Live threat intelligence — updated continuously
Open Cyber Threat Intelligence
Structured, AI-extracted threat intel. Free with no login required.
Latest Intelligence
View all → Attackers conceal phishing lures using invisible Unicode characters
18h ago · bleeping-computer
Threat actors are using a technique called ASCII smuggling, inserting invisible Unicode characters (from the Tags block U+E0000–U+E007F) into finance-related keywords in phishing emails to evade detection by email security filters. Microsoft observed a large-scale campaign peaking at 2.37 million messages per day, primarily using sender domains associated with the ActiveCampaign email platform. The obfuscation splits words like 'funding' into 'fun[Unicode]ding' to bypass keyword-based detection, though most messages were still caught by other signals such as sender reputation. Microsoft recommends normalizing or stripping invisible Unicode characters to defend against this tactic in both email filtering and AI prompt processing.
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
1d ago · hacker-news
Elastic Security Labs identified four malicious modules—ProManager, WinUpdate, SoftManager, and LockAppHost—linked to the REVSTEALER information stealer. These modules persist on infected systems after the main stealer deletes itself and perform various malicious activities, including cryptocurrency wallet theft, clipboard manipulation, reverse proxy setup, and cryptocurrency mining. LockAppHost disables Windows Update and Microsoft Defender to run a miner with elevated privileges, weakening system defenses. The modules share code and infrastructure with REVSTEALER, including use of Polygon blockchain for C2 resiliency and common packer techniques.
9 IoCs
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
23h ago · hacker-news
Attackers are exploiting a vulnerability chain in MikroTik RouterOS, dubbed 'MikroTrick' by CERT Polska, to gain full administrative control of internet-exposed routers via SSH without authentication. The attacks, observed since at least September 2, 2026, target unpatched devices across multiple RouterOS versions. CERT recommends immediate updates to fixed firmware versions, as temporary mitigations include disabling exposed management services and avoiding use of built-in clients from unpatched systems. Evidence of compromise includes unexpected privileged accounts and specific SSH login logs.
The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications
3w ago · unit42
Aeternum is a recently discovered C++ botnet loader that uses the Polygon blockchain for decentralized command-and-control (C2) operations. The malware retrieves encrypted or plaintext instructions from smart contracts on the blockchain by querying public RPC endpoints, enabling resilient and low-cost infrastructure resistant to takedowns. Three distinct malware samples were analyzed: the initial Aeternum loader, a Python-based downloader, and a multi-component payload combining XWorm RAT, XMRig cryptocurrency miner, and data exfiltration tools. The threat leverages Telegram APIs and GitHub repositories for secondary C2 and payload delivery, while using weak encryption schemes that allow decryption via contract address and payload analysis.
28 IoCs 2 Malware
An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation
4d ago · unit42
Unit 42 investigated a cyber attack in which a threat actor used frontier AI and agentic AI frameworks to autonomously breach an enterprise network, achieving in under 10 hours what would typically take human operators two weeks. The AI agents systematically executed reconnaissance, harvested credentials from code repositories, escalated privileges by accessing secrets management systems, hijacked CI/CD pipelines, and abused stolen cloud keys to leverage the victim's own AI infrastructure for further attacks. The attacker left behind an 80-page technical audit detailing exploited findings, highlighting the operational efficiency of AI-assisted attacks without relying on zero-day vulnerabilities.
UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations
2w ago · talos
Cisco Talos identified a Chinese-speaking threat actor, UAT-10147, conducting a global campaign targeting Windows and Linux web servers in government, education, media, technology, and gaming sectors. The actor leverages publicly disclosed vulnerabilities for initial access, including CVE-2022-27925, CVE-2021-23758, and CVE-2019-18935, and uses AI-driven tooling to automate exploitation, reconnaissance, payload generation, and validation. Post-compromise, the actor deploys malware such as QuasarRAT, Gh0stCringe, and SPECTRE, establishes persistence via scheduled tasks and rogue user accounts, and uses AI-generated scripts to refine attacks and bypass defenses. A misconfigured command-and-control server at 139.180.197[.]150 exposed operational details, including a target list of 170,000 URLs and AI-assisted attack workflows.
14 IoCs 2 Malware 8 CVEs
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
1d ago · hacker-news
A zero-day vulnerability in Magento Open Source and Adobe Commerce, dubbed StyleSmuggler, is being actively exploited to achieve unauthenticated remote code execution and install persistent backdoors on e-commerce platforms. The attack chain leverages malicious input in log files and abuse of Magento's internal classes to execute a PHP dropper, which downloads and runs a malicious Rust-based implant. The backdoor runs under a disguised process name and establishes persistence via cron, with capabilities to read session data from Redis. No data exfiltration or lateral movement has been observed so far, but the threat is ongoing. Adobe has not yet released a patch or official advisory.
13 IoCs
Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted
1d ago · hacker-news
Trezor disclosed that a breach at its shipping provider ShipMonk exposed personal data of 67,000 U.S. customers, including names, email addresses, phone numbers, shipping addresses, and order numbers from November 2019 to August 2021. The breach resulted from a zero-day SQL injection vulnerability, CVE-2026-72898, in Metabase that was exploited by the ShinyHunters extortion gang. Although Trezor had received assurances from ShipMonk that customer data was deleted, it remained in ShipMonk's systems and was accessed during the incident. Trezor warned users about potential social engineering and phishing attacks leveraging the stolen data.
1 Actors
Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
1d ago · hacker-news
Broadcom has patched two security vulnerabilities in VMware Workstation and Fusion, including a critical integer-overflow flaw (CVE-2026-59346) that could allow a local attacker with administrative privileges on a virtual machine to execute arbitrary code on the host. The second vulnerability is a stack-based buffer overflow in HGFS (CVE-2026-59347) that can also be exploited by a local admin to run code in the context of the VMX process on the host. Both vulnerabilities require local admin access within the VM, but could be leveraged after initial compromise via phishing or misconfigurations. The updates apply to versions 25H2 and 26H1, with fixes included in 26H1u1 releases. While no known in-the-wild exploitation of these specific flaws has been observed, recent VMware vCenter vulnerabilities have been actively exploited, including by a China-nexus APT actor.
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
1d ago · hacker-news
In August 2026, unidentified threat actors exploited a critical vulnerability, CVE-2026-63077, in JetBrains' TeamCity server to breach the Cadence cloud service environment. The attackers gained access to a 2024 backup of the Cadence server, extracting sensitive data including personal information, source code, and AWS IAM credentials belonging to JetBrains employees and users. JetBrains confirmed unauthorized access between August 8 and 24, 2026, and urged all Cadence users to immediately rotate credentials and treat all executions as potentially compromised due to exposure of secrets and configurations.
6 IoCs