Live threat intelligence — updated continuously

Open Cyber Threat Intelligence

Structured, AI-extracted threat intel. Free with no login required.

Latest Intelligence

View all →
Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks

22h ago · hacker-news

The Gigabud banking trojan, attributed to the threat actor GoldFactory, has evolved to use a second malicious app called Vwork to create Android work profiles. This technique isolates a tampered banking app within the work profile, evading malware detection by legitimate banking apps running in the personal profile. The attacker gains full control via Accessibility services, overlays fake login screens, and steals credentials and transaction data. This method has been confirmed in Indonesia, with activity observed across multiple countries, resulting in nearly $1 million in estimated losses.
3 IoCs 1 Actors 1 Malware
ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

15h ago · hacker-news

A Chinese-speaking threat actor is leveraging AI models like Anthropic Claude, Alibaba Qwen, and DeepSeek to automate cyber intrusions against government and financial systems in multiple countries, including Taiwan, Afghanistan, Thailand, and the U.S. The campaign uses an AI orchestration framework called SecFlow to divide tasks among specialized AI agents for reconnaissance, exploitation, and data collection. Exploited vulnerabilities include Log4Shell, Spring4Shell, and Shiro deserialization, leading to web shell deployment and lateral movement using a Go-based backdoor named SecBox. The campaign was first reported in July 2026. Another related campaign involves EtherRAT and TukTuk malware, where attackers deploy ransomware known as The Gentlemen after gaining access via malicious MSI installers and conducting credential theft and lateral movement.
3 IoCs 1 Malware
New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws

19h ago · bleeping-computer

A new exploit kit named 'BlueMoon' has been observed in the wild, leveraging chained zero-day vulnerabilities in Google Chrome and Microsoft Windows to achieve remote code execution and privilege escalation. The kit has been used by multiple cyber-espionage groups, including JungleBamboo (APT31) and UTA0560, in targeted attacks against NGOs, aerospace, defense, and manufacturing sectors. BlueMoon exploits three specific flaws: two in Chrome's V8 engine and one in Windows ALPC, enabling sandbox escape and local privilege escalation. The attacks are delivered via spearphishing, with payloads including malware loaders and in-memory backdoors such as Grimwedge and ShadowPad.
1 Actors 1 Malware 1 CVEs
Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers

17h ago · bleeping-computer

Cisco Talos identified three threat clusters exploiting two recently patched vulnerabilities in Cisco Secure Firewall Management Center (FMC): CVE-2026-20079 (authentication bypass, CVSS 10.0) and CVE-2026-20316 (static credentials, CVSS 5.3). UAT-11988, linked to Qilin ransomware affiliates, used static credentials to deploy ransomware after reconnaissance and lateral movement. UAT-11823, attributed to the Sandworm APT group, exploited both flaws to deploy a Cyclops Blink variant for persistent access and credential theft. UAT-12197 deployed a JSP web shell and malicious JAR file to steal credentials. Cisco confirmed exploitation of both vulnerabilities in active attacks.
2 IoCs 1 Actors 1 Malware
The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE

23h ago · unit42

This research demonstrates a post-exploitation technique enabling an attacker with root access on a compromised Kubernetes node to spoof workload identities in SPIFFE/SPIRE environments by manipulating Linux cgroup metadata. The attacker can trick the SPIRE agent into issuing legitimate SPIFFE Verifiable Identity Documents (SVIDs) belonging to co-located workloads, enabling identity impersonation and lateral movement. The trust model of SPIFFE/SPIRE collapses when node integrity is breached, as workload attestation relies on unspoofed cgroup information. The researchers developed an open-source tool called Spooffe to automate this attack for defensive testing purposes.
1 IoCs
Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE

21h ago · hacker-news

Check Point disclosed two critical vulnerabilities in its Security Gateways and Security Management Server products that could allow unauthenticated remote code execution during VPN certificate processing. The first, CVE-2026-85102, stems from improper certificate trust validation, while the second, CVE-2026-85103, is a heap-based buffer overflow in ASN.1 certificate decoding. Both vulnerabilities carry a CVSS score of 9.8 and affect multiple versions of Check Point's R81 and R82 product lines. While Check Point states the flaws were internally discovered and not yet exploited, mitigation is advised through Live Patch or Jumbo Hotfix updates, though some customers reported delays in patch availability and unclear mitigation instructions.
Google Play Early Access Abused to Push Thousands of Deceptive Android Apps

19h ago · hacker-news

Threat actors are abusing Google Play's Early Access program to distribute deceptive Android apps that promise rewards, casino winnings, or premium content but fail to deliver. These apps bypass user reviews and ratings, enabling malicious actors to promote them via social media ads featuring AI-generated celebrity deepfakes. The apps often deliver virtual rewards initially but stall progression before withdrawals, serving excessive ads to generate illicit revenue. Additional Android malware families such as Hagaseca, Mantax Otax, StreamRat, and Vwork are also active, with capabilities ranging from remote access and data theft to ransomware and financial fraud.
1 IoCs 1 Malware
IDScan confirms breach tied to 153 million stolen driver’s licenses

18h ago · bleeping-computer

IDScan, an identity verification company, confirmed a data breach in which an unauthorized third party may have accessed or copied customer information stored on its IDScan.net cloud platform. The breach is linked to a dark-web service called 'Nexus' that advertised access to over 153 million driver's license scans, along with millions of other government-issued IDs. The exposed data includes full names, government-issued identification numbers, and scanned images of driver's licenses. IDScan has engaged third-party specialists, is cooperating with federal law enforcement including the FBI, and is offering credit monitoring to affected individuals.
1 IoCs
Active exploitation of Cisco Secure Firewall Management Center vulnerabilities

1d ago · talos

Cisco Talos is tracking active exploitation of two vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software: CVE-2026-20079, a critical authentication bypass flaw, and CVE-2026-20316, which allows login via a low-privileged account. Three distinct threat clusters have been identified: UAT-12197 deployed a JSP web shell and a JAR-based command executor; UAT-11823, linked to Sandworm, used CVE-2026-20079 and CVE-2026-20316 to deploy Cyclops Blink malware via a Netcat reverse shell; and UAT-11988, a Qilin ransomware operator, leveraged static credentials to conduct reconnaissance, deploy tunneling tools, and execute ransomware. Customers are urged to apply available patches immediately.
10 IoCs 1 Malware
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

1d ago · hacker-news

Multiple espionage-motivated threat actors, including APT31 and several China-aligned clusters, have leveraged a previously undocumented exploit kit named BlueMoon to exploit unpatched vulnerabilities in Google Chrome and Microsoft Windows. The exploit chain combines CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 to achieve sandbox escape and local privilege escalation, delivered via phishing emails leading to malicious URLs. The kit downloads payloads such as the GemStone browser backdoor, ShadowPad, and Rust-based malware using DLL sideloading and in-memory execution techniques. The U.S. CISA has added all three CVEs to its KEV catalog, mandating federal agencies to patch them by mid-September 2026.
11 IoCs 1 Actors 1 Malware 1 CVEs