hacker-news

A critical vulnerability, CVE-2026-89026, in the Issabel Framework is being actively exploited, allowing unauthenticated remote attackers to execute arbitrary operating system commands. The flaw stems from a hard-coded JSON Web Token (JWT) signing key used across all installations, enabling attackers to forge valid bearer tokens. These tokens can be used to call the '/pbxapi/manager/originate' endpoint with the System application parameter, resulting in command execution as the Asterisk user. A patch was released on August 1, 2026, which replaces the hard-coded key with one stored in a configuration file.
4 IoCs
Malware bypasses browser checks to force install Chrome, Edge extensions

13h ago · bleeping-computer

A banking malware operation active since mid-2025, dubbed KREMLIN, has been force-installing malicious Chrome and Edge extensions to steal credentials, session tokens, and other sensitive data. The malware bypasses Chromium's integrity checks by copying extensions into browser profile directories and modifying Secure Preferences using extracted encryption keys and regenerated HMACs. The infection begins via malicious JavaScript files disguised as financial documents, establishes persistence through scheduled tasks, downloads Node.js, and retrieves payloads from Ethereum smart contracts or images hosted on the Internet Archive.
3 IoCs 2 Malware
Iranian hackers use CHOSEN BRICK Windows malware to spy on targets

11h ago · bleeping-computer

Iranian state-linked hackers are deploying a Windows malware named CHOSEN BRICK to conduct cyber espionage against dissidents, activists, and journalists globally. The malware is distributed via social engineering lures on messaging platforms like WhatsApp and Telegram, using disguised malicious files that mimic legitimate applications. Once installed, CHOSEN BRICK collects system information, steals communications from email and messaging apps, captures screenshots, records audio, and can download additional payloads or wipe the system. Data is exfiltrated through Telegram or cloud services, with newer variants using SOCKS5 proxies for stealth.
5 IoCs
Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks

21h ago · hacker-news

A high-severity vulnerability, CVE-2026-87886, in the Acronis Backup plugin for cPanel & WHM and Plesk has been exploited in limited, targeted attacks. The flaw allows local privilege escalation due to insecure file permissions, enabling low-privileged attackers to escalate privileges and execute arbitrary code on affected Linux systems. Acronis has released patches, urging all users to update immediately, though details about the attackers or their objectives remain unknown.
Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation

20h ago · hacker-news

Google has patched a high-severity privilege escalation vulnerability in the Pixel Cellular Modem, tracked as CVE-2026-58704, which has shown signs of limited, targeted exploitation in the wild. The flaw stems from a logic error that allows remote, proximal escalation of privilege without user interaction, enabling zero-click attacks. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to patch by September 19, 2026. No specific threat actor or campaign has been attributed, and technical details about the exploitation remain limited.
Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix

18h ago · hacker-news

A vulnerability in Parallels Desktop for Mac, tracked as CVE-2026-90894 and dubbed ParaShells, allows non-admin local users to gain root privileges by exploiting a world-writable socket and command injection in the prl_disp_service. The flaw affects versions prior to 27.0.0 and is actively exploitable on Apple silicon Macs; however, Intel Macs cannot install the fixed version (27.0.0 or later) due to dropped hardware support. JFrog, which discovered the issue, demonstrated a working exploit involving tar command injection via a maliciously crafted directory path, enabling privilege escalation to root without network access.
2 IoCs
Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories

18h ago · hacker-news

An attacker hijacked an active AI coding-assistant session at an unnamed SaaS provider and used it to recommend a poisoned PyPI package, which was accepted by a developer. This allowed the attacker to install an infostealer, steal GitHub OAuth tokens, and deploy the self-spreading Shai-Hulud worm across approximately 100 internal code repositories. The attacker also poisoned a package in the company's official namespace, leading to a second infection when another employee pulled the compromised version.
1 IoCs 1 Malware